Patents by Inventor Michael Tsirkin
Michael Tsirkin has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12730888Abstract: An execution measurement event associated with a Virtual Machine (VM) managed by a hypervisor is detected, wherein the VM is implemented using a first processor device of one or more processor devices. Responsive to detecting the execution measurement event, execution measurement information descriptive of a period of execution for the VM prior to detection of the execution measurement event is measured using the first processor device of the one or more processor devices. A cryptographic signature is generated for the execution measurement information, wherein the cryptographic signature verifies that the execution measurement information was measured using the first processor device.Type: GrantFiled: September 17, 2024Date of Patent: September 8, 2026Assignee: Red Hat, LLCInventor: Michael Tsirkin
-
Patent number: 12717934Abstract: A system includes a memory, a processor in communication with the memory, and a first TEE instance. The first TEE instance is configured to maintain an encrypted secret, obtain a cryptographic measurement associated with a second TEE instance, validate the cryptographic measurement, and provision the second TEE instance with the encrypted secret. Additionally, the first TEE instance and the second TEE instance are both configured to service at least a first type of request.Type: GrantFiled: April 3, 2023Date of Patent: August 25, 2026Assignee: Red Hat, Inc.Inventor: Michael Tsirkin
-
Patent number: 12717605Abstract: The technology disclosed herein generates, by a virtual machine running on a host computer system, a plurality of direct guest physical addresses, maps each guest virtual address of a plurality of guest virtual addresses to a direct guest physical address of the plurality of direct guest physical addresses, and updates, for each guest virtual address to direct guest physical address mapping, an entry of a shadow page table with the direct guest physical address to a guest physical address mapping.Type: GrantFiled: April 18, 2023Date of Patent: August 25, 2026Assignee: Red Hat, LLCInventor: Michael Tsirkin
-
Patent number: 12717601Abstract: Systems and methods for memory management for nested virtual machines. An example method may comprise running, by a host computer system, a hypervisor managing a first virtual machine; responsive to receiving, by the hypervisor, a request to create a second virtual machine nested within the first virtual machine, determining whether the second virtual machine will be using a physical address as a virtual address for a peripheral device; and responsive to determining that the second virtual machine will be using the physical address as the virtual address for the peripheral device, initializing a first data structure for address translation of the physical addresses of the second virtual machine corresponding to virtual addresses of the peripheral device to a host virtual addresses.Type: GrantFiled: December 14, 2021Date of Patent: August 25, 2026Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Patent number: 12710973Abstract: An example method may include generating a block list comprising a plurality of list items, wherein each list item identifies a respective block of a source virtual machine image, and the list items are ordered in the block list according to a timestamp of each respective block, wherein the timestamp indicates a time of a last access of the respective block, sending the block list to a destination computing device, receiving, from the destination computing device, one or more candidate blocks, determining whether the one or more candidate blocks are included in the source virtual machine image, and sending, to the destination computing device, a result indicating whether the one or more candidate blocks are included in the source virtual machine image.Type: GrantFiled: June 28, 2022Date of Patent: August 18, 2026Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, David Gilbert
-
Patent number: 12712829Abstract: Systems and methods for supporting page faults for virtual machine network accelerators. In one implementation, a processing device may receive, at a network accelerator device of a computer system, from a network, a first incoming packet and a second incoming packet. Responsive to receiving a first notification that an attempt to store the first incoming packet at a first buffer of a plurality of buffers associated with the network accelerator device caused a page fault, the processing device may store the first incoming packet at a second buffer and append a first identifier of the first buffer to a faulty buffer data structure. Responsive to receiving a second notification indicating a resolution of the page fault, the processing device may remove the first identifier from the faulty buffer data structure. The processing device may store the second incoming packet at the first buffer.Type: GrantFiled: November 14, 2022Date of Patent: August 18, 2026Assignee: Red Hat, LLCInventor: Michael Tsirkin
-
Patent number: 12705083Abstract: Systems, methods, and apparatuses for regulating virtual processing device usage by emulating thermal throttling are provided herein. An example method comprises limiting a processing capacity allocated for a virtual processing device to a value equal to or below a threshold by transmitting, via a hypervisor, an indication to a guest that the virtual processing device has exceeded an operating temperature, wherein the value is below a current processing capacity of a host processing device.Type: GrantFiled: September 5, 2023Date of Patent: August 11, 2026Assignee: Red Hat, Inc.Inventor: Michael Tsirkin
