Method and apparatus for securing and segregating host to host messaging on PCIe fabric
First Claim
Patent Images
1. A method of operating a switch fabric having a point-to-point network protocol, the method comprising:
- receiving an input from a switch fabric administrator defining subnets;
generating a virtual fabric ID (VFID) for at least one defined subnet;
tagging packets of outgoing messages from at least one host with the virtual fabric ID; and
determining if an incoming message to at least one host has a tag matching the virtual fabric ID;
wherein receive processing for incoming messages is supported if the tag of the incoming message matches an approved virtual fabric ID and the message is dropped within the switch if the tag does not match the approved virtual fabric ID.
8 Assignments
0 Petitions
Accused Products
Abstract
A PCIe fabric includes at least one PCIe switch. The fabric may be used to connect multiple hosts. The PCIe switch implements security and segregation measures for host-to-host message communication. A management entity defines a Virtual PCIe Fabric ID (VPFID). The VPFID is used to enforce security and segregation. The fabric ID may be extended to be used in switch fabrics with other point-to-point protocols.
-
Citations
23 Claims
-
1. A method of operating a switch fabric having a point-to-point network protocol, the method comprising:
-
receiving an input from a switch fabric administrator defining subnets; generating a virtual fabric ID (VFID) for at least one defined subnet; tagging packets of outgoing messages from at least one host with the virtual fabric ID; and determining if an incoming message to at least one host has a tag matching the virtual fabric ID; wherein receive processing for incoming messages is supported if the tag of the incoming message matches an approved virtual fabric ID and the message is dropped within the switch if the tag does not match the approved virtual fabric ID. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A method of operating a switch fabric having a point-to-point network protocol, the method comprising:
-
generating a table defining a virtual fabric ID (VFID) for at least one defined subnet; tagging packets of outgoing messages from at least one host with the virtual fabric ID; and determining if an incoming message to at least one host has a tag matching the virtual fabric ID; wherein receive processing for incoming messages is supported if the tag matches the virtual fabric ID and the message is dropped within the switch if the tag does not match the virtual fabric ID. - View Dependent Claims (13, 14, 15, 16, 17, 18, 19, 20, 21, 22)
-
-
23. A PCI express switch in connection with a management system, wherein a memory in the management system stores a table of virtual fabric IDs to enforce security and segregation of host-to-host message flows for hosts coupled to the PCI express switch.
Specification