A Secure Invocation Method, Device, Equipment and Medium for GPGPU
By using target decryption and encryption algorithms in the security control module of GPGPU, and physical isolation between the security control module and the computing unit and scheduler is achieved through the bus, the problem of low security protection efficiency in the prior art is solved, and efficient security protection and system performance improvement is achieved.
Patent Information
- Application Number
- CN202510266147.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-03-07
AI Technical Summary
The prior art is difficult to effectively prevent security challenges such as cache-side channel attacks, memory vulnerability attacks, and heterogeneous units misaccess in GPGPU access, and software security protection is inefficient. The hardware solution cannot achieve physical isolation between the hardware security control module and the GPGPU computing unit.
By implementing ciphertext instruction decryption and encryption processing in the security control module of the GPGPU, the target decryption algorithm and encryption algorithm corresponding to the remote user node are used to encrypt and decrypt the GPGPU access request and processing results, verify the legitimacy of the request, and realize physical isolation between the security control module and the computing unit and the scheduler through the bus.
It improves the security protection efficiency of GPGPU access, realizes physical isolation between the security control module and the computing unit and scheduler, and significantly improves system performance and user experience.
Smart Images

Figure CN119760704B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of graphics processing, and particularly relates to a secure call method, device, equipment and medium for GPGPU. Background Art
[0002] GPGPU (General-purpose computing on graphics processing units) is a powerful computing tool. Different from GPUs, GPGPU has a higher degree of parallelism in computing cores and is more proficient in some non-graphics-related program operations and repetitive tasks with a large amount of data, such as large-scale data encryption, decryption, data calculation, AI computing acceleration, etc.
[0003] With the rapid development of the current technological level, the application demand for GPGPU has increased significantly. Currently, the commonly supported application mode is that multiple clients share GPGPU. This design supports several users to remotely call a heterogeneous GPGPU for computing in the form of a network, which can reduce the number of GPGPU applications and maximize the GPGPU application efficiency without affecting the computing requirements, thus enhancing the economy. However, in this design, remote users access the Host (host) through the network and call the heterogeneous GPGPU, but security challenges such as cache side-channel attacks, memory vulnerability attacks, and incorrect access to heterogeneous units caused by remote access through the network are inevitable.
[0004] Currently, software security protection methods are usually adopted, that is, illegal access to the heterogeneous GPGPU is avoided by installing software security drivers on the Host. However, the software security protection verification scheme based on the CPU (Central Processing Unit) is inefficient, has a long delay, and the complicated security authentication process will directly affect the feedback efficiency of GPGPU computing. Moreover, this scheme will increase the task load of the Host CPU, thus affecting the execution of other important processes. In addition, the existing hardware solutions cannot achieve physical isolation between the hardware security control module and the GPGPU computing unit, which will inevitably cause waste of logical resources of the GPGPU computing unit and may also affect the correct recognition rate of illegal access by the GPGPU due to problems such as data transmission metastability, seriously affecting the user experience.
[0005] In summary, how to improve the security protection efficiency of GPGPU access is a problem to be solved currently. Summary of the Invention
[0006] In view of this, the purpose of the present invention is to provide a secure call method, device, equipment and medium for GPGPU, which can improve the security protection efficiency of GPGPU access. The specific solutions are as follows:
[0007] In a first aspect, the present application discloses a secure call method for a GPGPU, which is applied to a security control module in the GPGPU. The method includes:
[0008] Obtain the ciphertext instruction and request data carried in the GPGPU access request sent by the target host after parsing the GPGPU access request sent by the remote user node.
[0009] Use the target decryption algorithm corresponding to the remote user node to decrypt the ciphertext instruction to obtain the plaintext instruction, and verify the legality of the GPGPU access request based on the plaintext instruction.
[0010] If the GPGPU access request is a legal request, send the plaintext instruction and the request data to a preset scheduler through a bus, so that the preset scheduler calls a target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data, and obtain a processing result.
[0011] Obtain the processing result sent by the target computing unit through the bus, use the target encryption algorithm corresponding to the remote user node to encrypt the processing result to obtain a ciphertext result, and then send the ciphertext result to the target host, so that the target host sends the ciphertext result to the remote user node.
[0012] Optionally, the using the target decryption algorithm corresponding to the remote user node to decrypt the ciphertext instruction to obtain the plaintext instruction includes:
[0013] Authenticate the target host. If the authentication is passed, extract the ciphertext to be decrypted, the instruction identification number, and the IP information of the remote user node from the ciphertext instruction, establish an association relationship between the ciphertext to be decrypted and the instruction identification number, and send them to a locally preset decryption state machine.
[0014] Determine the corresponding target decryption algorithm based on the IP information, establish an association relationship between the target decryption algorithm and the instruction identification number, and send them to the decryption state machine.
[0015] Determine the instruction encryption format through the decryption state machine using the access request category and calculation type obtained from a preset instruction comparison table based on the instruction identification number.
[0016] In the decryption state machine, based on the instruction identification number, use the target decryption algorithm and the instruction encryption format to decrypt the ciphertext to be decrypted in the ciphertext instruction to obtain the plaintext instruction.
[0017] Optionally, the preset instruction comparison table stores preset legal instruction parameters;
[0018] Correspondingly, verifying the legality of the GPGPU access request based on the plaintext instruction includes:
[0019] Determining whether the instruction parameters of the plaintext instruction are consistent with the legal instruction parameters stored in the preset instruction comparison table;
[0020] If they are consistent, it is determined that the GPGPU access request is a legal request; otherwise, it is an illegal request.
[0021] Optionally, after it is determined that the GPGPU access request is a legal request, it further includes:
[0022] Based on the instruction identification number, splicing the corresponding plaintext instruction and the request data according to a first preset format to obtain first spliced data;
[0023] Correspondingly, the preset scheduler calls a target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data, including:
[0024] The preset scheduler calls a target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the first spliced data.
