Configuration file loading method, device, system and storage medium

By encrypting the configuration file of the FPGA board and decrypting it using a decryption key, the security problem of the configuration file on the FPGA cloud platform is solved, enabling normal configuration and secure loading of user functional logic.

CN113378173BActive Publication Date: 2026-03-03ALIBABA GROUP HOLDING LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-03-10
Publication Date
2026-03-03

AI Technical Summary

Technical Problem

On an FPGA cloud platform, how can we ensure the security of configuration files while guaranteeing that the functional logic required by users can be configured correctly?

Method used

The configuration file of the FPGA board is encrypted, and the encrypted configuration file and decryption key are provided to the FPGA board. The configuration file is decrypted using the decryption key and the burning operation is performed to complete the loading of the configuration file.

Benefits of technology

While ensuring the security of the configuration file, it also ensures that the functional logic required by the user can be configured normally, thereby improving the security and reliability of the configuration file.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113378173B_ABST
    Figure CN113378173B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a configuration file loading method, device, system and storage medium. In the embodiments of the present application, an FPGA board card is plugged into an FPGA device, and the FPGA board card loads a configuration file of corresponding function logic to provide corresponding services for an instance deployed on the FPGA device. In the process of loading the configuration file by the FPGA board card, the configuration file of the FPGA board card is encrypted, which is conducive to ensuring the security of the configuration file. In addition, the encrypted configuration file and a decryption key required for decrypting the encrypted configuration file are sent to the FPGA board card, so that the FPGA board card decrypts the configuration file according to the decryption key, and then performs a burn-writing operation of the configuration file to complete the loading of the configuration file. The embodiments of the present application can ensure that the required function logic of the user can be normally configured while ensuring the security of the configuration file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cloud computing technology, and in particular to a configuration file loading method, device, system, and storage medium. Background Technology

[0002] With the development of cloud computing technology, Field Programmable Gate Arrays (FPGAs) have received increasing attention in cloud computing applications, and more and more cloud computing applications are switching to FPGA cloud platforms.

[0003] Configuration files, as a way to configure FPGA functional logic, are also important IP assets for users, reflecting the functional logic required by the user. On FPGA cloud platforms, ensuring the security of configuration files while guaranteeing the correct configuration of the required functional logic is a pressing issue that needs to be addressed. Summary of the Invention

[0004] This application provides a configuration file loading method, device, system, and storage medium to ensure the security of the configuration file and to ensure that the functional logic required by the user can be configured normally.

[0005] This application provides an FPGA-based cloud network, including: a network management device and an FPGA device; at least one FPGA board is plugged into the FPGA device, and a first instance is also deployed on the FPGA device, the first instance forming a binding relationship with the first FPGA board in the FPGA board;

[0006] The first instance is used to encrypt the configuration file of the first FPGA board to obtain an encrypted configuration file; the encrypted configuration file and the decryption key required to decrypt the encrypted configuration file are provided to the first FPGA board.

[0007] The network management device is used to send configuration file burning instructions to the FPGA device according to the user's FPGA configuration instructions, so as to instruct the FPGA device to trigger the first FPGA board to perform the configuration file burning operation;

[0008] The first FPGA board is used to decrypt the configuration file from the encrypted configuration file according to the decryption key and perform the configuration file burning operation.

[0009] This application also provides a configuration file loading method applicable to FPGA devices. A first instance is deployed on the FPGA device, and the first instance is bound to a first FPGA board on the FPGA device. The method includes: encrypting the configuration file of the first FPGA board to obtain an encrypted configuration file; providing the encrypted configuration file and the decryption key required to decrypt the encrypted configuration file to the first FPGA board, so that the first FPGA board can decrypt the configuration file and perform the configuration file burning operation.

[0010] This application also provides a configuration file loading method applicable to FPGA boards. The method includes: receiving an encrypted configuration file and a decryption key for decrypting the encrypted configuration file provided by the user of the FPGA board; decrypting the encrypted configuration file according to the decryption key to obtain the configuration file required by the first FPGA; and performing a configuration file burning operation.

[0011] This application embodiment also provides an FPGA device, including: one or more memories, one or more processors, communication components, and at least one FPGA board; the FPGA device is further deployed with a first instance, and the first instance is bound to the first FPGA board in the FPGA board;

[0012] Among them, one or more memories store the program corresponding to the first instance; one or more processors are used to execute the program corresponding to the first instance for: generating a configuration file for the first FPGA board, encrypting the configuration file to obtain an encrypted configuration file; and providing the encrypted configuration file and the decryption key required to decrypt the encrypted configuration file to the first FPGA board.

[0013] One or more memories also store FPGA management programs, and one or more processors are also used to execute FPGA management programs for: receiving configuration file writing instructions through a communication component, triggering a first FPGA board to decrypt the configuration file from the encrypted configuration file according to the decryption key and perform the configuration file writing operation according to the configuration file writing instructions.

[0014] This application embodiment also provides an FPGA board, including: a logic layer and a dynamic area; the logic area includes: a decryption engine and a PR configuration module; the dynamic area includes: a key control engine; the key control engine is used to obtain a decryption key for decrypting an encrypted configuration file and provide the decryption key to the decryption engine; the decryption engine is used to decrypt the encrypted configuration file according to the decryption key and provide the decrypted configuration file to the PR configuration module; the PR configuration module is used to perform the configuration file burning operation; wherein, the encrypted configuration file is provided by the user of the FPGA board.

[0015] In this embodiment, an FPGA board is plugged into the FPGA device. The FPGA board loads a configuration file containing the corresponding functional logic to provide services to the instances deployed on the FPGA device. During the configuration file loading process, encrypting the FPGA board's configuration file helps ensure its security. Furthermore, by sending the encrypted configuration file and the decryption key required to decrypt it to the FPGA board, the FPGA board can decrypt the configuration file using the decryption key and then perform the configuration file programming operation to complete the loading. Therefore, while ensuring the security of the configuration file, it also ensures that the functional logic required by the user can be configured normally. Attached Figure Description

[0016] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0017] Figure 1a A schematic diagram of the structure of an FPGA-based cloud network provided for an exemplary embodiment of this application;

[0018] Figure 1b A schematic diagram of another FPGA-based cloud network structure provided for an exemplary embodiment of this application;

[0019] Figure 1c for Figure 1b The diagram shows a detailed workflow of an FPGA-based cloud network.