-
Publication number: 20260211715Abstract: Memory pages can be migrated between non-uniform memory access (NUMA) nodes based on entries in a page modification log according to some examples described herein. In one example, a physical processor can detect a request from a virtual machine to access a memory page. The physical processor can then update a page modification log to include an entry indicating the request. A hypervisor supporting the virtual machine can be configured to detect the request based on the entry in the page modification log and, in response to detecting the request, migrate the memory page from a second NUMA node to a destination NUMA node.Type: ApplicationFiled: March 9, 2026Publication date: July 23, 2026Applicant: Red Hat, LLCInventor: Michael Tsirkin
-
Publication number: 20260186811Abstract: During a post-copy migration process, latency and memory overrides can be avoided by implementing some techniques described herein. For example, during a post-copy migration process involving migrating a virtual machine from a source computing device to the destination computing device, a hypervisor can start the virtual machine on the destination computing device. After starting the virtual machine, the hypervisor can receive a message associated with storing data from a passthrough device to a virtual memory segment of the virtual machine on the destination computing device. Based on receiving the message, the hypervisor can prevent the virtual memory segment from being migrated from the source computing device to the destination computing device. This can prevent the data from the passthrough device from being overridden.Type: ApplicationFiled: December 26, 2024Publication date: July 2, 2026Inventors: Michael Tsirkin, Eugenio Antolin Pérez Martín
-
Patent number: 12670004Abstract: A supervisor on a destination host receives a request to migrate an application from a source host to the destination host and determines a total amount of memory associated with the application on the source host. The supervisor on the destination host allocates one or more memory pages in a page table on the destination host to satisfy the total amount of memory associated with the application on the source host, where the one or more memory pages are to be associated with the application on the destination host. Responsive to determining that the one or more memory pages have been allocated on the destination host, the supervisor on the destination host initiates migration of the application from the source host to the destination host.Type: GrantFiled: October 17, 2022Date of Patent: June 30, 2026Assignee: Red Hat, LLCInventors: Michael Tsirkin, Andrea Arcangeli
-
Patent number: 12670014Abstract: An example system includes a memory, at least one processor in communication with the memory, a plurality of threads executing on the at least one processor, and a supervisor. The supervisor is configured to preempt a first thread of the plurality of threads and determine a status of the first thread as either (i) executing in an atomic section or (ii) executing outside of the atomic section. The atomic section is a region of code tagged as atomic, and the atomic section includes instructions that run under a lock. Responsive to determining the status as executing in the atomic section, the supervisor is configured to notify a second thread of the plurality of threads to execute a system call based lock to block execution until the lock is released by the first thread.Type: GrantFiled: October 18, 2021Date of Patent: June 30, 2026Assignee: Red Hat, Inc.Inventor: Michael Tsirkin
-
Patent number: 12670005Abstract: Systems and methods for secure saving sand restoration of virtualized states is disclosed herein, wherein a guest and/or a virtual machine is aware of being executed from a restored snapshot. An example system comprises a hypervisor; an application running in an encrypted virtual machine; a memory; a processor in communication with the memory executing an application, wherein the application is configured to modify, by an application running in an encrypted VM, a shadow identifier (Shadow ID) saved in private memory; and save a state of the encrypted VM, as a snapshot.Type: GrantFiled: March 22, 2023Date of Patent: June 30, 2026Assignee: Red Hat, Inc.Inventor: Michael Tsirkin
-
Publication number: 20260178725Abstract: Secure drivers for confidential virtual machines. A communication channel is established by a first device driver executing in a memory of a virtual machine manager (VMM) with a second device driver executing in a private memory of a user space memory of a confidential virtual machine that was initiated by the VMM. The private memory is inaccessible by the VMM. The first device driver provides the data over the communication channel to the second device driver within the user space memory. The second device driver receives the data. The second device driver modifies the private memory to include the data or prevents the data from being written to the private memory based on a criterion.Type: ApplicationFiled: December 19, 2024Publication date: June 25, 2026Inventor: Michael Tsirkin
-
Publication number: 20260169778Abstract: Systems and methods are provided. An example method can include obtaining, by guest firmware executing in a virtual machine, data indicative of a first request for a virtual device to perform a first action, wherein the first request was generated by a guest operating system executing in the virtual machine. The example method can include providing, by the guest firmware to a physical hardware component of a physical computing device on which the virtual machine is executing, a second request for the physical hardware component to perform the first action. The example method can include receiving, by the guest firmware from the physical hardware component, a first response indicative of a first result of the first action. The example method can include providing, by the guest firmware to the guest operating system, a second response indicative of the first result of the first action.Type: ApplicationFiled: December 13, 2024Publication date: June 18, 2026Inventor: Michael Tsirkin
