Neural network accelerator authorization method, system and equipment based on software and hardware collaboration
Through the neural network accelerator authorization method based on software and hardware collaboration, the DNA code of FPGA is used for double-layer encryption and decoding, which solves the problem of insufficient authorization structure optimization in the existing technology, and improves the operating speed and security of the neural network accelerator.
Patent Information
- Application Number
- CN202510101300.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art cannot effectively optimize the authorization structure of neural network accelerators, resulting in additional resource and power consumption, weakening the performance advantages of NPUs and hindering its application in real-time and security scenarios.
Using a neural network accelerator authorization method based on software and hardware collaboration, two levels of encryption and decoding are performed by obtaining the FPGA DNA code to ensure the security and accuracy of the authorization code, thereby authorizing the startup of the neural network accelerator.
The running rate of neural network accelerator is optimized, the security of authorization code is enhanced, unauthorized access and use is prevented, and the optimization balance between encryption authorization security and hardware resource utilization is achieved.
Smart Images

Figure CN120012175A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer hardware acceleration, and relates to a neural network accelerator authorization method, system and device based on software and hardware collaboration. Background Art
[0002] With the rapid development of artificial intelligence technology, convolutional neural networks (CNN) are increasingly being used in embedded systems, which has promoted scholars' research on neural network accelerators (NPUs). Considering the speed of technology iteration and the flexibility of deployment connections, neural network accelerators (NPUs) usually need to go through the stage of deployment based on field programmable logic array (FPGA) platforms, and work with matching runtime software to complete intelligent acceleration tasks. The form submitted to users or third parties is usually a neural network accelerator (NPU) netlist or comprehensive bit file. This form of delivery naturally has the possibility of deployment on multiple hardware platforms or multiple boards of the same model, and the controllability is low, which makes the economic value generated difficult to estimate. Therefore, it is necessary to encrypt the provided NPU IP and authorize the opening of functions according to the different platforms used by users. It should be noted that NPU is the abbreviation of Neural Network Processing Unit (NPU), and IP is the abbreviation of Intellectual Property (IP) formed by FPGA encoding.
[0003] Xilinx FPGA contains DNA shift registers, which can be understood as the unique "identity ID" of each FPGA chip, which can be used to determine whether it is a designated legal hardware. There are two common Xilinx FPGA bit widths. On 7series and previous versions of FPGA chips, the DNA code bit width is 57 bits, while the ultrascale architecture is 96 bits. Encryption needs to be compatible with both bit widths. Xilinx FPGA is a field programmable logic array (FPGA) chip produced by Xilinx.
[0004] There is no encryption authorization method for neural network accelerator (NPU) hardware and software in existing patents and papers, and the general FPGA encryption method is not well adapted to the NPU system.
[0005] When a neural network accelerator processes a convolutional neural network (CNN) algorithm model, it often requires the runtime program on the software side and the NPU on the FPGA side to interact according to the design mechanism. Therefore, when designing an encryption authorization method, this software-hardware collaboration mechanism must be considered to ensure better results in encryption reliability and security. However, traditional authorization methods do not take into account the functional and structural characteristics of neural network accelerators, and cannot optimize the authorization structure in a targeted manner. They often bring additional resources and power consumption, which will weaken the performance advantages of the NPU itself and hinder the application of the NPU in real-time and security scenarios. Summary of the invention
[0006] The purpose of the present invention is to provide a neural network accelerator authorization method, system and device based on software and hardware collaboration to solve the technical problem that the existing methods cannot optimize the authorization structure in a targeted manner, resulting in additional resources and power consumption. The present invention is conducive to optimizing the operating rate of the neural network accelerator.
[0007] In order to achieve the above object, the present invention adopts the following technical solutions: In a first aspect, the present invention provides a neural network accelerator authorization method based on software and hardware collaboration, comprising the following steps: Obtaining DNA code from a field programmable gate array; The DNA code of the field programmable gate array is encrypted at two levels to obtain the authorization code; After obtaining the neural network accelerator running instructions, the authorization code is decoded at two levels to obtain the final result data; Compare the final result data with the DNA code of the field programmable gate array. If the final result data is the same as the DNA code of the field programmable gate array, the neural network accelerator is authorized to start, otherwise the neural network accelerator enters an authorization failure state.
