-
公开(公告)号:US10592434B2
公开(公告)日:2020-03-17
申请号:US15001379
申请日:2016-01-20
IPC分类号: G06F12/14 , G06F9/455 , G06F12/1009
摘要: Methods and systems for securing memory within a computing fabric are disclosed. One method includes allocating memory of one or more host computing systems in the computing fabric to a partition, the partition included among a plurality of partitions, the computing fabric including a hypervisor installed on the one or more host computing platforms and managing interactions among the plurality of partitions. The method includes defining an address range associated with the memory allocated to the partition, receiving a memory operation including an address within the address range, and, based on the memory operation including an address within the address range, issuing, by the hypervisor, an indication that the memory operation is occurring at an encrypted memory location. The method also includes performing the memory operation, and performing an encryption operation on data associated with the memory operation.
-
公开(公告)号:US11163597B2
公开(公告)日:2021-11-02
申请号:US15001374
申请日:2016-01-20
IPC分类号: G06F9/455 , G06F3/06 , G06F12/06 , G06F12/1081 , G06F12/02 , G06F15/173
摘要: A computing fabric includes one or more host computing platforms and a plurality of partitions instantiated across the one or more host computing platforms, each of the plurality of partitions allocated computing resources of the one or more host computing platforms. The computing fabric further includes a hypervisor installed on the one or more host computing platforms and managing interactions among the plurality of partitions. The plurality of partitions includes a persistent partition to which one or more storage devices are allocated, the persistent partition executing software loaded from a trusted storage location and executing from a non-volatile memory.
-
公开(公告)号:US09672058B2
公开(公告)日:2017-06-06
申请号:US14468651
申请日:2014-08-26
CPC分类号: G06F9/45558 , G06F9/5077 , G06F2009/45575 , G06F2009/45583
摘要: A reduced service partition system and method for a host computing device having a host processor and system resources including memory divided into most privileged system memory and less privileged user memory. The system includes a virtualization boot application that operates in the less privileged user memory and divides the host computing device into a resource management partition, at least one virtual service partition and at least one virtual guest partition. The virtual guest partition provides a virtualization environment for at least one guest operating system. The virtual service partition provides a virtualization environment for the basic operations of the virtualization system. The resource management partition maintains a resource database for use in managing the use of the host processor and the system resources. A monitor operates in the most privileged system memory, and maintains guest applications in the at least one virtual guest partition within memory space allocated by the virtual service partition to the at least one virtual guest partition. A context switch between the at least one monitor and the respective virtual guest partitions and the virtual service partition controls multitask processing in the partitions on the at least one host processor.
-
4.
公开(公告)号:US09384060B2
公开(公告)日:2016-07-05
申请号:US14487192
申请日:2014-09-16
申请人: James R Hunter , Sung V Huynh , Edward T Cavanagh , John A Landis
发明人: James R Hunter , Sung V Huynh , Edward T Cavanagh , John A Landis
CPC分类号: G06F9/5077 , G06F9/4411 , G06F9/45545 , G06F9/45558 , G06F2009/45579
摘要: Methods and systems for allocating, one or more virtual functions of a plurality of virtual functions associated with physical functions of I/O interface devices of a computing device are described. One method includes managing one or more physical functions of an I/O interface device within an interconnect partition of a multi-partition virtualization system implemented at least in part on the computing device. The method further includes, during a boot process of a second partition on the computing device, parsing a file to determine an assignment of one or more virtual functions to the second partition and associate each of the one or more virtual functions to corresponding physical functions.
摘要翻译: 描述用于分配与计算设备的I / O接口设备的物理功能相关联的多个虚拟功能的一个或多个虚拟功能的方法和系统。 一种方法包括管理至少部分地在计算设备上实现的多分区虚拟化系统的互连分区内的I / O接口设备的一个或多个物理功能。 该方法还包括在计算设备上的第二分区的引导过程期间,解析文件以确定一个或多个虚拟功能对第二分区的分配,并将一个或多个虚拟功能中的每一个与相应的物理功能相关联。
-
公开(公告)号:US10965616B2
公开(公告)日:2021-03-30
申请号:US14519532
申请日:2014-10-21
IPC分类号: H04L12/933 , H04L29/08 , H04L29/12 , G06F9/50
摘要: Systems and methods for non-stop computing in a virtualization fabric are disclosed. One system includes a computing fabric comprising a plurality of host platforms, the plurality of host platforms including at least a first host platform and a second host platform communicatively connected to the first host platform. The system also includes an interconnect service partitions residing on the first host platform. The system includes a plurality of guest partitions distributed across the plurality of host platforms. The system further includes a DNS server instance managed by at least one of the plurality of interconnect service partitions and defining at least one zone, the at least one zone including one or more partitions from among the plurality of guest partitions distributed across the plurality of host platforms.
-
公开(公告)号:US10599458B2
公开(公告)日:2020-03-24
申请号:US14603496
申请日:2015-01-23
IPC分类号: G06F15/177 , G06F9/455 , G06F9/50 , H04L12/46 , H04L12/715
摘要: A Forward Fabric platform system for coupling to a data center platform. The Forward Fabric platform system includes a plurality of nodes, an interconnect backplane coupled between the nodes, and a Forward Fabric Manager (FFM) coupled to the nodes via the interconnect backplane for controlling and managing the Forward Fabric platform system. The Forward Fabric manager creates at least one secure partition (s-Par) application executing within at least one of the nodes. At least one of the nodes having a secure partition (s-Par) application executing therein also includes a software defined network (SDN) controller executing therein for receiving configuration information and providing at least one secure and non-stop Forward Fabric endpoint on the Forward Fabric platform system for connecting with at least one endpoint on the data center platform. At least one of the nodes having a secure partition (s-Par) application executing therein also includes a traffic control component and a router switch component. At least one the nodes is coupled to the data center platform via one or more non-stop fabric segments.
-
公开(公告)号:US09804877B2
公开(公告)日:2017-10-31
申请号:US14487210
申请日:2014-09-16
申请人: James R Hunter , Sung V Huynh , Edward T Cavanagh , John A Landis
发明人: James R Hunter , Sung V Huynh , Edward T Cavanagh , John A Landis
CPC分类号: G06F9/45558 , G06F9/5077 , G06F13/28 , G06F13/4221 , G06F2009/45579 , G06F2009/45583 , G06F2213/0026
摘要: Methods and systems for managing reset of a physical function of an I/O device in a computing system are disclosed, where the physical function is included in a single-root PCI manager. One method includes maintaining a count of active virtual functions associated with the physical function included in the single-root PCI manager, and, upon determining that no active virtual functions are associated with the physical function, allowing the physical function to be reset within the single-root PCI manager. The method further includes while resetting the physical function, persisting a configuration memory space associated with the physical function, and associating the persisted configuration memory space with the physical function after the physical function is reset.
-
-
-
-
-
-