[0025] Optionally, encrypting the processing result using a target encryption algorithm corresponding to the remote user node to obtain a ciphertext result includes:
[0026] Determining the unit identification number of the target computing unit, and obtaining an encryption operation code and encryption algorithm data corresponding to the IP information of the remote user node from a computing unit identification list corresponding to the unit identification number;
[0027] Establishing an association relationship between the encryption algorithm data and the unit identification number, and sending it to a locally preset encryption state machine, and obtaining a target encryption algorithm corresponding to the encryption operation code from a preset kernel;
[0028] Establishing an association relationship between the target encryption algorithm and the unit identification number, and sending it to the encryption state machine, so that in the encryption state machine, based on the unit identification number, using the target encryption algorithm and the encryption algorithm data to encrypt the processing result to obtain a ciphertext result.
[0029] Optionally, after encrypting the processing result using a target encryption algorithm corresponding to the remote user node to obtain a ciphertext result, it further includes:
[0030] Concatenate the ciphertext result and the processing result according to a second preset format based on the unit identification number to obtain second concatenated data;
[0031] Correspondingly, the sending the ciphertext result to the target host so that the target host sends the ciphertext result to the remote user node includes:
[0032] Send the second concatenated data to the target host so that the target host sends the second concatenated data to the remote user node.
[0033] Optionally, after verifying the legality of the GPGPU access request based on the plaintext instruction, it further includes:
[0034] If the GPGPU access request is an illegal request, discard the GPGPU access request to prohibit the execution of the step of invoking the target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data.
[0035] In a second aspect, the present application discloses a security call device for a GPGPU, which is applied to a security control module in the GPGPU. The device includes:
[0036] An information acquisition module, configured to acquire the ciphertext instruction and the request data carried in the GPGPU access request sent by the target host after parsing the GPGPU access request sent by the remote user node;
[0037] A decryption verification module, configured to decrypt the ciphertext instruction using a target decryption algorithm corresponding to the remote user node to obtain a plaintext instruction, and verify the legality of the GPGPU access request based on the plaintext instruction;
[0038] A calculation module, configured to, if the GPGPU access request is a legal request, send the plaintext instruction and the request data to a preset scheduler through a bus, so that the preset scheduler invokes a target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data, and obtain a processing result;
[0039] An encryption module, configured to acquire the processing result sent by the target computing unit through the bus, encrypt the processing result using a target encryption algorithm corresponding to the remote user node to obtain a ciphertext result, and then send the ciphertext result to the target host so that the target host sends the ciphertext result to the remote user node.
[0040] In a third aspect, the present application discloses an electronic device, including:
[0041] A memory for storing a computer program;
[0042] A processor for executing the computer program to implement the steps of the aforementioned secure call method of the GPGPU.
[0043] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the aforementioned secure call method of the GPGPU are implemented.
[0044] It can be seen that the security control module in the GPGPU obtains the ciphertext instruction and request data carried in the GPGPU access request sent by the target host after parsing the GPGPU access request sent by the remote user node; decrypts the ciphertext instruction using the target decryption algorithm corresponding to the remote user node to obtain the plaintext instruction, and verifies the legality of the GPGPU access request based on the plaintext instruction; if the GPGPU access request is a legitimate request, the plaintext instruction and the request data are sent to a preset scheduler via a bus, so that the preset scheduler invokes a target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data and obtain a processing result; obtains the processing result sent by the target computing unit via the bus, encrypts the processing result using the target encryption algorithm corresponding to the remote user node to obtain a ciphertext result, and then sends the ciphertext result to the target host, so that the target host sends the ciphertext result to the remote user node.
[0045] Beneficial effects: After receiving a GPGPU access request sent by a remote user node in this application, the target host first needs to parse the GPGPU access request to convert it into a relevant machine code stream recognizable by the GPGPU, so as to send the ciphertext instructions and request data carried in the GPGPU access request to the security control module in the GPGPU. The security control module first needs to decrypt the ciphertext instructions using the target decryption algorithm corresponding to the remote user node to obtain the plaintext instructions, so as to verify the legality of the GPGPU access request based on the plaintext instructions. That is to say, the security control module in this application is equipped with a variety of decryption algorithms, and different users have their own independent decryption protection methods, that is, the security control module can configure different decryption algorithms for users according to the information of legitimate users, with high flexibility. Further, if it is determined that the current access is legal, the plaintext instructions and request data are sent to the preset scheduler through the bus, so that the preset scheduler can call the target computing unit determined from the GPGPU based on the preset scheduling algorithm to process the plaintext instructions and request data, and obtain the processing result. That is to say, the communication between the security control module and the preset scheduler is realized through the bus to achieve physical isolation between the two, and different processes do not interfere with each other. Moreover, the communication between the security control module and the computing unit is also realized through the bus. Therefore, the security control module obtains the processing result sent by the target computing unit through the bus. Similarly, the security control module can also configure different encryption algorithms for users according to the information of legitimate users, that is, then use the target encryption algorithm corresponding to the remote user node to encrypt the processing result to obtain the ciphertext result, and then send the ciphertext result to the host, so that the target host can send the ciphertext result to the remote user node. In this way, through the above solution, the security protection efficiency of GPGPU access can be improved, the physical isolation between the security control module and the computing unit and the scheduler is realized, which can help users better achieve the unified scheduling control of GPGPU and significantly improve the system performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0047] Figure 1 It is a system architecture diagram applicable to the secure call of a GPGPU disclosed in the present application;
[0048] Figure 2 It is a detailed architecture diagram of a GPGPU disclosed in the present application;
[0049] Figure 3Flowchart of a secure call method for GPGPU disclosed in this application;
[0050] Figure 4 Schematic diagram of an input instruction decryption architecture disclosed in this application;
[0051] Figure 5 Decryption flowchart of a ciphertext instruction disclosed in this application;
[0052] Figure 6 Schematic diagram of an encrypted architecture for outputting processing results disclosed in this application;
[0053] Figure 7 Encryption flowchart of a processing result disclosed in this application;
[0054] Figure 8 Schematic diagram of the structure of a secure call device for GPGPU disclosed in this application;
[0055] Figure 9 Schematic diagram of the structure of an electronic device disclosed in this application. Specific implementation manner
[0056] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0057] Remote users access the Host (host) through the network and call the heterogeneous GPGPU. However, security challenges such as cache side-channel attacks, memory vulnerability attacks, and incorrect access to heterogeneous units caused by remote access through the network are difficult to avoid. Currently, software security protection methods are usually adopted, that is, illegal access to the heterogeneous GPGPU is avoided by installing software security drivers on the Host. However, the verification scheme of software security protection based on the CPU is inefficient and has a long delay. The complicated security authentication process will directly affect the feedback efficiency of GPGPU computing, and this scheme will increase the task load of the Host CPU, thereby affecting the execution of other important processes. In addition, the existing hardware solutions cannot achieve physical isolation between the hardware security control module and the GPGPU computing unit, which will inevitably cause waste of logical resources of the GPGPU computing unit, and may also affect the correct recognition rate of the GPGPU for illegal access due to problems such as data transmission metastability, seriously affecting the user experience.
