Electronic device, medium, and method for virtual nodes

By employing a platform controller to simulate PTP clock devices independently of main processors, the method addresses inefficiencies and security vulnerabilities in existing time synchronization methods, achieving efficient and secure time synchronization for virtual machines and containers.

CN116996151BActive Publication Date: 2025-07-15HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211321352.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-04-26
Filing Date
2022-10-26
Publication Date
2025-07-15
Estimated Expiration
2042-10-26

AI Technical Summary

Technical Problem

The prior art has performance flaws and security issues when providing accurate time protocol clock devices for virtual machines, especially the use of super managers to emulate PTP clock devices can lead to waste of processing resources and security vulnerabilities of computer platforms.

Method used

By simulating the physical hardware PTP clock device in the platform controller of the computer platform, providing virtual PTP clock devices is provided for virtual nodes, reducing dependence on the main processor, and using PCIe bus and SR-IOV technology to realize lightweight PTP clock device simulation.

Benefits of technology

It reduces the overhead of the main processor, reduces the risk of security attacks, and improves the efficiency and security of processing resource utilization of computer platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116996151B_ABST
    Figure CN116996151B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a virtual Precision Time Protocol (PTP) clock device for virtual nodes. A manager provides a plurality of virtual nodes. A storage medium stores a plurality of information elements. A controller separate from the manager provides a plurality of virtual Precision Time Protocol (PTP) clock devices. Each virtual PTP clock device corresponds to an information element. The controller uses the information element corresponding to a given virtual PTP clock device to provide time based on the Precision Time Protocol for the given virtual PTP clock device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to managing computer platforms. Background Art

[0002] A bare metal computer platform can maintain system time associated with the system clock of the computer platform. The computer platform can use the system clock to timestamp various events, operations, and transactions of the computer platform (e.g., assign time via a marker representing time). For example, a bare metal computer platform can timestamp when a record (e.g., a file) is created or modified; timestamp a recorded event; timestamp a financial transaction; timestamp when an email is received or sent; timestamp a security alert; and so on. The computer platform can have one or more virtual machines, and the one or more virtual machines can maintain their respective system clocks to timestamp events, operations, and transactions associated with the virtual machines. Summary of the Invention

[0003] In one aspect, this disclosure provides an electronic device, including: a storage medium for storing a plurality of information elements; a manager for providing a plurality of virtual nodes; and a controller separate from the manager for providing a plurality of virtual Precision Time Protocol (PTP) clock devices, wherein: each of the plurality of virtual PTP clock devices corresponds to an information element among the plurality of information elements; the controller is configured to use the information element corresponding to a given virtual PTP clock device among the plurality of virtual PTP clock devices to provide PTP-based time for the given virtual PTP clock device; and the controller providing the PTP-based time includes transmitting a sequence of PTP-based messages by the given virtual PTP clock device and with a given virtual node among the plurality of virtual nodes to synchronize the clock of the given virtual node with the PTP-based time.

[0004] In one aspect, the present disclosure provides a non-transitory machine-readable storage medium storing machine-executable instructions that, when executed by a machine, cause the machine to perform the following operations: storing information indicating address locations of register sets of a plurality of virtual Precision Time Protocol (PTP) clock devices, wherein the virtual PTP clock devices are provided by a controller and are associated with a plurality of virtual nodes; and executing the plurality of virtual nodes to access the plurality of virtual PTP clock devices using the information, wherein a given virtual node among the plurality of virtual nodes is configured to transmit a sequence of Precision Time Protocol (PTP)-based messages with a given virtual PTP clock device among the virtual PTP clock devices to synchronize a clock of the given virtual node with PTP-based time.

[0005] In one aspect, the present disclosure provides a method for virtual nodes, including: dispatching, by a manager in a system including a hardware processor, a virtual function to respective virtual nodes among a plurality of virtual nodes, wherein the virtual function represents a respective PTP clock device and the virtual function is provided by a controller separate from the manager; and executing the plurality of virtual nodes in the system to access the respective PTP clock devices using information indicating addresses of the respective PTP clock devices, wherein a given virtual node among the plurality of virtual nodes is configured to transmit a sequence of PTP-based messages with a given respective PTP clock device among the respective PTP clock devices to synchronize a clock of the given virtual node with PTP-based time. BRIEF DESCRIPTION OF THE DRAWINGS

[0006] Figure 1 is a block diagram of a computer platform having a platform controller that provides virtual Precision Time Protocol (PTP) clock devices for virtual machines of a computer platform according to an example embodiment.

[0007] Figure 2 is Figure 1 a block diagram of a platform controller according to an example embodiment.

[0008] Figure 3 is a block diagram of a memory address space associated with a virtual PTP clock device according to an example embodiment.

[0009] Figure 4 is a block diagram of a device having a controller that provides virtual PTP clock devices for virtual nodes of the device according to an example embodiment.

[0010] Figure 5FIG. is a diagram of a non - transitory machine - readable storage medium storing machine - executable execution according to an example embodiment, the machine - executable execution, when executed, causing the machine to execute a virtual node to access a virtual PTP clock device.

[0011] Figure 6 FIG. is a flowchart depicting a process for providing a virtual PTP clock device to a virtual node according to an example embodiment. DETAILED DESCRIPTION

[0012] A computer platform can provide one or more instances of a computing environment. For example, a computer platform can be part of a cloud computing system. The cloud computing system can include a central management subsystem that orchestrates software - defined logical infrastructure and services (e.g., software - defined computing (SDC) services, software - defined storage (SDS) services, and software - defined networking (SDN) services), which are hosted on computer platforms of the cloud computing system. As part of providing the logical infrastructure and services, the computer platform can provide instances of the computing environment.

[0013] In various types of computing environments, a bare - metal computing environment is associated with actual hardware resources and software resources. A virtual computing environment (also referred to herein as a “virtual node”) is an abstraction or virtualization of actual hardware resources and software resources. A computer platform that contains actual hardware resources and software resources acts as a host for the virtual node.

[0014] A virtual machine (which can also be referred to as a “guest virtual machine”, “virtual machine”, “VM instance”, “guest VM”, or “VM”) is an example of a virtual node. A VM is a machine - level abstraction that has virtualized resources of its own host computer platform (e.g., (one or more) CPUs, system memory, (one or more) network interfaces, and storage). In addition, a VM can have its own guest operating system. A VM manager (also referred to as a virtual machine monitor (VMM) or hypervisor) performs actions for providing VM instances. Generally, the hypervisor can manage the lifecycle of VM instances executing on a host computer platform, maintain isolation between VM instances, and provide virtualization services to VM instances.

[0015] A "container" (also referred to as an "instantiated container", "container instance", or "software container") is another example of a virtual node. Generally, a container is a virtual runtime environment for one or more applications and / or application modules, and this virtual runtime environment is constructed to interface with an operating system kernel. For example, a container for a given application can contain the application's executable code and its dependencies, such as the application's system tools, libraries, configuration files, executables, and binaries. A container includes an operating system kernel mount interface but does not include the operating system kernel. Thus, for example, a given computer platform can contain several containers that share the operating system kernel of the host computer platform through the respective operating system kernel mount interfaces. Docker containers and rkt containers are examples of containers. A container manager (also referred to as a container engine daemon) performs the action of providing containers. Generally, the container engine daemon can perform the actions of building and running containers.

