Virtual Switch for Secure VM to PCIe Coupling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for PCIe with Single-Root Input/Output Virtualization (SR-IOV) are not designed for the embedded systems market and do not meet all automotive requirements, limiting their use in providing a safe and secure coupling between virtual machines and high-bandwidth devices in automotive computing units.
Innovation Solution
A computing device with a virtual switch that provides a safe and secure coupling between virtual machines and PCIe devices, using SR-IOV hardware functions to enable efficient, high-bandwidth communication while ensuring spatial and temporal isolation, and managing PCIe bus access to prevent overloading and ensure guaranteed bandwidth for each virtual machine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If existing PCIe with SR-IOV solutions are used for connecting virtual machines to high bandwidth devices, then data transmission speed is improved, but safety and security requirements for automotive applications are not met
Solution Approach 1:
The patent introduces a virtual switch as an intermediary component between virtual machines and PCIe devices. This virtual switch implements safety and security functions (such as ISO-26262 compliance and secure boot) while maintaining the high-speed data transmission capability of PCIe SR-IOV. The virtual switch acts as a mediator that ensures automotive requirements are met without sacrificing performance.
Solution Approach 2:
The system is segmented into distinct functional components: virtual machines, virtual switch, and PCIe devices. This segmentation allows the virtual switch to be specifically designed and certified for automotive safety and security requirements, while the PCIe devices can focus on providing high-speed data transmission. The separation enables independent optimization and certification of each component.
2Productivity
If virtual machines are directly coupled to PCIe devices for high bandwidth communication, then communication efficiency is improved, but CPU load increases and deterministic latency is compromised
Solution Approach 1:
The virtual switch serves as an intermediary that manages PCIe bus access and traffic flow between virtual machines and PCIe devices. It implements deterministic scheduling and traffic prioritization to ensure guaranteed latency bounds while maintaining high communication efficiency. The virtual switch controls and regulates traffic to prevent bus overloading.
Solution Approach 2:
The virtual switch dynamically manages resource allocation and traffic prioritization based on real-time requirements. It can adjust bandwidth allocation, implement quality of service (QoS) policies, and respond to changing traffic patterns to maintain deterministic latency while optimizing communication efficiency for different virtual machines and applications.
3Adaptability or versatility
If existing SR-IOV implementations are used, then high bandwidth device connectivity is achieved, but spatial and temporal isolation between virtual machines is insufficient
Solution Approach 1:
The virtual switch segments the PCIe bus access and implements spatial isolation by creating separate virtual channels and queues for different virtual machines. It provides temporal isolation through deterministic scheduling that guarantees bounded latency for each virtual machine. This segmentation ensures that one virtual machine cannot interfere with or overload the PCIe bus access of another virtual machine.
Solution Approach 2:
The virtual switch implements different quality levels of service for different virtual machines based on their specific requirements. It can allocate different bandwidth guarantees, latency bounds, and priority levels to different virtual machines, providing customized isolation and performance characteristics tailored to each application's needs.
Data Source
AI summary
The present invention is related to a computing device (CD), in particular for automotive applications, with a safe and secure coupling between virtual machines (VMi) and a peripheral component interconnect express device (PCIe-D). The invention is further related to a vehicle comprising such a computing device (CD). The computing device (CD) comprises one or more virtual machines (VMi) and a virtual switch (VS). The virtual switch (VS) is configured to provide a safe and secure coupling between the one or more virtual machines (VMi) and at least one peripheral component interconnect express device (PCIe-D) configured to support single-root input/output virtualization, to which the computing device (CD) is connected.

