PCIe Function Access Control for Multi-System Image Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing PCIe technologies face challenges in achieving high operating speed and security, particularly in managing access to PCIe functions across multiple system images, which can lead to security vulnerabilities and performance degradation.

Innovation Solution

The implementation of a PCIe function that includes an access identification information controller to generate and manage access identification information, a data packet receiver to handle data packets with target identification information, and an access allowance determiner to decide whether to allow access based on the access identification information and target identification information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control mechanisms are implemented for multiple system images, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The PCIe function is segmented into multiple access identification information controllers, each dedicated to a specific system image. This segmentation allows independent access control for each system image while maintaining overall system security. Each controller stores and verifies access identification information specific to its assigned system image, enabling fine-grained security control without requiring a single complex centralized controller.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Access identification information is generated and stored in advance in the access identification information controllers before actual access requests occur. This preliminary action enables rapid access verification when data packets are received, as the controllers already have the authorized identification information ready for comparison, reducing verification complexity during operation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If access verification is performed for each data packet, then security is improved, but operating speed deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidoperating speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

Access identification information is prepared and stored in advance in the access identification information controllers before data packet reception. This preliminary preparation eliminates the need for complex real-time generation or lookup during packet verification, enabling fast comparison operations that maintain high operating speed while ensuring security through verification of each incoming packet.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple access identification information controllers are used, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control functionality is segmented into multiple dedicated controllers, with each controller responsible for a specific system image. This segmentation distributes the security control burden across multiple simple, specialized units rather than requiring one complex centralized controller, achieving high security through parallel simple structures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each access identification information controller is designed with local quality - it is optimized specifically for handling access control for its assigned system image. This local specialization allows each controller to be simple and efficient in its own domain, while collectively providing comprehensive security coverage for all system images.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12242625B2PCIe function and operating method thereof
Publication Date: 2025.03.04 SK HYNIX INC
  • US12242625B2 patent drawing
  • US12242625B2 patent drawing
  • US12242625B2 patent drawing

AI summary

A Peripheral Component Interconnect Express (PCIe) function includes an access identification information controller generating first access identification information for allowing an access to the PCIe function, and providing the first access identification information to an assigned system image to which the PCIe function has been assigned, the assigned system image being one of a plurality of system images, a data packet receiver receiving a data packet including target identification information indicating a target system image selected from the plurality of system images from the target system image, and an access allowance determiner determining whether or not to allow an access of the target system image based on the first access identification information and the target identification information.