[0016] A given entity (e.g., a virtual node instance or a bare metal instance) executing on a computer platform can timestamp various events, operations, and transactions associated with the entity. When the operating system associated with the entity is running, the entity can maintain a system clock to track the current time. In the context used herein, a "clock" refers to a virtual or physical component or device that provides a value representing time (e.g., the time of day).

[0017] The entity can update the time of the system clock in response to host central processing unit (CPU) clock ticks. Since the memory associated with the operating system is cleared when the operating system starts, the operating system associated with the entity may initially not know the current time. During startup, the operating system can take action to discover the current time, or the time can be notified to the operating system. Since CPU clock ticks are relatively inaccurate (e.g., the CPU oscillator may have a variation of 50 parts per million (ppm), resulting in a drift of approximately 4.25 seconds per day), the system clock can be periodically refreshed (e.g., periodically resynchronized to the time represented by another clock) when the operating system is executing.

[0018] The operating system can obtain the current time (for the initial value after startup and subsequent refreshes) from a clock source internal to the computer platform or from a clock source external to the computer platform. For example, a VM instance can obtain its time from a hypervisor internal to the computer platform. A battery-backed real-time clock (RTC) is another example of an internal clock source. Another clock source that can be internal to the computer platform is a hardware-based Precision Time Protocol (PTP) clock device. Clock sources external to the computer platform can include Network Time Protocol (NTP) servers and PTP servers.

[0019] Clock sources can vary with respect to their accuracy and the associated cost of their implementation. For example, a battery-backed RTC may be implemented at a relatively low cost, but may not be as accurate as the clock tick of the host CPU. A PTP clock source may be relatively more accurate than a battery-backed RTC or an NTP clock source, but may be relatively more expensive to implement.

[0020] NTP and PTP are examples of time synchronization protocols. Generally, entities of a computer platform can use a time synchronization protocol to synchronize the entity's clock to a reference clock (e.g., to obtain an initial clock value representing the time of day and thereafter periodically refresh the clock value). The accuracy of time synchronization protocols can vary. For example, PTP can have an associated accuracy of 200 nanoseconds (ns) (i.e., a given clock can be synchronized to a reference clock within 200 ns using PTP), while NTP can have an associated relatively lower accuracy of 200 microseconds (μs).

[0021] Although it may be more expensive to implement, there can be many reasons to use a relatively more precise time synchronization protocol such as PTP. For example, industry standards and / or government regulations may impose precise clock constraints on certain computer-related events, operations, and transactions such as financial transactions, health record transactions, power transmission infrastructure events and fault records, earthquake event records, and so on. In addition, many security vulnerabilities, computer system outages, and other computer-related problems have arisen due to time synchronization failures and / or inaccurate time (e.g., leap second errors, security attacks, software failures, certificate verification failures, etc.).

[0022] PTP is associated with a hierarchy of nodes (or "clock hierarchy"). The PTP clock hierarchy can form a tree structure. At the root or beginning of the tree structure, the clock hierarchy includes a master node or primary node referred to herein as the "primary PTP leader". The primary PTP leader maintains the primary reference clock, and the clocks of the other nodes of the PTP clock hierarchy are synchronized to the clock of the primary PTP leader. A given node in the remaining nodes of the PTP clock hierarchy can be a PTP follower, or both a PTP follower and a PTP leader. Generally, a PTP leader (whether the primary PTP leader or another PTP leader) transmits a specific sequence of messages to a PTP follower to synchronize the PTP follower's clock to the PTP leader's clock. A node that is both a PTP follower and a PTP leader is considered a boundary node, while a node that is only a PTP follower (i.e., a leaf node of the PTP clock hierarchy tree) is considered a client node.

[0023] As an example, the clock of the primary PTP leader can be synchronized to an atomic clock (e.g., the clock of the primary PTP leader can be synchronized to the U.S. atomic clock located in Boulder, CO via radio frequency (RF) communication). As another example, the clock of the primary PTP leader can be synchronized to a Global Navigation Satellite System (GNSS) clock. As a more specific example, a computer platform can include a hardware component such as a timing card (e.g., a Peripheral Component Interconnect Express (PCIe) card) that acts as the primary PTP leader to which the clocks of other PTP followers are synchronized. As another example, a computer platform can have PTP followers that synchronize their clocks to an off-platform PTP leader such as a network switch.

[0024] Physical hardware PTP clock devices (e.g., PTP clock devices formed by dedicated hardware components such as gate arrays, application-specific integrated circuits (ASICs), and / or microcontrollers or processing cores) can be relatively expensive. When a computer platform has several (e.g., dozens to hundreds) VM instances executing on the computer platform and provides PTP clock devices for the corresponding VM instances, the cost can be complex.

[0025] A method for providing a PTP clock source (instead of a dedicated physical, hardware PTP clock device) for VM instances involves the hypervisor of the computer platform emulating a hardware PTP clock device for the VM instances. In this way, the hypervisor can have an emulation layer for emulating hardware PTP clock devices for several VM instances, such that due to this emulation, the hypervisor provides virtual PTP clock devices to each VM instance. However, this method may have performance drawbacks and / or security drawbacks. Hypervisor-based emulation of PTP clock devices may introduce latency variations because other execution entities wait while the hypervisor executes PTP clock emulation code. For example, an NTP client can perform mathematical filtering on the time received by the NTP client from an NTP server to reduce the impact of incorrect time values. Performing mathematical filtering may involve some mathematical functions employed (e.g., a mathematical function that adds the last n values and divides by n), which consume some CPU cycles. Additionally, using the hypervisor to emulate PTP clock devices can create security vulnerabilities for the computer platform. In this way, to allow guest operating systems to make hypervisor system calls, a specific driver can be provided for each guest operating system. This paravirtualization can provide a highly sensitive security attack surface for invading the hypervisor.

[0026] According to an example embodiment described herein, a controller of a computer platform emulates a physical hardware PTP clock device (referred to herein as a "PTP clock device") to provide a corresponding virtual PTP clock device for a corresponding virtual node instance. Emulating the PTP clock device provided by the controller may be beneficial for reasons such as reducing the security attack surface of the computer platform. In addition, emulating the PTP clock device provided by the controller can free up processing resources of the computer platform (e.g., free up processing resources such as CPU resources that would otherwise be used to emulate the PTP clock device as part of an emulation layer for a hypervisor).

[0027] According to some embodiments, the controller may be a "platform controller" which refers to a controller that performs specified tasks in a computer platform. In some examples, the platform controller is a bus device on a bus such as a Peripheral Component Interconnect (PCI) bus or a PCIe bus. In other examples, the platform controller may be a bus device connected to another type of bus in the computer platform. A "bus" refers to a communication link through which several devices can communicate with each other.

