PCIe Function Access Control for Multi-System Image Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing PCIe technologies face challenges in achieving high operating speed and security, particularly in managing access to PCIe functions across multiple system images, which can lead to security vulnerabilities and performance degradation.
Innovation Solution
The implementation of a PCIe function that includes an access identification information controller to generate and manage access identification information, a data packet receiver to handle data packets with target identification information, and an access allowance determiner to decide whether to allow access based on the access identification information and target identification information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control mechanisms are implemented for multiple system images, then security is improved, but device complexity increases
Solution Approach 1:
The PCIe function is segmented into multiple access identification information controllers, each dedicated to a specific system image. This segmentation allows independent access control for each system image while maintaining overall system security. Each controller stores and verifies access identification information specific to its assigned system image, enabling fine-grained security control without requiring a single complex centralized controller.
Solution Approach 2:
Access identification information is generated and stored in advance in the access identification information controllers before actual access requests occur. This preliminary action enables rapid access verification when data packets are received, as the controllers already have the authorized identification information ready for comparison, reducing verification complexity during operation.
2Reliability
If access verification is performed for each data packet, then security is improved, but operating speed deteriorates
Solution Approach 1:
Access identification information is prepared and stored in advance in the access identification information controllers before data packet reception. This preliminary preparation eliminates the need for complex real-time generation or lookup during packet verification, enabling fast comparison operations that maintain high operating speed while ensuring security through verification of each incoming packet.
3Reliability
If multiple access identification information controllers are used, then security is improved, but device complexity increases
Solution Approach 1:
The access control functionality is segmented into multiple dedicated controllers, with each controller responsible for a specific system image. This segmentation distributes the security control burden across multiple simple, specialized units rather than requiring one complex centralized controller, achieving high security through parallel simple structures.
Solution Approach 2:
Each access identification information controller is designed with local quality - it is optimized specifically for handling access control for its assigned system image. This local specialization allows each controller to be simple and efficient in its own domain, while collectively providing comprehensive security coverage for all system images.
Data Source
AI summary
A Peripheral Component Interconnect Express (PCIe) function includes an access identification information controller generating first access identification information for allowing an access to the PCIe function, and providing the first access identification information to an assigned system image to which the PCIe function has been assigned, the assigned system image being one of a plurality of system images, a data packet receiver receiving a data packet including target identification information indicating a target system image selected from the plurality of system images from the target system image, and an access allowance determiner determining whether or not to allow an access of the target system image based on the first access identification information and the target identification information.


