IP Library Granted Patent US 12,494,898
Granted Patent B2
US 12,494,898 · App. 17/900,845 · Granted Dec 9, 2025

Secured peripheral device communication via bridge device in virtualized computer system

Inventors: Michael Tsirkin (Yokne'am Illit, IL); Amnon Ilan (Raanana, IL)
Assignee: Red Hat, Inc.
H04L9/0819G06F13/4027G06F13/4221G06F2213/0024G06F2213/0026
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,494,898
App. No.
17/900,845
Granted
Dec 9, 2025
Kind
B2
Abstract

Systems and methods for secured peripheral device communication via a bridge device in virtualized computer systems. An example method may comprise receiving, by a virtualized execution environment running on a computing system, a state measurement associated with a bridge device of the computing system; generating an ephemeral key; responsive to validating the state measurement, transmitting, to the bridge device, the ephemeral key encrypted using a device key associated with the bridge device; and transmitting, to the bridge device, an access request directed to a peripheral device accessible via the bridge device, wherein the access request is encrypted using a value derived from the ephemeral key.

Claims (47)

1 . A method comprising:

receiving, by a virtualized execution environment running on a computing system, a state measurement associated with a bridge device of the computing system;

generating an ephemeral key;

responsive to validating the state measurement, transmitting, to the bridge device, the ephemeral key encrypted using a device key associated with the bridge device;

transmitting, to the bridge device, an access request directed to a peripheral device accessible via the bridge device, wherein the access request is encrypted using a value derived from the ephemeral key; and

responsive to receiving an interrupt from the bridge device, suspending the virtualized execution environment.

2 . The method of claim 1 , wherein the virtualized execution environment is represented by one of: a virtual machine or a container.

3 . The method of claim 1 , wherein the bridge device is a Peripheral Component Interconnect (PCI)-to-PCI bridge.

4 . The method of claim 1 , wherein the peripheral device is one of: a Peripheral Component Interconnect express (PCIe) device, a virtual function of the PCIe device, or a sub-function of the PCIe device.

5 . The method of claim 1 , where the bridge device is one of: a physical bridge device or a virtual bridge device.

6 . The method of claim 1 , wherein generating the ephemeral key comprises applying a predetermined transformation on an ephemeral value and the device key.

7 . The method of claim 1 , wherein validating the state measurement comprises:

comparing the state measurement of the bridge device with an expected state measurement of the bridge device.

8 . The method of claim 1 , wherein transmitting the ephemeral key includes encrypting the ephemeral key.

9 . The method of claim 8 , further comprising:

transmitting the validated state measurement using the device key associated with the bridge device.

10 . The method of claim 1 , wherein the access request is initiated by an application of the virtualized execution environment running on the computing system.

11 . The method of claim 1 ,

wherein the interrupt indicates that a configuration space of the bridge device has been altered.

12 . A bridge device of a computing system, the bridge device comprising:

a memory; and

a controller operatively coupled to the memory, the controller to:

receive an ephemeral key;

responsive to receiving, from a processor of the computing system, an encrypted access request directed to a peripheral device accessible via the bridge device, decrypt, the access request using the ephemeral key;

forward the decrypted access request to the peripheral device;

receive, from the peripheral device, a response to the access request;

encrypt the response using the ephemeral key;

forward the response to the processor; and

responsive to an alteration of a configuration space of the bridge device, transmit an interrupt command to the processor.

13 . The bridge device of claim 12 , wherein the controller is to:

obtain a current state measurement associated with the bridge device;

compare the current state measurement and a state measurement validated by the processor; and

determine whether the current state measurement matches the state measurement validated by the processor.

14 . The bridge device of claim 13 , wherein the controller is to forward the decrypted access request to the peripheral device responsive to determining that current state measurement matches the state measurement validated by the processor.

15 . The bridge device of claim 13 , wherein the controller is further to:

responsive to determining that current state measurement does not match the state measurement validated by the processor, transmit a reset command to the peripheral device.

16 . The bridge device of claim 13 , wherein the controller is further to:

responsive to determining that current state measurement does not match the state measurement validated by the processor, transmit the interrupt command to the processor.

17 . A non-transitory computer readable storage medium including instructions that, when executed by a processing device, cause the processing device to:

receive, by a virtualized execution environment running on a computing system, a state measurement associated with a bridge device of the computing system;

generate an ephemeral key;

responsive to validating the state measurement, transmit, to the bridge device, the ephemeral key encrypted using a device key associated with the bridge device;

transmit, to the bridge device, an access request directed to a peripheral device accessible via the bridge device, wherein the access request is encrypted using a value derived from the ephemeral key; and

responsive to receiving an interrupt from the bridge device, suspend the virtualized execution environment.

