A Software-only Mechanism for Device Passthrough and Sharing
نویسندگان
چکیده
Network processing elements in virtual machines, also known as Network Function Virtualization (NFV) often face CPU bottlenecks at the virtualization interface. Even highly optimized paravirtual device interfaces fall short of the throughput requirements of modern devices. Passthrough devices, together with SR-IOV support for multiple device virtual functions (VF) and IOMMU support, mitigate this problem somewhat, by allowing a VM to directly control a device partition bypassing the virtualization stack. However, device passthrough is riddled with its own problems of low consolidation ratios, relatively static resource partitioning, and difficulties in VM migration. We present a paravirtual interface that securely exposes an I/O device directly to the guest OS running inside the VM, and yet allows that device to be securely shared among multiple VMs and the host. Compared to the best-known paravirtualization interfaces, our paravirtual interface supports up to 2x higher throughput, and is closer in performance to device passthrough. Unlike device passthrough however, we do not require SR-IOV or IOMMU support, and allow fine-grained dynamic resource allocation, significantly higher consolidation ratios, and seamless VM migration. Our security mechanism is based on a novel approach called dynamic binary opcode subtraction.
منابع مشابه
An Incentive-Aware Lightweight Secure Data Sharing Scheme for D2D Communication in 5G Cellular Networks
Due to the explosion of smart devices, data traffic over cellular networks has seen an exponential rise in recent years. This increase in mobile data traffic has caused an immediate need for offloading traffic from operators. Device-to-Device(D2D) communication is a promising solution to boost the capacity of cellular networks and alleviate the heavy burden on backhaul links. However, dir...
متن کاملTowards Virtual Passthrough I/O on Commodity Devices
A commodity I/O device has no support for virtualization. A VMM can assign such a device to a single guest with direct, fast, but insecure access by the guest’s native device driver. Alternatively, the VMM can build virtual devices on top of the physical device, allowing it to be multiplexed across VMs, but with lower performance. We propose a technique that provides an intermediate option. In ...
متن کاملIncentive mechanism based on cooperative advertising for cost information sharing in a supply chain with competing retailers
This paper proposes a new motivation for information sharing in a decentralized channel consisting of a single manufacturer and two competing retailers. The manufacturer provides a common product to the retailers at the same wholesale price. Both retailers add their own values to the product and distribute it to consumers. Factors such as retail prices, values added to the product, and local ad...
متن کاملA Procurement-distribution Coordination Model in Humanitarian Supply Chain Using the Information-sharing Mechanism
The coordination problem of relief items’ distribution operations is essential in humanitarian relief chains. If the coordination is proper, it will improve the response phase to the crisis. In order to improve the coordination in humanitarian relief chains, distribution and warehousing operations of relief items were outsourced to the third-party logistics. In this paper, the procurement-distr...
متن کاملارائه الگوی پیشنهادی اشتراک دانش درون سازمانی میان اعضای هیأت علمی بر مبنای عوامل فردی، سازمانی و فنی
Introduction: Nowadays, knowledge sharing has become a source of gaining competitive advantage. The purpose of this paper is the identification and authentication of factors influencing intra-organizational knowledge sharing as well as proposing a model of knowledge sharing among faculty members engaged in medicine in universities and research centers. Methods : The present study was based ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1508.06367 شماره
صفحات -
تاریخ انتشار 2015