A device virtualization method, system, terminal and storage medium across bus domains

By using connection bridges and control bridges between hosts for address translation and access request forwarding, the problem of device virtualization method application scenarios is limited to a single bus domain and a low security in device access across bus domains, and device virtual and secure device access across bus domains is achieved.

CN118445223BActive Publication Date: 2025-05-13SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410549431.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-06
Publication Date
2025-05-13
Estimated Expiration
2044-05-06

AI Technical Summary

Technical Problem

The application scenarios of device virtual methods in the prior art are limited to a single PCIe bus domain, and the device access method across the PCIe bus domain is relatively low in security.

Method used

By obtaining access requests for the terminal devices corresponding to the connection bridge in the borrower host, the access request is obtained and address translation is performed. Through the connection bridge and control bridge in the lender host, the update access request is forwarded to the virtual device, realizing device virtualization across the bus domain, and improving the security of device access through the control bridge.

Benefits of technology

Device virtualization across the bus domain is implemented, allowing the borrower host to use virtualized devices in other bus domains like using its own devices, and improve the security of device access through the control bridge.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118445223B_ABST
    Figure CN118445223B_ABST
Patent Text Reader

Abstract

The present invention discloses a device virtualization method, system, terminal and storage medium across bus domains, and relates to the field of device virtualization technology. The present invention connects the bus domains corresponding to two host machines respectively through a connection bridge, so that the borrowing host machine can access the virtualized device of the lending host machine through its own virtualized device, thereby realizing device virtualization across bus domains. A control bridge is used to connect the bus of the virtualized device and the lending host machine to avoid direct access to the virtualized device, realize further control of the virtualized device, and improve the security of device access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of device virtualization, and in particular to a method, system, terminal and storage medium for cross-bus domain device virtualization. Background Art

[0002] Device virtualization of the high-speed serial computer expansion bus standard (PCI-Express, PCIe) is usually the process of simulating and managing physical PCIe devices in a virtual machine environment under a PCIe bus domain. Virtualized PCIe devices allow virtual machines to access and use these devices. PCIe devices across PCIe bus domains can expose access interfaces to each other through a PCIe non-transparent bridge (NTB). The application scenarios of device virtualization methods in the prior art are limited to a single PCIe bus domain, and device access methods across PCIe bus domains can directly access devices through a non-transparent bridge, which has low security.

[0003] Therefore, the existing technology still needs to be improved and developed. Summary of the invention

[0004] The technical problem to be solved by the present invention is that, in view of the above-mentioned defects of the prior art, a device virtualization method, system, terminal and storage medium across bus domains are provided, aiming to solve the problem that the application scenarios of the device virtualization methods in the prior art are limited to a single bus domain and the security of the device access methods across bus domains is low.

[0005] The technical solution adopted by the present invention to solve the problem is as follows:

[0006] In a first aspect, an embodiment of the present invention provides a device virtualization method across bus domains, the method comprising:

[0007] Obtaining, through the end device corresponding to the connection bridge in the borrower host machine, an access request of the borrower host machine to the virtual device, wherein the virtual device is a device virtualized by the borrower host machine based on the virtual device in the lender host machine;

[0008] Performing address conversion on the access request to obtain an update access request;

[0009] The update access request is sent to the control bridge corresponding to the virtualized device through the end device corresponding to the connection bridge in the lender host machine, so that the control bridge forwards the update access request to the virtualized device, wherein the control bridge is used to connect the bus of the virtualized device and the lender host machine.

[0010] In one implementation, performing address conversion on the access request to obtain an update access request includes:

[0011] The request address of the access request is converted through the address space mapping relationship between the virtual device and the control bridge to obtain the update access request.

[0012] In one embodiment, causing the control bridge to forward the update access request to the virtualized device includes:

[0013] The control bridge determines a usage mode based on an access type of the update access request, and forwards the update access request to the virtualized device according to the usage mode, wherein the types of the usage mode include a transparent bridge mode and a non-transparent bridge mode.

