Peripheral para-virtualization system and device and storage medium

By setting up shared memory and message queues in the virtual machine manager, communication between multiple virtual machines and peripherals are realized, and the problems of code complexity and security risks of virtual machine managers in the prior art are solved.

CN120066672APending Publication Date: 2025-05-30RESIDE (SHANGHAI) INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411958013.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing peripheral paravirtualization technology increases code scale and complexity in the virtual machine manager, increasing the system's functional security and information security risks.

Method used

By setting up shared memory in the virtual machine manager, multiple virtual machines are allowed to access the same piece of memory at the same time and send and receive data through message queues, realizing communication between virtual machines and semi-virtualization of peripherals.

Benefits of technology

The peripherals are realized, the complexity of the virtual machine manager is reduced, and the information security risks of the system are reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120066672A_ABST
    Figure CN120066672A_ABST
Patent Text Reader

Abstract

The invention provides a peripheral para-virtualization system. The peripheral para-virtualization system comprises a first virtual machine, a second virtual machine and a virtual machine manager, a shared memory is arranged in a virtual machine manager, the shared memory communicates with a first virtual machine and a second virtual machine, and one shared memory is configured among a plurality of virtual machines, so that the plurality of virtual machines can access the same memory at the same time, interrupt is sent among the virtual machines, and the interrupt is used for notification. Complicated modules and programs in the virtual machine manager do not need to participate, and possible information security risks of the system are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of embedded virtualization, and in particular relates to a peripheral semi-virtualization system, device and storage medium. Background Art

[0002] Peripheral Para-Virtualization is a virtualization technology that allows virtual machines to efficiently access and utilize these devices by modifying client virtual machines, which can significantly improve the performance of virtual machines. Especially in application scenarios such as high-performance computing, GPU virtualization, and network virtualization, peripheral para-virtualization provides higher performance than full virtualization.

[0003] In the current processing method of peripheral paravirtualization, the virtual machine manager (such as KVM, Xen, etc.) plays a core management and scheduling role, responsible for coordinating and controlling the interaction between the virtual machine and the physical hardware.

[0004] The process implemented in the virtual machine manager involves a variety of key technologies related to virtualization, hardware abstraction and performance optimization. The implementation process relies on hardware-supported IOMMU and VT-d technologies, combined with key technologies such as VFIO, QEMU / KVM, SR-IOV, and DMA isolation. The above technologies all require complex operation processes in the virtual machine manager, which invisibly increases the code size and complexity of the virtual machine manager. For the embedded virtualization field, due to the requirements of functional safety and information security, increasing the code size and complexity of the virtual machine manager will increase the functional safety and information security risks of the system.

[0005] Therefore, a method is needed to implement the peripheral paravirtualization backend without increasing the size and complexity of the virtual machine manager code. Summary of the invention

[0006] In order to solve the above technical problems, the present invention provides a peripheral semi-virtualization system, device and storage medium.

[0007] The present invention is achieved through the following technical solutions.

[0008] The invention provides a peripheral semi-virtualization system, comprising a first virtual machine, a second virtual machine and a virtual machine manager, wherein a shared memory is arranged in the virtual machine manager, and the shared memory communicates with the first virtual machine and the second virtual machine respectively.

[0009] Further, a virtual peripheral, a virtual network, a para-virtualized peripheral backend service program, a virtual network, and a first virtual memory are provided in the first virtual machine. The first virtual memory communicates with the shared memory, and the first virtual memory communicates with the virtual network, the para-virtualized peripheral backend service program, the virtual network, and the virtual peripheral in sequence.

[0010] Further, a physical peripheral is also provided in the virtual machine manager, and the first virtual peripheral communicates with the physical peripheral.

[0011] Further, a second virtual memory, a para-virtualized peripheral front-end driver, and an application program are provided in the second virtual machine. The second virtual memory communicates with the shared memory, and the second virtual memory communicates with the para-virtualized peripheral front-end driver and the application program in sequence.

[0012] Further, a message queue is set in the shared memory. The shared memory is configured by the user, allocated by the virtual machine manager, mapped from the kernel space to the user space by the para-virtualized front-end and back-end drivers of the peripheral, and the message queue is established and used by the para-virtualized peripheral backend service program and application 1.

[0013] Further, the first virtual memory and the second virtual memory perform data transmission and reception through the message queue in the shared memory, and the message queue stores communication messages between virtual machines.

[0014] Further, the first virtual memory communicates with the virtual network, the para-virtualized peripheral backend service program, the virtual network, and the virtual peripheral by sending and receiving IO requests.

[0015] Further, the second virtual memory communicates with the para-virtualized peripheral front-end driver and the application program by sending and receiving IO requests.

[0016] The present invention also provides a para-virtualized peripheral device, including a processor and an interface circuit. The interface circuit is used to receive signals from other devices outside the device that executes the kernel state command and transmit them to the processor, or send signals from the processor to other devices outside the device that executes the kernel state command.