[0028] The platform controller may be separate from the (one or more) main processors of the computer platform. The (one or more) main processors may execute various machine-readable instructions of the system, such as virtual node instances (e.g., container instances and / or VM instances); operating system instances; application instances; firmware (e.g., boot code, hardware initialization code, etc.); and so on. The platform controller may be designated to perform specified tasks of the computer platform, including emulating the PTP clock device, as well as other tasks (e.g., power management tasks, thermal management tasks, system monitoring tasks, etc.). In some examples, the platform controller may be a separate system-on-chip coupled to the (one or more) main processors. In a more specific example, the platform controller may be made of an intelligent network interface controller (NIC) or be part of a baseboard management controller (BMC). The platform controller may have its own processing circuitry (separate from the (one or more) main processors that execute the operating system and / or other program code of the computer system) and run its own firmware. The BMC is a dedicated service processor that can monitor the physical state of the computer platform using sensors. The BMC can communicate with a management system through an independent out-of-band connection (e.g., communicate with a remote management server).

[0029] The BMC can also communicate with applications running at the operating system level through the following: an Input / Output Controller (IOCTL) interface driver, a Representational State Transfer (REST) Application Programming Interface (API), or some other system software agent that facilitates communication between the BMC and the application. The BMC can have hardware-level access to hardware components located within the computer platform. The BMC may be able to directly modify the hardware components. The BMC can operate independently of the operating system of the computer platform in which the BMC is set. The BMC can be located on the motherboard or main circuit board of the computer platform to be monitored. The fact that the BMC is installed on the motherboard of the managed computer platform or otherwise connected or attached to the managed computer platform does not prevent the BMC from being considered separate from the processing resources that execute the operating system. The BMC has the management ability to manage the components of the computer platform. Examples of the management ability of the BMC can include any one or some combination of the following: power control, thermal monitoring and control, fan control, system health monitoring, remote access to the computer system, remote restart of the computer system, system settings, operating system image deployment and recovery, system security, and so on.

[0030] In some examples, the BMC can provide a so-called "lights-out" function for the computer platform. Even if no operating system is installed on the computer platform or the operating system is not working, the lights-out function can allow users such as system administrators to perform management operations on the computer platform. In addition, in some examples, the BMC can operate on an auxiliary power source (e.g., battery power or auxiliary power rail). Therefore, the computer platform does not have to be powered on to allow the BMC to perform its operations. The services provided by the BMC can be considered "out-of-band" services because the operating system may not be running. In some cases, when all or part of the rest of the computer platform is powered off or not working properly (e.g., the computer platform has experienced a fault or hardware failure), the BMC can provide out-of-band services via a management channel.

[0031] The platform controller can be part of an entity other than a bus device or the BMC. For example, the platform controller can be a chassis management controller. Regardless of its specific form, according to an example embodiment, the platform controller provides a separate physical processor (separate from the (multiple) main processors of the computer platform), and in the separate physical processor, PTP clock device emulation can be provided in a secure manner. For example, according to an example embodiment, the platform controller is protected from attacks that may affect the operation of the (multiple) main processors, such as when malware infects the computer platform and executes on the (multiple) main processors.

[0032] Offloading the PTP clock device emulation to the platform controller reduces the overhead otherwise incurred by the host processor for generating the virtual PTP clock device. According to an example embodiment, a portion of the PCI memory is allocated to include information elements individually associated with respective virtual node instances (e.g., VM instances or container instances). According to an example embodiment, the information element can be a register or a register bank. Each register bank includes registers that can be accessed to transfer messages related to synchronizing the clock of the virtual node instance with the respective virtual PTP clock device. The platform controller can detect access to the registers in the portion of the PCI memory, which allows the platform controller to generate an appropriate response to emulate the PTP clock device.

[0033] Reference Figure 1 , as a more specific example, according to some embodiments, the computing system 99 can include one or more computer platforms 100. According to some embodiments, the computer platform 100 can be part of a computer network. According to further embodiments, the computer platform 100 can be a stand-alone platform. For Figure 1 the example embodiment depicted in, the computing system 99 is a cloud computing system, and the one or more computer platforms 100 form corresponding domain nodes of the cloud computing system. According to an example embodiment, the computer platform 100 can be one of a plurality of cloud resources 188 that are interconnected with each other and interconnected to one or more clients 186 (i.e., clients associated with cloud tenants) via a network fabric 180.

[0034] Generally, the network fabric 180 can be associated with one or more types of communication networks such as (by way of example) a Fibre Channel network, a Gen-Z fabric, a dedicated management network, a local area network (LAN), a wide area network (WAN), a global network (e.g., the Internet), a wireless network, or any combination thereof.

[0035] As used herein, a "computer platform" refers to a modular unit that includes a frame or chassis. Additionally, the modular unit can include hardware that is mounted to the chassis and capable of executing machine-executable instructions. According to an example embodiment, a blade server is an example of the computer platform 100. However, according to further embodiments, the computer platform 100 can be any of a plurality of different platforms other than blade servers, such as rack-mounted servers, clients, desktop computers, smart phones, laptop computers, tablet computers, modular switches, compute nodes, storage arrays, cluster nodes, wearable computers, and so on.

[0036] According to an example embodiment, the computer platform 100 includes N virtual node instances, where "N" is an integer greater than or equal to one. By way of example, the virtual node instance can be a VM instance. Figure 1Specifically depict VM instances 101-1 to VM instances 101-N. It should be noted that although the following discussion describes an example implementation where the virtual node instance is a VM instance, according to further implementations, the virtual node instance can be other types of virtual computing environments, such as container instances. According to further example implementations, the computer platform can execute different types of virtual node instances such as VM instances and container instances. Regardless of the specific implementation of the virtual nodes or types of virtual node instances executed on the computer platform, the computer platform includes one or more managers that provide one or more virtual node instances; and the computer platform includes a controller in addition to the (multiple) managers, and the controller provides an emulated PTP clock device for the corresponding (multiple) virtual node instances. For Figure 1 the specific example implementation depicted in, the manager is the hypervisor 106. According to further example implementations, the virtual node instance is a container instance, and the manager can be a container engine daemon. According to yet further example implementations, the virtual node instances can be VM instances and container instances respectively having a manager based on the container engine daemon and a manager based on the hypervisor.

[0037] Referring to Figure 1 the example implementation depicted in, the VM instance 101 can be started on demand by a user or other entity. The computer platform 100 can start with zero VM instances 101 and can start (multiple) additional VM instances 101 upon request. According to an example implementation, each VM instance 101 includes a corresponding guest operating system instance 102 (or "guest operating system"). The guest operating system instance 102 can correspond to a LINUX operating system, a WINDOWS operating system, and / or another type of operating system. Different guest operating system instances 102 can be of the same type or different types. Each VM instance 101 can also include one or more application instances 104 (or "applications 104") executed within the VM instance 101. It should be noted that before the creation of the VM instance 101, there is no guest operating system instance 102 nor application instance 104.

[0038] According to an example implementation, the computer platform 100 includes a hypervisor 106. The hypervisor 106 can generally provide the VM instances 101. In this way, the hypervisor 106 can create the VM instances 101 and manage the execution of the VM instances 101. The hypervisor 106 can emulate the physical resources of the computer platform 100 that can be accessed by the VM instances 101. In addition, the hypervisor 106 can provide isolation between the VM instances 101 and perform various virtualization tasks for the VM instances 101.

[0039] According to an example embodiment, instead of using the hypervisor 106 to emulate a PTP clock device, the PTP clock device emulation is offloaded to the platform controller 108 of the computer platform 100. According to an example embodiment, the platform controller 108 is a bus device on the bus 110 of the computer platform 100. As an example, the bus 110 can be a PCIe bus. According to a further example embodiment, the bus 110 can be a bus type other than a PCIe bus. Additionally, according to a further embodiment, the platform controller 108 can be coupled to a communication fabric other than a bus.

