IP Library › Granted Patent US 12,411,719
Granted Patent B2
US 12,411,719 · App. 17/394,642 · Granted Sep 9, 2025

Deferred reclaiming of secure guest resources

Inventors: Claudio Imbrenda (Boeblingen, DE); Christian Borntraeger (Stuttgart, DE); Janosch Andreas Frank (Stuttgart, DE); Jonathan D. Bradbury (Poughkeepsie, NY)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F9/5077G06F9/45558G06F21/70G06F2009/45587G06F2221/2141G06F2221/2143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,411,719
App. No.
17/394,642
Granted
Sep 9, 2025
Kind
B2
Abstract

Deferred reclaiming of secure guest resources within a computing environment is provided, which includes initiating, by a host of the computing environment, removal of a secure guest from the computing environment, while leaving one or more resources of the secure guest to be reclaimed asynchronous to the removal of the secure guest. The deferring also includes reclaiming the one or more secure guest resources asynchronous to the removal of the secure guest, where the one or more secure guest resources are available for reuse as the one or more secure guest resources are reclaimed asynchronous to the removal of the secure guest.

Claims (34)

1. A computer program product for facilitating processing within a computing environment, the computer program product comprising:

at least one computer-readable storage medium having program instructions embodied therewith, the program instructions being readable by a processing circuit to cause the processing circuit to perform a method comprising:

initiating, by a host of the computing environment, starting of a secure guest within the computing environment, the initiating comprising sending a secure guest image and secure guest metadata to a secure platform of the computing environment separate from the host for use in starting the secure guest using one or more secure guest resources that are indicated inaccessible by the host via the secure guest metadata;

initiating, by the host of the computing environment, removal of the secure guest from the computing environment and reclaiming of secure guest resources, including leaving one or more secure guest resources of the secure guest to be reclaimed by the host asynchronous to the removal of the secure guest by the secure platform, wherein interaction with a state of the secure guest is to be processed by the secure platform of the computing environment, the secure platform being trusted by the secure guest and by the host, and wherein the initiating comprises sending, by the host, a request to the secure platform to remove the secure guest and change state metadata associated with the one or more secure guest resources of the secure guest to indicate that the one or more secure guest resources are in a discarded state, the discarded state allowing the one or more secure guest resources to be reclaimed by the host asynchronous to removal of the secure guest by the secure platform; and

reclaiming, by the host subsequent to the initiating removal of the secure guest, the one or more secure guest resources in the discarded state asynchronous to removal of the secure guest, the reclaiming including determining, by the host, that the state metadata associated with the one or more secure guest resources is in the discarded state and, based on the state metadata of the one or more secure guest resources being in the discarded state, clearing by the host the one or more secure guest resources for reuse, wherein the one or more secure guest resources are available for reuse as the one or more secure guest resources are reclaimed asynchronous to the removal of the secure guest by the secure platform.

2. The computer program product of claim 1 , wherein reclaiming the one or more secure guest resources of the secure guest occurs after, and asynchronous to, removal of the secure guest.

3. The computer program product of claim 1 , wherein removal of the secure guest includes reclaiming of one or more other secure guest resources coextensive with removal of the secure guest, while leaving the one or more secure guest resources of the secure guest to be reclaimed asynchronously.

4. The computer program product of claim 1 , wherein the one or more secure guest resources comprise guest memory associated with the secure guest.

5. The computer program product of claim 1 , further comprising specifying, by the host, the one or more secure guest resources of the secure guest to be reclaimed asynchronous to removal of the secure guest.

6. The computer program product of claim 1 , wherein the one or more secure guest resources comprise one or more secure memory pages, and the determining comprises checking page metadata to confirm that a secure memory page of the one or more secure memory pages is in the discarded state prior to clearing by the host the secure memory page for reuse.

7. The computer program product of claim 6 , further comprising clearing one or more security flags associated with the one or more secure memory pages based on clearing by the host the one or more secure memory pages.

8. The computer program product of claim 1 , wherein the host comprises a hypervisor of the computing environment, and the secure platform is separate from the hypervisor.

