Hypervisor-enforced self encrypting memory in computing fabric

    公开(公告)号:US10592434B2

    公开(公告)日:2020-03-17

    申请号:US15001379

    申请日:2016-01-20

    摘要: Methods and systems for securing memory within a computing fabric are disclosed. One method includes allocating memory of one or more host computing systems in the computing fabric to a partition, the partition included among a plurality of partitions, the computing fabric including a hypervisor installed on the one or more host computing platforms and managing interactions among the plurality of partitions. The method includes defining an address range associated with the memory allocated to the partition, receiving a memory operation including an address within the address range, and, based on the memory operation including an address within the address range, issuing, by the hypervisor, an indication that the memory operation is occurring at an encrypted memory location. The method also includes performing the memory operation, and performing an encryption operation on data associated with the memory operation.

    Reduced service partition virtualization system and method

    公开(公告)号:US09672058B2

    公开(公告)日:2017-06-06

    申请号:US14468651

    申请日:2014-08-26

    IPC分类号: G06F9/455 G06F9/50

    摘要: A reduced service partition system and method for a host computing device having a host processor and system resources including memory divided into most privileged system memory and less privileged user memory. The system includes a virtualization boot application that operates in the less privileged user memory and divides the host computing device into a resource management partition, at least one virtual service partition and at least one virtual guest partition. The virtual guest partition provides a virtualization environment for at least one guest operating system. The virtual service partition provides a virtualization environment for the basic operations of the virtualization system. The resource management partition maintains a resource database for use in managing the use of the host processor and the system resources. A monitor operates in the most privileged system memory, and maintains guest applications in the at least one virtual guest partition within memory space allocated by the virtual service partition to the at least one virtual guest partition. A context switch between the at least one monitor and the respective virtual guest partitions and the virtual service partition controls multitask processing in the partitions on the at least one host processor.

    Dynamic allocation and assignment of virtual functions within fabric
    4.
    发明授权
    Dynamic allocation and assignment of virtual functions within fabric 有权
    织物内虚拟功能的动态分配和分配

    公开(公告)号:US09384060B2

    公开(公告)日:2016-07-05

    申请号:US14487192

    申请日:2014-09-16

    摘要: Methods and systems for allocating, one or more virtual functions of a plurality of virtual functions associated with physical functions of I/O interface devices of a computing device are described. One method includes managing one or more physical functions of an I/O interface device within an interconnect partition of a multi-partition virtualization system implemented at least in part on the computing device. The method further includes, during a boot process of a second partition on the computing device, parsing a file to determine an assignment of one or more virtual functions to the second partition and associate each of the one or more virtual functions to corresponding physical functions.

    摘要翻译: 描述用于分配与计算设备的I / O接口设备的物理功能相关联的多个虚拟功能的一个或多个虚拟功能的方法和系统。 一种方法包括管理至少部分地在计算设备上实现的多分区虚拟化系统的互连分区内的I / O接口设备的一个或多个物理功能。 该方法还包括在计算设备上的第二分区的引导过程期间,解析文件以确定一个或多个虚拟功能对第二分区的分配,并将一个或多个虚拟功能中的每一个与相应的物理功能相关联。

    Nonstop computing fabric arrangements

    公开(公告)号:US10965616B2

    公开(公告)日:2021-03-30

    申请号:US14519532

    申请日:2014-10-21

    摘要: Systems and methods for non-stop computing in a virtualization fabric are disclosed. One system includes a computing fabric comprising a plurality of host platforms, the plurality of host platforms including at least a first host platform and a second host platform communicatively connected to the first host platform. The system also includes an interconnect service partitions residing on the first host platform. The system includes a plurality of guest partitions distributed across the plurality of host platforms. The system further includes a DNS server instance managed by at least one of the plurality of interconnect service partitions and defining at least one zone, the at least one zone including one or more partitions from among the plurality of guest partitions distributed across the plurality of host platforms.

    Fabric computing system having an embedded software defined network

    公开(公告)号:US10599458B2

    公开(公告)日:2020-03-24

    申请号:US14603496

    申请日:2015-01-23

    摘要: A Forward Fabric platform system for coupling to a data center platform. The Forward Fabric platform system includes a plurality of nodes, an interconnect backplane coupled between the nodes, and a Forward Fabric Manager (FFM) coupled to the nodes via the interconnect backplane for controlling and managing the Forward Fabric platform system. The Forward Fabric manager creates at least one secure partition (s-Par) application executing within at least one of the nodes. At least one of the nodes having a secure partition (s-Par) application executing therein also includes a software defined network (SDN) controller executing therein for receiving configuration information and providing at least one secure and non-stop Forward Fabric endpoint on the Forward Fabric platform system for connecting with at least one endpoint on the data center platform. At least one of the nodes having a secure partition (s-Par) application executing therein also includes a traffic control component and a router switch component. At least one the nodes is coupled to the data center platform via one or more non-stop fabric segments.