IP Library Granted Patent US 11,989,575
Granted Patent B2
US 11,989,575 · App. 16/893,904 · Granted May 21, 2024

Bi-directional interpositioning of virtual hardware

Inventors: Adrianne Conage (Baltimore, MD); Yasmine A. Zakout (Alexandria, VA)
Assignee: NIGHTWING GROUP, LLC.
G06F9/45558G06F9/546G06F13/4221G06F2009/45562G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,989,575
App. No.
16/893,904
Granted
May 21, 2024
Kind
B2
Abstract

A method is provided comprising: retrieving a message that is designated for transmission via a first one of a plurality of communications hardware devices, the message being retrieved from a virtual device queue that is associated with the first communications hardware device, the message being generated by a first virtual machine, and the message being designated for transmission to a second virtual machine; selecting a second one of the plurality of communications hardware devices based on a characteristic of the message; and storing the message in a socket queue that is associated with the second communications hardware device, wherein storing the message in the socket queue that is associated with the second communications hardware device causes the message to be transmitted to the second virtual machine via the second communications hardware device rather than the first communications hardware device.

Claims (35)

1. A method comprising:

retrieving a message that is designated for transmission via a first one of a plurality of communications hardware devices, the message being retrieved from a virtual device queue associated with an abstraction of the first communications hardware device, the abstraction of the first communication s hardware device and the virtual device queue being provided by a hypervisor executing a first virtual machine, the message being generated by the first virtual machine, and the message being designated for transmission to a second virtual machine;

selecting a second one of the plurality of communications hardware devices based on a policy rule, the policy rule including a condition identifying: (i) the first virtual machine as a source virtual machine for messages against which the policy rule is applied, (ii) the second virtual machine as a destination virtual machine for the messages against which the policy rule is applied, and (iii) a respective identifier of the second communications hardware device, thereby designating the second communications hardware device as a preferred device for handling messages that are transmitted from the first virtual machine to the second virtual machine, the policy rule being enforced against messages that are transmitted from the first virtual machine to the second virtual machine; and

storing the message in a socket queue that is associated with the second communications hardware device, the socket queue being provided outside of the hypervisor in an operating system that is executing the hypervisor,

wherein storing the message in the socket queue that is associated with the second communications hardware device causes the message to be transmitted to the second virtual machine via the second communications hardware device rather than the first communications hardware device, the first and second communications hardware devices being part of a computing system that is executing the first virtual machine,

wherein the first communications hardware device is configured to transmit and receive data over a first communications channel that is not monitored by a monitoring utility, the second communications hardware device is configured to transmit and receive data over a second communications channel that is monitored by the monitoring utility, and storing the message in the socket queue that is associated with the second communications hardware device causes the message to be examined by the monitoring utility.

2. The method of claim 1 , wherein the second virtual machine is executed by the hypervisor.

3. The method of claim 1 , wherein the first virtual machine and the second virtual machine are at least one of: (i) executed by using different hypervisors or (ii) executed on different computing systems.

4. The method of claim 1 , wherein the identifier of the second communications hardware device includes an identifier of the socket queue that is associated with the second communications hardware device.

5. The method of claim 1 , wherein the first communications hardware device includes a Peripheral Component Interconnect (PCI) bus controller, and the second communications hardware device includes an Ethernet controller.

6. The method of claim 1 , wherein the first virtual machine and the second virtual machine are both executed by the hypervisor, and the virtual device queue is part of the abstraction of the first communications hardware device.

7. A system comprising:

a plurality of communications hardware devices;

a memory; and

at least one processor operatively coupled to the memory, the at least one processor being configured to perform the operations of:

retrieving a message that is designated for transmission via a first one of the plurality of communications hardware devices, the message being retrieved from a virtual device queue associated with an abstraction of the first communications hardware device, the abstraction of the first communications hardware device and the virtual device queue being provided by a hypervisor executing a first virtual machine, the message being generated by the first virtual machine, and the message being designated for transmission to a second virtual machine, the first virtual machine being executed by the at least one processor;

selecting a second one of the plurality of communications hardware devices based on a policy rule, the policy rule including a condition identifying: (i) the first virtual machine as a source virtual machine for messages against which the policy rule is applied, (ii) the second virtual machine as a destination virtual machine for the messages against which the policy rule is applied, and (iii) a respective identifier of the second communications hardware device, thereby designating the second communications hardware device as a preferred device for handling messages that are transmitted from the first virtual machine to the second virtual machine, the policy rule being enforced against messages that are transmitted from the first virtual machine to the second virtual machine; and

storing the message in a socket queue that is associated with the second communications hardware device, the socket queue being provided outside of the hypervisor in an operating system that is executing the hypervisor,

wherein storing the message in the socket queue that is associated with the second communications hardware device causes the message to be transmitted to the second virtual machine via the second communications hardware device rather than the first communications hardware device,

wherein the first communications hardware device is configured to transmit and receive data over a first communications channel that is not monitored by a monitoring utility, the second communications hardware device is configured to transmit and receive data over a second communications channel that is monitored by the monitoring utility, and storing the message in the socket queue that is associated with the second communications hardware device causes the message to be examined by the monitoring utility.

