PCIe Manageability Security via Address Validation Filters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for manageability applications in networked systems, such as MCTP over PCIe, face challenges in providing scalable and secure communication due to increased component costs and limited motherboard placement options with dedicated sideband buses, and internal buses restrict media redirection and mix-and-match capabilities.

Innovation Solution

Implementing Address Validation Filters (AVF) and Access Control Lists (ACL) using PCI Express architecture, where Privileged MCTP Endpoints (PME) and Service Provider MCTP Endpoints (SPME) verify identities through unique PCI Bus, Device, and Function numbers, ensuring secure communication by preventing rogue endpoint spoofing and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated sideband bus is used for manageability applications, then communication speed and reliability are improved, but component cost increases due to more pins and motherboard placement options are limited

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidcomponent cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges manageability traffic with regular PCIe traffic by using the existing PCIe bus infrastructure. Instead of creating a separate dedicated sideband bus, the invention combines multiple traffic types (management, media redirection, video redirection) over the same PCIe transport layer, thereby eliminating the need for additional physical pins and reducing component cost while maintaining communication reliability through protocol-level separation and Address Validation Filters.

Inventive Principle:
Principle #5Merging (Combining)

2Device complexity

If internal buses are used for manageability applications, then component cost is reduced, but media redirection and mix-and-match capabilities are restricted

Engineering Contradiction:
Improvecomponent costVSAvoidmedia redirection capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal PCIe-based manageability solution that can handle multiple functions including traditional management traffic, media redirection, and video redirection. By using the versatile PCIe interface instead of dedicated internal buses, the system achieves mix-and-match capabilities allowing different endpoint configurations while maintaining cost-effectiveness. The Address Validation Filter and ACL mechanisms provide flexible access control for these diverse functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If Address Validation Filters and Access Control Lists are implemented, then security against spoofing attacks is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces Address Validation Filters (AVF) and Access Control Lists (ACL) as intermediary security mechanisms within the PCIe architecture. These intermediaries operate at the protocol layer to validate endpoint identities and control access without requiring fundamental changes to the physical infrastructure. The AVF acts as a mediator that intercepts and validates address information, while ACL provides layered access control policies, thereby enhancing security while maintaining reasonable system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10691839B2Method, apparatus, and system for manageability and secure routing and endpoint access
Publication Date: 2020.06.23 INTEL CORP
  • US10691839B2 patent drawing
  • US10691839B2 patent drawing
  • US10691839B2 patent drawing

AI summary

A solution is presented to securing endpoints without the need for a separate bus or communication path. The solution allows for controlling access to endpoints by utilizing a management protocol by overlapping with existing interconnect communication paths in a packet format and utilizing a PCI address BDF (Bus number, Device number, and Function number) for verification.