IP Library › Granted Patent US 12,253,955
Granted Patent B2
US 12,253,955 · App. 18/625,880 · Granted Mar 18, 2025

Methods, systems, articles of manufacture and apparatus to control address space isolation in a virtual machine

Inventors: Jun Tian (Beijing, CN); Kun Tian (Shanghai, CN); Yu Zhang (Beijing, CN)
Assignee: Intel Corporation
G06F12/1009G06F9/45558G06F9/4812G06F12/109G06F2009/45583G06F2212/657
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,253,955
App. No.
18/625,880
Granted
Mar 18, 2025
Kind
B2
Abstract

Methods, apparatus, systems and articles of manufacture to control address space isolation in a virtual machine are disclosed. An example apparatus includes an address width adjustor to identify a memory width value corresponding to a guest memory associated with a virtual machine (VM), and generate an expanded emulated memory width value. The example apparatus also includes a memory mirror manager to generate a first guest physical address (GPA) range based on the memory width value, and generate a second GPA range based on the expanded emulated memory width value. The example apparatus also includes an EPT generator to generate root paging structures of a first type of EPT with respective addresses within the first GPA range, and generate root paging structures of a second type of EPT with respective addresses within (a) the first GPA range and (b) the second GPA range.

Claims (41)

1. An apparatus comprising:

interface circuitry;

machine-readable instructions; and

at least one processor circuit to be programmed by the machine-readable instructions to:

generate a first guest physical address (GPA) range based on a memory width value of a virtual machine (VM);

generate a second GPA range based on an expanded emulated memory width value;

generate first root paging structures of a first extended page table (EPT) corresponding to address values within the first GPA range; and

generate second root paging structures of a second EPT corresponding to address values within (a) the first GPA range and (b) the second GPA range.

2. The apparatus as defined in claim 1 , wherein the memory width value is a guest memory of the VM.

3. The apparatus as defined in claim 1 , wherein one or more of the at least one processor circuit is to detect a guest virtual address (GVA) provided by the VM.

4. The apparatus as defined in claim 3 , wherein one or more of the at least one processor circuit is to determine if the GVA provided by the VM is associated with one of a user mode or a kernel mode.

5. The apparatus as defined in claim 4 , wherein one or more of the at least one processor circuit is to (a) map the GVA to the first EPT when the VM is in the user mode and (b) map the GVA to the second EPT when the VM is in the kernel mode.

6. The apparatus as defined in claim 3 , wherein one or more of the at least one processor circuit is to:

map the GVA to the first EPT; and

map a clone of the GVA to the second EPT.

7. The apparatus as defined in claim 6 , wherein one or more of the at least one processor circuit is to calculate an offset for the clone of the GVA based on a base address of the GVA.

8. At least one non-transitory machine-readable medium comprising machine-readable instructions to cause at least one processor circuit to at least:

generate a first guest physical address (GPA) range based on a memory width value of a virtual machine (VM);

generate a second GPA range based on an expanded emulated memory width value;

generate first root paging structures of a first extended page table (EPT) corresponding to address values within the first GPA range; and

generate second root paging structures of a second EPT corresponding to address values within (a) the first GPA range and (b) the second GPA range.

9. The at least one non-transitory machine-readable medium as defined in claim 8 , wherein the machine-readable instructions are to cause one or more of the at least one processor circuit to identify the memory width value of a guest memory of the VM.

10. The at least one non-transitory machine-readable medium as defined in claim 8 , wherein the machine-readable instructions are to cause one or more of the at least one processor circuit to detect a guest virtual address (GVA) provided by the VM.

11. The at least one non-transitory machine-readable medium as defined in claim 10 , wherein the machine-readable instructions are to cause one or more of the at least one processor circuit to determine if the GVA provided by the VM corresponds to one of a user mode or a kernel mode.

12. The at least one non-transitory machine-readable medium as defined in claim 11 , wherein the machine-readable instructions are to cause one or more of the at least one processor circuit to at least one of (a) map the GVA to the first EPT when the VM is in the user mode or (b) map the GVA to the second EPT when the VM is in the kernel mode.

13. The at least one non-transitory machine-readable medium as defined in claim 10 , wherein the machine-readable instructions are to cause one or more of the at least one processor circuit to:

map the GVA to the first EPT; and

map a clone of the GVA to the second EPT.

14. The at least one non-transitory machine-readable medium as defined in claim 13 , wherein the machine-readable instructions are to cause one or more of the at least one processor circuit to calculate an offset for the clone of the GVA based on a base address of the GVA.

15. A system comprising:

means for memory mirroring to:

generate a first guest physical address (GPA) range based on a memory width value of a virtual machine (VM);

generate a second GPA range based on an expanded emulated memory width value; and

means for extended page table (EPT) generation to:

generate a first root paging structure of a first extended page table (EPT) corresponding to address values within the first GPA range; and

generate a second root paging structure of a second EPT corresponding to address values within (a) the first GPA range and (b) the second GPA range.

