Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

423 results about "Hypervisor" patented technology

A hypervisor or virtual machine monitor (VMM) is a computer software, firmware or hardware that creates and runs virtual machines. A computer on which a hypervisor runs one or more virtual machines is called a host machine, and each virtual machine is called a guest machine. The hypervisor presents the guest operating systems with a virtual operating platform and manages the execution of the guest operating systems. Multiple instances of a variety of operating systems may share the virtualized hardware resources: for example, Linux, Windows, and macOS instances can all run on a single physical x86 machine. This contrasts with operating-system-level virtualization, where all instances (usually called containers) must share a single kernel, though the guest operating systems can differ in user space, such as different Linux distributions with the same kernel.

Communication method for user program and virtual machine on microkernel Hypervisor

The invention discloses a method for communication between a user program and a virtual machine on a microkernel Hypervisor, the microkernel Hypervisor is provided with two shared memory areas, the shared memory area 1 is accessed by the user program and a root service Rootserver, the shared memory area 2 is accessed by the Rootserver and the virtual machine, the user program writes communication request data with the virtual machine into the shared memory area 1, and the user program writes communication request data with the virtual machine into the shared memory area 2. The method comprises the following steps that a VMM sub-thread is used as a shared memory area 1, a Rootserver is notified through inter-process communication, the Rootserver reads communication request data from the shared memory area 1, the communication request data is written into a shared memory area 2 after being analyzed by the VMM sub-thread, a system calls a syscale to transmit a communication request to a kernel, the kernel injects virtual interrupt into a virtual machine, and the virtual machine sends the communication request to the Rootserver. And an interrupt processing program of the virtual machine processes the communication request and writes a processing result into the shared memory area 2, then the processing result is returned to the Hypervisor through the Hypercall, and a Rootserver of the Hypervisor feeds back the processing result to a user program through the IPC. The method is designed for the microkernel Hypervisor environment, and the overall performance and efficiency of the embedded virtualization system are improved.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Methods and systems for dynamically optimizing and modifying allocation of virtual resources to processes

A method for dynamically optimizing and modifying allocation of virtual resources to processes includes allocating, by a first hypervisor, a first amount of a first virtual resource to a process executing in a virtual machine on a first machine. An agent, in communication with a resource allocation process executing in the virtual machine, determines a second amount of the first virtual resource to be utilized by the process. A scheduler receives an identification of the determined second amount and directs migration of the process to a second machine. A second hypervisor executing on the second machine allocates a third amount of the first virtual resource, the third amount substantially similar to the second amount. The method includes communicating, by the resource allocation process, to the process, that the first amount of the first virtual resource is allocated to the at least one process.
Owner:EXOSTELLAR INC

Hybrid key task scheduling method, system and equipment based on virtualization technology

The invention relates to the technical field of vehicle-mounted intelligent computing, in particular to a hybrid key task scheduling method, system and equipment based on a virtualization technology. The method comprises the following steps: firstly, carrying out hybrid criticality grading on vehicle-mounted intelligent cabin tasks, and establishing a priority table; then, creating a dynamic resource partition based on a QNX Hypervisor platform, monitoring a system load state in real time through a hardware performance counter, and predicting a computing power demand of a large model; dynamically calculating an allocation scheme in combination with the task criticality level and the system energy efficiency state; then determining an optimal calculation unit selection strategy and a model precision grade by adopting an energy consumption-time delay joint optimization model; and finally, executing encrypted storage and integrity verification of large model parameters in a trusted environment, and completing end-side deployment and security verification. According to the method, the dynamic resource scheduling of the mixed key task is realized, the resource utilization rate is improved, the real-time requirement of the safety key task is ensured, and the dynamic balance between the performance and the energy efficiency is realized.
Owner:SHENZHEN ZHONGHONG TECH

ARMv8-based virtual machine interrupt straight-through routing method

The invention discloses an ARMv8-based virtual machine interrupt through routing method, which comprises the following steps that: a Hypervisor directly routes a physical interrupt to an EL1 through configuration, sets a top page table address of a vCPU (Virtual Central Processing Unit) and a Hypervisor control register at the same time, and sets a vcpudid flag bit for indicating whether the vCPU adopts a virtual interrupt injection mechanism or a physical interrupt through routing mechanism; and judging whether an interrupt through routing condition is met or not so as to determine whether an interrupt through routing mechanism or a virtual interrupt injection mechanism is adopted, periodically judging whether a switching condition is met or not when the interrupt through routing mechanism is adopted, and switching from the interrupt through routing mechanism to the virtual interrupt injection mechanism if the switching condition is met. The method is compatible with two interrupt controller specifications of GICv2 and GICv3, supports the virtual machine and the hypervisor to respectively and independently respond to respective corresponding interrupt requests, and meanwhile, the method has the capability of dynamically switching an interrupt routing mechanism during the system operation period, so that the flexibility of interrupt processing and the expandability of the system are improved.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Firmware partitioning for GPU via virtual SoC