[0014] In a second aspect, an embodiment of the present invention further provides a device virtualization system across bus domains, the system comprising a lender host machine, a borrower host machine and a connection bridge; the lender host machine comprises a virtualized device, the borrower host machine comprises a virtual device virtualized based on the virtualized device, and the connection bridge has corresponding end devices in the borrower host machine and the lender host machine respectively;

[0015] The borrower host is used to send an access request for the virtual device to an end device corresponding to the connection bridge in the borrower host;

[0016] The connection bridge is used to perform address conversion on the access request to obtain an update access request, and send the update access request to the control bridge through the end device corresponding to the connection bridge in the lender host machine;

[0017] The lender host machine is used to forward the update access request to the virtualized device through the control bridge, wherein the control bridge is used to connect the bus of the virtualized device and the lender host machine.

[0018] In one embodiment, the borrower host machine further includes:

[0019] A virtual device driver, used for obtaining the access request of the borrower host machine to the virtual device;

[0020] The access request is sent to the end device corresponding to the connection bridge in the lender host machine.

[0021] In one embodiment, the lender host machine further includes:

[0022] The bridge driver is used to configure information of the connection bridge and the control bridge in the lender host.

[0023] In one embodiment, the configuration information of the connection bridge in the lender host includes: information and address of the virtualized device, information and address of the control bridge;

[0024] The configuration information of the control bridge includes: the information and address of the connection bridge in the lender host machine, and the identity information of the control bridge.

[0025] In one implementation, the types of usage modes of the control bridge include a transparent bridge mode and a non-transparent bridge mode, and the transparent bridge mode and the non-transparent bridge mode are respectively used to forward the update access requests of different access types.

[0026] In a third aspect, an embodiment of the present invention further provides a terminal comprising a memory and one or more processors; the memory stores one or more programs; the program comprises instructions for executing a device virtualization method across bus domains as described in any one of the above; and the processor is used to execute the program.

[0027] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium on which a plurality of instructions are stored, wherein the instructions are suitable for being loaded and executed by a processor to implement any of the steps of the cross-bus domain device virtualization method described above.

[0028] Beneficial effects of the present invention: The embodiment of the present invention connects the bus domains corresponding to the two host machines respectively through a connection bridge, so that the borrowing host machine can access the virtualized device of the lending host machine through its own virtualized device, thereby realizing device virtualization across bus domains. A control bridge is used to connect the bus of the virtualized device and the lending host machine to avoid direct access to the virtualized device, realize further control of the virtualized device, and improve the security of device access. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0030] Figure 1 It is a flowchart of a device virtualization method across bus domains provided by an embodiment of the present invention.

[0031] Figure 2 It is a module structure diagram of a cross-bus domain device virtual system provided by an embodiment of the present invention.

[0032] Figure 3 It is a principle block diagram of a terminal provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0033] The present invention discloses a device virtualization method, system, terminal and storage medium across bus domains. In order to make the purpose, technical solution and effect of the present invention clearer and more specific, the present invention is further described in detail with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0034] It will be understood by those skilled in the art that, unless expressly stated, the singular forms "one", "said", and "the" used herein may also include plural forms. It should be further understood that the term "comprising" used in the specification of the present invention refers to the presence of the features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. It should be understood that when we refer to an element as being "connected" or "coupled" to another element, it may be directly connected or coupled to the other element, or there may be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The term "and / or" used herein includes all or any unit and all combinations of one or more associated listed items.

[0035] It will be understood by those skilled in the art that, unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as generally understood by those skilled in the art in the art to which the present invention belongs. It should also be understood that terms such as those defined in general dictionaries should be understood to have meanings consistent with the meanings in the context of the prior art, and will not be interpreted with idealized or overly formal meanings unless specifically defined as herein.

[0036] In view of the above-mentioned defects of the prior art, the present invention provides a device virtualization method across bus domains, the method comprising: obtaining an access request of the borrower host to a virtual device through an end device corresponding to a connection bridge in a borrower host, wherein the virtual device is a device virtualized by the borrower host based on a virtual device in a lender host; performing address conversion on the access request to obtain an update access request; sending the update access request to a control bridge corresponding to the virtual device through an end device corresponding to the connection bridge in the lender host, so that the control bridge forwards the update access request to the virtual device, wherein the control bridge is used to connect the bus of the virtual device and the lender host. The present invention connects the bus domains corresponding to the two host machines respectively through a connection bridge, so that the borrower host can access the virtual device of the lender host through its own virtualized device, thereby realizing device virtualization across bus domains. A control bridge is used to connect the bus of the virtual device and the lender host, so as to avoid direct access to the virtual device, realize further control of the virtual device, and improve the security of device access.

