IP Library › Granted Patent US 12,737,209
Granted Patent B2
US 12,737,209 · App. 18/090,740 · Granted Sep 15, 2026

Interrupt control using a guest owned backing page

Inventors: David Kaplan (Austin, TX); Jelena Ilic (Austin, TX); Nippon Raval (Markham, CA); Philip Ng (Toronto, CA)
Assignees: ADVANCED MICRO DEVICES, INC.; ATI TECHNOLOGIES ULC
G06F9/45558G06F9/45545G06F2009/45579G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,209
App. No.
18/090,740
Granted
Sep 15, 2026
Kind
B2
Abstract

Techniques for implementing programmable control by a guest virtual machine (VM) of interrupts at a processing system using a guest owned backing page are disclosed. The VM programs a guest owned backing page (e.g., a data structure in memory) that designates particular interrupts that are to be blocked. In response to detecting a designated interrupt, system hardware or software blocks the interrupt, rather than executing an interrupt handler to process the interrupt. The VM is thereby able to protect confidential information and program behavior with less risk of a malicious hypervisor failing to protect the VM from, e.g., unexpected or unwanted interrupts, thereby improving overall system security and predictability.

Claims (33)

1 . A method, comprising:

receiving, at a processor operatively coupled to a memory, a request from a trusted layer of a virtual machine to store control information in a guest owned backing page in the memory to allow or block an interrupt, wherein the virtual machine comprises a plurality of layers and the trusted layer is designated by a security co-processor performing a security process; and

in response to the request and in response to detecting the interrupt, allowing or blocking the interrupt based on the control information.

2 . The method of claim 1 , wherein the control information designates a particular type of interrupt.

3 . The method of claim 1 , wherein the control information designates interrupts associated with a particular device.

4 . The method of claim 1 , wherein the control information designates interrupts associated with a particular type of device.

5 . The method of claim 1 , wherein blocking the interrupt comprises generating an exception.

6 . The method of claim 1 , wherein blocking the interrupt comprises blocking the interrupt at the processor.

7 . The method of claim 1 , wherein blocking the interrupt comprises blocking the interrupt at a memory management unit.

8 . The method of claim 1 , further comprising encrypting the guest owned backing page.

9 . The method of claim 1 , further comprising:

translating a location of a guest owned interrupt remapping table from a guest physical address to a system physical address based on a guest virtual vector, wherein:

the guest virtual vector is identified based on a device table entry and the interrupt, and

the guest owned interrupt remapping table maps interrupts to guest physical vectors; and

blocking the interrupt if the memory at the translated system physical address is not guest owned.

10 . The method of claim 9 , further comprising blocking the interrupt if the guest owned interrupt remapping table does not specify a mapping for the interrupt.

11 . The method of claim 9 , further comprising storing an indication of the interrupt in the guest owned backing page when the memory at the translated system physical address is guest owned.

12 . A system, comprising:

a memory configured to store a guest owned backing page; and

a processor operatively coupled to the memory, wherein the processor is configured to:

receive a request from a trusted layer of a virtual machine to store control information in the guest owned backing page to allow or block an interrupt, wherein the virtual machine comprises a plurality of layers and the trusted layer is designated by a security co-processor performing a security process; and

in response to the request and in response to detecting the interrupt, allow or block the interrupt based on the control information.

13 . The system of claim 12 , wherein the control information designates a particular type of interrupt.

14 . The system of claim 12 , wherein the control information designates interrupts associated with a particular device.

15 . The system of claim 12 , wherein the control information designates interrupts associated with a particular type of device.

16 . The system of claim 12 , wherein blocking the interrupt comprises generating an exception.

17 . The system of claim 12 , wherein blocking the interrupt comprises blocking the interrupt at a memory management unit.

18 . The system of claim 12 , wherein the guest owned backing page is encrypted.

19 . A system, comprising:

a memory configured to store a guest owned paging page;

a processor operatively coupled to the memory, wherein the processor is configured to receive a request from a trusted layer of a virtual machine to store control information in the guest owned backing page to allow or block an interrupt, wherein the virtual machine comprises a plurality of layers and the trusted layer is designated by a security co-processor performing a security process; and

input/output memory management unit (IOMMU) hardware configured to, in response to detecting the interrupt, allow or block the interrupt based on the control information.

20 . The system of claim 19 , wherein the IOMMU hardware is further configured to use a guest owned interrupt remapping table to control interrupts in the virtual machine.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2023
From: KAPLAN, DAVID; ILIC, JELENA
To: ADVANCED MICRO DEVICES, INC.
Reel/Frame 062473/0208 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2023
From: RAVAL, NIPPON; NG, PHILLIP
To: ATI TECHNOLOGIES ULC
Reel/Frame 062473/0280 →
Continuity (1)
Related Publication 20240220297A1 · Jul 4, 2024
References Cited (13)
US 20110197004A1 · Serebrin · 2011 [cited by examiner]
US 20150127866A1 · Zeng et al. · 2015 [cited by applicant]
US 20160224362A1 · Tsirkin · 2016 [cited by examiner]
US 20170206105A1 · Alvarez et al. · 2017 [cited by applicant]
US 20170220369A1 · Kaplan · 2017 [cited by examiner]
US 20170242721A1 · Tsirkin et al. · 2017 [cited by applicant]
US 20200364158A1 · Panginwar et al. · 2020 [cited by applicant]
US 20200379927A1 · Chan · 2020 [cited by examiner]
US 20200387326A1 · Chan · 2020 [cited by examiner]
US 20210089480A1 · Chan · 2021 [cited by examiner]
US 20230099517A1 · Neiger · 2023 [cited by examiner]
International Search Report and Written Opinion issued in Application No. PCT/US2023/085134, mailed Apr. 24, 2024, 11 pages. [cited by applicant]
International Preliminary Report on Patentability mailed Jul. 10, 2025 for International Application No. PCT/US2023/085134, 7 pages. [cited by applicant]