Rate This Document
Findability
Accuracy
Completeness
Readability

PF Passthrough

Device passthrough utilizes the PCIe protection controller (PCIPC) embedded in the PCIe root complex of the Kunpeng processor. A selector is added to the PCIe bus to regulate communication between the processor and peripherals. Operating through the system memory management unit (SMMU), this selector controls both inbound and outbound traffic. In confidential computing scenarios, PCIPC-enabled PCIe devices can be directly connected to the Realm, eliminating data forwarding or copying operations to protect the entire data link. Based on this technology, Kunpeng confidential computing supports heterogeneous confidential computing without requiring any device reconstruction. Figure 1 shows the PF passthrough process.

Based on the CCA PCIPC device passthrough capability, secure isolation and performance enhancements for PCIe devices are achieved, providing the following advantages:

  • Secure isolation

    Once the CCA capability is enabled, secure devices protected by PCIPC can only be accessed from the Realm side, and are inaccessible to host-side software.

  • High performance

    cVM passthrough in the Realm eliminates performance overhead on the data plane compared to industry encryption and decryption solutions.

  • Ease of use

    Compatibility with existing open-source OSs removes the requirement for kernel driver modifications.

    Figure 1 PF passthrough process