[0037] For example, host machine H1 is the lending host machine, and device A is mounted on the bus of H1 through the control bridge. Host machine H2 is the borrowing host machine. In order to borrow device A, H2 generates a virtual device a corresponding to device A through virtualization technology. Since H1 and H2 correspond to different bus domains, in order to achieve cross-bus domain device access, an end device EP0 is set in H2, and an end device EP1 is set in H1. EP0 and EP1 constitute the two ends of the connection bridge, and the connection bridge forwards the access request between H1 and H2 across the bus domain. When H2 needs to borrow device A, H2 will initiate an access request to virtual device a, and the access request will be redirected to EP0. Since virtual device a and device A are in different bus domains and have different address spaces, after the connection bridge obtains the access request, it needs to perform address conversion on the request address of the access request to obtain an updated access request. The access request is then sent from the bus of H1 through EP1. The access request will first reach the control bridge and then be forwarded to device A through the control bridge, thereby enabling H2 to access device A.

[0038] like Figure 1 As shown, the method specifically includes:

[0039] Step S100: obtaining an access request from the borrower host to a virtual device through an end device corresponding to a connection bridge in the borrower host, wherein the virtual device is a device virtualized by the borrower host based on a virtual device in the lender host.

[0040] Specifically, the virtualized device in this embodiment refers to a virtualized PCIe device, and the lender host refers to the host where the virtualized device is located. The virtualized device is connected to the PCIe bus of the host through a control bridge. The borrower host borrows / accesses the virtualized device in the lender host through a virtual method. The virtual device is a PCIe device virtualized by the borrower host through virtualization technology based on the virtualized device, and is mounted on the PCIe bus of the borrower host. Through the virtual device, the borrower host can use the virtualized device as its own device. Since the borrower host and the lender host correspond to different PCIe bus domains, in order to realize data interaction between the two bus domains, this embodiment constructs a connection bridge to connect the two bus domains. One end of the connection bridge is represented as an end device in the bus domain of the borrower host machine, which is used to obtain the borrower host machine's access request to the virtual device; the other end is represented as an end device in the bus domain of the lender host machine, which is used to forward the access request to the bus domain of the lender host machine.

[0041] For example, host machine H1 is the lender host, and device A is mounted on the bus of H1 through a control bridge. Host machine H2 is the borrower host. In order to borrow device A, H2 generates a virtual device a corresponding to device A through virtualization technology. A connection bridge is constructed using a PCIe non-transparent bridge to connect the PCIe bus domains of the lender host and the borrower host. The connection bridge appears as a PCIe EP (Endpoint) in the PCIe bus of the borrower host and the lender host. The EP of the connection bridge in the borrower host is EP0, and the EP in the lender host is EP1. Both EP0 and EP1 have specific address spaces. In actual application scenarios, when H2 needs to borrow device A, H2 will initiate an access request to the virtual device a, and the access request will be redirected to EP0.

[0042] Step S200: performing address conversion on the access request to obtain an update access request.

[0043] Specifically, since the borrower host and the lender host correspond to different bus domains and cannot directly interact with data, the connection bridge needs to perform address conversion on the received access request so that the update access request obtained after the address conversion can point to the specific address space of the bus domain of the lender host.

[0044] For example, when the borrower's host machine's access request to the virtual device reaches EP0, the connection bridge will perform address conversion on the access request to obtain an update access request, so that the request address of the update access request can point to a specific address space of the lender's host machine's bus domain.

[0045] Step S300: Send the update access request to the control bridge corresponding to the virtualized device through the end device corresponding to the connection bridge in the lender host machine, so that the control bridge forwards the update access request to the virtualized device, wherein the control bridge is used to connect the bus of the virtualized device and the lender host machine.