[0020] Figure 1d A schematic diagram of the structure of a first FPGA board provided for an exemplary embodiment of this application;

[0021] Figure 1e A schematic diagram of another first FPGA board provided as an exemplary embodiment of this application;

[0022] Figure 2a A flowchart illustrating a configuration file loading method provided for an exemplary embodiment of this application;

[0023] Figure 2b A flowchart illustrating another configuration file loading method provided for an exemplary embodiment of this application;

[0024] Figure 3 A schematic diagram of the structure of an FPGA device provided for an exemplary embodiment of this application;

[0025] Figure 4 This is a schematic diagram of the structure of an FPGA board provided as an exemplary embodiment of this application. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0027] To address the security issues of configuration files faced by existing FPGA cloud platforms, this embodiment of the application incorporates an FPGA board plugged into the FPGA device. The FPGA board loads a configuration file containing the corresponding functional logic to provide services to instances deployed on the FPGA device. During the configuration file loading process, encrypting the FPGA board's configuration file helps ensure its security. Furthermore, by sending the encrypted configuration file and the decryption key required to decrypt it to the FPGA board, the FPGA board can decrypt the configuration file using the decryption key and then perform the configuration file programming operation to complete the loading process. Therefore, while ensuring the security of the configuration file, it also ensures that the functional logic required by the user can be configured correctly.

[0028] FPGA is a further development based on programmable devices such as PAL (Programmable Array Logic) and GAL (Generic Array Logic). It emerged as a semi-custom circuit in the field of application-specific integrated circuits (ASICs), addressing the shortcomings of custom circuits while overcoming the limited gate count of traditional programmable devices. Therefore, this application provides an FPGA-based cloud network 100, which is a computing service network based on FPGA. Figure 1a As shown, the FPGA-based cloud network 100 includes: a network management device 101 and an FPGA device 102; the FPGA device 102 is equipped with at least one FPGA board 103, which is used to provide corresponding services to the users of the cloud network 100.

[0029] In this embodiment, the number of FPGA devices 102 is not limited; there can be one or multiple devices. The FPGA device 102 can be a desktop computer, laptop computer, smartphone, or IoT device, or a server-side device such as a conventional server, cloud server, or server array. Figure 1aThe image shows multiple FPGA devices 102, but is not limited to this. Similarly, in this embodiment, the number of FPGA boards 103 that each FPGA device 102 can connect to is not limited; for example, it can be one or multiple boards. Furthermore, the number of FPGA boards 103 that different FPGA devices 102 can connect to can be the same or different. Figure 1a As shown, the FPGA device 102 includes not only the FPGA board 103, but also other hardware resources such as CPU, network card, and I / O interface; above the hardware resource layer is the operating system (OS) layer, and above the OS layer is the application layer, wherein the first instance 104 is deployed in the application layer.

[0030] The cloud network 100 can provide computing, storage, and network resources to the outside world, thereby offering various services such as cloud computing services, cloud storage services, and edge computing services. Users can purchase or rent the various resources provided by the cloud network 100 and deploy various instances on these resources to obtain the services they need. Alternatively, users can directly purchase or rent various instances provided by the cloud network 100 to obtain the services they require. The implementation form of the instance is related to the virtualization technology supported by the cloud network 100, which is not limited in this embodiment; for example, it can be a virtual machine (VM), a container (Docker), or a native application. Users of the cloud network 100 can be individuals or enterprises. Of course, from another perspective, users of the cloud network 100 can also be other services requiring services, applications, application systems, hardware modules, or computer equipment.

[0031] Whether the instances are deployed by users of cloud network 100 or provided by cloud network 100 itself, these instances are primarily deployed on FPGA devices 102 within cloud network 100. In this embodiment, instances deployed on FPGA devices 102 can use FPGA boards 103 plugged into FPGA devices 102 as their resources and utilize FPGA boards 103 to provide corresponding services. The process of using FPGA boards to provide corresponding services is the same or similar for any instance. In this embodiment, taking the first instance 104 deployed on a certain FPGA device 102 as an example, the process of an instance using FPGA boards to provide corresponding services is explained.

[0032] The first instance 104 can provide one or more computing services, such as cloud computing services. The first instance 104 can be implemented as a VM, Docker, or a native application. Different instance types offer different computing and storage capabilities, suitable for different application scenarios, and users can choose the instance type based on their specific needs. Taking a virtual machine (VM) as an example, the first instance 104 is a complete computer system simulated by software, possessing full hardware system functionality and running in a completely isolated environment. All tasks that can be performed on a physical computer can be performed in the first instance 104. Creating the first instance 104 on the FPGA device 102 is equivalent to creating a VM, which includes basic computing components such as CPU, memory, operating system, network, and disk. Users and / or deployers of the first instance 104 (collectively referred to as users) can manipulate the first instance 104 to meet their service needs according to their own requirements.

[0033] In this application embodiment, the specific method by which the user controls the first instance 104 is not limited. For example, the user of the first instance 104 can control the first instance 104 through human-computer interaction. Any human-computer interaction method that enables the user to control the first instance 104 can be used in this application embodiment. For example, the first instance 104 can provide a human-computer interaction interface to the user, which can be a webpage, an APP page, or a command window, etc. Then, the user can open a webpage, APP page, or command window on their local terminal, remotely log in to the first instance 104 through the webpage, APP page, or command window, and control the first instance 104. In the command window mode, the first instance 104 supports various command lines, and the user can directly enter command lines to control the first instance 104.

[0034] In this embodiment, at least one FPGA board 103 is plugged into the FPGA device 102 where the first instance 104 is deployed. The first instance 104 and the first FPGA board 103a of the FPGA board 103 form a binding relationship, that is, the first FPGA board 103 bound to the first instance 104 can serve as a computing resource for the first instance 104, providing corresponding services to the first instance 104. The number of first FPGA boards 103a is not limited; for example, it can be one or more. Of course, the first FPGA board bound to different first instances will also be different.

[0035] In this scenario, the primary operation of the first instance 104 using the first FPGA board 103a to provide services involves programming the functional logic required by the first instance 104 (or the user) onto the first FPGA board 103a. This programming is typically achieved by loading a configuration file. Optionally, the configuration file required by the first FPGA board 103a can be pre-generated based on the user's desired functional logic. Alternatively, an Integrated Drive Electronics (IDE) tool can be installed in the first instance 104, and the configuration file for the first FPGA board 103a can be generated after completing synthesis, placement, and routing processes using the IDE tool, based on the user's required functional logic. The configuration file is a computer file that configures the FPGA's functional logic; loading the configuration file enables the implementation of the user's logic functions on the FPGA.

[0036] In this embodiment, to securely configure the configuration file into the first FPGA board 103a, the first instance 104 can encrypt the configuration file of the first FPGA board 103a to obtain an encrypted configuration file. Optionally, the first instance 104 may have software, program code, or SDK with encryption function installed. In this embodiment, the encryption method for the configuration file is not limited; any method that can encrypt the configuration file is applicable to this embodiment.

[0037] For example, the first instance 104 can use a symmetric encryption algorithm to encrypt the configuration file of the first FPGA board 103a. The process of encrypting the configuration file of the first FPGA board 103a using a symmetric encryption algorithm includes: generating a key, using this key to encrypt the configuration file of the first FPGA board 103a to obtain an encrypted configuration file; simultaneously, this key can also be provided to the first FPGA board 103a as a decryption key to decrypt the encrypted configuration file, so that the first FPGA board 103a can decrypt the configuration file. The symmetric encryption algorithms that can be used include, but are not limited to, the Advanced Encryption Standard (AES) algorithm and the Data Encryption Standard (DES) algorithm.

