IP Library › Granted Patent US 12,248,807
Granted Patent B2
US 12,248,807 · App. 17/134,339 · Granted Mar 11, 2025

Methods, apparatus, systems, and instructions to migrate protected virtual machines

Inventors: Ravi Sahita (Portland, OR); Dror Caspi (Kiryat Yam, IL); Vincent Scarlata (Beaverton, OR); Sharon Yaniv (Kiryat Tivon, IL); Baruch Chaikin (D.N. Misagv, IL); Vedvyas Shanbhogue (Austin, TX); Jun Nakajima (San Ramon, CA); Arumugam Thiyagarajah (Folsom, CA); Sean Christopherson (Portland, OR); Haidong Xia (Folsom, CA); Vinay Awasthi (San Francisco, CA); Isaku Yamahata (Urayasu, JP); Wei Wang (Shanghai, CN); Thomas Adelmeyer (Phoenix, AZ)
Assignee: Intel Corporation
G06F9/4856G06F9/3836G06F9/45558G06F21/602G06F2009/4557G06F2009/45587G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,248,807
App. No.
17/134,339
Granted
Mar 11, 2025
Kind
B2
Abstract

Techniques for migration of a source protected virtual machine from a source platform to a destination platform are descried. A method of an aspect includes enforcing that bundles of state, of a first protected virtual machine (VM), received at a second platform over a stream, during an in-order phase of a migration of the first protected VM from a first platform to the second platform, are imported to a second protected VM of the second platform, in a same order that they were exported from the first protected VM. Receiving a marker over the stream marking an end of the in-order phase. Determining that all bundles of state exported from the first protected VM prior to export of the marker have been imported to the second protected VM. Starting an out-of-order phase of the migration based on the determination that said all bundles of the state exported have been imported.

Claims (61)

1. An apparatus comprising:

a processor; and

a non-transitory machine-readable storage medium, the non-transitory machine-readable storage medium storing a plurality of instructions, the plurality of instructions, if executed by the processor, to cause the processor to perform operations comprising to:

enforce, in response to execution of bundle import control primitives by circuitry of the processor, that a plurality of bundles of state of a first protected virtual machine (VM), received at a second platform over a stream during an in-order phase of a migration of the first protected VM from a first platform to the second platform, are imported and stored to a memory of a second protected VM of the second platform, in a same order that the plurality of bundles of state were exported from the first protected VM;

determine whether all bundles of state exported from the first protected VM prior to export of a marker of an end of the in-order phase of the migration, which is to have been received over the stream, have been imported to the second protected VM; and

determine whether to start an out-of-order phase of the migration based on whether the determination is that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have been imported to the second protected VM.

2. The apparatus of claim 1 , wherein the instructions to determine whether to start the out-of-order phase of the migration further comprise instructions that, if executed by the processor, are to cause the processor to perform operations comprising to:

determine to start the out-of-order phase of the migration upon a determination that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have been imported to the second protected VM;

determine to abort the migration upon a determination that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have not been imported to the second protected VM; and

in response to determining to abort the migration, send an abort token to the first platform, the abort token to indicate the first protected VM on the first platform is allowed to restart after its execution has stopped.

3. The apparatus of claim 1 , wherein the plurality of bundles of state are encrypted with a migration capable key according to a counter-mode encryption, further comprising a protected migration service VM to authenticate the second platform to the first platform, and wherein the migration capable key is not kept confidential from the protected migration service VM but is kept confidential from a virtual machine monitor (VMM).

4. The apparatus of claim 1 , wherein the marker is encrypted and integrity protected according to counter-mode encryption with a migration capable key that is kept confidential from a virtual machine monitor (VMM).

5. An apparatus comprising:

a central processing unit (CPU); and

a processor coupled with the CPU, the processor comprising:

first circuitry to enforce, in response to execution of control primitives by circuitry of the processor, that a plurality of bundles of state of a first protected virtual machine (VM), received at a second platform over a stream during an in-order phase of a migration of the first protected VM from a first platform to the second platform, are imported and stored to a memory of a second protected VM of the second platform, in a same order that the plurality of bundles of state were exported from the first protected VM;

second circuitry to determine whether all bundles of state exported from the first protected VM prior to export of a marker of an end of the in-order phase of the migration, which is to have been received over the stream, have been imported to the second protected VM; and

third circuitry to determine whether to start an out-of-order phase of the migration based on whether the determination is that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have been imported to the second protected VM.

6. The apparatus of claim 5 , wherein the third circuitry is to:

determine to start the out-of-order phase of the migration upon a determination that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have been imported to the second protected VM;

determine to abort the migration upon a determination that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have not been imported to the second protected VM; and

in response to determining to abort the migration, send an abort token to the first platform, the abort token to indicate that the first protected VM on the first platform is allowed to restart after its execution has stopped.

7. The apparatus of claim 5 , wherein the plurality of bundles of state are encrypted with a migration capable key according to a counter-mode encryption, further comprising a protected migration service VM to authenticate the second platform to the first platform, and wherein the migration capable key is not kept confidential from the protected migration service VM but is kept confidential from a virtual machine monitor (VMM).

