IP Library Granted Patent US 10,452,420
Granted Patent B1
US 10,452,420 · App. 15/341,445 · Granted Oct 22, 2019

Virtualization extension modules

Inventors: Alexey Koryakin (Moscow, RU); Nikolay Dobrovolskiy (Moscow, RU); Serguei M. Beloussov (Singapore, SG)
G06F9/45558G06F2009/45575G06F2009/45579
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,452,420
App. No.
15/341,445
Granted
Oct 22, 2019
Kind
B1
Abstract

Systems and methods for processing virtual machine I/O requests by virtualization extension modules. An example method comprises: receiving, by a virtual machine monitor (VMM) running on a host computer system, a request initiated by a virtual machine managed by the VMM; processing the request by a VMM extension module identified by one or more parameters of the request; invoking, by the VMM extension module, an application programming interface (API) exported by the VMM to perform an action identified by the request; and resuming execution of the virtual machine.

Claims (36)

1. A method, comprising:

receiving, by a virtual machine monitor (VMM) running on a host computer system, execution control via a virtual machine (VM) exit triggered by a first input/output (I/O) request initiated by a virtual machine managed by the VMM, wherein the VMM is executed in a privileged context which is isolated from a kernel context of the host computer system;

processing the first I/O request by a VMM extension module identified by one or more parameters of the first I/O request;

invoking, by the VMM extension module, an application programming interface (API) exported by the VMM to perform an action identified by the first I/O request; and

resuming execution of the virtual machine.

2. The method of claim 1 , wherein the action comprises transmitting, to an extension module of a virtual machine controller running on the host computer system, a second request associated with the first I/O request.

3. The method of claim 2 , wherein resuming execution of the virtual machine is performed responsive to receiving a response to the second request from the virtual machine controller.

4. The method of claim 2 , wherein the virtual machine controller is running in a user space context of the host computer system.

5. The method of claim 1 , wherein the first I/O request is represented by a synchronous I/O request initiated by issuing a pre-defined instruction of an instruction set architecture of the virtual machine.

6. The method of claim 1 , wherein the first I/O request is represented by an asynchronous I/O request.

7. The method of claim 6 , wherein the asynchronous I/O request is initiated by issuing a direct memory access (DMA) request.

8. The method of claim 1 , wherein processing the first I/O request by a VMM extension module further comprises:

responsive to matching one or more parameters of the first I/O request to a request inspection pattern, raising a guest execution exception.

9. The method of claim 8 , wherein the request inspection pattern comprises a combination of values of at least one of: a type of the fist I/O request, an identifier of an application issuing the fist I/O request, a current privilege level of the application issuing the fist I/O request, a device identifier or a memory address.

10. The method of claim 1 , wherein processing the first I/O request by the VMM extension module further comprises:

responsive to failing to match parameters of the first I/O request to one or more request inspection patterns, forwarding the fist I/O request to a virtual machine controller running on the host computer system.

11. The method of claim 1 , wherein the first I/O request is initiated by a device driver running in a privileged context of the virtual machine.

12. The method of claim 1 , wherein the first I/O request is initiated by a virtual machine extension module associated with the virtual machine.

13. The method of claim 12 , wherein the VMM extension module implements antivirus functionality.

14. The method of claim 1 , further comprising:

exporting, by the VMM extension module, a callback interface specifying a callback function to be invoked prior to invoking a specified function of a VMM API for accessing a resource of the host computer system.

15. A computer system, comprising:

a memory; and

a processing device coupled to the memory, the processing device configured to execute a virtual machine (VM) controller application running in a user space context of the computer system, a virtual machine monitor (VMM) running in a privileged execution mode context which is isolated from a kernel context of the computer system, and a virtual machine executing a guest operating system managing one or more guest applications;

wherein the VMM is configured to:

receive an input/output (I/O) request initiated by the virtual machine;

identify, based on one or more parameters of the I/O request, a VMM extension module running in a context shared with the VMM; and

responsive to matching, by the VMM extension module, one or more parameters of the I/O request to a request inspection pattern, raise a guest execution exception.

16. The system of claim 15 , wherein the VMM extension module is further configured to:

responsive to failing to match parameters of the I/O request to one or more request inspection patterns, forwarding the I/O request to the VM controller application.

17. A non-transitory computer-readable storage medium comprising executable instructions that, when executed by a processing device of a host computer system, cause the processing device to:

receive, by a virtual machine monitor (VMM) running on a host computer system, execution control via a virtual machine (VM) exit triggered by a first input/output (I/O) request initiated by a virtual machine managed by the VMM, wherein the VMM is executed in a privileged context which is isolated from a kernel context of the host computer system;

process the first I/O request by a VMM extension module identified by one or more parameters of the first I/O request;

invoke, by the VMM extension module, an application programming interface (API) exported by the VMM to transmit, to a virtual machine controller application running in a user space context of the host computer system, a second request associated with the first I/O request; and

resume execution of the virtual machine.

18. The non-transitory computer-readable storage medium of claim 17 , wherein resuming execution of the virtual machine is performed responsive to receiving a response to the second request from the virtual machine controller.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jul 18, 2019
From: UBS AG, STAMFORD BRANCH, AS ADMINISTRATIVE AND COLLATERAL AGENT
To: COREL CORPORATION; CLEARSLIDE, INC.; PARALLELS INTERNATIONAL GMBH
Reel/Frame 049787/0073 →
RELEASE OF SECURITY INTEREST RECORDED AT : REEL 047973 FRAME 0797 Recorded Jul 17, 2019
From: UBS AG, STAMFORD BRANCH
To: PARALLELS INTERNATIONAL GMBH
Reel/Frame 049773/0590 →
SECURITY INTEREST Recorded Dec 21, 2018
From: PARALLELS INTERNATIONAL GMBH
To: UBS AG, STAMFORD BRANCH
Reel/Frame 047973/0797 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2016
From: KORYAKIN, ALEXEY; DOBROVOLSKIY, NIKOLAY; BELOUSSOV, SERGUEI M.
To: PARALLELS INTERNATIONAL GMBH
Reel/Frame 040199/0312 →
Cited By (2)
US 12,322,228 US 12,639,131