9. A computer system for facilitating processing within a computing environment, the computer system comprising:

a memory; and

at least one processor in communication with the memory, wherein the computer system is configured to perform a method, the method comprising:

initiating, by a host of the computing environment, starting of a secure guest within the computing environment, the initiating comprising sending a secure guest image and secure guest metadata to a secure platform of the computing environment separate from the host for use in starting the secure guest using one or more secure guest resources that are indicated inaccessible by the host via the secure guest metadata;

initiating, by the host of the computing environment, removal of the secure guest from the computing environment and reclaiming of secure guest resources, including leaving one or more secure guest resources of the secure guest to be reclaimed by the host asynchronous to the removal of the secure guest by the secure platform, wherein interaction with a state of the secure guest is to be processed by the secure platform of the computing environment, the secure platform being trusted by the secure guest and by the host, and wherein the initiating comprises sending, by the host, a request to the secure platform to remove the secure guest and change state metadata associated with the one or more secure guest resources of the secure guest to indicate that the one or more secure guest resources are in a discarded state, the discarded state allowing the one or more secure guest resources to be reclaimed by the host asynchronous to removal of the secure guest by the secure platform; and

reclaiming, by the host subsequent to the initiating removal of the secure guest, the one or more secure guest resources in the discarded state asynchronous to removal of the secure guest, the reclaiming including determining, by the host, that the state metadata associated with the one or more secure guest resources is in the discarded state and, based on the state metadata of the one or more secure guest resources being in the discarded state, clearing by the host the one or more secure guest resources for reuse, wherein the one or more secure guest resources are available for reuse as the one or more secure guest resources are reclaimed asynchronous to the removal of the secure guest by the secure platform.

10. The computer system of claim 9 , wherein reclaiming the one or more secure guest resources of the secure guest occurs after, and asynchronous to, removal of the secure guest.

11. The computer system of claim 9 , wherein removal of the secure guest includes reclaiming of one or more other secure guest resources coextensive with removal of the secure guest, while leaving the one or more secure guest resources of the secure guest to be reclaimed asynchronously.

12. The computer system of claim 9 , wherein the one or more secure guest resources comprise guest memory associated with the secure guest.

13. The computer system of claim 9 , further comprising specifying, by the host, the one or more secure guest resources of the secure guest to be reclaimed asynchronous to removal of the secure guest.

14. The computer system of claim 9 , wherein the one or more secure guest resources comprise one or more secure memory pages, and the determining comprises checking page metadata to confirm that a secure memory page of the one or more secure memory pages is in the discarded state prior to clearing by the host the secure memory page for reuse.

15. The computer system of claim 14 , further comprising clearing one or more security flags associated with the one or more secure memory pages based on clearing by the host the one or more secure memory pages.

16. The computer system of claim 9 , wherein the host comprises a hypervisor of the computing environment, and the secure platform is separate from the hypervisor.

17. A computer-implemented method for facilitating processing within a computing environment, the computer-implemented method comprising:

initiating, by a host of the computing environment, starting of a secure guest within the computing environment, the initiating comprising sending a secure guest image and secure guest metadata to a secure platform of the computing environment separate from the host for use in starting the secure guest using one or more secure guest resources that are indicated inaccessible by the host via the secure guest metadata;

initiating, by the host of the computing environment, removal of the secure guest from the computing environment and reclaiming of secure guest resources, including leaving one or more secure guest resources of the secure guest to be reclaimed by the host asynchronous to the removal of the secure guest by the secure platform, wherein interaction with a state of the secure guest is to be processed by the secure platform of the computing environment, the secure platform being trusted by the secure guest and by the host, and wherein the initiating comprises sending, by the host, a request to the secure platform to remove the secure guest and change state metadata associated with the one or more secure guest resources of the secure guest to indicate that the one or more secure guest resources are in a discarded state, the discarded state allowing the one or more secure guest resources to be reclaimed by the host asynchronous to removal of the secure guest by the secure platform; and

reclaiming, by the host subsequent to the initiating removal of the secure guest, the one or more secure guest resources in the discarded state asynchronous to removal of the secure guest, the reclaiming including determining, by the host, that the state metadata associated with the one or more secure guest resources is in the discarded state and, based on the state metadata of the one or more secure guest resources being in the discarded state, clearing by the host the one or more secure guest resources for reuse, wherein the one or more secure guest resources are available for reuse as the one or more secure guest resources are reclaimed asynchronous to the removal of the secure guest by the secure platform.

