IP Library Granted Patent US 12,328,222
Granted Patent B2
US 12,328,222 · App. 17/704,807 · Granted Jun 10, 2025

Reverse virtual ethernet port aggregator bridging for single root I/O virtualization

Inventors: Michael Tsirkin (Westford, MA); Amnon Ilan (Katzir, IL)
Assignee: Red Hat, Inc.
H04L41/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,328,222
App. No.
17/704,807
Granted
Jun 10, 2025
Kind
B2
Abstract

A system includes a physical host, a host operating system, and a virtual machine having a virtual network-interface controller. The virtual network-interface controller comprises an uplink, a virtual function, and a physical function having a physical channel and a virtual channel. The hypervisor is configured to receive data that originates at the virtual function, which is forwarded to the physical function on the physical channel of the physical function. The data is further forwarded from the physical function to the uplink. Additionally, the hypervisor is configured to send data that does not originate at the virtual function. The hypervisor sends the data on the virtual channel of the physical function and the physical function forwards the data to the virtual function.

Claims (57)

1. A system comprising:

a physical network-interface controller (pNIC) that includes a physical function and a virtual function, the pNIC being configured to send and receive data packets via a physical link, wherein the physical function includes a virtual channel and a physical channel;

a virtual machine including a virtual network-interface controller (vNIC) that represents the pNIC in a virtual environment of the virtual machine;

a hypervisor managing the virtual machine, the hypervisor being configured to execute a physical function driver that provides a virtual bridge device and a virtual uplink device for the vNIC, the virtual uplink device being different from the physical link associated with the pNIC, wherein the virtual bridge device is configured to connect to the pNIC through the virtual channel of the physical function, and wherein the virtual uplink device is configured to connect to the pNIC through the physical channel of the physical function;

wherein the hypervisor is configured to:

receive first data from the physical function via the virtual bridge device, wherein the first data originates at the virtual machine;

filter the first data;

transmit the filtered first data to the virtual uplink device for forwarding to the physical function, the physical function being configured to forward the filtered first data to the physical link for transmission to an external destination;

receive second data from the physical function via the virtual uplink device, wherein the second data originates from a source other than the virtual machine and is received at the pNIC via the physical link;

filter the second data; and

transmit the filtered second data to the virtual bridge device for forwarding to the physical function, the physical function being configured to forward the filtered second data to the virtual machine.

2. The system of claim 1 , wherein the hypervisor is configured to send the second data on the physical channel of the physical function to the virtual uplink device.

3. The system of claim 1 , wherein the hypervisor is configured to receive the first data via the virtual channel.

4. The system of claim 1 , wherein the hypervisor is configured to:

receive third data from the virtual uplink device; and

forward fourth data from the physical function to the virtual function.

5. The system of claim 4 , wherein the hypervisor is configured to forward the third data from the physical function to the virtual function by sending the third data on the virtual channel.

6. The system of claim 1 , wherein the vNIC is configured to:

transmit, from the virtual function, the first data to the virtual channel of the physical function;

transmit, from the physical channel of the physical function, the first data to the virtual uplink device; and

transmit the second data, from the physical channel of the physical function, to the virtual uplink device.

7. The system of claim 6 , wherein the vNIC is further configured to:

receive third data forwarded from the virtual uplink device to the physical function; and

forward fourth data from the physical function to the virtual function.

8. The system of claim 6 , further comprising a guest application configured to transmit packets to the vNIC.

9. A method comprising:

managing, by a hypervisor executing on a processor, a virtual machine that includes a virtual network-interface controller (vNIC), the vNIC representing a physical network-interface controller (pNIC) in a virtual environment of the virtual machine, wherein the pNIC includes a physical function and a virtual function, the pNIC being configured to send and receive data packets via a physical link, wherein the physical function includes a virtual channel and a physical channel, the hypervisor being separate from the virtual machine;

executing, by the hypervisor, a physical function driver that provides a virtual bridge device and a virtual uplink device for the vNIC, the virtual uplink device being different from the physical link associated with the pNIC, wherein the virtual bridge device is connected to the pNIC through the virtual channel of the physical function, and wherein the virtual uplink device connected to the pNIC through the physical channel of the physical function;

wherein the hypervisor:

receives first data from the physical function via the virtual bridge device, wherein the first data originates at the virtual machine;

filters the first data;

transmits the filtered first data to the virtual uplink device for forwarding to the physical function, wherein the physical function forwards the filtered first data to the physical link for transmission to an external destination;

receives second data from the physical function via the virtual uplink device, wherein the second data originates from a source other than the virtual machine and is received at the pNIC via the physical link;

filters the second data; and

transmits the filtered second data to the virtual bridge device for forwarding to the physical function, wherein the physical function forwards the filtered second data to the virtual machine.

