IP Library Granted Patent US 12681887
Granted Patent B2
US 12681887 · App. 18/973,137 · Granted Jul 14, 2026

Secured cross-address-space bridging

Inventors: Gal Shalom (Givat-Avni, IL); Eliav Bar-Ilan (Or Akiva, IL); Daniil Provotorov (Tel-Aviv, IL); Ran Koren (Haifa, IL); Shay Aisman (Zichron Yaacov, IL); Amir Sharaffy (Ashkelon, IL); Jason Gunthorpe (Bedford, CA); Aviad Yehezkel (Yokneam Ilit, IL)
Assignee: Mellanox Technologies, Ltd
G06F13/4221G06F2213/0026
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12681887
App. No.
18/973,137
Granted
Jul 14, 2026
Kind
B2
Abstract

A network device includes a bus interface and one or more circuits. The bus interface communicates with a memory using a first bus domain, and with user applications using a second bus domain. The one or more circuits execute a first bus function that accesses a region of the memory using a memory-domain MKEY in the first bus domain, execute a second bus function that communicates with the user applications using the second bus domain, and communicates packets over the network for the user applications, wherein processing of the packets includes accessing the region of the memory via a cross-bus-domain MKEY that points to the memory-domain MKEY in the first bus function, and, in response to authorizing access to a sub-region in the region of the memory, defines for the sub-region a cross-security-domain MKEY pointing to the cross-bus-domain MKEY, which in turn points to the memory-domain MKEY.

Claims (55)

1 . A network device, comprising:

one or more ports, to connect to a network;

a bus interface, to (i) communicate with a memory using a first bus domain of a peripheral bus, and (i) communicate with one or more user applications using a second bus domain of the peripheral bus; and

one or more circuits, to:

execute a first bus function that accesses a region of the memory using a memory-domain memory key (MKEY) defined in the first bus domain;

execute a second bus function that communicates with the user applications using the second bus domain, and communicates packets over the network for the user applications, wherein processing of the packets includes accessing the region of the memory via a cross-bus-domain MKEY that points to the memory-domain MKEY in the first bus function; and

in response to authorizing a user application to access a sub-region in the region of the memory, define for the sub-region a respective cross-security-domain MKEY that points to the cross-bus-domain MKEY, which in turn points to the memory-domain MKEY.

2 . The network device according to claim 1 , wherein, in response to authorizing one or more of the user applications to access one or more additional sub-regions in the region of the memory, the one or more circuits are to define one or more additional cross-security-domain MKEYs for the one or more additional sub-regions, the one or more additional cross-security-domain MKEYs pointing to the cross-bus-domain MKEY.

3 . The network device according to claim 1 , wherein the first bus function is to receive the cross-security-domain MKEY from a policer that authorizes requests from the user applications to access sub-regions in the region of the memory and defines respective cross-security-domain MKEYs for the sub-regions.

4 . The network device according to claim 1 , wherein, in response to a memory-access command from the user application that specifies a virtual address (VA), the one or more circuits are to translate the VA into a physical address (PA) in the sub-region, in accordance with an address mapping defined in the memory-domain MKEY, and to access the PA in the memory.

5 . The network device according to claim 1 ,

wherein the first bus function is to communicate with a Graphics Processing Unit (GPU), and the memory is internal to the GPU; and

wherein the second bus function is to communicate with one or more hosts, and the user applications run on the one or more hosts.

6 . The network device according to claim 1 ,

wherein the network device is a Data Processing Unit (DPU) comprising a CPU and one or more processor cores;

wherein the first bus function is to communicate with the CPU, and the memory is internal to the CPU; and

wherein the second bus function is to communicate with the one or more processor cores, and the user applications run on the one or more processor cores.

7 . The network device according to claim 1 , wherein the cross-security-domain MKEY comprises a first MKEY that modifies a Protection Domain (PD) of the sub-region, and a second MKEY that maps addresses of the sub-region.

8 . A method in a network device, the method comprising:

communicating, by the network device, with a memory using a first bus domain of a peripheral bus, and with one or more user applications using a second bus domain of the peripheral bus;

executing in the network device a first bus function that accesses a region of the memory using a memory-domain memory key (MKEY) defined in the first bus domain;

executing in the network device a second bus function that communicates with the user applications using the second bus domain, and communicates packets over the network for the user applications, wherein processing of the packets includes accessing the region of the memory via a cross-bus-domain MKEY that points to the memory-domain MKEY in the first bus function; and

in response to authorizing a user application to access a sub-region in the region of the memory, defining for the sub-region a respective cross-security-domain MKEY that points to the cross-bus-domain MKEY, which in turn points to the memory-domain MKEY.

