IP Library Granted Patent US 11,836,517
Granted Patent B2
US 11,836,517 · App. 17/961,314 · Granted Dec 5, 2023

Support for encrypted memory in nested virtual machines

Inventors: Michael Tsirkin (Westford, MA); Karen Lee Noel (Concord, CA)
Assignee: Red Hat, Inc.
G06F9/45558G06F12/10G06F21/602H04L9/0819G06F2009/45583G06F2009/45587G06F2212/654
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,836,517
App. No.
17/961,314
Granted
Dec 5, 2023
Kind
B2
Abstract

A method includes receiving a memory access request comprising a first memory address and translating the first memory address to a second memory address using a first page table associated with the first virtual machine. The first page table indicates whether the memory of the first virtual machine is encrypted. The method further includes determining that the first virtual machine is nested within a second virtual machine and translating the second memory address to a third memory address using a second page table associated with the second virtual machine. The second page table indicates whether the memory of the second virtual machine is encrypted.

Claims (53)

1. A method comprising:

receiving, from a first virtual machine, a memory access request comprising a memory address;

determining that the first virtual machine is nested within one or more additional virtual machines;

performing a plurality of address translations for the memory access request based on a plurality of page tables associated with the first virtual machine and the one or more additional virtual machines;

determining, by a processing device, from the first virtual machine and the one or more additional virtual machines, a deepest nested virtual machine that is encrypted based on page table entries of the plurality of page tables indicating whether the memory address is encrypted; and

obtaining an encryption key associated with the deepest nested virtual machine that is encrypted.

2. The method of claim 1 , wherein determining that the first virtual machine is nested within the one or more additional virtual machines comprises determining that a context of the first virtual machine comprises a parent context pointer for a a second virtual machine.

3. The method of claim 1 , further comprising:

obtaining an encryption key associated with the first virtual machine in view of a first page table of the plurality of page tables indicating that the memory address is encrypted.

4. The method of claim 3 , further comprising:

obtaining an encryption key associated with a parent virtual machine of the first virtual machine in view of the first page table indicating that the memory address is not encrypted and a second page table associated with the parent virtual machine indicating that the memory address is encrypted.

5. The method of claim 1 , wherein determining that the first virtual machine is nested comprises:

determining that the first virtual machine comprises a parent context pointer to one of the one or more additional virtual machines.

6. The method of claim 5 , further comprising:

in response to determine that the first virtual machine comprises the parent context pointer, switching from a context of the first virtual machine to a context of the parent virtual machine.

7. The method of claim 1 , further comprising:

accessing the memory address using the encryption key associated with the deepest nested virtual machine that is encrypted.

8. A system comprising:

a memory; and

a processing device operatively coupled to the memory, the processing device to:

receive, from a first virtual machine, a memory access request comprising a memory address;

determine that the first virtual machine is nested within one or more additional virtual machines;

perform a plurality of address translations for the memory access request based on a plurality of page tables associated with the first virtual machine and the one or more additional virtual machines;

determine, from the first virtual machine and the one or more additional virtual machines, a deepest nested virtual machine that is encrypted based on page table entries of the plurality of page tables indicating whether the memory address is encrypted; and

obtain an encryption key associated with the deepest nested virtual machine that is encrypted.

9. The system of claim 8 , wherein to determine that the first virtual machine is nested within the one or more additional virtual machines, the processing device is to:

determine that a context of the first virtual machine comprises a parent context pointer for a a second virtual machine.

10. The system of claim 8 , wherein the processing device is further to:

obtain an encryption key associated with the first virtual machine in view of a first page table of the plurality of page tables indicating that the memory address is encrypted.

11. The system of claim 10 , wherein the processing device is further to:

obtain an encryption key associated with a parent virtual machine of the first virtual machine in view of the first page table indicating that the memory address is not encrypted and a second page table associated with the parent virtual machine indicating that the memory address is encrypted.

12. The system of claim 8 , wherein to determine that the first virtual machine is nested, the processing device is to:

determine that the first virtual machine comprises a parent context pointer to one of the one or more additional virtual machines.

13. The system of claim 12 , wherein the processing device is further to:

in response to determine that the first virtual machine comprises the parent context pointer, switch from a context of the first virtual machine to a context of the parent virtual machine.

14. The system of claim 8 , wherein the processing device is further to:

access the memory address using the encryption key associated with the deepest nested virtual machine that is encrypted.

15. A non-transitory computer-readable storage medium including instructions that, when executed by a processing device, cause the processing device to:

receive, from a first virtual machine, a memory access request comprising a memory address;

determine that the first virtual machine is nested within one or more additional virtual machines;

perform a plurality of address translations for the memory access request based on a plurality of page tables associated with the first virtual machine and the one or more additional virtual machines;

determine, from the first virtual machine and the one or more additional virtual machines, a deepest nested virtual machine that is encrypted based on page table entries of the plurality of page tables indicating whether the memory address is encrypted; and

obtain an encryption key associated with the deepest nested virtual machine that is encrypted.

16. The non-transitory computer-readable storage medium of claim 15 , wherein to determine that the first virtual machine is nested within the one or more additional virtual machines, the processing device is to:

determine that a context of the first virtual machine comprises a parent context pointer for a second virtual machine.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the processing device is further to:

obtain an encryption key associated with the first virtual machine in view of a first page table of the plurality of page tables indicating that the memory address is encrypted.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the processing device is further to:

obtain an encryption key associated with a parent virtual machine of the first virtual machine in view of the first page table indicating that the memory address is not encrypted and a second page table associated with the parent virtual machine indicating that the memory address is encrypted.

19. The non-transitory computer-readable storage medium of claim 15 , wherein to determine that the first virtual machine is nested, the processing device is to:

determine that the first virtual machine comprises a parent context pointer to one of the one or more additional virtual machines.

20. The non-transitory computer-readable storage medium of claim 19 , wherein the processing device is further to:

in response to determine that the first virtual machine comprises the parent context pointer, switch from a context of the first virtual machine to a context of the parent virtual machine.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2022
From: TSIRKIN, MICHAEL; NOEL, KAREN LEE
To: RED HAT, INC.
Reel/Frame 061339/0504 →
Continuity (2)
Continuation 16913879 · Jun 26, 2020
Related Publication 20230031775A1 · Feb 2, 2023