USB (Universal Serial Bus) equipment redirection method, device and equipment for virtual machine

By detecting USB devices on the host machine and selecting the target virtual machine based on the virtual machine's VNC connection status and activity rules, and setting operation permissions, the problem of USB device redirection under non-support of the SPICE protocol is solved, native-level USB device redirection is achieved, and deployment complexity and maintenance costs are reduced.

CN120602338APending Publication Date: 2025-09-05INSPUR BUSINESS MACHINE CO LTD

Patent Information

Application Number
CN202510758938.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-09
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing technologies cannot implement USB device redirection in scenarios that do not support the SPICE protocol, and the reliance on third-party tools increases deployment complexity and maintenance costs.

Method used

The host machine detects the USB device and obtains the authorized virtual machine, selects the target virtual machine based on the virtual machine's VNC connection status and activity rules, sets the operation permissions and executes the redirection script, binds the USB device to the target virtual machine, and realizes native-level USB device redirection.

Benefits of technology

Without relying on the SPICE protocol and third-party tools, native-level redirection of USB devices is achieved, reducing deployment complexity and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602338A_ABST
    Figure CN120602338A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computers, and provides a USB (Universal Serial Bus) equipment redirection method, device and equipment for a virtual machine. The method comprises the steps that in response to the fact that a host machine detects that a registered USB device is inserted, a virtual machine authorized by the USB device is obtained according to registration information, and whether the authorized virtual machine is online or not is checked; if the plurality of virtual machines are detected to be online, selecting a target virtual machine from the plurality of virtual machines based on a virtual machine activeness rule or a VNC traffic size according to the VNC connection states of the plurality of virtual machines; and setting the operation authority of the target virtual machine to the USB device through the host machine, executing the redirection script, binding the USB device to the target virtual machine, and completing redirection. The scheme does not depend on the support of a specific SPICE protocol, realizes the redirection of the native-level USB equipment, does not need to additionally install a third-party tool for supporting the redirection of the USB, reduces the deployment complexity, and contributes to reducing the maintenance cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a method, apparatus and device for redirecting a USB device to a virtual machine. Background Art

[0002] A virtual machine (VM) is a software-emulated computer system that runs on a host (physical) computer and shares the host's hardware resources, such as the CPU (Central Processing Unit), memory, and disks. It also has its own operating system and applications. USB redirection uses virtualization technology to "map" or "transparently transmit" USB (Universal Serial Bus) devices on the host computer to the VM, enabling the VM to directly identify and use the USB devices.

[0003] Some virtual machine-targeted USB redirection methods rely on the Simple Protocol for Independent Computing Environment (SPICE) protocol. The SPICE protocol includes a built-in USB redirection channel (usbredir), allowing transparent forwarding of USB devices from the host machine to the virtual machine. In scenarios that don't support the SPICE protocol, USB device redirection is unavailable due to the lack of a USB redirection channel. For example, in scenarios that support the VNC (Virtual Network Console) protocol, USB device redirection is unavailable due to VNC's lack of USB device transparent transmission.

[0004] In other methods for implementing USB redirection for virtual machines, third-party tools that support USB redirection are installed on the client or server. Implementing USB redirection through third-party tools increases deployment complexity and requires manual installation by users. In addition, this type of USB redirection is non-native integration and increases maintenance costs.

[0005] Therefore, there is an urgent need for a virtual machine-oriented USB redirection method that does not rely on specific SPICE protocol support and does not require the additional installation of a third-party tool that supports USB redirection. Summary of the Invention

[0006] In view of this, the present invention provides a method, apparatus and device for redirecting a USB device to a virtual machine.

[0007] According to a first aspect of the present invention, a method for redirecting a USB device to a virtual machine is provided, comprising: In response to the host machine detecting that a registered USB device is inserted, obtaining a virtual machine authorized by the USB device according to the registration information and checking whether the authorized virtual machine is online; In response to detecting that multiple virtual machines are online, selecting a target virtual machine from the multiple virtual machines based on a virtual machine activity rule or based on a VNC traffic size according to VNC connection status of the multiple virtual machines; The host machine sets the target virtual machine's operating authority for the USB device, executes a redirection script, binds the USB device to the target virtual machine, and completes the redirection.

