首页> 外文会议>VLSI circuits and systems VI >An IOMMU for Hardware-assisted Full Virtualization of Heterogeneous Multi-core SoCs
【24h】

An IOMMU for Hardware-assisted Full Virtualization of Heterogeneous Multi-core SoCs

机译:一个IOMMU,用于异构多​​核SoC的硬件辅助完全虚拟化

获取原文
获取原文并翻译 | 示例

摘要

Hardware virtualization is a major challenge in embedded virtualization. The key to improving resource utilization in a virtualized system is to allow maximum possible resource access operations to perform natively with minimal intervention by the virtual machine monitor, while at the same time ensuring protected operation among different virtual machines' address space. An innovative I/O Memory Management Unit component (IOMMU) is architected to enable mapping of virtual addresses from multiple devices to the correct VM's physical memory locations, offering enhanced protection, scatter-gather functions on distributed memory organizations, high performance supported by a configurable TLB and an integrated lightweight hardware monitoring unit to facilitate dynamic system optimizations. This new IOMMU is designed in a modular way supporting address translation along with protection and security extensions. The principal objective is to ensure device isolation by safely mapping a device to a particular guest without risking the integrity of other guests. Additionally, the IOMMU is designed to provide an increased level of security in scenarios without virtualization; with the aid of the IOMMU, the operating system is able to protect itself from malicious device drivers by limiting a device's memory accesses and managing the permissions of peripheral devices.
机译:硬件虚拟化是嵌入式虚拟化的主要挑战。在虚拟化系统中提高资源利用率的关键是允许最大可能的资源访问操作在不受虚拟机监视器干预的情况下以本机方式执行,同时确保不同虚拟机地址空间之间的受保护操作。创新的I / O内存管理单元组件(IOMMU)旨在支持将虚拟地址从多个设备映射到正确的VM物理内存位置,从而提供增强的保护,分布式内存组织上的分散收集功能,可配置支持的高性能TLB和集成的轻量级硬件监视单元可促进动态系统优化。这个新的IOMMU以模块化的方式设计,支持地址转换以及保护和安全扩展。主要目标是通过将设备安全地映射到特定来宾来确保设备隔离,而不会冒其他来宾的完整性的风险。此外,IOMMU旨在在没有虚拟化的情况下提供更高级别的安全性;借助IOMMU,操作系统可以通过限制设备的内存访问并管理外围设备的权限来保护自己免受恶意设备驱动程序的侵害。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号