Memory sharing method and related device
In the memory sharing scenario between computing nodes in the data center, the memory access control table is used to manage the access rights of the source node to the remote node memory, which solves the computing security problem in memory sharing and improves the security of memory sharing.
Patent Information
- Application Number
- CN202411989373.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-13
AI Technical Summary
In the memory sharing scenario between computing nodes in the data center, there are computing security problems, and it is difficult to effectively limit the range of the source node's access to remote memory.
By setting a memory access control table on the communication hardware of the source node, the authority of the source node to access the remote node memory is recorded. When the communication hardware receives a processing request, it queries the memory access control table to determine whether to perform the operation of accessing the remote node memory.
It effectively limits the range of source nodes accessing remote memory, improves the security of memory sharing, and prevents potential computing security threats.
Smart Images

Figure CN119988057A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a memory sharing method and related devices. Background Art
[0002] At present, in order to meet the computing needs of users, a large number of computing nodes are usually deployed inside the data center. Among them, different computing nodes can be used to provide computing services for different users, thereby meeting the computing needs of each user. Since there are a large number of computing nodes inside the data center, and different computing nodes are often used to process different computing tasks, the computing nodes in the data center are prone to uneven memory usage. That is, the memory of some computing nodes in the data center cannot meet the computing needs, while the memory of other computing nodes is idle.
[0003] In order to solve the problem of uneven memory usage, the concept of memory sharing is proposed in related technologies. Specifically, in a data center, the idle memory on a computing node can be shared with other computing nodes with large memory requirements, thereby improving memory utilization.
[0004] However, in the memory sharing scenario, different computing nodes can access each other's memory, which may easily lead to computing security issues. Therefore, there is an urgent need for a memory sharing method that can ensure computing security. Summary of the invention
[0005] The present application provides a memory sharing method and related devices, which can effectively limit the scope of source node access to remote memory and improve the security of memory sharing.
[0006] In a first aspect, a memory sharing method is provided, which is applied to a scenario where memory is shared between computing nodes. The memory sharing method includes: the communication hardware on the first node obtains a first processing request, and the first processing request is used to indicate the execution of a first processing operation on data at a first address in the memory of the second node. The communication hardware is used to communicate with the second node, and the first processing request can be obtained by the communication hardware on the first node from the processor on the first node. And the first processing request is, for example, a data read request, a data write request, or a data calculation request.
[0007] Then, the communication hardware queries the memory access control table to obtain the access rights corresponding to the first address to determine whether the first node has the right to access the first address in the memory of the second node. The memory access control table is configured on the communication hardware, and the memory access control table is used to record the access rights corresponding to the address in the memory of the remote node.
[0008] Secondly, the communication hardware processes the first processing request according to the access permission. That is, the communication hardware determines whether to execute the first processing request according to the access permission obtained by query.
[0009] In this scheme, a memory access control table is set on the communication hardware of the source node, and the memory access control table records the source node's permission to access the remote node's memory. When the source node triggers access to the remote node's memory, the communication hardware queries the memory access control table to determine whether access to the remote node's memory can be executed, thereby effectively limiting the scope of the source node's access to the remote memory and improving the security of memory sharing.
[0010] In a possible implementation, the communication hardware receives a configuration instruction, which is used to request to modify the content in the memory access control table. For example, the configuration instruction may be an instruction to modify the value of a field in any one or more entries in the memory access control table, thereby instructing to modify the address or access permission recorded in the entry. Then, the communication hardware chooses whether to execute the configuration instruction according to whether the configuration instruction has management authority.
[0011] In this solution, by setting the communication hardware to only execute configuration instructions for the memory access control table with management authority, the configuration of the memory access control table cannot be modified at will, ensuring the security of the content in the memory access control table, thereby ensuring the security of memory sharing between nodes.
[0012] In one possible implementation, the communication hardware selects whether to execute the configuration instruction according to whether the configuration instruction has management authority, including: if the configuration instruction has management authority, the communication hardware executes the configuration instruction; or if the configuration instruction does not have management authority, the communication hardware refuses to execute the configuration instruction.
[0013] In one possible implementation, when the communication hardware recognizes that the configuration instruction comes from the management node, the communication hardware determines that the configuration instruction has management authority; or, when the communication hardware recognizes that the configuration instruction does not come from the management node, the communication hardware determines that the configuration instruction does not have management authority.
[0014] That is, the communication hardware determines whether the configuration instruction has management authority by identifying the source of the configuration instruction. In this way, only the management node can configure or modify the memory access control table on the communication hardware, while other nodes cannot modify the memory access control table, which effectively ensures the security of the memory access control table.
[0015] In one possible implementation, the communication hardware recognizes that the configuration instruction comes from the management node, specifically including: the communication hardware recognizes that the configuration instruction is received from the management interface of the communication hardware; or, the communication hardware recognizes that the value of the target field in the message carrying the configuration instruction is a preset value, wherein the value of the target field is a preset value used to mark that the message comes from the management node.
[0016] That is, the communication hardware may determine whether the configuration instruction comes from the management node by identifying the interface receiving the configuration instruction; or the communication hardware may determine whether the configuration instruction comes from the management node by identifying the value of a specific field in a message carrying the configuration instruction.
[0017] In one possible implementation, the memory access control table includes multiple table entries, the first processing request carries a second address, the first processing request is specifically used to request to perform a first processing operation on data at the second address, the second address is a logical address, and the multiple table entries correspond to different logical addresses.
[0018] When the communication hardware queries the memory access control table, the communication hardware determines the target entry corresponding to the second address in the memory access control table; and the communication hardware obtains the first address and the access rights corresponding to the first address based on the target entry.
[0019] That is, the first address on the memory of the second node and the access rights corresponding to the first address are stored in the target table entry, and the target table entry corresponds to the second address perceived by the processor of the first node. Therefore, the communication hardware can obtain the real address on the memory of the second node (that is, the first address) and the access rights corresponding to the first address based on the second address.
[0020] In this solution, by setting the table entry in the memory access control table to record the address on the remote node memory, and the table entry corresponds to the logical address perceived by the processor on the source node, the processor on the source node can use the memory on the remote node without perceiving the remote node memory address, reducing the complexity of the processor using the remote memory. In addition, when the processor of the source node cannot perceive the remote node memory address, the application on the source node cannot maliciously read the data on the remote node memory based on the processor, further ensuring the security of memory sharing.
[0021] In a possible implementation, the second address is an address in a preset address space, part of the addresses in the preset address space corresponds to the memory in the first node, and another part of the addresses in the preset address space corresponds to the entries in the memory access control table.
[0022] That is, the address space on the remote memory actually recorded by each entry in the memory access control table can be considered as the memory that can be allocated to the source node, and each entry can record a segment of address on the remote memory. Therefore, in order to facilitate address management, a segment of logical address can be uniformly allocated to each entry in the memory access control table from the preset address space, so that the processor can access the real address on the remote memory based on the logical address.
[0023] In this solution, by allocating a fixed address segment from the preset address space to each table entry, changes in the content of the table entry will not affect the processor's normal access to the memory on the remote node, and the processor does not need to perceive changes in the memory shared by the remote node, thereby enabling the processor to use the remote memory without perception.
