IP Library Granted Patent US 12,204,925
Granted Patent B2
US 12,204,925 · App. 17/589,567 · Granted Jan 21, 2025

Securing virtual machines in computer systems

Inventors: Michael Tsirkin (Westford, MA); Amnon Ilan (Raanana, IL)
Assignee: Red Hat Israel, Ltd.
G06F9/45558G06F9/45545G06F9/4856G06F9/5005G06F9/5077H04L43/04G06F2009/45575G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,204,925
App. No.
17/589,567
Granted
Jan 21, 2025
Kind
B2
Abstract

Aspects of the disclosure provide for mechanisms for securing virtual machines in a computer system. A request for a resource is received by a processing device. The request is initiated by a guest application. A determination is made by the processing device of whether an initialization of the guest application is completed. In response to a determination that the initialization of the guest application is completed, at least one system call associated with the request initiated by the guest application is blocked to reject execution of the request for the resource.

Claims (51)

1. A method comprising:

receiving, prior to initiation of packet processing by a guest application executed on a virtual machine, a request to allocate a resource to the guest application;

receiving an indication of a completion of initialization of the guest application with the allocated resource;

intercepting, by a guest supervisor executed in user space on the virtual machine, a subsequent request to allocate the resource initiated by the guest application subsequent to the initiation of the packet processing by the guest application; and

blocking, by a processing device, resource allocation to the guest application based on the subsequent request to allocate the resource intercepted by the guest supervisor executed on the virtual machine.

2. The method of claim 1 , further comprising:

receiving a message from the guest application indicating that the initialization of the guest application is completed; and

determining whether the initialization of the guest application is completed based on the received message.

3. The method of claim 1 , wherein blocking the resource allocation comprises:

stopping the virtual machine executing the guest application.

4. The method of claim 1 , further comprising:

responsive to detecting an exit initiated by the virtual machine executing the guest application, transferring execution control of the virtual machine to the guest supervisor.

5. The method of claim 4 , further comprising:

configuring a central processing unit (CPU) to facilitate transferring the execution control of the virtual machine to the guest supervisor by configuring a virtual control structure associated with the virtual machine.

6. The method of claim 1 , wherein the initialization of the guest application corresponds to at least one of a first initiation of execution of the guest application using an allocated resource or the initiation of the packet processing by the guest application.

7. The method of claim 1 , further comprising:

responsive to determining that the initialization of the guest application is not completed, allocating the resource for the guest application in response to the received request.

8. A system comprising:

a memory; and

a processing device operatively coupled to the memory, the processing device to:

receive, prior to initiation of packet processing by a guest application executed on a virtual machine, a request to allocate a resource to the guest application;

receive an indication of a completion of initialization of the guest application with the allocated resource;

intercept, by a guest supervisor executed in user space on the virtual machine, a subsequent request to allocate the resource initiated by the guest application subsequent to the initiation of the packet processing by the guest application; and

block resource allocation to the guest application responsive to the subsequent request based on the subsequent request to allocate the resource intercepted by the guest supervisor executed on the virtual machine.

9. The system of claim 8 , wherein the processing device is further to:

receive a message from the guest application indicating that the initialization of the guest application is completed; and

determine whether the initialization of the guest application is completed based on the received message.

10. The system of claim 8 , wherein to block the resource allocation, the processing device is further to:

stop the virtual machine executing the guest application.

11. The system of claim 8 , wherein the processing device is further to:

responsive to a detection of an exit initiated by the virtual machine executing the guest application, transfer execution control of the virtual machine to the guest supervisor.

12. The system of claim 11 , wherein the processing device is further to:

configure a central processing unit (CPU) to facilitate transferring the execution control of the virtual machine executing to the guest supervisor by configuring a virtual control structure associated with the virtual machine.

13. The system of claim 8 , wherein the initialization of the guest application corresponds to at least one of a first initiation of execution of the guest application using an allocated resource or the initiation of the packet processing by the guest application.

14. The system of claim 8 , wherein the processing device is further to:

responsive to a determination that the initialization of the guest application is not completed, allocate the resource for the guest application in response to the received request.

15. A non-transitory machine-readable storage medium including instructions that, when accessed by a processing device, cause the processing device to:

receive, prior to initiation of packet processing by a guest application executed on a virtual machine, a request to allocate a resource to the guest application;

receive an indication of a completion of initialization of the guest application with the allocated resource;

intercept, by a guest supervisor executed in user space on the virtual machine, a subsequent request to allocate the resource initiated by the guest application subsequent to the initiation of the packet processing by the guest application; and

block, by the processing device, resource allocation to the guest application based on the subsequent request to allocate the resource intercepted by the guest supervisor executed on the virtual machine.