The invention relates to firmware partitioning for a GPU via a virtual SOC. One embodiment provides a graphics processor, the graphics processor comprising: an interpolator comprising a plurality of core grain sockets; a plurality of core particles coupled with the plurality of core particle sockets; and circuitry configured to provide a firmware super supervisor for causing the processing resources of the plurality of core particles to be dynamically divided into a plurality of partitions.
Owner:INTEL CORP

System startup memory detection method and device, equipment and storage medium

The embodiment of the invention discloses a system startup memory detection method and device, equipment and a storage medium, and the method comprises the steps: calculating the maximum value of a Hypervisor early virtual address mapping range according to the initial address of Hypervisor operation before a final page table takes effect; when the dynamic allocation pool is utilized to allocate the memory page, determining a virtual address range of the allocated memory page by utilizing a base address of the allocated memory page, and detecting whether the virtual address range of the allocated memory page exceeds a maximum value of a Hypervisor early virtual address mapping range or not; and when the maximum value of the Hypervisor early virtual address mapping range is exceeded, outputting an error prompt, and returning a memory error. Compared with a traditional estimation mode, the probability that estimation is inaccurate due to the fact that dynamic allocation changes is reduced, the memory errors can be accurately detected in advance before the system crashes, and a developer can conveniently locate the reason of crashes.
Owner:KYLIN CORP

Hardware apparatus for isolated virtual environments

A hardware apparatus for isolated virtual environments includes graphics processing unit comprising a first dedicated memory and a first plurality of processing cores, a central processing unit comprising a second dedicated memory and a second plurality of processing cores, a field programmable gate array comprising a third dedicated memory, a control and data bus assembly connecting the field programmable gate array, the central processing unit, and the graphics processing unit, and a hypervisor located on a non-volatile memory of the hardware apparatus, the hypervisor configured to create one or more virtual machines by isolating the graphics processing unit, the central processing unit and the field programmable gate array.
Owner:PARRY LABS LLC

Firmware partitioning for a GPU via a virtual SOC GPU

One embodiment provides a graphics processor comprising an interposer including a plurality of chiplet sockets, a plurality of chiplets coupled with the plurality of chiplet sockets, and circuitry configured to provide a firmware hypervisor to enable dynamic partitioning of processing resources of the plurality of chiplets into a plurality of partitions.
Owner:INTEL CORP

Signal processing device, and vehicle display device comprising same

A signal processing device and a vehicle display device comprising same, according to an embodiment of the present disclosure, comprise a processor for executing a hypervisor, wherein the processor: executes, on the hypervisor, a recognition service for performing recognition on the basis of sensor data and a safety monitor service for monitoring the recognition service; and performs a recovery mode by using a redundant recognition service when the recognition service is executed. Accordingly, the stability of the recognition service can be improved.
Owner:LG ELECTRONICS INC

Runtime memory repair without requiring a reboot of a server computer

A host server computer with an uncorrectable memory error can be repaired without a reboot operation. While initially booting a hypervisor, a special software Application Programming Interface (API) can be loaded between a BIOS System Management Mode (SMM) code and the hypervisor. Once the host server computer is booted and a number of virtual machines are executing, a memory error (e.g., uncorrectable error correction code (UECC)) can occur. In response, the hypervisor calls into the special software API identifying the defective memory rows that the BIOS needs to repair. The BIOS starts a soft Post Package Repair (PPR) process on those rows and gives back control to the hypervisor. When the repair is completed, the hypervisor loads a scrubbing virtual machine and validates that the memory is corrected. After the repair is validated, the hypervisor allows the available partition to take a new customer instance.
Owner:AMAZON TECH INC

Signal processing device and vehicle display device comprising same

The signal processing device and the vehicle display apparatus including the same according to an embodiment of the present disclosure includes a processor to process a vehicle signal, wherein the processor is configured to execute a server virtual machine and a plurality of guest virtual machines on a hypervisor in the processor, wherein the server virtual machine is configured to transmit processed camera data to a shared memory, a second guest virtual machine is configured to receive the camera data from the shared memory, to generate first data for a first application service based on the camera data and to transmit the first data to the shared memory, and a first guest virtual machine is configured to display an image, synthesized based on the camera data from the shared memory and the first data, on the first display. Accordingly, data processing may be performed efficiently.
Owner:LG ELECTRONICS INC

