IP Library Granted Patent US 10,275,269
Granted Patent B1
US 10,275,269 · App. 15/167,853 · Granted Apr 30, 2019

Hypervisor to support nested virtualization

Inventors: Ian Pratt (Cambridge, GB); James Misra McKenzie (Cambridge, GB)
Assignee: Bromium, Inc.
G06F9/45558G06F2009/4557G06F2009/45583
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,275,269
App. No.
15/167,853
Granted
Apr 30, 2019
Kind
B1
Abstract

Approaches for performing nested virtualization using a hypervisor which does not support nested virtualization. A first hypervisor is loaded upon booting a computing device. The first hypervisor instantiates a first virtual machine, exposes an emulated hardware virtualization support interface to the first virtual machine, and executes a second hypervisor, which does not support nested virtualization, within the first virtual machine. The first hypervisor provides nested virtualization support to the second hypervisor to allow the second hypervisor to execute a third hypervisor within a second virtual machine by the first hypervisor abstracting hardware virtualization support to the third hypervisor.

Claims (44)

1. One or more non-transitory machine-readable storage mediums storing one or more sequences of instructions for performing nested virtualization, which when executed by one or more processors, causes:

performing nested virtualization using a hypervisor which does not support nested virtualization by:

upon booting a computing device, loading a first hypervisor;

the first hypervisor (1) instantiating a first virtual machine, (2) exposing an emulated hardware virtualization support interface to the first virtual machine, and (3) executing a second hypervisor, which does not support nested virtualization, within the first virtual machine;

the first hypervisor providing nested virtualization support to the second hypervisor to allow the second hypervisor to execute a third hypervisor within a second virtual machine, wherein providing nested virtualization support comprises the first hypervisor abstracting hardware virtualization support directly to the third hypervisor using a paravirtual interface; and

the first hypervisor dynamically assigning the second hypervisor root privilege when the second hypervisor is not executing the third hypervisor or any virtual machine instantiated by the third hypervisor.

2. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein the first hypervisor ensures a correct enactment and enforcement of constraints against any virtual machines instantiated by said third hypervisor, wherein said constraints are those constraints applied by the second hypervisor to the second virtual machine in which the third hypervisor executes.

3. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein the third hypervisor is an unmodified hypervisor.

4. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein said paravirtual interface is employed by said third hypervisor to communicate, to the first hypervisor, information about CPU state in which a particular virtual machine, either currently instantiated or requested to be instantiated by the third hypervisor, is to be executed.

5. The one or more non-transitory machine-readable storage of claim 1 , wherein said paravirtual interface is employed by said third hypervisor to communicate, to the first hypervisor, information about a mapping between (a) memory pages for a virtual machine in which the third hypervisor wishes to execute and (b) memory pages belonging to the second virtual machine.

6. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein the second hypervisor is in an unmodified state.

7. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein the second hypervisor is in a modified state, relative to any manufacturer release, as stored on disk or is binary patched.

8. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein the first hypervisor corrects any known security issue in the operation of the second hypervisor prior to an official update to address said known security issue being available for the second hypervisor.

9. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein the first hypervisor ensures a correct enactment and enforcement of any constraints applied by the second hypervisor and the third hypervisor.

10. One or more non-transitory machine-readable storage mediums storing one or more sequences of instructions for providing one or more services to a hypervisor, which when executed by one or more processors, causes:

upon booting a computing device, loading a first hypervisor;

the first hypervisor (1) instantiating a first virtual machine, (2) exposing an emulated hardware virtualization support interface to the first virtual machine, and (3) executing a second hypervisor;

the second hypervisor executing a third hypervisor within a second nested virtual machine; and

the first hypervisor dynamically assigning the second hypervisor root privilege when the second hypervisor is not executing the third hypervisor or any virtual machine instantiated by the third hypervisor,

wherein the first hypervisor provides one or more services directly to the third hypervisor.

11. An apparatus for performing nested virtualization, comprising:

one or more processors; and

one or more non-transitory computer-readable storage mediums storing one or more sequences of instructions, which when executed, cause:

performing nested virtualization using a hypervisor which does not support nested virtualization by:

upon booting a computing device, loading a first hypervisor;

the first hypervisor (1) instantiating a first virtual machine, (2) exposing an emulated hardware virtualization support interface to the first virtual machine, and (3) executing a second hypervisor, which does not support nested virtualization, within the first virtual machine;

the first hypervisor providing nested virtualization support to the second hypervisor to allow the second hypervisor to execute a third hypervisor within a second virtual machine, wherein providing nested virtualization support comprises the first hypervisor abstracting hardware virtualization support directly to the third hypervisor using a paravirtual interface;

the first hypervisor dynamically assigning the second hypervisor root privilege when the second hypervisor is not executing the third hypervisor or any virtual machine instantiated by the third hypervisor.

12. The apparatus of claim 11 , wherein the first hypervisor ensures a correct enactment and enforcement of constraints against any virtual machines instantiated by said third hypervisor, wherein said constraints are those constraints applied by the second hypervisor to the second virtual machine in which the third hypervisor executes.

13. The apparatus of claim 11 , wherein the third hypervisor is an unmodified hypervisor.

14. The apparatus of claim 11 , wherein said paravirtual interface is employed by said third hypervisor to communicate, to the first hypervisor, information about CPU state in which a particular virtual machine, either currently instantiated or requested to be instantiated by the third hypervisor, is to be executed.

15. The apparatus of claim 11 , wherein said paravirtual interface is employed by said third hypervisor to communicate, to the first hypervisor, information about a mapping between (a) memory pages for a virtual machine in which the third hypervisor wishes to execute and (b) memory pages belonging to the second virtual machine.

16. The apparatus of claim 11 , wherein the second hypervisor is in an unmodified state.

17. The apparatus of claim 11 , wherein the second hypervisor is in a modified state, relative to any manufacturer release, as stored on disk or is binary patched.

18. The apparatus of claim 11 , wherein the first hypervisor corrects any known security issue in the operation of the second hypervisor prior to an official update to address said known security issue being available for the second hypervisor.

19. The apparatus of claim 11 , wherein the first hypervisor ensures a correct enactment and enforcement of any constraints applied by the second hypervisor and the third hypervisor.

20. An apparatus for providing one or more services to a hypervisor, comprising:

one or more processors; and

one or more non-transitory computer-readable storage mediums storing one or more sequences of instructions, which when executed, cause:

upon booting a computing device, loading a first hypervisor;

the first hypervisor (1) instantiating a first virtual machine, (2) exposing an emulated hardware virtualization support interface to the first virtual machine, and (3) executing a second hypervisor; and

the second hypervisor executing a third hypervisor within a second nested virtual machine,

wherein the first hypervisor provides one or more services directly to the third hypervisor; and

the first hypervisor dynamically assigning the second hypervisor root privilege when the second hypervisor is not executing the third hypervisor or any virtual machine instantiated by the third hypervisor.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2019
From: BROMIUM, INC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 051305/0894 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2016
From: PRATT, IAN; MCKENZIE, JAMES MISRA
To: BROMIUM, INC.
Reel/Frame 039031/0032 →
Cited By (3)
US 12,346,718 US 12,353,903 US 12,625,959