Storage encryption engine system of neural network processor

By integrating the storage encryption engine system in the NPU, optimizing address mapping and encrypted metadata generation, the problems of high and low NPU energy consumption are solved, and energy consumption is reduced and performance improvement is achieved.

CN120297342APending Publication Date: 2025-07-11中电信数字城市科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510301322.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing neural network processor (NPU) storage encryption engines have high energy consumption, poor operating efficiency and performance, which affect equipment battery life and processing speed.

Method used

The storage encryption engine system of the neural network processor is integrated into the NPU, connected to the dynamic random access memory through the controller, stored data using the cache area, and generated different types of encrypted metadata according to the data attributes, optimized address mapping rules, reduced the generation and verification process of encrypted metadata, and compressed the overflow limit of the counter.

Benefits of technology

It reduces energy consumption, improves system performance and operation efficiency, solves the counter overflow problem, and improves the execution efficiency and processing speed of the NPU.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120297342A_ABST
    Figure CN120297342A_ABST
Patent Text Reader

Abstract

The invention provides a storage encryption engine system of a neural network processor, and belongs to the technical field of information security and data protection, and the system comprises a controller which is used for receiving a data access request sent by the neural network processor; wherein the data access request comprises a first target access address and a request type; if the data is not stored at the target memory access address in the first cache region, generating a second target memory access address according to the first target memory access address and a configured address mapping rule; according to the request type and the second target memory access address, generating a data memory access instruction, and sending the data memory access instruction to the dynamic random access memory, so that the dynamic random access memory executes processing corresponding to the data memory access request; and the first cache region is used for plaintext storage of partial data required by the neural network processor. By integrating the storage encryption engine system of the neural network processor into the NPU, the system performance and the operation efficiency can be improved, and the energy consumption can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of information security and data protection. Specifically, it relates to a storage encryption engine system for a neural network processor. Background Art

[0002] As CNN has become a key method for solving complex problems in a wide range of fields, neural network processors (NPUs) are widely used to execute neural network inference tasks. However, data security and privacy protection have become one of the important challenges faced by NPUs. To this end, TEE provides an isolated execution environment to ensure reliable protection of sensitive operations and data. In addition, MEE is a key component of TEE, responsible for encrypting and storing data in memory to ensure the confidentiality, integrity, and timeliness of the data.

[0003] Existing NPU storage encryption engines consume relatively high energy, which not only increases the overall system power consumption but also affects the battery life of the device. In addition, the operating efficiency and performance of NPU storage encryption engines are poor, resulting in slow data encryption and decryption speeds, which in turn affect the overall processing speed and response time of NPUs. Summary of the Invention

[0004] The purpose of the embodiments of this application is to provide a storage encryption engine system for a neural network processor, which is used to solve the problems of high energy consumption, poor operating efficiency and performance of the storage encryption engine of the NPU in the existing technology. Integrating the storage encryption engine system of the neural network processor of this application into the NPU can improve the system performance, operating efficiency, and reduce energy consumption.

[0005] In a first aspect, the present invention provides a storage encryption engine system for a neural network processor. The neural network processor is connected to a dynamic random access memory through the system; the dynamic random access memory is used to encrypt and store the data required when the neural network processor executes data processing tasks; the system includes: a controller and a first buffer; the controller is connected to the first buffer;

[0006] The controller is used to receive a data memory access request sent by the neural network processor; wherein, the data memory access request includes: a first target memory access address and a request type; if there is no data stored at the target memory access address in the first buffer, a second target memory access address is generated according to the first target memory access address and the configured address mapping rule; a data memory access instruction is generated according to the request type and the second target memory access address, and the data memory access instruction is sent to the dynamic random access memory to make the dynamic random access memory execute the processing corresponding to the data memory access request;

[0007] The first buffer is used to store in plaintext some of the data required by the neural network processor when performing data processing tasks.

[0008] In an alternative embodiment, the data access request further includes: a target data attribute; wherein, the target data attribute includes a first attribute and a second attribute; the request types of the data access request include: a data access request and a data storage request; when the request type is a data storage request, the data access request further includes: target stored data; the second target access address includes: a second buffer address and a second storage address.

[0009] In an alternative embodiment, when the request type is a data storage request, the controller is further configured to:

[0010] Match the target type of the encryption metadata corresponding to the target data attribute from a configured comparison table of different target data attributes and different types of encryption metadata;

[0011] Encrypt the target stored data to obtain the ciphertext of the target stored data and the encryption metadata of the corresponding target type;

[0012] Match the target buffer corresponding to the target type from a configured comparison table of different target types and different buffers; store the encryption metadata at the second buffer address of the target buffer;

[0013] Generate a data storage instruction according to the ciphertext and the second storage address, and send the data storage instruction to the dynamic random access memory to instruct the dynamic random access memory to store the ciphertext of the target stored data at the second storage address of the dynamic random access memory.