[0008] In some embodiments, the step of selecting a target virtual machine from the multiple virtual machines based on a virtual machine activity rule or based on a VNC traffic size according to the VNC connection status of the multiple virtual machines includes: In response to none of the multiple virtual machines being in a VNC connection state, selecting a target virtual machine from the multiple virtual machines based on a virtual machine activity rule; In response to a virtual machine among the multiple virtual machines being in a VNC connection state, using the virtual machine as the target virtual machine; In response to multiple virtual machines among the multiple virtual machines being in a VNC connection state, whether the VNC traffic of the virtual machines in the VNC connection state is balanced is determined based on a traffic balancing rule, and according to the judgment result, a target virtual machine is selected from the virtual machines in the VNC connection state based on the virtual machine activity rule or based on the VNC traffic size.

[0009] In some embodiments, the step of selecting a target virtual machine from the multiple virtual machines based on a virtual machine activity rule includes: The activity levels of the multiple virtual machines are determined based on one or more of the number of sessions, the number of logged-in users, the CPU usage, and the memory usage of the virtual machines, and the virtual machine with the highest activity is selected as the target virtual machine.

[0010] In some embodiments, the step of determining whether the VNC traffic of the virtual machines in the VNC connection state is balanced based on the traffic balancing rule, and determining, based on the determination result, whether to select a target virtual machine from the virtual machines in the VNC connection state based on the virtual machine activity rule or based on the VNC traffic size, includes: Get the maximum VNC flow rate and the minimum VNC flow rate among the VNC flows of the virtual machines in the VNC connection state; Calculating a ratio of the maximum VNC flow rate to the minimum VNC flow rate, and comparing the ratio with a preset balancing threshold; In response to the ratio being greater than the balancing threshold, selecting the virtual machine corresponding to the maximum VNC traffic as the target virtual machine; In response to the ratio being not greater than the balance threshold, a target virtual machine is selected from the virtual machines in the VNC connection state based on the virtual machine activity rule.

[0011] In some embodiments, the step of selecting a target virtual machine from the virtual machines in the VNC connection state based on the virtual machine activity rule includes: The activity of the virtual machines in the VNC connection state is determined based on one or more of the number of virtual machine sessions, the number of logged-in users, the CPU usage, and the memory usage, and the virtual machine with the highest activity is selected as the target virtual machine.

[0012] In some embodiments, the step of setting, by the host machine, the target virtual machine's operating permissions for the USB device includes: Reading the preset operation authority in the registration information, and obtaining the default operation authority of the target virtual machine for the USB device; Performing a bitwise AND calculation on each permission bit of the preset operation permission and the default operation permission, and updating the preset operation permission in the registration information according to the calculation result; Based on the updated preset operation permissions, permission rules that conform to the target virtual machine environment are generated and written into the target virtual machine to complete the operation permission setting of the target virtual machine for the USB device.

[0013] In some embodiments, the step of obtaining a virtual machine authorized by the USB device according to the registration information includes: Determine whether the USB device is an administrator device according to the registration information; In response to determining that the USB device is the management device, mounting the USB device on the host machine; In response to determining that the USB device is a common device, a virtual machine authorized by the USB device is obtained.

[0014] In some embodiments, the method further comprises: In response to detecting that only one virtual machine is online, the virtual machine is selected as the target virtual machine.

[0015] According to a second aspect of the present invention, there is provided a USB device redirection apparatus for a virtual machine, the apparatus comprising: The first module, in response to the host machine detecting that a registered USB device is inserted, obtains a virtual machine authorized by the USB device according to the registration information and checks whether the authorized virtual machine is online; The second module selects a target virtual machine from the multiple virtual machines based on a virtual machine activity rule or a VNC traffic size in response to detecting that multiple virtual machines are online and according to the VNC connection status of the multiple virtual machines; The third module sets the target virtual machine's operating authority for the USB device through the host machine, executes a redirection script, binds the USB device to the target virtual machine, and completes the redirection.

[0016] According to a third aspect of the present invention, an electronic device is also provided, which includes: at least one processor; and a memory, the memory storing a computer program that can be run on the processor, and the processor executes the aforementioned USB device redirection method for a virtual machine when executing the program.

