Virtual Machine Security with WorldGuard™ Integration
Overview
The SiFive IOMMU Gen 2 is a scalable address translation engine connecting DMA capable I/O devices to system memory. Fully RISC-V IOMMU 1.0.1 compliant, it delivers advanced memory protection and nested virtualization. Its distributed microarchitecture removes the need for scatter-gather lists or bounce buffers, addressing core security and virtualization for high throughput subsystems. Supported across key SiFive Core IP products.
Challenge
Modern SoCs face explosive I/O traffic. Managing direct memory access across virtual machines creates security risks where unisolated drivers can corrupt privileged memory. Additionally, legacy 32-bit devices are disadvantaged in 64-bit addressing spaces. High throughput environments demand reliable isolation and translation without compromising speed.
Solution
SiFive IOMMU Gen 2 brings advanced virtualization support to the RISC-V open standard, featuring PCIe ATS and PRI support. Up to eight distributed IOTLBs communicate with a central IOMMU handling parallel page table walks, delivering safe, multi-tenant hardware architectures.
Impact
Architects can directly assign I/O devices to guest OSs without hypervisor intervention, reducing driver complexity. SiFive WorldGuard integration provides distinct logical partitions for secure execution. By accelerating translation, IOMMU Gen 2 empowers next-generation SoCs to achieve maximum performance.
ARCHITECTURAL HIGHLIGHTS
Distributed Micro-Architecture Scaling
The SiFive IOMMU Gen 2 implements a distributed design that splits address translation into a multitiered infrastructure. Small, low latency IOTLB modules sit close to the devices it serves to intercept device transactions instantly. When a local lookaside buffer misses, translation requests flow out of order via high speed AXI4 Stream links to the centralized main IOMMU. The main IOMMU core holds a large translation lookaside buffer and in case of miss it orchestrates parallel page table walkers (up to 32 instances) to navigate memory structures with minimal latency.
Deep WorldGuard Solution Integration
Security is handled through native coordination with system isolation policies. The IOMMU Gen 2 partitions its control planes into up to 4 distinct ways. Each incoming translation request is tagged with a World Identifier (WID), which is propagated through all internal caches, directory tables, and data structure paths. This ensures complete hardware enforced isolation between secure and non-secure execution environments.
Comprehensive PCIe ATS and PRI Support
For high speed peripheral component interconnect express (PCIe) topologies, the architecture incorporates Address Translation Services (ATS) and Page Request Interface (PRI). This enables endpoint devices to manage their own Address Translation Caches (ATCs), requesting page availability dynamically through in-memory circular buffer queues managed by system software.
Block Diagram
Benefits
- Full Spec Compliance: Built in strict accordance with the RISC-V IOMMU 1.0.1 architecture standard.
- Distributed Micro Architecture: Features a centralized main IOMMU core coupled with up to 8 distributed I/O Translation Lookaside Buffers (IOTLBs) placed close to individual devices.
- Advanced Virtualization: Supports single stage translation and nested translation for first and second stage.
- Flexible Paging Scheme: Full hardware support for standard RISC-V Sv39, Sv48 and Sv57 paging rules.
- Industry Standard Interfaces: Implements Arm® AMBA® Distributed Translation Interface (DTI-ATSv2 and DTI-ATSv3) protocol support for PCIe ATS standard mechanisms.
- Security Partitioning: Seamlessly integrates up to 4 independent logical ways, facilitating robust isolation across distinct software worlds.
- Quality of Service (QoS): Native Resource Capacity ID (RCID) propagation to enforce strict cache capacity and bandwidth allocation policies.
- Integrated Diagnostics: Comprehensive Hardware Performance Monitor (HPM) utilizing independent 40-bit event counters per domain.
Applications
- Data Center
- AI & ML
- Automotive
- Edge Computing
Specifications
Identity
Files
Note: some files may require an NDA depending on provider policy.
Provider
Learn more about DMA IP core
DMA IP Integration
Using peripheral DMA boosts networked 32 bit MCU security and bandwidth
New AXI Scatter-Gather DMA Core Transfers Streaming Data to/from System Memory
Moving to AMBA® 5? Your AMBA® 4 IP Can Still Come With You
Hitting the Memory Wall:Why Cache Miss Tolerance Defines CPU Performance Now
Frequently asked questions about DMA IP
What is Virtual Machine Security with WorldGuard™ Integration?
Virtual Machine Security with WorldGuard™ Integration is a DMA IP core from Sifive, Inc. listed on Semi IP Hub.
How should engineers evaluate this DMA?
Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this DMA IP.
Can this semiconductor IP be compared with similar products?
Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.