Jailhouse inter-partition communication method

The invention discloses a method for communication between jailhome partitions. The method comprises the following steps: configuring a jailhome cell configuration file according to hardware platform resources and task requirements in a cell; compiling and operating jailhouse, starting an inmate cell, and completing registration of a destination port and a source port and memory mapping of an FIFO annular buffer area; sending data to the virtual PCI device through a source port, filling in a Doorbell register after data sending is completed, and sending an interrupt signal to a destination port through a Hypervisor; reading data from the virtual PCI device through the destination port; and after the application program of the destination port receives the data, executing the predefined task. According to the method, the controllability, verifiability and adaptation flexibility of communication behaviors are enhanced, and the method is suitable for safety key scenes with strict requirements for high-frequency, small-data-volume, low-delay and deterministic communication.
Owner:KYLIN CORP

Signal processing device and vehicle display device comprising same

The signal processing device and the vehicle display apparatus including the same according to an embodiment of the present disclosure includes a processor to process a vehicle signal, wherein the processor is configured to execute a server virtual machine and a plurality of guest virtual machines on a hypervisor in the processor, wherein the server virtual machine is configured to transmit processed camera data to a shared memory, a second guest virtual machine is configured to receive the camera data from the shared memory, to generate first data for a first application service based on the camera data and to transmit the first data to the shared memory, and a first guest virtual machine is configured to display an image, synthesized based on the camera data from the shared memory and the first data, on the first display. Accordingly, data processing may be performed efficiently.
Owner:LG ELECTRONICS INC

ARM processor-oriented microkernel operating system confidential computing environment construction method

The invention relates to an operating system environment construction technology, and discloses an ARM (Advanced RISC Machines) processor-oriented micro-kernel operating system confidential computing environment construction method, which is characterized in that a hierarchical system architecture is constructed, a virtual machine monitor and a confidential domain management monitor are decoupled at an ARM exception level EL2, and the virtual machine monitor and the confidential domain management monitor run in mutually isolated address spaces. The RMM is used as an independent module for dynamic loading, a management mechanism of a confidential computing domain is specially used, and the Hypervisor is only responsible for strategy scheduling, so that the defect that the Hypervisor is bloated in function in a traditional scheme is overcome. According to the method, the RMM is loaded through the security startup process during startup, the confidential virtual machine is dynamically created during running, mirror image security verification, memory encryption and other mechanisms are integrated, and finally the security domain is destroyed after the application is finished. The method has the advantages that a flexible and safe confidential computing environment conforming to the minimum privilege principle is provided for the microkernel system, and the method is particularly suitable for embedded scenes with high safety requirements such as the Internet of Things and industrial control.
Owner:CHENGDU TIANRUAN TECHNOLOGY CO LTD

Secure and efficient access to host memory for guests

Secure and efficient access to host memory for guests is disclosed. For example, a system includes (i) a processor, (ii) a host memory, (iii) a hypervisor including a filesystem daemon, (iv) a guest including a storage controller, and (v) a first filesystem queue. The storage controller is configured to receive a file request, translate the file request, and add the translated file request to a filesystem queue. The filesystem daemon is configured to retrieve the translated file request from the filesystem queue and provide access to a file in the host memory identified in the file request to the guest.
Owner:RED HAT INC

Secure boot method, system and device for in-vehicle infotainment system, and medium and vehicle

A secure boot method, system and device for an in-vehicle infotainment system, and a medium and a vehicle, which improve the security of a vehicle startup process. The method comprises: when a microcontroller unit detects an in-vehicle infotainment system power-on signal, using a first preset encryption algorithm to verify an application program; and if the verification of the application program is successful, outputting an enable signal to initiate the boot of a system on chip (S100); the system on chip using a second preset encryption algorithm to verify a digital signature of the system on chip; and if the verification of the digital signature is successful, loading a bootloader (S200); once the bootloader starts successfully, launching a hypervisor and a kernel to boot the system on chip (S300); and once the system on chip is successfully booted, loading a file system to boot an in-vehicle infotainment system (S400). The present invention can improve the security of the vehicle startup process and can be widely applied in the technical field of automotive control.
Owner:CHINA FAW CO LTD

Confidential compute architecture for silicon initialization for IP protection and assurance

