Secured cross-address-space bridging
A network device includes a bus interface and one or more circuits. The bus interface communicates with a memory using a first bus domain, and with user applications using a second bus domain. The one or more circuits execute a first bus function that accesses a region of the memory using a memory-domain MKEY in the first bus domain, execute a second bus function that communicates with the user applications using the second bus domain, and communicates packets over the network for the user applications, wherein processing of the packets includes accessing the region of the memory via a cross-bus-domain MKEY that points to the memory-domain MKEY in the first bus function, and, in response to authorizing access to a sub-region in the region of the memory, defines for the sub-region a cross-security-domain MKEY pointing to the cross-bus-domain MKEY, which in turn points to the memory-domain MKEY.
1 . A network device, comprising:
one or more ports, to connect to a network;
a bus interface, to (i) communicate with a memory using a first bus domain of a peripheral bus, and (i) communicate with one or more user applications using a second bus domain of the peripheral bus; and
one or more circuits, to:
execute a first bus function that accesses a region of the memory using a memory-domain memory key (MKEY) defined in the first bus domain;
execute a second bus function that communicates with the user applications using the second bus domain, and communicates packets over the network for the user applications, wherein processing of the packets includes accessing the region of the memory via a cross-bus-domain MKEY that points to the memory-domain MKEY in the first bus function; and
in response to authorizing a user application to access a sub-region in the region of the memory, define for the sub-region a respective cross-security-domain MKEY that points to the cross-bus-domain MKEY, which in turn points to the memory-domain MKEY.
2 . The network device according to claim 1 , wherein, in response to authorizing one or more of the user applications to access one or more additional sub-regions in the region of the memory, the one or more circuits are to define one or more additional cross-security-domain MKEYs for the one or more additional sub-regions, the one or more additional cross-security-domain MKEYs pointing to the cross-bus-domain MKEY.
3 . The network device according to claim 1 , wherein the first bus function is to receive the cross-security-domain MKEY from a policer that authorizes requests from the user applications to access sub-regions in the region of the memory and defines respective cross-security-domain MKEYs for the sub-regions.
4 . The network device according to claim 1 , wherein, in response to a memory-access command from the user application that specifies a virtual address (VA), the one or more circuits are to translate the VA into a physical address (PA) in the sub-region, in accordance with an address mapping defined in the memory-domain MKEY, and to access the PA in the memory.
5 . The network device according to claim 1 ,
wherein the first bus function is to communicate with a Graphics Processing Unit (GPU), and the memory is internal to the GPU; and
wherein the second bus function is to communicate with one or more hosts, and the user applications run on the one or more hosts.
6 . The network device according to claim 1 ,
wherein the network device is a Data Processing Unit (DPU) comprising a CPU and one or more processor cores;
wherein the first bus function is to communicate with the CPU, and the memory is internal to the CPU; and
wherein the second bus function is to communicate with the one or more processor cores, and the user applications run on the one or more processor cores.
7 . The network device according to claim 1 , wherein the cross-security-domain MKEY comprises a first MKEY that modifies a Protection Domain (PD) of the sub-region, and a second MKEY that maps addresses of the sub-region.
8 . A method in a network device, the method comprising:
communicating, by the network device, with a memory using a first bus domain of a peripheral bus, and with one or more user applications using a second bus domain of the peripheral bus;
executing in the network device a first bus function that accesses a region of the memory using a memory-domain memory key (MKEY) defined in the first bus domain;
executing in the network device a second bus function that communicates with the user applications using the second bus domain, and communicates packets over the network for the user applications, wherein processing of the packets includes accessing the region of the memory via a cross-bus-domain MKEY that points to the memory-domain MKEY in the first bus function; and
in response to authorizing a user application to access a sub-region in the region of the memory, defining for the sub-region a respective cross-security-domain MKEY that points to the cross-bus-domain MKEY, which in turn points to the memory-domain MKEY.