[0008] In a second aspect, the present invention provides a neural network accelerator authorization system based on software and hardware collaboration, comprising: DNA code acquisition module: used to acquire the DNA code of the field programmable gate array; Encryption module: used to encrypt the DNA code of the field programmable gate array at two levels to obtain the authorization code; Decoding module: used to decode the authorization code at two levels to obtain the final result data after obtaining the neural network accelerator running instruction; Neural network accelerator authorization module: used to compare the final result data with the DNA code of the field programmable gate array. If the final result data is the same as the DNA code of the field programmable gate array, the neural network accelerator is authorized to start, otherwise the neural network accelerator enters the authorization failure state.
[0009] In a third aspect, the present invention provides an electronic device comprising: a processor; a memory for storing computer program instructions; and steps for implementing a neural network accelerator authorization method based on software and hardware collaboration when executing the computer program.
[0010] In a fourth aspect, the present invention provides a storage medium storing computer program instructions. When the computer program instructions are loaded and executed by a processor, the processor executes a neural network accelerator authorization method based on software and hardware collaboration.
[0011] Compared with the prior art, the present invention has the following beneficial effects: 1. The present invention ensures the pertinence of subsequent encryption and decoding operations by acquiring the DNA code of the field programmable gate array; encrypts the DNA code of the field programmable gate array at two levels to obtain the authorization code, thereby enhancing the security of the authorization code; after obtaining the neural network accelerator operation instruction, decodes the authorization code at two levels to obtain the final result data; compares the final result data with the DNA code of the field programmable gate array, and if the final result data is the same as the DNA code of the field programmable gate array, the neural network accelerator is authorized to start, otherwise the neural network accelerator enters the authorization failure state, thereby preventing unauthorized access and use. The present invention ensures the security and reliability of the neural network accelerator by acquiring the DNA code of the FPGA, performing two levels of encryption and decoding, and comparing the final result data with the DNA code of the FPGA, providing a strong guarantee for the wide application of the neural network accelerator. At the same time, the present invention implements a double-layer encryption and double-decryption mechanism at the runtime end and the neural network accelerator (NPU) end, implements the AES encryption algorithm on the software end, and designs the hardware end as a safe, efficient, and low-resource-consuming independent secondary decoding, thereby allocating more resources to CNN calculations on the NPU, achieving an optimal balance between encryption authorization security and hardware resource utilization, and is conducive to optimizing the operating rate of the neural network accelerator.
[0012] 2. When the present invention is running, the encrypted authorization code is written into the internal register group of the neural network accelerator (NPU) to achieve multi-board adaptation of the hardware netlist and bitstream. After the customer replaces the board of the same model, he only needs to provide the corresponding encrypted authorization code, avoiding multiple integrations for different DNA boards.
[0013] 3. The system of the present invention includes: a DNA code acquisition module, an encryption module, a decoding module and a neural network accelerator authorization module. The DNA code acquisition module is used to obtain the DNA code of the field programmable gate array; the encryption module is used to perform two-level encryption on the DNA code of the field programmable gate array to obtain the authorization code; the decoding module is used to perform two-level decoding on the authorization code to obtain the final result data after obtaining the neural network accelerator operation instruction; the neural network accelerator authorization module is used to compare the final result data with the DNA code of the field programmable gate array. If the final result data is the same as the DNA code of the field programmable gate array, the neural network accelerator is authorized to start, otherwise the neural network accelerator enters the authorization failure state. The various modules cooperate with each other to optimize the operating rate of the neural network accelerator in a reliable encryption environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 This is a flowchart of a neural network accelerator authorization based on software and hardware collaboration according to an embodiment of the present invention; Figure 2 This is a diagram of the software and hardware collaborative authorization structure of the neural network accelerator according to an embodiment of the present invention; Figure 3 This is a diagram of the NPU submodule and dual clock domain authorization structure of an embodiment of the present invention; Figure 4 This is a diagram of the NPU controller authorization processing structure according to an embodiment of the present invention; Figure 5 This is a diagram of a multi-platform configurable authorization matching structure according to an embodiment of the present invention; Figure 6 is a flow chart of the method of the present invention; Figure 7 It is a system module diagram of the present invention; DETAILED DESCRIPTION In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0015] It should be noted that the terms "first", "second", etc. in the specification of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0016] The present invention is further described in detail below in conjunction with the accompanying drawings: See also Figure 6 The present invention discloses a neural network accelerator authorization method based on software and hardware collaboration, comprising the following steps: S1, obtain the DNA code of the field programmable gate array to ensure the pertinence of subsequent encryption and decoding operations. The DNA code of the FPGA is usually unique, which helps to ensure the accuracy and security of the authorization process; S2, encrypting the DNA code of the field programmable gate array at two levels to obtain the authorization code, thereby enhancing the security of the authorization code; S3, after obtaining the neural network accelerator running instruction, the authorization code is decoded at two levels to obtain the final result data; S4, compares the final result data with the DNA code of the field programmable gate array. If the final result data is the same as the DNA code of the field programmable gate array, the neural network accelerator is authorized to start, otherwise the neural network accelerator enters an authorization failure state, thereby preventing unauthorized access and use.
