Virtual processor allocation techniques
    2.
    发明授权
    Virtual processor allocation techniques 有权
    虚拟处理器分配技术

    公开(公告)号:US09183030B2

    公开(公告)日:2015-11-10

    申请号:US13095671

    申请日:2011-04-27

    IPC分类号: G06F9/455 G06F9/46

    摘要: One or more virtual processors can be added or removed from a virtual machine based on CPU pressure measured within the virtual machine. In addition to the foregoing, CPU pressure can also be used to determine whether to remove a virtual processor from a virtual machine, which may cause the computer system to consume less power. In the alternative, virtual processors can be parked and/or unparked in order to reduce the amount of power consumed by the virtual machine. In addition, virtual processors can be forcibly parked during a migration operation.

    摘要翻译: 可以根据在虚拟机内测量的CPU压力从虚拟机添加或移除一个或多个虚拟处理器。 除了上述之外,还可以使用CPU压力来确定是否从虚拟机移除虚拟处理器,这可能导致计算机系统消耗较少的功率。 在替代方案中,可以将虚拟处理器停放和/或未停机,以便减少虚拟机消耗的功率量。 此外,虚拟处理器可以在迁移操作期间被强制停放。

    Changing frequency of a virtual programmable interrupt timer in virtual machines to control virtual time
    4.
    发明授权
    Changing frequency of a virtual programmable interrupt timer in virtual machines to control virtual time 有权
    在虚拟机中更改虚拟可编程中断定时器的频率,以控制虚拟时间

    公开(公告)号:US08533709B2

    公开(公告)日:2013-09-10

    申请号:US11197614

    申请日:2005-08-04

    IPC分类号: G06F9/455

    CPC分类号: G06F9/45533 G06F9/4825

    摘要: A catch-up mode that runs a virtual programmable interrupt timer faster than a nominal rate to prevent time loss in a virtual machine can be implemented. If time loss is determined, a catch-up mode can be initiated to cause increased firings, beyond a nominal rate, of the programmable interrupt timer to adjust the clock of the virtual machine to the clock of the host system. The virtual programmable interrupt timer can also be readjusted to a predetermined nominal rate when the time loss in the guest operating system is determined approximately within a predetermined tolerance range. The catch-up mode can be monitored to avoid “interrupt storms” on the virtual machine. The virtual programmable interrupt timer can be altered by the guest operating system to accommodate different operating systems.

    摘要翻译: 可以实现一种追赶模式,其运行虚拟可编程中断定时器比名义速率更快以防止虚拟机中的时间损失。 如果确定时间损失,则可启动追赶模式,以引起可编程中断定时器超出标称速率的增加的启动,以将虚拟机的时钟调整到主机系统的时钟。 当客人操作系统中的时间损失大致在预定的公差范围内被确定时,虚拟可编程中断定时器也可以重新调整到预定的标称速率。 可以监视追赶模式,以避免虚拟机中的“中断风暴”。 虚拟可编程中断定时器可以由客户机操作系统改变,以适应不同的操作系统。

    Systems and methods for data encryption using plugins within virtual systems and subsystems
    5.
    发明授权
    Systems and methods for data encryption using plugins within virtual systems and subsystems 有权
    使用虚拟系统和子系统中的插件进行数据加密的系统和方法

    公开(公告)号:US07987497B1

    公开(公告)日:2011-07-26

    申请号:US10794898

    申请日:2004-03-05

    摘要: Several embodiments of the present invention provide a means for improving data access security in computer systems to support high-security applications, and certain of these embodiments are specifically directed to providing sector-level encryption of a virtual hard disk in a virtual machine environment. More specifically, certain embodiments are directed to providing sector-level encryption by using plug-ins in a virtual machine environment, thereby providing improved data access security in a computer system that supports high-security applications. Certain embodiments also use encryption plug-ins associated with standard encryption software for exchanging data between a virtual machine (VM) and its associated virtual hard drive(s) (VHDs). Moreover, several embodiments of the present invention are directed to the use of plug-in encryption services that interface with, and provide services for, a VM via a VM Encryption API (or its equivalent).

    摘要翻译: 本发明的几个实施例提供了一种用于改善计算机系统中的数据访问安全性以支持高安全性应用的手段,并且这些实施例中的某些具体涉及在虚拟机环境中提供虚拟硬盘的扇区级加密。 更具体地,某些实施例旨在通过在虚拟机环境中使用插件来提供扇区级加密,从而在支持高安全性应用的计算机系统中提供改进的数据访问安全性。 某些实施例还使用与标准加密软件相关联的加密插件来在虚拟机(VM)及其相关联的虚拟硬盘驱动器(VHD)之间交换数据。 此外,本发明的若干实施例涉及使用通过VM加密API(或其等价物)与VM接口并为VM提供服务的插件加密服务。

    Scalability of virtual TLBs for multi-processor virtual machines
    6.
    发明授权
    Scalability of virtual TLBs for multi-processor virtual machines 有权
    用于多处理器虚拟机的虚拟TLB的可扩展性

    公开(公告)号:US07788464B2

    公开(公告)日:2010-08-31

    申请号:US11644502

    申请日:2006-12-22

    IPC分类号: G06F12/10

    CPC分类号: G06F12/1027

    摘要: Various operations are provided that improve the scalability of virtual TLBs in multi-processor virtual machines, and they include: implicitly locking SPTs using per-processor generation counters; waiting for pending fills on other virtual processors to complete before servicing a GVA invalidation using the counters; write-protecting or unmaping guest pages in a deferred two-stage process or reclaiming SPTs in a deferred two-stage process; periodically coalescing two SPTs that shadow the same GPT with the same attributes; sharing SPTs between two SASes only at a specified level in a SPTT; flushing the entire virtual TLB using a generation counter; allocating a SPT to GPT from a NUMA node on which the GPT resides; having an instance for each NUMA node on which a virtual machine runs; and, correctly handling the serializing instructions executed by a guest in a virtual machine with more than one virtual processor sharing the virtual TLB.