9 . The method according to claim 8 , and comprising, in response to authorizing one or more of the user applications to access one or more additional sub-regions in the region of the memory, defining one or more additional cross-security-domain MKEYs for the one or more additional sub-regions, the one or more additional cross-security-domain MKEYs pointing to the cross-bus-domain MKEY.
10 . The method according to claim 8 , wherein executing the first bus function comprises receiving the cross-security-domain MKEY from a policer that authorizes requests from the user applications to access sub-regions in the region of the memory and defines respective cross-security-domain MKEYs for the sub-regions.
11 . The method according to claim 8 , and comprising, in response to a memory-access command from the user application that specifies a virtual address (VA), translating the VA into a physical address (PA) in the sub-region, in accordance with an address mapping defined in the memory-domain MKEY, and accessing the PA in the memory.
12 . The method according to claim 8 ,
wherein executing the first bus function comprises communicating with a Graphics Processing Unit (GPU);
wherein the memory is internal to the GPU;
wherein executing the second bus function comprises communicating with one or more hosts; and
wherein the user applications run on the one or more hosts.
13 . The method according to claim 8 ,
wherein the network device is a Data Processing Unit (DPU) comprising a CPU and one or more processor cores;
wherein executing the first bus function comprises communicating with the CPU;
wherein the memory is internal to the CPU;
wherein executing the second bus function comprises communicating with the one or more processor cores; and
wherein the user applications run on the one or more processor cores.
14 . The method according to claim 8 , wherein defining the cross-security-domain MKEY comprises defining a first MKEY that modifies a Protection Domain (PD) of the sub-region, and defining a second MKEY that maps addresses of the sub-region.
15 . A data center, comprising one or more network devices, at least a network device among the network devices comprising:
one or more ports, to connect to a network;
a bus interface, to (i) communicate with a memory using a first bus domain of a peripheral bus, and (i) communicate with one or more user applications using a second bus domain of the peripheral bus; and
one or more circuits, to:
execute a first bus function that accesses a region of the memory using a memory-domain memory key (MKEY) defined in the first bus domain;
execute a second bus function that communicates with the user applications using the second bus domain, and communicates packets over the network for the user applications, wherein processing of the packets includes accessing the region of the memory via a cross-bus-domain MKEY that points to the memory-domain MKEY in the first bus function; and
in response to authorizing a user application to access a sub-region in the region of the memory, define for the sub-region a respective cross-security-domain MKEY that points to the cross-bus-domain MKEY, which in turn points to the memory-domain MKEY.
16 . The data center according to claim 15 , wherein, in response to authorizing one or more of the user applications to access one or more additional sub-regions in the region of the memory, the one or more circuits are to define one or more additional cross-security-domain MKEYs for the one or more additional sub-regions, the one or more additional cross-security-domain MKEYs pointing to the cross-bus-domain MKEY.
17 . The data center according to claim 15 , wherein the first bus function is to receive the cross-security-domain MKEY from a policer that authorizes requests from the user applications to access sub-regions in the region of the memory and defines respective cross-security-domain MKEYs for the sub-regions.
18 . The data center according to claim 15 , wherein, in response to a memory-access command from the user application that specifies a virtual address (VA), the one or more circuits are to translate the VA into a physical address (PA) in the sub-region, in accordance with an address mapping defined in the memory-domain MKEY, and to access the PA in the memory.
19 . The data center according to claim 15 ,
wherein the first bus function is to communicate with a Graphics Processing Unit (GPU), and the memory is internal to the GPU; and
wherein the second bus function is to communicate with one or more hosts, and the user applications run on the one or more hosts.
20 . The data center according to claim 15 ,
wherein the network device is a Data Processing Unit (DPU) comprising a CPU and one or more processor cores;
wherein the first bus function is to communicate with the CPU, and the memory is internal to the CPU; and
wherein the second bus function is to communicate with the one or more processor cores, and the user applications run on the one or more processor cores.