IP Library Granted Patent US 9,223,737
Granted Patent B1
US 9,223,737 · App. 13/826,884 · Granted Dec 29, 2015

Computer interconnect isolation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,223,737
App. No.
13/826,884
Granted
Dec 29, 2015
Kind
B1
Abstract

Methods and systems are provided routing access requests produced by a function to a physical sharing machine on a computer interconnect fabric. Access requests are routed through a switch that includes an NTB, the NTB using an address-lookup table to ensure that access requests made by multiple physical sharing machines are appropriately isolated from one another.

Claims (39)

1. A method for routing access requests produced by a function to a physical sharing machine on a computer interconnect fabric, the method comprising:

receiving an access request at a computer interconnect fabric, caused by accessing a function provided by a device coupled to the computer interconnect fabric, the access request being directed to a physical sharing machine that is communicatively coupled to the computer interconnect fabric through a non-transparent bridge (NTB), wherein the physical sharing machine is a host and the physical sharing machine is associated with a global address range and an ID;

routing the access request through the computer interconnect fabric from the device to a pre-defined port of a switch at which an NTB is enabled;

using address and source identity information related to the access request received at the switch to retrieve a corresponding entry in an address-translation lookup table at the switch, wherein the entry in the address-translation lookup table includes bus-device-function information for which the entry allows communication, and the global address range and the ID of the physical sharing machine;

confirming, based on the information in the address-translation lookup table associated with the entry, that the function is allowed to access the physical sharing machine, and in response to the confirming:

translating the access request based on the entry, to be routed using the switch to an offset within the global address range of the physical sharing machine with which the request is associated; and

routing the access request to the physical sharing machine based on the global address range, the offset, and the ID.

2. The method of claim 1 , wherein the computer interconnect fabric is a PCIe fabric and wherein the ID is a PCIe source ID.

3. The method of claim 1 , wherein the device is a self-virtualizing device under the SR-IOV specification.

4. The method of claim 1 , wherein the function is a virtual function.

5. The method of claim 1 , wherein the switch is located on a chip that is distinct from the computer interconnect fabric.

6. The method of claim 1 , wherein the switch is located on a chip that is integrated into the computer interconnect fabric.

7. The method of claim 1 , wherein the access request is a bus-master access request.

8. The method of claim 1 , wherein all access requests from the device are required to pass through the pre-defined port by access control services built into the computer interconnect fabric.

9. The method of claim 1 , wherein the translating the access request comprises:

sending the access request through a loopback connection back into the switch; and

translating the access request into the global address range, by the switch, after receiving the access request from the loopback connection.

10. The method of claim 1 , wherein the translating the access request comprises:

translating the access request into the global address range, by the switch, prior to routing the access request to the physical sharing machine.

11. A system for routing access requests produced by a function to a physical sharing machine on a computer interconnect fabric, the system comprising:

a computer interconnect fabric, configured to:

receive an access request at a computer interconnect fabric, caused by accessing a function provided by a device coupled to the computer interconnect fabric, the access request being directed to a physical sharing machine that is communicatively coupled to the computer interconnect fabric through a non-transparent bridge (NTB), wherein the physical sharing machine is a host and the physical sharing machine is associated with a global address range and an ID; and

route the access request from the device to a pre-defined port of a switch at which an NTB is enabled, wherein the switch is configured to:

use address and source identity information related to the access request received at the switch to retrieve a corresponding entry in an address-translation lookup table at the switch, wherein the entry in the address-translation lookup table includes bus-device-function information for which the entry allows communication, and the global address range and the ID of the physical sharing machine;

confirm, based on the information in the address-translation lookup table associated with the entry, that the function is allowed to access the physical sharing machine, and in response to the confirming:

translate the access request based on the entry, to be routed using the switch to an offset within the global address range of the physical sharing machine with which the request is associated; and

route the access request to the physical sharing machine based on the global address range, the offset, and the ID.

12. The system of claim 11 , wherein the computer interconnect fabric is a PCIe fabric and wherein the ID is a PCIe source ID.

13. The system of claim 11 , wherein the device is a self-virtualizing device under the SR-IOV specification.

14. The system of claim 11 , wherein the function is a virtual function.

15. The system of claim 11 , wherein the switch is located on a chip that is distinct from the computer interconnect fabric.

16. The system of claim 11 , wherein the switch is located on a chip that is integrated into the computer interconnect fabric.

17. The system of claim 11 , wherein the access request is a bus-master access request.

18. The system of claim 11 , wherein all access requests from the device are required to pass through the pre-defined port by access control services built into the computer interconnect fabric.

19. The system of claim 11 , wherein the translating the access request comprises:

sending the access request through a loopback connection back into the switch; and

translating the access request into the global address range, by the switch, after receiving the access request from the loopback connection.

20. The system of claim 11 , wherein the translating the access request comprises:

translating the access request into the global address range, by the switch, prior to routing the access request to the physical sharing machine.

Assignments (2)
CHANGE OF NAME Recorded Oct 2, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044566/0657 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2013
From: SEREBRIN, BENJAMIN C.
To: GOOGLE INC.
Reel/Frame 030393/0593 →