[0024] In a possible implementation, the first processing operation is a data read operation, and the first processing request comes from a processor on the first node. Processing the first processing request specifically includes: the communication hardware reads the target data from the first address according to the first processing request; and the communication hardware transmits the target data to the processor.
[0025] In a possible implementation, the memory access control table further records an access mode corresponding to the first address, where the access mode is used to indicate exclusive access and / or cache access.
[0026] In one possible implementation, the communication hardware processes a first processing request according to access rights, including: when the communication hardware determines that the first node has permission to perform a first processing operation on data at a first address according to the access rights, the communication hardware sends a second processing request to the second node, the second processing request being used to instruct to perform the first processing operation on the data at the first address; when the communication hardware determines that the first node does not have permission to perform the first processing operation on the data at the first address according to the access rights, the communication hardware refuses to execute the first processing request.
[0027] In a possible implementation, the first node may also share memory with other nodes. In this scenario, the communication hardware may receive a third processing request, the third processing request is used to instruct to perform a second processing operation on data at a third address of the memory of the first node, the second processing operation including data reading, data writing or data calculation; the communication hardware performs the second processing operation on the data at the third address according to the third processing request.
[0028] In a second aspect, a memory sharing device is provided, which is deployed on communication hardware on a first node, and the memory sharing device includes: a transceiver module, which is used to obtain a first processing request, the first processing request is used to indicate to perform a first processing operation on data at a first address in the memory of a second node, and the communication hardware is used to communicate with the second node; a processing module, which is used to query a memory access control table to obtain access rights corresponding to the first address, wherein the memory access control table is configured on the communication hardware, and the memory access control table is used to record access rights corresponding to an address in the memory of a remote node; the processing module is also used to process the first processing request according to the access rights.
[0029] In a possible implementation, the transceiver module is further used to receive a configuration instruction, where the configuration instruction is used to request modification of the content in the memory access control table; the processing module is further used to select whether to execute the configuration instruction according to whether the configuration instruction has management authority.
[0030] In a possible implementation, the processing module is specifically configured to: execute the configuration instruction if the configuration instruction has management authority; or refuse to execute the configuration instruction if the configuration instruction does not have management authority.
[0031] In a possible implementation, the processing module is specifically configured to: determine that the configuration instruction has management authority when it is identified that the configuration instruction comes from the management node; or determine that the configuration instruction does not have management authority when it is identified that the configuration instruction does not come from the management node.
[0032] In one possible implementation, the processing module recognizes that the configuration instruction comes from the management node, including: the processing module recognizes that the configuration instruction is received from the management interface of the communication hardware; or, the processing module recognizes that the value of the target field in the message carrying the configuration instruction is a preset value, wherein the value of the target field is a preset value used to mark that the message comes from the management node.
[0033] In one possible implementation, a memory access control table includes multiple table entries, a first processing request carries a second address, the first processing request is specifically used to request to perform a first processing operation on data at the second address, the second address is a logical address, and multiple table entries correspond to different logical addresses; a processing module is specifically used to: determine a target table entry corresponding to the second address in the memory access control table; obtain the first address and the access rights corresponding to the first address based on the target table entry.
[0034] In a possible implementation, the second address is an address in a preset address space, part of the addresses in the preset address space corresponds to the memory in the first node, and another part of the addresses in the preset address space corresponds to the entries in the memory access control table.
[0035] In one possible implementation, the first processing operation is a data read operation, and the first processing request comes from a processor on the first node; the processing module is further used to read target data from the first address according to the first processing request; the transceiver module is further used to transmit the target data to the processor.
[0036] In a possible implementation, the memory access control table further records an access mode corresponding to the first address, where the access mode is used to indicate exclusive access and / or cache access.
[0037] In one possible implementation, when the processing module determines that the first node has the authority to perform the first processing operation on the data at the first address based on the access rights, the transceiver module is further used to send a second processing request to the second node, and the second processing request is used to instruct to perform the first processing operation on the data at the first address; when the processing module determines that the first node does not have the authority to perform the first processing operation on the data at the first address based on the access rights, the transceiver module is further used to refuse to execute the first processing request.
[0038] In one possible implementation, the transceiver module is further used to receive a third processing request, where the third processing request is used to indicate that a second processing operation is to be performed on data at a third address in the memory of the first node, where the second processing operation includes data reading, data writing, or data calculation; the processing module is further used to perform the second processing operation on the data at the third address according to the third processing request.
[0039] A third aspect of the present application provides a computing device, including a processor and communication hardware, the processor is used to send a data read request to the communication hardware, and the communication hardware is used to execute a method as in any one of the implementations of the first aspect.
[0040] A fourth aspect of the present application provides a computing system, comprising a plurality of computing devices as described in the third aspect.
[0041] A fifth aspect of the present application provides a computer-readable storage medium storing instructions, which, when executed on a computer, enables the computer to execute a method as in any one of the embodiments of the first aspect.
[0042] A sixth aspect of the present application provides a computer program product, which, when executed on a computer, enables the computer to execute a method as in any one of the embodiments of the first aspect.
[0043] The solutions provided in the second to sixth aspects are used to implement or cooperate with the method provided in the first aspect, and therefore can achieve the same or corresponding beneficial effects as the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 A schematic diagram of a memory sharing system architecture provided for this application;
[0045] Figure 2 A flowchart of a memory sharing method provided in this application;
[0046] Figure 3 A schematic diagram of a process for node 1 to read data in the memory of node 2 provided in this application;
[0047] Figure 4 A schematic diagram of a process of node 1 writing data to the memory of node 2 provided in this application;
[0048] Figure 5 A schematic diagram of the structure of a memory access control table provided for this application;
[0049] Figure 6 A schematic diagram of the correspondence between a memory access control table and a logical address provided in this application;
[0050] Figure 7 A comparative diagram of a processor accessing local memory and remote node memory provided in this application;
[0051] Figure 8 A flow chart of a communication hardware provided in this application performing a management authority check on a configuration instruction;
[0052] Fig. 9 A schematic diagram of a node connection through a control network and a data network provided in this application;
[0053] Fig.10 A schematic diagram of the structure of a memory sharing device provided in this application;
[0054] Fig.11 A schematic diagram of the structure of a computing device provided in this application. DETAILED DESCRIPTION
[0055] In order to make the purpose, technical solutions and advantages of the present application clearer, the embodiments of the present application are described below in conjunction with the accompanying drawings. Obviously, the described embodiments are only embodiments of a part of the present application, rather than all embodiments. It is known to those of ordinary skill in the art that with the emergence of new application scenarios, the technical solutions provided by the present application are also applicable to similar technical problems.
[0056] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the descriptions used in this way can be interchanged where appropriate, so that the embodiments can be implemented in a sequence other than that illustrated or described in the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or modules is not necessarily limited to those steps or modules that are clearly listed, but may include other steps or modules that are not clearly listed or inherent to these processes, methods, products or devices. The naming or numbering of the steps that appear in the present application does not mean that the steps in the method flow must be executed in the time / logical sequence indicated by the naming or numbering. The process steps that have been named or numbered can change the execution order according to the technical purpose to be achieved, as long as the same or similar technical effects can be achieved. The division of units in this application is a logical division. There may be other division methods when it is implemented in actual applications. For example, multiple units can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection between units can be electrical or other similar forms, which are not limited in this application. In addition, the units or sub-units described as separate components may or may not be physically separated, may or may not be physical units, or may be distributed in multiple circuit units, and some or all of the units may be selected according to actual needs to achieve the purpose of the present application.