-
Publication number: 20260169785Abstract: A first computing system determines that a first virtual machine (VM) executing on the first computing system is to be live migrated to generate a second VM on a second computing system. The first computing system requests from the second computing system power state configuration data indicative of available power states on the second computing system. The first computing system provides the power state configuration data to a guest operating system (OS) of the first VM, and subsequent to transmitting the power state configuration data to the guest OS, initiates, a switch over to the second computing system, such that subsequent processing is implemented by the second VM and not the first VM.Type: ApplicationFiled: December 18, 2024Publication date: June 18, 2026Inventor: Michael Tsirkin
-
Patent number: 12657115Abstract: Disclosed herein is technology to efficiently test versions. An example method may include: receiving a plurality of versions of one or more code objects, wherein each version of the plurality of versions has at least one ancestor or descendent version among the plurality of versions; determining a first number of versions in a testing round; selecting, from the plurality of versions, a first set of versions satisfying a weight-based criterion, wherein a number of the first set of versions equals the first number; testing the first set of versions; and updating the plurality of versions based on a result of testing the first set of versions.Type: GrantFiled: December 23, 2022Date of Patent: June 16, 2026Assignee: Red Hat, LLCInventor: Michael Tsirkin
-
Publication number: 20260161438Abstract: Techniques described herein relate to supporting legacy input/output (I/O) device functionality for virtual machines. For example, an I/O device can be communicatively coupled to a computing system. The I/O device may have an actual identification number. The I/O device may expose a window of I/O device memory to the computing system. The window of I/O device memory may be associated with a virtual I/O port that has a virtual identification number that differs from the actual identification number. An intermediate driver executed by the computing system can expose the window of I/O device memory to a virtual machine. the intermediate driver can map, for the virtual machine, access to the virtual I/O port via the window of I/O device memory using the virtual identification number. The virtual machine can, based on the mapping, transmit an access request to the window of I/O device memory via the virtual I/O port.Type: ApplicationFiled: December 10, 2024Publication date: June 11, 2026Applicant: Red Hat, Inc.Inventor: Michael Tsirkin
-
Patent number: 12650868Abstract: System and method for running virtual machines within containers. An example method may include: running, by a host computer system, a hypervisor managing a first virtual machine implemented by a first container with a first set of resources, creating, by the hypervisor, a second container implementing the second virtual machine, wherein the second container is nested within the first container, determining, by the first virtual machine of the first container, one or more of the first set of resources to assign to the second container, and assigning, by the hypervisor, to the second container one or more of the first set of resources.Type: GrantFiled: August 3, 2021Date of Patent: June 9, 2026Assignee: Red Hat, Inc.Inventors: Michael Tsirkin, Amnon Ilan
-
Patent number: 12645482Abstract: Systems and methods for encryption support for virtual machines. An example method may comprise initializing, by a firmware module associated with a virtual machine running on a host computer system, an exclusion range register associated with the virtual machine with a value specifying a first portion of guest memory. The first portion of the guest memory may include an exclusion range marked as reserved. The second portion of the guest memory may b e encrypted using an ephemeral encryption key. Virtual machine firmware may identify, in the second portion of the guest memory, an instruction to a virtual device associated with the virtual machine, copy data corresponding to the instruction to the first portion of guest memory, and alert the hypervisor of the data stored in the first portion of guest memory.Type: GrantFiled: March 13, 2023Date of Patent: June 2, 2026Assignee: Red Hat, LLCInventor: Michael Tsirkin
-
Patent number: 12647454Abstract: A virtual device can be provided to a virtual machine from a hypervisor. The virtual can correspond to a backend element accessible to the VM via communications with the virtual device. The hypervisor can intercept a communication from the VM directed to the backend element via the virtual device. The hypervisor can set a timer. The timer can track an elapsed time from the communication to a response from the backend element. The hypervisor can send the communication from the virtual machine to the backend element. The timer can then be determined to have expired without a response being received. The virtual device can then be disabled.Type: GrantFiled: August 31, 2022Date of Patent: June 2, 2026Assignee: Red Hat, LLCInventor: Michael Tsirkin