Virtual Switch for Secure VM to PCIe Coupling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for PCIe with Single-Root Input/Output Virtualization (SR-IOV) are not designed for the embedded systems market and do not meet all automotive requirements, limiting their use in providing a safe and secure coupling between virtual machines and high-bandwidth devices in automotive computing units.

Innovation Solution

A computing device with a virtual switch that provides a safe and secure coupling between virtual machines and PCIe devices, using SR-IOV hardware functions to enable efficient, high-bandwidth communication while ensuring spatial and temporal isolation, and managing PCIe bus access to prevent overloading and ensure guaranteed bandwidth for each virtual machine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If existing PCIe with SR-IOV solutions are used for connecting virtual machines to high bandwidth devices, then data transmission speed is improved, but safety and security requirements for automotive applications are not met

Engineering Contradiction:
Improvedata transmission speedVSAvoidsafety and security compliance
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces a virtual switch as an intermediary component between virtual machines and PCIe devices. This virtual switch implements safety and security functions (such as ISO-26262 compliance and secure boot) while maintaining the high-speed data transmission capability of PCIe SR-IOV. The virtual switch acts as a mediator that ensures automotive requirements are met without sacrificing performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional components: virtual machines, virtual switch, and PCIe devices. This segmentation allows the virtual switch to be specifically designed and certified for automotive safety and security requirements, while the PCIe devices can focus on providing high-speed data transmission. The separation enables independent optimization and certification of each component.

Inventive Principle:
Principle #1Segmentation

2Productivity

If virtual machines are directly coupled to PCIe devices for high bandwidth communication, then communication efficiency is improved, but CPU load increases and deterministic latency is compromised

Engineering Contradiction:
Improvecommunication efficiencyVSAvoiddeterministic latency
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The virtual switch serves as an intermediary that manages PCIe bus access and traffic flow between virtual machines and PCIe devices. It implements deterministic scheduling and traffic prioritization to ensure guaranteed latency bounds while maintaining high communication efficiency. The virtual switch controls and regulates traffic to prevent bus overloading.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtual switch dynamically manages resource allocation and traffic prioritization based on real-time requirements. It can adjust bandwidth allocation, implement quality of service (QoS) policies, and respond to changing traffic patterns to maintain deterministic latency while optimizing communication efficiency for different virtual machines and applications.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If existing SR-IOV implementations are used, then high bandwidth device connectivity is achieved, but spatial and temporal isolation between virtual machines is insufficient

Engineering Contradiction:
Improvedevice connectivityVSAvoidspatial and temporal isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The virtual switch segments the PCIe bus access and implements spatial isolation by creating separate virtual channels and queues for different virtual machines. It provides temporal isolation through deterministic scheduling that guarantees bounded latency for each virtual machine. This segmentation ensures that one virtual machine cannot interfere with or overload the PCIe bus access of another virtual machine.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual switch implements different quality levels of service for different virtual machines based on their specific requirements. It can allocate different bandwidth guarantees, latency bounds, and priority levels to different virtual machines, providing customized isolation and performance characteristics tailored to each application's needs.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12117958B2Computing device with safe and secure coupling between virtual machines and peripheral component interconnect express device
Publication Date: 2024.10.15 ELEKTROBIT AUTOMOTIVE GMBH
  • US12117958B2 patent drawing
  • US12117958B2 patent drawing

AI summary

The present invention is related to a computing device (CD), in particular for automotive applications, with a safe and secure coupling between virtual machines (VMi) and a peripheral component interconnect express device (PCIe-D). The invention is further related to a vehicle comprising such a computing device (CD). The computing device (CD) comprises one or more virtual machines (VMi) and a virtual switch (VS). The virtual switch (VS) is configured to provide a safe and secure coupling between the one or more virtual machines (VMi) and at least one peripheral component interconnect express device (PCIe-D) configured to support single-root input/output virtualization, to which the computing device (CD) is connected.