IP Library Granted Patent US 9,858,184
Granted Patent B2
US 9,858,184 · App. 14/840,829 · Granted Jan 2, 2018

Efficient and secure direct storage device sharing in virtualized environments

Inventors: Gheorghe Almasi (Ardsley, NY); Hubertus Franke (Cortlandt Manor, NY); Gokul B. Kandiraju (Briarcliff Manor, NY); Davide Pasetto (Bedford Hills, NY); Hartmut Penner (Herrenberg, DE)
Assignee: International Business Machines Corporation
G06F12/0646G06F3/06G06F9/50G06F12/109G06F13/16G06F21/78G06F2212/1016G06F2212/152G06F2212/657
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,858,184
App. No.
14/840,829
Granted
Jan 2, 2018
Kind
B2
Abstract

A method, system and computer program product are disclosed for direct storage device sharing in a virtualized environment. In an embodiment, the method comprises assigning each of a plurality of virtual functions an associated memory area of a physical memory, and executing the virtual functions in a single root-input/output virtualization environment to provide each of a plurality of guests with direct access to the physical memory. In one embodiment, each of the guests is associated with a respective one of the virtual functions; and the assigning each of the plurality of virtual functions an associated memory area includes maintaining a per-virtual function mapping table identifying a respective one mapping function for each of the virtual functions, and each of the mapping functions mapping one of the memory areas of the physical area to an associated virtual memory.

Claims (30)

1. A method of direct storage device sharing in a virtualized environment, comprising:

a storage controller assigning each of a plurality of virtual functions of a plurality of guests an associated memory area of a physical memory, including at a first boot of one of the guests, the storage controller receiving a request from the one of the guests, said request including an authentication key, and in response to the request, triggering an interrupt of a physical function to a hypervisor; and the storage controller receiving from the hypervisor a configuration command over the physical function, the configuration command setting up hardware in the storage controller to allocate storage in the storage device for said one of the guests and to provide a mapping function for the authentication key to provide the one of the guests with access to a specified storage area in the storage device; and

the storage controller executing the virtual functions in a single root-input/output virtualization environment to provide each of a plurality of guests with direct access to the physical memory, including for a subsequent boot of the one of the guests, after said first boot, the storage controller receiving a subsequent request from the one of the guests, said subsequent request including the authentication key, and the storage controller setting up a mapping function for the authentication key, without intervention of the hypervisor during said subsequent boot, to provide said one of the guests with direct access only to the specified storage area in the storage device set up for the authentication key.

2. The method according to claim 1 , wherein:

each of the guests is associated with a respective one of the virtual functions; and

the assigning each of the plurality of virtual functions an associated memory area includes:

maintaining a per-virtual function mapping table identifying a respective one mapping function for each of the virtual functions; and

each of the mapping functions mapping one of the memory areas of the physical area to an associated virtual memory.

3. The method according to claim 1 , wherein:

each of the guests is associated with one of the virtual functions; and

the assigning each of a plurality of virtual functions an associated memory area includes allocating storage memory area in the physical memory to each of the virtual functions, and providing a mapping function for each of the virtual functions to map the memory area in the physical memory assigned to said each virtual function to a virtual memory area for said each virtual function.

4. The method according to claim 3 , wherein the allocating storage memory area in the physical memory includes:

the one of the guests sending the request to the storage controller using the virtual functions associated with said one of the guests; and

the storage controller allocating said storage memory area in the physical memory to said associated virtual function, and providing the mapping function to said associated virtual function.

5. The method according to claim 4 , wherein the allocating storage memory area in the physical memory further includes:

said associated virtual function, in response to said request, triggering the interrupt of the physical function to the hypervisor; and

the hypervisor determining whether to grant or to reject the request.

6. The method according to claim 5 , wherein the allocating storage memory area in the physical memory further includes:

when the hypervisor determines to grant the request, the hypervisor sending the configuration command over the physical function to the storage controller; and

the storage controller using the configuration command to allocate the storage memory area in the physical memory to said associated virtual function, and to provide the mapping function to said associated virtual function.

7. The method according to claim 6 , wherein:

the one of the guests sending a request includes said one of the guests sending a request control block including the request to the storage controller; and

the storage controller using the configuration command includes the storage controller sending an interrupt to said associated virtaul function and providing the request control block with a positive result of the request.

8. The method according to claim 4 , wherein:

the authentication key identifies said one of the guests; and

the storage controller allocating said storage memory area further includes the storage controller maintaining a table identifying one of the mapping functions for said authentication key.

9. The method according to claim 8 , wherein the executing the virtual functions includes the storage controller using said one of the mapping functions to map one of the memory areas in the physical memory to said one of the guests.

10. The method according to claim 1 , wherein:

the assigning each of a plurality of virtual functions an associated memory area includes assigning each of the virtual functions a respective one memory area of the physical memory; and

the executing the virtual functions includes executing the virtual functions in the single-root input/output virtualization environment to provide each of the guests with direct access to a respective one of the memory areas of the physical memory.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2017
From: ALMASI, GHEORGHE; FRANKE, HUBERTUS; KANDIRAJU, GOKUL B.; PASETTO, DAVIDE; PENNER, HARTMUT
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 043781/0369 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2015
From: ALMASI, GHEORGHE; FRANKE, HUBERTUS; KANDIRAJU, GOKUL B.; PENNER, HARTMUT
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 036460/0221 →
Continuity (2)
Continuation 14584058 · Dec 29, 2014
Related Publication 20160188465A1 · Jun 30, 2016