IP Library › Granted Patent US 12,639,098
Granted Patent B2
US 12,639,098 · App. 18/486,767 · Granted May 26, 2026

Sharing access to a physical device with multiple virtual machines

Inventors: Alberto Carlos Ruiz (Madrid, ES); Francisco Javier Martinez Canillas (Barcelona, ES); Sergio Lopez Pascual (Saragossa, ES)
Assignee: Red Hat, Inc.
G06F9/45558G06F2009/45579G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,639,098
App. No.
18/486,767
Granted
May 26, 2026
Kind
B2
Abstract

Access to a physical device associated with a computing system can be shared with multiple virtual machines by delegating control of the physical device to a primary virtual machine (PVM). In some aspects, a virtual machine monitor (VMM) of the computing system can generate a hardware description that describes the physical device. The VMM can initiate the PVM, which can use the hardware description to acquire control of the physical device from a host kernel of the computing system. The VMM can delegate control of the physical device from the host kernel to the PVM. After control of the physical device is delegated to the PVM, the PVM is configured to perform a device sharing process to share access to the physical device with the SVM.

Claims (51)

1 . A computer system comprising:

a physical device;

a processing device communicatively coupled to the physical device, the physical device being separate from the processing device; and

a memory device including instructions that are executable by the processing device for causing the processing device to perform operations for allowing a secondaryvirtual machine (SVM) to access the physical device via a primary virtual machine (PVM), the operations comprising:

generating, by a virtual machine monitor (VMM), a hardware description configured to describe the physical device;

initiating, by the VMM, the PVM, the PVM configured to use the hardware description to acquire control of the physical device from a host kernel;

delegating, by the VMM, control of the physical device from the host kernel to the PVM, wherein after control of the physical device is delegated to the PVM, the PVM is configured to perform a device sharing process to share access to the physical device with the SVM;

transmitting, by the VMM to the PVM, an access request for the SVM to access the physical device, wherein the VMM is configured to support the PVM and the SVM; and

subsequent to transmitting the access request to the PVM, allocating, by the VMM, a shared memory region of a guest memory of the PVM usable to perform the device sharing process to enable the SVM to access the physical device, wherein the shared memory region of the guest memory is configured to map to a user space of the PVM, wherein the user space of the PVM is configured to expose a PVM service that is usable by the SVM to access the physical device, and wherein the SVM is configured to initialize the PVM service as a virtual device associated with the physical device, the virtual device being configured to enable the SVM to access the physical device.

2 . The computer system of claim 1 , wherein the operations further comprise, prior to initiating the PVM:

transmitting, bythe VMM, a mapping request to the host kernel to map computing resources of the physical device into the guest memory of the PVM, wherein the host kernel is configured to isolate computing resources of the physical device by creating a protected group in an input-output memory management unit (IOMMU) of the computer system, and wherein the protected group prevents unauthorized access of the computing resources.

3 . The computer system of claim 1 , wherein the PVM is further configured to acquire control of the physical device by initializing a kernel subsystem and one or more device drivers associated with the physical device to enable the user space of the PVM to access the physical device.

4 . The computer system of claim 1 , wherein the operations further comprise, prior to generating the hardware description:

configuring, by the VMM based on the physical device, a virtual management device to expose to the PVM; and

generating the hardware description that describes a plurality of PVM devices, wherein the plurality of PVM devices comprises the physical device and the virtual management device.

5 . The computer system of claim 1 , wherein the SVM is configured to share a dataset with the PVM by:

initializing the virtual device usable to access the physical device;

creating, by the virtual device, a buffer object associated with the dataset, wherein the buffer object is usable to locate the dataset; and

transmitting, by the virtual device, a reference to the buffer object to the PVM, wherein the user space of the PVM is configured to use the reference to the buffer object to map the dataset to the guest memory of the PVM.

6 . A method comprising:

generating, by a virtual machine monitor (VMM) executing on a processing device of a computer system, a hardware description that describes a physical device of the computer system, the physical device being separate from the processing device;

initiating, by the VMM, a primary virtual machine (PVM) that is configured to use the hardware description to acquire control of the physical device from a host kernel;

delegating, bythe VMM, control of the physical device from the host kernel to the PVM, wherein after control of the physical device is delegated to the PVM, the PVM is configured to perform a device sharing process to share access to the physical device with a secondary virtual machine (SVM);

transmitting, by the VMM to the PVM, an access request for the SVM to access the physical device, wherein the VMM is configured to support the PVM and the SVM; and

subsequent to transmitting the access request to the PVM, allocating, by the VMM, a shared memory region of a guest memory of the PVM usable to perform the device sharing process to enable the SVM to access the physical device, wherein the shared memory region of the guest memory is mapped to a user space of the PVM, wherein the user space of the PVM exposes a PVM service that is usable by the SVM to access the physical device, and wherein the SVM initializes the PVM service as a virtual device associated with the physical device, the virtual device enabling the SVM to access the physical device.