[0058] Therefore, the embodiments of this application disclose a secure call method, device, device and medium for GPGPU, which can improve the security protection efficiency for accessing GPGPU.
[0059] In the secure call solution of the GPGPU of the present application, the system architecture adopted can be referred to Figure 1 as shown in, which mainly includes remote users, a host, and a GPGPU. Among them, multiple remote user nodes are independently connected to the host through the network respectively, and the heterogeneous GPGPU communicates and exchanges information with the host in the form of DMA (Direct Memory Access) through the PCIe (Peripheral Component Interconnect Express, a high-speed serial computer expansion bus standard) interface. Among them, the user node refers to the user terminal, which can be an intelligent device such as a mobile phone or a computer.
[0060] In addition, the GPGPU mainly consists of a security control module, a computing scheduling module (with a preset scheduler inside), several computing units, an on-chip cache, etc. After the host receives the GPGPU access request from the remote user node, it sends the encrypted computing instructions and relevant data to the GPGPU through the PCIe interface. After the GPGPU completes the security verification of the current GPGPU access request, it schedules the computing task to the target computing unit. After the target computing unit completes the processing, the security control module encrypts the processing result, and then feeds back the processing result to the requesting user node through the host via the PCIe interface.
[0061] Furthermore, Figure 2 shows the detailed architecture of the GPGPU, including an interrupt control module, a configuration module, a computing scheduling module, a DMA data transceiver module, a security control module, a GPGPU computing module, and corresponding data storage modules, as well as the AXI (Advanced eXtensible Interface, a high-performance and high-bandwidth on-chip bus) bus connecting each module.
[0062] Among them, the top layer of the interrupt control module is a PIC (Programmable Interrupt Controller), and inside it, a TMR (Timer Module) timer module, an MTHD (Multiple Thread Hardware Dispatch) interrupt handling mode configuration module, a CTXSW (Context Switch) process / thread switching module, etc. are deployed, which are responsible for processing the interrupt handling requests from the host;
[0063] The configuration module is equipped with a CFG BUS (Configuration Bus) configuration bus module, which is responsible for configuring the relevant parameters involved in the security control module, the kernel scheduling module, the GPGPU computing module, etc. by the host.
[0064] The computing scheduling module arranges the warp / thread scheduling functional kernel and the necessary Icache (Instruction Cache) and Dcache (Data Cache), and is responsible for allocating the computing tasks that have passed the security verification to the corresponding computing units of the GPGPU computing module;
[0065] The DMA data transceiver module deploys a DMA data transceiver engine, which is responsible for the data exchange between the GPGPU and the host memory, and real-time transceiver of computing tasks and processing results;
[0066] The security control module mainly consists of two parts: an input instruction decryption architecture and a processing result output encryption architecture. This module deploys relevant symmetric or asymmetric encryption algorithms such as SHA (Secure Hash Algorithm), AES (Advanced Encryption Standard, a symmetric encryption algorithm), RSA (Rivest-Shamir-Adleman, an asymmetric encryption algorithm), and ECC (Elliptic Curve Cryptography), as well as corresponding decryption algorithms. After receiving a GPGPU access request, the GPGPU needs to first perform a security check on the relevant request to ensure that the current request is a legal access. Only after passing the security check of the security control module can this request be sent to the computing scheduling module;
[0067] The GPGPU computing module deploys all the computing units of the GPGPU and is responsible for executing all the computing tasks sent by the user node;
[0068] The data storage module includes instruction TCM (Tightly-Coupled Memory) storage and data TCM storage, which is responsible for storing relevant instruction data and computing requirement data, and completes data exchange with the host through the AXI bus;
[0069] The above modules are connected through the AXI control bus and the AXI data bus. The AXI bus transmits the instructions and relevant data necessary for the operation of each module, and all functional modules are uniformly controlled and deployed by the GPGPU.
[0070] See Figure 3 As shown, an embodiment of the present application discloses a security call method for a GPGPU, which is applied to the security control module in the GPGPU. The method includes:
[0071] Step S11: Obtain the ciphertext instruction and request data carried in the GPGPU access request sent by the target host after parsing the GPGPU access request sent by the remote user node.
[0072] In this embodiment, the remote user node will send a GPGPU access request to the target host through a wired / wireless network. After receiving the GPGPU access request, the target host first needs to parse the GPGPU access request to convert it into a relevant machine code stream recognizable by the GPGPU, so as to send the ciphertext instruction and request data carried in the GPGPU access request to the security control module in the GPGPU in the form of DMA through the PCIe interface.