[0017] The above-mentioned USB device redirection method for virtual machines, when the host machine detects that the inserted USB device has been registered, directly obtains the virtual machine authorized by the USB device based on its registration information in the host machine and checks whether it is online. If multiple virtual machines are detected to be online, according to the VNC connection status of the multiple virtual machines, a target virtual machine is selected from the multiple virtual machines based on the virtual machine activity rule or the VNC traffic size. It does not rely on specific SPICE protocol support. Based on the VNC connection status of the virtual machine and the preset target virtual machine determination rule, the inserted USB device is matched to the corresponding target virtual machine. In scenarios where the SPICE protocol is not supported, native-level USB device redirection for virtual machines can also be implemented, thereby expanding the applicable scenarios of USB device redirection for virtual machines.

[0018] By setting the target virtual machine's operation permissions for the USB device on the host machine, executing the redirection script, binding the target virtual machine to the target virtual machine, and completing the redirection, it helps to dynamically redirect the USB device to the target virtual machine and improve the flexibility of USB permission deployment.

[0019] The entire process of redirection for virtual machines described above does not rely on specific SPICE protocol support, nor does it require the installation of additional third-party tools that support USB redirection, reducing deployment complexity. The entire process is automatically triggered by the system and does not require manual installation by the user. It also implements native-level USB device redirection, does not incur additional fees, and helps reduce maintenance costs.

[0020] In addition, the present invention also provides a USB device redirection device for a virtual machine and an electronic device, which can also achieve the above technical effects and will not be described in detail here. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other embodiments can be obtained based on these drawings without paying any creative work.

[0022] Figure 1 A flowchart of a USB device redirection method for a virtual machine provided by an embodiment of the present invention; Figure 2 A flowchart of registering a USB device in a host machine is provided in another embodiment of the present invention; Figure 3 A flowchart of a host machine writing permission rules to a target virtual machine provided in another embodiment of the present invention; Figure 4 A flowchart of a host machine binding a USB device to a target virtual machine provided in another embodiment of the present invention; Figure 5 A flowchart of starting virtual machine status monitoring provided by another embodiment of the present invention; Figure 6 Another flowchart of USB device redirection provided by another embodiment of the present invention; Figure 7 A schematic structural diagram of a USB device redirection apparatus for a virtual machine provided by another embodiment of the present invention; Figure 8 FIG. 1 is a diagram showing the internal structure of an electronic device in another embodiment of the present invention. DETAILED DESCRIPTION

[0023] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the embodiments of the present invention are further described in detail below in conjunction with specific embodiments and with reference to the accompanying drawings.

[0024] It should be noted that all expressions using "first" and "second" in the embodiments of the present invention are for distinguishing two non-identical entities with the same name or non-identical parameters. It can be seen that "first" and "second" are only for the convenience of expression and should not be understood as limitations on the embodiments of the present invention. Subsequent embodiments will not explain this one by one.

[0025] In one embodiment, please refer to Figure 1As shown, the present invention provides a virtual machine-oriented USB device redirection method 100, specifically, comprising: Step 101: In response to a host machine detecting that a registered USB device is inserted, a virtual machine authorized by the USB device is obtained according to registration information and whether the authorized virtual machine is online is checked.

[0026] Specifically, the registration information of the USB device includes the manufacturer ID and product ID of the USB device, the USB port number of the host machine, the user's preset operation permissions, and the redirectable virtual machine (that is, the virtual machine authorized by the USB device).

[0027] In a specific embodiment, the registration process of the USB device in the host machine is as follows: Figure 2 As shown, when the host receives a registration request for a USB device to be registered, it determines whether it is an administrator device based on its device type. If it is an administrator device, it is directly mounted on the host and its device information is recorded. If it is not an administrator device, a USB device redirection udev rule is generated based on the USB device's registration information. Furthermore, based on the virtual machine and user's preset operation permissions authorized in the registration information, a virtual machine permission udev rule is generated. The device information of the USB device is then recorded on the host, completing the registration of the USB device. After the USB device is registered on the host, device rules are automatically generated under the host system. The Linux device discovery mechanism can be used to check whether the USB device is registered.

