Patents by Inventor Amnon Ilan
Amnon Ilan has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12650868Abstract: System and method for running virtual machines within containers. An example method may include: running, by a host computer system, a hypervisor managing a first virtual machine implemented by a first container with a first set of resources, creating, by the hypervisor, a second container implementing the second virtual machine, wherein the second container is nested within the first container, determining, by the first virtual machine of the first container, one or more of the first set of resources to assign to the second container, and assigning, by the hypervisor, to the second container one or more of the first set of resources.Type: GrantFiled: August 3, 2021Date of Patent: June 9, 2026Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Patent number: 12609811Abstract: Systems and methods for securing assigned peripheral device in virtualized computer system. An example method may comprise receiving, by a virtualized execution environment, a state measurement associated with a peripheral device of the computing system. Generating a guest cryptographic key. Responsive to validating the state measurement, transmitting, to the peripheral device, the guest cryptographic key encrypted using the device cryptographic key. Transmitting, to the peripheral device, an access request that is cryptographically signed using a first value derived from the device cryptographic key or a second value derived from the guest cryptographic key and encrypted using a third value derived from the guest cryptographic key.Type: GrantFiled: July 28, 2022Date of Patent: April 21, 2026Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Publication number: 20260010489Abstract: Techniques described herein relate to performing write-only swapping of memory pages in a computing environment. For example, the computing environment can execute one or more processes accessing memory pages. The computing environment can request, by a process of the one or more processes, a new memory page. The computing environment can determine that a memory consumption limit predefined for the memory device has been exceeded by the one or more processes. The computing environment can, in response to (i) requesting the new memory page and (ii) determining that the memory consumption limit has been exceeded, discard an existing memory page. The computing environment can allocate the new memory page for the process subsequent to discarding the existing memory page.Type: ApplicationFiled: July 5, 2024Publication date: January 8, 2026Inventors: Michael Tsirkin, Amnon Ilan
-
Patent number: 12494898Abstract: Systems and methods for secured peripheral device communication via a bridge device in virtualized computer systems. An example method may comprise receiving, by a virtualized execution environment running on a computing system, a state measurement associated with a bridge device of the computing system; generating an ephemeral key; responsive to validating the state measurement, transmitting, to the bridge device, the ephemeral key encrypted using a device key associated with the bridge device; and transmitting, to the bridge device, an access request directed to a peripheral device accessible via the bridge device, wherein the access request is encrypted using a value derived from the ephemeral key.Type: GrantFiled: August 31, 2022Date of Patent: December 9, 2025Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Publication number: 20250350543Abstract: Systems and methods for zero-copy forwarding for network function virtualization (NFV). An example method comprises: receiving, by a supervisor of a host computer system, a definition of a packet filter originated by a virtual execution environment running on the host computer system; responsive to validating the packet filter, associating the packet filter with a vNIC of the virtual execution environment; receiving, by the supervisor, a network packet originated by the vNIC; and responsive to matching the network packet to a network connection specified by the packet filter, causing the packet filter to forward the network packet via the network connection.Type: ApplicationFiled: July 22, 2025Publication date: November 13, 2025Inventors: Amnon Ilan, Michael Tsirkin
-
Patent number: 12455755Abstract: Peripheral component interface (PCI) cards can be used to coordinate timer access for virtual machines. For example, a computing device can send, by a virtual machine deployed by a hypervisor, a request for a timer. A guest driver can write a timer for the virtual machine into a first portion of memory on a PCI card. The first portion of memory can be mapped to the virtual machine by the hypervisor. The computing device can receive a card interrupt for the timer. The computing device can translate the card interrupt into a timer interrupt. For example, the card interrupt may be received and translated by the hypervisor or the guest driver. The computing device can inject the timer interrupt to the virtual machine. In some examples, the virtual machine may receive the timer interrupt without exiting to the hypervisor.Type: GrantFiled: February 4, 2022Date of Patent: October 28, 2025Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Patent number: 12375372Abstract: Systems and methods for zero-copy forwarding for network function virtualization (NFV). An example method comprises: receiving, by a supervisor of a host computer system, a definition of a packet filter originated by a virtual execution environment running on the host computer system; responsive to validating the packet filter, associating the packet filter with a vNIC of the virtual execution environment; receiving, by the supervisor, a network packet originated by the vNIC; and responsive to matching the network packet to a network connection specified by the packet filter, causing the packet filter to forward the network packet via the network connection.Type: GrantFiled: June 16, 2022Date of Patent: July 29, 2025Assignee: Red Hat, Inc.Inventors: Amnon Ilan, Michael Tsirkin
