PCIe Packet Integrity Protection Across Non-Transparent Bridges
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In PCIe networks, traditional end-to-end integrity checks become ineffective when a non-transparent bridge (NTB) modifies packet contents, such as address information, rendering standard integrity codes invalid.
Innovation Solution
The implementation of a packet format with two integrity codes: a first integrity code for validating the integrity of the segment between a device and the NTB, and a second integrity code for validating the integrity of the segment between the NTB and a destination device, both generated by the originating device based on path information provided by the NTB.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a non-transparent bridge modifies packet contents to enable communication across different PCIe domains, then adaptability and connectivity are improved, but packet integrity validation becomes ineffective
Solution Approach 1:
The patent divides the communication path into two segments: first segment from source to NTB, and second segment from NTB to destination. Each segment has its own integrity code (first integrity code and second integrity code respectively). This segmentation allows integrity validation to be performed on each segment independently, resolving the contradiction by making integrity validation adaptable to the modified packet contents while maintaining reliability.
Solution Approach 2:
The patent changes the integrity code parameter from a single end-to-end code to multiple segment-specific codes. The first integrity code is generated based on original packet contents for the first segment, and the second integrity code is generated based on modified packet contents for the second segment. This parameter change allows integrity validation to remain effective despite NTB modifications.
2Reliability
If traditional end-to-end integrity codes are used, then packet integrity protection is maintained, but the system cannot handle packet modifications by non-transparent bridges
Solution Approach 1:
The patent segments the single end-to-end integrity code into multiple integrity codes corresponding to different communication segments. This allows each segment to have its own integrity validation independent of NTB modifications, enabling both integrity protection and NTB compatibility.
Solution Approach 2:
The patent introduces an intermediary mechanism where the NTB generates or modifies integrity codes for the second segment based on the modified packet contents. This intermediary approach allows the system to maintain integrity protection while accommodating NTB modifications.
3Reliability
If integrity codes are regenerated after NTB modification, then integrity validation remains effective, but additional processing overhead is introduced
Solution Approach 1:
The patent performs preliminary action by having the source device generate both the first integrity code (for source-to-NTB segment) and the second integrity code (for NTB-to-destination segment) before packet transmission. This preliminary generation of both integrity codes eliminates the need for complex regeneration operations at the NTB, reducing processing overhead while maintaining validation effectiveness.
Data Source
AI summary
A method may include protecting integrity of a first segment of a communication path across different PCIe domains with a first integrity code, the different PCIe domains connected by a non-transparent bridge; and protecting integrity of a second segment of the communication path with a second integrity code, wherein the second integrity code is different than the first MAC.