7 . The method of claim 6 , further comprising, prior to initiating the PVM:

transmitting, by the VMM, a mapping request to the host kernel to map computing resources of the physical device into the guest memory of the PVM, wherein the host kernel is configured to isolate computing resources of the physical device by creating a protected group in an input-output memory management unit (IOMMU), and wherein the protected group prevents unauthorized access of the computing resources.

8 . The method of claim 6 , wherein the PVM is further configured to obtain control of the physical device by initializing a kernel subsystem and one or more device drivers associated with the physical device to enable the user space of the PVM to access the physical device.

9 . The method of claim 6 , further comprising, prior to generating the hardware description:

configuring, by the VMM based on the physical device, a virtual management device to expose to the PVM; and

generating the hardware description that describes a plurality of PVM devices, wherein the plurality of PVM devices comprises the physical device and the virtual management device.

10 . The method of claim 6 , wherein the SVM is configured to share a dataset with the PVM by:

initializing the virtual device usable to access the physical device;

creating, by the virtual device, a buffer object associated with the dataset, wherein the buffer object is usable to locate the dataset; and

transmitting, bythe virtual device, a reference to the buffer object to the PVM, wherein the user space of the PVM is configured to use the reference to the buffer object to map the dataset to the guest memory of the PVM.

11 . A non-transitory computer-readable medium comprising program code executable by a processing device for causing the processing device to perform operations comprising:

generating, by a virtual machine monitor (VMM), a hardware description that describes a physical device;

initiating, by the VMM, a primary virtual machine (PVM) that is configured to use the hardware description to acquire control of the physical device from a host kernel;

delegating, bythe VMM, control of the physical device from the host kernel to the PVM, wherein after control of the physical device is delegated to the PVM, the PVM is configured to perform a device sharing process to share access to the physical device with a secondary virtual machine (SVM);

transmitting, by the VMM to the PVM, an access request for the SVM to access the physical device, wherein the VMM is configured to support the PVM and the SVM; and

subsequent to transmitting the access request to the PVM, allocating, by the VMM, a shared memory region of a guest memory of the PVM usable to perform the device sharing process to enable the SVM to access the physical device, wherein the shared memory region of the guest memory is configured to map to a user space of the PVM, wherein the user space of the PVM is configured to expose a PVM service that is usable by the SVM to access the physical device, and wherein the SVM is configured to initialize the PVM service as a virtual device associated with the physical device, the virtual device being configured to enable the SVM to access the physical device.

12 . The non-transitory computer-readable medium of claim 11 , wherein the operations further comprise, prior to initiating the PVM:

transmitting, by the VMM, a mapping request to the host kernel to map computing resources of the physical device into the guest memory of the PVM, wherein the host kernel is configured to isolate computing resources of the physical device by creating a protected group in an input-output memory management unit (IOMMU), and wherein the protected group prevents unauthorized access of the computing resources.

13 . The non-transitory computer-readable medium of claim 11 , wherein the PVM is further configured to obtain control of the physical device by initializing a kernel subsystem and one or more device drivers associated with the physical device to enable the user space of the PVM to access the physical device.

14 . The non-transitory computer-readable medium of claim 11 , wherein the operations further comprise, prior to generating the hardware description:

configuring, by the VMM based on the physical device, a virtual management device to expose to the PVM; and

generating the hardware description that describes a plurality of PVM devices, wherein the plurality of PVM devices comprises the physical device and the virtual management device.

15 . The non-transitory computer-readable medium of claim 11 , wherein the SVM is configured to share a dataset with the PVM by:

initializing the virtual device usable to access the physical device;

creating, by the virtual device, a buffer object associated with the dataset, wherein the buffer object is usable to locate the dataset; and

transmitting, by the virtual device, a reference to the buffer object to the PVM, wherein the user space of the PVM is configured to use the reference to the buffer object to map the dataset to the guest memory of the PVM.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2023
From: RUIZ, ALBERTO CARLOS; MARTINEZ CANILLAS, FRANCISCO JAVIER; LOPEZ PASCUAL, SERJIO
To: RED HAT, INC.
Reel/Frame 065215/0333 →
Continuity (1)
Related Publication 20250123868A1 · Apr 17, 2025
References Cited (6)
US 7743389B2 · Mahalingam · 2010 [cited by examiner]
US 9069591B1 · Beloussov · 2015 [cited by examiner]
US 10754676B2 · Alvarez · 2020 [cited by examiner]
US 20050198632A1 · Lantz · 2005 [cited by examiner]
US 20170364428A1 · Ganesan · 2017 [cited by examiner]
US 20220066811A1 · Zhao · 2022 [cited by examiner]