PCIe Memory Controller Virtual Function Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In memory systems, especially in vehicles, there is a lack of effective isolation of virtual PCIe functions, leading to unauthorized access and potential security breaches, as any device accessing a PCIe switch can access multiple or all virtual functions, compromising intended access control.
Innovation Solution
Implementing a memory apparatus with a controller that provides PCIe functions and isolates access to each function using unique passwords and digital signatures created from host keys, ensuring only intended devices can access specific virtual functions sharing physical resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple virtual PCIe functions share physical resources without access isolation, then device versatility and resource utilization are improved, but security and access control are compromised
Solution Approach 1:
The patent segments the unified access control into function-specific access control by dividing the physical PCIe resources into multiple virtual functions, each with its own password protection. This allows each virtual function to be accessed independently with dedicated credentials, preventing unauthorized access while maintaining versatility.
Solution Approach 2:
The patent introduces passwords as an intermediary mechanism between the device and virtual PCIe functions. The password acts as a mediator that verifies device identity and grants or denies access to specific virtual functions, thereby securing access control while allowing multiple devices to access different functions legitimately.
2Object-affected harmful factors
If access control is implemented for each virtual PCIe function using passwords, then security is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal password-based access control framework that can be applied to multiple virtual PCIe functions simultaneously. Rather than creating separate complex authentication mechanisms for each function, a single password system serves all virtual functions, reducing overall complexity while maintaining security.
Data Source
AI summary
Systems, apparatuses, and methods related to isolating virtual machines in a memory device are described. A memory apparatus includes a memory device and a controller coupled to the memory device, wherein the controller is configured to provide a plurality of Peripheral Component Interconnect express (PCIe) functions of the memory device and isolate access to each of the plurality of PCIe functions via respective passwords and digital signatures created from host keys.