9 . The method according to claim 8 , and comprising, in response to authorizing one or more of the user applications to access one or more additional sub-regions in the region of the memory, defining one or more additional cross-security-domain MKEYs for the one or more additional sub-regions, the one or more additional cross-security-domain MKEYs pointing to the cross-bus-domain MKEY.

10 . The method according to claim 8 , wherein executing the first bus function comprises receiving the cross-security-domain MKEY from a policer that authorizes requests from the user applications to access sub-regions in the region of the memory and defines respective cross-security-domain MKEYs for the sub-regions.

11 . The method according to claim 8 , and comprising, in response to a memory-access command from the user application that specifies a virtual address (VA), translating the VA into a physical address (PA) in the sub-region, in accordance with an address mapping defined in the memory-domain MKEY, and accessing the PA in the memory.

12 . The method according to claim 8 ,

wherein executing the first bus function comprises communicating with a Graphics Processing Unit (GPU);

wherein the memory is internal to the GPU;

wherein executing the second bus function comprises communicating with one or more hosts; and

wherein the user applications run on the one or more hosts.

13 . The method according to claim 8 ,

wherein the network device is a Data Processing Unit (DPU) comprising a CPU and one or more processor cores;

wherein executing the first bus function comprises communicating with the CPU;

wherein the memory is internal to the CPU;

wherein executing the second bus function comprises communicating with the one or more processor cores; and

wherein the user applications run on the one or more processor cores.

14 . The method according to claim 8 , wherein defining the cross-security-domain MKEY comprises defining a first MKEY that modifies a Protection Domain (PD) of the sub-region, and defining a second MKEY that maps addresses of the sub-region.

15 . A data center, comprising one or more network devices, at least a network device among the network devices comprising:

one or more ports, to connect to a network;

a bus interface, to (i) communicate with a memory using a first bus domain of a peripheral bus, and (i) communicate with one or more user applications using a second bus domain of the peripheral bus; and

one or more circuits, to:

execute a first bus function that accesses a region of the memory using a memory-domain memory key (MKEY) defined in the first bus domain;

execute a second bus function that communicates with the user applications using the second bus domain, and communicates packets over the network for the user applications, wherein processing of the packets includes accessing the region of the memory via a cross-bus-domain MKEY that points to the memory-domain MKEY in the first bus function; and

in response to authorizing a user application to access a sub-region in the region of the memory, define for the sub-region a respective cross-security-domain MKEY that points to the cross-bus-domain MKEY, which in turn points to the memory-domain MKEY.

16 . The data center according to claim 15 , wherein, in response to authorizing one or more of the user applications to access one or more additional sub-regions in the region of the memory, the one or more circuits are to define one or more additional cross-security-domain MKEYs for the one or more additional sub-regions, the one or more additional cross-security-domain MKEYs pointing to the cross-bus-domain MKEY.

17 . The data center according to claim 15 , wherein the first bus function is to receive the cross-security-domain MKEY from a policer that authorizes requests from the user applications to access sub-regions in the region of the memory and defines respective cross-security-domain MKEYs for the sub-regions.

18 . The data center according to claim 15 , wherein, in response to a memory-access command from the user application that specifies a virtual address (VA), the one or more circuits are to translate the VA into a physical address (PA) in the sub-region, in accordance with an address mapping defined in the memory-domain MKEY, and to access the PA in the memory.

19 . The data center according to claim 15 ,

wherein the first bus function is to communicate with a Graphics Processing Unit (GPU), and the memory is internal to the GPU; and

wherein the second bus function is to communicate with one or more hosts, and the user applications run on the one or more hosts.

20 . The data center according to claim 15 ,

wherein the network device is a Data Processing Unit (DPU) comprising a CPU and one or more processor cores;

wherein the first bus function is to communicate with the CPU, and the memory is internal to the CPU; and

wherein the second bus function is to communicate with the one or more processor cores, and the user applications run on the one or more processor cores.