[0057] The applicant has found through research that in the memory sharing scenario, since different computing nodes can access each other's memory, it is easy to cause computing security problems. For example, when different computing nodes are leased to different tenants, after a computing node is hacked, the computing node can read the data of other computing nodes by accessing the shared memory on other computing nodes, or directly attack other computing nodes, thereby causing computing security problems.
[0058] Based on this, the present application provides a memory sharing method, which sets a memory access control table on the communication hardware of the source node, and the memory access control table records the source node's access rights to the remote node's memory. When the source node triggers access to the remote node's memory, the communication hardware queries the memory access control table to determine whether access to the remote node's memory can be performed, thereby effectively limiting the scope of the source node's access to the remote memory and improving the security of memory sharing.
[0059] For example, see Figure 1 , Figure 1 A schematic diagram of a memory sharing system architecture provided by this application. Figure 1 As shown, the system architecture includes a management node, node 1, and node 2. Node 1 includes processor 1, memory 1, and communication hardware 1. Node 2 includes processor 2, memory 2, and communication hardware 2. Memory 1 of node 1 and memory 2 of node 2 participate in memory sharing. In addition, memory access control tables are deployed on communication hardware 1 of node 1 and communication hardware 2 of node 2 to record the access rights of the local node to the addresses on the memory of the remote node.
[0060] For example, when the memory 1 on node 1 cannot meet the usage requirements of processor 1, processor 1 sends a data processing request to communication hardware 1, which is used to request to perform a data processing operation on the target address on memory 2 of node 2. After receiving the data processing request, communication hardware 1 queries the deployed memory access control table to confirm whether node 1 has access rights to the target address on memory 2 of node 2. After confirming that node 1 has access rights to the target address, communication hardware 1 on node 1 forwards the data processing request to communication hardware 2 on node 2, thereby completing node 1's use of the memory shared by node 2.
[0061] Optionally, Node 1 and Node 2 may also be connected to a management node, which is responsible for configuring and modifying the memory access control list in Node 1 and Node 2 to ensure the security of the memory access control list. That is, the memory access control list on Node 1 and Node 2 can only be modified by the management node, and the software running on Node 1 and Node 2 cannot modify the memory access control list.
[0062] It should be noted that Figure 1 The system architecture includes two nodes, node 1 and node 2, which implement memory sharing. In practical applications, the system architecture may also include other nodes that participate in memory sharing, and the application does not specifically limit the number of nodes.
[0063] See also Figure 2 , Figure 2 A flowchart of a memory sharing method provided in this application. Figure 2 As shown, the memory sharing method includes the following steps 201-203.
[0064] Step 201: Communication hardware on a first node obtains a first processing request, where the first processing request is used to instruct to perform a first processing operation on data at a first address in a memory of a second node, and the communication hardware is used to communicate with the second node.
[0065] In the present application, the first processing request may be obtained by the communication hardware on the first node from the processor on the first node. For example, the processor sends the first processing request to the communication hardware in the form of memory operation semantics such as Load semantics or Store semantics to request to perform an operation on the memory. In other words, for the processor on the first node, the processor may treat the memory of the second node as local memory to perform memory access operations, so that the processor does not need to perceive the memory of the remote node.
[0066] The first processing request acquired by the communication hardware is, for example, a data read request, a data write request, or a data calculation request. In the case where the first processing request is a data read request, the first processing operation is specifically a data read operation, that is, the first processing request is used to instruct to read the data at the first address. In the case where the first processing request is a data write request, the first processing operation is specifically a data write operation, that is, the first processing request is used to instruct to write data to the first address. In the case where the first processing request is a data calculation request, the first processing operation is specifically a data calculation operation, that is, the first processing request is used to instruct to calculate the data at the first address (for example, add 1 to the data).
[0067] Specifically, the first node and the second node are, for example, hardware such as servers or artificial intelligence (AI) accelerators. Among them, AI accelerators include, for example, hardware such as graphics processing units (GPUs), tensor processing units (TPUs), or neural network processors (NPUs). In the case where the first node is a server, the processor on the first node is, for example, a central processing unit (CPU), and the communication hardware is, for example, a network card. In the case where the first node is an AI accelerator, the processor on the first node is a computing unit on the AI accelerator, and the communication hardware on the first node is a hardware module responsible for communicating with the outside.
[0068] Step 202: The communication hardware queries a memory access control table to obtain access rights corresponding to the first address, wherein the memory access control table is configured on the communication hardware, and is used to record access rights corresponding to addresses on the memory of the remote node.
[0069] After obtaining the first processing request for the address on the memory of the second node, the communication hardware queries the memory access control table configured by itself to obtain the access rights corresponding to the first address to determine whether the first node has the right to access the first address on the memory of the second node. The memory access control table is pre-configured on the communication hardware, and the memory access control table is used to record the access rights that the first node has for the address on the memory of the remote node. The remote node refers to other nodes other than the current node (i.e., the first node).
[0070] The access rights recorded in the memory access control table may include multiple types of rights, such as no access rights, data read rights, data write rights, and data read and write rights. The data read rights indicate that the first node only has the right to read data, the data write rights indicate that the first node only has the right to write data, and the data read and write rights indicate that the first node has the right to both read and write data.
[0071] It should be noted that if the memory access control table does not record the access permission corresponding to the first address, the communication hardware may deem that the first node does not have access permission for the first address, that is, the access permission corresponding to the first address is no access permission.
[0072] Step 203: The communication hardware processes the first processing request according to the access permission.
[0073] Specifically, the communication hardware determines whether to execute the first processing request based on the access rights obtained by the query. If the communication hardware obtains through the query that the first node does not have the access rights to the first address, the communication hardware refuses to execute the first processing request. If the communication hardware obtains through the query that the first node has the access rights to the first address, the communication hardware further confirms whether the access rights to the first address possessed by the first node match the first processing operation, thereby determining whether to execute the first processing request.
[0074] Exemplarily, when the communication hardware determines that the first node has the permission to perform the first processing operation on the data at the first address according to the access permission, the communication hardware sends a second processing request to the second node, and the second processing request is used to instruct to perform the first processing operation on the data at the first address. In this way, after receiving the second processing request, the second node will execute the second processing request, thereby realizing the execution of the first processing operation on the data at the first address.
[0075] For example, assuming that the access permission corresponding to the first address is data read and write permission, and the first processing request is to instruct to perform a data read operation on the data at the first address, then the communication hardware can determine that the first node has permission to perform the first processing operation on the data at the first address, thereby sending a second processing request to the second node.
[0076] If the communication hardware determines based on the access rights that the first node does not have the authority to perform the first processing operation on the data at the first address, the communication hardware refuses to perform the first processing request.
[0077] For example, assuming that the access permission corresponding to the first address is data read permission, and the first processing request is to instruct to perform a data write operation on the data at the first address, then the communication hardware can determine that the first node does not have permission to perform the first processing operation on the data at the first address, and thus refuse to execute the first processing request.
