Virtual USB device connection method, system and device and storage medium
By assigning a unique USB device identifier to the virtual machine and using a custom USB Hub, the difficulty of hardware pass-through technology in partitioning USB device resources is solved, and the virtual machine's isolated access and efficient utilization of physical USB devices is achieved.
Patent Information
- Application Number
- CN202510471520.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-15
AI Technical Summary
Hardware pass-through technology has difficulty in dividing resources when facing USB devices extended through USB Hub, resulting in the virtual machine being unable to allocate USB devices independently, affecting system performance and stability.
Through virtualization technology, each virtual USB device instance is assigned a unique identifier, and the virtual machine's isolated access to physical USB devices is achieved through a virtual USB controller and a custom USB Hub.
Improves the utilization rate of USB devices, ensures isolation of USB device access between virtual machines, prevents data leakage and unauthorized access, and improves system security and performance.
Smart Images

Figure CN119988279A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computers, and in particular to a virtual USB device connection method, system, device and storage medium. Background Art
[0002] In the field of embedded virtualization, hardware pass-through technology is widely used to achieve efficient allocation of different hardware devices in different virtual machines. This technology bypasses the host machine's operating system by directly allocating physical devices to specific virtual machines, significantly reducing device access latency and improving overall performance. Hardware pass-through technology is particularly suitable for devices with high performance requirements, such as graphics processing units (GPUs) and network interface cards (NICs). It can effectively ensure the exclusivity and efficiency of virtual machines for hardware resources and meet the strict requirements of embedded systems for real-time and performance.
[0003] However, hardware passthrough technology has obvious limitations when it comes to USB devices extended through USB Hubs. Since the USB Hub is connected to the host through only one USB bus, hardware passthrough cannot effectively divide resources for multiple USB devices on the bus. In this case, all devices connected through the USB Hub share the same bus bandwidth, making it impossible to independently assign a single USB device to a specific virtual machine. This not only limits the flexible use of USB devices by virtual machines, but may also cause resource competition between devices, thus affecting the overall performance and stability of the system. Summary of the invention
[0004] The main purpose of the present invention is to provide a virtual USB device connection method, system, device and storage medium. Through virtualization technology, multiple virtual machines can share the same physical USB device, thereby improving the utilization rate of USB devices. By assigning a unique identifier to each virtual USB device instance, it is ensured that USB device access between different virtual machines is isolated, thereby preventing data leakage and unauthorized access. Allowing a virtual machine to access a physical USB device through a virtual USB controller enables the virtual machine to access the USB device just like accessing a local device.
[0005] In order to achieve the above objectives, the present application provides the following technical solutions: According to a first aspect of an embodiment of the present application, a virtual USB device connection method is provided, the method comprising: In response to the connection instruction of the target USB device, the virtual machine creates a corresponding USB device virtual instance for the target USB device through a virtual USB controller and generates a connection data packet, wherein the connection data packet carries a USB device virtual instance identifier; The connection data packet is forwarded to the USB hub through a back-end driver, so that the USB hub controls the connection of the target USB device according to the USB device virtual instance identifier.
[0006] Optionally, the virtual machine creates a corresponding USB device virtual instance for the target USB device through a virtual USB controller and generates a connection data packet, including: The virtual machine creates a corresponding USB device virtual instance according to the attribute configuration of the target USB device through a virtual USB controller, and allocates a unique USB device virtual instance identifier to the USB device virtual instance; A corresponding connection data packet is generated according to the USB device virtual instance, wherein the connection data packet includes the USB device virtual instance identifier and a connection instruction of the target USB device.
[0007] Optionally, before responding to the connection instruction of the target USB device, the method further includes: A port control signal is sent to the USB hub via a sideband control bus to set or change identification information of several physical ports connected to the USB hub.
[0008] Optionally, the USB hub controls the connection of the target USB device according to the USB device virtual instance identifier, including: The USB hub determines whether the USB device virtual instance identifier matches according to a preconfigured identifier filter rule, wherein the identifier filter rule represents a mapping relationship between the USB device virtual instance identifier, the corresponding virtual machine, and the identifier information of the physical port; If the USB device virtual instance identifier matches successfully, the corresponding physical port is controlled to be mapped to the corresponding virtual port to achieve the connection of the target USB device; if the match fails, the USB hub discards the connection data packet.