[0040] The platform controller 108 can be implemented using any type of hardware processing circuitry, including, for example, hardware processing circuitry that includes one or more microcontrollers, one or more programmable integrated circuit devices (e.g., one or more ASICs, one or more programmable gate arrays, one or more microprocessor processing cores, etc.).

[0041] In some examples, the platform controller 108 is separate and distinct from one or more main processors 112 of the computer platform 100. The main processors 112 can include one or more microprocessors; one or more cores of a multi-core microprocessor; one or more microcontrollers; one or more programmable integrated circuits; one or more programmable gate arrays; one or more digital signal processors; one or more other hardware processing circuits; etc.

[0042] Generally, according to a particular embodiment, the platform controller 108 can adopt one of many different architectures. As an example, the platform controller 108 can be part of a smart NIC, a smart input / output (I / O) peripheral, a BMC, a chassis management controller, etc. Regardless of its particular embodiment, the platform controller 108 is separate from the main processor(s) 112 and performs a designated task in the computer platform 100.

[0043] (The) main processor(s) 112 are directly or indirectly coupled to the bus 110 through another device such as a bridge device. According to an example embodiment, (the) main processor(s) 112 execute machine-readable instructions of the computer platform 100, which include instructions for forming the hypervisor 106, instructions for forming the VM instance 101, instructions for forming the host operating system (if present), and other instructions associated with other software programs and / or firmware programs.

[0044] As Figure 1Depicted, according to an example embodiment, (multiple) main processors 112 may be coupled to system memory 113. System memory 113 is a non-transitory storage medium and may include one or more memory devices for storing data and machine-readable instructions. The memory devices may include volatile memory devices such as dynamic random access memory (DRAM) devices; static random access memory (SRAM) devices; and so on. Alternatively, the memory devices may include non-volatile memory devices. Although not shown, system memory 113 may include a memory controller, or alternatively, a memory controller may be connected to the (multiple) memory devices to control access to data in the (multiple) memory devices.

[0045] According to an example embodiment, devices of computer platform 100 other than (multiple) main processors 112 and platform controller 108 may be coupled to bus 110. For example, according to some embodiments, one or more network interface controllers (NICs) 129 and persistent storage 132 may be coupled to bus 110. According to an example embodiment, components of computer platform 100 (including VM instance 101) communicate with entities external to computer platform 100 of computing system 99 using NIC 129. According to some embodiments, components of computer platform 100 (including VM instance 101) may communicate with entities of computing system 99 using passthrough communication via one or more NICs 130 of platform controller 108.

[0046] Persistent storage 132 may store data that remains even when power is removed from computer platform 100 or from persistent storage 132. Persistent storage 132 may be implemented using non-volatile storage devices (or multiple non-volatile storage devices). The non-volatile storage devices may include flash memory devices, disk-based storage devices, and so on.

[0047] According to an example embodiment, platform controller 108 performs PTP clock device emulation using PCI function 114. Figure 1 Depicted are N PCI functions 114 ( Figure 1 depicted therein are PCI functions 114-1 to 114-N), and according to an example embodiment, hypervisor 106 may dispatch PCI functions 114 to each VM instance 101. According to an example embodiment, hypervisor 106 may dispatch several PCI functions 114 to a given VM instance 101. As Figure 1 depicted, according to an example embodiment, PCI function 114 includes a corresponding virtual PTP clock device (vPTPCD) 128 (in Figure 1Depicted as N vPTPCDs 128-1 to 128-N provided via PCI functions 114-1 to 114-N, respectively.

[0048] A PTP leader (e.g., vPTPCD 128) may transmit a message sequence to a PTP follower (e.g., VM instance 101) to synchronize the clock of the PTP follower with the clock of the PTP leader. According to an example embodiment, the message sequence includes an initial synchronization message. More specifically, according to an example embodiment, the PTP leader reads its clock value, generates a synchronization message containing the read clock value, and transmits the synchronization message. The synchronization message is received by the PTP follower, and in response to receiving the synchronization message, the PTP follower records a timestamp (referred to herein as the "first timestamp") that represents the time when the PTP follower received the synchronization message (as the PTP follower's clock).

[0049] There is a time difference between the time when the PTP leader reads its clock value and the time when the PTP follower receives the synchronization message. This time difference includes two components, and the PTP follower uses the information obtained from the message sequence to determine these components to determine the adjustment to the clock value transmitted via the synchronization message.

[0050] The first component of the time difference is the propagation delay of the communication path between the PTP leader and the PTP follower. The second component of the time difference is the time elapsed from the time when the PTP leader reads its clock value to the time when the PTP leader transmits the synchronization message to the communication path.

[0051] To enable the PTP follower to obtain the second component of the time difference, the message sequence may include a second message called a "follow-up message". The PTP leader transmits the follow-up message. The follow-up message contains data representing a timestamp (referred to herein as the "second timestamp") that indicates the actual time when the PTP leader transmitted the synchronization message to the communication path (as the PTP leader's clock). The PTP follower may determine the second component of the time difference based on the first timestamp (representing the time when the PTP follower received the synchronization message) and the second timestamp (representing the time when the PTP leader transmitted the synchronization message).

[0052] To provide the PTP follower with information for determining the first component of the time difference (i.e., the propagation delay), the message sequence can include two additional messages sent after the synchronization message. More specifically, after receiving the follow-up message, the PTP follower can transmit a delay request message to the PTP leader and record a timestamp (referred to herein as the "third timestamp") that represents the transmission time of the delay request message (as mentioned in terms of the PTP follower's clock). The PTP leader receives the delay request message and records a timestamp (referred to herein as the "fourth timestamp") that represents the time when the delay request message is received (as mentioned in terms of the PTP leader's clock). The PTP leader can then transmit a delay response message to the PTP follower. The delay response message contains data representing the fourth timestamp. The PTP follower can determine the second component of the time difference (i.e., the propagation delay) based on the third timestamp and the fourth timestamp.

[0053] When the PTP follower determines the time difference between the time when the PTP leader reads its clock value and the time when the PTP follower receives the synchronization message, the PTP follower can then obtain an adjustment made to the PTP follower's clock based on the PTP leader's clock value and the time difference, so as to synchronize the PTP follower's clock to the PTP leader's clock.

[0054] According to a further embodiment, to synchronize the PTP follower's clock to the PTP leader's clock, the PTP follower and the PTP leader can transmit messages other than the message sequence described herein.

[0055] In the context used herein, "synchronizing" a first clock to a second clock means performing one or more actions to coordinate the first clock with the second clock. Synchronization may or may not result in the first clock and the second clock being exactly the same, and furthermore, after synchronization, the first clock and the second clock may deviate (or deviate further). According to an example embodiment, the PTP follower can synchronize its clock with the PTP leader's clock periodically (e.g., periodically). In this way, according to some embodiments, the PTP leader can initiate a message sequence corresponding to clock synchronization at fixed time intervals, where each message sequence starts with the PTP leader transmitting a synchronization message and ends with the PTP leader transmitting a delay response message.