[0028] In another specific embodiment, the USB device redirection udev rule is as follows: ACTION=="add",SUBSYSTEMS="usb",ENV{DEVTYPE}=="disk",RUN+=" / path / to / redir.sh ATTRS{idVendor}ATTRS{idVendor}. When the host system loads the USB device, the system executes the rederict.sh script, and the script parameters are ATTRS{idVendor} ATTRS{idVendor}. Among them, ACTION represents the identified device action, SUBSYSTEMS represents the device type, ATTRS represents the device attributes, idVendor represents the manufacturer ID of the registered device, idProduct is the product ID of the registered device, and Run represents the redirection script, which is responsible for redirecting the specific execution action.

[0029] In another specific embodiment, the host machine detects that an inserted USB device has been registered, obtains a virtual machine authorized by the USB device based on the registration information, and checks whether the virtual machine is online. Specifically, the host machine detects that a device has been inserted, detects the type of the inserted device to determine whether it is a USB device, and if so, further checks whether it is registered in the host machine. If not, the USB device is ejected from the host machine; if so, whether the USB device is an administrator device is directly mounted on the host machine and the administrator device information is recorded in the host machine without redirection; if not, the host machine obtains the virtual machine authorized by the USB device based on the registration information and checks whether it is online.

[0030] Step 102 : In response to detecting that multiple virtual machines are online, a target virtual machine is selected from the multiple virtual machines based on a virtual machine activity rule or a VNC traffic size according to the VNC connection status of the multiple virtual machines.

[0031] In a specific embodiment, according to the VNC connection status of multiple virtual machines, selecting a target virtual machine from multiple virtual machines based on a virtual machine activity rule or based on the VNC traffic size includes: if none of the multiple virtual machines are in a VNC connection state, selecting a target virtual machine from the multiple virtual machines based on the virtual machine activity rule; if one of the multiple virtual machines is in a VNC connection state, using it as the target virtual machine; if multiple virtual machines are in a VNC connection state, determining whether the VNC traffic of the virtual machines in the VNC connection state is balanced based on a traffic balancing rule, and determining based on the judgment result whether to select a target virtual machine from the virtual machines in the VNC connection state based on the virtual machine activity rule or based on the VNC traffic size.

[0032] In another specific embodiment, a target virtual machine is selected from multiple virtual machines based on a virtual machine activity rule, which includes: judging the activity levels of multiple virtual machines based on one or more of the number of sessions, number of logged-in users, CPU usage, and memory usage of the virtual machine, and selecting the virtual machine with the highest activity as the target virtual machine.

[0033] In another specific embodiment, whether the VNC traffic of the virtual machines in the VNC connection state is balanced is determined based on the traffic balancing rule, and according to the judgment result, the target virtual machine is selected from the virtual machines in the VNC connection state based on the virtual machine activity rule or based on the VNC traffic size, including: obtaining the maximum VNC traffic and the minimum VNC traffic in the VNC traffic of the virtual machines in the VNC connection state; calculating the ratio of the maximum VNC traffic to the minimum VNC traffic, and comparing it with a preset balancing threshold; if the ratio is greater than the balancing threshold, selecting the virtual machine corresponding to the maximum VNC traffic as the target virtual machine; if the ratio is not greater than the balancing threshold, selecting the target virtual machine from the virtual machines in the VNC connection state based on the virtual machine activity rule.

[0034] In another specific embodiment, the step of selecting a target virtual machine from virtual machines in a VNC connection state based on a virtual machine activity rule includes: judging the activity of the virtual machines in a VNC connection state based on one or more of the number of sessions, the number of logged-in users, the CPU usage, and the memory usage of the virtual machine, and selecting the virtual machine with the highest activity as the target virtual machine.

[0035] In another specific embodiment, if multiple virtual machines are not in a VNC connection state, it means that the virtual machines may be remotely accessed via SSH, and a target virtual machine is selected based on a scoring mechanism established based on the virtual machine activity rule. It is understandable that the activity factors for determining the activity of a virtual machine include but are not limited to the number of sessions of the virtual machine, the number of logged-in users, CPU usage, and memory usage. Total score = number of virtual machine sessions + number of logged-in users + CPU occupancy bonus + memory occupancy bonus. Number of virtual machine sessions: 1 point for each session; number of logged-in users: 1 point for each independent user login; CPU occupancy bonus: 1 point for the highest usage; memory occupancy bonus: 1 point for the highest usage. Based on the scores corresponding to the multiple virtual machines calculated according to the above scoring mechanism, a comparison is made and the one with the highest score is taken as the target virtual machine. It is understandable that the scoring mechanism established by the virtual machine activity rule includes but is not limited to the above-mentioned scoring rules. Other scoring methods that can accurately select the most active virtual machines are also within the scope of protection of this application and will not be repeated here. For example, VM A has 3 sessions, 2 users, 80% CPU usage (+1), and 70% memory usage (+1), resulting in a final score of 7. VM B has 2 sessions, 1 user, 60% CPU usage, and 50% memory usage, resulting in a final score of 3. Based on the comparison of the final scores of VM A and VM B, VM A is selected as the target VM.

