IP Library › Granted Patent US 11,604,673
Granted Patent B2
US 11,604,673 · App. 16/943,556 · Granted Mar 14, 2023

Memory encryption for virtual machines by hypervisor-controlled firmware

Inventor: Michael Tsirkin (Lexington, MA)
Assignee: Red Hat, Inc.
G06F9/45558G06F9/45545G06F12/1018G06F12/1408G06F2009/45583G06F2009/45587G06F2212/151
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,604,673
App. No.
16/943,556
Filed
Jul 30, 2020
Granted
Mar 14, 2023
Kind
B2
Examiner
KIM, DONG U
Art Unit
2196
USPC
718/1
Abstract

Systems and methods for encryption support for virtual machines. An example method may comprise initializing, by a firmware module associated with a virtual machine running on a host computer system, an exclusion range register associated with the virtual machine with a value specifying a first portion of guest memory, wherein the first portion of the guest memory comprises an exclusion range marked as reserved; encrypting, by the firmware using an ephemeral encryption key, a second portion of the guest memory; booting, by a hypervisor of the host computer system, the virtual machine; and responsive to intercepting, by the hypervisor, a privileged instruction executed by the virtual machine, performing at least one of: copying data for performing the privileged instruction to the first portion of the guest memory or copying data for performing the privileged instruction from the first portion of the guest memory.

Claims (55)

1. A method comprising:

initiating, by a virtual central processing unit (vCPU) running on a host computer system, a boot sequence for a virtual machine associated with the vCPU;

in response to the initiating, generating, during the boot sequence and by a hypervisor of the host computer system, a firmware module associated with the virtual machine;

initializing, during the boot sequence and by the firmware module, an exclusion range register associated with the virtual machine with a value specifying a first portion of guest memory, wherein the first portion of the guest memory comprises an exclusion range marked as reserved;

encrypting, during the boot sequence and by the firmware module using an ephemeral encryption key, a second portion of the guest memory;

booting, by the hypervisor, the virtual machine; and

responsive to intercepting, by the hypervisor, a privileged instruction executed by the virtual machine, performing at least one of: copying data for performing the privileged instruction from the hypervisor to the first portion of the guest memory or copying data for performing the privileged instruction from the first portion of the guest memory to the hypervisor.

2. The method of claim 1 , further comprising:

sending a measurement reflecting a handler address, a control environment, and the exclusion range register to a guest owner.

3. The method of claim 2 , wherein the control environment comprises a page table.

4. The method of claim 2 , wherein the measurement comprises a cryptographic hash of the handler address, contents of the control environment, an address of the exclusion range register, and contents of the exclusion range register.

5. The method of claim 1 , further comprising:

generating, by the hypervisor, the firmware module associated with the virtual machine.

6. The method of claim 1 , wherein the second portion comprises all guest memory except for the first portion.

7. The method of claim 1 , further comprising:

receiving the ephemeral encryption key from a guest owner;

supplying, by the firmware module, the ephemeral encryption key to the virtual machine through the second portion of guest memory; and

booting a guest operating system.

8. A system, comprising:

a memory;

a processing device operatively coupled to the memory, the processing device configured to:

initiate, by a virtual central processing unit (vCPU) running on a host computer system, a boot sequence for a virtual machine associated with the vCPU;

in response to the initiating, generate, during the boot sequence and by a hypervisor of the host computer system, a firmware module associated with the virtual machine;

initialize, during the boot sequence and by the firmware module, an exclusion range register associated with the virtual machine with a value specifying a first portion of guest memory, wherein the first portion of the guest memory comprises an exclusion range marked as reserved;

encrypt, during the boot sequence and by the firmware module using an ephemeral encryption key, a second portion of the guest memory;

boot, by the hypervisor of the host computer system, the virtual machine; and

responsive to intercepting, by the hypervisor, a privileged instruction executed by the virtual machine, perform at least one of: copying data for performing the privileged instruction from the hypervisor to the first portion of the guest memory or copying data for performing the privileged instruction from the first portion of the guest memory to the hypervisor.

9. The system of claim 8 , further comprising the processing device configured to:

send a measurement reflecting a handler address, a control environment, and the exclusion range register to a guest owner.

10. The system of claim 9 , wherein the control environment comprises a page table.

11. The system of claim 9 , wherein the measurement comprises a cryptographic hash of the handler address, contents of the control environment, an address of the exclusion range register, and contents of the exclusion range register.

12. The system of claim 8 , further comprising the processing device configured to:

generate, by the hypervisor, the firmware module associated with the virtual machine.

13. The system of claim 8 , wherein the second portion comprises all guest memory except for the first portion.

14. The system of claim 8 , further comprising the processing device configured to:

receive the ephemeral encryption key from a guest owner;

supply, by the firmware module, the ephemeral encryption key to the virtual machine through the second portion of guest memory; and

boot a guest operating system.

15. A non-transitory machine-readable storage medium storing instructions that cause a processing device to:

initiate, by a virtual central processing unit (vCPU) running on a host computer system, a boot sequence for a virtual machine associated with the vCPU;

in response to the initiating, generate, during the boot sequence and by a hypervisor of the host computer system, a firmware module associated with the virtual machine;

initialize, during the boot sequence and by the firmware module, an exclusion range register associated with the virtual machine with a value specifying a first portion of guest memory, wherein the first portion of the guest memory comprises an exclusion range marked as reserved;

encrypt, during the boot sequence and by the firmware module using an ephemeral encryption key, a second portion of the guest memory;

boot the virtual machine; and

responsive to intercepting a privileged instruction executed by the virtual machine, perform at least one of: copying data for performing the privileged instruction from the hypervisor to the first portion of the guest memory or copying data for performing the privileged instruction from the first portion of the guest memory to the hypervisor.

16. The non-transitory machine-readable storage medium of claim 15 , further comprising the processing device configured to:

send a measurement reflecting a handler address, a control environment, and the exclusion range register to a guest owner.

17. The non-transitory machine-readable storage medium of claim 16 , wherein the measurement comprises a cryptographic hash of the handler address, contents of the control environment, an address of the exclusion range register, and contents of the exclusion range register.

18. The non-transitory machine-readable storage medium of claim 15 , further comprising the processing device configured to:

generate the firmware module associated with the virtual machine.

19. The non-transitory machine-readable storage medium of claim 15 , wherein the second portion comprises all guest memory except for the first portion.

20. The non-transitory machine-readable storage medium of claim 15 , further comprising the processing device configured to:

receive the ephemeral encryption key from a guest owner;

supply, by the firmware module, the ephemeral encryption key to the virtual machine through the second portion of guest memory; and

boot a guest operating system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2020
From: TSIRKIN, MICHAEL
To: RED HAT, INC.
Reel/Frame 053980/0282 →
Continuity (1)
Related Publication 20220035648A1 · Feb 3, 2022