[0046] Specifically, the virtualized device is the borrowed device. The control bridge in this embodiment exists in the lender's host machine, between the virtualized device and the PCIe bus of the lender's host machine, and is used to achieve further control of the virtualized device. Since direct access to the virtualized device is likely to lead to low security of the device, in this embodiment, the virtualized device is connected / mounted on the bus of the lender's host machine through the control bridge. After adding the control bridge, the access request to the virtualized device needs to be forwarded to the virtualized device through the control bridge, thereby achieving further control of the virtualized device. In actual application scenarios, after the connection bridge performs address conversion on the access request, the request address of the update access request has a matching address space in the lender's host machine. The update access request is sent to the bus domain of the lender's host machine through the corresponding end device in the lender's host machine at the other end of the connection bridge. The update access request will first reach the control bridge, and then be forwarded to the virtualized device through the control bridge, rather than directly reaching the virtualized device, thereby improving the security of the device.

[0047] For example, a PCIe bridge is added as a control bridge between the bus of the virtualized device and the lender's host machine in advance to achieve further control over the virtualized device. The end device at the other end of the connection bridge in the bus domain of the lender's host machine is EP1. The update access request after address conversion is sent through EP1 on the PCIe bus of the lender's host machine, and then forwarded to the virtualized device through the control bridge of the virtualized device, realizing access from the borrower's host machine to the lender's host machine.

[0048] In one implementation, performing address conversion on the access request to obtain an update access request includes:

[0049] The request address of the access request is converted through the address space mapping relationship between the virtual device and the control bridge to obtain the update access request.

[0050] Specifically, the connection bridge pre-stores the address space mapping relationship between one or more virtual devices and the corresponding control bridge of the virtualized device. In actual application scenarios, the connection bridge can convert the request address of the access request into the corresponding address space in the bus domain of the lender host through the address space mapping relationship to obtain an update access request.

[0051] For example, the address space of the control bridge of the virtual device in the bus domain of the lender host is A1, and the address space of the virtual device in the bus domain of the borrower host is A2. The connection bridge pre-stores the address space mapping relationship between A1 and A2. When EP0 obtains the access request of the borrower host to the virtual device, it converts the request address in the access request from A2 to A1, and obtains an update access request. The request address of the update access request points to the specific address space of the bus domain of the lender host.

[0052] In one implementation, causing the control bridge to forward the update access request to the virtualized device includes:

[0053] The control bridge determines a usage mode based on an access type of the update access request, and forwards the update access request to the virtualized device according to the usage mode, wherein the types of the usage mode include a transparent bridge mode and a non-transparent bridge mode.

[0054] Specifically, the lender host may include one or more virtualized devices, and the virtualized devices and the control bridges are in a one-to-one correspondence, that is, one control bridge can only be used to connect one virtualized device to the bus of the lender host, so that the borrower host can borrow devices of multiple lender hosts at the same time. In order to ensure the normal access of the lender host to the virtualized devices, the control bridge in this embodiment has the characteristics of both a PCIe transparent bridge and a PCIe non-transparent bridge, so that the virtualized devices can be used in both the lender host and the borrower host. As a transparent bridge, the control bridge will not change the PCIe bus topology of the lender host, ensuring the normal use of the virtualized devices in the lender host. As a non-transparent bridge, when the borrower host uses the virtualized device, the control bridge can further process and control the PCIe data entering and leaving the virtualized device, including but not limited to: enabling the connection bridge to access the configuration space of the virtualized device; enabling the redirection of the virtualized device's DMA requests (direct memory access requests) and MSI / MSI-X requests (interrupt requests); if support for secure computing is required, identity authentication, data encryption and decryption, state management, process control and other security operations can be added to the control bridge.

[0055] In one implementation, the method further includes:

[0056] Obtain a reverse access request through the end device corresponding to the connection bridge in the lender's host machine;

[0057] Performing address conversion on the request address of the reverse access request through the connection bridge to obtain an updated reverse access request;

[0058] The update reverse access request is sent through the end device corresponding to the connection bridge in the borrower host.