16. The non-transitory machine-readable storage medium of claim 15 , wherein the instructions, when executed by the processing device, cause the processing device further to:

receive a message from the guest application indicating that the initialization of the guest application is completed; and

determine whether the initialization of the guest application is completed based on the received message.

17. The non-transitory machine-readable storage medium of claim 15 , wherein to block the resource allocation associated with the subsequent request, the instructions, when executed by the processing device, cause the processing device further to:

stop the virtual machine executing the guest application.

18. The non-transitory machine-readable storage medium of claim 15 , wherein the instructions, when executed by the processing device, cause the processing device further to:

responsive to a detection of an exit initiated by the virtual machine executing the guest application, transfer execution control of the virtual machine to the guest supervisor.

19. The non-transitory machine-readable storage medium of claim 18 , wherein the instructions, when executed by the processing device, cause the processing device further to:

configure a central processing unit (CPU) to facilitate transferring the execution control of the virtual machine to the guest supervisor by configuring a virtual control structure associated with the virtual machine.

20. The non-transitory machine-readable storage medium of claim 15 , wherein the initialization of the guest application corresponds to at least one of a first initiation of execution of the guest application using an allocated resource or the initiation of the packet processing by the guest application.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2022
From: TSIRKIN, MICHAEL; ILAN, AMNON
To: RED HAT ISRAEL LTD.
Reel/Frame 060018/0692 →
Continuity (2)
Continuation 16203060 · Nov 28, 2018
Related Publication 20220156103A1 · May 19, 2022
References Cited (37)
US 8327059B2 · Chen · 2012 [cited by examiner]
US 8327353B2 · Traut · 2012 [cited by examiner]
US 8381284B2 · Dang · 2013 [cited by examiner]
US 8407699B2 · Larkin · 2013 [cited by examiner]
US 8539222B2 · Ashok et al. · 2013 [cited by applicant]
US 9021476B1 · Pratt · 2015 [cited by applicant]
US 9292328B2 · Pratt · 2016 [cited by examiner]
US 9454497B2 · Nakajima · 2016 [cited by examiner]
US 9715410B2 · Bonzini · 2017 [cited by examiner]
US 9864859B2 · Sood et al. · 2018 [cited by applicant]
US 9880871B2 · Tsirkin · 2018 [cited by examiner]
US 10043007B2 · Brech et al. · 2018 [cited by applicant]
US 10564997B2 · Hong · 2020 [cited by examiner]
US 20070050764A1 · Traut · 2007 [cited by examiner]
US 20140157363A1 · Banerjee · 2014 [cited by examiner]
US 20160048464A1 · Nakajima · 2016 [cited by examiner]
US 20160180079A1 · Sahita · 2016 [cited by examiner]
US 20160224383A1 · Bonzini · 2016 [cited by examiner]
US 20160379003A1 · Kapoor · 2016 [cited by examiner]
US 20170109197A1 · Coleman · 2017 [cited by examiner]
US 20170257399A1 · Mooring · 2017 [cited by examiner]
US 20180129525A1 · Hong · 2018 [cited by examiner]
US 20180247082A1 · Durham · 2018 [cited by examiner]
US 20180373895A9 · Durham · 2018 [cited by examiner]
US 20190034633A1 · Seetharamaiah · 2019 [cited by examiner]
US 20190044971A1 · Sukhomlinov · 2019 [cited by examiner]
US 20200081737A1 · Peter · 2020 [cited by examiner]
US 20200167180A1 · Tsirkin · 2020 [cited by examiner]
CN 108062269A · 2018 [cited by applicant]
EP 2846273A1 · 2015 [cited by examiner]
WO 20180522A · 2016 [cited by applicant]
WO 2016097954A1 · 2016 [cited by applicant]
Azhar Sayeed, “Is NFV ready for containers?”, Vertical Industries Blog (https://ww.redhat.com/blog/verticalindus), How open source drives innovation across industries, Jun. 28, 2016, 8 pages. [cited by applicant]
Intel, “Container and Kernel-Based Virtual Machine (KVM) Virtualization for Network Function Virtualization (NFV)”, White Paper, Aug. 2015, 26 pages. [cited by applicant]
Bhardwaj, Rishi, et al. “A Choices Hypervisor on the ARM architecture.” University of Illinois 5 (2006). (Year: 2006). [cited by applicant]
Li, Chunxiao, Anand Raghunathan, and Ni raj K. Jha. “Secure virtual machine execution under an untrusted management OS.” 2010 IEEE 3rd International Conference on Cloud Computing. IEEE, 2010. (Year: 2010). [cited by applicant]
Shi, Jiangyong, Yuexiang Yang, and Chu an Tang. “Hardware assisted hypervisor introspection.” SpringerPlus 5.1 (2016): 1-23. (Year: 2016). [cited by applicant]