US2020218821A1PendingUtilityA1

Method and system for providing secure communications between a host system and a data processing accelerator

Assignee: BAIDU COM TIMES TECH BEIJING CO LTDPriority: Jan 4, 2019Filed: Jan 24, 2020Published: Jul 9, 2020
Est. expiryJan 4, 2039(~12.4 yrs left)· nominal 20-yr term from priority
H04L 63/0428G06F 21/606G06F 21/602G06F 21/62G06F 21/30H04L 63/0442H04L 2463/062H04L 63/062G06F 13/1668H04L 63/04G06F 21/6218
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

According to one embodiment, a system establishes a secure connection between a host system and a data processing (DP) accelerator over a bus, the secure connection including one or more data channels. The system transmits a first instruction from the host system to the DP accelerator over a command channel, the first instruction requesting the DP accelerator to perform a data preparation operation. The system receives a first request to read a first data from a first memory location of the host system from the DP accelerator over one data channel. In response to the request, the system transmits the first data to the DP accelerator over the data channel, where the first data is utilized for a computation or a configuration operation. The system transmits a second instruction from the host system to the DP accelerator over the command channel to perform the computation or the configuration operation.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method for secure communications between a host system and a data processing accelerator, the method comprising:
 establishing a secure connection between a host system and a data processing (DP) accelerator over a bus, the secure connection including a data channel;   transmitting a first instruction from the host system to the DP accelerator over a command channel, the first instruction requesting the DP accelerator to perform a data preparation operation;   receiving a first request to read a first data from a first memory location of the host system from the DP accelerator over the data channel, in response to the first instruction;   in response to the first request, transmitting the first data retrieved from the first memory location of the host system to the DP accelerator over the data channel, wherein the first data is utilized for a computation or a configuration operation; and   transmitting a second instruction from the host system to the DP accelerator over the command channel, the second instruction requesting the DP accelerator to perform the computation or the configuration operation.   
     
     
         2 . The method of  claim 1 , further comprising:
 examining the first request to determine whether the DP accelerator is entitled to read from the first memory location of the host system; and   allowing the DP accelerator to read from the first memory location, in response to determining that the DP accelerator is entitled to read from the first memory location.   
     
     
         3 . The method of  claim 2 , wherein the DP accelerator is not allowed to directly access the first memory location of the host system. 
     
     
         4 . The method of  claim 2 , wherein the DP accelerator is one of a plurality of DP accelerators coupled to the host system. 
     
     
         5 . The method of  claim 1 , further comprising:
 receiving a second request to write second data from the DP accelerator over the data channel, wherein the second data is to be written to a second memory location of the host system; and   in response to the second request, storing the second data at the second memory location of the host system.   
     
     
         6 . The method of  claim 5 , further comprising:
 examining the second request to determine whether the DP accelerator is entitled to write to the second memory location of the host system; and   allowing the DP accelerator to write to the second memory location, in response to determining that the DP accelerator is entitled to write to the second memory location.   
     
     
         7 . The method of  claim 5 , wherein the second data represents at least a portion of a result of the computation or the configuration operation in response to the instruction. 
     
     
         8 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations, the operations comprising:
 establishing a secure connection between a host system and a data processing (DP) accelerator over a bus, the secure connection including a data channel;   transmitting a first instruction from the host system to the DP accelerator over a command channel, the first instruction requesting the DP accelerator to perform a data preparation operation;   receiving a first request to read a first data from a first memory location of the host system from the DP accelerator over the data channel, in response to the first instruction;   in response to the first request, transmitting the first data retrieved from the first memory location of the host system to the DP accelerator over the data channel, wherein the first data is utilized for a computation or a configuration operation; and   transmitting a second instruction from the host system to the DP accelerator over the command channel, the second instruction requesting the DP accelerator to perform the computation or the configuration operation.   
     
     
         9 . The machine-readable medium of  claim 8 , wherein the operations further comprise:
 examining the first request to determine whether the DP accelerator is entitled to read from the first memory location of the host system; and   allowing the DP accelerator to read from the first memory location, in response to determining that the DP accelerator is entitled to read from the first memory location.   
     
     
         10 . The machine-readable medium of  claim 9 , wherein the DP accelerator is not allowed to directly access the first memory location of the host system. 
     
     
         11 . The machine-readable medium of  claim 9 , wherein the DP accelerator is one of a plurality of DP accelerators coupled to the host system. 
     
     
         12 . The machine-readable medium of  claim 8 , wherein the operations further comprise:
 receiving a second request to write second data from the DP accelerator over the data channel, wherein the second data is to be written to a second memory location of the host system; and   in response to the second request, storing the second data at the second memory location of the host system.   
     
     
         13 . The machine-readable medium of  claim 12 , wherein the operations further comprise:
 examining the second request to determine whether the DP accelerator is entitled to write to the second memory location of the host system; and   allowing the DP accelerator to write to the second memory location, in response to determining that the DP accelerator is entitled to write to the second memory location.   
     
     
         14 . The machine-readable medium of  claim 12 , wherein the second data represents at least a portion of a result of the computation or the configuration operation in response to the instruction. 
     
     
         15 . A computer-implemented method for secure communications between a host system and a data processing accelerator, the method comprising:
 establishing a secure connection between a host system and a data processing (DP) accelerator over a bus, the secure connection including a data channel;   receiving, at the DP accelerator, a first instruction from the host system over a command channel, the first instruction requesting the DP accelerator to perform a data preparation operation;   in response to the first instruction, transmitting a first request from the DP accelerator to the host system over the data channel to read a first data from a first memory location of the host system; receiving the first data from the host system over the data channel, wherein the first data was retrieved by the host system from the first memory location of the host system;   receiving a second instruction from the host system over the command channel, the second instruction requesting the DP accelerator to perform a computation or a configuration operation; and   performing the computation or the configuration operation based on at least the first data.   
     
     
         16 . The method of  claim 15 , wherein the host system is to examine the first request to determine whether the DP accelerator is entitled to read from the first memory location of the host system, and wherein the host system is to allow the DP accelerator to read from the first memory location, in response to determining that the DP accelerator is entitled to read from the first memory location. 
     
     
         17 . The method of  claim 16 , wherein the DP accelerator is not allowed to directly access the first memory location of the host system. 
     
     
         18 . The method of  claim 16 , wherein the DP accelerator is one of a plurality of DP accelerators coupled to the host system. 
     
     
         19 . The method of  claim 15 , further comprising transmitting a second request from the DP accelerator to the host system over the data channel to write second data to a second memory location of the host system, wherein the second data represents at least a portion of a result of the computation or the configuration operation. 
     
     
         20 . The method of  claim 19 , wherein the host system is to examine the second request to determine whether the DP accelerator is entitled to write to the second memory location of the host system, and wherein the host system is to allow the DP accelerator to write to the second memory location, in response to determining that the DP accelerator is entitled to write to the second memory location.

Join the waitlist — get patent alerts

Track US2020218821A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.