[0036] In another specific embodiment, if one of the multiple virtual machines is in a VNC connection state, it is directly used as the target virtual machine, and the virtual machine permission configuration script mode-set.sh and the device addition script attach-device.sh are executed under the online virtual machine. The parameters of the two scripts include idVendor, idProduct, virtual machine name, registration permission mode information, etc., so that the online virtual machine is used as the target virtual machine to redirect the USB device to the online virtual machine.

[0037] In another specific embodiment, if multiple virtual machines are in a VNC connection state, tcpdump (a powerful command-line network packet capture tool that can completely intercept data packets transmitted in the network and provide analysis) is first used to capture the VNC port traffic of each virtual machine, calculate the traffic multiplier, divide the maximum traffic by the minimum traffic to obtain the traffic multiplier N, and compare it with the preset balancing threshold. The balancing threshold is flexibly set according to actual conditions, for example, 3 is often selected. If the traffic multiplier N is greater than the preset balancing threshold, it means that the VNC traffic between the virtual machines in the VNC connection state is significantly different, then the virtual machine with the largest VNC traffic is selected as the target virtual machine. If the traffic multiplier N is not greater than the preset balancing threshold, it means that the VNC traffic between the virtual machines in the VNC connection state is balanced, then the target virtual machine is selected based on the virtual machine activity rule. The process of selecting the virtual machine with the highest activity as the target virtual machine based on the virtual machine activity rule is as described above and will not be repeated.

[0038] By using this VNC state-based target VM determination rule, native-level USB device redirection is achieved even without SPICE protocol support, expanding the applicable scenarios for USB device redirection for virtual machines. This overcomes the drawback of existing VNC protocol scenarios, which require the installation of third-party USB redirection tools and prevent native-level USB device redirection. This also avoids the complexity of third-party tool deployment, reducing maintenance costs.

[0039] Step 103: The host machine sets the target virtual machine's operating authority for the USB device, executes the redirection script, binds the USB device to the target virtual machine, and completes the redirection.

[0040] Specifically, the operation permissions include read and / or write permissions, etc. Setting the operation permissions of the target virtual machine to the USB device through the host machine includes permission checking, permission rule generation, and permission rule injection into the target virtual machine.

[0041] In one specific embodiment, setting the target virtual machine's operating permissions for a USB device through a host machine includes: reading preset operating permissions in registration information and obtaining the target virtual machine's default operating permissions for the USB device; performing a bitwise AND operation on each permission bit of the preset operating permissions and the default operating permissions, and updating the preset operating permissions in the registration information based on the calculation result; generating permission rules that conform to the target virtual machine's environment based on the updated preset operating permissions, and writing the rules into the target virtual machine to complete the target virtual machine's operating permissions for the USB device. By checking the configured permissions, that is, checking whether each field of the permissions is legal, the legality of the permissions is ensured to prevent excessive permissions or the addition of permissions that should not exist.

[0042] By configuring the permissions of the target virtual machine, the dynamic permission setting of the target virtual machine for USB devices is realized, which improves the flexibility of configuring USB device operation permissions. The entire process of the virtual machine-oriented redirection realizes the dynamic redirection of USB devices to the target virtual machine, and realizes native USB device redirection.

[0043] In another specific embodiment, if the host machine detects that only one virtual machine is online, it directly selects it as the target virtual machine. Thereafter, the host machine sets the target virtual machine's operation permissions for the USB device, executes the redirection script, and binds the USB device to the target virtual machine, completing the redirection step.

[0044] In another specific embodiment, the host machine's configuration of operating permissions for the target virtual machine consists of three fields: owner-group-other. Each field is typically a combination of r, w, and x. r represents read permission, represented by the number 4, or 100 in binary; w represents write permission, represented by the number 2, or 010 in binary; and x represents execute permission, represented by the number 1, or 001 in binary.

