I/O Accelerator Device for Secure Inter-Container Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtualized information handling systems face challenges in ensuring security and performance for inter-container communication, particularly due to limitations in hypervisor driver stacks that lead to low data throughput and high latency.

Innovation Solution

An I/O accelerator device is introduced, programmed by a storage virtual appliance, which provides managed access to local and remote storage resources using direct memory access (DMA) and employs endpoints configured as logical hardware adapters to analyze and facilitate inter-process communications between containers, ensuring permissions-based security and optimized data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional hypervisor driver stacks are used for inter-container communication, then system compatibility and ease of operation are maintained, but data throughput is low and latency is high

Engineering Contradiction:
Improvedata throughputVSAvoidcommunication latency
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent extracts the inter-container communication functionality from the traditional hypervisor driver stack and implements it directly in hardware via the I/O accelerator device. This extraction removes the communication path from the software layer that causes latency, allowing containers to communicate through dedicated hardware endpoints with direct memory access, thereby achieving high throughput and low latency while maintaining system compatibility through the hypervisor interface.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The I/O accelerator device serves as a hardware intermediary between containers and storage resources. It provides dedicated endpoints that facilitate direct communication between containers without requiring traversal through the hypervisor driver stack, thus maintaining ease of operation through standardized interfaces while dramatically improving data throughput and reducing communication latency through hardware-optimized paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-based security is implemented for inter-container communication, then security reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The I/O accelerator device implements self-service security by performing permission validation and authentication directly in hardware without requiring external security processing. The device autonomously evaluates container permissions and enforces security policies through its permission validation circuitry, improving security reliability through hardware-enforced constraints while avoiding the complexity of software-based security management layers.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent merges security validation functionality directly into the I/O accelerator device's hardware architecture, combining communication acceleration and security enforcement in a single component. This integration improves security reliability by making security checks mandatory and hardware-enforced, while reducing overall system complexity compared to separate hardware security modules and software security stacks.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If I/O accelerator device with DMA is used, then data transfer performance is improved and processor workload is reduced, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improvedata transfer performanceVSAvoiddevice configuration
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces software-based data transfer mechanisms with hardware-based direct memory access (DMA) in the I/O accelerator device. This substitution eliminates the need for processor involvement in data copying operations, dramatically improving data transfer performance while reducing processor workload. The DMA capability is integrated into the device's core architecture, reducing configuration complexity compared to software-based alternatives.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Productivity

If endpoints are configured as logical hardware adapters, then inter-container communication efficiency is improved, but ease of operation and driver requirements increase

Engineering Contradiction:
Improvecommunication efficiencyVSAvoiddriver configuration
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The I/O accelerator device implements universal endpoint interfaces that can function as logical hardware adapters for multiple containers simultaneously. These endpoints are designed with standardized interfaces that can be configured for different communication scenarios, improving communication efficiency through hardware-optimized paths while maintaining ease of operation through consistent, predictable interface behavior across different container configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10503922B2Systems and methods for hardware-based security for inter-container communication
Publication Date: 2019.12.10 DELL PROD LP
  • US10503922B2 patent drawing
  • US10503922B2 patent drawing
  • US10503922B2 patent drawing

AI summary

In accordance with embodiments of the present disclosure, an information handling system may include a processor subsystem having access to a memory subsystem and a device communicatively coupled to the processor subsystem, the device having an endpoint assigned for access by a container executing on the processor subsystem such that the endpoint appears to the container as a logical hardware adapter. The device may be configured to receive an inter-process communication from the container via the endpoint, the inter-process communication intended for a target container, analyze the inter-process communication to determine if the container has permissions for communicating the inter-process communication to the target container, and communicate the inter-process communication to the target container responsive to determining that the container has permissions for communicating the inter-process communication to the target container.