[0038] For example, in the first instance 104, an asymmetric encryption algorithm can be used to encrypt the configuration file of the first FPGA board 103a. The process of encrypting the configuration file of the first FPGA board 103a using an asymmetric encryption algorithm includes: generating a key pair; encrypting the configuration file of the first FPGA board 103a using the private key to obtain an encrypted configuration file; and providing the public key as the decryption key to the first FPGA board 103a so that the first FPGA board 103a can decrypt the configuration file. The asymmetric encryption algorithms that can be used include, but are not limited to, elliptic curve cryptography, RSA encryption, and ElGamal encryption, etc.

[0039] After encrypting the configuration file of the first FPGA board 103a, the first instance 104 can provide the obtained encrypted configuration file and the decryption key required to decrypt the encrypted configuration file to the first FPGA board 103a.

[0040] In this application embodiment, the specific implementation of the first instance 104 providing the encrypted configuration file to the first FPGA board 103a is not limited. For example, the first instance 104 may directly configure the encrypted configuration file to the first FPGA board 103a. As another example, such as... Figure 1b As shown, the cloud network 100 may further include a storage system 106. The first instance 104 can provide an encrypted configuration file to the storage system 106, which stores the encrypted configuration file and allows any party requiring the encrypted configuration file to retrieve it from the storage system 106. In this embodiment, the implementation of the storage system 106 is not limited; it can refer to any storage system capable of storing data. For example, the storage system 106 can be various types of databases, a data warehouse, or a data lake. A data lake is a system that provides users with serverless, interactive query and analysis services in the cloud. This data lake includes or integrates an object storage system (OSS) for storing data, databases supporting different database languages ​​(e.g., PostgreSQL, MySQL), and a non-relational (NoSQL) distributed storage system (e.g., TableStore). Figure 1b The illustration uses OSS (Object Storage Service) as an example for storage system 106, but it is not limited to this. In this embodiment, the configuration file is transmitted and stored in encrypted form throughout the entire process, which can improve the security of the configuration file.

[0041] Similarly, in this embodiment, the specific implementation of the first instance 104 providing the decryption key to the first FPGA board 103a is not limited. For example, the first instance 104 can directly configure the decryption key into the first FPGA board 103a in plaintext. Alternatively, to further improve the security of the configuration file, the first instance 104 can encrypt the decryption key and provide the encrypted decryption key to the first FPGA board 103a. Encrypting the decryption key improves its security, thereby increasing the difficulty of cracking the configuration file and further enhancing its security. In this embodiment, the encryption algorithm used to encrypt the decryption key is not limited. For example, a symmetric encryption algorithm or an asymmetric encryption algorithm can be used to encrypt the decryption key.

[0042] In the method of encrypting the decryption key using a symmetric encryption algorithm, optionally, an encryption key required for encrypting the decryption key can be temporarily generated and provided to the first FPGA board 103a for decryption. For example, a random number can be generated as the encryption key required for encrypting the decryption key. Or,

[0043] In the method of encrypting the decryption key using a symmetric encryption algorithm, optionally, the encryption key required for encrypting the decryption key can be pre-set and pre-installed in the first FPGA board 103a, so that the first FPGA board 103a can decrypt the decryption key. For example, the user ID bound to the first instance can be used as the encryption key required for encrypting the decryption key. The user ID bound to the first instance can then be used to encrypt the decryption key, and this user ID can be pre-configured on the first FPGA board for the first FPGA board to decrypt the decryption key. Here, the user ID is strongly correlated with the first instance, making it difficult to crack, which helps improve the security of the decryption key, and thus improves the security of the configuration file.

[0044] Whether the decryption key is provided to the first FPGA board 103a in plaintext or ciphertext, the first instance 104 can directly configure either the plaintext or ciphertext decryption key into the first FPGA board 103a. Alternatively, in the case of providing the decryption key to the first FPGA board 103a in ciphertext, the first instance 104 can also upload the ciphertext decryption key to the storage system 106, so that the party requiring the decryption key can retrieve it from the storage system 106.

[0045] After providing the encrypted configuration file and decryption key to the first FPGA board 103a, the user can initiate FPGA configuration commands. For example... Figure 1a and Figure 1b As shown, the cloud network 100 in this embodiment also includes a network management device 101. This embodiment does not limit the product form of the network management device 101; for example, it can be a terminal device such as a desktop computer, laptop computer, smartphone, or IoT device, or a server-side device such as a conventional server, cloud server, or server array. Figure 1a and Figure 1b The diagram illustrates a network management device 101 using a server array as an example. The network management device 101 is primarily responsible for managing various resources within the cloud network 100, such as the FPGA device 102, the FPGA boards 103 on the FPGA device 102, and the instances on the FPGA device 102. It also provides users with an interface for interaction with the cloud network 100, allowing users to manage their instances and the FPGA boards bound to those instances. Based on this, users can initiate FPGA configuration commands through the network management device 101. This embodiment does not limit the specific implementation method of users initiating FPGA configuration commands through the network management device 101. For example, the network management device 101 can provide a web page with FPGA configuration controls. Users can initiate FPGA configuration commands by clicking the FPGA configuration controls on the web page. The FPGA configuration command includes the identification information of the FPGA board, used to identify which FPGA board is being configured. This embodiment does not limit the identification information of the FPGA board; it can be, but is not limited to, the FPGA board's ID, name, or serial number, or the ID or name of the instance bound to the FPGA board. In cases where there is a one-to-one binding relationship between FPGA boards and instances, the ID or name of the instance bound to the FPGA board can also uniquely identify the FPGA board.

[0046] For network management device 101, a configuration file writing command can be sent to FPGA device 102 according to the user's FPGA configuration instructions, instructing FPGA device 102 to trigger the first FPGA board 103a to perform the configuration file writing operation. The configuration file writing operation refers to the process of writing the configuration file to the FPGA board. Figure 1a and Figure 1bAs shown, the FPGA device 102 can also be equipped with an FPGA management program 105. Running this FPGA management program 105 can trigger or control the configuration file burning operations performed by each FPGA board 103 plugged into the FPGA device 102. The FPGA management program 105 is different from the first instance 104. After triggering the configuration file burning operation, the first FPGA board 103a can decrypt the configuration file from the encrypted configuration file using the decryption key and perform the configuration file burning operation, completing the configuration file loading process. After successfully loading the configuration file, the first FPGA board 103a can provide the necessary services to the first instance, such as acceleration services, decoding services, encryption services, or cloud computing services.