[0017] The present invention ensures the security and reliability of the neural network accelerator by obtaining the DNA code of the FPGA, performing two levels of encryption and decoding, and comparing the final result data with the DNA code of the FPGA, providing a strong guarantee for the wide application of the neural network accelerator. At the same time, the present invention implements a double-layer encryption and double-decryption mechanism at the runtime end and the neural network accelerator (NPU) end, implements the AES encryption algorithm at the software end, and designs the hardware end as a safe, efficient, and low-resource-consuming independent secondary decoding, thereby allocating more resources to NPUCNN calculations, achieving an optimal balance between encryption authorization security and hardware resource utilization, and is conducive to optimizing the operating rate of the neural network accelerator.
[0018] Embodiment 1: See also Figure 6The present invention discloses a neural network accelerator authorization method based on software and hardware collaboration, comprising the following steps: S1, obtain the DNA code of the field programmable gate array, as follows: The DNA code of the field programmable gate array was obtained using Xilinx Vivado tool.
[0019] S2, encrypt the DNA code of the field programmable gate array at two levels to obtain the authorization code; S3, after obtaining the neural network accelerator running instructions, performs two levels of decoding on the authorization code to obtain the final result data, as follows: After obtaining the neural network accelerator running instructions, the authorization code is first-level decrypted to obtain the key code, and the key code is written into the neural network accelerator through the AXI_Lite interface; Preferably, the authorization code is first-level decrypted to obtain the key code, as follows: The AES encryption and decryption algorithm is used to perform a first-level decryption on the authorization code to obtain the key code. An irregular random number is used as the key in the first-level decryption process.
[0020] The key code is decoded in the neural network accelerator hardware at the second level to obtain the final result data, as follows: The key code is written into four 32-bit registers in sequence to obtain four groups of 32-bit data, the 32-bit data are sorted in order from low to high, and the four groups of 32-bit data are spliced to obtain a spliced key code; Using bit field selection and a preset mapping table, the spliced key code is converted into a 96-bit or 57-bit value to be compared to obtain the final result data. The mapping table is shown in Table 1. Preferably, the two levels of encryption and the two levels of decoding are inverse processes of each other.
[0021] S4, compare the final result data with the DNA code of the field programmable gate array. If the final result data is the same as the DNA code of the field programmable gate array, the neural network accelerator is authorized to start, otherwise the neural network accelerator enters the authorization failure state.
[0022] Preferably, if the final result data is different from the DNA code of the field programmable gate array, the neural network accelerator enters an authorization failure state, and shuts down the DDR memory access module, cache control module, PE computing array and input and output cache.
[0023] Embodiment 2: This embodiment discloses a neural network accelerator authorization method based on software and hardware collaboration, which is as follows: Generally speaking, intelligent computing tasks require runtime software and neural network accelerator (NPU) hardware to complete. The runtime analyzes the convolutional neural network (CNN) model to be processed, decomposes its operator layers into instruction codes that can be recognized and executed by the neural network accelerator (NPU), and arranges the feature map and weight data in a way that is easy for the hardware to read efficiently. The two parts of data are stored in a specific address of DDR. Then, the neural network accelerator (NPU) startup address is configured through the AXI_Lite interface, and information such as depth and task mode are read. The neural network accelerator (NPU) completes DDR memory access and efficient parallel computing based on this.