[0078] In general, in this scheme, a memory access control table is set on the communication hardware of the source node (i.e., the first node mentioned above), and the memory access control table records the permission of the source node to access the memory of the remote node (i.e., the second node mentioned above). When the source node triggers access to the memory of the remote node, the communication hardware queries the memory access control table to determine whether access to the remote node memory can be executed, thereby effectively limiting the scope of the source node's access to the remote memory and improving the security of memory sharing.
[0079] In addition, since the present solution sets a memory access control table at the source node to limit the source node's memory access to the remote node, data processing requests that do not have access rights can flow only within the source node and will not be sent to the remote node (i.e., will not flow on the network), thereby minimizing the communication overhead between nodes.
[0080] For example, see Figure 3 , Figure 3 This is a schematic diagram of a process flow of node 1 reading data in the memory of node 2 provided in this application. Figure 3 As shown, the process of node 1 reading data in the memory of node 2 includes the following steps 301-306.
[0081] Step 301 , processor 1 of node 1 sends data read request 1 to communication hardware 1 , where data read request 1 is used to instruct reading data at address 1 in memory 2 of node 2 .
[0082] Specifically, when the application program executed by the processor 1 needs to read data, the processor 1 triggers to send a data read request 1 to the communication hardware 1 to instruct to read the data at address 1 on the memory 2 of the node 2. The node 1 is, for example, the first node mentioned above, the communication hardware 1 is, for example, the communication hardware on the first node mentioned above, the node 2 is, for example, the second node mentioned above, and the data read request 1 is, for example, the first processing request mentioned above.
[0083] Step 302 , the communication hardware 1 queries the memory access control table to determine whether the node 1 has the permission to read the data at address 1 in the memory 2 of the node 2 .
[0084] Based on the received data read request 1 , the communication hardware 1 queries the memory access control table to determine whether the node 1 has the data read permission for the address 1 .
[0085] Step 303 , after determining that node 1 has the data read permission at address 1 on memory 2 , communication hardware 1 sends a data read request 2 to communication hardware 2 on node 2 .
[0086] After determining that node 1 has the data read permission at address 1 by querying the memory access control table, communication hardware 1 processes data read request 1. For example, communication hardware 1 generates a data read request 2 according to the encapsulation requirements of the communication protocol, and sends data read request 2 to communication hardware 2 on node 2, where data read request 2 is used to instruct to read data at address 1 on memory 2 of node 2. Data read request 2 is, for example, the second processing request mentioned above.
[0087] Step 304 , the communication hardware 2 reads the target data at address 1 of the memory 2 .
[0088] Based on the received data read request 2 , the communication hardware 2 reads the target data located at the address 1 of the memory 2 .
[0089] Step 305 , communication hardware 2 sends the read target data to communication hardware 1 .
[0090] Step 306 , the communication hardware 1 sends the target data to the processor 1 .
[0091] After communication hardware 1 receives the target data sent by communication hardware 2, communication hardware 1 can directly send the target data to processor 1 without storing the target data in the local memory of node 1. In this way, when processor 1 sends data read request 1 to communication hardware 1 with memory operation semantics (i.e., Load semantics), processor 1 cannot perceive that the target data is actually read from the memory of the remote node, thus realizing processor-unaware memory sharing.
[0092] For example, see Figure 4 , Figure 4 This is a schematic diagram of a process of node 1 writing data to the memory of node 2 provided in this application. Figure 4 As shown, the process of node 1 writing data to the memory of node 2 includes the following steps 401-404.
[0093] Step 401 , processor 1 of node 1 sends data write request 1 to communication hardware 1 , where data write request 1 is used to instruct writing target data to address 1 of memory 2 of node 2 .
[0094] Step 401 is similar to step 301, except that in step 401, processor 1 sends data write request 1. Data write request 1 may carry target data to indicate that the target data is written to address 1 of memory 2 of node 2.
[0095] Step 402 , the communication hardware 1 queries the memory access control table to determine whether the node 1 has the permission to write data at address 1 in the memory 2 of the node 2 .
[0096] Step 403 , after determining that node 1 has the data writing permission for address 1 on memory 2 , communication hardware 1 sends a data writing request 2 to communication hardware 2 on node 2 .
[0097] That is to say, only after determining that node 1 has the data write permission for address 1 of node 2 by querying the memory access control table, communication hardware 1 will trigger the processing of data write request 1, thereby sending data write request 2 to communication hardware 2 on node 2. Among them, data write request 2 is used to indicate writing target data to address 1 on memory 2 of node 2.
[0098] Step 404 , the communication hardware 2 writes the target data to address 1 of the memory 2 .
[0099] Based on the received data write request 2, the communication hardware 2 writes the target data to the address 1 in the memory 2 of the node 2, thereby completely writing the data across the node memory.
[0100] It should be noted that the above describes the process of the first node using the shared memory on the second node. In some embodiments, the memory on the first node can also be shared with other nodes, so that other nodes can read data in the memory on the first node or write data to the memory on the first node.
[0101] Exemplarily, the communication hardware on the first node may receive a third processing request, the third processing request being used to instruct to perform a second processing operation on data at a third address in the memory of the first node, the second processing operation including data reading, data writing, or data calculation. Furthermore, the third processing request is received by the communication hardware on the first node from the communication hardware of other nodes.
[0102] Then, the communication hardware on the first node performs a second processing operation on the data at the third address according to the third processing request, thereby assisting other nodes in using the memory on the first node.
[0103] That is to say, for any node participating in memory sharing, the node can use the memory shared by other nodes when the memory is tight, or share the memory with other nodes when there is a lot of free memory, thereby realizing flexible memory allocation.
[0104] The above describes the process of implementing memory sharing control based on the memory access control table by the communication hardware. For ease of understanding, the memory access control table configured on the communication hardware will be described in detail below.
[0105] In communication hardware, the memory access control table includes multiple entries, each of which is used to record the access rights corresponding to a segment of address. For example, each entry includes multiple fields, which are: a valid field, an address field, and a permission field. Among them, the valid field is used to indicate whether the current entry is valid. For example, when the value of the valid field is 0, it means that the current entry is invalid, and when the value of the valid field is 1, it means that the current entry is valid.
[0106] The address field is used to indicate the address on the remote node. When the address length indicated by an entry is the default address length, the address field can specifically record the starting address on the remote node. Therefore, based on the starting address and the default address length recorded in the address field, the communication hardware can determine a segment of addresses indicated by the current entry (i.e., the address range consisting of the starting address and the default address length). Of course, the address field can also record the starting address and address length on the remote node, or record the starting address and ending address on the remote node, so as to indicate a segment of addresses on the remote node.
[0107] In addition, in the case where the system includes multiple nodes participating in memory sharing, the memory addresses in different nodes can be uniformly addressed so that the memory on different nodes will have different addresses. In this way, based on the address indicated by the address, the communication hardware can uniquely determine the node corresponding to the address. Of course, the memory addresses in different nodes can also be independently addressed. In the case where the memory addresses in different nodes are independently addressed, each entry in the memory access control table can also include a node field, which is used to record the node identification, so that the communication hardware can determine the node and address indicated by the current entry.