[0056] According to some embodiments, the message sequence transmitted between the PTP leader and the PTP follower may follow the protocol described in the IEEE 1588-2019 standard released in 2020. According to further embodiments, the message sequence transmitted between the PTP leader and the PTP follower may follow a protocol according to an IEEE 1588 standard version other than the IEEE 1588-2019 standard. Additionally, according to still further embodiments, the message sequence transmitted between the PTP leader and the PTP follower may follow a protocol other than a protocol based on the IEEE 1588 standard.

[0057] According to an example embodiment, the computing system 99 may include an actual or physical PTP leader clock device 184. According to some embodiments, the PTP leader clock device 184 may be the primary PTP leader of a corresponding PTP clock hierarchy. For example, according to some embodiments, the PTP leader clock device 184 may include a GNSS radio for receiving GNSS signals indicating the time of day, and the PTP clock device 184 sets its clock, the primary clock, to this time. As another example, the PTP leader clock device 184 may include an RF radio that receives a signal (e.g., a frequency modulation (FM) signal corresponding to a dedicated FM channel) to synchronize the primary clock of the PTP leader clock device 184 to an atomic clock. According to some embodiments, the PTP leader clock device 184 may be a network component such as a network switch (e.g., a top-of-rack (ToR) switch), which may be part of the network fabric 180. According to a further example embodiment, the PTP leader clock device 184 may be a boundary node of a clock hierarchy that synchronizes its clock to another PTP leader. Additionally, according to further embodiments, the PTP leader clock device 184 may be a device of the computer platform 100 (e.g., a bus device such as a PCIe bus device).

[0058] According to an example embodiment, the vPTPCD 128 serves as a boundary node of the PTP clock hierarchy. In this way, according to an example embodiment, the vPTPCD 128 acts as a PTP follower that transmits messages with the PTP leader clock device 184 to synchronize the clock of the vPTPCD 128 with the clock of the PTP leader clock device 184. Additionally, the vPTPCD 128 serves as a PTP leader to transmit messages with a given VM instance 101 to synchronize the clock of the VM instance 101 with the clock of the vPTPCD 128.

[0059] Figure 2 Further details of the platform controller 108 according to an example embodiment are depicted. In conjunction with Figure 1Reference Figure 2 According to an example embodiment, the PCI function 114 is implemented as a virtual function (VF) 150 (or "virtual function instance"). Figure 2 Depicts N virtual functions 150-1 to 150-N. According to an example embodiment, the VF 150 is based on PCIe single root I / O virtualization (SR-IOV) as defined by the PCI Special Interest Group (SIG), which is a group that defines standards related to PCIe (including the SR-IOV specification).

[0060] According to an example embodiment, each VF 150 includes a corresponding vPTPCD 128. Additionally, according to an example embodiment, each VF 150 can be assigned to a corresponding single VM instance 101. For example, vPTPCD 128-1 emulates a PTP clock device for VM101-1, and vPTPCD 128-N emulates a PTP clock device for VM 101-N. According to a further example embodiment, a given VF 150 can be assigned to several VM instances 101.

[0061] According to a further example embodiment, one or more PCI functions 114 can be implemented as functions other than virtual functions (e.g., physical PCI functions).

[0062] SR-IOV allows a PCIe device (such as the vPTPCD 128 implemented by the platform controller 108) to present itself as several different virtual devices to a host (e.g., the computer platform 100). The PCIe device (e.g., the platform controller 108) implements a PCIe physical function (PF) 252, which is divided into several VFs 150 (e.g., for the example embodiment depicted in Figure 2 N VFs 150-1 to 150-N) to share the resources of the PCIe device in a virtual environment.

[0063] The PF 252 provides control over the creation and assignment of the VFs 150. The PF 252 includes an SR-IOV capability structure, and the PF252 manages the SR-IOV function. According to an example embodiment, the PF 252 can be discovered, managed, and manipulated like any other PCIe device in the computer platform 100. According to an example embodiment, the VFs 150 share the underlying hardware of the platform controller and the PCIe interface to the PCI bus 110.

[0064] As Figure 2Depicted in [description], according to an example embodiment, platform controller 108 includes one or more processors 254 and a memory 256. The (multiple) processors 254 are configured to execute instructions 257 of the platform controller 108 (e.g., instructions stored in the memory 257) to perform tasks of the platform controller 108. According to an example embodiment, the (multiple) processors 254 may include one or more processing cores, one or more microcontrollers, one of multiple ASICs, one or more programmable gate arrays, and the like. The memory 256 is a non-transitory storage medium and may include one or more memory devices for storing data and machine-readable instructions. Although not shown, the memory 256 may include a memory controller, or alternatively, the memory controller may be connected to the (multiple) memory devices to control access to data in the (multiple) memory devices.

[0065] According to an example embodiment, the platform controller 108 is a PTP follower, and the platform controller 108 synchronizes its system clock 260 to the clock of a PTP leader. More specifically, according to an example embodiment, the (multiple) processors 254 execute instructions (e.g., a subset of the instructions 257) for transmitting PTP messages via a network port 258 (e.g., an Ethernet port) of the platform controller's NIC 130 to a PTP leader clock device 184 ( Figure 1 ) to synchronize the system clock 260 to the clock of the PTP leader clock device 184. Thus, in response to the transmission of PTP messages with the PTP leader clock device 184, the platform controller 108 calibrates its system clock 260 at certain adjustment times. According to a further embodiment, instead of or in combination with the execution of instructions, the hardware of the platform controller 108 may transmit PTP messages with the PTP leader clock device 184. According to an example embodiment, in response to a VM instance 101 reading the clock register of the vPTPCD 128 (e.g., in response to a read request for the clock register from the VM instance 101), the platform controller 108 reads the current value of the system clock 260, adjusts the value based on the number of platform controller clock ticks since the last adjustment time, and returns the clock value to the VM instance 101 representing the PTP clock time. According to a particular embodiment, the platform controller 108 may perform these actions by executing instructions, using the hardware of the platform controller 108, or via a combination of instruction execution and hardware.

[0066] According to an example embodiment, SR-IOV enables the activation of PTP clock devices performed by VM instance 101 to bypass the emulation layer in hypervisor 106. The VFs 150 according to SR-IOV are lightweight, enabling a large number of VFs 150 to be implemented in platform controller 108. For example, if computer platform 100 includes a large number of VM instances 101, a corresponding large number of VFs 150 can be implemented on platform controller 108 to perform PTP clock device emulation for the corresponding VM instances 101.

[0067] A device supporting SR-IOV (e.g., platform controller 108) can be configured (e.g., by hypervisor 106 or another entity of computer platform 100) to appear in the PCI memory space as several VFs 150, where each VF 150 has its own PCI memory space. The PCI memory can refer to a portion of the memory space in computer platform 100 that includes structures that can be used by an entity of computer platform 100 (e.g., VM instance 101 or any other entity) to interact with a corresponding PCI device such as any VF 150.

[0068] According to an example embodiment, for performing PTP clock device emulation, each VF 150 has a class code representing a PTP clock device. According to PCI, the class code is a three-byte field in the configuration space header of a function, and the configuration space header of the function identifies the functionality of the function. For example, the class code can include a base class subfield (e.g., one byte in length), a subclass subfield (e.g., one byte in length), and a programming interface subfield (e.g., one byte in length). The base class subfield broadly classifies the type of function provided by VF 150. The subclass subfield more specifically identifies the type of function provided by VF 150. The programming interface subfield identifies the specific register-level interface (if any) of VF 150, enabling device-independent software (e.g., a VM) to interact with VF 150.