[0073] Step S12: Decrypt the ciphertext instruction using the target decryption algorithm corresponding to the remote user node to obtain the plaintext instruction, and verify the legality of the GPGPU access request based on the plaintext instruction.
[0074] In this embodiment, the security control module needs to decrypt the ciphertext instruction using the target decryption algorithm corresponding to the remote user node to obtain the plaintext instruction, so as to verify the legality of the GPGPU access request based on the plaintext instruction. For example, whether the decrypted data conforms to the predefined data format, and whether the user identity information carried in the instruction belongs to the pre-stored legal user identity information.
[0075] That is to say, the security control module in this application pre-stores a variety of encryption and decryption algorithms, such as SHA, AES, RSA, ECC, etc., and different users have their own independent decryption protection methods, that is, the security control module can configure different decryption algorithms for users according to the information of legal users, with high flexibility.
[0076] It should be noted that an input instruction decryption architecture is set in the security control module to decrypt the ciphertext instruction to obtain the plaintext instruction and verify the legality of the GPGPU access request. Its architecture diagram is as Figure 4 shown. As can be seen from Figure 4 it, the input instruction decryption architecture includes a management information configuration module, an instruction queue module, an instruction ciphertext decomposition module, a user IP decomposition module, an algorithm decryption FSM state machine, a decryption algorithm information selection module, a request-side instruction comparison table, a MUX data merging module, an instruction decryption result cache module, and an instruction parameter cache module.
[0077] Among them, the management information configuration module is responsible for performing necessary parameter settings and initialization configurations on other modules, and configuring the information preset by the management terminal; the instruction queue module is responsible for verifying the legality of the host administrator's identity, caching relevant instructions of the user in the input order, and issuing them sequentially; the instruction ciphertext decomposition module is used to decompose the ciphertext to be decrypted that is necessary for the instruction to execute the decryption algorithm; the user IP decomposition module is responsible for decomposing the IP information of the remote user node in the instruction information; the instruction parameter cache module is responsible for caching the relevant request data in the instruction marked by the instruction identification number represented by the instruction PC (Program Counter); the decryption algorithm information selection module prestores multiple decryption algorithms corresponding to the IP information of legal users, such as the symmetric decryption algorithm AES, SHA, and the asymmetric decryption algorithm RSA. This module determines the category of the decryption algorithm corresponding to the current GPGPU access request user IP, and selects the relevant decryption parameters involved in the corresponding decryption algorithm from the module kernel; the algorithm decryption FSM (Finite State Machine) state machine is responsible for decrypting the input instructions sequentially, and then judging the legality of the current request; the request-side instruction comparison table stores information such as the instruction access request category and calculation type corresponding to different instruction PCs; the MUX (Multiplexer) data merging module merges and splices the decrypted relevant GPGPU access request instructions and the instruction calculation-related request data cached in the instruction parameter according to the instruction PC and in the format preset by the user; the instruction decryption result cache module is responsible for caching the relevant instruction decryption results and the relevant data necessary for the instruction execution.
[0078] Therefore, as Figure 5 shown, in some specific embodiments, the steps of decrypting the ciphertext instruction with the target decryption algorithm corresponding to the remote user node to obtain the plaintext instruction may include:
[0079] Step S121: Authenticate the identity of the target host. If the authentication is passed, extract the ciphertext to be decrypted, the instruction identification number, and the IP information of the remote user node from the ciphertext instruction, and establish an association relationship between the ciphertext to be decrypted and the instruction identification number, and then send them to the locally preset decryption state machine.
[0080] In this embodiment, the security control module first needs to authenticate the identity of the target host, specifically, it can authenticate the identity of the current administrator of the host. For example, when receiving an instruction from the host, it will extract the included administrator identity identification information from the instruction and compare it with the prestored information. If the two are consistent, it is considered that the administrator identity authentication is passed.
[0081] If the authentication is successful, cache the relevant instructions in the order of instruction input, and sequentially send the instructions and related data to the instruction ciphertext decomposition module, the user IP decomposition module, and the instruction parameter cache module. Among them, the instruction ciphertext decomposition module decomposes the ciphertext to be decrypted and the instruction identification number necessary for algorithm decryption from the ciphertext instruction, and sends the ciphertext to be decrypted marked with the instruction identification number to the local algorithm decryption FSM state machine; the user IP decomposition module is responsible for decomposing the IP information of the remote user node in the instruction information, and sending the decomposed user IP information to the decryption algorithm information selection module, which pre-stores various decryption algorithms corresponding to legal user IPs, such as the symmetric decryption algorithm AES, SHA, and the asymmetric decryption algorithm RSA, etc.
[0082] Step S122: Determine the corresponding target decryption algorithm based on the IP information, and establish an association relationship between the target decryption algorithm and the instruction identification number, and then send it to the decryption state machine.
[0083] In this embodiment, the decryption algorithm information selection module selects the corresponding target decryption algorithm and related decryption parameters involved in the algorithm from the module kernel according to the decryption algorithm category corresponding to the user IP information of the current GPGPU access request, and sends it to the algorithm decryption FSM state machine marked with the instruction identification number.
[0084] Step S123: Use the decryption state machine to determine the instruction encryption format based on the access request category and calculation type obtained from the preset instruction comparison table based on the instruction identification number.
[0085] In this embodiment, the decryption state machine uses the access request category and calculation type obtained from the preset instruction comparison table (i.e., the instruction comparison table on the request side) based on the instruction identification number to determine the instruction encryption format inside the instruction. It should be noted that the access request category here refers to whether it is a calculation category that requires the participation of the model or a conventional data processing category, etc., and the calculation type is the specific calculation method under the corresponding category, such as sorting, filtering, etc.