[0108] The permission field is used to indicate the access rights that this node has for the address indicated by the address field. For example, when the value of the permission field is 0, it means no access rights; when the value of the permission field is 1, it means data read rights; when the value of the permission field is 2, it means data write rights; when the value of the permission field is 3, it means data read and write rights.
[0109] Optionally, the memory access control table may also include an access mode field, which is used to record the access mode corresponding to the address indicated by the address field. For example, in the above embodiment, the memory access control table also records the access mode corresponding to the first address, which is used to indicate exclusive access and / or cache access. Among them, exclusive access refers to whether the access to the address is exclusive access. Exclusive access means that when a process of a node accesses an address, other processes cannot access the address, that is, the access to the address is monopolized by one process at the same time. Cache access refers to whether the data accessed from the address of a remote node needs to be cached on this node. For example, when the value of the access mode is 0, it represents ordinary access (that is, no exclusive access is required and no data of the remote node needs to be cached); when the value of the access mode is 1, it represents exclusive access; when the value of the access mode is 2, it represents that the data accessed from the address of the remote node needs to be cached on this node; when the value of the access mode is 3, it represents exclusive access and the data accessed from the address of the remote node needs to be cached on this node.
[0110] For example, see Figure 5 , Figure 5 A schematic diagram of the structure of a memory access control table provided in this application. Figure 5 As shown, the memory access control table includes N entries, namely entry 1 to entry N. The value of N can be set according to the size of the storage space inside the communication hardware, for example, N is 500, 1000 or 2000. Each entry includes a Valid field, an address field, a permission field and an access mode field. In this way, the communication hardware can obtain the access rights of the node to any address on the memory of the remote node by querying each entry in the memory access control table.
[0111] Optionally, in order to enable the processor to use the memory on the remote node without perception, the first processing request sent by the processor to the communication hardware may specifically carry a second address, and the first processing request is specifically used to request to perform a first processing operation on the data at the second address, and the second address is a logical address. That is, the processor does not actually perceive the address of the memory on the remote node, but requests to perform data processing on the memory address on the remote node corresponding to the logical address based on the assigned logical address. In this case, the multiple entries included in the memory access control table actually correspond to different logical addresses, and based on the logical address in the first processing request sent by the processor, a corresponding entry can be uniquely determined, and then the content included in the entry can be obtained.
[0112] Exemplarily, based on the received first processing request, the communication hardware determines the target entry corresponding to the second address in the memory access control table. Then, the communication hardware obtains the first address and the access rights corresponding to the first address based on the target entry. That is, the first address on the memory of the second node and the access rights corresponding to the first address are stored in the target entry, and the target entry corresponds to the second address perceived by the processor of the first node, so the communication hardware can obtain the real address (i.e., the first address) on the memory of the second node and the access rights corresponding to the first address based on the second address.
[0113] In this solution, by setting the table entry in the memory access control table to record the address on the remote node memory, and the table entry corresponds to the logical address perceived by the processor on the source node, the processor on the source node can use the memory on the remote node without perceiving the remote node memory address, reducing the complexity of the processor using the remote memory. In addition, when the processor of the source node cannot perceive the remote node memory address, the application on the source node cannot maliciously read the data on the remote node memory based on the processor, further ensuring the security of memory sharing.
[0114] Exemplarily, the second address is an address in a preset address space. Part of the addresses in the preset address space correspond to the memory in the first node, and another part of the addresses in the preset address space correspond to entries in a memory access control table. Furthermore, each entry in the memory access control table can correspond to a segment of addresses in the preset address space.
[0115] In other words, the address range of the preset address space is actually determined by the memory size in the first node and the address range that all entries in the memory access control table can correspond to. That is, the address space on the remote memory actually recorded by each entry in the memory access control table can be considered as the memory that can be allocated to the source node, and each entry can record a segment of address on the remote memory. Therefore, in order to facilitate address management, a segment of logical address can be uniformly allocated to each entry in the memory access control table from the preset address space, so that the processor can access the real address on the remote memory based on the logical address. In this way, by allocating a fixed segment of address from the preset address space to each entry, changes in the content of the entry will not affect the processor's normal access to the memory on the remote node, and the processor does not need to perceive changes in the memory shared by the remote node, so that the processor can use the remote memory without perception.
[0116] For example, assuming that the first part of the address in the preset address space corresponds to the memory in the first node, and the second part of the address corresponds to the entry in the memory access control table, then the first processor in the first node can use any address in the first part of the address to access the memory in the first node, and use any address in the second part of the address to access the memory in the remote node. In this way, based on the address in a preset address space, the processor can access the local memory and the remote memory without sensing the specific address of the remote memory. That is, when the memory address range that can be shared on the remote memory changes, it is only necessary to modify the content recorded in the entry on the memory access control table of the source node. The processor does not need to sense the changes in the remote memory, and can still use the same logical address in the preset address space to access the remote memory.
[0117] For example, see Figure 6 , Figure 6 A schematic diagram of the correspondence between a memory access control table and a logical address provided in this application. Figure 6 As shown, it is assumed that the address range (10000, 20000) in the preset address space is allocated to all entries in the memory access control table, and each entry in the memory access control table corresponds to an address range of size 1000. At this time, the address range corresponding to entry 1 is (10000, 11000); the address range corresponding to entry 2 is (11000, 12000), the address range corresponding to entry 3 is (12000, 13000)... The address range corresponding to entry 10 is (19000, 20000). That is, assuming that the starting address in the address range allocated to the memory access control table is baseAddress, and the size of the address range corresponding to each entry is entrySize, then the address range corresponding to each entry is (baseAddress+idx*entrySize, baseAddress+(idx+1)*entrySize). Among them, idx is the index of the entry, and the index of the entry increases from 0.
[0118] In general, each entry in the memory access control table corresponds to an address range of 1000. When receiving a data processing request from the processor, the communication hardware can determine the entry corresponding to the logical address according to the address range of the logical address in the data processing request, and then determine the memory address of the remote node that the processor actually needs to access.
[0119] For example, suppose the communication hardware receives a data read request 1 from the processor, and the data read request 1 is used to indicate the data to be read from the address with a starting address of 11500 and an address length of 300. At this time, the communication hardware determines that the starting address 11500 is within the address range (11000, 12000) corresponding to table entry 2, so the communication hardware queries the remote node address and access rights recorded in table entry 2. Among them, table entry 2 records the starting address 23000 on the memory of node 2, and the current node has data read rights for the address range (23000, 24000) on the memory of node 2. Therefore, the communication hardware generates a data read request 2 based on the data read request 1, and sends the data read request 2 to node 2. The data read request 2 is used to indicate the data to be read from the address with a starting address of 23500 and an address length of 300.
[0120] For another example, suppose that the communication hardware receives a data write request 1 from the processor, and the data write request 1 is used to indicate that data is written to an address with a starting address of 13200 and an address length of 500. At this time, the communication hardware determines that the starting address 13200 is within the address range (13000, 14000) corresponding to table entry 4, so the communication hardware queries the remote node address and access rights recorded in table entry 4. Among them, table entry 4 records the starting address 30000 on the memory of node 3, and the current node has data read permission for the address range (30000, 40000) on the memory of node 3. Therefore, the communication hardware generates a data write request 2 based on the data write request 1, and sends the data write request 2 to node 3. The data write request 2 is used to indicate the data in the address with a starting address of 30200 and an address length of 500.