18. The computer-implemented method of claim 17 , wherein reclaiming the one or more secure guest resources of the secure guest occurs after, and asynchronous to, removal of the secure guest.

19. The computer-implemented method of claim 17 , wherein removal of the secure guest includes reclaiming of one or more other secure guest resources coextensive with removal of the secure guest, while leaving the one or more secure guest resources of the secure guest to be reclaimed asynchronously.

20. The computer-implemented method of claim 17 , wherein the host comprises a hypervisor of the computing environment, and the secure platform is separate from the hypervisor.

21. The computer-implemented method of claim 20 , wherein the one or more secure guest resources comprise one or more secure memory pages, and the determining comprises checking page metadata to confirm that a secure memory page of the one or more secure memory pages is in the discarded state prior to clearing by the host the secure memory page for reuse.

22. The computer-implemented method of claim 21 , further comprising clearing one or more security flags associated with the one or more secure memory pages based on clearing by the host the one or more secure memory pages.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2021
From: IMBRENDA, CLAUDIO; BORNTRAEGER, CHRISTIAN; FRANK, JANOSCH ANDREAS; BRADBURY, JONATHAN D.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 057094/0004 →
Continuity (1)
Related Publication 20230039894A1 · Feb 9, 2023
References Cited (39)
US 6223256B1 · Gaither · 2001 [cited by examiner]
US 8578006B2 · Sobel et al. · 2013 [cited by applicant]
US 8943260B2 · Ben-Yehuda et al. · 2015 [cited by applicant]
US 9280458B2 · Durrant · 2016 [cited by applicant]
US 9323552B1 · Adogla et al. · 2016 [cited by applicant]
US 9454451B2 · Campbell · 2016 [cited by applicant]
US 9507540B1 · Adogla et al. · 2016 [cited by applicant]
US 9600362B2 · Kang et al. · 2017 [cited by applicant]
US 9798482B1 · Tsirkin et al. · 2017 [cited by applicant]
US 10474359B1 · Volpe et al. · 2019 [cited by applicant]
US 10956216B2 · van Riel et al. · 2021 [cited by applicant]
US 11467864B2 · Zu et al. · 2022 [cited by applicant]
US 11669441B1 · Adogla · 2023 [cited by examiner]
US 20050235045A1 · Narayanaswami et al. · 2005 [cited by applicant]
US 20180124163A1 · Abali · 2018 [cited by examiner]
US 20180314632A1 · Krishnamurthy · 2018 [cited by examiner]
US 20180374072A1 · Zhao · 2018 [cited by examiner]
US 20200225972A1 · Karunaratne · 2020 [cited by examiner]
US 20200259640A1 · Leavy · 2020 [cited by examiner]
US 20200409740A1 · Li · 2020 [cited by examiner]
US 20210064546A1 · Zmudzinski · 2021 [cited by examiner]
US 20210096895A1 · Reid · 2021 [cited by examiner]
US 20210234681A1 · Buendgen et al. · 2021 [cited by applicant]
US 20220318042A1 · Davis · 2022 [cited by examiner]
CN 101410818A · 2009 [cited by applicant]
CN 103430159A · 2013 [cited by applicant]
CN 103620559A · 2014 [cited by applicant]
CN 103870332A · 2014 [cited by applicant]
CN 106503547A · 2017 [cited by applicant]
CN 117751352A · 2024 [cited by applicant]
DE 112022003818T5 · 2024 [cited by applicant]
GB 2624593A · 2024 [cited by applicant]
JP 2024530593A · 2024 [cited by applicant]
TW 202021328A · 2020 [cited by applicant]
TW I840804B · 2023 [cited by applicant]
WO 2023012655A1 · 2023 [cited by applicant]
Mel et al., “The NIST Definition of Cloud Computing,” National Institute of Standards and Technology, Information Technology Laboratory, Special Publication 800-145, Sep. 2011 (pp. 1-7). [cited by applicant]
IBM Publication, “z/Architecture Principles of Operation,” IBM® Publication No. SA22-7832-12, 13th Edition, Sep. 2019 (pp. 1-2000). [cited by applicant]
PCT/IB2022/057151, International Search Report & Written Opinion, dated Oct. 26, 2022 (6 pages) (Year: 2022). [cited by applicant]