[0086] Step S124: In the decryption state machine, based on the instruction identification number, use the target decryption algorithm and the instruction encryption format to decrypt the ciphertext to be decrypted in the ciphertext instruction to obtain the plaintext instruction.
[0087] In this embodiment, the decryption state machine decrypts the ciphertext to be decrypted in the ciphertext instruction according to the instruction encryption format, the target decryption algorithm and related parameters, so as to obtain the plaintext instruction.
[0088] Further, the preset instruction comparison table may also store pre-set legal instruction parameters; correspondingly, verifying the legality of the GPGPU access request based on the plaintext instruction includes: determining whether the instruction parameters of the plaintext instruction are consistent with the legal instruction parameters stored in the preset instruction comparison table; if they are consistent, determining that the GPGPU access request is a legal request, otherwise it is an illegal request. That is, the decrypted instruction can also be compared with the legal instruction parameters stored in the request-side instruction comparison table, and it is determined whether the two pieces of information are consistent. If they are consistent, it is determined that the GPGPU access request is a legal request, otherwise it is an illegal request. In addition, it is also possible to check whether the access request category and calculation type of the instruction are consistent with the information recorded in the comparison table. If the instruction claims to perform a matrix multiplication operation, but the corresponding instruction PC in the comparison table is marked as a data read operation, then this request is illegal.
[0089] In addition, the legality of the GPGPU access request can also be verified through a timestamp. For example, in some systems with high security requirements, the instruction will carry timestamp information. The state machine needs to check whether the timestamp is within a reasonable range to prevent replay attacks. If the timestamp indicates that the instruction was sent a long time ago or is too different from the current system time, then this request may have been intercepted and re-sent by an attacker and should be determined as an illegal request.
[0090] Step S13: If the GPGPU access request is a legal request, send the plaintext instruction and the request data to a preset scheduler through the bus, so that the preset scheduler calls a target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data, and obtain a processing result.
[0091] In this embodiment, if it is determined that the current access is legal, the plaintext instruction and the request data are sent to the preset scheduler in the computing scheduling module through the bus, so that the preset scheduler determines a target computing unit based on the preset scheduling algorithm, and sends the plaintext instruction and the request data to the target computing unit to perform a computing operation and obtain a processing result. That is, communication between the security control module and the preset scheduler is achieved through the bus to achieve physical isolation between the two, and different processes do not interfere with each other. Moreover, communication between the security control module and the computing unit is also achieved through the bus, with high transmission efficiency and good stability.
[0092] In addition, it can also be pointed out that the above-mentioned preset scheduling algorithm can specifically adopt algorithms such as the first-come-first-served algorithm, the shortest-job-first algorithm, and the load-balancing-based scheduling algorithm, etc. Among them, the first-come-first-served algorithm means that the computing units are allocated in sequence according to the arrival order of tasks, and the tasks that arrive first are executed first, and subsequent tasks are processed only after completion. The shortest-job-first algorithm means that the scheduler selects the task with the shortest expected execution time and preferentially allocates computing units for processing. The load-balancing-based scheduling algorithm needs to monitor the load conditions of each computing unit in real time, so as to allocate new tasks to the computing unit with the lightest load to achieve load balancing among the computing units.
[0093] Further, after the above-mentioned GPGPU access request is a legal request, it further includes: splicing the corresponding plaintext instruction and the request data according to a first preset format based on the instruction identification number to obtain first spliced data; correspondingly, the preset scheduler calls the target computing unit determined from the GPGPU based on the preset scheduling algorithm to process the plaintext instruction and the request data, including: the preset scheduler calls the target computing unit determined from the GPGPU based on the preset scheduling algorithm to process the first spliced data.
[0094] That is to say, if the current GPGPU access request is legal, the algorithm decryption FSM state machine sends the decrypted plaintext instruction to the MUX module. The MUX combines and splices the plaintext instruction and the relevant request data cached by the instruction parameters based on the instruction PC according to the user's first preset format, and then sends the obtained first spliced data to the instruction decryption result cache module. The instruction decryption result cache module then sequentially outputs the instruction decryption results to be sent to the computing scheduling module, so that the preset scheduler calls the corresponding computing units to complete the computing tasks. Here, by splicing the instruction and the request data with the instruction identification number, the corresponding relationship between the instruction and the parameter can be ensured to be accurate, ensuring the consistency and accuracy in data transmission. In addition, it can be transmitted as a whole during the data transmission process, reducing the additional overhead caused by multiple transmissions and also improving the data transmission efficiency.
[0095] In addition, after verifying the legality of the GPGPU access request based on the plaintext instruction, the following steps are further included: if the GPGPU access request is an illegal request, discard the GPGPU access request to prohibit the execution of the step of invoking the target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data. That is to say, if the current GPGPU access request is an illegal request, directly discard the GPGPU access request without further computing on it, that is, prohibit the execution of the step of invoking the target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the instruction and the request data.
[0096] Step S14: Obtain the processing result sent by the target computing unit through the bus, encrypt the processing result using the target encryption algorithm corresponding to the remote user node to obtain a ciphertext result, and then send the ciphertext result to the target host so that the target host sends the ciphertext result to the remote user node.
[0097] In this embodiment, the security control module obtains the processing result sent by the target computing unit through the bus. Similarly, the security control module can also configure different encryption algorithms for users according to the information of legitimate users, that is, use the target encryption algorithm corresponding to the remote user node to encrypt the processing result to obtain a ciphertext result, and then send the ciphertext result to the host in the form of DMA through the PCIe interface, so that the target host sends the ciphertext result to the remote user node. In this way, through the above solution, the security protection efficiency of GPGPU access can be improved, the physical isolation between the security control module and the computing unit and the scheduler is achieved, which can help users better achieve the unified scheduling control of GPGPU and significantly improve the system performance.
