IP Library Granted Patent US 9,946,870
Granted Patent B2
US 9,946,870 · App. 14/922,898 · Granted Apr 17, 2018

Apparatus and method thereof for efficient execution of a guest in a virtualized enviroment

Inventors: Izik Eidus (Kfar Saba, IL); Leonid Shatz (Raanana, IL); Michael Rapoport (Haifa, IL); Alexander Fishman (Netanya, IL)
Assignee: Ravello Systems Ltd.
G06F21/53G06F9/45545G06F9/45558G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,946,870
App. No.
14/922,898
Granted
Apr 17, 2018
Kind
B2
Abstract

A method and apparatus for efficiently executing guest programs in a virtualized computing environment are presented. The method includes executing a virtual machine on a computing hardware; executing a single hypervisor in a first security ring on the virtual machine; executing a single guest program on the virtual machine, wherein the single guest program includes a single kernel being executed in the first security ring and at least one application being executed in a second security ring; and executing at least an instruction issued by the at least one application without trapping the single hypervisor.

Claims (39)

1. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising:

receiving a request to execute a particular guest program on a virtual machine;

identifying a set of one or more virtual machines currently being executed;

determining whether any of the set of virtual machines are executing without a corresponding guest program;

responsive to determining that all of the set of virtual machines are executing with at least one corresponding guest program:

instantiating a new virtual machine for execution of the particular guest program, wherein a hypervisor corresponding to the new virtual machine executes in a first security ring;

executing the particular guest program on the new virtual machine, wherein a kernel of the particular guest program executes in the first security ring.

2. The medium of claim 1 , wherein the operations further comprise: refraining from executing any additional guest programs on the new virtual machine.

3. The medium of claim 1 , wherein the operations further comprise: executing a single guest program on the new virtual machine.

4. The medium of claim 1 , wherein the operations further comprise: refraining from executing any additional guest programs on the hypervisor corresponding to the new virtual machine.

5. The medium of claim 1 , wherein the operations further comprise executing at least one application of the guest program in a different security ring than (a) the hypervisor and (b) the kernel of the guest program.

6. The medium of claim 1 , wherein both (a) the hypervisor and (b) the kernel of the guest program include functionality to access a same memory region.

7. The medium of claim 1 , wherein both (a) the hypervisor and (b) the kernel of the guest program include functionality to access a same data set.

8. The medium of claim 1 , wherein execution of at least one instruction by an application of the guest program requires processing by (a) the hypervisor and (b) the kernel of the guest program.

9. The medium of claim 1 , wherein an execution context may be switched between applications of the guest program while accessing address space corresponding to a same security ring and without accessing address space corresponding to any other security ring.

10. A method comprising:

receiving a request to execute a particular guest program on a virtual machine;

identifying a set of one or more virtual machines currently being executed;

determining whether any of the set of virtual machines are executing without a corresponding guest program;

responsive to determining that all of the set of virtual machines are executing with at least one corresponding guest program:

instantiating a new virtual machine for execution of the particular guest program, wherein a hypervisor corresponding to the new virtual machine executes in a first security ring;

executing the particular guest program on the new virtual machine, wherein a kernel of the particular guest program executes in the first security ring,

wherein the method is executed by at least one device including a hardware processor.

11. The method of claim 10 , wherein the operations further comprise: refraining from executing any additional guest programs on the new virtual machine.

12. The method of claim 10 , wherein the operations further comprise: executing a single guest program on the new virtual machine.

13. The method of claim 10 , wherein the operations further comprise: refraining from executing any additional guest programs on the hypervisor corresponding to the new virtual machine.

14. The method of claim 10 , wherein the operations further comprise executing at least one application of the guest program in a different security ring than (a) the hypervisor and (b) the kernel of the guest program.

15. The method of claim 10 , wherein both (a) the hypervisor and (b) the kernel of the guest program include functionality to access a same memory region or a same data set.

16. The method of claim 10 , wherein execution of at least one instruction by an application of the guest program requires processing by (a) the hypervisor and (b) the kernel of the guest program.

17. The method of claim 10 , wherein an execution context may be switched between applications of the guest program while accessing address space corresponding to a same security ring and without accessing address space corresponding to any other security ring.

18. A system comprising:

at least one device including a hardware processor;

the system being configured to perform operations comprising:

receiving a request to execute a particular guest program on a virtual machine;

identifying a set of one or more virtual machines currently being executed;

determining whether any of the set of virtual machines are executing without a corresponding guest program;

responsive to determining that all of the set of virtual machines are executing with at least one corresponding guest program:

instantiating a new virtual machine for execution of the particular guest program, wherein a hypervisor corresponding to the new virtual machine executes in a first security ring;

executing the particular guest program on the new virtual machine, wherein the particular guest program executes in the first security ring.

Assignments (3)
CHANGE OF NAME Recorded Mar 4, 2021
From: RAVELLO SYSTEMS LTD.
To: ORACLE RAVELLO SYSTEMS LTD.
Reel/Frame 055489/0754 →
CHANGE OF NAME Recorded Mar 4, 2021
From: RAVELLO SYSTEMS LTD
To: ORACLE RAVELLO SYSTEMS LTD
Reel/Frame 055492/0005 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2021
From: EIDUS, IZIK; SHATZ, LEONID; RAPOPORT, MICHAEL; FISHMAN, ALEXANDER
To: RAVELLO SYSTEMS, LTD.
Reel/Frame 055364/0286 →
Continuity (3)
Continuation 13685099 · Nov 26, 2012
Provisional Application 61563859 · Nov 28, 2011
Related Publication 20160048676A1 · Feb 18, 2016