[0121] For example, see Figure 7 , Figure 7 A comparative diagram of a processor accessing local memory and remote node memory provided in this application. Figure 7 As shown, the processor includes a computing unit and a memory management unit (MMU), and the memory management unit is responsible for converting virtual addresses into physical addresses. When the preset address space is specifically (00000, 20000), the address range (00000, 10000) in the preset address space is allocated to the local memory, and the address range (10000, 20000) is allocated to the memory access control table. That is, the addresses in the address range (10000, 20000) are actually logical addresses.
[0122] During the memory access process, the computing unit will send a data processing request to the MMU, and the MMU will convert the virtual address in the data processing request into a physical address, that is, convert the virtual address into an address within the address range (00000, 20000). After completing the conversion from the virtual address to the physical address, if the physical address in the data processing request is within the address range (00000, 10000), then the MMU can send the data processing request to the local memory, and the local memory will complete the corresponding data processing; if the physical address in the data processing request is within the address range (10000, 20000), then the MMU can send the data processing request to the communication hardware, and the communication hardware will complete the corresponding data processing by accessing the remote node memory.
[0123] In general, for a processor, the processor always performs memory access based on the address in a preset address space without being aware of whether the actual access is to local memory or memory on a remote node, and the processor also does not need to be aware of the actual address of the memory on the remote node.
[0124] The above describes how the source node accesses the memory on the remote node based on the memory access control list. The following describes how to configure the memory access control list on the source node.
[0125] It is understandable that in actual scenarios, the memory shared by each node may change. For example, when a node is short of memory, it is often necessary to reclaim the memory shared with other nodes. For example, when a node has more free memory, it may increase the memory that can be shared with other nodes. Therefore, in actual applications, the content of the memory access control table stored on the communication hardware of each node may need to be modified. For example, when the memory shared by the node changes, it is necessary to modify a certain address in the memory access control table to realize the dynamic change of the shared memory. For another example, when the security of the node needs to be increased, the permissions of the memory shared by the node may change. For example, other nodes can only read the data on the memory shared by the node, but cannot write data to the memory shared by the node. At this time, it is necessary to modify the permissions in the memory access control table.
[0126] Exemplarily, based on the above embodiment, the communication hardware on the first node may receive a configuration instruction, and the configuration instruction is used to request to modify the content in the memory access control table. For example, the configuration instruction may be an instruction to modify the value of a field in any one or more entries in the memory access control table, thereby instructing to modify the address or access rights recorded in the entry.
[0127] Then, the communication hardware chooses whether to execute the configuration instruction according to whether the configuration instruction has management authority. That is, after receiving the configuration instruction for the memory access control table, the communication hardware does not immediately execute the configuration instruction, but first determines whether the configuration instruction has management authority, and then decides whether to execute the configuration instruction.
[0128] Specifically, if the configuration instruction has management authority, the communication hardware executes the configuration instruction. If the configuration instruction does not have management authority, the communication hardware refuses to execute the configuration instruction.
[0129] In this solution, by setting the communication hardware to only execute configuration instructions for the memory access control table with management authority, the configuration of the memory access control table cannot be modified at will, ensuring the security of the content in the memory access control table, thereby ensuring the security of memory sharing between nodes.
[0130] Optionally, the communication hardware determines whether the configuration instruction has management authority by identifying the source of the configuration instruction.
[0131] For example, when the communication hardware recognizes that the configuration instruction comes from the management node, the communication hardware determines that the configuration instruction has management authority. Alternatively, when the communication hardware recognizes that the configuration instruction does not come from the management node, the communication hardware determines that the configuration instruction does not have management authority. Among them, the management node can be a node independent of the nodes participating in memory sharing, that is, the management node does not participate in memory sharing, but is responsible for managing each node participating in memory sharing. Of course, in some embodiments, the management node itself can also be a node participating in memory sharing (for example, the management node is the first node or the second node mentioned above).
[0132] That is to say, only the configuration instructions sent by the management node to the communication hardware have management authority, while the configuration instructions sent by other nodes (including the source node itself) do not have management authority. In this way, only the management node can configure or modify the memory access control table on the communication hardware, while other nodes cannot modify the memory access control table, which effectively ensures the security of the memory access control table.
[0133] For example, even if the system on the source node participating in memory sharing is compromised, since the source node does not have management authority, the system on the source node cannot instruct the communication hardware to modify the memory access control table, thereby ensuring that the memory behavior on the remote node accessed by the source node is controlled, effectively preventing the source node from attacking other nodes by modifying the memory access control table.
[0134] For example, see Figure 8 , Figure 8A flow chart of a communication hardware performing management authority check on a configuration instruction provided by the present application. Figure 8 As shown, after the communication hardware receives the configuration instruction requesting to modify the memory access control table, the communication hardware first checks whether the configuration instruction has management authority. If the configuration instruction has management authority, the communication hardware executes the configuration instruction, thereby modifying the content in the memory access control table based on the instructions of the configuration instruction. If the configuration instruction does not have management authority, the communication hardware refuses to execute the configuration instruction and discards the configuration instruction.
[0135] The above is an introduction to the communication hardware determining whether to execute a configuration instruction by checking whether the configuration instruction has management authority. In some possible embodiments, if the communication hardware receives an access instruction requesting access to a memory access control table, the communication hardware may not check whether the access instruction has management authority, but directly execute the access instruction, thereby returning the content in the memory access control table.
[0136] In the present application, there may be multiple ways for the communication hardware to identify whether the configuration instruction comes from the management node.
[0137] In a possible implementation, the communication hardware determines whether the configuration instruction comes from the management node by identifying the interface for receiving the configuration instruction.
[0138] Specifically, the communication hardware may be connected to the management node through a dedicated management interface, and connected to other nodes through other data interfaces. The management interface and the data interface are different hardware interfaces on the communication hardware. For example, see Fig. 9 , Fig. 9 This is a schematic diagram of a node connection through a control network and a data network provided by this application. Fig. 9 As shown, the communication hardware 1 in node 1 and the communication hardware 2 on node 2 can be connected to the control network through the management interface, and then connected to the management node. Therefore, the configuration instructions received by the communication hardware 1 and the communication hardware 2 from the management interface can be considered to come from the management node. In addition, the communication hardware 1 in node 1 and the communication hardware 2 on node 2 are connected to the data network through the data interface, thereby realizing the connection between the nodes participating in memory sharing.
[0139] Then, in the scenario where the communication hardware has a management interface, when the communication hardware recognizes that the configuration instruction is received from the management interface of the communication hardware, the communication hardware can determine that the configuration instruction comes from the management node, and further determine that the configuration instruction has management authority. When the communication hardware recognizes that the configuration instruction is received from the data interface of the communication hardware, the communication hardware can determine that the configuration instruction does not come from the management node, and further determine that the configuration instruction does not have management authority.
[0140] In another possible implementation manner, the communication hardware determines whether the configuration instruction comes from the management node by identifying the value of a specific field in the message carrying the configuration instruction.