[0024] It should be noted that DDR stands for Double Data Rate Synchronous Dynamic Random Access Memory, which is double data rate synchronous dynamic random access memory, that is, memory.
[0025] Based on the above infrastructure, the present invention proposes a neural network accelerator authorization method that cooperates with software and hardware. The overall authorization process is as follows: Figure 1 As shown, Figure 1 Authorization flow chart for neural network accelerator based on software and hardware collaboration.
[0026] First, it is necessary to assist the user to connect the field programmable gate array (FPGA) board to be deployed to the computer through the jtag interface, and use the integrated development environment tool corresponding to the field programmable gate array (FPGA) to read the DNA code, such as the Xilinx Vivado tool. Then, according to the platform to be deployed provided by the user, the DNA code of the field programmable gate array (FPGA) is obtained, and two-level encryption is performed to obtain the authorization code, which is provided to the user. Design a dedicated software tool to complete the encryption of the DNA code in this step, and reversely decrypt it at runtime and in the neural network accelerator (NPU). Encryption and decryption are designed to be implemented in two levels, which are inverse processes of each other.
[0027] It should be noted that Xilinx Vivado is an integrated design environment released by Xilinx, which is specially designed for the design and development of field programmable gate arrays (FPGAs).
[0028] The encryption process is as follows: A special software tool is designed to implement two-level encryption of DNA codes. First, the DNA code read by the FPGA hardware is expanded with random numbers. The low bits of the 96-bit DNA code are supplemented with 4 random numbers to 100 bits, and the low bits of the 57-bit DNA code are supplemented with 3 random numbers to 60 bits. Then, the expanded 100-bit or 60-bit data are inversely mapped according to Table 1 to obtain the key code. For example, the first bit of the DNA code is mapped to the 95th bit of the key code, and the second bit is mapped to the 117th bit of the key code. Since the key code is 128 bits, there are non-mapped bits, which are filled with random 0 and 1 data. Finally, the key code is encrypted with a key to obtain an authorization code for the user.
[0029] The decryption process is as follows: Next, before using the neural network accelerator (NPU) function, the user enters the authorization code into the runtime software, and performs a first-level decryption during runtime. The decrypted result data is called the key code, which is written into the neural network accelerator (NPU) through the AXI_Lite interface.
[0030] Finally, the key code is decoded in the neural network accelerator (NPU) hardware at the second level to obtain the final result data. The final result data is compared with the DNA code of the field programmable gate array actually read by the hardware. If the data is the same, the neural network accelerator (NPU) is authorized to start, otherwise it enters the authorization failure state. In the authorization failure state, the read value of the state feedback register inside the neural network accelerator (NPU) shows locked. When the authorization is passed, it is in the normal state. During operation, it is determined whether the neural network accelerator (NPU) calculation can be started based on the state value of the register.
[0031] The decoding process requires the cooperation of both software and hardware to achieve, as follows Figure 2 As shown, Figure 2 A collaborative licensing structure for neural network accelerator (NPU) hardware and software.
[0032] The runtime mainly includes a first-level decoding module for encryption authorization, as well as a neural network accelerator (NPU) driver and data processing module that supports convolutional neural network (CNN) calculations. The first-level decoding module uses the AES (Advanced Encryption Standard) 128-bit encryption and decryption algorithm, which is referred to as the AES encryption and decryption algorithm. As a symmetric encryption algorithm, the encryption and decryption keys of the AES encryption and decryption algorithm are the same, using irregular random numbers as the key, and are used in the software tool encryption (first-level encryption) and runtime decryption process.
[0033] The neural network accelerator (NPU) mainly includes a secondary decoding module and an authorization module, as well as modules that implement functions such as cache and computing array required for neural network accelerator (NPU) calculations. The secondary decryption module converts the key code (the output result of the primary decoding) input at runtime into a 96-bit or 57-bit comparison value, and participates in the subsequent DNA matching comparison. The secondary decoding is implemented by using a mapping table plus a bit field selection method, and different decoding methods are used for different DNA bit widths, which will be described in detail later.