Embodiments are directed to utilizing a confidential compute architecture for silicon initialization for IP protection and assurance. An embodiment of a processing system includes a memory device communicably coupled to hardware components and to memory modules, the memory device to store platform initialization firmware to cause the processing system to execute a firmware hypervisor to initiate a trust domain (TD) of a confidential compute architecture, wherein the TD to provide confidentiality and integrity protection for data loaded in the TD; load IP firmware and an initial program loader (IPL) for the IP firmware in the TD, wherein the IP firmware corresponds to an IP component and is encrypted; obtain, by the IPL, an IP firmware key to decrypt the IP firmware in the TD; and execute an initialization process for the IP component using the decrypted IP firmware.
Owner:INTEL CORP

Live migration for confidential compute environments

Systems and methods are directed toward migration operations, such as live migration operations, associated with confidential computing environments. Responsive to a request to migrate data, a secure hypervisor may establish a secure communication channel to a network interface controller to pass one or more keys for accessing securely stored data. The secure hypervisor may generate a descriptor associated with a memory location of the data and then pass the descriptor to the network interface controller. As a result, encryption / decryption operations may be offloaded to the network interface controller, which may use the descriptor and key to migrate the data from a source location to a destination location.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Big language model parameter encryption protection method and system based on virtualization

The invention provides a virtualization-based big language model parameter encryption protection method and system, and the method comprises the steps: carrying out the corresponding preprocessing of a current to-be-protected big language model in a trusted environment, obtaining a modified linear operator parameter, and carrying out the encryption of a nonlinear operator; the non-trusted virtual machine is a main interface which can be accessed by a user, executes a reasoning task on the preprocessed large language model, and when operation of nonlinear operator encryption needs to be carried out, the non-trusted virtual machine is switched to the trusted virtual machine by calling the service of the virtual machine hypervisor, and the trusted virtual machine completes the operation of nonlinear operator encryption; and the trusted virtual machine processes the encryption operator operation unauthorized to be processed by the non-trusted virtual machine, and returns a result to the non-trusted virtual machine for next calculation of the non-trusted virtual machine. According to the method, mathematical characteristics of different operators of the model are identified, a mode of dynamically modifying the weight of the linear operator without influencing the output result of the model is provided, and safe and efficient operation of the linear operator is ensured.
Owner:SHANGHAI JIAOTONG UNIV

Hypervisor controller and method for assigning application identifier to specific application running on virtual machine

A hypervisor controller is configured to assign an application identifier to a specific application running on a virtual machine in response to a transfer of control from the virtual machine to the hypervisor. Moreover, the virtual machine runs a plurality of applications of which the specific application is one and the hypervisor controller is further configured to generate the application identifier based on one or more registers of an emulated processor of the virtual machine. Therefore, the hypervisor controller provides a robust, secure, and efficient framework for managing the plurality of applications that are executed on the virtual machine, contributing to a high-performance virtualized environment.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD +1

Remote secure boot verification service for secure deployment of virtual machines

Disclosed systems and methods for authenticating virtual machines, upon detecting a virtual machine launch (VML) request associated with a hypervisor and an unconfirmed VM, request a VM signing (VMS) certificate from a deployment / verification cloud server. The VMS certificate is forwarded to a certificate store of the hypervisor. After an unconfirmed VM is successfully authenticated, the VMS certificate may be deleted from the hypervisor certificate store. If an alert indicating a failed authentication associated is detected, termination operations are performed to prevent the unconfirmed VM from running under the hypervisor. The termination operations may include identifying a suspect key or signature associated with the unconfirmed VM and recording the suspect key or signature in a prohibited database store, such as a UEFI Secure Boot DBX variable store. For example, a suspect key or signature may be a key used to sign the unconfirmed VM.
Owner:DELL PROD LP

Hypervisor-based interception of memory and register accesses

A security agent configured to initiate a security agent component as a hypervisor for a computing device is described herein. The security agent component may then determine pages of the memory which include identified memory locations and set privilege attributes of those pages to prevent specific types of access to the memory locations, such as executing code stored at a memory location. Also, the security agent component may refrain from setting intercepts for pages including a whitelisted memory location. Further, the security agent component may set intercepts for debug registers, note read operations from the operating system for those registers, and respond with operating-system-permitted values. Additionally, the security agent component may set intercepts for instructions for performing write operations on control registers.
Owner:CROWDSTRIKE

Hyper visor-independent reference copies of virtual machine payload data

Hypervisor-independent reference copies of virtual machine payload data based on block-level pseudo-mount infrastructure and techniques are generated and stored in an illustrative data storage management system. An illustrative hypervisor-independent reference copy includes one or more virtual-machine payload data files that originated from a first virtual machine. The hypervisor-independent virtual-machine-payload reference copy is governed by a distinct reference copy policy that controls retention, storage, tiering, scheduling, etc. for the reference copy, independently of how the illustrative system treats other virtual machine payload data files originating from the same virtual machine.
Owner:COMMVAULT SYSTEMS INC