[0059] Specifically, device access is usually a two-way data interaction process. Therefore, when the lender host accesses the specific space of EP1, the connection bridge will convert the reverse access request through EP0 on the PCIe bus of the borrower host after the address conversion operation, thereby realizing reverse access from the lender host to the borrower host.

[0060] Based on the above embodiments, the present invention also provides a device virtualization system across bus domains, such as Figure 2 As shown, the system includes a lender host machine, a borrower host machine and a connection bridge; the lender host machine includes a virtualized device, the borrower host machine includes a virtual device virtualized based on the virtualized device, and the connection bridge has corresponding end devices in the borrower host machine and the lender host machine respectively;

[0061] The borrower host is used to send an access request for the virtual device to an end device corresponding to the connection bridge in the borrower host;

[0062] The connection bridge is used to perform address conversion on the access request to obtain an update access request, and send the update access request to the control bridge through the end device corresponding to the connection bridge in the lender host machine;

[0063] The lender host machine is used to forward the update access request to the virtualized device through the control bridge, wherein the control bridge is used to connect the bus of the virtualized device and the lender host machine.

[0064] Specifically, the aforementioned explanation of the embodiment of the cross-bus domain device virtualization method is also applicable to the cross-bus domain device virtualization system of this embodiment. Therefore, the functions corresponding to the lender host machine, the borrower host machine, the virtualized device, the virtual device, the connection bridge and the control bridge are not repeated here.

[0065] In one implementation, the borrower host machine further includes:

[0066] A virtual device driver, used for obtaining the access request of the borrower host machine to the virtual device;

[0067] The access request is sent to the end device corresponding to the connection bridge in the lender host machine.

[0068] Specifically, Figure 2As shown, this embodiment will also add a corresponding virtual device driver in the borrower's host machine. The virtual device driver is the driver program of the virtual device in the borrower's host machine. When the borrower's host machine accesses the virtual device, the virtual device driver will send the access request to the end device corresponding to the connection bridge in the lender's host machine, and pass it to the virtualized device of the lender's host machine through the connection bridge, so that the virtual device is consistent with the virtualized device in use, so that the borrower's host machine can use the virtualized device as its own device.

[0069] In one implementation, the lender host machine further includes:

[0070] The bridge driver is used to configure information of the connection bridge and the control bridge in the lender host.

[0071] Specifically, Figure 2 As shown, this embodiment will also add a bridge driver in the lender host, and the bridge driver is a driver for controlling the bridge in the lender host. The bridge driver can realize the configuration of the connection bridge and the configuration of the control bridge in the lender host. This embodiment adds a virtual device and its driver to the borrower host, adds a control bridge and its driver to the lender host, and adds a connection bridge between the borrower host and the lender host, so that the borrower host can use the virtual device as its own device.

[0072] For example, during the initial configuration, the bridge driver will configure the connection bridge EP1 and the control bridge in the lender host. After the configuration is completed, a configuration completion flag is established. After the borrower host checks that the configuration completion flag is valid, or knows that the initial configuration is completed through other methods, a virtual PCIe device can be generated through relevant software, and the virtual device can be mounted on the bus of the borrower host, thus completing the virtual device establishment process.

[0073] In one implementation, the configuration information of the connection bridge in the lender host includes: information and address of the virtualized device, information and address of the control bridge;

[0074] The configuration information of the control bridge includes: the information and address of the connection bridge in the lender host machine, and the identity information of the control bridge.

[0075] Specifically, the configuration of the bridge driver to the connection bridge EP1 includes: the information and address of the virtualized device, and the information and address of the control bridge. The configuration of the bridge driver to the control bridge includes: the information and address of the connection bridge EP1, the identity information of the control bridge, such as the number of the control bridge, so as to be applicable to the scenario of multiple control bridges. It should be noted that the connection bridge and the bridge driver of the lender host only need to complete the mapping configuration of the address and resources of the virtualized device before the device is virtualized. During the use of the virtual device, the software of the lender host does not need to participate. Therefore, by adding security means (such as identity authentication, data encryption and decryption, state management, flow control and other security operations) to the connection bridge and the control bridge, the virtualized device can also be used for secure computing (regardless of whether the lender host itself is secure). In short, the method of this embodiment can be used not only in ordinary computing scenarios, but also in secure computing scenarios. For example, the borrower host is a confidential computing environment / trusted execution environment TEE, and the lender host is an ordinary environment, which can also realize the safe use of the virtualized device by the borrower host.