[0009] Optionally, the USB hub determines whether the USB device virtual instance identifier matches according to a preconfigured identifier filter rule, including: The USB hub determines a requesting virtual machine for connection according to the USB device virtual instance identifier; Searching the identification information of the physical port for a list of virtual machines that are allowed to establish a connection; The list of virtual machines allowed to establish a connection is searched to see whether there is the requested virtual machine; if so, the match is successful; if not, the match fails.
[0010] Optionally, forwarding the connection data packet to the USB hub via a back-end driver includes: The virtual machine sends the connection data packet to the back-end driver, so that the back-end driver verifies the validity of the connection data packet; If the verification is successful, the connection data packet is sent to the corresponding USB bus driver, so that the USB bus driver forwards the connection data packet to the USB hub.
[0011] Optionally, after controlling the corresponding physical port to be mapped to the corresponding virtual port to achieve connection of the target USB device, the method further includes: The USB hub sends a connection confirmation signal to the USB bus driver, so that the USB bus driver forwards the connection confirmation signal to the back-end driver; The back-end driver returns the connection confirmation signal to the corresponding virtual machine, so that the virtual machine exchanges data with the target USB device through the USB device virtual instance.
[0012] According to a second aspect of an embodiment of the present application, a virtual USB device connection system is provided, the system comprising: A virtual module, configured to respond to a connection instruction of a target USB device, and the virtual machine creates a corresponding USB device virtual instance for the target USB device through a virtual USB controller and generates a connection data packet, wherein the connection data packet carries a USB device virtual instance identifier; The connection module is used to forward the connection data packet to the USB hub through the back-end driver, so that the USB hub controls the connection of the target USB device according to the USB device virtual instance identifier.
[0013] According to a third aspect of an embodiment of the present application, an electronic device is provided, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method described in the first aspect above.
[0014] According to a fourth aspect of an embodiment of the present application, a computer-readable storage medium is provided, on which computer-readable instructions are stored. The computer-readable instructions can be executed by a processor to implement the method described in the first aspect above.
[0015] In summary, the embodiments of the present application provide a virtual USB device connection method, system, device and storage medium. In response to the connection instruction of the target USB device, the virtual machine creates a corresponding USB device virtual instance for the target USB device through a virtual USB controller and generates a connection data packet, and the connection data packet carries the USB device virtual instance identifier; the connection data packet is forwarded to the USB hub through the back-end driver, so that the USB hub controls the connection of the target USB device according to the USB device virtual instance identifier. Through virtualization technology, multiple virtual machines can share the same physical USB device, which improves the utilization rate of USB devices. By assigning a unique identifier to each virtual USB device instance, it is ensured that the USB device access between different virtual machines is isolated to prevent data leakage and unauthorized access. Allowing the virtual machine to access the physical USB device through the virtual USB controller enables the virtual machine to access the USB device like accessing a local device. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying creative work.
[0017] The structures, proportions, sizes, etc. illustrated in this specification are only used to match the contents disclosed in the specification so as to facilitate understanding and reading by persons familiar with the technology. They are not used to limit the conditions under which the present invention can be implemented, and therefore have no substantial technical significance. Any structural modification, change in proportion or adjustment of size shall still fall within the scope of the technical contents disclosed in the present invention without affecting the effects and purposes that can be achieved by the present invention.
[0018] Figure 1 A flow chart of a virtual USB device connection method provided in an embodiment of the present application; Figure 2 A schematic diagram of the system architecture provided for an embodiment of the present application; Figure 3 A schematic diagram of a virtual USB device connection system provided in an embodiment of the present application; Figure 4 A structural diagram of an electronic device provided in an embodiment of the present application is shown; Figure 5 A diagram showing a computer-readable storage medium provided by an embodiment of the present application.
[0019] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0020] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0021] It should be noted that all directional indications (such as up, down, left, right, front, back, etc.) in the embodiments of the present invention are only used to explain the relative position relationship, movement status, etc. between the components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication will also change accordingly.
[0022] In addition, in the present invention, descriptions such as "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of the present invention, the meaning of "plurality" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined.
[0023] In the present invention, unless otherwise clearly specified and limited, the terms "connection", "fixation", etc. should be understood in a broad sense. For example, "fixation" can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, it can be the internal connection of two elements or the interaction relationship between two elements, unless otherwise clearly defined. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0024] In addition, the technical solutions between the various embodiments of the present invention can be combined with each other, but it must be based on the fact that ordinary technicians in the field can implement it. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by the present invention.
[0025] USB virtualization is a technology that implements the functions of physical USB devices in virtual machines. Its core is to abstract the USB resources of physical machines into virtual resources that can be used by virtual machines, so that virtual machines can access these virtual devices just like accessing local devices. Currently, USB virtualization is usually implemented in the following ways: 1. Directly call the host USB device: This method is suitable for the Linux operating system. The virtual machine can directly use the USB devices on the host, but it is limited to specific types of devices, such as keyboards, mice, etc.