[0069] According to an example embodiment, in hypervisor 106, instead of emulating a PTP clock device at a specific memory space address, each VM instance 101 can be assigned its corresponding VF 150. Thus, according to a particular embodiment, several VM instances 101 can share a VF 150, or a VM instance 101 can have its own VF 150.

[0070] Figure 3 Depicts the memory address space 318 of computer platform 100 according to an example embodiment. In conjunction with Figure 1 and Figure 2 reference Figure 3, According to some embodiments, the VM instance 101 can identify that the VF 150 is providing the function of a PTP clock device based on the base class sub - fields and the subclass sub - fields together. The programming interface sub - field can identify the PTP clock device information element. According to an example embodiment, the information element can be a register or several registers such as the PTP clock device register group 316. Figure 3 Depicts N PTP clock device register groups 316 - 1 to 316 - N. In this way, the VM instance 101 can read the PTP clock value from the registers of the PTP clock device register group 316, and the platform controller 108 synchronizes the PTP clock value with the clock of a PTP leader such as the PTP leader clock device 184 ( Figure 1 ), as described herein.

[0071] According to an example embodiment, the PTP clock device register group 316 is part of the corresponding vPTPCD 128. The PTP clock device register group 316 in the corresponding vPTPCD 128 is mapped to the memory address space 318, and more specifically, to the PCI memory in the memory address space 318. The memory address space 318 can be implemented with multiple storage devices in the computer platform 100, and the multiple storage devices include Figure 1 the system memory 113, registers in the platform controller 108, and so on. According to an example embodiment, the PTP clock device register group 316 includes memory - mapped registers that are part of the memory address space 318.

[0072] According to a further example embodiment, such as in the example where the function 114 is a PF, the PTP clock device register group 316 can be part of the I / O address space of the computer platform 100.

[0073] The memory addresses of the memory address space 318 can be mapped to the memory controller and / or the PCIe controller. The memory controller is connected to a memory device (or alternatively, multiple memory devices). The memory device can include volatile memory devices (e.g., dynamic random - access memory or DRAM devices, static random - access memory or SRAM devices, etc.). Alternatively, the memory device can include non - volatile memory devices (e.g., flash memory devices, etc.). The PCIe controller is connected to PCIe devices. The PCIe devices can support memory access, but these devices may not actually access memory devices such as DRAM or SRAM. Instead, the PCIe devices can access the memory - mapped registers that are part of the memory address space 318.

[0074] According to an example embodiment, the starting address (or base address) of the PCI memory space of each PTP clock device register group 316 is based on the memory address included in the PCI base address register (BAR) 220 ( Figure 2 ) in the PCI configuration space. The PCI BAR 220 is included in the PF 252, as Figure 2 depicted. PCI defines several BARs that can be used to hold multiple memory addresses for a PCI device or function.

[0075] Figure 3 Illustrates N example base addresses 360-1 to 360-N of the corresponding PTP clock device register group 316. According to an example embodiment, the base address 360 is obtained based on the memory address included in the BAR 220 ( Figure 2 ), and the hypervisor 106 writes the memory address to the BAR 220. The memory address included in the BAR 220 defines a block of PCI memory space to be evenly divided across the VFs 150. The defined block of PCI memory space has a size BARSIZE. Each VF 150 can be assigned a portion of the block of PCI memory space with a size of BARSIZE / N (where "N" is the number of VFs 150). The base address 360 of the PCI memory containing a given PTP clock device register group 316 is calculated based on the VF number of the corresponding VF 150 in combination with the memory address included in the BAR 220.

[0076] In combination Figure 2 with reference to Figure 1 , according to an example embodiment, the PTP clock device driver 122 ( Figure 1 ) in the VM instance 101 or another program can access the PCI memory space of the corresponding VF 150. According to an example embodiment, each guest operating system 102 may include the PTP clock device driver 122. According to some embodiments, the guest operating system 102 in the VM instance 101 may include an application programming interface (API) that allows the PTP clock device driver 122 of the VM instance 101 to access the PCI memory space of the corresponding VF 150.

[0077] After enabling SR-IOV in PF 252 of platform controller 108, VF 150 can be enumerated by configuration software running on host processor 112 and can be accessed by the bus, device, and function. The configuration software (which is the hypervisor 106 in some examples) can then configure a desired number of VFs 150 from the VFs supported by PF 252 and thus allocate resources (i.e., allocate a portion of memory space 318 for VF 150 by programming BAR 220). Once complete, the PTP clock device register set 316 can be addressed by processor 112.

[0078] In conjunction Figure 3 with reference Figure 1 , according to an example embodiment, the PTP clock device driver 122 of the guest operating system 102 is able to query the hypervisor 106 to obtain the corresponding base address 360 of the PTP clock device register set 316 of the corresponding vPTPCD 128. This allows the PTP clock device driver 122 of the guest operating system 102 to communicate with the vPTPCD 128 to synchronize the clock of the VM instance 101 to the clock of the vPTPCD 128.

[0079] In an example where the guest operating system 102 cannot automatically detect the PTP clock device (e.g., the guest operating system 102 cannot recognize the base class / subclass / programming interface values of the PTP clock device discussed above), the address of the PTP clock device can be provided to the guest operating system 102 in a different manner. An example of a guest operating system that cannot automatically detect a PCI PTP clock device is the LINUX operating system. According to an example embodiment, by including the address in the kernel command line used to boot the guest operating system 102, the address of the PTP clock device can be provided to the guest operating system 102. According to a further embodiment, other means can be used to provide the address of the PTP clock device to the guest operating system 102.

[0080] According to an example embodiment, each vPTPCD 128 can include write detection logic for detecting writes to the corresponding PTP clock register set 316 and / or read detection logic for detecting reads from the corresponding PTP clock register set 316. The write detection logic is capable of detecting writes by the VM instance 101 or other entity to the PTP clock device register set 316 of the corresponding vPTPCD 128. The VM instance 101 writing to a register in the PTP clock device register set 316 can be performed as part of PTP message passing. For example, the VM instance 101 can write to a register to send a PTP delay request message to the vPTPCD 128.

[0081] The reading of the registers of the PTP clock device register bank 316 can also be performed as part of PTP message passing. For example, VM instance 101 can read from the registers to receive messages such as PTP synchronization messages, PTP follow-up messages, and PTP delay response messages sent by vPTPCD 128.

[0082] In combination Figure 1 with reference Figure 2 , in response to a write or read, the write detection logic or read detection logic in vPTPCD 128 can signal an interruption to the processor 254 of the platform controller 108, such as using the corresponding PTP clock device indication 224 ( Figure 2 depicted in the figure as PTP clock device indications 224-1 through 224-N). The PTP clock device indication 224 can indicate which register in the registers of the PTP clock device register bank 316 has been written or read. The PTP clock indication 224 can include a signal, an interruption, a command, or any other indication related to PTP synchronization message passing operations, or generally operations related to communication with vPTPCD 128. The PTP clock device indication 224 can include information identifying the associated VF 150 and the register where the read / write occurred.