[0076] In one implementation, the types of usage modes of the control bridge include a transparent bridge mode and a non-transparent bridge mode, and the transparent bridge mode and the non-transparent bridge mode are respectively used to forward the update access requests of different access types.

[0077] Specifically, the aforementioned explanation of the cross-bus domain device virtualization method embodiment is also applicable to the cross-bus domain device virtualization system of this embodiment, so the transparent bridge characteristics and non-transparent bridge characteristics of the control bridge are not repeated here.

[0078] The advantages of the present invention are:

[0079] 1. Implement cross-bus domain device virtualization through a connection bridge, so that the borrowing host can use virtualized devices in other bus domains just like using its own devices.

[0080] 2. Further control of virtual devices can be achieved through the control bridge. While meeting ordinary computing needs, security measures can be added to the connection bridge and the control bridge for application in secure computing tasks.

[0081] Based on the above embodiment, the present invention further provides a terminal, whose principle block diagram can be shown as follows: Figure 3As shown. The terminal includes a processor, a memory, a network interface, and a display screen connected via a system bus. Among them, the processor of the terminal is used to provide computing and control capabilities. The memory of the terminal includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the terminal is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a device virtualization method across bus domains is implemented. The display screen of the terminal can be a liquid crystal display screen or an electronic ink display screen.

[0082] Those skilled in the art will understand that Figure 3 The principle block diagram shown in the figure is only a block diagram of a partial structure related to the scheme of the present invention, and does not constitute a limitation on the terminal to which the scheme of the present invention is applied. The specific terminal may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0083] In one implementation, the memory of the terminal stores one or more programs, and is configured to be executed by one or more processors. The one or more programs include instructions for performing a device virtualization method across bus domains.

[0084] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided by the present invention can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0085] In summary, the present invention discloses a device virtualization method, system, terminal and storage medium across bus domains. The method comprises: obtaining an access request of the borrower host to a virtual device through an end device corresponding to a connection bridge in a borrower host, wherein the virtual device is a device virtualized by the borrower host based on a virtual device in a lender host; performing address conversion on the access request to obtain an update access request; sending the update access request to a control bridge corresponding to the virtual device through an end device corresponding to the connection bridge in the lender host, so that the control bridge forwards the update access request to the virtual device, wherein the control bridge is used to connect the virtual device to the bus of the lender host. The present invention connects the bus domains corresponding to the two host machines respectively through a connection bridge, so that the borrower host can access the virtual device of the lender host through its own virtualized device, thereby realizing device virtualization across bus domains. A control bridge is used to connect the bus of the virtual device and the lender host, so as to avoid direct access to the virtual device, realize further control of the virtual device, and improve the security of device access.

[0086] It should be understood that the application of the present invention is not limited to the above examples. For ordinary technicians in this field, improvements or changes can be made based on the above description. All these improvements and changes should fall within the scope of protection of the claims attached to the present invention.

