Co-processor Data Plane Virtualization via GMID Manager
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtualization systems in computer networks fail to adequately protect co-processor data plane communications, allowing rogue guest software to access unauthorized resources and leading to conflicts between virtual machines, and lack private numbering spaces for guests.
Innovation Solution
Implementing a Guest Machine Identifier (GMID) manager to assign unique GMIDs to each data plane entity, ensuring that all information exchanges involve authorized access to virtualization system resources, and using a GMID-based translation structure to map guest resources to hardware resources, ensuring secure and isolated access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional virtualization systems are used without GMID-based isolation, then resource sharing and virtualization functionality are provided, but unauthorized access by rogue guest software and resource conflicts between virtual machines occur
Solution Approach 1:
The patent introduces a GMID manager as an intermediary component that mediates all data plane communications between virtual machines and co-processors. The GMID manager translates guest resource identifiers to hardware resource identifiers, acting as a security barrier that prevents rogue guest software from directly accessing unauthorized resources while maintaining the virtualization functionality.
Solution Approach 2:
The patent segments the virtualization system by introducing unique GMIDs for each data plane entity (virtual machine, co-processor, data plane entity). This segmentation creates isolated address spaces where each guest operates with its own GMID namespace, preventing cross-tenant attacks and resource conflicts while allowing controlled resource sharing through the GMID translation mechanism.
2Productivity
If guest resource identifiers are directly mapped to hardware resources without translation, then access speed is maintained, but private numbering spaces for guests are lost and resource conflicts occur
Solution Approach 1:
The patent adds a new dimension to the address translation process by introducing GMID as an intermediate identifier layer between guest resource identifiers and hardware resource identifiers. This three-level translation structure (guest ID → GMID → hardware ID) maintains access speed through hardware-assisted translation while providing private numbering spaces through GMID-based isolation, allowing each guest to have its own identifier namespace without sacrificing performance.
3Device complexity
If co-processor data plane communications are not protected, then system complexity is reduced, but unauthorized access to resources and resource conflicts occur
Solution Approach 1:
The GMID manager is designed as a universal security mechanism that handles all data plane communications between any virtual machine and any co-processor. Rather than implementing separate security mechanisms for each communication path, the GMID-based translation system provides universal protection across the entire virtualization platform, maintaining co-processor functionality while securing all resource accesses through a single unified approach.
Data Source
AI summary
A method and a system embodying the method for a data plane virtualization, comprising assigning each of at least one data plane a unique identifier; providing a request comprising an identifier of one of the at least one data plane together with an identifier of a virtual resource assigned to a guest; determining validity of the provided request in accordance with the identifier of the one of the at least one data plane and the identifier of the virtual resource assigned to the guest; and processing the request based on the determined validity of the request are disclosed.