[0098] It should be noted that a processing result output encryption architecture is set in the security control module to encrypt the processing result using the target encryption algorithm corresponding to the remote user node to obtain a ciphertext result, and its architecture diagram is as Figure 6 shown. As can be seen from Figure 6 it, the processing result output encryption architecture includes a management information configuration module, a processing result receiving module, a computing unit ID comparison and extraction module, a GPGPU computing unit ID list, a processing result cache module, an encryption algorithm information selection module, an algorithm encryption FSM state machine, a ciphertext cache module, a MUX data merging module, and a processing result encryption processing cache module.
[0099] Among them, the management information configuration module is responsible for performing necessary parameter settings and initialization configurations on other modules, and configuring the information of the management host; the processing result receiving module is responsible for receiving the processing results output by the GPGPU computing module from the AXI bus, and the processing result caching module caches the original unencrypted processing results to be output in sequence; the computing unit ID comparison and extraction module extracts the encryption operation code and encryption algorithm data corresponding to the IP information of the remote user node from the GPGPU computing unit ID list according to the computing unit ID information of the input processing result; the encryption algorithm information selection module pre-stores multiple decryption algorithms corresponding to legal user IPs, such as the symmetric decryption algorithm AES, SHA, and the asymmetric decryption algorithm RSA, and determines the encryption algorithm category corresponding to the IP of the current GPGPU access request user according to the encryption operation code, and selects the corresponding encryption algorithm and related encryption parameters involved; the algorithm encryption FSM state machine generates a ciphertext result in a specific format corresponding to the encryption algorithm according to the encryption algorithm and encryption algorithm data corresponding to the current processing result for the current processing result data; the ciphertext caching module is used to cache the ciphertext of the processing result generated by the algorithm encryption FSM state machine; the MUX data merging module is used to merge and splice the processing result and the related ciphertexts involved in different processing results in a specific format to form an encrypted processing result, which can only be read and decrypted by a specific user; the processing result encryption processing caching module is used to cache the encrypted processing result and send it to the user terminal of the GPGPU access request in a specific format.
[0100] Therefore, as Figure 7 shown, in some specific embodiments, the steps of encrypting the processing result with the target encryption algorithm corresponding to the remote user node to obtain a ciphertext result may include:
[0101] Step S141: Determine the unit identification number of the target computing unit, and obtain the encryption operation code and encryption algorithm data corresponding to the IP information of the remote user node from the computing unit identification list corresponding to the unit identification number.
[0102] In this embodiment, the processing result receiving module receives the processing result from the target computing unit, determines the unit identification number of the target computing unit, and caches the original unencrypted processing result to the processing result caching module based on the ID (unit identification number) of the computing unit. Further, the GPGPU computing unit ID comparison and extraction module extracts the encryption operation code and related encryption algorithm data corresponding to the IP information of the remote user node from the corresponding computing unit identification list according to the unit identification number of the target computing unit of the input processing result.
[0103] Step S142: After establishing an association relationship between the encryption algorithm data and the unit identification number, send them to the locally preset encryption state machine, and obtain the target encryption algorithm corresponding to the encryption operation code from the preset kernel.
[0104] In this embodiment, after establishing an association relationship between the encryption algorithm data and the unit identification number, send them to the algorithm encryption FSM state machine, and send the encryption operation code to the encryption algorithm information selection module; the encryption algorithm information selection module pre-stores various decryption algorithms corresponding to legal user IPs, such as the symmetric decryption algorithm AES, SHA, and the asymmetric decryption algorithm RSA, and determines the encryption algorithm category corresponding to the current GPGPU access request user IP according to the encryption operation code, so as to select the corresponding target encryption algorithm and related encryption parameters involved from the preset kernel.
[0105] Step S143: After establishing an association relationship between the target encryption algorithm and the unit identification number, send them to the encryption state machine, so as to encrypt the processing result with the target encryption algorithm and the encryption algorithm data based on the unit identification number in the encryption state machine to obtain a ciphertext result.
[0106] In this embodiment, send the target encryption algorithm marked with the unit identification number of the corresponding computing unit to the algorithm encryption FSM state machine. The algorithm encryption FSM state machine generates a ciphertext result in a specific format corresponding to the encryption algorithm for the current processing result according to the target encryption algorithm and related encryption algorithm data based on the unit identification number, and sends the ciphertext result marked with the ID of the corresponding computing unit of the processing result to the ciphertext cache module.
[0107] Further, after encrypting the processing result with the target encryption algorithm corresponding to the remote user node to obtain a ciphertext result, it further includes: splicing the ciphertext result and the processing result in a second preset format based on the unit identification number to obtain second spliced data; correspondingly, the step of sending the ciphertext result to the target host so that the target host sends the ciphertext result to the remote user node includes: sending the second spliced data to the target host so that the target host sends the second spliced data to the remote user node.
[0108] That is, the MUX data merging module marks the ciphertext result cached in the ciphertext cache module and the original unencrypted processing result cached in the processing result cache module with the unit identification number, merges and splices the data according to the second preset format of the user, and sends the obtained second spliced data to the processing result encryption processing cache module for storage. Further, the processing result encryption processing cache module sequentially outputs the second spliced data marked with the unit identification number to the target data until the sending is completed, and then the target host sends the second spliced data to the remote user node. Similarly, by splicing the ciphertext result and the processing result with the unit identification number, the corresponding relationship between each computing unit and its result can be ensured to be accurate, ensuring the consistency and accuracy in data transmission. In addition, it can be transmitted as a whole during the data transmission process, reducing the additional overhead caused by multiple transmissions and improving the data transmission efficiency.