[0026] 2. Full virtualization: By simulating USB devices, applications running inside the virtual machine can access virtual devices just like accessing real devices. The present invention does not belong to the above existing methods and achieves more efficient and flexible USB device access.
[0027] 3. Network redirection: Use USB redirection technology to transfer the data packets of USB devices from the host to the virtual machine through the network protocol. This method requires the use of specific client software. The present invention achieves more sophisticated control and more efficient resource management by customizing the USB Hub and the sideband control bus.
[0028] In addition, the USB host controller transparent transmission technology implements the transparent transmission of the USB host controller through the system's VFIO framework and IOMMU hardware, so that the virtual machine can directly access the physical USB host controller and can dynamically perceive the plugging and unplugging of USB devices on the host manager. USB port transparent transmission allows the transparent transmission of the specified USB port to the virtual machine, so that different USB devices mounted on the same host controller can be assigned to different virtual machines. These technologies meet the demand for USB device access in a virtualized environment to a certain extent, but there are still some limitations. The present invention provides a more flexible solution by introducing ID-based Domain division and custom USB Hub, allowing multiple virtual machines to share devices under the same USB host controller.
[0029] Although existing USB virtualization technologies have achieved virtual machine access to USB devices to a certain extent, these technologies still have obvious defects. For example, the method of directly calling the host USB device is limited to specific types of devices and cannot achieve flexible allocation of devices; although the full virtualization method can simulate devices, the performance loss is large and cannot meet the requirements of applications with high real-time requirements; the network redirection method requires additional client software support, which increases the complexity and deployment difficulty of the system. In addition, although the USB host controller transparent transmission technology can achieve transparent transmission of the entire USB host controller, this method can only be used by one virtual machine, and the host and other virtual machines cannot use the USB devices mounted under it, which lacks flexibility. Although USB port transparent transmission allows the specified USB port to be transparently transmitted to the virtual machine, the support for dynamic device plugging and unplugging and multi-virtual machine sharing is still limited. These defects limit the widespread use of USB virtualization technology in complex application scenarios and cannot meet the needs of efficient and flexible allocation of USB devices in embedded virtualization environments.
[0030] In order to solve the problem of how to efficiently and safely allocate physical USB devices to different virtual machines in a virtualized environment, in traditional virtualization technology, the virtualization of USB devices often faces problems such as large performance loss, incomplete resource isolation, and device access conflicts.
[0031] The embodiment of the present application aims to improve the efficiency of virtual machines accessing USB devices, enhance the security of resource isolation, and meet the needs of efficient and flexible allocation of USB devices in embedded virtualization environments through innovative USB virtualization technology. By introducing ID-based Domain division and custom implementation of USB Hub in the virtualization environment, multiple virtual machines can be isolated and accessed by multiple USB devices connected to the same USB Host. By using a combination of software and hardware, an ID filtering mechanism is added to the data transmission path to ensure that each virtual machine can only access the USB device assigned to it, thereby achieving effective isolation and secure access to resources.
[0032] Each virtual machine is connected to the host machine through a virtual USB controller, and the virtual USB controller is connected to a simulated USB device; each simulated USB device is connected to the actual USB bus through a back-end driver; the USB bus driver on the host machine manages data transmission on the USB bus; the custom USB Hub is connected to the host machine and physical USB devices through a high-speed bus and a sideband control bus, and an ID filter is set in the USB Hub; an ID filter is set in front of each physical USB device to decide whether to allow the data packet to pass through the corresponding USB interface based on the ID information carried by the data packet.
[0033] Figure 1 A virtual USB device connection method provided in an embodiment of the present application is shown, and the method includes: Step 101: In response to a connection instruction of a target USB device, the virtual machine creates a corresponding USB device virtual instance for the target USB device through a virtual USB controller and generates a connection data packet, wherein the connection data packet carries a USB device virtual instance identifier; Step 102: forwarding the connection data packet to the USB hub through the back-end driver, so that the USB hub controls the connection of the target USB device according to the USB device virtual instance identifier.
[0034] In a possible implementation, before responding to the connection instruction of the target USB device, the method further includes: sending a port control signal to the USB hub via a sideband control bus to set or change identification information of several physical ports connected to the USB hub.