[0017] The beneficial effects of the present invention are as follows: A shared memory is configured between multiple virtual machines, enabling multiple virtual machines to simultaneously access the same piece of memory, send interrupts to each other, and use interrupts for notification. The para-virtualized front-end and back-end of the peripheral send and receive IO requests through a transceiver queue, thereby realizing the para-virtualization of the peripheral. At the same time, it does not require the participation of complex modules and programs in the virtual machine manager, reducing the potential information security risks of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 It is a schematic diagram of the module connection relationship in the system of the embodiment of the present invention. Detailed implementation mode

[0019] The technical solution of the present invention will be further described below, but the scope of protection claimed is not limited thereto.

[0020] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments.

[0021] Industrial embedded device A is selected. Device A has only one physical network interface (the virtual machine 101 communicates with the external network through the only physical network interface). The virtual machine 101 and the virtual machine 102 are simultaneously running on device A. The virtual machine 101 is provided with a virtual memory 201, a virtual network, a para-virtualized peripheral backend service program, a para-virtualized backend driver, and a network card driver. At the same time, the application program 2 is set in the virtual machine 101. The virtual machine 102 is provided with a virtual memory 202 and a para-virtualized peripheral front-end driver, and the application program 1 is set in the virtual machine 102. The virtual machine manager 301 is provided with a shared memory 401. Among them, the Linux system runs in the virtual machine 101, and the RTOS system runs in the virtual machine 102. The data transfer method between the application program 1 and the application program 2: The application program 1 sends the data to the para-virtualized peripheral front-end driver. After parsing the data, the para-virtualized peripheral front-end driver sends the data to the virtual memory 2. The virtual memory 2 directly sends the data to the shared memory 401. The shared memory 401 is a part of the memory partition of the virtual machine manager 301. In this embodiment, the shared memory 401 is used to receive and send the data transferred between the virtual memory 1 and the virtual memory 2. After receiving the data sent by the virtual memory 2, the shared memory 401 performs the reception and transmission of the IO requests through the reception and transmission queue, transfers the data to the virtual memory 1. The virtual memory 1 transfers the data between the virtual network and the para-virtualized peripheral backend service program through the internal Ethernet data packet in the virtual machine 101, and then transfers it to the network card driver, and sends it to the physical network card through the network card driver. The physical network card then communicates with the external network to complete the entire system working process of the data transmission of the para-virtualized peripheral and the communication between virtual machines.

[0022] The above embodiments are the preferred solutions for the implementation of the present invention. It should be noted that, without departing from the concept of the present invention, any obvious replacement and minor changes are within the protection scope of the present invention.

Claims

1. A peripheral paravirtualization system, comprising a first virtual machine, a second virtual machine and a virtual machine manager, characterized in that: A shared memory is set in the virtual machine manager, and the shared memory communicates with the first virtual machine and the second virtual machine respectively.

2. The peripheral paravirtualization system according to claim 1, wherein: The first virtual machine is provided with virtual peripherals, a virtual network, a semi-virtualized peripheral backend service program, a virtual network and a first virtual memory. The first virtual memory and the shared memory communicate with each other, and the first virtual memory communicates with the virtual network, the semi-virtualized peripheral backend service program, the virtual network and the virtual peripherals in sequence.

3. The peripheral paravirtualization system according to claim 2, characterized in that: The virtual machine manager is also provided with a physical peripheral, and the first virtual peripheral communicates with the physical peripheral.

4. The peripheral paravirtualization system according to claim 1, wherein: The second virtual machine is provided with a second virtual memory, a paravirtualized peripheral front-end driver and an application program. The second virtual memory and the shared memory communicate with each other, and the second virtual memory communicates with the paravirtualized peripheral front-end driver and the application program in sequence.

5. The peripheral paravirtualization system according to claim 1, wherein: Setting up a message queue in shared memory involves: The shared memory is configured by the user and allocated by the virtual machine manager; The paravirtualized peripheral front end and the virtual network are mapped from the kernel space to the user space, and the paravirtualized peripheral back end service program and the application 1 establish and use the message queue.

6. The peripheral paravirtualization system according to claim 1 or 5, characterized in that: The first virtual memory and the second virtual memory send and receive data through a message queue in the shared memory, and the message queue stores communication messages between virtual machines.

7. The peripheral paravirtualization system according to claim 1, wherein: The first virtual memory communicates with the virtual network, the paravirtualized peripheral backend service program, the virtual network, and the virtual peripheral by sending and receiving I / O requests.

8. The peripheral paravirtualization system according to claim 1, wherein: The second virtual memory communicates with the paravirtualized peripheral front-end driver and the application program by sending and receiving I / O requests.

9. A peripheral semi-virtualization device, comprising a module for executing the system according to any one of claims 1 to 8, characterized in that: It includes a processor and an interface circuit, wherein the interface circuit is used to receive signals from other devices other than the device for executing kernel mode commands and transmit them to the processor or send signals from the processor to other devices other than the device for executing kernel mode commands, and the processor is used to implement the system as described in any one of claims 1-8 through logic circuits or execution code instructions.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the system according to any one of claims 1 to 8 is implemented.