[0034] See also Figure 3 , which is the neural network accelerator (NPU) submodule and dual clock domain authorization structure. The neural network accelerator (NPU) includes a controller, a clock control module, a DDR memory access module, a cache control module, a PE computing array, an input and output cache and other modules. The external interface includes an AXI_Lite register interface and an AXI4_Full data interface. The hardware structure used for encryption authorization mainly includes the key code decryption and authorization module in the controller, as well as the clock control module. The structure diagram is as follows Figure 3 shown.
[0035] The present invention designs dual clock domains to implement encryption authorization operations. The external input clock is clk_in, which is mainly connected to the configuration register module, key code decryption and authorization module, and clock control module of the controller. The module connected to the clock is in a continuous working state and is turned on before and after the neural network accelerator (NPU) is authorized. Figure 3 The clock control module in the clock control module realizes the gating of the output clock clk_g according to the high and low levels of the clock control signal. The clock clk_g is valid only when the authorization is passed, otherwise the gating is closed. Therefore, in the unauthorized state, the clocks of the CNN computing main modules such as the DDR memory access module, cache control module, PE computing array, input and output cache are turned off and are in a low-power, non-working state. The modules using gated clocks are also power-intensive. In the non-intelligent processing task stage or when the unauthorization is successful due to other reasons, the overall power consumption can be significantly reduced, and the possibility of unauthorized state computing by cracking the neural network accelerator (NPU) is eliminated.
[0036] The key code decryption and authorization function is implemented as a sub-function of the controller of the neural network accelerator (NPU). The structure is as follows Figure 4 , Figure 4 The authorization processing structure for the neural network accelerator (NPU) controller.
[0037] After the first level decoding at runtime, the key code is generated and input into the configuration register group of the controller of the neural network accelerator (NPU), and then the key decoding is performed to obtain the input DNA information to be matched. The controller itself can read the DNA code of the FPGA board through the primitive. When the DNA information calculated by the key code matches the real DNA code of the FPGA read by the primitive, the disconnection control module outputs the authorization pass signal. If it does not match, the authorization fails. The authorization result is also fed back to the runtime through the readable register to control the authorization status at runtime.
[0038] The detailed design structure is as follows Figure 5 As shown, Figure 5 It is a multi-platform configurable authorization matching structure. The key code is 128 bits in total. The key code is written in sequence through four 32-bit registers REG1~REG4, corresponding to the 32 bits from low to high in order. The four written register data are spliced to obtain the spliced key code, and the spliced key code is input into the secondary decoding module.
[0039] The DNA code reading of the field programmable gate array (FPGA) needs to adapt to three situations, as shown in a, b and c: a. 57-bit DNA code on Xilinx 7series and earlier FPGAs; b. 96-bit DNA code under ultrascale architecture; c. The encryption authorization function is turned off (for example, for internal testing by the design team).
[0040] Xilinx specifies two primitives, DNA_PORTE and DNA_PORTE2, for 57-bit and 96-bit DNA field programmable gate array (FPGA) devices respectively. According to the timing sequence described in the official document UG570, the DNA code of the current hardware can be read out by shifting. The "0" on the lower right side of the figure means that the encryption authorization function is turned off. The above three situations are selected and adjusted through the macro definition parameters of the code in the field programmable gate array (FPGA).
[0041] The disconnection control module matches the input DNA data with the DNA code directly read by the hardware. If the match is successful, the gated clock clk_g is turned on, otherwise clk_g is kept in the off state. At the same time, the authorization result is fed back to the read-only register REG R, and the authorization status of the software end is determined according to the register value during operation.
[0042] The key code undergoes two transformations inside the secondary decoding module. The first is data mapping. Table 1 is the secondary decoding mapping table, as shown below. For the 96-bit DNA code, the 128-bit key code is mapped to the 100-bit secondary transformation intermediate code through the following table. That is, the 95th bit of the 128-bit is used as the first bit of the 100-bit data, and the 117th bit of the 128-bit is used as the second bit of the 100-bit data, and so on. For 57-bit DNA, the mapping table only uses 60 mapping values in 6 rows to obtain a 60-bit secondary transformation intermediate code.