[0047] Furthermore, in Figure 1b In the case where the cloud network 100 includes a storage system 106, the first instance 104 can upload the encrypted configuration file to the storage system 106. Based on this, the FPGA device 102 can also be used to: read the encrypted configuration file from the storage system 106 according to the configuration file writing instructions, and configure the encrypted configuration file into the first FPGA board 103a. Furthermore, the first FPGA board 103a can decrypt the configuration file from the encrypted configuration file according to the decryption key, and perform the configuration file writing operation to complete the configuration file loading process.

[0048] The following is combined Figure 1b The diagram shows an overall schematic of an FPGA-based cloud network, combined with... Figure 1c The flowchart shown illustrates the complete process of loading and programming the configuration file onto the first FPGA board 103a. The entire process includes the generation and encryption of the user-side configuration file, as well as the decryption and loading of the internal configuration file of the first FPGA board 103a. Figure 1c In the diagram, the first instance 104 is represented as a VM. The user side of the instance (e.g., VM) corresponds to the first instance 104 and its user side, primarily responsible for generating and encrypting the configuration file. The control end corresponds to the FPGA management program 105 in the above embodiment; the NC end corresponds to the first FPGA board 103a in the above embodiment. The control end and NC end work together to primarily implement the decryption and loading of the configuration file. Figure 1c As shown, the detailed process includes the following steps:

[0049] 1. The user performs PFGA logic design.

[0050] 2. After completing the PFGA logic design, the original bit file, i.e. the configuration file before encryption, is generated after completing the synthesis, placement and routing processes using relevant FPGA IDE tools.

[0051] 3. The original bit file (the configuration file before encryption) is encrypted using a configuration file encryption engine, and the encrypted configuration file and corresponding decryption key are output. In this way, the configuration file is transmitted and stored in encrypted form throughout the entire process, ensuring security.

[0052] 4. Upload the encrypted configuration file to the storage system.

[0053] 5. Encrypt the decryption key using the user ID associated with the first instance to obtain the encrypted decryption key. Encrypting the decryption key ensures that it remains unknown to the third party throughout the entire transmission chain, thus guaranteeing its security.

[0054] The order of steps 4 and 5 is not limited; they can be executed in parallel or sequentially. When executed sequentially, step 4 can be executed first, followed by step 5, or vice versa.

[0055] 6. Initiate the configuration command for the decryption key, that is, send the encrypted decryption key to the NC side (i.e., the first FPGA board 103a) so that the NC side can configure and expand the decryption key.

[0056] 7. Wait for the configuration and expansion of the decryption key to complete.

[0057] 8. On the NC side, decrypt the decryption key and initiate decryption key configuration and extension.

[0058] 9. After completing the configuration and expansion of the decryption key, send the FPGA configuration command to the control terminal.

[0059] 10. After receiving the FPGA configuration command, the control terminal retrieves the encrypted configuration file from the storage system.

[0060] 11. The control terminal determines whether the logic version of the configuration file matches the FPGA version. If yes, proceed to step 12; otherwise, inform the user that the versions do not match.

[0061] 12. Send a configuration file burning command to the NC terminal.

[0062] 13. The NC terminal receives the configuration file burning command.

[0063] 14. The NC terminal uses the decryption key to decrypt the configuration file and then burns the decrypted configuration file into the FPGA.

[0064] 15. After performing the programming operation, the programming result is checked, and the configuration result is returned to the control terminal. If programming fails, it means that the configuration file and the decryption key do not match. The original logic on the FPGA remains unchanged, and a system alarm is triggered. If programming is successful, the FPGA executes the new configuration logic.

[0065] 16. The control terminal determines whether the burning result is successful; if yes, proceed to step 17, i.e., exit normally; if no, proceed to step 18, i.e., exit with an error.

[0066] In the above embodiments of this application, by encrypting the configuration file of the FPGA board and transmitting and storing it in ciphertext, the configuration file cannot be cracked even if it is attacked or intercepted by a third party without the decryption key and encryption algorithm, thus improving the security of the configuration file. Furthermore, the decryption key required to decrypt the encrypted configuration file is also encrypted, and is transmitted and presented in ciphertext throughout the entire process, ensuring the security of the decryption key and further enhancing the security of the configuration file.

[0067] In this application embodiment, the implementation structure of the first FPGA board 103a is not limited. Any FPGA board structure that can obtain the encrypted configuration file and decryption key, and can use the decryption key to decrypt the configuration file and perform the configuration file burning operation is applicable to this application embodiment.

[0068] In an alternative embodiment, such as Figure 1d As shown, one implementation structure of the first FPGA board 103a includes: a decryption engine 31, a partial-reconfiguration (PR) configuration module 32, and a key control engine 33. When the first instance 104 encrypts the decryption key and provides the encrypted decryption key to the first FPGA board 103a, the key control engine 33 is used to receive and store the encrypted decryption key provided by the first instance 104, and to decrypt the decryption key from the encrypted decryption key and provide the decryption key to the decryption engine 31. The decryption engine 31 is used to receive the encrypted configuration file provided by the first instance 104 or the FPGA device 102, and to decrypt the encrypted configuration file according to the decryption key, and to provide the decrypted configuration file to the PR configuration module 32. The PR configuration module 32 is used to perform the configuration file burning operation to complete the loading of the configuration file.

[0069] It should be noted that the key control engine 33 is an optional module. When the decryption key is transmitted in plaintext, the first FPGA board 103a may not include the key control engine 33. Of course, when the first FPGA board 103a includes the key control engine 33, the decryption key can also be transmitted in plaintext. Furthermore, the key control engine 33 can be implemented logically within the FPGA, for example, designed using a Hardware Description Language (HDL) or a High Level Synthesis Language (HLS). This implementation method is independent of the specific hardware environment of the FPGA board. Simultaneously, the storage and configuration of the decryption key within the FPGA board can be logically controlled, independent of specific resources on the FPGA board. This implementation provides favorable conditions for cross-platform and cloud-based implementation of configuration file loading. At the same time, the decryption scheme can be more diversified, providing different encryption and decryption methods for different users or instances in the cloud, which is beneficial to improving the trustworthiness and security of the cloud network.

[0070] Further optional, such as Figure 1d As shown, the first FPGA board 103a includes a logic layer (Shell) 107 and a dynamic area (Role) 108. Modifying the logic layer 107 is relatively costly, as it typically stores the basic infrastructure that different applications might require, such as DRAM controllers, high-speed serial transceivers, PCIe modules responsible for communication with the host, DDR, clock configuration, PR, and other general-purpose functional logic such as various I / O interfaces. The dynamic area 108 has a relatively low update cost and can be considered a reconfigurable logic unit, programmable and configurable according to different user applications. In this implementation, the decryption engine 31 and PR configuration module 32, as the basic architecture of the FPGA, can be located in the logic area 107, while the key control engine 32, which can provide different decryption methods for different user or instance needs and has a higher probability of being updated or changed, can be located in the dynamic area 108. This combination of the logic layer and the dynamic area ensures the lightweight design of the Shell, greatly improves development convenience, and helps shorten development time.