[0045] In another specific embodiment, setting the target virtual machine's operating authority for the USB device through the host machine includes: (1) obtaining the user's preset operating authority config_mode from the registration information; (2) obtaining the default authority default_mode of the USB device from the system; (3) performing an AND operation on each permission bit of config_node and default_mode to obtain new_mode; (4) determining whether new_mode and config_mode are the same. If they are different, updating config_mode in the registration information to new_mode. Then, generating permission rules based on device parameters, permission parameters, and virtual machine configuration: (1) obtaining idVendor and idProduct of the USB device and using them as device field information of the permission rule; (2) obtaining the registered device permission information mode as the permission field; (3) obtaining the bus field value busid in the usb.xml configuration information; (4) replacing the corresponding value according to the device rule template to complete the permission rule generation.

[0046] In another specific embodiment, the permission specifications are as follows: ACTION=="add",SUBSYSTEMS="usb",ATTRS{idVendor}=="0951",ATTRS{idProduct}=="1666",BUS="0","MODE="0644".

[0047] When the virtual machine system loads a USB device with a manufacturer ID of 0951 and a product ID of 1666 and adds it to the device with bus number 0, the device's usb.xml configuration information is as follows: <hostdev mode="subsystem" type="usb" managed="yes"> <source> <vendor id="0x0000" / > <product id="0x0000" / > <address bus="0" device="0">< / address> < / hostdev> Implement device rules in the virtual machine system. When the virtual machine system detects that a specific USB device performs an add action, the device permission is set to configuration permission.

[0048] In another specific embodiment, Figure 3The figure shows a flowchart of the host writing permission rules to the target virtual machine. If the target virtual machine has the qemu-guest-agent client software installed, the host can use qemu-guest-agent to create a file. The steps for the host to inject permission rules into the target virtual machine are as follows: (1) Obtain the generated permission rules, where idVendor and idProduct can identify the device and mode is the permission parameter. (2) The host performs base64 encoding on the permission rules to generate a base64-encoded rule. (3) The host executes the guest-file-open command to open the file of the virtual machine and returns the handle information. (4) The host executes the guest-file-write command based on the handle information to write the base64-encoded rule data. (5) Close the guest / etc / udev / rule.d / usb.rule file. After executing the above steps, the virtual machine has the permission rules that control the permissions of the specific USB device. When the USB device is redirected to the target virtual machine, the permission rules are automatically executed and the device permissions are set to the configuration permissions.

[0049] In another specific embodiment, USB redirection is completed by adding a device attach-device.sh script, which generates a device configuration file based on the device information and executes a device add command to complete the function of adding the USB device to the virtual machine. Figure 4 The figure shows the flow chart of how the host binds the USB device to the target virtual machine. The details are as follows: (1) Find the device size file and enable (enable switch) file based on the device information. (2) Determine whether the size is 0. If it is 0, re-enable the USB device file using the enable file. (3) Re-read the size file to check whether the capacity has returned to normal. If it has, proceed to the next step. If it is still 0, return error code 1. (4) Generate the device rule file usb.xml based on the input parameters, where the vendor id is filled with idVendor information and the product id is filled with idProduct: <hostdev mode="subsystem" type="usb" managed="yes"> <source> <vendor id="0x0000" / > <product id="0x0000" / > <address bus="0" device="0">< / address> < / hostdev> (5) Execute the specific device addition command virsh attach-device guestname --file usb.xml –current. After completing the above steps, the redirection of the USB device is completed.

[0050] In another specific embodiment, the host machine provides a monitoring process for the virtual machine status and performs the addition or deletion of devices during the virtual machine power on and off process. Figure 5As shown in the figure, the process of starting virtual machine status monitoring is as follows: (1) Register the libvirt interface on the host and trigger the (VIR_DOMAIN_EVENT_STARTED) event when the host is powered on. (2) If the host monitors the power-on event, it checks the registration information to see if a USB device has been ejected by the host system. (3) If a USB device has been ejected by the host system, first find the corresponding enable file based on its device information and execute the command to re-enable the USB device. (4) Execute the permission configuration script mode-set.sh and the device addition script attach-device.sh to complete the redirection of the USB device. This effectively avoids the problem of state asynchrony between the host and the virtual machine. For example, after the host ejects the USB device, the virtual machine can still redirect it but cannot use the USB device, or after the virtual machine performs the eject operation on the USB device, the host fails to redirect the USB device to another virtual machine.