[0109] It can be seen that after receiving the GPGPU access request sent by the remote user node in this application, the target host first needs to parse the GPGPU access request to convert it into a relevant machine code stream recognizable by the GPGPU, so as to send the ciphertext instruction and request data carried in the GPGPU access request to the security control module in the GPGPU. The security control module first needs to decrypt the ciphertext instruction using the target decryption algorithm corresponding to the remote user node to obtain the plaintext instruction, and verify the legality of the GPGPU access request based on the plaintext instruction. That is, the security control module in this application is equipped with multiple decryption algorithms, and different users have their own independent decryption protection methods, that is, the security control module can configure different decryption algorithms for users according to the information of legitimate users, with high flexibility. Further, if it is determined that the current access is legal, the plaintext instruction and request data are sent to the preset scheduler through the bus, so that the preset scheduler can call the target computing unit determined from the GPGPU based on the preset scheduling algorithm to process the plaintext instruction and request data and obtain the processing result. That is, the communication between the security control module and the preset scheduler is realized through the bus to achieve physical isolation between the two, and different processes do not interfere with each other. And the communication between the security control module and the computing unit is also realized through the bus. Therefore, the security control module obtains the processing result sent by the target computing unit through the bus. Similarly, the security control module can also configure different encryption algorithms for users according to the information of legitimate users, that is, then encrypt the processing result using the target encryption algorithm corresponding to the remote user node to obtain the ciphertext result, and then send the ciphertext result to the host, so that the target host can send the ciphertext result to the remote user node. In this way, through the above solution, the security protection efficiency of GPGPU access can be improved, the physical isolation between the security control module and the computing unit and the scheduler is realized, which can help users better achieve the unified scheduling control of the GPGPU and significantly improve the system performance.
[0110] See Figure 8 As shown, an embodiment of the present application discloses a secure call device for GPGPU, which is applied to a security control module in GPGPU. The device includes:
[0111] An information acquisition module 11, configured to acquire a ciphertext instruction and request data carried in the GPGPU access request sent by the target host after parsing the GPGPU access request sent by the remote user node;
[0112] A decryption verification module 12, configured to decrypt the ciphertext instruction using a target decryption algorithm corresponding to the remote user node to obtain a plaintext instruction, and verify the legality of the GPGPU access request based on the plaintext instruction;
[0113] A calculation module 13, configured to, if the GPGPU access request is a legal request, send the plaintext instruction and the request data to a preset scheduler through a bus, so that the preset scheduler invokes a target calculation unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data, and obtain a processing result;
[0114] An encryption module 14, configured to acquire the processing result sent by the target calculation unit through the bus, encrypt the processing result using a target encryption algorithm corresponding to the remote user node to obtain a ciphertext result, and then send the ciphertext result to the target host, so that the target host sends the ciphertext result to the remote user node.
[0115] It can be seen that after the target host in the present application receives the GPGPU access request sent by the remote user node, it first needs to parse the GPGPU access request to convert it into a relevant machine code stream recognizable by the GPGPU, so as to send the ciphertext instruction and request data carried in the GPGPU access request to the security control module in the GPGPU. The security control module first needs to decrypt the ciphertext instruction using the target decryption algorithm corresponding to the remote user node to obtain the plaintext instruction, so as to verify the legality of the GPGPU access request based on the plaintext instruction. That is to say, the security control module in the present application is equipped with a variety of decryption algorithms, and different users have their own independent decryption protection methods, that is, the security control module can configure different decryption algorithms for users according to the information of legitimate users, with high flexibility. Further, if it is determined that the current access is legal, the plaintext instruction and request data are sent to the preset scheduler through the bus, so that the preset scheduler can call the target computing unit determined from the GPGPU based on the preset scheduling algorithm to process the plaintext instruction and request data, and obtain the processing result. That is to say, the communication between the security control module and the preset scheduler is realized through the bus to achieve physical isolation between the two, and different processes do not interfere with each other. Moreover, the communication between the security control module and the computing unit is also realized through the bus. Therefore, the security control module obtains the processing result sent by the target computing unit through the bus. Similarly, the security control module can also configure different encryption algorithms for users according to the information of legitimate users, that is, then encrypt the processing result using the target encryption algorithm corresponding to the remote user node to obtain the ciphertext result, and then send the ciphertext result to the host, so that the target host can send the ciphertext result to the remote user node. In this way, through the above solution, the security protection efficiency of GPGPU access can be improved, the physical isolation between the security control module and the computing unit and the scheduler is realized, which can help users better realize the unified scheduling control of the GPGPU and significantly improve the system performance.
[0116] Figure 9 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Specifically, it may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the GPGPU security call method executed by the electronic device disclosed in any of the foregoing embodiments.
[0117] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitation is imposed here.
[0118] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 can be implemented in at least one of the hardware forms of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may also include an AI (Artificial Intelligence) processor, and this AI processor is used to process computing operations related to machine learning.
[0119] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, a random access memory, a disk, or an optical disc, etc. The resources stored thereon include an operating system 221, a computer program 222, data 223, etc., and the storage method can be temporary storage or permanent storage.
[0120] Among them, the operating system 221 is used to manage and control each hardware device and computer program 222 on the electronic device 20, so as to implement the operation and processing of the massive data 223 in the memory 22 by the processor 21. It can be Windows, Unix, Linux, etc. In addition to the computer program that can be used to complete the secure call method of the GPGPU executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs that can be used to complete other specific tasks. In addition to the data transmitted by external devices received by the electronic device, the data 223 may also include data collected by its own input / output interface 25, etc.
[0121] Furthermore, the embodiment of the present application also discloses a computer-readable storage medium. When the computer program stored in the storage medium is loaded and executed by a processor, the steps of the secure call method of the GPGPU disclosed in any of the foregoing embodiments are implemented.
[0122] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts between the various embodiments, reference can be made to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple. For the relevant parts, reference can be made to the description in the method part.
[0123] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0124] The steps of the method or algorithm described in combination with the embodiments disclosed in this article can be directly implemented by hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, compact disc read-only memory (CD-ROM), or any other form of storage medium well-known in the technical field.