[0035] Allows the host to dynamically set or change the identification information of the physical port on the USB hub through the sideband control bus to control which virtual machines can access specific USB devices. By ensuring that each virtual machine can only access the USB devices assigned to it, the security and isolation of the system are enhanced. Through dynamic configuration and precise control, the management and allocation of USB devices are optimized, making resource utilization more efficient.
[0036] In a possible implementation, in step 101, the virtual machine creates a corresponding USB device virtual instance for the target USB device through a virtual USB controller and generates a connection data packet, including: The virtual machine creates a corresponding USB device virtual instance according to the attribute configuration of the target USB device through a virtual USB controller, and allocates a unique USB device virtual instance identifier to the USB device virtual instance; generates a corresponding connection data packet according to the USB device virtual instance, and the connection data packet includes the USB device virtual instance identifier and a connection instruction of the target USB device.
[0037] By assigning unique identifiers to each virtual instance of a USB device and including these identifiers in the connection packets, virtual machine access to USB devices can be precisely controlled.
[0038] Assume that a data center runs multiple virtual machines, each of which needs to access different types of USB devices, such as storage devices, printers, or scanners. Before the virtual machine is started, the system administrator can select which virtual machines need to access specific USB devices through the management interface, and send port control signals to the USB hub through the sideband control bus to set or change the identification information of the physical port. For example, USB port 1 is assigned to virtual machine A and port 2 is assigned to virtual machine B. When virtual machine A requests to connect to its assigned USB storage device, the virtual machine creates a corresponding USB device virtual instance through the virtual USB controller and assigns a unique identifier (such as ID_A) to the instance. The virtual machine then generates a connection packet containing ID_A and a connection instruction.
[0039] The connection data packet is forwarded to the USB hub through the backend driver. The USB hub recognizes that the request comes from virtual machine A based on ID_A and checks whether the identification information of port 1 matches ID_A. If it matches, the USB hub maps port 1 to the virtual port of virtual machine A, allowing virtual machine A to access the USB storage device. Since each virtual machine has a unique identifier and the USB hub controls port mapping based on these identifiers, it can ensure that virtual machine A can only access the USB storage device assigned to it, but not the devices of virtual machine B. This enhances the security and isolation of the system.
[0040] In a possible implementation, in step 102, the USB hub controls the connection of the target USB device according to the USB device virtual instance identifier, including: The USB hub determines whether the USB device virtual instance identifier matches according to a pre-configured identifier filter rule, wherein the identifier filter rule represents a mapping relationship between the USB device virtual instance identifier, the corresponding virtual machine, and the identifier information of the physical port; if the USB device virtual instance identifier matches successfully, the corresponding physical port is controlled to be mapped to the corresponding virtual port to achieve the connection of the target USB device; if the match fails, the USB hub discards the connection data packet.
[0041] Through pre-configured identification filter rules, the USB hub can precisely control which virtual machines can access specific USB devices. By ensuring that only matching virtual instance identities can successfully establish a connection, unauthorized access is prevented, thereby enhancing the security of the virtualized environment. By discarding unmatched connection packets, only the correct packets are routed to the corresponding virtual machine, thus avoiding data confusion and potential security risks.
[0042] In a possible implementation manner, the USB hub determines whether the USB device virtual instance identifier matches according to a preconfigured identifier filter rule, including: The USB hub determines the requesting virtual machine for connection according to the USB device virtual instance identifier; searches for a list of virtual machines allowed to establish a connection in the identification information of the physical port; searches for whether there is the requesting virtual machine in the list of virtual machines allowed to establish a connection; if there is, matching is successful, otherwise matching fails.
[0043] Assume that the system administrator pre-configures the identification filter rules of the USB hub according to business needs. For example, the rules may specify that virtual machine VM1 can access the USB key on USB port 1, while virtual machine VM2 can access the USB drive on USB port 2. When virtual machine VM1 needs to access the USB key, it creates a USB device virtual instance through the virtual USB controller and generates a connection packet containing a unique identifier (ID_VM1). After receiving the connection packet, the USB hub determines that the virtual machine VM1 is requesting the connection based on ID_VM1. The USB hub searches the list of virtual machines that are allowed to establish a connection in the identification information of physical port 1, and searches for virtual machine VM1 in the list. If virtual machine VM1 is found, the match is successful, and the USB hub controls physical port 1 to be mapped to the virtual port of virtual machine VM1, thereby realizing the connection of the USB key. If virtual machine VM2 attempts to access the USB key (i.e., sends a connection packet containing ID_VM2), the USB hub cannot find VM2 in the list of allowed connections of physical port 1, the match fails, and the USB hub discards the connection packet, thereby preventing VM2 from accessing the USB key without authorization.
