PCIe Switch Virtual Fabric ID Segregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional PCI Express switch fabric architectures lack adequate security and segregation features for host-to-host communications, particularly as cluster sizes increase and functionality becomes more complex.
Innovation Solution
Implementing a virtual fabric ID (VPFID) mechanism within the PCI Express switch to enforce security and segregation of host-to-host message flows by tagging and filtering packets based on approved IDs, ensuring only authorized communications are allowed through the switch.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional PCI Express switch fabric architecture is used, then device complexity is reduced and ease of operation is maintained, but security and segregation of host-to-host communications are inadequate
Solution Approach 1:
The patent segments the PCIe fabric communications by introducing Virtual Fabric IDs (VFIDs) that divide the fabric into multiple virtual fabrics. Each virtual fabric is isolated from others, providing security and segregation for host-to-host communications without requiring complete redesign of the switch fabric architecture.
Solution Approach 2:
The patent introduces VFIDs as an intermediary mechanism that mediates communications between hosts on the PCIe fabric. The switch fabric uses VFIDs to control and manage communication flows, providing security and segregation while maintaining the existing fabric infrastructure.
2Reliability
If virtual fabric ID mechanism is implemented, then security and segregation of host-to-host communications are improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent implements preliminary action by pre-configuring VFID mappings and permissions in the switch fabric before communications occur. This allows the switch to automatically enforce security policies without complex runtime processing, reducing the processing overhead despite the added security mechanism.
3Reliability
If virtual fabric ID tagging and filtering is implemented, then unauthorized access is prevented and message integrity is maintained, but processing time and runtime overhead increase
Solution Approach 1:
The patent applies preliminary action by pre-tagging messages with VFIDs at the source and pre-configuring filter rules in the switch fabric. This allows for rapid lookup and filtering operations during runtime, minimizing processing time overhead while maintaining strong security and message integrity controls.
Data Source
AI summary
A PCIe fabric includes at least one PCIe switch. The fabric may be used to connect multiple hosts. The PCIe switch implements security and segregation measures for host-to-host message communication. A management entity defines a Virtual PCIe Fabric ID (VPFID). The VPFID is used to enforce security and segregation. The fabric ID may be extended to be used in switch fabrics with other point-to-point protocols.