10. The method of claim 9 , wherein the second data is sent on the physical channel of the physical function to the virtual uplink device.

11. The method of claim 9 , wherein the hypervisor receives the first data via the virtual channel.

12. The method of claim 9 , wherein third data forwarded from the virtual uplink device to the physical function is received; and

fourth data is forwarded from the physical function to the virtual function.

13. The method of claim 12 , wherein the third data is forwarded from the physical function to the virtual function by sending the third data on the virtual channel.

14. The method of claim 9 , wherein the vNIC:

transmits, from the virtual function, the first data to the virtual channel of the physical function;

transmits, from the physical channel of the physical function, the first data to the virtual uplink device; and

transmits the second data, from the physical channel of the physical function, to the virtual uplink device.

15. The method of claim 14 , wherein the vNIC:

receives third data forwarded from the virtual uplink device to the physical function; and

forwards fourth data from the physical function to the virtual function.

16. The method of claim 14 , wherein a guest application transmits packets to the vNIC.

17. A non-transitory machine-readable medium storing code for a hypervisor that is executable by a processor to:

manage a virtual machine that is separate from the hypervisor, the virtual machine including a virtual network-interface controller (vNIC) representing a physical network-interface controller (pNIC) in a virtual environment of the virtual machine, the pNIC including a physical function and a virtual function, the pNIC being configured to send and receive data packets via a physical link, the physical function including a virtual channel and a physical channel;

execute a physical function driver that provides a virtual bridge device and a virtual uplink device for the vNIC, the virtual uplink device being different from the physical link associated with the pNIC, wherein the virtual bridge device is connected to the pNIC through the virtual channel of the physical function, and wherein the virtual uplink device connected to the pNIC through the physical channel of the physical function;

receive first data from the physical function via the virtual bridge device, wherein the first data originates at the virtual machine;

filter the first data;

transmit the filtered first data to the virtual uplink device for forwarding to the physical function, wherein the physical function forwards the filtered first data to the physical link for transmission to an external destination;

receive second data from the physical function via the virtual uplink device, wherein the second data originates from a source other than the virtual machine and is received at the pNIC via the physical link;

filter the second data; and

transmit the filtered second data to the virtual bridge device for forwarding to the physical function, wherein the physical function forwards the filtered second data to the virtual machine.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2022
From: TSIRKIN, MICHAEL; ILAN, AMNON
To: RED HAT, INC.
Reel/Frame 059409/0689 →
Continuity (1)
Related Publication 20230308345A1 · Sep 28, 2023
References Cited (16)
US 8265075B2 · Pandey · 2012 [cited by applicant]
US 8514890B2 · Kidambi et al. · 2013 [cited by applicant]
US 8930690B2 · Zuo et al. · 2015 [cited by applicant]
US 9311120B2 · Elzu · 2016 [cited by applicant]
US 9600313B2 · Nimmagadda et al. · 2017 [cited by applicant]
US 10812632B2 · Shah et al. · 2020 [cited by applicant]
US 11005755B2 · Yu et al. · 2021 [cited by applicant]
US 20120016970A1 · Shah · 2012 [cited by examiner]
US 20130152075A1 · Cardona · 2013 [cited by examiner]
US 20190042741A1 · Abodunrin · 2019 [cited by examiner]
US 20190089640A1 · To · 2019 [cited by examiner]
US 20200150997A1 · Chang · 2020 [cited by examiner]
US 20220029934A1 · Jiang · 2022 [cited by examiner]
US 20230208810A1 · Dhanasekar · 2023 [cited by examiner]
Shah et al., “Virtual Networking Management White Paper”, Distributed Management Task Force, Inc. (DMTF), published Nov. 8, 2011, pp. 1-58. [cited by applicant]
Smolyar et al., “Securing Self-Virtualizing Ethernet Devices”, Proceedings of the 24th USENIX Security Symposium (2015), USENIX Association, pp. 335-350. [cited by applicant]