[0044] In a possible implementation, in step 102, forwarding the connection data packet to the USB hub via a backend driver includes: The virtual machine sends the connection data packet to the back-end driver so that the back-end driver verifies the validity of the connection data packet; if the verification passes, the connection data packet is sent to the corresponding USB bus driver so that the USB bus driver forwards the connection data packet to the USB hub.
[0045] The validity of the connection data packets is verified through the back-end driver to ensure that only data packets with correct format and complete content can be forwarded, thereby improving the security and stability of the system.
[0046] In a possible implementation manner, after controlling the corresponding physical port to be mapped to the corresponding virtual port to achieve connection of the target USB device, the method further includes: The USB hub sends a connection confirmation signal to the USB bus driver, so that the USB bus driver forwards the connection confirmation signal to the back-end driver; the back-end driver returns the connection confirmation signal to the corresponding virtual machine, so that the virtual machine exchanges data with the target USB device through the USB device virtual instance.
[0047] The USB hub sends a confirmation signal to the USB bus driver, and the back-end driver returns the confirmation signal to the virtual machine to ensure that the virtual machine knows whether the connection is successfully established. After confirming that the connection is established, the virtual machine is allowed to exchange data with the target USB device through the USB device virtual instance, so that the virtual machine can use the USB device normally.
[0048] The method provided in the embodiments of the present application is described in detail below with reference to the accompanying drawings.
[0049] Figure 2 The system architecture provided by the embodiment of the present application is shown, which represents the connection and isolation between multiple virtual machines (VM1 and VM2) and multiple physical USB devices (device 1 to device n) in a virtualized environment through USB virtualization technology. The whole system consists of the following main parts: 1. Virtual machines (VM1 and VM2): Each virtual machine is connected to the host machine through a USB interface, and each virtual machine has an emulated USB controller (Emulate USB Controller) and an emulated USB device (Emulate USB Device). Emulated devices are distinguished from different virtual machines by adding ID tags.
[0050] 2. Emulated USB controllers and devices: Inside each virtual machine, the simulated USB controller is connected to the simulated USB device (Emulate USBDevice). These simulated devices are distinguished from different virtual machines by adding ID tags (Add ID tags). Inside each virtual machine, the host machine's Hypervisor provides a virtual USB controller. This virtual controller looks no different from the real USB controller to the virtual machine. Under the virtual controller, simulated USB devices are provided, and USB devices are virtualized into ports. In this way, even if the physical USB device is not connected, the virtual machine can recognize these ports.
[0051] 3. Back-end Driver: Each emulated USB device is connected to a backend driver that is responsible for sending data packets to the actual USB bus.
[0052] Through the back-end driver, the data packet with the ID mark is sent to the actual USB bus.
[0053] 4. USB bus driver: The USB bus driver on the host is responsible for managing data transmission on the USB bus.
[0054] 5. USB Hub: A USB Hub is a hardware device that expands the number of USB interfaces so that multiple USB devices can be connected to a computer or other host system at the same time. The USB Hub connects to the host through a USB interface and then provides multiple USB interfaces for other devices to use. The USB Hub is a key component for connecting physical USB devices. It communicates with the host and physical devices through a high-speed bus (USB) and sideband signals (sideband control bus).
[0055] The USB Hub communicates with the host and physical devices through two types of buses: a high-speed bus is used to transmit USB data packet information, that is, actual data information. A sideband control bus is used to transmit control information, such as setting the ID information of each physical port of the USB Hub. This bus is only used to transmit control information and is a low-speed bus. In the embodiment of this application, an I2C bus is used.
[0056] In the USB Hub, the USB data packets transmitted through the high-speed bus are parsed. Based on the ID information carried in the data packets, the USB Hub decides whether to allow these data packets to pass through the corresponding USB interface. This is a key step in implementing virtual machine access control to physical USB devices.
[0057] It should be noted that the USB Hub here is not a standard USB Hub, but a custom dedicated Hub implemented through the USB PHY physical layer interface of ULPI (USB Link Power Management Interface) connected to FPGA (Field Programmable Gate Array). In the implementation of this application, the USB3340 chip is used as the USB PHY. This custom USB Hub receives ID control signals from the host through the sideband control bus (such as I2C bus). These signals are used to set the ID information of each physical port of the USB Hub, thereby controlling which data packets can pass.
[0058] 6. ID filter: There is an ID filter in front of each physical USB device, which is used to decide whether to allow the USB data packet to pass through the corresponding USB interface based on the ID information carried by the data packet.
