PCIe DOE Virtualization for Multiple Security Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy PCIe data object exchange (DOE) specifications limit a single DOE entity to support only a single security policy, making it impractical for PCIe devices to communicate with host entities that require different security policies.

Innovation Solution

A lightweight mechanism is introduced to virtualize the DOE entity by using a DOE mailbox with a virtual 'connection ID', allowing multiple connections with different security policies between a PCIe device and a host device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single DOE entity supports only a single security policy, then the system structure remains simple, but the adaptability to different security requirements is limited

Engineering Contradiction:
Improvesupport for multiple security policiesVSAvoidDOE entity structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the DOE entity by introducing multiple virtual DOE entities, each dedicated to supporting a specific security policy. This allows the system to handle multiple security policies simultaneously without requiring a single complex DOE entity to manage all policies, thereby improving adaptability while controlling complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between the physical DOE entity and the multiple security policies. This virtualization mechanism allows multiple virtual DOE entities to share the same physical hardware resources, enabling support for multiple security policies without proportionally increasing physical system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple connections with different security policies are established, then communication flexibility improves, but the difficulty of message routing increases

Engineering Contradiction:
Improvemultiple connections capabilityVSAvoidmessage routing identification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent assigns unique identifiers to each virtual DOE entity and establishes local quality attributes for message routing. By tagging messages with identifiers that correspond to specific virtual DOE entities, the system can easily route messages to the correct security policy handler without requiring complex routing logic, thus improving adaptability while keeping message routing manageable

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12314397B2Support of PCIe device with multiple security policies
Publication Date: 2025.05.27 INTEL CORP
  • US12314397B2 patent drawing
  • US12314397B2 patent drawing
  • US12314397B2 patent drawing

AI summary

Various embodiments provide apparatuses, systems, and methods for establishing, by a data object exchange (DOE entity) of a peripheral component interconnect express (PCIe) device, a first session for communication between a first host entity of a host device and a first PCIe entity of the PCIe device, and a second session for communication between a second host entity of the host device and a second PCIe entity of the PCIe device. The first session may have a first security policy and be a session of a first connection between the PCIe device and the host device. The second session may have a second security policy and be a session of a second connection between the PCIe device and the host device. Other embodiments may be described and claimed.