[0043] Table 1, secondary decoding mapping table:
[0044] After data mapping is completed, bit field selection is performed to remove redundant bits in the intermediate code. For 96-bit DNA, the lower 4 bits of the 100-bit intermediate code are removed to obtain the input DNA code for comparison. For 57-bit DNA, the lower 3 bits of the 60-bit intermediate code need to be removed.
[0045] In summary, the effects of the present invention are as follows: The present invention proposes a method for software-hardware collaborative encryption suitable for a neural network accelerator (NPU). Based on the unique DNA coding of FPGA, a double-layer encryption and double-decryption mechanism is implemented at the runtime end and the neural network accelerator (NPU). The software end implements the AES encryption algorithm, and the hardware end is designed as a safe, efficient, and low-resource-consuming independent secondary decoding, thereby allocating more resources to NPUCNN calculations and achieving an optimal balance between encryption authorization security and hardware resource utilization. The present invention proposes a configurable authorization encryption structure. During operation, the encrypted authorization code is written into the internal register group of the neural network accelerator (NPU) to achieve multi-board adaptation of the hardware netlist and bitstream. After the customer replaces the same model board, only the corresponding encrypted authorization code needs to be provided, avoiding multiple integrations for different DNA boards. The present invention proposes a "disconnect-enable" structure for encryption authorization of a neural network accelerator (NPU), sets up a homologous dual clock domain, and shuts down the clocks of energy-intensive memory access, computing and other modules in the neural network accelerator (NPU) when the system is in an unauthorized state. While ensuring the safety and reliability of the encryption disconnect operation, the power consumption of the hardware is significantly reduced during the period when there is no intelligent acceleration demand.
[0046] The present invention has high reliability and wide adaptability, and has been deployed based on Xilinx ZCU102, XC7VX690T, and XC7K325T platforms. Among them, Xilinx ZCU102 is a high-performance development board launched by Xilinx. The platform combines the dual advantages of processors and FPGAs, and can meet the needs of complex scenarios such as high-performance computing and real-time data processing. XC7VX690T is a high-performance FPGA chip in the Virtex-7 series of Xilinx. It has large-scale logic units and rich and diverse I / O bus interfaces, and can realize complex logic functions and large-scale digital circuit design. XC7K325T is an FPGA chip in the Xilinx Kintex-7 series, which has advantages in performance and power consumption. It integrates peripherals such as ADC, DAC, serial interface, Gigabit Ethernet, PCIE, etc., and can realize high-performance visual image analysis and algorithm processing.
[0047] After being provided to customers, neural network accelerators may be deployed on multiple hardware platforms, resulting in economic value that is difficult to assess, and NPU IP is uncontrolled after output. The present invention can well adapt to the collaborative working mechanism of NPU software and hardware systems, and only requires a single synthesis or provision of a netlist to achieve configurable encryption authorization, and adapt to different FPGA hardware platforms through authorization codes.
[0048] Based on the above method, the present invention also discloses a neural network accelerator authorization system based on software and hardware collaboration, see Figure 7 ,include: DNA code acquisition module: used to acquire the DNA code of the field programmable gate array; Encryption module: used to encrypt the DNA code of the field programmable gate array at two levels to obtain the authorization code; Decoding module: used to decode the authorization code at two levels to obtain the final result data after obtaining the neural network accelerator running instruction; Neural network accelerator authorization module: used to compare the final result data with the DNA code of the field programmable gate array. If the final result data is the same as the DNA code of the field programmable gate array, the neural network accelerator is authorized to start, otherwise the neural network accelerator enters the authorization failure state.
[0049] The various modules of the system of the present invention cooperate with each other to optimize the operating rate of the neural network accelerator. In addition, when the hardware platform is not fixed, there is no need to synthesize the code multiple times, which reduces the risk of the code synthesis process and the workload of modification and testing.
[0050] An electronic device comprises: a processor; a memory for storing computer program instructions; and steps for implementing a neural network accelerator authorization method based on software and hardware collaboration when executing the computer program.