[0059] In order to achieve resource isolation, the ports of devices belonging to a certain virtual machine are marked with ID tags. These ID tags are used to distinguish data packets from different virtual machines.
[0060] Through the above steps, the technical solution realizes that in a virtualized environment, physical USB devices are effectively isolated and allocated to different virtual machines through USB virtualization technology, while ensuring the security and isolation of data transmission.
[0061] In traditional USB virtualization methods, virtual machines can only recognize and access physical USB devices after they are actually connected to the USB port, which may cause access delays, especially in scenarios where fast access is required. With the pre-allocation capability, the host can allocate USB ports to specific virtual machines before the physical device is connected, thereby achieving instant recognition and access by the virtual machine after the device is connected. This mechanism allows system administrators to plan and allocate USB ports in advance according to the needs of the virtual machines and the expected device connections, optimizing the use of USB resources.
[0062] In addition, the host uses a sideband control bus (such as the I2C bus) to dynamically set the ID information of each physical port in the USB hub and pre-assign these ports to specific virtual machines. This pre-allocation capability not only allows virtual machines to access physical devices immediately after they are connected, but also provides flexibility that traditional USB virtualization methods do not have. The use of the sideband control bus provides the host with flexible control over the ownership of USB devices, including pre-allocating USB ports and dynamically adjusting port allocations, which are control operations that are not included in the USB data bus because it is mainly used for data transmission rather than device control. In this way, the system can manage USB device resources more efficiently and improve the performance and responsiveness of the virtualized environment.
[0063] Compared with the prior art, the present invention only needs to modify the virtual USB driver part of the host machine, and does not need to modify the implementation of the client (virtual machine). This greatly simplifies the implementation process and improves the flexibility and scalability of the system. The steps for implementing the virtual USB device connection are as follows: Step 1: Simulation of virtual USB controller and device: In each virtual machine, the Hypervisor provides a virtual USB controller and simulates USB devices under the controller, virtualizing the USB devices into ports. This creates a virtual USB environment inside the virtual machine, allowing the virtual machine to access the simulated USB devices as if they were real USB devices. This step provides the necessary environment for the subsequent ID tag addition and data packet sending.
[0064] Step 2: Implement resource isolation: In order to achieve resource isolation, the ports of devices belonging to a certain virtual machine are marked with ID tags. These ID tags are used to distinguish data packets from different virtual machines, which is the key to achieving device isolation and access control, and provides identification basis for the ID filter in the subsequent USB Hub. By marking the USB device port of each virtual machine with a unique ID tag, the isolation of USB devices between different virtual machines is achieved.
[0065] Step 3: Send data packets through the backend driver: The data packet with the ID mark is sent to the actual USB bus through the back-end driver. The sending of the data packet is the bridge connecting the virtual machine and the physical device. It connects the simulated device inside the virtual machine with the physical device to realize the data transmission between the virtual machine and the physical USB device.
[0066] Step 4: Implementation of custom USB Hub: A custom dedicated Hub is implemented by connecting FPGA to ULPI's USB PHY. The Hub has a high-speed bus and a sideband control bus for transmitting USB data packets and setting the ID information of the physical port. The custom USB Hub is the core component for implementing device isolation and access control. It determines the forwarding of data packets based on the ID flag.
[0067] Step 5: ID filter settings: The USB Hub parses the incoming USB data packets and uses the ID filter to determine whether to allow the USB data packets to pass through the corresponding USB interface based on the ID information carried in the data packets. The ID filter ensures that only authorized virtual machines can access specific USB devices.
[0068] Step 6: Use of Sideband Control Bus: The ID information of each physical port of the USB Hub is set through the sideband control bus (such as the I2C bus) to achieve access control to the USB device. The sideband control bus is used to transmit control signals and set ID filters to control which data packets can be forwarded to specific USB devices.
[0069] Step 7: Communication between host and USB Hub: The host writes ID control signals to the USB Hub through the I2C bus to control the behavior of the USB Hub. The host sends control signals, and the USB Hub sets the port ID information according to these signals. Data packets are correctly forwarded or discarded according to the ID information, ensuring that the virtual machine's access to the USB device is controlled, thereby improving the security and isolation of the system.
[0070] The difference between this mechanism and the existing technology is that it only needs to modify the virtual USB driver part of the host machine, without modifying the implementation of the virtual machine, thus simplifying the deployment and maintenance of the system. Through the collaborative work of these steps, the solution realizes the isolation and access control of USB devices in a virtualized environment, meeting the needs of different application scenarios. Application scenarios include but are not limited to: Cloud computing platform: In the virtualized environment of a cloud service provider, physical USB devices (such as storage devices, network devices, etc.) need to be allocated to different virtual machines for use.