[0071] It should be noted that the aforementioned decryption engine 31 and PR configuration module 32 are located in the logical area 107, and the key control engine 32 is located in the dynamic area 108. This is merely an exemplary and preferred implementation method, and is not limited thereto. For example, the key control engine 32, decryption engine 31, and PR configuration module 32 can all be located in the logical area 107.

[0072] Further optional, such as Figure 1eAs shown, the logic area 107 also includes a key configuration and expansion module 34. Logically, the key configuration and expansion module 34 is located between the key control engine 33 and the decryption engine 31. After the key control engine 32 decrypts the decryption key, it can send the decryption key to the key configuration and expansion module 34. The key configuration and expansion module 34 receives the decryption key provided by the key control engine 32, performs configuration and expansion processing on the decryption key, and provides the expanded decryption key to the decryption engine 31 so that the decryption engine 31 can decrypt the encrypted configuration file. Specifically, the decryption engine 31 can receive the expanded decryption key provided by the key configuration and expansion module 34 and use the expanded decryption key to decrypt the encrypted configuration file. It should be noted that the key configuration and expansion module 34 is an optional module. If the encryption algorithm used in the first instance 104 requires key expansion, the first FPGA board 103a can include the key configuration and expansion module 34; otherwise, it may not include the key configuration and expansion module 34. Of course, if the first FPGA board 103a includes a key configuration and expansion module 34, an encryption algorithm that does not require key expansion can also be used.

[0073] Further optional, such as Figure 1e As shown, the logic area 107 also includes a PR monitoring module 35. The PR monitoring module 35 is used to monitor whether the configuration file burning operation is successful and output alarm information in case of failure. In this embodiment, the output method of the alarm information is not limited; for example, it may include, but is not limited to, voice prompt alarm, buzzer alarm, diode light prompt, etc. Specifically, in the case of a failed burning operation, the original functional logic of the first FPGA board 103a remains unchanged; in the case of a successful burning operation, the first FPGA board 103a will execute new functional logic. It should be noted that when the first FPGA board 103a is used for the first time, it may not contain any functional logic.

[0074] It should be noted that, in Figure 1d and Figure 1e In order to highlight the structure of the first FPGA board 103a and the configuration file loading logic, the internal structure of the FPGA device 102 was simplified.

[0075] Based on the above embodiments, optionally, after receiving the user's FPGA configuration command, before sending the configuration file burning command to the FPGA device 102, the network management device 101 may also obtain the version number of the encrypted configuration file, determine whether the version number of the encrypted configuration file is consistent with the shell version number of the first FPGA board 103a, and if it is determined that they are consistent, send the configuration file burning command to the FPGA device 102. In this application embodiment, the specific implementation method of the network management device 101 obtaining the version number of the encrypted configuration file is not limited. Examples are given below:

[0076] Method 1: The FPGA configuration command issued by the user carries the version number of the encrypted configuration file. The network management device 101 can parse the version number of the encrypted configuration file from the FPGA configuration command; then, it determines whether the version number is consistent with the shell version number of the first FPGA board 103a.

[0077] Method 2: FPGA device 102 can store the binding relationship between the first instance 104 and the first FPGA board 103a. After generating the configuration file, the first instance 104 can also add the version number of the configuration file to the binding relationship. Based on this, network management device 101 can obtain the version number of the configuration file (that is, the version number of the encrypted configuration file) from the binding relationship and determine whether the version number is consistent with the shell version number of the first FPGA board 103a.

[0078] Method 3: After receiving the user's FPGA configuration instruction, before sending the configuration file burning instruction to the FPGA device 102, the network management device 101 can read the encrypted configuration file from the storage system 106, and thus know the version number of the encrypted configuration file; determine whether the version number of the encrypted configuration file is consistent with the shell version number of the first FPGA board 103a, and when it is determined that they are consistent, send the configuration file burning instruction to the FPGA device 102.

[0079] Regardless of the method used, if it is determined that the version number of the encrypted configuration file is inconsistent with the shell version number of the first FPGA board, the user can be informed of the version mismatch so that the user can correct the version of the configuration file.

[0080] In conjunction with the aforementioned cloud network, this application embodiment also provides a configuration file loading method. This method is applicable to FPGA devices, specifically to a first instance deployed on the FPGA device. In other words, the FPGA device runs the program code corresponding to the first instance to implement the steps in the following method embodiments. The first instance is bound to a first FPGA board on the FPGA device. The first instance can be any instance on the FPGA device, and the first FPGA board can be any one or more boards on the FPGA device. Figure 2a As shown, the method includes the following steps:

[0081] 21a. Encrypt the configuration file of the first FPGA board to obtain an encrypted configuration file;

[0082] 22a. Provide the encrypted configuration file and the decryption key required to decrypt the encrypted configuration file to the first FPGA board, so that the first FPGA board can decrypt the configuration file and perform the configuration file burning operation.

[0083] In this embodiment, the first FPGA board can provide corresponding services for the first instance, that is, to program the functional logic required by the first instance (or user) onto the first FPGA board. Typically, programming functional logic onto an FPGA board is achieved by loading a configuration file. A configuration file is a computer file that configures the functional logic of an FPGA; loading the configuration file completes the implementation of the user's logic functions on the FPGA.

[0084] In this embodiment, the method of obtaining the configuration file is not limited. For example, the configuration file required by the first FPGA board can be generated in advance according to the functional logic required by the user. Alternatively, an IDE tool can be installed in the first instance, and then the configuration file of the first FPGA board can be generated after the synthesis, placement and routing processes are completed by the IDE tool according to the functional logic required by the user.

[0085] In this embodiment, to securely configure the configuration file onto the first FPGA board, the FPGA device can encrypt the configuration file of the first FPGA board to obtain an encrypted configuration file. Optionally, the first instance may have software, program code, or SDK with encryption functions installed; correspondingly, the FPGA device can run the software, program code, or SDK with encryption functions in the first instance to complete the encryption operation of the configuration file of the first FPGA board. In this embodiment, the encryption method of the configuration file is not limited; any method that can encrypt the configuration file is applicable to this application embodiment. For example, it can be symmetric encryption or asymmetric encryption, etc. Please refer to the foregoing system embodiment for details.

[0086] After encrypting the configuration file of the first FPGA board, the obtained encrypted configuration file and the decryption key required to decrypt it can be provided to the first FPGA board. In this embodiment, the specific implementation of providing the encrypted configuration file to the first FPGA board is not limited. For example, the encrypted configuration file can be directly configured onto the first FPGA board. Alternatively, the encrypted configuration file can be provided to a storage system, allowing a party requiring the encrypted configuration file to obtain it from the storage system. In this embodiment, the implementation of the storage system is not limited; it can refer to any storage system with data storage capabilities.

