Vendor: Sifive, Inc. Category: DMA

Virtual Machine Security with WorldGuard™ Integration

Overview

The SiFive IOMMU Gen 2 is a scalable address translation engine connecting DMA capable I/O devices to system memory. Fully RISC-V IOMMU 1.0.1 compliant, it delivers advanced memory protection and nested virtualization. Its distributed microarchitecture removes the need for scatter-gather lists or bounce buffers, addressing core security and virtualization for high throughput subsystems. Supported across key SiFive Core IP products.

Challenge

Modern SoCs face explosive I/O traffic. Managing direct memory access across virtual machines creates security risks where unisolated drivers can corrupt privileged memory. Additionally, legacy 32-bit devices are disadvantaged in 64-bit addressing spaces. High throughput environments demand reliable isolation and translation without compromising speed.

Solution

SiFive IOMMU Gen 2 brings advanced virtualization support to the RISC-V open standard, featuring PCIe ATS and PRI support. Up to eight distributed IOTLBs communicate with a central IOMMU handling parallel page table walks, delivering safe, multi-tenant hardware architectures.

Impact

Architects can directly assign I/O devices to guest OSs without hypervisor intervention, reducing driver complexity. SiFive WorldGuard integration provides distinct logical partitions for secure execution. By accelerating translation, IOMMU Gen 2 empowers next-generation SoCs to achieve maximum performance.

ARCHITECTURAL HIGHLIGHTS

Distributed Micro-Architecture Scaling

The SiFive IOMMU Gen 2 implements a distributed design that splits address translation into a multitiered infrastructure. Small, low latency IOTLB modules sit close to the devices it serves to intercept device transactions instantly. When a local lookaside buffer misses, translation requests flow out of order via high speed AXI4 Stream links to the centralized main IOMMU. The main IOMMU core holds a large translation lookaside buffer and in case of miss it orchestrates parallel page table walkers (up to 32 instances) to navigate memory structures with minimal latency.

Deep WorldGuard Solution Integration

Security is handled through native coordination with system isolation policies. The IOMMU Gen 2 partitions its control planes into up to 4 distinct ways. Each incoming translation request is tagged with a World Identifier (WID), which is propagated through all internal caches, directory tables, and data structure paths. This ensures complete hardware enforced isolation between secure and non-secure execution environments.

Comprehensive PCIe ATS and PRI Support

For high speed peripheral component interconnect express (PCIe) topologies, the architecture incorporates Address Translation Services (ATS) and Page Request Interface (PRI). This enables endpoint devices to manage their own Address Translation Caches (ATCs), requesting page availability dynamically through in-memory circular buffer queues managed by system software.

Block Diagram

Benefits

  • Full Spec Compliance: Built in strict accordance with the RISC-V IOMMU 1.0.1 architecture standard.
  • Distributed Micro Architecture: Features a centralized main IOMMU core coupled with up to 8 distributed I/O Translation Lookaside Buffers (IOTLBs) placed close to individual devices.
  • Advanced Virtualization: Supports single stage translation and nested translation for first and second stage.
  • Flexible Paging Scheme: Full hardware support for standard RISC-V Sv39, Sv48 and Sv57 paging rules.
  • Industry Standard Interfaces: Implements Arm® AMBA® Distributed Translation Interface (DTI-ATSv2 and DTI-ATSv3) protocol support for PCIe ATS standard mechanisms.
  • Security Partitioning: Seamlessly integrates up to 4 independent logical ways, facilitating robust isolation across distinct software worlds.
  • Quality of Service (QoS): Native Resource Capacity ID (RCID) propagation to enforce strict cache capacity and bandwidth allocation policies.
  • Integrated Diagnostics: Comprehensive Hardware Performance Monitor (HPM) utilizing independent 40-bit event counters per domain.

Applications

  • Data Center
  • AI & ML
  • Automotive
  • Edge Computing

Specifications

Identity

Part Number
IOMMU Gen 2
Vendor
Sifive, Inc.
Type
Silicon IP

Files

Note: some files may require an NDA depending on provider policy.

Provider

HQ: USA

Learn more about DMA IP core

DMA IP Integration

There are many IP’s today . These IP’s can be simple IP’s like Timer to complex IP’s like Accelerators. In Most of the cases IP’s are Integrated in standard way. There are cases where you have the option of Integrating it differently. This goes un-noticed or unable to be implemented due to time constraints. One such IP that would be discussed in this paper is DMA . This paper tries to explain idea of Integrating Direct Memory access(DMA) and Interrupt Control Unit(ICU) differently but final implementation requires some changes in IP. There is a possibility that alternate design explained below may be already implemented.

Moving to AMBA® 5? Your AMBA® 4 IP Can Still Come With You

As SoC architectures adopt AMBA® 5 fabrics and components, many proven IP blocks still rely on AMBA® 4 or earlier interfaces. That creates a common integration problem: how do designers connect newer AMBA® 5 system components to existing IP without redesigning the IP or replacing verified blocks?

Frequently asked questions about DMA IP

What is Virtual Machine Security with WorldGuard™ Integration?

Virtual Machine Security with WorldGuard™ Integration is a DMA IP core from Sifive, Inc. listed on Semi IP Hub.

How should engineers evaluate this DMA?

Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this DMA IP.

Can this semiconductor IP be compared with similar products?

Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.

×
Semiconductor IP