[0071] Enterprise data center: In the virtualized environment of an enterprise data center, fine-grained access control of USB devices is required to improve data security.
[0072] Embedded system development: During embedded system development, it is necessary to simulate the behavior of USB devices in a virtual machine to perform system testing and debugging.
[0073] Internet of Things (IoT) devices: In IoT devices, access control to multiple USB devices needs to be implemented through virtualization technology to improve the flexibility and scalability of the devices.
[0074] In summary, an embodiment of the present application provides a virtual USB device connection method, in response to a connection instruction of a target USB device, a virtual machine creates a corresponding USB device virtual instance for the target USB device through a virtual USB controller and generates a connection data packet, the connection data packet carries a USB device virtual instance identifier; the connection data packet is forwarded to a USB hub through a back-end driver, so that the USB hub controls the connection of the target USB device according to the USB device virtual instance identifier. Through virtualization technology, multiple virtual machines can share the same physical USB device, improving the utilization rate of USB devices. By assigning a unique identifier to each virtual USB device instance, it is ensured that USB device access between different virtual machines is isolated to prevent data leakage and unauthorized access. Allowing a virtual machine to access a physical USB device through a virtual USB controller enables the virtual machine to access the USB device as if it were a local device.
[0075] Based on the same technical concept, the embodiment of the present application also provides a virtual USB device connection system, such as Figure 3 As shown, the system comprises: The virtual module 301 is used for responding to the connection instruction of the target USB device, and the virtual machine creates a corresponding USB device virtual instance for the target USB device through the virtual USB controller and generates a connection data packet, wherein the connection data packet carries the USB device virtual instance identifier; The connection module 302 is used to forward the connection data packet to the USB hub through the back-end driver, so that the USB hub controls the connection of the target USB device according to the USB device virtual instance identifier.
[0076] The present application also provides an electronic device corresponding to the method provided in the above embodiment. Figure 4 , which shows an electronic device diagram provided by some embodiments of the present application. The electronic device 20 may include: a processor 200, a memory 201, a bus 202 and a communication interface 203, wherein the processor 200, the communication interface 203 and the memory 201 are connected via the bus 202; the memory 201 stores a computer program that can be run on the processor 200, and the processor 200 executes the method provided by any of the aforementioned embodiments of the present application when running the computer program.
[0077] The memory 201 may include a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk memory. The communication connection between the system network element and at least one other network element is realized through at least one physical port (which may be wired or wireless), and the Internet, wide area network, local area network, metropolitan area network, etc. may be used.
[0078] The bus 202 may be an ISA bus, a PCI bus, or an EISA bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. The memory 201 is used to store programs, and the processor 200 executes the programs after receiving execution instructions. The method disclosed in any implementation of the aforementioned embodiment of the present application may be applied to the processor 200, or implemented by the processor 200.
[0079] The processor 200 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the processor 200. The above processor 200 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a readily available programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiments of the present application can be directly embodied as a hardware decoding processor to be executed, or the hardware and software modules in the decoding processor can be executed. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 201, and the processor 200 reads the information in the memory 201 and completes the steps of the above method in combination with its hardware.
[0080] The electronic device provided in the embodiment of the present application and the method provided in the embodiment of the present application are based on the same inventive concept and have the same beneficial effects as the method adopted, operated or implemented by them.
[0081] The present application also provides a computer-readable storage medium corresponding to the method provided in the above embodiment. Figure 5 The computer-readable storage medium shown is a CD 30 on which a computer program (ie, a program product) is stored. When the computer program is run by a processor, the method provided in any of the aforementioned embodiments is executed.
[0082] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical or magnetic storage media, which are not listed here one by one.
[0083] The computer-readable storage medium provided in the above-mentioned embodiments of the present application and the method provided in the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the method adopted, run or implemented by the application program stored therein.
[0084] It should be noted that the above embodiments illustrate the present application rather than limit the present application, and that those skilled in the art may design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference symbol between brackets should not be constructed as a limitation to the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "one" or "an" preceding an element does not exclude the presence of multiple such elements. The present application may be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In a unit claim that lists several devices, several of these devices may be embodied by the same hardware item. The use of the words first, second, and third, etc. does not indicate any order. These words may be interpreted as names.