[0141] Specifically, the communication hardware may obtain configuration instructions by receiving a message, wherein the configuration instructions are carried in the payload of the message. Furthermore, the message for carrying the configuration instructions includes a target field, which is used to represent the role of the source of the message. That is, the target field may represent the role of the source of the message through different values. For example, when the value of the target field is 0, it means that the node sending the message is a non-management node; when the value of the target field is 1, it means that the node sending the message is a management node.
[0142] Then, when the communication hardware recognizes that the value of the target field in the message carrying the configuration instruction is a preset value (such as 1 above), the communication hardware can determine that the configuration instruction comes from the management node. The value of the target field is a preset value used to mark that the message comes from the management node.
[0143] In actual application scenarios, the communication hardware on each node in the system is pre-configured with the role of the node. When the node where the communication hardware is located is a non-management node, when the communication hardware sends a message outward, the value of the target field in the message will be set to 0 to represent that the source of the message is a non-management node. When the node where the communication hardware is located is a management node, when the communication hardware sends a message outward, the value of the target field in the message will be set to 1 to represent that the source of the message is a management node. In this way, even if the non-management node is compromised and sends an attack message carrying configuration instructions to other nodes, since the communication hardware of the non-management node will inevitably set the value of the target field in the message to 0, the configuration instructions carried in the message sent by the non-management node will not be executed, thereby ensuring the security of the memory access control table.
[0144] The above describes in detail the memory sharing method provided by the present application, and the following will introduce a device for executing the memory sharing method.
[0145] See also Fig.10 , Fig.10 This is a schematic diagram of the structure of a memory sharing device provided by this application. Fig.10As shown, the memory sharing device is deployed on the communication hardware on the first node, and the memory sharing device includes: a transceiver module 1001, used to obtain a first processing request, the first processing request is used to indicate the execution of a first processing operation on the data at the first address in the memory of the second node, and the communication hardware is used to communicate with the second node; a processing module 1002, used to query the memory access control table to obtain the access rights corresponding to the first address, wherein the memory access control table is configured on the communication hardware, and the memory access control table is used to record the access rights corresponding to the address on the memory of the remote node; the processing module 1002 is also used to process the first processing request according to the access rights.
[0146] In a possible implementation, the transceiver module 1001 is further used to receive a configuration instruction, where the configuration instruction is used to request modification of the content in the memory access control table; the processing module 1002 is further used to select whether to execute the configuration instruction according to whether the configuration instruction has management authority.
[0147] In a possible implementation, the processing module 1002 is specifically configured to: execute the configuration instruction if the configuration instruction has management authority; or refuse to execute the configuration instruction if the configuration instruction does not have management authority.
[0148] In a possible implementation, the processing module 1002 is specifically used to: determine that the configuration instruction has management authority when it is identified that the configuration instruction comes from the management node; or determine that the configuration instruction does not have management authority when it is identified that the configuration instruction does not come from the management node.
[0149] In one possible implementation, the processing module 1002 recognizes that the configuration instruction comes from the management node, including: the processing module 1002 recognizes that the configuration instruction is received from the management interface of the communication hardware; or, the processing module 1002 recognizes that the value of the target field in the message carrying the configuration instruction is a preset value, wherein the value of the target field is a preset value used to mark that the message comes from the management node.
[0150] In one possible implementation, a memory access control table includes multiple entries, a first processing request carries a second address, the first processing request is specifically used to request to perform a first processing operation on data at the second address, the second address is a logical address, and multiple entries correspond to different logical addresses; the processing module 1002 is specifically used to: determine a target entry corresponding to the second address in the memory access control table; and obtain the first address and the access rights corresponding to the first address based on the target entry.
[0151] In a possible implementation, the second address is an address in a preset address space, part of the addresses in the preset address space corresponds to the memory in the first node, and another part of the addresses in the preset address space corresponds to the entries in the memory access control table.
[0152] In one possible implementation, the first processing operation is a data read operation, and the first processing request comes from a processor on the first node; the processing module 1002 is also used to read target data from the first address according to the first processing request; the transceiver module 1001 is also used to pass the target data to the processor.
[0153] In a possible implementation, the memory access control table further records an access mode corresponding to the first address, where the access mode is used to indicate exclusive access and / or cache access.
[0154] In one possible implementation, when the processing module 1002 determines, based on the access rights, that the first node has the authority to perform a first processing operation on the data at the first address, the transceiver module 1001 is further used to send a second processing request to the second node, where the second processing request is used to instruct to perform the first processing operation on the data at the first address; when the processing module 1002 determines, based on the access rights, that the first node does not have the authority to perform the first processing operation on the data at the first address, the transceiver module 1001 is further used to refuse to execute the first processing request.
[0155] In one possible implementation, the transceiver module 1001 is further used to receive a third processing request, where the third processing request is used to indicate that a second processing operation is to be performed on data at a third address in the memory of the first node, where the second processing operation includes data reading, data writing, or data calculation; the processing module 1002 is further used to perform a second processing operation on the data at the third address according to the third processing request.
[0156] See also Fig.11 , Fig.11 The schematic diagram of the structure of a computing device provided in this application. The computing device is equipped with the above Fig.10 The memory sharing device of the present invention is implemented by a general bus architecture. That is, the first data node and the second data node can be implemented by a computing device.
[0157] The computing device includes at least one processor 1101 , a communication bus 1102 , a memory 1103 , and communication hardware 1104 .
[0158] Optionally, the processor 1101 is a general-purpose CPU, NP, microprocessor, or one or more integrated circuits, such as an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or a combination thereof. The above-mentioned PLD is a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.
[0159] The communication bus 1102 is used to transmit information between the above components. The communication bus 1102 is divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0160] Optionally, the memory 1103 is a read-only memory (ROM) or other types of static storage devices that can store static information and instructions. Alternatively, the memory 1103 is a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions. Alternatively, the memory 1103 is an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to this. Optionally, the memory 1103 exists independently and is connected to the processor 1101 through the communication bus 1102. Optionally, the memory 1103 and the processor 1101 are integrated together.
[0161] The communication hardware 1104 uses any transceiver-like device for communicating with other devices or communication networks. The communication hardware 1104 includes wired communication hardware. Optionally, the communication hardware 1104 also includes wireless communication hardware. Among them, the wired communication hardware is, for example, an Ethernet interface. The Ethernet interface is an optical interface, an electrical interface, or a combination thereof. The wireless communication hardware is wireless local area network (WLAN) transceiver hardware, cellular network communication hardware, or a combination thereof, etc.
[0162] In a specific implementation, as an embodiment, the processor 1101 includes one or more CPUs, such as Fig.11 CPU0 and CPU1 are shown in the figure.
[0163] In a specific implementation, as an embodiment, the computing device includes multiple processors, such as Fig.11 1 and 1105. Each of these processors is a single-CPU or a multi-CPU. A processor here refers to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0164] In some embodiments, the memory 1103 is used to store program code 1106 for executing the solution of the present application, and the processor 1101 executes the program code 1106 stored in the memory 1103. In other words, the computing device implements the above method embodiment through the processor 1101 and the program code 1106 in the memory 1103.
[0165] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments. Wherein, A refers to B, which means that A is the same as B or A is a simple variation of B.