[0051] In another specific embodiment, Figure 6 As shown, it is another flowchart of USB device redirection. After the USB device is inserted into the host machine, the steps for executing the USB device redirection are as follows: When the host machine detects that the device is inserted, it determines the device type to determine whether it is a USB device. If the device is a USB storage device, it is necessary to further determine whether it is an administrator device. If it is not an administrator device, the number of online virtual machines authorized by it is obtained. If the number of online virtual machines is 0, the device is ejected. If the number of online virtual machines is 1, it is directly used as the target virtual machine, and the permission configuration and device script are subsequently executed to complete the device redirection. If the number of online virtual machines is greater than 1, the target virtual machine is selected from multiple virtual machines. This step is as described above and will not be repeated here. After that, the permission configuration and device script are executed to complete the device redirection.

[0052] The above-mentioned USB device redirection method for virtual machines does not rely on specific SPICE protocol support. It matches the inserted USB device to the corresponding target virtual machine based on the VNC connection status of the virtual machine and the preset target virtual machine determination rule. In scenarios where the SPICE protocol is not supported, native-level USB device redirection for virtual machines can also be achieved. The host machine sets the target virtual machine's operating permissions for the USB device, executes the redirection script, binds the target virtual machine to the target virtual machine, and completes the redirection. The entire process of the above-mentioned virtual machine-oriented redirection does not rely on specific SPICE protocol support, nor does it require the additional installation of third-party tools that support USB redirection, which reduces deployment complexity. The entire process is automatically triggered by the system and does not require manual installation by the user. What is achieved is native-level USB device redirection, which does not incur additional costs and helps reduce maintenance costs.

[0053] According to some embodiments of the present invention, please refer to Figure 7 As shown, the present invention also provides a USB device redirection device 200 for virtual machines, the device comprising: a first module 201, for, in response to a host machine detecting that a registered USB device is inserted, obtaining a virtual machine authorized by the USB device according to registration information and checking whether the authorized virtual machine is online; a second module 202, for, in response to detecting that multiple virtual machines are online, selecting a target virtual machine from multiple virtual machines based on a virtual machine activity rule or based on the VNC traffic size according to the VNC connection status of the multiple virtual machines; a third module 203, for setting the target virtual machine's operating authority for the USB device through the host machine, executing a redirection script, binding the USB device to the target virtual machine, and completing the redirection.

[0054] It should be noted that each module in the aforementioned USB device redirection apparatus for virtual machines can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in an electronic device in the form of hardware, or can be stored in a memory in the electronic device in the form of software, so that the processor can call and execute the corresponding operations of each module.

[0055] According to another aspect of the present invention, an electronic device is provided. The electronic device may be a server. Figure 8 As shown. The electronic device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the electronic device is used to store data. The network interface of the electronic device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, the above-mentioned USB device redirection method for a virtual machine is implemented.

[0056] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0057] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0058] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.

Claims

1. A USB device redirection method for a virtual machine, characterized in that: include: In response to the host machine detecting that a registered USB device is inserted, obtaining a virtual machine authorized by the USB device according to the registration information and checking whether the authorized virtual machine is online; In response to detecting that multiple virtual machines are online, selecting a target virtual machine from the multiple virtual machines based on a virtual machine activity rule or based on a VNC traffic size according to VNC connection status of the multiple virtual machines; The host machine sets the target virtual machine's operating authority for the USB device, executes a redirection script, binds the USB device to the target virtual machine, and completes the redirection.

2. The method for redirecting a USB device to a virtual machine according to claim 1, wherein: The step of selecting a target virtual machine from the multiple virtual machines based on a virtual machine activity rule or based on a VNC traffic size according to the VNC connection status of the multiple virtual machines includes: In response to none of the multiple virtual machines being in a VNC connection state, selecting a target virtual machine from the multiple virtual machines based on a virtual machine activity rule; In response to a virtual machine among the multiple virtual machines being in a VNC connection state, using the virtual machine as the target virtual machine; In response to multiple virtual machines among the multiple virtual machines being in a VNC connection state, whether the VNC traffic of the virtual machines in the VNC connection state is balanced is determined based on a traffic balancing rule, and according to the judgment result, a target virtual machine is selected from the virtual machines in the VNC connection state based on the virtual machine activity rule or based on the VNC traffic size.