-
Patent number: 12333322Abstract: Systems and methods for virtual machine networking can include creating, by a hypervisor running on a host computer system, a first virtual machine (VM) using a first set of computing resources, where the first set of computing resources includes a portion of a second set of computing resources allocated to a second VM managed by the hypervisor. They can further include assigning a first vNIC (virtual Network Interface Controller) to the first VM and setting up a second vNIC to receive data packets transmitted by the first vNIC. Additionally, they can include associating the second vNIC with an identifier of the first VM and assigning the second vNIC to the second VM.Type: GrantFiled: March 25, 2022Date of Patent: June 17, 2025Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Patent number: 12328222Abstract: A system includes a physical host, a host operating system, and a virtual machine having a virtual network-interface controller. The virtual network-interface controller comprises an uplink, a virtual function, and a physical function having a physical channel and a virtual channel. The hypervisor is configured to receive data that originates at the virtual function, which is forwarded to the physical function on the physical channel of the physical function. The data is further forwarded from the physical function to the uplink. Additionally, the hypervisor is configured to send data that does not originate at the virtual function. The hypervisor sends the data on the virtual channel of the physical function and the physical function forwards the data to the virtual function.Type: GrantFiled: March 25, 2022Date of Patent: June 10, 2025Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Patent number: 12204925Abstract: Aspects of the disclosure provide for mechanisms for securing virtual machines in a computer system. A request for a resource is received by a processing device. The request is initiated by a guest application. A determination is made by the processing device of whether an initialization of the guest application is completed. In response to a determination that the initialization of the guest application is completed, at least one system call associated with the request initiated by the guest application is blocked to reject execution of the request for the resource.Type: GrantFiled: January 31, 2022Date of Patent: January 21, 2025Assignee: Red Hat Israel, Ltd.Inventors: Michael Tsirkin, Amnon Ilan
-
Patent number: 12175271Abstract: System and method for reducing latency for nested virtual machines. An example method may include: running, by a host computer system, a hypervisor managing a first virtual machine associated with a first virtual processor (vCPU) implemented by a first processing thread, wherein the first virtual machine manages a second virtual machine; creating, by the hypervisor, a second processing thread implementing a second vCPU associated with the second virtual machine; and responsive to receiving an interrupt directed to the second virtual machine, causing, by the hypervisor, the second processing thread to process the interrupt.Type: GrantFiled: June 29, 2021Date of Patent: December 24, 2024Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Publication number: 20240291803Abstract: Zero trust support for secure networks can be provided via a modified virtual private network (VPN) server. For example, the VPN server may receive, from a VPN client executing on a client device, a first access request for a first software application in a computing environment that is accessible via the VPN server. The first access request can include authentication credentials for the VPN server. The VPN server can authenticate the first access request based on the authentication credentials. In response, a first connection tunnel can be provided between the client device and the first software application. The client device can access the first software application via the first connection tunnel. The VPN server can also deny a second access request received via the first connection tunnel for a second software application in the computing environment.Type: ApplicationFiled: February 28, 2023Publication date: August 29, 2024Inventors: Michael TSIRKIN, Amnon ILAN
-
Publication number: 20240281311Abstract: Queue adjustments to avoid message underrun and usage spikes are provided by placing a first plurality of messages into sequential slots in a first ring queue; in response to receiving a ring adjustment flag, placing the ring adjustment flag into a next available slot of the sequential slots in the first ring queue; and placing a second plurality of messages received after the first plurality of messages into sequential slots in a second ring queue.Type: ApplicationFiled: February 21, 2023Publication date: August 22, 2024Inventors: Amnon Ilan, Michael Tsirkin
-
