VM-to-VM Communication Accelerator Circuit for Direct Memory Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtual machine (VM) communication in computing devices relies on software-based network virtualization, which is inefficient and slower compared to inter-process communication on non-virtual platforms, due to the need for virtual machine monitors (VMMs) to emulate communication channels between VMs.
Innovation Solution
A hardware-based VM-to-VM communication solution utilizing Peripheral Component Interconnect Express (PCIe) protocols, including PCIe SR-IOV, to enable direct memory access (DMA) between VMs, bypassing the VMM through a VM-to-VM communication accelerator circuit that manages access control and data transfer using DMA descriptors and PCIe-enabled devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software-based network virtualization is used for VM communication, then VM isolation and management are achieved, but data communication speed deteriorates compared to inter-process communication on non-virtual platforms
Solution Approach 1:
The patent introduces a dedicated hardware intermediary component (VM communication accelerator) that mediates between VMs and the VMM. This accelerator provides direct communication pathways while maintaining VMM-managed isolation, thus preserving reliability while improving speed by eliminating software emulation overhead.
Solution Approach 2:
The patent replaces the software-based mechanical emulation system with a hardware-based acceleration system. By substituting software network virtualization with hardware-assisted direct communication, the system maintains isolation guarantees while achieving speeds comparable to native inter-process communication.
2Extent of automation
If VMM emulation is used for VM communication, then centralized control and security are maintained, but communication efficiency deteriorates
Solution Approach 1:
The patent segments the communication control function into two parts: the VMM retains high-level policy control and security management, while the hardware accelerator handles low-level data transfer operations. This segmentation allows centralized control to be maintained at the appropriate level while improving communication efficiency through hardware acceleration.
Solution Approach 2:
The hardware accelerator acts as an intermediary that implements VMM-controlled policies in hardware. This allows the VMM to maintain centralized control over security and resource allocation while the accelerator handles high-speed data transfer, thus improving productivity without sacrificing control.
3Speed
If hardware-based DMA communication is implemented, then data transfer speed is improved, but system complexity increases due to additional accelerator circuits
Solution Approach 1:
The patent designs the VM communication accelerator to perform multiple functions: it handles DMA operations, implements access control policies, manages address translation, and provides security verification. By consolidating these functions into a single multi-functional hardware component, the patent improves data transfer speed while minimizing the increase in overall system complexity.
Solution Approach 2:
The patent merges the communication acceleration function with existing VM management infrastructure. The accelerator integrates with the VMM and memory management units, combining multiple functions into a unified hardware solution that provides fast communication without proportionally increasing system complexity.
Data Source
AI summary
A processing system includes a processor and a VM-to-VM communication accelerator circuit comprising a first interface device to support direct memory access (DMA) data transfers by the first VM, a register to store a reference to a primary physical function (PF) associated with the first interface device, wherein the first primary PF is associated with an access control table (ACT) specifying an access permission for the first VM with respect to a second VM, and a direct memory access (DMA) descriptor processing circuit to process, using a working queue associated with the first primary PF, a DMA descriptor referencing a request for a DMA data transfer between the first VM and the second VM, and execute, using the first interface device, the DMA data transfer based on the access permission.