    摘要翻译: 提供了提高多处理器虚拟机中虚拟TLB可扩展性的各种操作,包括:使用每处理器生成计数器隐式锁定SPT; 在使用计数器服务GVA无效之前等待其他虚拟处理器上的待处理填充; 在延迟的两阶段过程中写入保护或取消映射访客页面或在延迟的两阶段过程中回收SPT; 定期合并两个具有相同属性的相同GPT的SPT; 在SPTT之间仅在指定级别共享两个SAS之间的SPT; 使用生成计数器刷新整个虚拟TLB; 从GPT所在的NUMA节点向GPT分配SPT; 具有运行虚拟机的每个NUMA节点的实例; 并且正确地处理由具有多个共享虚拟TLB的虚拟处理器的虚拟机中的来宾执行的序列化指令。

    Method and System For Caching Address Translations From Multiple Address Spaces In Virtual Machines
    9.
    发明申请
    Method and System For Caching Address Translations From Multiple Address Spaces In Virtual Machines 有权
    用于从虚拟机中的多个地址空间缓存地址转换的方法和系统

    公开(公告)号:US20080215848A1

    公开(公告)日:2008-09-04

    申请号:US12098766

    申请日:2008-04-07

    IPC分类号: G06F12/10

    摘要: A method of virtualizing memory through shadow page tables that cache translations from multiple guest address spaces in a virtual machine includes a software version of a hardware tagged translation look-aside buffer. Edits to guest page tables are detected by intercepting the creation of guest-writable mappings to guest page tables with translations cached in shadow page tables. The affected cached translations are marked as stale and purged upon an address space switch or an indiscriminate flush of translations by the guest. Thereby, non-stale translations remain cached but stale translations are discarded. The method includes tracking the guest-writable mappings to guest page tables, deferring discovery of such mappings to a guest page table for the first time until a purge of all cached translations when the number of untracked guest page tables exceeds a threshold, and sharing shadow page tables between shadow address spaces and between virtual processors.

    摘要翻译: 通过影像页表虚拟化存储器的方法,其缓存来自虚拟机中的多个访客地址空间的转换,包括硬件标记的翻译后备缓冲器的软件版本。 通过拦截向客户页面表创建客户机可写映射,并通过缓存在阴影页表中的翻译来检测访客页面表的编辑。 受影响的缓存翻译被标记为陈旧,并被清除在地址空间开关或客人不加区别地翻译翻译。 因此,非陈旧的翻译仍保持高速缓存,但是陈旧的翻译将被丢弃。 该方法包括跟踪访客页面表的访客可写映射,将此类映射的发现推迟到访客页面表,直到当未跟踪的访客页面表的数量超过阈值时清除所有缓存的翻译,并共享阴影 阴影地址空间和虚拟处理器之间的页表。

    Systems and methods for running a legacy 32-bit x86 virtual machine on a 64-bit x86 processor
    10.
    发明授权
    Systems and methods for running a legacy 32-bit x86 virtual machine on a 64-bit x86 processor 有权
    用于在64位x86处理器上运行旧版32位x86虚拟机的系统和方法

    公开(公告)号:US07260702B2

    公开(公告)日:2007-08-21

    申请号:US10883496

    申请日:2004-06-30

    IPC分类号: G06F12/00 G06F9/44 G06F9/46

    摘要: The present invention provides a virtualized computing systems and methods for transitioning in real time between LONG SUPER-MODE and LEGACY SUPER-MODE in the x86-64 architecture. In doing so, a virtual machine, which relies on the traditional 32-bit modes, i.e., REAL MODE and PROTECTED MODE (V86 SUB-MODE, RING-0 SUB-MODE, and RING-3 SUB-MODE), is able to run alongside other applications on x86-64 computer hardware (i.e., 64-bit). The method of performing a temporary processor mode context switch includes the steps of the virtual machine monitor's setting up a “virtual=real” page, placing the transition code for performing the processor mode context switch on this page, jumping to this page, disabling the memory management unit (MMU) of the x86-64 computer hardware, modifying the mode control register to set either the LONG SUPER-MODE bit or LEGACY SUPER-MODE bit, loading a new page table, and reactivating the MMU of the x86-64 computer hardware.

    摘要翻译: 本发明提供了一种用于在x86-64架构中的LONG SUPER-MODE和LEGACY SUPER-MODE之间实时转换的虚拟化计算系统和方法。 这样做,依靠传统的32位模式,即REAL模式和PROTECTED MODE(V86 SUB-MODE,RING-0 SUB-MODE和RING-3 SUB-MODE)的虚拟机能够 与x86-64计算机硬件(即64位)上的其他应用程序一起运行。 执行临时处理器模式上下文切换的方法包括虚拟机监视器设置“虚拟=真实”页面的步骤,将用于执行处理器模式上下文切换的转换代码放置在该页面上,跳转到该页面,禁用 x86-64计算机硬件的存储器管理单元(MMU),修改模式控制寄存器以设置LONG SUPER-MODE位或LEGACY SUPER-MODE位,加载新的页表,并重新激活x86-64的MMU 电脑硬件。