IP Library Granted Patent US 11,734,048
Granted Patent B2
US 11,734,048 · App. 17/408,817 · Granted Aug 22, 2023

Efficient user space driver isolation by shallow virtual machines

Inventors: Michael Tsirkin (Haifa, IL); Amnon Ilan (Raanana, IL)
Assignee: Red Hat Israel, Ltd.
G06F9/45558G06F8/65G06F9/5077G06F9/545G06F12/1009G06F2009/45583
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,734,048
App. No.
17/408,817
Granted
Aug 22, 2023
Kind
B2
Abstract

Technology for configuring and executing a shallow virtual machine to enhance memory protection between different portions of user space memory of a particular computing process. An example method involves: receiving, by a processor of a host, a request to create a computing process comprising a first and second executable code, wherein the computing process comprises an instruction to cause the processor to switch between first and second page table structures; loading the first and second executable code into memory of the host, wherein the first page table structure comprises mapping data for the first executable code and for the second executable code and wherein the second executable code comprises driver code of a device; updating the second page table structure to disable execution of the first executable code and to provide the second executable code with access to the device; and restricting the first executable code from accessing the device.

Claims (35)

1. A method comprising:

receiving, by a processor of a host device, a request to create a computing process comprising a first executable code and a second executable code, wherein the computing process comprises an instruction to cause the processor to switch between a first page table structure and a second page table structure;

loading, by the processor, the first executable code and the second executable code into memory of the host device, wherein the first page table structure comprises mapping data for the first executable code and for the second executable code and wherein the second executable code comprises driver code of a device;

updating the second page table structure to disable execution of the first executable code and to provide the second executable code with access to the device; and

restricting, by the processor, the first executable code from accessing the device.

2. The method of claim 1 , wherein the computing process is associated with a virtual machine data structure and is executed by a shallow virtual machine on the host device without a hypervisor.

3. The method of claim 2 , wherein the shallow virtual machine comprises a guest memory address space that is mapped to host physical memory of the host device, and wherein the guest memory address space comprises addresses that are identical to addresses of the host physical memory.

4. The method of claim 1 , further comprising activating, by a kernel, a hardware assisted virtualization feature of the processor, wherein the instruction comprises a processor instruction of the hardware assisted virtualization feature of the processor and updates a page table pointer of the processor from the first page table structure to the second page table structure.

5. The method of claim 4 , wherein the driver code comprises a first call to the processor instruction to switch to the second page table structure that provides access to the device and comprises a second call to the processor instruction to switch to the first page table structure that restricts access to the device.

6. The method of claim 4 , wherein the processor instruction comprises a virtual machine function (VMFUNC) that switches an extended page table pointer (EPTP) from the first page table structure to the second page table structure.

7. The method of claim 3 , wherein the first page table structure comprises mapping data for application code in a first region of the guest memory address space and, wherein the second page table structure comprises mapping data for the application code in a second region of the guest memory address space, wherein the application code in the first region of the guest memory address space is executable and the application code in the second region of the guest memory address space is non-executable.

8. The method of claim 1 , wherein restricting the first executable code from accessing the device comprises the processor generating an error in response to the first executable code attempting to run after switching to the second page table structure.

9. The method of claim 3 , further comprising enabling the second executable code to access a portion of the guest memory address space mapped to the device in response to initiating the update to switch the first page table structure to the second page table structure.

10. The method of claim 1 , wherein the first page table structure and the second page table structure each comprise a host page table structure comprising identical mappings between guest physical memory addresses and host physical memory addresses.

11. The method of claim 4 , wherein the processor comprises one or more x86 processors and wherein the hardware assisted virtualization feature comprises virtual machine extensions (VMX).

12. A system comprising:

a memory;

a processor operatively coupled to the memory, wherein the processor to:

receive a request to create a computing process comprising a first executable code and a second executable code, wherein the computing process comprises an instruction to cause the processor to switch between a first page table structure and a second page table structure;

load the first executable code and the second executable code into the memory, wherein the first page table structure comprises mapping data for the first executable code and for the second executable code and wherein the second executable code comprises driver code of a device;

update the second page table structure to disable execution of the first executable code and to provide the second executable code with access to the device; and

restrict the first executable code from accessing the device.

13. The system of claim 12 , wherein the computing process is associated with a virtual machine data structure and is executed by a shallow virtual machine that is running on the system without a hypervisor.

14. The system of claim 13 , wherein the shallow virtual machine comprises a guest memory address space that is mapped identically to host physical memory of the system, and wherein the guest memory address space comprises addresses that are identical to addresses of the host physical memory.

15. The system of claim 12 , wherein the processor comprises a hardware assisted virtualization feature and wherein the instruction comprises a processor instruction to update a page table pointer of the processor from the first page table structure to the second page table structure.

16. The system of claim 15 , wherein the driver code comprises a first call to the processor instruction to switch to the second page table structure that provides access to the device and comprises a second call to the processor instruction to switch to the first page table structure that restricts access to the device.

17. The system of claim 14 , wherein the first page table structure comprises mapping data for application code in a first region of the guest memory address space and the second page table structure comprises mapping data for the application code in a second region of the guest memory address space, wherein the application code in the first region of the guest memory address space is executable and the application code in the second region of the guest memory address space is non-executable.

18. A non-transitory machine-readable storage medium storing instructions that cause a processor of a host device to:

activate a hardware assisted virtualization feature of the processor, wherein the hardware assisted virtualization feature is associated with a virtual machine data structure;

associate the virtual machine data structure with a computing process that comprises a first executable code and a second executable code, wherein the computing process comprises an instruction to cause the processor to switch between a first page table structure and a second page table structure;

load the first executable code and the second executable code into a memory of the host device, wherein the first page table structure comprises mapping data for the first executable code and for the second executable code and wherein the second executable code comprises driver code of a device;

update the second page table structure to disable execution of the first executable code and to provide the second executable code with access to the device; and

restrict the first executable code from accessing device.

19. The non-transitory machine-readable storage medium of claim 18 , wherein the computing process is executed in a shallow virtual machine on the host device without a hypervisor.

20. The non-transitory machine-readable storage medium of claim 18 , wherein the instruction comprises a processor instruction of the hardware assisted virtualization feature of the processor and updates a page table pointer of the processor from the first page table structure to the second page table structure.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2021
From: TSIRKIN, MICHAEL; ILAN, AMNON
To: RED HAT ISRAEL, LTD.
Reel/Frame 057880/0763 →
Continuity (2)
Continuation 16258924 · Jan 28, 2019
Related Publication 20210382747A1 · Dec 9, 2021