Coordinated container scheduling for improved resource allocation in virtual computing environment

The technology provides for allocating an available resource in a computing system by bidirectional communication between a hypervisor and a container scheduler in the computing system. The computing system for allocating resources includes one or more processors configured to receive a first scheduling request to initiate a first container on a first virtual machine having a set of resources. A first amount of resources is allocated from the set of resources to the first container on the first virtual machine in response to the first scheduling request. A hypervisor is notified in a host of the first amount of resources allocated to the first container. A second amount of resources from the set of resources is allocated to a second virtual machine in the host. A reduced amount of resources available in the set of resources is determined. A container scheduler is notified by the hypervisor for the reduced amount of resources of the set of resources available on the first virtual machine.
Owner:GOOGLE LLC

Virtualization-based security isolation management system

The invention relates to the technical field of computer security, in particular to a security isolation management system based on virtualization, which comprises a virtual machine intrusion behavior monitoring module, a Hypervisor monitoring system call frequency and a network connection request of a target virtual machine, and obtaining an intrusion behavior feature matching event. According to the method, the system calling frequency and the network connection request are monitored in real time when the target virtual machine runs, the intrusion behavior characteristics are captured, the targeted alarm instruction is generated, the memory of the target virtual machine is subjected to copy-on-write snapshot when the threat behavior is triggered, and the memory state at the intrusion moment is completely stored; establishing a new virtual processor context, and dynamically redirecting a network socket associated with an attack session to realize immediate isolation and transparent shunting of intrusion behaviors; and further, taking the data entering the memory as a taint source starting point, and tracking a flow path of a data taint among a register, a memory address and a process file handle.
Owner:DEEP THINKING COMPUTER (QINGDAO) CO LTD

Translation lookaside buffer (TLB) poisoning attacks on secure encrypted virtualization

TLB poisoning attacks take advantage of security issues of translation lookaside buffer (TLB) management on SEV processors in Secure Encrypted Virtualization (SEV) virtual machines (VMs). In various embodiments, a hypervisor may poison TLB entries between two processes of a SEV VM to compromise the integrity and confidentiality of the SEV VM. Variants of TLB poisoning attacks and end-to-end attacks are shown to be successful on both Advanced Micro Devices (AMD) SEV and SEV-Encrypted State (SEV-ES). Countermeasures for thwarting TLB poisoning attacks include hardware-enforced TLB flush processes and re-exec schemes that, among other things, prevent attackers from manipulating TLB entries and causing a privileged victim process to execute malicious code in an attempt to bypass a password authentication.
Owner:BAIDU USA LLC

Cryptographic security between containers and authenticated non-volatile memory

An exemplary system includes a computing device configured to host a hypervisor. The hypervisor is configured to create a first container configured to host a first application and is allocated a first location of the plurality of locations of the memory and a second container configured to host a second application and is allocated a second location of the plurality of locations of the memory. During boot of the first container, the first container is configured to generate a cryptographic key that is based on a measurement or characteristic of process code of the first container, a configuration parameter of the first container, or any combination thereof. During boot of the second container, the second container is configured to generate a cryptographic key that is based on a measurement or characteristic of process code of the second container, a configuration parameter of the second container, or any combination thereof.
Owner:MICRON TECHNOLOGY INC

Power management on a vehicle

A vehicle controller can include a hypervisor for controlling a power state of the vehicle controller, the vehicle controller comprising at least two virtual machines hosted on the vehicle controller. The hypervisor is configured to: receive an active status indication from at least one virtual machine; determine, in dependence on the active status indication, if at least one virtual machine is active; and inhibit a reduced power state of the vehicle controller if the hypervisor determines that at least one virtual machine is active.
Owner:JAGUAR LAND ROVER LTD

Electronic device for authentication using virtual machine and operation method thereof

A method for authentication using a virtual machine by an electronic device is provided. The method includes identifying, in a first virtual machine in which a host operating system (OS) is implemented, a user input for an application or data requiring authentication, in response to the user input, setting, by the first virtual machine through a hypervisor, a control authority for the application or the data to a second virtual machine in which a guest operating system (OS) is implemented, and performing, based on control of the second virtual machine, an external authentication procedure for the application or the data, wherein the hypervisor is a platform for concurrently executing the host OS and the guest OS on the electronic device.
Owner:SAMSUNG ELECTRONICS CO LTD