[0087] Similarly, in this embodiment, the specific implementation of providing the decryption key to the first FPGA board is not limited. For example, the decryption key can be directly configured into the first FPGA board in plaintext. As another example, to further improve the security of the configuration file, in an optional embodiment, the decryption key can be encrypted, and the encrypted decryption key can be provided to the first FPGA board. Encrypting the decryption key improves its security, thereby increasing the difficulty of cracking the configuration file and further enhancing its security. In this embodiment, the encryption algorithm used to encrypt the decryption key is not limited. For example, a symmetric encryption algorithm or an asymmetric encryption algorithm can be used to encrypt the decryption key.

[0088] In the method of encrypting the decryption key using a symmetric encryption algorithm, optionally, a temporary encryption key required for encrypting the decryption key can be generated and provided to the first FPGA board for decryption. For example, a random number can be generated as the encryption key required for encrypting the decryption key. Or,

[0089] In the method of encrypting the decryption key using a symmetric encryption algorithm, optionally, the encryption key required for encrypting the decryption key can be pre-set and pre-installed in the first FPGA board for the first FPGA board to decrypt and extract the decryption key. For example, the user ID bound to the first instance can be used as the encryption key required for encrypting the decryption key. The user ID bound to the first instance can then be used to encrypt the decryption key, and this user ID can be pre-configured on the first FPGA board for the first FPGA board to decrypt and extract the decryption key. Here, the user ID is strongly correlated with the first instance, making it difficult to crack, which helps improve the security of the decryption key, and thus improves the security of the configuration file.

[0090] Whether the decryption key is provided to the first FPGA board in plaintext or ciphertext, for the first instance, the decryption key in either plaintext or ciphertext can be directly configured into the first FPGA board. Alternatively, in the method of providing the decryption key to the first FPGA board in ciphertext, the ciphertext decryption key can also be uploaded to the storage system so that the party requiring the decryption key can retrieve it from the storage system.

[0091] In summary, after providing the encrypted configuration file and the decryption key required to decrypt it to the first FPGA board, the first FPGA board can decrypt the encrypted configuration file using the decryption key to obtain the configuration file (referred to as the configuration file decryption operation), and then perform the configuration file programming operation (referred to as the configuration file programming operation). Optionally, the first FPGA board can initiate the configuration file decryption and programming operations automatically after receiving the encrypted configuration file and decryption key, or it can initiate the configuration file decryption and programming operations under the trigger of the FPGA device. In addition to deploying the first instance, the FPGA device also deploys an FPGA management program. By running the FPGA management program, the FPGA device can receive configuration file programming instructions issued by the network management device, and trigger the first FPGA board to perform the configuration file decryption and programming operations according to the configuration file programming instructions.

[0092] This application also provides a configuration file loading method, which is described from the perspective of an FPGA board (e.g., the first FPGA board described above). Figure 2b As shown, the method includes the following steps:

[0093] 21b. Receive the encrypted configuration file and the decryption key used to decrypt the encrypted configuration file provided by the user of the FPGA board;

[0094] 22b. Decrypt the encrypted configuration file using the decryption key to obtain the configuration file required by the first FPGA;

[0095] 23b. Perform the configuration file burning operation.

[0096] In this embodiment, the user of the FPGA board is not limited. For example, it can be an instance deployed on the FPGA device where the FPGA board resides. This instance can be a virtual machine, container, or native application, but is not limited to these. Similarly, this embodiment does not limit the method by which the FPGA board receives the encrypted configuration file and decryption key. For example, the computer device containing the encrypted configuration file and decryption key can be connected to the FPGA board, and the encrypted configuration file and decryption key can be downloaded to the FPGA board via a download cable or network transmission. Another example is that the user of the FPGA board uploads the encrypted configuration file and decryption key to a storage system, and the FPGA device where the FPGA board resides reads the encrypted configuration file and decryption key from the storage system and configures it into the FPGA board. Yet another example is that when the user of the FPGA board is an instance deployed on the FPGA device where the FPGA board resides, the user uploads the encrypted configuration file to a storage system, and the FPGA device where the FPGA board resides reads the encrypted configuration file from the storage system and configures it into the FPGA board; alternatively, the user of the FPGA board directly configures the decryption key into the FPGA board.

[0097] In this embodiment, the FPGA board decrypts the encrypted configuration file using the decryption key to obtain the configuration file required by the first FPGA. This embodiment does not limit the specific implementation method of the FPGA board decrypting the encrypted configuration file using the decryption key. The decryption method will vary depending on the encryption method of the configuration file. For descriptions related to encryption and decryption, please refer to the foregoing embodiments, which will not be repeated here.

[0098] In one optional embodiment, to ensure the security of the decryption key and further improve the security of the configuration file, the decryption key required to decrypt the encrypted configuration file is also encrypted. Thus, the decryption key is transmitted and presented in ciphertext throughout the entire process. The FPGA board receives the encrypted decryption key. Based on this, before using the decryption key to decrypt the encrypted configuration file, the decryption key can be decrypted from the encrypted decryption key.

[0099] Alternatively, if the user of the FPGA board is an instance deployed on the FPGA device where the FPGA board resides, the decryption key can be encrypted using a user ID bound to that instance, which is pre-configured on the FPGA board. Based on this, after receiving the encrypted decryption key provided by the user, the FPGA board can decrypt the encrypted decryption key according to the pre-configured user ID to obtain the decryption key; wherein, the user ID is bound to the user and can uniquely identify the user of the FPGA board.

[0100] In one alternative embodiment, depending on the encryption algorithm used to encrypt the configuration file, after the FPGA board decrypts the decryption key, it can configure and extend the decryption key before using the decryption key to decrypt the encrypted configuration file, and then use the extended decryption key to decrypt the encrypted configuration file.

[0101] In another optional embodiment, the configuration file programming operation performed on the FPGA board can be monitored to determine whether the programming operation was successful. Furthermore, in the event of failure, an alarm message can be output. In this embodiment, the output method of the alarm message is not limited; it may include, but is not limited to, voice prompts, buzzer alarms, LED indicator lights, etc. Specifically, in the event of a programming failure, the original functional logic of the FPGA board remains unchanged; in the event of a successful programming operation, the FPGA board will execute new functional logic.

[0102] In this embodiment, the implementation structure of the FPGA board is not limited. Optionally, the implementation structure of the FPGA board can be found in [reference needed]. Figure 1d or Figure 1e As shown, no limitations are imposed on this. When using FPGA boards... Figure 1d or Figure 1e For the configuration shown, a description of the FPGA's configuration file decryption and programming operations can be found in [reference needed]. Figure 1d or Figure 1e The descriptions in the illustrated embodiments will not be repeated here.

[0103] It should be noted that the execution subject of each step of the method provided in the above embodiments can be the same device, or the method can be executed by different devices. For example, the execution subject of steps 21b to 23b can be device A; or the execution subject of steps 21b and 22b can be device A, and the execution subject of step 23b can be device B; and so on.

[0104] Furthermore, in some of the processes described in the above embodiments and accompanying drawings, multiple operations appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order they appear herein, or they may be executed in parallel. The operation numbers, such as 21b, 22b, etc., are merely used to distinguish different operations and do not represent any execution order. Additionally, these processes may include more or fewer operations, and these operations may be executed sequentially or in parallel. It should be noted that the descriptions such as "first" and "second" in this document are used to distinguish different messages, devices, modules, etc., and do not represent a sequential order, nor do they limit "first" and "second" to different types.

[0105] Figure 3This is a schematic diagram of the structure of an FPGA device provided for an exemplary embodiment of this application. Figure 3 As shown, the FPGA device includes: one or more memories 301, one or more processors 302, communication components 303, and at least one FPGA board 304; a first instance 305 is also deployed on the FPGA device, and the first instance 305 is bound to the first FPGA board 304a in the at least one FPGA board 304.

[0106] One or more memories 301 are used to store computer programs and can be configured to store various other data to support operation on the FPGA device. Examples of this data include instructions for any application or method operating on the FPGA device, contact data, phone book data, messages, pictures, videos, etc.

[0107] One or more memories 301 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.

[0108] One or more memories 301 store the program of the first instance 305; one or more processors 302 are used to execute the program of the first instance 305 to: generate a configuration file of the first FPGA board 304a, encrypt the configuration file to obtain an encrypted configuration file; and provide the encrypted configuration file and the decryption key required to decrypt the encrypted configuration file to the first FPGA board 304a.

[0109] One or more memories 301 also store FPGA management programs, and one or more processors 302 are also used to execute FPGA management programs for: receiving configuration file burning instructions through communication components, triggering the first FPGA board 304a to decrypt the configuration file from the encrypted configuration file according to the decryption key and perform the configuration file burning operation according to the configuration file burning instructions.

[0110] In an alternative embodiment, when one or more processors 302 provide the decryption key required for decrypting the encrypted configuration file to the first FPGA board 304a, they are specifically configured to: encrypt the decryption key and provide the encrypted decryption key to the first FPGA board 304a.

[0111] In an optional embodiment, one or more processors 302, when encrypting the decryption key, specifically encrypt the decryption key using a user ID bound to the first instance 305; wherein the user ID is pre-configured on the first FPGA board 304a so that the first FPGA board can decrypt the decryption key.

[0112] In an optional embodiment, when one or more processors 302 provide the encrypted decryption key to the first FPGA board 304a, they are specifically configured to: directly configure the encrypted decryption key into the first FPGA board 304a.

[0113] Furthermore, such as Figure 3 As shown, the FPGA device also includes other components such as a display 307, a power supply component 308, and an audio component 30. Figure 3 The diagram only shows some components and does not mean that the FPGA device only includes... Figure 3 The components shown. Additionally... Figure 3 The components within the dashed box are optional, not mandatory, and their specific requirements depend on the server's product form. The FPGA device in this embodiment can be implemented as a terminal device such as a desktop computer, laptop computer, smartphone, or IoT device, or as a server-side device such as a conventional server, cloud server, or server array. If the FPGA device in this embodiment is implemented as a terminal device such as a desktop computer, laptop computer, or smartphone, it may include... Figure 3 The components within the dashed box; if the FPGA device in this embodiment is implemented as a conventional server, cloud server, or server array, etc., then it may not include... Figure 3 The component within the dashed box.

[0114] Accordingly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed, can perform the above-described functions. Figure 2a Each step in the method embodiment shown.

[0115] The above Figure 3 The communication component is configured to facilitate wired or wireless communication between the device containing the communication component and other devices. The device containing the communication component can access wireless networks based on communication standards, such as WiFi, 2G, or 3G, or combinations thereof. In one exemplary embodiment, the communication component receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, the communication component may further include a Near Field Communication (NFC) module, Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wideband (UWB) technology, Bluetooth (BT) technology, etc.

[0116] The above Figure 3The display includes a screen, which may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can sense not only the boundaries of the touch or swipe action, but also the duration and pressure associated with the touch or swipe operation.

[0117] The above Figure 3 The power supply component provides power to the various components of the device in which it resides. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the device in which it resides.

[0118] The above Figure 3 The audio component can be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC) configured to receive external audio signals when the device containing the audio component is in an operating mode, such as call mode, recording mode, or voice recognition mode. The received audio signals can be further stored in memory or transmitted via a communication component. In some embodiments, the audio component also includes a speaker for outputting audio signals.

[0119] Figure 4 A schematic diagram of the structure of an FPGA board provided as an exemplary embodiment of this application is shown below. Figure 4 As shown, the FPGA board includes: a logic layer 401 and a dynamic area 402; the logic area 401 includes: a decryption engine 403 and a PR configuration module 404; the dynamic area 402 includes: a key control engine 405;

[0120] The key control engine 405 is used to obtain the decryption key for decrypting the encrypted configuration file and provide the decryption key to the decryption engine 403;

[0121] Decryption engine 403 is used to decrypt the encrypted configuration file according to the decryption key and provide the decrypted configuration file to the PR configuration module;

[0122] PR configuration module 404 is used to perform the burning operation of the configuration file; the encrypted configuration file is provided by the user of the FPAG board.

[0123] In an optional embodiment, the key control engine 405 is specifically configured to: receive an encrypted decryption key provided by the user, and decrypt the encrypted decryption key according to a pre-configured user ID to obtain a decryption key; wherein the user ID is bound to the user.

[0124] In an optional embodiment, the logic area 401 further includes a key configuration and expansion module 406; the key configuration and expansion module 406 is specifically used to: configure and expand the decryption key, and provide the expanded decryption key to the decryption engine 403 so that the decryption engine can decrypt the encrypted configuration file.

[0125] In an optional embodiment, the logic area 401 further includes: a PR monitoring module 407; the PR monitoring module 407 is specifically used to: monitor whether the burning operation of the configuration file is successful, and output alarm information in case of failure.

[0126] Accordingly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed, can perform the above-described functions. Figure 2b Each step in the method embodiment shown.

[0127] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0128] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.

[0129] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.

[0130] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.

[0131] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0132] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0133] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0134] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0135] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. An FPGA-based cloud network, comprising: Network control equipment and FPGA equipment; At least one FPGA board is plugged into the FPGA device, and a first instance is also deployed on the FPGA device. The first instance is bound to the first FPGA board in the FPGA board. The first instance is used to encrypt the configuration file of the first FPGA board to obtain an encrypted configuration file; Using the encryption key bound to the first instance, the decryption key required to decrypt the encrypted configuration file is encrypted, and the encrypted configuration file and the encrypted decryption key are provided to the first FPGA board. The network management device is used to send a configuration file burning instruction to the FPGA device according to the user's FPGA configuration instruction, so as to instruct the FPGA device to trigger the first FPGA board to perform the configuration file burning operation; The encryption key is pre-configured on the first FPGA board, which is used to decrypt the decryption key according to the encryption key, decrypt the configuration file from the encryption configuration file according to the decryption key, and perform the burning operation of the configuration file.

