IP Library Granted Patent US 11,907,748
Granted Patent B2
US 11,907,748 · App. 17/239,443 · Granted Feb 20, 2024

Secure graphics processing unit (GPU) virtualization using sandboxing

Inventors: Michael Banack (Mountain View, CA); Mark Sheldon (Fremont, CA)
Assignee: VMware LLC
G06F9/45558G06F9/547G06T1/20G06F2009/45579
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,907,748
App. No.
17/239,443
Granted
Feb 20, 2024
Kind
B2
Abstract

Techniques for implementing secure GPU virtualization using sandboxing are provided. In one set of embodiments, a hypervisor of a host system can receive one or more first graphics/compute commands issued by a guest application running within a VM of the host system. The hypervisor can further communicate the one or more first graphics/compute commands to a sandboxed software process that is separate from the hypervisor. The sandboxed software process can then translate the one or more first graphics/compute commands into one or more second graphics/compute commands and issue the one or more second graphics/compute commands for execution on a physical GPU.

Claims (40)

1. A method comprising:

receiving, by a hypervisor of a host system, one or more first graphics or compute commands issued by a guest application running within a virtual machine (VM) of the host system;

communicating, by the hypervisor, the one or more first graphics or compute commands to a sandboxed software process that is separate from the hypervisor;

translating, by the sandboxed software process, the one or more first graphics or compute commands into one or more second graphics or compute commands; and

issuing, by the sandboxed software process, one or more second graphics or compute commands for execution on a physical graphics processing unit (GPU).

2. The method of claim 1 wherein the sandboxed software process runs on a host operating system (OS) of the host system.

3. The method of claim 2 wherein the one or more second graphics or compute commands are calls to a host graphics or compute API (application programming interface) library of the host OS.

4. The method of claim 3 wherein upon being issued, the one or more second graphics or compute commands are handled by a host GPU driver of the host system that implements the host graphics or compute API library.

5. The method of claim 1 wherein the sandboxed software process runs within another VM of the host system.

6. The method of claim 1 wherein the sandboxed software process runs within another VM of another host system.

7. The method of claim 1 wherein communicating the one or more first graphics or compute commands to the sandboxed software process comprises:

writing the one or more first graphics or compute commands to a memory region shared by the hypervisor and the sandboxed software process; and

transmitting, via a control channel, a signal to the sandboxed software process indicating that the memory region includes command data to be consumed.

8. A non-transitory computer readable storage medium having stored thereon instructions executable by a host system, the instructions embodying a method comprising:

receiving, by a hypervisor of the host system, one or more first graphics or compute commands issued by a guest application running within a virtual machine (VM) of the host system;

communicating, by the hypervisor, the one or more first graphics or compute commands to a sandboxed software process that is separate from the hypervisor;

translating, by the sandboxed software process, the one or more first graphics or compute commands into one or more second graphics or compute commands; and

issuing, by the sandboxed software process, one or more second graphics or compute commands for execution on a physical graphics processing unit (GPU).

9. The non-transitory computer readable storage medium of claim 8 wherein the sandboxed software process runs on a host operating system (OS) of the host system.

10. The non-transitory computer readable storage medium of claim 9 wherein the one or more second graphics or compute commands are calls to a host graphics or compute API (application programming interface) library of the host OS.

11. The non-transitory computer readable storage medium of claim 10 wherein upon being issued, the one or more second graphics or compute commands are handled by a host GPU driver of the host system that implements the host graphics or compute API library.

12. The non-transitory computer readable storage medium of claim 8 wherein the sandboxed software process runs within another VM of the host system.

13. The non-transitory computer readable storage medium of claim 8 wherein the sandboxed software process runs within another VM of another host system.

14. The non-transitory computer readable storage medium of claim 8 wherein communicating the one or more first graphics or compute commands to the sandboxed software process comprises:

writing the one or more first graphics or compute commands to a memory region shared by the hypervisor and the sandboxed software process; and

transmitting, via a control channel, a signal to the sandboxed software process indicating that the memory region includes command data to be consumed.

15. A host system comprising:

a hypervisor; and

a non-transitory computer readable medium having stored thereon instructions that, when executed by the hypervisor, causes the hypervisor to:

receive one or more first graphics or compute commands issued by a guest application running within a virtual machine (VM) of the host system; and

communicate the one or more first graphics or compute commands to a sandboxed software process that is separate from the hypervisor,

wherein upon receiving the one or more first graphics or compute commands, the sandboxed software process translates the one or more first graphics or compute commands into one or more second graphics or compute commands and issues the one or more second graphics or compute commands for execution on a physical graphics processing unit (GPU).

16. The host system of claim 15 wherein the sandboxed software process runs on a host operating system (OS) of the host system.

17. The host system of claim 16 wherein the one or more second graphics or compute commands are calls to a host graphics or compute API (application programming interface) library of the host OS.

18. The host system of claim 17 wherein upon being issued, the one or more second graphics or compute commands are handled by a host GPU driver of the host system that implements the host graphics or compute API library.

19. The host system of claim 15 wherein the sandboxed software process runs within another VM of the host system.

20. The host system of claim 15 wherein the sandboxed software process runs within another VM of another host system.

21. The host system of claim 15 wherein the instructions that cause the hypervisor to communicate the one or more first graphics or compute commands to the sandboxed software process comprise instructions that cause the hypervisor to:

write the one or more first graphics or compute commands to a memory region shared by the hypervisor and the sandboxed software process; and

transmit, via a control channel, a signal to the sandboxed software process indicating that the memory region includes command data to be consumed.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2021
From: BANACK, MICHAEL; SHELDON, MARK
To: VMWARE INC.
Reel/Frame 058504/0388 →