Publication number: 20240211289Abstract: Systems and methods for networking overhead reduction for encrypted virtual machines are disclosed. A method may include receiving, by a virtual machine running on a host computer system, a request to send a data packet to a specified recipient via a network; identifying a network connection to the specified recipient; determining whether the identified network connection is associated with an encryption option indicating data encryption; responsive to determining that the identified network connection is associated with the encryption option, storing the data packet in a shared memory buffer of the host computer system; and notifying an input/output (I/O) device driver of an address of the shared memory buffer.Type: ApplicationFiled: December 23, 2022Publication date: June 27, 2024Inventors: Amnon Ilan, Michael Tsirkin
-
Patent number: 11983555Abstract: Systems and methods for storage snapshots for nested virtual machines. An example method may comprise running, by a host computer system, a hypervisor managing a first virtual machine associated with a first virtual device. Responsive to creating a second virtual machine by the hypervisor, requesting, by the first virtual machine, a first snapshot of the first virtual device. The hypervisor generates the first snapshot of the first virtual device and forwards the first snapshot of the first virtual device to the second virtual machine.Type: GrantFiled: August 3, 2021Date of Patent: May 14, 2024Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Publication number: 20240072995Abstract: Systems and methods for secured peripheral device communication via a bridge device in virtualized computer systems. An example method may comprise receiving, by a virtualized execution environment running on a computing system, a state measurement associated with a bridge device of the computing system; generating an ephemeral key; responsive to validating the state measurement, transmitting, to the bridge device, the ephemeral key encrypted using a device key associated with the bridge device; and transmitting, to the bridge device, an access request directed to a peripheral device accessible via the bridge device, wherein the access request is encrypted using a value derived from the ephemeral key.Type: ApplicationFiled: August 31, 2022Publication date: February 29, 2024Inventors: Michael Tsirkin, Amnon Ilan
-
Patent number: 11900142Abstract: Systems and methods for memory management for nested virtual machines. An example method may comprise running, by a host computer system, a Level 0 hypervisor managing a Level 1 virtual machine running a Level 1 hypervisor, wherein the Level 1 hypervisor manages a Level 2 virtual machine, wherein the Level 2 virtual machine is associated with a Peripheral Component Interconnect (PCI) device; generating, by the Level 0 hypervisor, a Level 1 page table by combining records from the guest page table with records from a host page table maintained by the Level 0 hypervisor; generating a Level 2 page table comprising a plurality of Level 2 page table entries; and causing a device driver of the Level 2 virtual machine to use the Level 2 page table for second level address translation.Type: GrantFiled: June 16, 2021Date of Patent: February 13, 2024Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Publication number: 20240039700Abstract: Systems and methods for securing assigned peripheral device in virtualized computer system. An example method may comprise receiving, by a virtualized execution environment, a state measurement associated with a peripheral device of the computing system. Generating a guest cryptographic key. Responsive to validating the state measurement, transmitting, to the peripheral device, the guest cryptographic key encrypted using the device cryptographic key. Transmitting, to the peripheral device, an access request that is cryptographically signed using a first value derived from the device cryptographic key or a second value derived from the guest cryptographic key and encrypted using a third value derived from the guest cryptographic key.Type: ApplicationFiled: July 28, 2022Publication date: February 1, 2024Inventors: Michael Tsirkin, Amnon Ilan
-
Patent number: 11868796Abstract: Page request interface overhead reduction for virtual machine migration and write protection in memory may be provided by generating a page table associated with the memory; in response to receiving a write-protection command to prevent write-access to data from a portion of the memory, write-protecting a first range of memory addresses comprising the data write protected from the portion of the memory, wherein a second range of memory addresses comprises data not write protected in the memory; and modifying the page table to include a page table entry associated with the first range of memory addresses being write-protected, wherein write access to a memory address in the first range of memory addresses by a device during write-protection is tracked.Type: GrantFiled: April 25, 2022Date of Patent: January 9, 2024Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Patent number: 11847227Abstract: A method includes detecting a change in control of a peripheral device from a first security domain to a second security domain of a computer system and in response to detecting the change in control of the peripheral device, reading a current firmware version of the peripheral device and determining whether the current firmware version of the peripheral device is trusted by the computer system. The method further includes in response to determining that the current firmware version is trusted by the computer system, providing control of the peripheral device to the second security domain.Type: GrantFiled: November 30, 2020Date of Patent: December 19, 2023Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan