IP Library › Granted Patent US 12,170,624
Granted Patent B2
US 12,170,624 · App. 17/492,420 · Granted Dec 17, 2024

Technologies that provide policy enforcement for resource access

Inventors: Anjali Singhai Jain (Portland, OR); Daniel Daly (Santa Barbara, CA); Sridhar Samudrala (Portland, OR); Linden Cornett (Portland, OR); Phani Burra (Beaverton, OR); Brett Creeley (Hillsboro, OR)
Assignee: Intel Corporation
H04L47/762H04L47/2425H04L47/781H04L47/803H04L63/0428H04L63/101H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,170,624
App. No.
17/492,420
Granted
Dec 17, 2024
Kind
B2
Abstract

Examples described herein relate to one or more processors, when operational, to execute instructions stored in memory device, to cause performance of: execute a driver that is to: negotiate capabilities of hardware with a control plane for a virtualized execution environment and limit capabilities of the hardware available to the virtualized execution environment based on a service level agreement (SLA) associated with the virtualized execution environment. In some examples, the driver is to advertise hardware capabilities requested by the virtualized execution environment. In some examples, the control plane is to set capabilities of a hardware available to the virtualized execution environment based on the SLA.

Claims (31)

1. At least one non-transitory computer-readable medium comprising instructions stored thereon that if executed, cause on or more processors to:

execute a driver that is to:

negotiate device capabilities available to a virtualized execution environment with a control plane, wherein the device comprises a network interface device and a processor to execute the control plane and

provide access, by the virtualized execution environment, to fewer capabilities of the device than capabilities available from the device based on a service level agreement (SLA) associated with the virtualized execution environment.

2. The computer-readable medium of claim 1 , wherein the driver advertises requested capabilities of the virtualized execution environment.

3. The computer-readable medium of claim 1 , wherein the control plane sets available capabilities based on the SLA.

4. The computer-readable medium of claim 1 , wherein the control plane applies one or more access control lists (ACLs) to limit device capabilities usable by the virtualized execution environment.

5. The computer-readable medium of claim 1 , wherein the device capabilities comprise one or more of: checksum performance offload to a device, packet segmentation offload performance to the device, use of multiple cores to process traffic using multiple queues, receive side scaling (RSS) input set determination at the device, header split offset performance at the device, receive (RX) descriptor formats supported by the virtualized execution environment, transmit (TX) descriptors supported by the virtualized execution environment, Receive Side Coalescing performance offload to the device, remote direct memory access (RDMA) performance by a device, cryptographic operations performance by the device, multi-channel support by the device, number of interrupt vectors supported by the device, number of virtual ports (vports) supported by a device, or queues per vport supported by the device.

6. The computer-readable medium of claim 1 , wherein the device comprises one or more of: a central processing unit (CPU), graphics processing unit (GPU), memory device, storage device, storage controller, accelerator, a cryptographic accelerator device, infrastructure processing unit (IPU), data processing unit (DPU), smartNIC, or fabric interface.

7. A method comprising:

at a virtual device driver:

negotiating capabilities of a device available to a virtualized execution environment by communication with a control plane executed by the device, wherein the device comprises a network interface device and a processor to execute the control plane and

limiting capabilities of the device available to the virtualized execution environment based on a service level agreement (SLA) associated with the virtualized execution environment.

8. The method of claim 7 , wherein the virtual device driver advertises device capabilities requested by the virtualized execution environment.

9. The method of claim 7 , wherein the control plane sets capabilities of the device available to a virtualized execution environment based on the SLA.

10. The method of claim 7 , wherein the control plane applies one or more access control lists (ACLs) to limit device capabilities usable by the virtualized execution environment.

11. The method of claim 7 , wherein the capabilities of the device comprise one or more of: checksum performance offload to the device, packet segmentation offload performance to the device, use of multiple cores to process traffic using multiple queues, receive side scaling (RSS) input set determination at the device, header split offset performance at the device, receive (RX) descriptor formats supported by the virtualized execution environment, transmit (TX) descriptors supported by the virtualized execution environment, Receive Side Coalescing performance offload to the device, remote direct memory access (RDMA) performance by a device, cryptographic operations performance by the device, multi-channel support by the device, number of interrupt vectors supported by the device, number of virtual ports (vports) supported by a device, or queues per vport supported by the device.

12. The method of claim 7 , wherein the device comprises one or more of: a central processing unit (CPU), graphics processing unit (GPU), memory device, storage device, storage controller, accelerator, a cryptographic accelerator device, infrastructure processing unit (IPU), data processing unit (DPU), smartNIC, or fabric interface.

13. An apparatus comprising:

one or more processors, when operational, to execute instructions stored in memory device, to cause performance of:

execute a driver that is to:

negotiate capabilities of device with a control plane for a virtualized execution environment, wherein the device comprises a network interface device and a processor to execute the control plane and

limit capabilities of the device available to the virtualized execution environment based on a service level agreement (SLA) associated with the virtualized execution environment.

14. The apparatus of claim 13 , wherein the driver is to advertise device capabilities requested by the virtualized execution environment.

15. The apparatus of claim 13 , wherein the control plane is to set capabilities of the device available to the virtualized execution environment based on the SLA.

16. The apparatus of claim 13 , wherein the control plane is to apply one or more access control lists (ACLs) to limit device capabilities usable by the virtualized execution environment.

17. The apparatus of claim 13 , wherein the device capabilities comprise one or more of:

checksum performance offload to the device, packet segmentation offload performance to the device, use of multiple cores to process traffic using multiple queues, receive side scaling (RSS) input set determination at the device, header split offset performance at the device, receive (RX) descriptor formats supported by the virtualized execution environment, transmit (TX) descriptors supported by the virtualized execution environment, Receive Side Coalescing performance offload to the device, remote direct memory access (RDMA) performance by a device, cryptographic operations performance by the device, multi-channel support by the device, number of interrupt vectors supported by the device, number of virtual ports (vports) supported by a device, or queues per vport supported by the device.

18. The apparatus of claim 13 , wherein the device comprises one or more of: a central processing unit (CPU), graphics processing unit (GPU), memory device, storage device, storage controller, accelerator, a cryptographic accelerator device, infrastructure processing unit (IPU), data processing unit (DPU), smartNIC, or fabric interface.

19. The apparatus of claim 13 , comprising a server coupled to the device, wherein the server is to execute the virtualized execution environment.

20. The apparatus of claim 19 , comprising a data center coupled to the server, wherein the data center includes a controller that is to provide the SLA associated with the virtualized execution environment and cause the virtualized execution environment to be launched on the server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2021
From: JAIN, ANJALI SINGHAI; DALY, DANIEL; SAMUDRALA, SRIDHAR; CORNETT, LINDEN; BURRA, PHANI; CREELEY, BRETT
To: INTEL CORPORATION
Reel/Frame 058369/0307 →
Continuity (3)
Provisional Application 63145327 · Feb 3, 2021
Provisional Application 63122896 · Dec 8, 2020
Related Publication 20220029929A1 · Jan 27, 2022