Claims

1. A device virtualization method across bus domains, characterized in that: The method comprises: Obtaining, through the end device corresponding to the connection bridge in the borrower host machine, an access request of the borrower host machine to the virtual device, wherein the virtual device is a device virtualized by the borrower host machine based on the virtual device in the lender host machine; Performing address conversion on the access request to obtain an update access request; The update access request is sent to the control bridge corresponding to the virtualized device through the end device corresponding to the connection bridge in the lender host machine, so that the control bridge forwards the update access request to the virtualized device, wherein the control bridge is used to connect the bus of the virtualized device and the lender host machine; the lender host machine includes one or more virtualized devices, and the virtualized devices and the control bridge are in a one-to-one correspondence; The performing address conversion on the access request to obtain an update access request includes: Performing address conversion on the request address of the access request through the address space mapping relationship between the virtual device and the control bridge to obtain the update access request; The step of causing the control bridge to forward the update access request to the virtualized device includes: The control bridge determines a usage mode based on the access type of the update access request, and forwards the update access request to the virtualized device through the usage mode, wherein the types of usage modes include transparent bridge mode and non-transparent bridge mode; as a transparent bridge, the control bridge will not change the PCIe bus topology of the lender host machine, ensuring the normal use of the virtualized device on the lender host machine; as a non-transparent bridge, when the borrower host machine uses the virtualized device, the control bridge can further process and control the PCIe data entering and leaving the virtualized device, including: realizing the access of the connection bridge to the configuration space of the virtualized device; realizing the redirection of the DMA request and MSI / MSI-X request of the virtualized device; if it is necessary to support secure computing, identity authentication, data encryption and decryption, state management, and process control security operations can be added to the control bridge.

2. A device virtualization system across bus domains, characterized in that: The system includes a lender host machine, a borrower host machine and a connection bridge; the lender host machine includes a virtualized device, the borrower host machine includes a virtual device virtualized based on the virtualized device, and the connection bridge has corresponding end devices in the borrower host machine and the lender host machine respectively; The borrower host is used to send an access request for the virtual device to an end device corresponding to the connection bridge in the borrower host; The connection bridge is used to perform address conversion on the access request to obtain an update access request, and send the update access request to the control bridge through the end device corresponding to the connection bridge in the lender host machine; The lender host is used to forward the update access request to the virtualized device through the control bridge, wherein the control bridge is used to connect the virtualized device and the bus of the lender host; the lender host includes one or more virtualized devices, and the virtualized devices and the control bridge are in a one-to-one correspondence; The performing address conversion on the access request to obtain the update access request includes: performing address conversion on the request address of the access request through the address space mapping relationship between the virtual device and the control bridge to obtain the update access request; Forwarding the update access request to the virtualized device through the control bridge includes: The control bridge determines a usage mode based on the access type of the update access request, and forwards the update access request to the virtualized device through the usage mode, wherein the types of usage modes include transparent bridge mode and non-transparent bridge mode; as a transparent bridge, the control bridge will not change the PCIe bus topology of the lender host machine, ensuring the normal use of the virtualized device on the lender host machine; as a non-transparent bridge, when the borrower host machine uses the virtualized device, the control bridge can further process and control the PCIe data entering and leaving the virtualized device, including: realizing the access of the connection bridge to the configuration space of the virtualized device; realizing the redirection of the DMA request and MSI / MSI-X request of the virtualized device; if it is necessary to support secure computing, identity authentication, data encryption and decryption, state management, and process control security operations can be added to the control bridge.

3. The cross-bus domain device virtualization system according to claim 2, characterized in that: The borrower host machine also includes: A virtual device driver, used for obtaining the access request of the borrower host machine to the virtual device; The access request is sent to the end device corresponding to the connection bridge in the lender host machine.

4. The cross-bus domain device virtualization system according to claim 2, characterized in that: The lender host machine also includes: The bridge driver is used to configure information of the connection bridge and the control bridge in the lender host.

5. The cross-bus domain device virtualization system according to claim 4, characterized in that: The configuration information of the connection bridge in the lender host includes: the information and address of the virtualized device, and the information and address of the control bridge; The configuration information of the control bridge includes: the information and address of the connection bridge in the lender host machine, and the identity information of the control bridge.

6. A terminal, characterized in that: The terminal includes a memory and one or more processors; the memory stores one or more programs; the programs contain instructions for executing the device virtualization method across bus domains as described in claim 1; and the processor is used to execute the programs.

7. A computer-readable storage medium having a plurality of instructions stored thereon, characterized in that: The instructions are suitable for being loaded and executed by a processor to implement the steps of the cross-bus domain device virtualization method described in claim 1 above.

Citation Information

Patent Citations

  • METHOD TO USE PCIe DEVICE RESOURCES BY USING UNMODIFIED PCIe DEVICE DRIVERS ON CPUs IN A PCIe FABRIC WITH COMMODITY PCI SWITCHES

    US20160098372A1