[0125] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.
[0126] The above has introduced in detail a security call method, device, equipment and storage medium of a GPGPU provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A GPGPU secure calling method, characterized in that: A security control module applied to a GPGPU, the method comprising: Obtaining the ciphertext instruction and request data carried in the GPGPU access request sent by the target host after parsing the GPGPU access request sent by the remote user node; Decrypting the ciphertext instruction using a target decryption algorithm corresponding to the remote user node to obtain a plaintext instruction, and verifying the legitimacy of the GPGPU access request based on the plaintext instruction; If the GPGPU access request is a legitimate request, the plaintext instruction and the request data are sent to a preset scheduler through a bus, so that the preset scheduler calls a target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data and obtain a processing result; Acquire the processing result sent by the target computing unit through the bus, encrypt the processing result using a target encryption algorithm corresponding to the remote user node to obtain a ciphertext result, and then send the ciphertext result to the target host, so that the target host sends the ciphertext result to the remote user node; After verifying the legitimacy of the GPGPU access request based on the plaintext instruction, the method further includes: If the GPGPU access request is an illegal request, the GPGPU access request is discarded to prohibit the step of calling a target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data.
2. The GPGPU secure calling method according to claim 1, characterized in that: The step of decrypting the ciphertext instruction by using a target decryption algorithm corresponding to the remote user node to obtain a plaintext instruction includes: Authentication is performed on the target host. If the authentication is successful, the ciphertext to be decrypted, the instruction identification number and the IP information of the remote user node are extracted from the ciphertext instruction, and the ciphertext to be decrypted and the instruction identification number are associated with each other and sent to a locally preset decryption state machine; Determine a corresponding target decryption algorithm based on the IP information, and associate the target decryption algorithm with the instruction identification number and send it to the decryption state machine; Determining the instruction encryption format by the decryption state machine using the access request category and the calculation type obtained from the preset instruction comparison table based on the instruction identification number; In the decryption state machine, based on the instruction identification number, the target decryption algorithm and the instruction encryption format are used to decrypt the ciphertext to be decrypted in the ciphertext instruction to obtain a plaintext instruction.
3. The GPGPU secure calling method according to claim 2, characterized in that: The preset instruction comparison table stores preset legal instruction parameters; Accordingly, the verifying the legitimacy of the GPGPU access request based on the plaintext instruction includes: Determining whether the instruction parameters of the plain text instruction are consistent with the legal instruction parameters stored in the preset instruction comparison table; If they are consistent, the GPGPU access request is determined to be a legal request, otherwise it is an illegal request.
4. The GPGPU secure calling method according to claim 2, characterized in that: If the GPGPU access request is a legitimate request, the method further includes: Based on the instruction identification number, splicing the corresponding plaintext instruction and the request data according to a first preset format to obtain first spliced data; Accordingly, the preset scheduler calls the target computing unit determined from the GPGPU based on the preset scheduling algorithm to process the plaintext instruction and the request data, including: The preset scheduler calls a target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the first spliced data.
5. The GPGPU secure calling method according to claim 1, characterized in that: The step of encrypting the processing result by using a target encryption algorithm corresponding to the remote user node to obtain a ciphertext result includes: Determine the unit identification number of the target computing unit, and obtain the encryption operation code and encryption algorithm data corresponding to the IP information of the remote user node from the computing unit identification list corresponding to the unit identification number; The encryption algorithm data and the unit identification number are associated with each other and sent to a locally preset encryption state machine, and a target encryption algorithm corresponding to the encryption operation code is obtained from a preset kernel; The target encryption algorithm is associated with the unit identification number and then sent to the encryption state machine, so that in the encryption state machine, based on the unit identification number, the processing result is encrypted using the target encryption algorithm and the encryption algorithm data to obtain a ciphertext result.
6. The GPGPU secure calling method according to claim 5, characterized in that: After the processing result is encrypted using the target encryption algorithm corresponding to the remote user node to obtain a ciphertext result, the method further includes: Based on the unit identification number, the ciphertext result and the processing result are spliced in a second preset format to obtain second spliced data; Correspondingly, the step of sending the ciphertext result to the target host so that the target host sends the ciphertext result to the remote user node includes: The second spliced data is sent to the target host, so that the target host sends the second spliced data to the remote user node.
7. A GPGPU security calling device, characterized in that: A safety control module applied to GPGPU, the device comprising: An information acquisition module, used for acquiring the ciphertext instruction and request data carried in the GPGPU access request sent by the target host after parsing the GPGPU access request sent by the remote user node; A decryption verification module, configured to decrypt the ciphertext instruction using a target decryption algorithm corresponding to the remote user node to obtain a plaintext instruction, and verify the legitimacy of the GPGPU access request based on the plaintext instruction; a computing module, configured to send the plaintext instruction and the request data to a preset scheduler through a bus if the GPGPU access request is a legitimate request, so that the preset scheduler calls a target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data and obtain a processing result; an encryption module, used for acquiring the processing result sent by the target computing unit through the bus, encrypting the processing result using a target encryption algorithm corresponding to the remote user node to obtain a ciphertext result, and then sending the ciphertext result to the target host, so that the target host sends the ciphertext result to the remote user node; Among them, after verifying the legitimacy of the GPGPU access request based on the plaintext instruction, the security calling device is also used to discard the GPGPU access request if the GPGPU access request is an illegal request, so as to prohibit the execution of the step of calling the target computing unit determined from the GPGPU based on a preset scheduling algorithm to process the plaintext instruction and the request data.
8. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor is used to execute the computer program to implement the steps of the GPGPU security calling method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein, when the computer program is executed by a processor, the steps of the GPGPU security calling method as described in any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Dynamic multi-factor identity authentication and authentication method and storage medium
CN114385987A
Data secure transmission method and device, computer equipment and storage medium
CN117081815A