[0166] The terms "first" and "second" in the description and claims of the embodiments of the present application are used to distinguish different objects, rather than to describe the specific order of the objects, and cannot be understood as indicating or implying relative importance. For example, the first speed-limited channel and the second speed-limited channel are used to distinguish different speed-limited channels, rather than to describe the specific order of the speed-limited channels, and cannot be understood as the first speed-limited channel being more important than the second speed-limited channel.
[0167] In the embodiments of the present application, unless otherwise specified, “at least one” means one or more, and “plurality” means two or more.
[0168] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When loading and executing computer program instructions on a computer, the process or function described in accordance with the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (Digital Subscriber Line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server, data center, etc. that contains one or more available media integrations. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (eg, a solid state drive (SSD)).
[0169] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A memory sharing method, characterized in that: include: The communication hardware on the first node obtains a first processing request, the first processing request is used to instruct to perform a first processing operation on data at a first address in the memory of the second node, and the communication hardware is used to communicate with the second node; The communication hardware queries a memory access control table to obtain access rights corresponding to the first address, wherein the memory access control table is configured on the communication hardware, and the memory access control table is used to record access rights corresponding to addresses on the memory of the remote node; The communication hardware processes the first processing request according to the access permission.
2. The method according to claim 1, characterized in that The method further comprises: The communication hardware receives a configuration instruction, wherein the configuration instruction is used to request modification of the content in the memory access control table; The communication hardware selects whether to execute the configuration instruction according to whether the configuration instruction has management authority.
3. The method according to claim 2, characterized in that The communication hardware selects whether to execute the configuration instruction according to whether the configuration instruction has management authority, including: In the case where the configuration instruction has management authority, the communication hardware executes the configuration instruction; Alternatively, when the configuration instruction does not have management authority, the communication hardware refuses to execute the configuration instruction.
4. The method according to claim 2 or 3, characterized in that: The method further comprises: In the case where the communication hardware recognizes that the configuration instruction comes from a management node, the communication hardware determines that the configuration instruction has management authority; Alternatively, when the communication hardware recognizes that the configuration instruction does not come from the management node, the communication hardware determines that the configuration instruction does not have management authority.
5. The method according to claim 4, characterized in that The communication hardware recognizes that the configuration instruction comes from the management node, including: The communication hardware recognizes that the configuration instruction is received from a management interface of the communication hardware; Alternatively, the communication hardware recognizes that the value of the target field in the message carrying the configuration instruction is a preset value, wherein the value of the target field is the preset value used to mark that the message comes from the management node.
6. The method according to any one of claims 1 to 5, characterized in that: The memory access control table includes a plurality of table entries, the first processing request carries a second address, the first processing request is specifically used to request to perform the first processing operation on the data at the second address, the second address is a logical address, and the plurality of table entries correspond to different logical addresses; The communication hardware queries a memory access control table to obtain access rights corresponding to the first address, including: The communication hardware determines, in the memory access control table, a target entry corresponding to the second address; The communication hardware obtains the first address and the access permission corresponding to the first address based on the target entry.
7. The method according to claim 6, characterized in that The second address is an address in a preset address space, part of the addresses in the preset address space corresponds to the memory in the first node, and another part of the addresses in the preset address space corresponds to the entries in the memory access control table.
8. The method according to any one of claims 1 to 7, characterized in that: The first processing operation is a data read operation, and the first processing request comes from a processor on the first node; The processing of the first processing request comprises: The communication hardware reads target data from the first address according to the first processing request; The communication hardware communicates the target data to the processor.
9. The method according to any one of claims 1 to 8, characterized in that: The memory access control table also records an access mode corresponding to the first address, where the access mode is used to indicate exclusive access and / or cache access.
10. The method according to any one of claims 1 to 9, characterized in that: The communication hardware processes the first processing request according to the access permission, including: When the communication hardware determines, according to the access permission, that the first node has permission to perform the first processing operation on the data at the first address, the communication hardware sends a second processing request to the second node, where the second processing request is used to instruct to perform the first processing operation on the data at the first address; In the event that the communication hardware determines, based on the access rights, that the first node does not have authority to perform the first processing operation on the data at the first address, the communication hardware refuses to perform the first processing request.
11. The method according to any one of claims 1 to 10, characterized in that: The method further comprises: The communication hardware receives a third processing request, the third processing request is used to instruct to perform a second processing operation on data at a third address of the first node memory, the second processing operation includes data reading, data writing or data calculation; The communication hardware performs the second processing operation on the data at the third address according to the third processing request.
12. A memory sharing device, characterized in that: The memory sharing device is deployed on the communication hardware of the first node, and the device includes: a transceiver module, configured to obtain a first processing request, wherein the first processing request is used to instruct to perform a first processing operation on data at a first address in a memory of a second node, and the communication hardware is used to communicate with the second node; A processing module, configured to query a memory access control table to obtain access rights corresponding to the first address, wherein the memory access control table is configured on the communication hardware, and the memory access control table is used to record access rights corresponding to addresses on a remote node memory; The processing module is further configured to process the first processing request according to the access permission.
13. The device according to claim 12, characterized in that The transceiver module is further used to receive a configuration instruction, wherein the configuration instruction is used to request modification of the content in the memory access control table; The processing module is further used to select whether to execute the configuration instruction according to whether the configuration instruction has management authority.
14. The device according to claim 13, characterized in that The processing module is specifically used for: If the configuration instruction has management authority, execute the configuration instruction; Alternatively, if the configuration instruction does not have management authority, the configuration instruction is refused to be executed.
15. The device according to claim 13 or 14, characterized in that The processing module is specifically used for: In the case of identifying that the configuration instruction comes from a management node, determining that the configuration instruction has management authority; Alternatively, when it is identified that the configuration instruction does not come from the management node, it is determined that the configuration instruction does not have management authority.
16. The device according to claim 15, characterized in that The processing module recognizes that the configuration instruction comes from the management node, including: The processing module recognizes that the configuration instruction is received from the management interface of the communication hardware; Alternatively, the processing module identifies that the value of the target field in the message carrying the configuration instruction is a preset value, wherein the value of the target field is the preset value used to mark that the message comes from the management node.
17. The device according to any one of claims 12 to 16, characterized in that: The memory access control table includes a plurality of table entries, the first processing request carries a second address, the first processing request is specifically used to request to perform the first processing operation on the data at the second address, the second address is a logical address, and the plurality of table entries correspond to different logical addresses; The processing module is specifically used for: determining, in the memory access control table, a target entry corresponding to the second address; The first address and access rights corresponding to the first address are obtained based on the target entry.
18. The device according to claim 17, characterized in that The second address is an address in a preset address space, part of the addresses in the preset address space corresponds to the memory in the first node, and another part of the addresses in the preset address space corresponds to the entries in the memory access control table.
19. A computing device, characterized in that: include: A processor and communication hardware, wherein the processor is used to send a data read request to the communication hardware, and the communication hardware is used to execute the method according to any one of claims 1-11.
20. A computing system, characterized in that: include: A plurality of computing devices as claimed in claim 19.
21. A computer-readable storage medium, characterized in that: Instructions are stored, and when the instructions are executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 11.
22. A computer program product, characterized in that The computer program product comprises program codes, and when a computer runs the computer program product, the computer executes the method according to any one of claims 1 to 11.
Citation Information
Cited By
Memory sharing method and related apparatus
WO2026144202A1