Optimizing Nested Virtualization Performance Using Direct Virtual Hardware
Jin Tack Lim, Jason Nieh
Abstract
Nested virtualization, running virtual machines and hypervisors on top of other virtual machines and hypervisors, is increasingly important because of the need to deploy virtual machines running software stacks on top of virtualized cloud infrastructure. However, performance remains a key impediment to further adoption as application workloads can perform many times worse than native execution. To address this problem, we introduce DVH (Direct Virtual Hardware), a new approach that enables a host hypervisor, the hypervisor that runs directly on the hardware, to directly provide virtual hardware to nested virtual machines without the intervention of multiple levels of hypervisors. We introduce four DVH mechanisms, virtual-passthrough, virtual timers, virtual inter-processor interrupts, and virtual idle. DVH provides virtual hardware for these mechanisms that mimics the underlying hardware and in some cases adds new enhancements that leverage the flexibility of software without the need for matching physical hardware support. We have implemented DVH in the Linux KVM hypervisor. Our experimental results show that DVH can provide near native execution speeds and improve KVM performance by more than an order of magnitude on real application workloads.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers11
- A Secure and Formally Verified Linux KVM HypervisorShih-Wei Li, Xupeng Li, Ronghui Gu, Jason Nieh et al.S&P 2021 · 72 citations
- Formally Verified Memory Protection for a Commodity Multiprocessor HypervisorShih-Wei Li, Xupeng Li, Ronghui Gu, Jason Nieh et al.USENIX Security 2021 · 48 citations
- Hecate: Lifting and Shifting On-Premises Workloads to an Untrusted CloudXinyang Ge, Hsuan-Chi Kuo, Weidong CuiCCS 2022 · 14 citations
- Core slicing: closing the gap between leaky confidential VMs and bare-metal cloudZiqiao Zhou, Yizhou Shan, Weidong Cui, Xinyang Ge et al.OSDI 2023 · 12 citations
- Security and Performance in the Delegated User-level VirtualizationJiahao Chen, Dingji Li, Zeyu Mi, Yuxuan Liu et al.OSDI 2023 · 10 citations
Related papers
- Translation Pass-Through for Near-Native Paging Performance in VMsShai Bergman, Mark Silberstein, Takahiro Shinagawa, Peter R. Pietzuch et al.USENIX ATC 2023 · 10 citations
- (Mostly) Exitless VM Protection from Untrusted Hypervisor through Disaggregated Nested VirtualizationZeyu Mi, Dingji Li, Haibo Chen, Binyu Zang et al.USENIX Security 2020
- Direct Memory Translation for Virtualized CloudsJiyuan Zhang, Weiwei Jia, Siyuan Chai, Peizhe Liu et al.ASPLOS 2024 · 5 citations
- Accelerating Nested Virtualization with HyperTurtleOri Ben Zur, Jakob Krebs, Shai Aviram Bergman, Mark SilbersteinUSENIX ATC 2025 · 2 citations
- Nested SEV: Secure and Generic SEV Support for Nested VirtualizationKazuki Takiguchi, Kenichi KouraiOSDI 2026