2. The cloud network according to claim 1, further comprising: Storage system; The first instance is specifically used for: uploading the encrypted configuration file to the storage system; The FPGA device is also used to: read the encrypted configuration file from the storage system according to the configuration file burning instruction, and configure the encrypted configuration file into the first FPGA board.

3. The cloud network according to claim 1, wherein the encryption key is a user ID bound to the first instance, and the first instance is specifically used for: The decryption key is encrypted using the user ID bound to the first instance; wherein, The user ID is pre-configured on the first FPGA board so that the first FPGA board can decrypt the decryption key.

4. The cloud network according to claim 1, wherein the first instance is specifically used to: directly configure the encrypted decryption key into the first FPGA board.

5. The cloud network according to claim 1, wherein the first FPGA board comprises: Decryption engine, PR configuration module, and key control engine; The key control engine is configured to decrypt the decryption key from the encrypted decryption key based on the encryption key, and provide the decryption key to the decryption engine; The decryption engine is used to decrypt the encrypted configuration file according to the decryption key, and provide the decrypted configuration file to the PR configuration module; The PR configuration module is used to perform the burning operation of the configuration file.

6. The cloud network according to claim 5, wherein the first FPGA board comprises: Logical region and dynamic region; The decryption engine and PR configuration module are located in the logical area, and the key control engine is located in the dynamic area.

7. The cloud network according to claim 6, wherein the logical area further comprises: Key configuration and extension modules; The key configuration and extension module is used to configure and extend the decryption key, and provide the extended decryption key to the decryption engine so that the decryption engine can decrypt the encrypted configuration file.

8. The cloud network according to claim 6, wherein the logical area further comprises: PR monitoring module; The PR monitoring module is used to monitor whether the burning operation of the configuration file is successful and to output alarm information in case of failure.

9. The cloud network according to any one of claims 2-8, wherein the network management and control device is further configured to: Before sending the configuration file writing command to the FPGA device, the encrypted configuration file is read from the storage system, and it is determined whether the version number of the encrypted configuration file is consistent with the shell version number of the first FPGA board. If they are consistent, the configuration file writing command is sent to the FPGA device.

10. An FPGA device, comprising: One or more memories, one or more processors, communication components, and at least one FPGA board; The FPGA device is also equipped with a first instance, which is bound to the first FPGA board in the FPGA board. Wherein, the one or more memories store the program corresponding to the first instance; the one or more processors are used to execute the program corresponding to the first instance for: generating a configuration file for the first FPGA board, encrypting the configuration file to obtain an encrypted configuration file; using an encryption key bound to the first instance to encrypt the decryption key required to decrypt the encrypted configuration file, and providing the encrypted configuration file and the encrypted decryption key to the first FPGA board, wherein the encryption key is pre-configured on the first FPGA board; The one or more memories also store FPGA management programs, and the one or more processors are further configured to execute the FPGA management programs for: receiving configuration file burning instructions through the communication component; triggering the first FPGA board to decrypt the decryption key according to the encryption key based on the configuration file burning instructions; and decrypting the configuration file from the encrypted configuration file according to the decryption key and performing the configuration file burning operation.

11. An FPGA board, wherein the FPGA board is bound to a first instance deployed on its associated FPGA device, the FPGA board being pre-configured with an encryption key bound to the first instance, the FPGA board comprising: Logical region and dynamic region; The logical area includes a decryption engine and a PR configuration module; the dynamic area includes a key control engine. The key control engine is used to obtain a decryption key for decrypting the encrypted configuration file and to provide the decryption key to the decryption engine; the decryption key is provided by the user after being encrypted using the encryption key, and the user includes the first instance; The decryption engine is used to decrypt the encrypted decryption key according to the encryption key to obtain the decryption key, decrypt the encrypted configuration file according to the decryption key, and provide the decrypted configuration file to the PR configuration module. The PR configuration module is used to perform the burning operation of the configuration file; wherein the encrypted configuration file is provided by the user of the FPGA board.

12. The FPGA board according to claim 11, wherein the encryption key is a user ID bound to the first instance, and the key control engine is specifically used to: receive the encrypted decryption key provided by the user, and decrypt the encrypted decryption key according to the pre-configured user ID to obtain the decryption key; wherein, The user ID is bound to the user.

13. The FPGA board according to claim 11, wherein the logic area further comprises: Key configuration and extension modules; The key configuration and extension module is used to configure and extend the decryption key, and provide the extended decryption key to the decryption engine so that the decryption engine can decrypt the encrypted configuration file.

14. The FPGA board according to claim 11, wherein the logic area further comprises: PR monitoring module; The PR monitoring module is used to monitor whether the burning operation of the configuration file is successful and to output alarm information in case of failure.

15. A configuration file loading method, applicable to an FPGA device, wherein a first instance is deployed on the FPGA device, the first instance is bound to a first FPGA board on the FPGA device, and the first FPGA board is pre-configured with an encryption key bound to the first instance, the method comprising: The configuration file of the first FPGA board is encrypted to obtain an encrypted configuration file; The encryption key required to decrypt the encrypted configuration file is encrypted using the encryption key bound to the first instance; The encrypted configuration file and the encrypted decryption key are provided to the first FPGA board, so that the first FPGA board can decrypt the decryption key according to the encryption key, and decrypt the configuration file from the encrypted configuration file according to the decryption key and perform the configuration file burning operation.

16. The method according to claim 15, wherein the encryption key is a user ID bound to the first instance, and encrypting the decryption key includes: The decryption key is encrypted using the user ID bound to the first instance; wherein the user ID is pre-configured on the first FPGA board so that the first FPGA board can decrypt the decryption key.

17. The method according to claim 15, wherein the encrypted decryption key is provided to the first FPGA board, comprising: The encrypted decryption key is directly configured into the first FPGA board.

18. A configuration file loading method, applicable to an FPGA board, wherein the FPGA board is bound to a first instance deployed on its associated FPGA device, and the FPGA board is pre-configured with an encryption key bound to the first instance, the method comprising: The system receives an encrypted configuration file and a decryption key for decrypting the encrypted configuration file, provided by the user of the FPGA board. The decryption key is provided by the user of the FPGA board after being encrypted using the encryption key. The user includes the first instance. The encrypted decryption key is decrypted using the encryption key to obtain the decryption key. The encrypted configuration file is then decrypted using the decryption key to obtain the configuration file required by the FPGA board. Perform the burning operation of the configuration file.

19. A computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the steps of the method according to any one of claims 15-18.

Citation Information

Patent Citations

  • Logic repository service using encrypted configuration data

    CN110088742A

  • Faas cloud service-based vFPGA configuration method and equipment, and storage medium

    CN110502911A