Co-processor Data Plane Virtualization via GMID Manager

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtualization systems in computer networks fail to adequately protect co-processor data plane communications, allowing rogue guest software to access unauthorized resources and leading to conflicts between virtual machines, and lack private numbering spaces for guests.

Innovation Solution

Implementing a Guest Machine Identifier (GMID) manager to assign unique GMIDs to each data plane entity, ensuring that all information exchanges involve authorized access to virtualization system resources, and using a GMID-based translation structure to map guest resources to hardware resources, ensuring secure and isolated access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional virtualization systems are used without GMID-based isolation, then resource sharing and virtualization functionality are provided, but unauthorized access by rogue guest software and resource conflicts between virtual machines occur

Engineering Contradiction:
ImprovesecurityVSAvoidvirtualization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a GMID manager as an intermediary component that mediates all data plane communications between virtual machines and co-processors. The GMID manager translates guest resource identifiers to hardware resource identifiers, acting as a security barrier that prevents rogue guest software from directly accessing unauthorized resources while maintaining the virtualization functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the virtualization system by introducing unique GMIDs for each data plane entity (virtual machine, co-processor, data plane entity). This segmentation creates isolated address spaces where each guest operates with its own GMID namespace, preventing cross-tenant attacks and resource conflicts while allowing controlled resource sharing through the GMID translation mechanism.

Inventive Principle:
Principle #1Segmentation

2Productivity

If guest resource identifiers are directly mapped to hardware resources without translation, then access speed is maintained, but private numbering spaces for guests are lost and resource conflicts occur

Engineering Contradiction:
Improveaccess speedVSAvoidprivate numbering space isolation
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent adds a new dimension to the address translation process by introducing GMID as an intermediate identifier layer between guest resource identifiers and hardware resource identifiers. This three-level translation structure (guest ID → GMID → hardware ID) maintains access speed through hardware-assisted translation while providing private numbering spaces through GMID-based isolation, allowing each guest to have its own identifier namespace without sacrificing performance.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Device complexity

If co-processor data plane communications are not protected, then system complexity is reduced, but unauthorized access to resources and resource conflicts occur

Engineering Contradiction:
Improvesystem complexityVSAvoidresource protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The GMID manager is designed as a universal security mechanism that handles all data plane communications between any virtual machine and any co-processor. Rather than implementing separate security mechanisms for each communication path, the GMID-based translation system provides universal protection across the entire virtualization platform, maintaining co-processor functionality while securing all resource accesses through a single unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9678779B2Method and an apparatus for co-processor data plane virtualization
Publication Date: 2017.06.13 MARVELL ASIA PTE LTD
  • US9678779B2 patent drawing
  • US9678779B2 patent drawing
  • US9678779B2 patent drawing

AI summary

A method and a system embodying the method for a data plane virtualization, comprising assigning each of at least one data plane a unique identifier; providing a request comprising an identifier of one of the at least one data plane together with an identifier of a virtual resource assigned to a guest; determining validity of the provided request in accordance with the identifier of the one of the at least one data plane and the identifier of the virtual resource assigned to the guest; and processing the request based on the determined validity of the request are disclosed.