8. The system of claim 7 , wherein second virtual machine is executed by the hypervisor.

9. The system of claim 7 , wherein the first virtual machine and the second virtual machine are at least one of: (i) executed by using different hypervisors or (ii) executed on different computing devices.

10. The system of claim 7 , wherein the identifier of the second communications hardware device includes an identifier of the socket queue that is associated with the second communications hardware device.

11. The system of claim 7 , wherein the first communications hardware device includes a Peripheral Component Interconnect (PCI) bus controller, and the second communications hardware device includes an Ethernet controller.

12. The system of claim 7 , wherein the first virtual machine and the second virtual machine are both executed by the hypervisor, and the virtual device queue is part of the abstraction of the first communications hardware device.

13. A non-transitory computer-readable medium storing one or more processor-executable instructions, which when executed by at least one processor to perform the operations of:

retrieving a message that is designated for transmission via a first one of a plurality of communications hardware devices, the message being retrieved from a virtual device queue associated with an abstraction of the first communications hardware device, the abstraction of the first communications hardware device and the virtual device queue being provided by a hypervisor executing a first virtual machine, the message being generated by the first virtual machine, and the message being designated for transmission to a second virtual machine;

selecting a second one of the plurality of communications hardware devices based on a policy rule, the policy rule including a condition identifying: (i) the first virtual machine as a source virtual machine for messages against which the policy rule is applied, (ii) the second virtual machine as a destination virtual machine for the messages against which the policy rule is applied, and (iii) a respective identifier of the second communications hardware device, thereby designating the second communications hardware device as a preferred device for handling messages that are transmitted from the first virtual machine to the second virtual machine, the policy rule being enforced against messages that are transmitted from the first virtual machine to the second virtual machine; and

storing the message in a socket queue that is associated with the second communications hardware device, the socket queue being provided outside of the hypervisor in an operating system that is executing the hypervisor,

wherein storing the message in the socket queue that is associated with the second communications hardware device causes the message to be transmitted to the second virtual machine via the second communications hardware device rather than the first communications hardware device, the first communications hardware device, the second communications hardware device, and the processor being part of a computing system that is executing the first virtual machine,

wherein the first communications hardware device is configured to transmit and receive data over a first communications channel that is not monitored by a monitoring utility, the second communications hardware device is configured to transmit and receive data over a second communications channel that is monitored by the monitoring utility, and storing the message in the socket queue that is associated with the second communications hardware device causes the message to be examined by the monitoring utility.

14. The non-transitory computer-readable medium of claim 13 , wherein second virtual machine is executed by the hypervisor.

15. The non-transitory computer-readable medium of claim 13 , wherein the first virtual machine and the second virtual machine are at least one of: (i) executed by using different hypervisors or (ii) executed on different computing devices.

16. The non-transitory computer-readable medium of claim 13 , wherein the identifier of the second hardware device includes an identifier of the socket queue that is associated with the second communications hardware device.

17. The non-transitory computer-readable medium of claim 13 , wherein the first communications hardware device includes a Peripheral Component Interconnect (PCI) bus controller, and the second communications hardware device includes an Ethernet controller.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2024
From: RAYTHEON COMPANY
To: COLUMBUS BUYER LLC
Reel/Frame 067150/0174 →
CHANGE OF NAME Recorded Apr 18, 2024
From: COLUMBUS BUYER LLC
To: NIGHTWING GROUP, LLC
Reel/Frame 067160/0991 →
SECURITY INTEREST Recorded Apr 1, 2024
From: COLUMBUS BUYER LLC; RAYTHEON BLACKBIRD TECHNOLOGIES, INC.; RAYTHEON FOREGROUND SECURITY, INC.
To: WELLS FARGO BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066960/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2020
From: CONAGE, ADRIANNE; ZAKOUT, YASMINE A.
To: RAYTHEON COMPANY
Reel/Frame 052853/0961 →
Continuity (1)
Related Publication 20210382742A1 · Dec 9, 2021