[0083] In response to the PTP clock device indication 224, machine-readable instructions (e.g., firmware) running on the processor 254 can synthesize an appropriate response for the corresponding vPTPCD 128. According to a further embodiment, the platform controller 108 includes hardware that synthesizes a response under the orchestration of machine-readable instructions (e.g., firmware) running on the processor 254. For example, data transmitted from the PTP clock device driver 122 can be intercepted by vPTPCD 128 and directly placed into a circular buffer (or other storage structure) associated with the VM instance 101.

[0084] Other embodiments within the scope of the appended claims are envisioned. For example, returning to reference Figure 2, According to a further embodiment, the platform controller 108 may synchronize its system clock 260 to a clock source other than the PTP leader. As a more specific example, according to some embodiments, the platform controller 108 may include a GNSS receiver that receives GNSS signals (e.g., a composite signal representing transmissions received from several GNSS satellites). The platform controller 108 may process the GNSS signals to synchronize the clock 260 to the satellite clock of the nearest satellite. This processing may involve, for example: the platform controller 108 decoding the GNSS signals into content attributable to several satellites; the platform controller 108 determining the physical location of the GNSS receiver and identifying the nearest satellite based on the decoded content; the platform controller 108 determining the satellite clock value provided by the nearest satellite based on the decoded content; and the platform controller 108 compensating for the delay associated with the satellite clock value. For these example embodiments, the platform controller 108 may be considered the PTP leader. According to a further embodiment, the platform controller 108 may communicate with an NTP provider (e.g., an NTP server) to use NTP to synchronize the clock 260 to the clock of the NTP provider. For these example embodiments, the platform controller 108 is an NTP client, and the platform controller 108 is the PTP leader for the vPTPCD 128.

[0085] Reference Figure 4 , According to an example embodiment, the apparatus 400 includes: a storage medium 404; a manager 412; and a controller 416. According to an example embodiment, the manager 412 may be a super manager such as Figure 1 the super manager 106 or a container engine daemon, etc. As an example, the controller 416 may be a platform controller such as Figure 1 and Figure 2 the platform controller 108. The storage medium 404 stores a plurality of information elements 408. As an example, the information element 408 may be a corresponding register or register group such as Figure 3 the PTPCD register group 316. The manager 412 provides a plurality of virtual nodes. As an example, the virtual nodes may be virtual machine instances such as Figure 1 the VM instance 101 and / or container instances. The controller 416 is separate from the manager 412. The controller 416 is configured to provide a plurality of virtual PTP clock devices, such as Figure 1 and Figure 2 the vPTPCD 128. Each virtual PTP clock device corresponds to an information element 404. The controller 416 uses the information element 404 corresponding to a given virtual PTP clock device to provide PTP-based time for the given virtual PTP clock device.

[0086] Reference Figure 5, according to an example embodiment, the non-transitory machine-readable storage medium 500 stores machine-executable instructions 504. When executed by a machine, the instructions 504 cause the machine to store information indicating the address locations of the register sets of a plurality of virtual PTP clock devices. As an example, the register set may be the Figure 3 PTPCD register set, and the virtual PTP clock devices may be the Figure 1 and Figure 2 vPTPCD 128. The virtual PTP clock devices are provided by a controller and are associated with a plurality of virtual nodes. As an example, the controller 416 may be a platform controller such as the Figure 1 and Figure 2 platform controller 108. As an example, the virtual nodes may be virtual machine instances such as the Figure 1 VM instance 101 and / or container instances. When executed by a machine, the instructions 504 further cause the machine to execute the virtual nodes to access the virtual PTP clock devices using the information. A given virtual machine communicates with a given virtual PTP clock device to read the clock value provided by the given virtual PTP clock device.

[0087] Reference Figure 6 , according to an example embodiment, the process 600 includes a manager in a system including a hardware processor dispatching (block 604) virtual functions to corresponding virtual nodes. As an example, the manager may be a container engine daemon or a super manager such as the Figure 1 super manager 106. Figure 1 The processor 112 is an example of a hardware processor. The virtual function may be a PCI virtual function such as the Figure 2 virtual function 150. As an example, the virtual nodes may be virtual machine instances such as the Figure 1 VM instance 101 or container instances. The virtual function represents a corresponding PTP clock device. As an example, the PTP clock device may be a virtual clock device such as the Figure 1 and Figure 2 vPTPCD clock device 128. The virtual function is provided by a controller separate from the manager. The process 600 further includes executing (block 608) the virtual nodes in the system to access the corresponding PTP clock devices using the information indicating the addresses of the corresponding virtual functions. As an example, the information may be information provided by a register or a register set such as the Figure 3 register set 316. A given virtual node communicates with a given corresponding PTP clock device to read the clock value provided by the given corresponding PTP clock device.

[0088] According to an example embodiment, the virtual nodes may be virtual machines or containers. Specific advantages may include a reduction in main processing overhead and a reduction in the security attack surface.

[0089] According to an example embodiment, the controller includes a clock. The controller communicates with a Precision Time Protocol (PTP) leader clock device to synchronize the controller's clock to the clock of the PTP leader clock device. The controller provides PTP-based time based on the value of the controller's clock. Specific advantages can include a reduction in main processing overhead and a reduction in the security attack surface.

[0090] According to an example embodiment, the PTP leader clock device is part of a network switch. Specific advantages can include a reduction in main processing overhead and a reduction in the security attack surface.

[0091] According to an example embodiment, the controller synchronizes the controller's clock at an adjustment time. A given virtual node is used to read a register of the controller corresponding to a given virtual PTP clock device and in response to the reading of the register. The controller adjusts the value of the controller's clock based on the most recent adjustment time in the adjustment time in response to the reading to provide an adjusted clock value, and provides the adjusted clock value to the given virtual node. Specific advantages can include a reduction in main processing overhead and a reduction in the security attack surface.

[0092] According to an example embodiment, the controller transmits a message to a PTP leader device. The message includes a synchronization message provided by the PTP leader device. The synchronization message includes data representing the clock value of the PTP leader device and a first timestamp associated with the clock value of the PTP leader device. Specific advantages can include a reduction in main processing overhead and a reduction in the security attack surface.

[0093] According to an example embodiment, the message further includes a follow-up message and a delay request message. The follow-up message is provided by the PTP leader device, and the follow-up message includes data representing the time at which the given PTP leader device transmitted the synchronization message. The delay request message is provided by the controller, and the delay request message includes data representing the time at which the controller transmitted the delay request message. Specific advantages can include a reduction in main processing overhead and a reduction in the security attack surface.

[0094] According to an example embodiment, the controller includes a Global Navigation Satellite System (GNSS) receiver for receiving GNSS signals. The controller provides PTP-based time based on the GNSS signals. Specific advantages can include a reduction in main processing overhead and a reduction in the security attack surface.

[0095] According to an example embodiment, each of a plurality of information elements corresponds to one of a plurality of register groups. The plurality of register groups are in a memory address space of a computer platform. Specific advantages can include a reduction in main processing overhead and a reduction in the security attack surface.

[0096] According to an example embodiment, the information element includes a base address register. Each base address register contains a memory address for obtaining the address of a corresponding virtual PTP clock device. Specific advantages may include a reduction in main processing overhead and a reduction in the security attack surface.

