IP Library › Granted Patent US 12,505,050
Granted Patent B2
US 12,505,050 · App. 18/647,845 · Granted Dec 23, 2025

Physical memory isolation

Inventors: Sergej Proskurin (Munich, DE); Sebastian Wolfgang Vogl (Munich, DE); Jonas Pfoh (Radeberg, DE)
Assignee: BLUEROCK SECURITY, INC.
G06F12/1441G06F9/455G06F12/1054G06F12/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,050
App. No.
18/647,845
Granted
Dec 23, 2025
Kind
B2
Abstract

Physical memory isolation in a virtualized system is described. A notification is received from a guest in the virtualized system that an address space isolation component has been created in the guest. At the host of the virtualized system, a memory isolation domain that is bound with the address space isolation component is created. The memory isolation domain includes a set of second level address translation tables dedicated for that memory isolation domain. Guest-physical address (GPA) range(s) are received from the guest that are mapped into memory of the guest, and memory access permissions for the GPA range(s) are received and are being mapped for a process into the created memory isolation domain. The host determines whether the mapping for the process into the created memory isolation domain is permitted. If not permitted, the mapping is blocked thereby preventing access. If permitted, the mapping is granted thereby allowing access.

Claims (47)

1 . A method for physical memory isolation in a virtualized system, comprising:

receiving a notification from a guest in the virtualized system that an address space isolation component has been created in the guest;

creating, at a host of the virtualized system, a memory isolation domain that is bound with the address space isolation component, wherein the memory isolation domain includes a set of second level address translation (SLAT) tables dedicated for that memory isolation domain;

receiving, from the guest, a set of one or more guest-physical address (GPA) ranges that are mapped into memory of the guest and receiving memory access permissions to use for the GPA range that is being mapped for a process into the created memory isolation domain, wherein the host maintains multiple memory isolation domains and GPA mappings for each of the memory isolation domains;

determining, at the host, whether the mapping for the process into the created memory isolation domain is permitted;

responsive to determining that the mapping for the process is not permitted, blocking the mapping thereby preventing access; and

responsive to determining that the mapping for the process is permitted, granting the mapping and thereby allowing access.

2 . The method of claim 1 , wherein determining that the mapping for the process is permitted includes determining that the set of GPA ranges is not currently mapped to any of the memory isolation domains of the virtualized system.

3 . The method of claim 1 , wherein determining that the mapping for the process is permitted includes determining that the set of GPA ranges is already mapped with different memory access permissions inside of the memory isolation bound that is bound with the address space isolation component.

4 . The method of claim 1 , wherein determining that the mapping for the process is permitted includes determining that the set of GPA ranges is mapped with a same memory access permissions inside a different memory isolation domain from the memory isolation domain that is bound with the address space isolation component.

5 . The method of claim 1 , wherein determining that the mapping for the process is not permitted includes determining that none of the following conditions exist:

the set of GPA ranges is not currently mapped to any of the memory isolation domains of the virtualized system;

the set of GPA ranges is already mapped with different memory access permissions inside of the memory isolation bound that is bound with the address space isolation component; and

the set of GPA ranges is mapped with a same memory access permissions inside a different memory isolation domain from the memory isolation domain that is bound with the address space isolation component.

6 . The method of claim 1 , wherein the host does not track virtual memory area (VMA) region of the guest.

7 . A computing device that implements a virtualized system, comprising:

a processor; and

a non-transitory machine-readable storage medium that provides instructions that, if executed by the processor cause the computing device to perform operations including:

receiving a notification from a guest in the virtualized system that an address space isolation component has been created in the guest;

creating, at a host of the virtualized system, a memory isolation domain that is bound with the address space isolation component, wherein the memory isolation domain includes a set of second level address translation (SLAT) tables dedicated for that memory isolation domain;

receiving, from the guest, a set of one or more guest-physical address (GPA) ranges that are mapped into memory of the guest and receiving memory access permissions to use for the GPA range that is being mapped for a process into the created memory isolation domain, wherein the host maintains multiple memory isolation domains and GPA mappings for each of the memory isolation domains;

determining, at the host, whether the mapping for the process into the created memory isolation domain is permitted;

responsive to determining that the mapping for the process is not permitted, blocking the mapping thereby preventing access; and

responsive to determining that the mapping for the process is permitted, granting the mapping and thereby allowing access.

8 . The computing device of claim 7 , wherein determining that the mapping for the process is permitted includes determining that the set of GPA ranges is not currently mapped to any of the memory isolation domains of the virtualized system.