[0085] The above is only a preferred specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed in the present application should be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be based on the protection scope of the claims.
[0086] The above description is only a preferred embodiment of the present invention, and does not limit the patent scope of the present invention. All equivalent structural changes made by using the contents of the present invention specification and drawings under the concept of the present invention, or directly / indirectly applied in other related technical fields are included in the patent protection scope of the present invention.
Claims
1. A virtual USB device connection method, characterized in that: The method comprises: In response to the connection instruction of the target USB device, the virtual machine creates a corresponding USB device virtual instance for the target USB device through a virtual USB controller and generates a connection data packet, wherein the connection data packet carries a USB device virtual instance identifier; The connection data packet is forwarded to the USB hub through a back-end driver, so that the USB hub controls the connection of the target USB device according to the USB device virtual instance identifier.
2. The method according to claim 1, characterized in that The virtual machine creates a corresponding USB device virtual instance for the target USB device through a virtual USB controller and generates a connection data packet, including: The virtual machine creates a corresponding USB device virtual instance according to the attribute configuration of the target USB device through a virtual USB controller, and allocates a unique USB device virtual instance identifier to the USB device virtual instance; A corresponding connection data packet is generated according to the USB device virtual instance, wherein the connection data packet includes the USB device virtual instance identifier and a connection instruction of the target USB device.
3. The method according to claim 1, characterized in that Before responding to the connection instruction of the target USB device, the method further includes: A port control signal is sent to the USB hub via a sideband control bus to set or change identification information of several physical ports connected to the USB hub.
4. The method according to claim 3, characterized in that The USB hub controls the connection of the target USB device according to the USB device virtual instance identifier, including: The USB hub determines whether the USB device virtual instance identifier matches according to a preconfigured identifier filter rule, wherein the identifier filter rule represents a mapping relationship between the USB device virtual instance identifier, the corresponding virtual machine, and the identifier information of the physical port; If the USB device virtual instance identifier matches successfully, the corresponding physical port is controlled to be mapped to the corresponding virtual port to achieve the connection of the target USB device; if the match fails, the USB hub discards the connection data packet.
5. The method according to claim 4, characterized in that The USB hub determines whether the USB device virtual instance identifier matches according to a pre-configured identifier filter rule, including: The USB hub determines a requesting virtual machine for connection according to the USB device virtual instance identifier; Searching the identification information of the physical port for a list of virtual machines that are allowed to establish a connection; The list of virtual machines allowed to establish a connection is searched to see whether there is the requested virtual machine; if so, the match is successful; if not, the match fails.
6. The method according to claim 1, characterized in that Forwarding the connection data packet to the USB hub via a back-end driver includes: The virtual machine sends the connection data packet to the back-end driver, so that the back-end driver verifies the validity of the connection data packet; If the verification is successful, the connection data packet is sent to the corresponding USB bus driver, so that the USB bus driver forwards the connection data packet to the USB hub.
7. The method according to any one of claims 4 or 6, characterized in that: After controlling the corresponding physical port to be mapped to the corresponding virtual port to achieve the connection of the target USB device, the method further includes: The USB hub sends a connection confirmation signal to the USB bus driver, so that the USB bus driver forwards the connection confirmation signal to the back-end driver; The back-end driver returns the connection confirmation signal to the corresponding virtual machine, so that the virtual machine exchanges data with the target USB device through the USB device virtual instance.
8. A virtual USB device connection system, characterized in that: The system comprises: A virtual module, configured to respond to a connection instruction of a target USB device, and the virtual machine creates a corresponding USB device virtual instance for the target USB device through a virtual USB controller and generates a connection data packet, wherein the connection data packet carries a USB device virtual instance identifier; The connection module is used to forward the connection data packet to the USB hub through the back-end driver, so that the USB hub controls the connection of the target USB device according to the USB device virtual instance identifier.
9. An electronic device, comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: Computer-readable instructions are stored thereon, and the computer-readable instructions can be executed by a processor to implement the method according to any one of claims 1-7.
Citation Information
Patent Citations
USB device sharing method and system based on virtualization
CN116955236A
Storage equipment control method and device, electronic equipment and storage medium
CN117608757A
A system and method for setting virtual machines in a virtual server supporting zero clients
KR101239290B1
System and method for replay of peripheral device attacks
US12242397B1
Method and system for device address translation for virtualization
US20070043928A1
Cited By
Security isolation system for USB (Universal Serial Bus) mass storage equipment and use method of security isolation system
CN121051809A
Method for supporting read-only of high-speed USB storage device based on SPICE protocol
CN121957723A