3. The method for redirecting a USB device to a virtual machine according to claim 2, wherein: The step of selecting a target virtual machine from the multiple virtual machines based on the virtual machine activity rule includes: The activity levels of the multiple virtual machines are determined based on one or more of the number of sessions, the number of logged-in users, the CPU usage, and the memory usage of the virtual machines, and the virtual machine with the highest activity is selected as the target virtual machine.

4. The method for redirecting a USB device to a virtual machine according to claim 2, wherein: The step of determining whether the VNC traffic of the virtual machines in the VNC connection state is balanced based on the traffic balancing rule, and determining, according to the determination result, to select a target virtual machine from the virtual machines in the VNC connection state based on the virtual machine activity rule or based on the VNC traffic size, includes: Get the maximum VNC flow rate and the minimum VNC flow rate among the VNC flows of the virtual machines in the VNC connection state; Calculating a ratio of the maximum VNC flow rate to the minimum VNC flow rate, and comparing the ratio with a preset balancing threshold; In response to the ratio being greater than the balancing threshold, selecting the virtual machine corresponding to the maximum VNC traffic as the target virtual machine; In response to the ratio being not greater than the balance threshold, a target virtual machine is selected from the virtual machines in the VNC connection state based on the virtual machine activity rule.

5. The method for redirecting a USB device to a virtual machine according to claim 4, wherein: The step of selecting a target virtual machine from the virtual machines in the VNC connection state based on the virtual machine activity rule includes: The activity of the virtual machines in the VNC connection state is determined based on one or more of the number of virtual machine sessions, the number of logged-in users, the CPU usage, and the memory usage, and the virtual machine with the highest activity is selected as the target virtual machine.

6. The method for redirecting a USB device to a virtual machine according to claim 1, wherein: The step of setting the target virtual machine's operation permission for the USB device through the host machine includes: Reading the preset operation authority in the registration information, and obtaining the default operation authority of the target virtual machine for the USB device; Performing a bitwise AND calculation on each permission bit of the preset operation permission and the default operation permission, and updating the preset operation permission in the registration information according to the calculation result; Based on the updated preset operation permissions, permission rules that conform to the target virtual machine environment are generated and written into the target virtual machine to complete the operation permission setting of the target virtual machine for the USB device.

7. The method for redirecting a USB device to a virtual machine according to claim 1, wherein: The step of obtaining the virtual machine authorized by the USB device according to the registration information includes: Determine whether the USB device is an administrator device according to the registration information; In response to determining that the USB device is the management device, mounting the USB device on the host machine; In response to determining that the USB device is a common device, a virtual machine authorized by the USB device is obtained.

8. The method for redirecting a USB device to a virtual machine according to claim 1, wherein: The method further comprises: In response to detecting that only one virtual machine is online, the virtual machine is selected as the target virtual machine.

9. A USB device redirection device for a virtual machine, characterized in that: The device comprises: The first module, in response to the host machine detecting that a registered USB device is inserted, obtains a virtual machine authorized by the USB device according to the registration information and checks whether the authorized virtual machine is online; The second module selects a target virtual machine from the multiple virtual machines based on a virtual machine activity rule or a VNC traffic size in response to detecting that multiple virtual machines are online and according to the VNC connection status of the multiple virtual machines; The third module sets the target virtual machine's operating authority for the USB device through the host machine, executes a redirection script, binds the USB device to the target virtual machine, and completes the redirection.

10. An electronic device, characterized in that: include: at least one processor; as well as A memory storing a computer program executable in the processor, wherein the processor executes the virtual machine-oriented USB device redirection method according to any one of claims 1 to 8 when executing the program.

Citation Information

Patent Citations

  • Load balance method and system based on VNC dispatching

    CN105407115A

  • USB device and virtual machine hot binding method and device and storage medium

    CN112631721A

  • Virtual machine function detection method and apparatus, electronic device and storage medium

    WO2020177385A1

Cited By

  • Method for supporting read-only of high-speed USB storage device based on SPICE protocol

    CN121957723A

  • Method for supporting read-only of high-speed USB storage device based on SPICE protocol

    CN121957723B