9 . The computing device of claim 7 , wherein determining that the mapping for the process is permitted includes determining that the set of GPA ranges is already mapped with different memory access permissions inside of the memory isolation bound that is bound with the address space isolation component.

10 . The computing device of claim 7 , wherein determining that the mapping for the process is permitted includes determining that the set of GPA ranges is mapped with a same memory access permissions inside a different memory isolation domain from the memory isolation domain that is bound with the address space isolation component.

11 . The computing device of claim 7 , wherein determining that the mapping for the process is not permitted includes determining that none of the following conditions exist:

the set of GPA ranges is not currently mapped to any of the memory isolation domains of the virtualized system;

the set of GPA ranges is already mapped with different memory access permissions inside of the memory isolation bound that is bound with the address space isolation component; and

the set of GPA ranges is mapped with a same memory access permissions inside a different memory isolation domain from the memory isolation domain that is bound with the address space isolation component.

12 . The computing device of claim 7 , wherein the host does not track virtual memory area (VMA) region of the guest.

13 . A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor of a computing device that implements a virtualized system, will cause the computing device to perform operations including:

receiving a notification from a guest in the virtualized system that an address space isolation component has been created in the guest;

creating, at a host of the virtualized system, a memory isolation domain that is bound with the address space isolation component, wherein the memory isolation domain includes a set of second level address translation (SLAT) tables dedicated for that memory isolation domain;

receiving, from the guest, a set of one or more guest-physical address (GPA) ranges that are mapped into memory of the guest and receiving memory access permissions to use for the GPA range that is being mapped for a process into the created memory isolation domain, wherein the host maintains multiple memory isolation domains and GPA mappings for each of the memory isolation domains;

determining, at the host, whether the mapping for the process into the created memory isolation domain is permitted;

responsive to determining that the mapping for the process is not permitted, blocking the mapping thereby preventing access; and

responsive to determining that the mapping for the process is permitted, granting the mapping and thereby allowing access.

14 . The non-transitory machine-readable storage medium of claim 13 , wherein determining that the mapping for the process is permitted includes determining that the set of GPA ranges is not currently mapped to any of the memory isolation domains of the virtualized system.

15 . The non-transitory machine-readable storage medium of claim 13 , wherein determining that the mapping for the process is permitted includes determining that the set of GPA ranges is already mapped with different memory access permissions inside of the memory isolation bound that is bound with the address space isolation component.

16 . The non-transitory machine-readable storage medium of claim 13 , wherein determining that the mapping for the process is permitted includes determining that the set of GPA ranges is mapped with a same memory access permissions inside a different memory isolation domain from the memory isolation domain that is bound with the address space isolation component.

17 . The non-transitory machine-readable storage medium of claim 13 , wherein determining that the mapping for the process is not permitted includes determining that none of the following conditions exist:

the set of GPA ranges is not currently mapped to any of the memory isolation domains of the virtualized system;

the set of GPA ranges is already mapped with different memory access permissions inside of the memory isolation bound that is bound with the address space isolation component; and

the set of GPA ranges is mapped with a same memory access permissions inside a different memory isolation domain from the memory isolation domain that is bound with the address space isolation component.

18 . The non-transitory machine-readable storage medium of claim 13 , wherein the host does not track virtual memory area (VMA) region of the guest.

Assignments (2)
CHANGE OF NAME Recorded Aug 1, 2024
From: BEDROCK SYSTEMS, INC.
To: BLUEROCK SECURITY, INC.
Reel/Frame 068258/0162 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2024
From: PROSKURIN, SERGEJ; VOGL, SEBASTIAN WOLFGANG; PFOH, JONAS
To: BEDROCK SYSTEMS, INC.
Reel/Frame 067241/0985 →
Continuity (2)
Provisional Application 63499179 · Apr 28, 2023
Related Publication 20240362171A1 · Oct 31, 2024
References Cited (11)
US 10761872B1 · Lunev et al. · 2020 [cited by applicant]
US 11188367B2 · Patil · 2021 [cited by examiner]
US 20170090966A1 · Gupta · 2017 [cited by examiner]
US 20200073694A1 · Wallach · 2020 [cited by examiner]
US 20200073829A1 · Tsirkin et al. · 2020 [cited by applicant]
US 20200092252A1 · Tillotson · 2020 [cited by examiner]
US 20210132983A1 · Han · 2021 [cited by applicant]
US 20230334144A1 · Lin · 2023 [cited by examiner]
CN 107368354A · 2017 [cited by applicant]
CN 107562515A · 2018 [cited by applicant]
International Search Report and Written Opinion, PCT App. No. PCT/US2024/026775, Aug. 26, 2024, 09 pages. [cited by applicant]