Interrupt control using a guest owned backing page
Techniques for implementing programmable control by a guest virtual machine (VM) of interrupts at a processing system using a guest owned backing page are disclosed. The VM programs a guest owned backing page (e.g., a data structure in memory) that designates particular interrupts that are to be blocked. In response to detecting a designated interrupt, system hardware or software blocks the interrupt, rather than executing an interrupt handler to process the interrupt. The VM is thereby able to protect confidential information and program behavior with less risk of a malicious hypervisor failing to protect the VM from, e.g., unexpected or unwanted interrupts, thereby improving overall system security and predictability.
1 . A method, comprising:
receiving, at a processor operatively coupled to a memory, a request from a trusted layer of a virtual machine to store control information in a guest owned backing page in the memory to allow or block an interrupt, wherein the virtual machine comprises a plurality of layers and the trusted layer is designated by a security co-processor performing a security process; and
in response to the request and in response to detecting the interrupt, allowing or blocking the interrupt based on the control information.
2 . The method of claim 1 , wherein the control information designates a particular type of interrupt.
3 . The method of claim 1 , wherein the control information designates interrupts associated with a particular device.
4 . The method of claim 1 , wherein the control information designates interrupts associated with a particular type of device.
5 . The method of claim 1 , wherein blocking the interrupt comprises generating an exception.
6 . The method of claim 1 , wherein blocking the interrupt comprises blocking the interrupt at the processor.
7 . The method of claim 1 , wherein blocking the interrupt comprises blocking the interrupt at a memory management unit.
8 . The method of claim 1 , further comprising encrypting the guest owned backing page.
9 . The method of claim 1 , further comprising:
translating a location of a guest owned interrupt remapping table from a guest physical address to a system physical address based on a guest virtual vector, wherein:
the guest virtual vector is identified based on a device table entry and the interrupt, and
the guest owned interrupt remapping table maps interrupts to guest physical vectors; and
blocking the interrupt if the memory at the translated system physical address is not guest owned.
10 . The method of claim 9 , further comprising blocking the interrupt if the guest owned interrupt remapping table does not specify a mapping for the interrupt.
11 . The method of claim 9 , further comprising storing an indication of the interrupt in the guest owned backing page when the memory at the translated system physical address is guest owned.
12 . A system, comprising:
a memory configured to store a guest owned backing page; and
a processor operatively coupled to the memory, wherein the processor is configured to:
receive a request from a trusted layer of a virtual machine to store control information in the guest owned backing page to allow or block an interrupt, wherein the virtual machine comprises a plurality of layers and the trusted layer is designated by a security co-processor performing a security process; and
in response to the request and in response to detecting the interrupt, allow or block the interrupt based on the control information.
13 . The system of claim 12 , wherein the control information designates a particular type of interrupt.
14 . The system of claim 12 , wherein the control information designates interrupts associated with a particular device.
15 . The system of claim 12 , wherein the control information designates interrupts associated with a particular type of device.
16 . The system of claim 12 , wherein blocking the interrupt comprises generating an exception.
17 . The system of claim 12 , wherein blocking the interrupt comprises blocking the interrupt at a memory management unit.
18 . The system of claim 12 , wherein the guest owned backing page is encrypted.
19 . A system, comprising:
a memory configured to store a guest owned paging page;
a processor operatively coupled to the memory, wherein the processor is configured to receive a request from a trusted layer of a virtual machine to store control information in the guest owned backing page to allow or block an interrupt, wherein the virtual machine comprises a plurality of layers and the trusted layer is designated by a security co-processor performing a security process; and
input/output memory management unit (IOMMU) hardware configured to, in response to detecting the interrupt, allow or block the interrupt based on the control information.
20 . The system of claim 19 , wherein the IOMMU hardware is further configured to use a guest owned interrupt remapping table to control interrupts in the virtual machine.