8. The apparatus of claim 5 , wherein the marker is encrypted and integrity protected according to counter-mode encryption with a migration capable key that is kept confidential from a virtual machine monitor (VMM).

9. The apparatus of claim 5 , wherein the stream is a counter-mode encrypted and authenticated stream.

10. A method comprising:

enforcing, in response to execution of control primitives by circuitry of a processor, that a plurality of bundles of state, of a first protected virtual machine (VM), received at a second platform over a stream, during an in-order phase of a migration of the first protected VM from a first platform to the second platform, are imported and stored to a memory of a second protected VM of the second platform, in a same order that the plurality of bundles of state were exported from the first protected VM;

receiving a marker over the stream, the marker to mark an end of the in-order phase of the migration;

determining that all bundles of state exported from the first protected VM prior to export of the marker over the stream have been imported to the second protected VM; and

starting an out-of-order phase of the migration based on the determination that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have been imported to the second protected VM.

11. The method of claim 10 , further comprising, in the out-of-order phase of the migration, allowing a second plurality of bundles of state to be imported to the second protected VM in a different order than an order the second plurality of bundles of state were exported from the first protected VM.

12. The method of claim 10 , further comprising starting execution of the second protected VM based on the determination that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have been imported to the second protected VM.

13. The method of claim 10 , wherein said enforcing comprises enforcing values in the plurality of bundles of state, which are indicative of the order that the plurality of bundles of state were exported from the first protected VM, to be respectively consistent with values indicative of a number of the plurality of bundles of state imported into the second protected VM.

14. The method of claim 10 , further comprising:

receiving a plurality of bundles of state of the first protected VM over a second stream;

processing the plurality of bundles of state received over the stream with a first virtual central processing unit (vCPU); and

processing the plurality of bundles of state received over the second stream with a second vCPU.

15. The method of claim 10 , further comprising:

enforcing that a second plurality of bundles of state of the first protected VM, received at the second platform over a second stream during the in-order phase of the migration, are imported to the second protected VM, in a same order that the second plurality of bundles of state were exported from the first protected VM;

receiving a second marker over the second stream; and

determining that all bundles of state exported from the first protected VM prior to export of the second marker over the second stream have been imported to the second protected VM prior to the determination that said all bundles of state exported from the first protected VM prior to the export of the marker over the stream have been imported to the second protected VM.

16. The method of claim 10 , further comprising receiving a marker over each of a plurality of streams used to convey bundles of state of the first protected VM to the second platform, and wherein receiving the marker over the stream comprises receiving the marker over the stream after receiving the markers over the plurality of streams.

17. The method of claim 10 , further comprising receiving a command primitive from a virtual machine monitor, and wherein said determining and said starting are performed responsive to the command primitive.

18. The method of claim 10 , wherein the stream is a counter-mode encrypted and authenticated stream, wherein the second protected VM is a trust domain, and further comprising maintaining state of the trust domain confidential from a virtual machine monitor of the second platform.

19. The method of claim 10 , wherein the marker is encrypted with a migration capable key that is kept confidential from a virtual machine monitor (VMM).

20. The method of claim 10 , further comprising importing a plurality of bundles of state, of the first protected VM, received at the second platform over a second stream, to a third protected VM of the second platform, when a migration policy of the first protected VM permits multiple instances of the first protected VM to be created.

21. A non-transitory machine-readable storage medium, the non-transitory machine-readable storage medium storing a plurality of instructions, the plurality of instructions, if executed by a machine, to cause the machine to perform operations comprising to:

enforce, in response to execution of control primitives by circuitry of a processor, that a plurality of bundles of state of a first protected virtual machine (VM), received at a second platform over a stream during an in-order phase of a migration of the first protected VM from a first platform to the second platform, are imported and stored to a memory of a second protected VM of the second platform, in a same order that the plurality of bundles of state were exported from the first protected VM;

determine whether all bundles of state exported from the first protected VM prior to export of a marker of an end of the in-order phase of the migration, which is to have been received over the stream, have been imported to the second protected VM; and

determine whether to start an out-of-order phase of the migration based on whether the determination is that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have been imported to the second protected VM.

22. The non-transitory machine-readable storage medium of claim 21 , wherein the instructions to determine whether to start the out-of-order phase of the migration further comprise instructions that, if executed by the machine, are to cause the machine to perform operations comprising to:

determine to start the out-of-order phase of the migration upon a determination that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have been imported to the second protected VM.

23. The non-transitory machine-readable storage medium of claim 21 , wherein the instructions to determine whether to start the out-of-order phase of the migration further comprise instructions that, if executed by the machine, are to cause the machine to perform operations comprising to:

determine to abort the migration upon a determination that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have not been imported to the second protected VM; and

in response to determining to abort the migration, send an abort token to the first platform, the abort token to indicate that the first protected VM on the first platform is allowed to restart after its execution has stopped.