18 . The non-transitory computer readable storage medium of claim 17 , wherein the virtualized execution environment is represented by one of: a virtual machine or a container.

19 . The non-transitory computer readable storage medium of claim 17 , wherein the bridge device is a Peripheral Component Interconnect (PCI)-to-PCI bridge.

20 . The non-transitory computer readable storage medium of claim 17 , wherein the peripheral device is one of: a Peripheral Component Interconnect express (PCIe) device, a virtual function of the PCIe device, or a sub-function of the PCIe device.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2022
From: TSIRKIN, MICHAEL; ILAN, AMNON
To: RED HAT, INC.
Reel/Frame 060960/0864 →
Continuity (1)
Related Publication 20240072995A1 · Feb 29, 2024
References Cited (37)
US 5610715A · Yoshii et al. · 1997 [cited by applicant]
US 6377060B1 · Burkhart et al. · 2002 [cited by applicant]
US 8023528B2 · Hendel et al. · 2011 [cited by applicant]
US 8954897B2 · Neystadt et al. · 2015 [cited by applicant]
US 9477486B2 · Raj et al. · 2016 [cited by applicant]
US 9672052B1 · Berreth et al. · 2017 [cited by applicant]
US 9678895B2 · Scott-Nash · 2017 [cited by applicant]
US 9906493B1 · Rodgers et al. · 2018 [cited by applicant]
US 10048982B2 · Chen et al. · 2018 [cited by applicant]
US 10089124B2 · Barlev et al. · 2018 [cited by applicant]
US 10176122B2 · Kaplan et al. · 2019 [cited by applicant]
US 10303899B2 · Durham et al. · 2019 [cited by applicant]
US 20080066074A1 · Nutter et al. · 2008 [cited by applicant]
US 20120030730A1 · Smith · 2012 [cited by examiner]
US 20160239339A1 · Chen et al. · 2016 [cited by applicant]
US 20160246629A1 · Tsirkin · 2016 [cited by examiner]
US 20170177854A1 · Gligor · 2017 [cited by examiner]
US 20180107608A1 · Kaplan et al. · 2018 [cited by applicant]
US 20180239715A1 · Tsirkin et al. · 2018 [cited by applicant]
US 20180247082A1 · Durham et al. · 2018 [cited by applicant]
US 20190052617A1 · Chen · 2019 [cited by examiner]
US 20190227827A1 · Zmudzinski · 2019 [cited by examiner]
US 20190228145A1 · Shanbhogue · 2019 [cited by examiner]
US 20190311123A1 · Lal · 2019 [cited by examiner]
US 20200151362A1 · Harriman · 2020 [cited by examiner]
US 20200310972A1 · Shanbhogue · 2020 [cited by examiner]
US 20210294628A1 · Tsirkin · 2021 [cited by examiner]
US 20210389965A1 · Dabak et al. · 2021 [cited by applicant]
US 20220091998A1 · Lal · 2022 [cited by examiner]
US 20230115629A1 · Balasubramani · 2023 [cited by examiner]
CN 109858265A · 2019 [cited by applicant]
CN 109858265B · 2019 [cited by applicant]
Extended European Search Report of European Application No. 22214209.3 mailed Jul. 14, 2023, 10 pages. [cited by applicant]
Shih-Wei Li, John S. Koh, and Jason Nieh, “Protecting Cloud Virtual Machines from Hypervisor and Host Operating System Exploits”, https://www.usenix.org/system/files/sec19-li-shih-wei.pdf, Department of Computer Science… [cited by applicant]
David Kaplan et al., AMD Memory Encryption, https://developer.amd.com/wordpress/media/2013/12/AMD_Memory_Encryption_Whitepaper_v7-Public.pdf, Apr. 21, 2016, 12 pages, Advanced Micro Devices. [cited by applicant]
Mengyuan Li et al., Exploiting Unprotected I/O Operations in AMD's Secure Encrypted Virtualization, https://www.usenix.org/system/files/sec19-li-mengyuan_0.pdf, Aug. 14-16, 2019, 17 pages, The Ohio State University; Uni… [cited by applicant]
ZeCoRx—Zero Copy Receive, 1. https://www.mikelangelo-project.eu/technology/zecorx-zero-copy-receive/, 4 pages, downloaded Nov. 27, 2019. [cited by applicant]