Reverse V-Ethernet Port Aggregation Bridging for SR-IOV
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems involving virtual machines face challenges in efficiently filtering data and managing communication protocols, particularly in scenarios where virtual machines need to interact with physical functions and uplinks without direct access.
Innovation Solution
The proposed system configures the hypervisor to manage data communications between virtual functions and physical functions, allowing data to be filtered and forwarded through a bridge device without requiring virtual machines to exit the hypervisor. This is achieved by using a virtual network-interface controller with uplinks, virtual functions, and physical functions, each with dedicated channels for data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If virtual machines are given direct access to uplink for data transmission, then communication speed is improved, but device complexity and security control are worsened
Solution Approach 1:
The patent introduces a physical function as an intermediary component between the virtual function and the uplink. The physical function receives data from the virtual function via virtual channel, processes it, and then forwards it to the uplink via physical channel. This intermediary structure enables controlled data transmission while maintaining hypervisor management capabilities, resolving the contradiction between communication speed and device complexity.
2Productivity
If virtual machines can directly send data to uplink, then data transmission efficiency is improved, but hypervisor control and data filtering capabilities are worsened
Solution Approach 1:
The physical function serves as a mediator that maintains hypervisor control over data transmission. The hypervisor can filter and manage data through the physical function before it reaches the uplink, ensuring security and control while still enabling efficient data transmission. This resolves the contradiction by keeping the hypervisor in the data path through the physical function.
Solution Approach 2:
The network interface is segmented into distinct functional components: virtual function for virtual machine communication, physical function for data processing and filtering, and uplink for external connection. This segmentation allows each component to perform its specific function efficiently while maintaining overall system control and security.
3Loss of time
If virtual functions have direct uplink access, then communication overhead is reduced, but system reliability and security are worsened
Solution Approach 1:
The physical function acts as a reliable intermediary that validates and processes data before it reaches the uplink. This intermediate processing layer ensures data integrity and security while minimizing the impact on communication speed, thus resolving the contradiction between low overhead and high reliability.
Data Source
AI summary
A system includes a physical host, a host operating system, and a virtual machine having a virtual network-interface controller. The virtual network-interface controller comprises an uplink, a virtual function, and a physical function having a physical channel and a virtual channel. The hypervisor is configured to receive data that originates at the virtual function, which is forwarded to the physical function on the physical channel of the physical function. The data is further forwarded from the physical function to the uplink. Additionally, the hypervisor is configured to send data that does not originate at the virtual function. The hypervisor sends the data on the virtual channel of the physical function and the physical function forwards the data to the virtual function.