[0097] According to an example embodiment, the manager includes one of a hypervisor or a container engine, and the controller includes a baseboard management controller. Specific advantages may include a reduction in main processing overhead and a reduction in the security attack surface.

[0098] According to an example embodiment, each virtual Precision Time Protocol clock device corresponds to a different virtual function among a plurality of virtual functions, and the controller provides the plurality of virtual functions. Specific advantages may include a reduction in main processing overhead and a reduction in the security attack surface.

[0099] According to an example embodiment, the manager is configured to dispatch a given virtual machine to a virtual function corresponding to a given virtual PTP clock device. Specific advantages may include a reduction in main processing overhead and a reduction in the security attack surface.

[0100] According to an example embodiment, the controller includes a clock. The controller communicates with a Network Time Protocol (NTP) provider to synchronize the controller's clock with the NTP provider's clock. The controller provides a Precision Time Protocol-based time based on the value of the controller's clock. Specific advantages may include a reduction in main processing overhead and a reduction in the security attack surface.

[0101] According to an example embodiment, the manager is configured to associate a plurality of virtual PTP clock devices with a given virtual node. Specific advantages may include a reduction in main processing overhead and a reduction in the security attack surface.

[0102] According to an example embodiment, a plurality of virtual Precision Time Protocol clock devices correspond to one virtual function, and the controller provides the one virtual function. Specific advantages may include a reduction in main processing overhead and a reduction in the security attack surface.

[0103] Although the present disclosure has been described with respect to a limited number of embodiments, those skilled in the art who benefit from the present disclosure will appreciate many modifications and variations of the present disclosure. The appended claims are intended to cover all such modifications and variations.

Claims

1. An electronic device, comprising: A storage medium for storing a plurality of information elements; A manager for providing a plurality of virtual nodes; And A controller separate from the manager, the controller for providing a plurality of virtual Precision Time Protocol (PTP) clock devices, wherein: Each of the plurality of virtual PTP clock devices corresponds to an information element among the plurality of information elements; The controller is configured to use the information element corresponding to a given virtual PTP clock device among the plurality of virtual PTP clock devices to provide PTP-based time for the given virtual PTP clock device; and The controller providing the PTP-based time includes a sequence of PTP-based messages transmitted by the given virtual PTP clock device and with a given virtual node among the plurality of virtual nodes to synchronize the clock of the given virtual node with the PTP-based time.

2. The electronic device according to claim 1, wherein The plurality of virtual nodes includes at least one of a plurality of virtual machines or a plurality of containers.

3. The electronic device according to claim 1, wherein: The controller includes a clock; The controller is configured to communicate with a PTP leader clock device to synchronize the clock of the controller to the clock of the PTP leader clock device; And The controller is configured to provide the PTP-based time based on the value of the clock of the controller.

4. The electronic device according to claim 3, wherein, The PTP leader clock device is part of a network switch.

5. The electronic device according to claim 3, wherein: The controller is configured to adjust the clock of the controller during time adjustment; The given virtual node is configured to read a register of the controller, the register of the controller corresponding to the given virtual PTP clock device and in response to the reading of the register; And The controller is configured to, in response to the reading, adjust the value of the clock of the controller based on the most recent adjustment time among the adjustment times to provide an adjusted clock value, and provide the adjusted clock value to the given virtual node.

6. The electronic device according to claim 3, wherein, The controller transmits a message to the PTP leader device, the message including a synchronization message provided by the PTP leader device, and the synchronization message including data representing the clock value of the PTP leader device and a first timestamp associated with the clock value of the PTP leader device.

7. The electronic device according to claim 6, wherein, The message further includes: A follow-up message provided by the PTP leader device, the follow-up message including data representing the time when the given PTP leader device transmits the synchronization message; and A delay request message provided by the controller, the delay request message including data representing the time when the controller transmits the delay request message.

8. The electronic device according to claim 1, wherein: The controller includes a GNSS receiver for receiving Global Navigation Satellite System (GNSS) signals; and the controller is configured to provide the Precision Time Protocol (PTP)-based time based on the GNSS signals.

9. The electronic device according to claim 1, wherein, Each of the plurality of information elements corresponds to a register group among a plurality of register groups, and the plurality of register groups are in a memory address space of a computer platform.

10. The electronic device according to claim 1, wherein, The plurality of information elements includes a plurality of base address registers, wherein each of the plurality of base registers contains a memory address for obtaining an address of a corresponding virtual Precision Time Protocol clock device.

11. The electronic device according to claim 1, wherein, The manager includes one of a hypervisor or a container engine, and the controller includes a baseboard management controller.

12. The electronic device according to claim 1, wherein, Each of the plurality of virtual Precision Time Protocol (PTP) devices corresponds to a different virtual function among a plurality of virtual functions, and the controller provides the plurality of virtual functions.

13. The electronic device according to claim 1, wherein: the controller includes a clock; the controller communicates with a Network Time Protocol (NTP) provider to synchronize the clock of the controller with the clock of the NTP provider; and the controller is configured to provide the Precision Time Protocol (PTP)-based time based on a value of the clock of the controller.

14. The electronic device according to claim 1, wherein, The manager is configured to associate a plurality of virtual Precision Protocol clock devices with the given virtual node.

15. The electronic device according to claim 1, wherein, A plurality of the virtual Precision Time Protocol clock devices among the plurality of virtual Precision Time Protocol devices correspond to one virtual function, and the controller provides the one virtual function.

16. A non-transitory machine-readable storage medium storing machine-executable instructions that, when executed by a machine, cause the machine to perform the following operations: Store information indicating the address locations of register sets for multiple virtual Precision Time Protocol clock devices, where The virtual Precision Time Protocol clock device is provided by a controller and associated with a plurality of virtual nodes; and execute the plurality of virtual nodes to access the plurality of virtual Precision Time Protocol clock devices using the information, wherein a given virtual node among the plurality of virtual nodes is configured to transmit a sequence of Precision Time Protocol (PTP)-based messages with a given virtual Precision Time Protocol clock device among the virtual Precision Time Protocol clock devices to synchronize the clock of the given virtual node with the Precision Time Protocol (PTP)-based time.

17. The storage medium according to claim 16, wherein, The information includes the memory address of the register group.

18. The storage medium according to claim 16, wherein, The plurality of virtual Precision Time Protocol clock devices includes a plurality of virtual machines or a plurality of containers.

19. A method for a virtual node, comprising: dispatching, by a manager in a system including a hardware processor, a virtual function to a corresponding virtual node among a plurality of virtual nodes, wherein the virtual function represents a corresponding Precision Time Protocol clock device, and the virtual function is provided by a controller separate from the manager; and Execute the plurality of virtual nodes in the system to access the respective Precision Time Protocol (PTP) clock devices using information indicating the addresses of the respective PTP clock devices, wherein a given virtual node among the plurality of virtual nodes is used to transmit a sequence of messages based on the Precision Time Protocol with a given respective PTP clock device among the respective PTP clock devices to synchronize the clock of the given virtual node with the Precision Time Protocol-based time.

20. The method according to claim 19, wherein, The plurality of virtual nodes includes at least one of a plurality of virtual machines or a plurality of containers.

Citation Information

Patent Citations

  • Virtual machine time synchronization method and device

    CN108829493A

  • Clock synchronization method of virtual machine and cloud platform

    CN113489563A