Root Complex Virtual Bridge for External Component Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing architecture of coupling a processor with an external component via a downstream port and a coherent interface port lacks security checks on the coherent interface path, making the processor vulnerable to misbehaving or rogue external components, and existing software stacks cannot synchronize security checks across different interfaces.

Innovation Solution

The Basic Input/Output System (BIOS) extends the root complex to encompass the external component, obfuscates the downstream port from the Operating System, defines a virtual root bridge, and enables a security check at the external component to provide protection for both the coherent interface and downstream ports, ensuring security checks are at the root of the hierarchy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If an external component is coupled to the processor via a coherent interface port, then higher information transfer rate and bandwidth capacity are achieved, but security protection is lost because the coherent interface port does not have security checks

Engineering Contradiction:
Improveinformation transfer rateVSAvoidsecurity protection
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

A virtual root bridge is introduced as an intermediary between the external component and the processor. The virtual root bridge includes security check circuitry that intercepts and validates transactions on the coherent interface port, providing security protection without blocking the high-speed data transfer capability of the coherent interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The root complex is extended to include the external component, creating a segmented security domain. The BIOS obfuscates the downstream port from the operating system and defines a virtual root bridge that separates security management functions from the coherent interface path, allowing independent security checks on each interface type.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a security check is provided in the external component for transactions over the coherent interface port, then security protection is achieved, but architectural requirement violation occurs because the security check is not at the root of hierarchy

Engineering Contradiction:
Improvesecurity protectionVSAvoidarchitectural compliance
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The virtual root bridge acts as a mediator that restores proper hierarchical structure. It is positioned logically at the root of the hierarchy for the external component, even though physically the external component connects to the processor. This allows security checks to be performed at the appropriate hierarchical level without violating architectural requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The solution adds a virtualization dimension to the physical architecture. By creating a virtual root bridge that exists in the software/firmware domain (BIOS level), the system achieves proper hierarchical security structure without changing the physical connection topology, thus maintaining architectural compliance while enabling security checks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If the BIOS extends the root complex to encompass the external component and defines a virtual root bridge, then security checks are synchronized across all access paths, but device complexity increases

Engineering Contradiction:
Improvesynchronized security checksVSAvoidroot complex structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtual root bridge serves multiple functions: it provides security checks for the coherent interface port, maintains hierarchical architecture compliance, obfuscates the downstream port from the operating system, and enables synchronized security validation across both coherent and downstream interfaces. This multi-functionality reduces the need for separate dedicated structures for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The virtual root bridge is a software/firmware construct that copies the security management functionality of a physical root bridge without requiring duplicate hardware. The BIOS creates a virtual representation of the root bridge structure, allowing security checks to be performed through software logic rather than duplicating hardware security modules.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10789370B2Extending a root complex to encompass an external component
Publication Date: 2020.09.29 INTEL CORP
  • US10789370B2 patent drawing
  • US10789370B2 patent drawing
  • US10789370B2 patent drawing

AI summary

In accordance with embodiments disclosed herein, there is provided systems and methods for extending a root complex to encompass an external component. A processor includes a processor core and root complex circuitry coupled to the processor core. The processor core is to execute a basic input/output system (BIOS) and an operating system (OS). The root complex circuitry includes a coherent interface port and a downstream port. The root complex circuitry is to couple to an external component via the downstream port and the coherent interface port. The BIOS, to extend a root complex beyond the root complex circuitry to encompass the external component, is to obfuscate the downstream port from the OS, define a virtual root bridge for the external component, and enable a security check at the external component to provide protection for the coherent interface port and the downstream port.