Life cycle management for device input/output interfaces in virtualized environments
A security module of a processor manages the lifecycle of device interfaces of input/output (I/O) devices within a virtualization environment in a secure and trusted manner. For example, the security module is configured to bind a device interface of an I/O device interface to a virtual machine (VM). Responsive to the device interface being bound, the security module is configured to attest at least one of the device interface and the I/O device. Responsive to the at least one of the device interface or the I/O device being attested, the security module is configured to configure an input-output memory management unit (IOMMU) and memory resources associated with the VM.
1 . A method comprising:
binding a device interface of an input/output (I/O) device within a virtualization environment to a virtual machine (VM);
responsive to binding the device interface, attesting at least one of the device interface and the I/O device; and
responsive to attesting the at least one of the device interface or the I/O device,
configuring an input-output memory management unit (IOMMU) by creating an entry in a secure device table examined by the IOMMU during processing of memory access requests.
2 . The method of claim 1 , further comprising:
unbinding the device interface from the VM.
3 . The method of claim 2 , further comprising:
responsive to unbinding the device interface from the VM, binding the device interface to another VM.
4 . The method of claim 2 , further comprising:
responsive to unbinding of device interface from the VM, reclaiming a memory resource associated with the device interface, wherein the memory resource is used to track a device interface during its lifecycle.
5 . The method of claim 1 , wherein binding the device interface comprises:
mapping memory mapped I/O (MMIO) ranges associated with the device interface to guest physical addresses (GPAs) of the VM.
6 . The method of claim 1 , wherein binding the device interface further comprises:
transitioning the device interface from a first state that allows a configuration of the device interface to be changed to a second state, the second state locking the configuration and allowing the VM to access the device interface.
7 . The method of claim 1 , wherein attesting the at least one of the device interface or the I/O device comprises:
providing the VM with one or more of an attestation report or a certificate chain associated with the I/O device; and
providing the VM with an interface report associated with the device interface.
8 . The method of claim 7 , wherein attesting the at least one of the device interface or the I/O device further comprises:
responsive to providing the one or more of the attestation report or the certificate chain, determining that a configuration of the I/O device is valid; and
responsive to providing the interface report, determining that a configuration of the device interface is valid.
9 . The method of claim 8 , wherein determining that the configuration of the device interface is valid comprises determining that memory mapped I/O (MMIO) ranges identified in the interface report match MMIO ranges assigned by a hypervisor to the VM.
10 . The method of claim 8 , wherein the IOMMU is configured in response to determining that the configuration of the I/O device and the configuration of the device interface are valid.
11 . The method of claim 8 , further comprising unbinding the device interface from the VM in response to at least one of determining that a configuration of the I/O device is invalid based on the attestation report or the certificate chain, or determining that a configuration of the device interface is invalid based on the interface report.
12 . The method of claim 1 , further comprising:
responsive to attesting the at least one of the device interface or the I/O device, configuring memory resources associated with the VM by setting MMIO ranges assigned to the VM by a hypervisor as valid.
13 . The method of claim 1 , wherein the entry binds the device interface to the VM and encodes security attributes governing access by the device interface with the VM.
14 . A method comprising:
binding a device interface of an input/output (I/O) device within a virtualization environment to a virtual machine (VM);
responsive to binding the device interface, providing attestation information associated with at least one of the device interface and the I/O device to the VM;
responsive to providing the attestation information, receiving an indication from the VM that one or more of the device interface or the I/O device are untrusted; and
responsive to receiving the indication, unbinding the device interface from the VM, including removing an entry corresponding to the device interface from a secure device table examined by the IOMMU during processing of memory access requests.
15 . The method of claim 14 , wherein providing the attestation information comprises:
providing the VM with one or more of an attestation report or a certificate chain associated with the I/O device; and
providing the VM with an interface report associated with the device interface.
16 . The method of claim 15 , wherein providing the attestation information further comprises:
providing the VM with one or more of digest of the attestation report or a digest of the certificate chain; and
providing the VM with a digest of the interface report.
17 . The method of claim 16 , wherein the indication received from the VM is based on a comparison of one or more of the digest of the attestation report to the attestation report, the digest of the certificate chain to the certificate chain, or the digest of the interface report to the interface report.
18 . A processor comprising:
a security co-processor configured to:
bind a device interface of an input/output (I/O) device within a virtualization environment to a virtual machine (VM);
responsive to the device interface being bound, attest at least one of the device interface and the I/O device; and
responsive to the at least one of the device interface or the I/O device being attested,
configure an input-output memory management unit (IOMMU) by creating an entry in a secure device table examined by the IOMMU during processing of memory access requests.
19 . The processor of claim 18 , wherein the security co-processor is further configured to
unbind the device interface from the VM.
20 . The processor of claim 18 , wherein the security co-processor is configured to attest the at least one of the device interface or the I/O device by:
providing the VM with one or more of an attestation report or a certificate chain associated with the I/O device; and
providing the VM with an interface report associated with the device interface.
21 . A processor comprising:
a security co-processor configured to:
bind a device interface of an input/output (I/O) device within a virtualization environment to a virtual machine (VM);
responsive to the device interface being bound to the VM, provide attestation information associated with at least one of the device interface and the I/O device to the VM;
responsive to the attestation information being provided, receive an indication from the VM that one or more of the device interface or the I/O device are untrusted; and
responsive to the indication, unbind the device interface from the VM, including removing an entry corresponding to the device interface from a secure device table examined by the IOMMU during processing of memory access requests.
22 . The processor of claim 21 , wherein the security co-processor is configured to provide the attestation information by:
providing the VM with one or more of an attestation report or a certificate chain associated with the I/O device; and
providing the VM with an interface report associated with the device interface.
23 . The processor of claim 22 , wherein the security co-processor is further configured to provide the attestation information by:
providing the VM with one or more of digest of the attestation report or a digest of the certificate chain; and
providing the VM with a digest of the interface report.
24 . The processor of claim 23 , wherein the indication received from the VM is based on a comparison of one or more of the digest of the attestation report to the attestation report, the digest of the certificate chain to the certificate chain, or the digest of the interface report to the interface report.