24. The non-transitory machine-readable storage medium of claim 21 , wherein the instructions further comprise instructions that, if executed by the machine, are to cause the machine to perform operations comprising to:

allow, in the out-of-order phase of the migration, a second plurality of bundles of state to be imported to the second protected VM in a different order than an order the second plurality of bundles of state were exported from the first protected VM during the out-of-order phase of the migration.

25. The non-transitory machine-readable storage medium of claim 21 , wherein the instructions further comprise instructions that, if executed by the machine, are to cause the machine to perform operations comprising to:

determine whether to start execution of the second protected VM based on whether the determination is that said all bundles of the state exported from the first protected VM prior to export of the marker over the stream have been imported to the second protected VM.

26. The non-transitory machine-readable storage medium of claim 21 , wherein the instructions to said enforce further comprise instructions that, if executed by the machine, are to cause the machine to perform operations comprising to:

enforce values in the plurality of bundles of state, which are indicative of the order that the plurality of bundles of state were exported from the first protected VM, to be respectively consistent with values indicative of a number of the plurality of bundles of state imported into the second protected VM.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2021
From: SAHITA, RAVI; CASPI, DROR; SCARLATA, VINCENT; YANIV, SHARON; CHAIKIN, BARUCH; SHANBHOGUE, VEDVYAS; NAKAJIMA, JUN; THIYAGARAJAH, ARUMUGAM; CHRISTOPHERSON, SEAN; XIA, HAIDONG; AWASTHI, VINAY; YAMAHATA, ISAKU; WANG, WEI; ADELMEYER, THOMAS
To: INTEL CORPORATION
Reel/Frame 057508/0289 →
Continuity (1)
Related Publication 20220206842A1 · Jun 30, 2022
References Cited (31)
US 6549959B1 · Yates · 2003 [cited by examiner]
US 9712503B1 · Ahmed et al. · 2017 [cited by applicant]
US 10649911B2 · Khosravi et al. · 2020 [cited by applicant]
US 10671737B2 · Durham et al. · 2020 [cited by applicant]
US 10761996B2 · Sahita et al. · 2020 [cited by applicant]
US 10810321B2 · Sahita et al. · 2020 [cited by applicant]
US 20070094719A1 · Scarlata · 2007 [cited by examiner]
US 20120278804A1 · Narayanasamy · 2012 [cited by examiner]
US 20150029543A1 · Morita · 2015 [cited by examiner]
US 20160188353A1 · Shu · 2016 [cited by examiner]
US 20160378688A1 · Rozas et al. · 2016 [cited by applicant]
US 20190087575A1 · Sahita et al. · 2019 [cited by applicant]
US 20190227878A1 · Agarwal · 2019 [cited by examiner]
US 20200201648A1 · Memon · 2020 [cited by examiner]
EP 3408780A1 · 2018 [cited by applicant]
WO 2011049574A1 · 2011 [cited by applicant]
WO 2017129659A1 · 2017 [cited by applicant]
AMD, “AMD Memory Encryption Tutorial”, ISCA 2016, Jun. 19, 2016, 82 pages. [cited by applicant]
AMD, “Secure Encrypted Virtualization API Version 0.24”, Technical Preview, Advanced Micro Devices, Revision: 3.24, Apr. 2020, 122 pages. [cited by applicant]
AMD, “SEV Secure Nested Paging Firmware ABI Specification”, Advanced Micro Devices, Revision:0.8, Aug. 2020, 108 pages. [cited by applicant]
Gu et al., “Secure Live Migration of SGX Enclaves on Untrusted Cloud”, 47th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN, 2017, 12 pages. [cited by applicant]
Gustafsson, Erik, “Optimizing Total Migration Time in Virtual Machine Live Migration”, Department of Information Technology, Mar. 2013, 47 pages. [cited by applicant]
Hetzelt et al., “Security Analysis of Encrypted Virtual Machines”, ACM, Jul. 26, 2017, 14 pages. [cited by applicant]
Intel, “Architecture Specification: Intel(Registered) Trust Domain Extensions (Intel Registered TDX) Module”, Sep. 2020, 285 pages. [cited by applicant]
Intel, Guest-Host-Communication Interface(GHCI) for Intel (Registered) Trust Domain Extensions (Intel registered TDX), Sep. 2020, 48 pages. [cited by applicant]
Intel, “Intel(registered) Trust Domain CPU Architectural Extensions”, Sep. 2020, 40 pages. [cited by applicant]
Intel, “Intel(registered) Trust Domain Extensions”, White Paper, Aug. 2020, 9 pages. [cited by applicant]
Intel, “Intel(registered) Trust Domain Extensions—SEAM Loader(SEAMLDER) Interface Specification”, Sep. 2020, 20 pages. [cited by applicant]
Intel, “Intel, Intel(registered) TDX Virtual Firmware Design Guide”, Document No. 344991-001US, Oct. 2020, 55 pages. [cited by applicant]
Nitu et al., “Swift Birth and Quick Death: Enabling Fast Parallel Guest Boot and Destruction in the Xen Hypervisor”, ACM, Apr. 8-9, 2017, 14 pages. [cited by applicant]
European Search Report and Search Opinion, EP App. No. 21198666.6, Mar. 11, 2022, 8 pages. [cited by applicant]