Peripheral Device Virtualization via Intermediary Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems face inefficiencies in allocating computing resources to multiple virtual machines, leading to wasted resources and insecure data management when multiple users share peripheral devices, as they often disable useful features to prevent data mixing and malicious actions.
Innovation Solution
The introduction of a device controller intermediary that generates emulated physical functions and virtual composite peripheral devices, allowing policy-based control and efficient allocation of underutilized resources, enabling virtual machines to access combined functionalities of multiple devices as a single unified device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple virtual machines share a peripheral device, then resource utilization improves, but data security and system reliability deteriorate due to potential data mixing and malicious actions
Solution Approach 1:
The patent segments the peripheral device into multiple virtual functions (VF), where each VF is assigned to a specific virtual machine. This segmentation allows multiple VMs to share the physical device while maintaining isolated access paths, preventing data mixing and malicious actions between VMs. The virtualization layer divides the monolithic device into discrete, controllable units that can be independently managed and secured.
Solution Approach 2:
The patent introduces a virtualization intermediary layer (hypervisor/virtualization software) that sits between the virtual machines and the physical peripheral device. This intermediary manages access requests, enforces security policies, and routes communications appropriately. It acts as a mediator that enables resource sharing while maintaining security boundaries, allowing high resource utilization without compromising data security.
2Reliability
If control features are disabled to prevent malicious actions, then data security improves, but device functionality and versatility deteriorate
Solution Approach 1:
The patent applies local quality by enabling different control features for different virtual functions based on their specific requirements. Each virtual machine receives customized functionality through its assigned VF, allowing security-critical features to be restricted while non-critical features remain enabled. This granular control allows the system to maintain high security while preserving necessary device functionality and versatility for each workload.
Solution Approach 2:
The patent makes the peripheral device universal by creating virtual functions that can serve multiple purposes and different virtual machines. A single physical device can simultaneously provide different functional capabilities to different VMs, with each VF configured for its specific use case. This multi-functionality approach maintains device versatility while the virtualization layer ensures security through isolated access control.
3Reliability
If exclusive access is granted to prevent data mixing, then data security improves, but resource utilization and productivity deteriorate due to wasted resources
Solution Approach 1:
The patent merges multiple virtual functions into a single physical peripheral device while maintaining logical separation. Multiple VMs can simultaneously access the same physical device through their respective VFs, combining resource capacity while preserving security through virtualization. This merging approach eliminates resource waste by allowing concurrent access without data mixing, achieving both high security and high resource utilization.
Solution Approach 2:
The patent adds a virtualization dimension between the physical device and virtual machines, transforming the access model from physical to virtual. This dimensional change allows multiple VMs to share the device in a new space (virtual address space, virtual device space) without compromising security. Resources are utilized efficiently in this new dimension while maintaining security boundaries through virtual isolation mechanisms.
Data Source
AI summary
A method for processing a function command for a peripheral device, the method that includes obtaining, by a device controller intermediary, a function command from a virtual machine, where the function command is associated with a peripheral device, performing a lookup, in a function policy database to identify an emulated function policy associated with the function command, making a determination that the function command does not violate the emulated function policy, and in response to the determination, forwarding the function command to the peripheral device.


