IP Library Granted Patent US 11,880,481
Granted Patent B2
US 11,880,481 · App. 18/094,709 · Granted Jan 23, 2024

Secure modular devices

Inventors: Michael Tsirkin (Westford, MA); Sergio Lopez Pascual (Madrid, ES)
Assignee: Red Hat, Inc.
G06F21/6218G06F9/45558G06F12/1027G06F2009/45583G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,880,481
App. No.
18/094,709
Granted
Jan 23, 2024
Kind
B2
Abstract

A system includes a memory and a processor. The memory is in communication with the processor and configured to initialize a secure interface configured to provide access to a virtual machine (VM) from a device, where the VM is associated with a level of security. A buffer is allocated and associated with the secure interface, where the level of security of the VM indicates whether the device has access to guest memory of the VM via the buffer. The buffer is then provided to the device. Inputs/outputs (I/Os) are sent between the device and the VM using the secure interface.

Claims (61)

1. A method, comprising:

initializing a secure interface configured to provide access to a virtual machine (VM), a self-contained platform, or a container from a device, wherein the VM, the self-contained platform (SCP), or the container is associated with a level of security;

allocating a buffer associated with the secure interface, wherein the level of security indicates whether the device has access to guest memory of the VM, the SCP, or the container via the buffer;

providing the buffer to the device; and

sending input/outputs (I/Os) between the device and the VM, the SCP, or the container via the secure interface, wherein the buffer is allocated based on the level of security, wherein allocating comprises:

requesting, by a guest, the buffer, wherein the request includes the level of security;

allocating the buffer from a portion of host memory; and

configuring security of the buffer.

2. The method of claim 1 , wherein the secure interface is a Software Input Output Translation Lookaside Buffer (SWIOTLB).

3. The method of claim 1 , wherein, when the level of security is low, the buffer is allocated from a portion of the guest memory.

4. The method of claim 1 , wherein, when the device is a trusted device, the buffer is a total amount of the guest memory.

5. The method of claim 1 , wherein, when the level of security is high, the buffer is allocated from host memory.

6. The method of claim 1 , wherein configuring security of the buffer comprises setting permissions of the buffer.

7. The method of claim 1 , wherein the buffer is allocated such that:

when the level of security is low, the buffer is allocated from a portion of the guest memory,

when the device is a trusted device, the buffer is a total amount of the guest memory, and

when the level of security is high, the buffer is allocated outside the guest memory.

8. A system, comprising:

a memory; and

a processor in communication with the memory, wherein the processor is configured to perform:

initializing a secure interface configured to provide access to a virtual machine (VM), a self-contained platform, or a container from a device, wherein the VM, the self-contained platform (SCP), or the container is associated with a level of security;

allocating a buffer associated with the secure interface, wherein the level of security indicates whether the device has access to guest memory of the VM, the self-contained platform (SCP), or the container via the buffer;

providing the buffer to the device; and

sending input/outputs (I/Os) between the device and the VM, the self-contained platform (SCP), or the container via the secure interface,

wherein the buffer is allocated such that at least one of:

when the level of security is low, the buffer is allocated from a portion of the guest memory,

when the device is a trusted device, the buffer is a total amount of the guest memory, or

when the level of security is high, the buffer is allocated outside the guest memory.

9. The system of claim 8 , wherein the secure interface is a Software Input Output Translation Lookaside Buffer (SWIOTLB).

10. The system of claim 8 , wherein, when the level of security is low, the buffer is allocated from the portion of the guest memory.

11. The system of claim 8 , wherein the device is a data storage device.

12. The system of claim 8 ,

wherein allocating comprises:

requesting, by a guest, the buffer, wherein the request includes the level of security;

allocating the buffer from a portion of host memory; and

configuring security of the buffer based on the level of security.

13. The system of claim 12 , wherein configuring security of the buffer comprises setting permissions of the buffer.

14. The system of claim 8 , wherein the buffer is allocated such that:

when the level of security is low, the buffer is allocated from a portion of the guest memory,

when the device is a trusted device, the buffer is a total amount of the guest memory, and

when the level of security is high, the buffer is allocated outside the guest memory.

15. A non-transitory machine readable medium storing code, which when executed by a processor is configured to:

initialize a secure interface configured to provide access to a virtual machine (VM), a self-contained platform, or a container from a device, wherein the VM, the self-contained platform (SCP), or the container is associated with a level of security;

allocating a buffer associated with the secure interface, wherein the level of security indicates whether the device has access to guest memory of the VM, the self-contained platform (SCP), or the container via the buffer;

provide the buffer to the device; and

sending input/outputs (I/Os) between the device and the VM, the self-contained platform (SCP), or the container via the secure interface, wherein the buffer is allocated based on the level of security,

wherein the buffer is allocated such that at least one of:

when the level of security is low, the buffer is allocated from a portion of the guest memory,

when the device is a trusted device, the buffer is a total amount of the guest memory, or

when the level of security is high, the buffer is allocated outside the guest memory.

16. The non-transitory machine readable medium of claim 15 , wherein the secure interface is a Software Input Output Translation Lookaside Buffer (SWIOTLB).

17. The non-transitory machine readable medium of claim 15 , wherein, when the level of security is high, the buffer is allocated from host memory.

18. The non-transitory machine readable medium of claim 15 , wherein allocating comprises:

requesting, by a guest, the buffer, wherein the request includes the level of security;

allocating the buffer from a portion of host memory; and

configuring security of the buffer.

19. The non-transitory machine readable medium of claim 18 , wherein configuring security of the buffer comprises setting permissions of the buffer.

20. The non-transitory machine readable medium of claim 15 , wherein the buffer is allocated such that:

when the level of security is low, the buffer is allocated from a portion of the guest memory,

when the device is a trusted device, the buffer is a total amount of the guest memory, and

when the level of security is high, the buffer is allocated outside the guest memory.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2023
From: TSIRKIN, MICHAEL; LOPEZ PASCUAL, SERGIO
To: RED HAT, INC.
Reel/Frame 062844/0868 →