[0051] A storage medium stores computer program instructions. When the computer program instructions are loaded and executed by a processor, the processor executes a neural network accelerator authorization method based on software and hardware collaboration.
[0052] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0053] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0054] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0055] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0056] The above contents are only for explaining the technical idea of the present invention and cannot be used to limit the protection scope of the present invention. Any changes made on the basis of the technical solution in accordance with the technical idea proposed by the present invention shall fall within the protection scope of the present invention.
Claims
1. A neural network accelerator authorization method based on software and hardware collaboration, characterized in that: The following steps are involved: Obtaining DNA code from a field programmable gate array; The DNA code of the field programmable gate array is encrypted at two levels to obtain the authorization code; After obtaining the neural network accelerator running instructions, the authorization code is decoded at two levels to obtain the final result data; Compare the final result data with the DNA code of the field programmable gate array. If the final result data is the same as the DNA code of the field programmable gate array, the neural network accelerator is authorized to start, otherwise the neural network accelerator enters an authorization failure state.
2. The neural network accelerator authorization method based on software and hardware collaboration according to claim 1 is characterized in that: The DNA code of the field programmable gate array is obtained as follows: The DNA code of the field programmable gate array was obtained using Xilinx Vivado tool.
3. The neural network accelerator authorization method based on software and hardware collaboration according to claim 1, characterized in that: The two levels of encryption and the two levels of decoding are inverse processes of each other.
4. The neural network accelerator authorization method based on software and hardware collaboration according to claim 1, characterized in that: After obtaining the neural network accelerator running instruction, the authorization code is decoded at two levels to obtain the final result data, as follows: After obtaining the neural network accelerator running instruction, the authorization code is decrypted at the first level to obtain the key code, and the key code is written into the neural network accelerator through the AXI_Lite interface; The key code is decoded at the second level in the neural network accelerator hardware to obtain the final result data.
5. The neural network accelerator authorization method based on software and hardware collaboration according to claim 4 is characterized in that: The authorization code is decrypted at the first level to obtain the key code, as follows: The AES encryption and decryption algorithm is used to perform a first-level decryption on the authorization code to obtain the key code. An irregular random number is used as the key in the first-level decryption process.
6. The neural network accelerator authorization method based on software and hardware collaboration according to claim 4, characterized in that: The key code is decoded in the neural network accelerator hardware at the second level to obtain the final result data, as follows: The key code is written into four 32-bit registers in sequence to obtain four groups of 32-bit data, the 32-bit data are sorted in order from low to high, and the four groups of 32-bit data are spliced to obtain a spliced key code; By using bit field selection and a preset mapping table, the concatenated key code is converted into a 96-bit or 57-bit value to be compared to obtain the final result data.
7. The neural network accelerator authorization method based on software and hardware collaboration according to claim 1, characterized in that: The following steps are also included: If the final result data is different from the DNA code of the field programmable gate array, the neural network accelerator enters an authorization failure state and shuts down the DDR memory access module, cache control module, PE computing array and input and output cache.
8. A neural network accelerator authorization system based on software and hardware collaboration, characterized in that: include: DNA code acquisition module: used to acquire the DNA code of the field programmable gate array; Encryption module: used to encrypt the DNA code of the field programmable gate array at two levels to obtain the authorization code; Decoding module: used to decode the authorization code at two levels to obtain the final result data after obtaining the neural network accelerator running instruction; Neural network accelerator authorization module: used to compare the final result data with the DNA code of the field programmable gate array. If the final result data is the same as the DNA code of the field programmable gate array, the neural network accelerator is authorized to start, otherwise the neural network accelerator enters the authorization failure state.
9. An electronic device, comprising: A processor; a memory, an electronic device used to store computer program instructions; characterized in that it is used to implement the steps of the neural network accelerator authorization method based on software and hardware collaboration as described in any one of claims 1 to 7 when executing the computer program.
10. A storage medium storing computer program instructions, characterized in that: When the computer program instructions are loaded and executed by the processor, the processor executes the neural network accelerator authorization method based on software and hardware collaboration as described in any one of claims 1-7.