16. The system as defined in claim 15 , including means for address width adjusting to identify the memory width value of a guest memory of the VM.

17. The system as defined in claim 15 , including means for context switching to identify at least one of a system call or an interrupt, the at least one of the system call or the interrupt indicative of a context switch of the VM.

18. The system as defined in claim 17 , including means for EPT focus adjusting to invoke the first EPT based on one of a user mode context switch or a kernel mode context switch.

19. The system as defined in claim 15 , including means for spawn detecting to detect a guest virtual address (GVA) provided by the VM.

20. The system as defined in claim 19 , including means for initializing a VM to determine if the GVA provided by the VM is one of a user mode or a kernel mode.

Continuity (2)
Continuation 17438852
Related Publication 20240385970A1 · Nov 21, 2024
References Cited (25)
US 20120185667A1 · Gandhi · 2012 [cited by applicant]
US 20160306749A1 · Tsirkin et al. · 2016 [cited by applicant]
US 20160378678A1 · LeMay et al. · 2016 [cited by applicant]
US 20170249261A1 · Durham et al. · 2017 [cited by applicant]
US 20180136867A1 · Tsirkin · 2018 [cited by examiner]
US 20190266000A1 · Tsirkin · 2019 [cited by examiner]
CN 102754086A · 2012 [cited by applicant]
CN 105487837A · 2016 [cited by applicant]
CN 107844266A · 2018 [cited by applicant]
Snoeren, “Lecture 17: Virtual Machines,” CSE 120, University of California San Diego, Computer Science & Engineering, 7 pages. [cited by applicant]
Bhatia, “Performance Evaluation of Intel EPT Hardware Assist,” 2008-2009, retrieved from https://www.vmware.com/pdf/Perf_ESX_Intel-EPT-eval.pdf, 14 pages. [cited by applicant]
Wikipedia, “Kernel page-table isolation,” retrieved from https://en.wikipedia.org/wiki/Kernel_page-table_isolation, last edited on May 27, 2018, 5 pages. [cited by applicant]
Hua, et al., “EPTI: Efficient Defence against Meltdown attack for Unpatched VMS,” Proceedings of the 2018 USENIX Annual Technical Conference, Jul. 11-13, 2018, 13 pages. [cited by applicant]
Redhat, “L1TF-L1 Terminal Fault Attack-CVE-2018-3620 & CVE-2018-3646,” retrieved from https://access.redhat.com, Aug. 14, 2018, 9 pages. [cited by applicant]
Masters, “Understanding L1 Terminal Fault aka Foreshadow: What you need to know,” retrieved on Feb. 13, 2019, 10 pages. [cited by applicant]
Zhao, “On the Effectiveness of Virtualization Based Memory Isolation on Multicore Platforms,” Singapore Management University, retrieved from http://www.mysmu.edu/faculty/xhding/publications/fimce-eurosp17.pdf on Feb. 2… [cited by applicant]
Chase, “Soul of a New Machine,” Department of Computer Science, Duke University, retrieved from https://users.cs.duke.edu/˜chase/cps510/slides/dune-background.pptx on Feb. 21, 2019, 69 pages. [cited by applicant]
Belay, A, “Virtualization,” MIT CSAIL Parallel and Distributed Operating Systems Group, retrieved from https://pdos.csail.mit.edu/6.828/2017/lec/lvmware.pdf on Feb. 21, 2019, 39 pages. [cited by applicant]
Sallam et al., “4th Generation Intel® Core™ vPro™ Processors with Intel® VMCS Shadowing,” White Paper, downloaded on Mar. 13, 2019, 8 pages. [cited by applicant]
International Searching Authority, “International Search Report,” issued in connection with International Patent Application No. PCT/CN2019/092324, Mar. 24, 2020, 4 pages. [cited by applicant]
International Searching Authority, “Written Opinion of the International Searching Authority”, issued in connection with International Patent Application No. PCT/CN2019/092324, dated Mar. 24, 2020, 3 Pages. [cited by applicant]
International Searching Authority, “International Preliminary Report on Patentability,” issued in connection with International Application No. PCT/CN2019/092324, dated Dec. 21, 2021, 4 pages. [cited by applicant]
Intellectual Property of India, “Examination report under sections 12 & 13 of the Patents Act, 1970 and the Patents Rules, 2003,” issued in connection with Indian Patent Application No. 202147042311, dated Jan. 30, 2023… [cited by applicant]
United States Patent and Trademark Office, “Non-Final Office Action,” issued in connection with U.S. Appl. No. 17/438,852, mailed on Aug. 24, 2023, 10 pages. [cited by applicant]
United States Patent and Trademark Office, “Notice of Allowance and Fee(s) Due,” issued in connection with U.S. Appl. No. 17/438,852, dated Dec. 27, 2023, 10 pages. [cited by applicant]