[0014] In an alternative embodiment, when the request type is a data access request, the controller is specifically configured to:

[0015] Match the target type of the encryption metadata corresponding to the target data attribute from a configured comparison table of different target data attributes and different types of encryption metadata;

[0016] Match the target buffer corresponding to the target type from a configured comparison table of different target types and different buffers; obtain the encryption metadata stored at the second buffer address of the target buffer;

[0017] Generate a data access instruction according to the second storage address, and receive the ciphertext of the target access data returned by the dynamic random access memory in response to the data access instruction;

[0018] If the obtained encrypted metadata passes the verification, decrypt the ciphertext of the target access data and send it to the neural network processor.

[0019] In an alternative embodiment, when the target storage data or target access data is the weight data of a neural network, the corresponding target data attribute is the first attribute;

[0020] When the target storage data or target access data is the non-weight data of a neural network, the corresponding target data attribute is the second attribute;

[0021] When the target data attribute is the first attribute, the types of encrypted metadata corresponding to the target data attribute include: MAC type;

[0022] When the target data attribute is the second attribute, the types of encrypted metadata corresponding to the target data attribute include: MAC type, CTR type, and BMT type.

[0023] In an alternative embodiment, the system further includes: a second buffer, a third buffer, and a fourth buffer; the controller is connected to the second buffer, the third buffer, and the fourth buffer; the second buffer, the third buffer, and the fourth buffer are respectively used to store different types of encrypted metadata.

[0024] In an alternative embodiment, the address mapping rule adopts a non-power-of-two mapping method.

[0025] In a second aspect, the present invention provides a storage encryption control method for a neural network processor, which is applied to a controller of a storage encryption engine system of a neural network processor. The system further includes a first buffer; the method includes:

[0026] Receive a data access request sent by the neural network processor; wherein, the data access request includes: a first target access address and a request type; the neural network processor is connected to a dynamic random access memory through the system;

[0027] If no data is stored at the target access address in the first buffer, generate a second target access address according to the first target access address and the configured address mapping rule;

[0028] Generate a data access instruction according to the request type and the second target access address, and send the data access instruction to the dynamic random access memory to make the dynamic random access memory execute the processing corresponding to the data access request.

[0029] In a third aspect, the present invention provides an electronic device, which includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus;

[0030] The memory is used to store a computer program;

[0031] The processor is configured to implement the method described in the foregoing embodiments when executing the program stored on the memory.

[0032] In a fourth aspect, the present invention provides a computer-readable storage medium, in which a computer program is stored, and the computer program implements the method described in the foregoing embodiments when executed by a processor.

[0033] The system of the present application is provided with a first buffer for storing part of the plaintext, which reduces the generation of encrypted data and effectively reduces the impact of data storage encryption on performance; the present application generates different types of encrypted metadata according to different data attributes of the target data, reduces the generation of encrypted metadata, simplifies the data verification process, and reduces the performance loss caused by the generation of encrypted metadata; the present application compresses the overflow upper limit of the counter, maps more counter values to the same address block, optimizes the locality of the counter memory access address, and alleviates the performance degradation and increased energy consumption caused by storage encryption, thereby improving its execution efficiency and reducing energy consumption while ensuring the secure execution of the NPU.

[0034] After the first buffer is set in the present application, the average running cycle only accounts for about 33% of the benchmark, and the overflow problem of the counter is completely solved; generating different types of encrypted metadata for data with different data attributes and compressing the overflow upper limit of the counter further reduce the memory access data volume by about 3% and 2% respectively on the basis of the optimization of the first buffer, which helps to reduce the memory access energy consumption. Integrating the storage encryption engine system of the neural network processor of the present application into the NPU can improve the system performance, running efficiency and reduce energy consumption. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0036] Figure 1 It is an architecture diagram of a storage encryption engine system of a neural network processor provided by an embodiment of the present application;

[0037] Figure 2Schematic diagram of the interaction between a neural network processor and DRAM provided by an embodiment of the present application;

[0038] Figure 3 Flowchart of the storage encryption control method for a neural network processor provided by an embodiment of the present application;

[0039] Figure 4 Schematic diagram of an address mapping structure provided by an embodiment of the present application;

[0040] Figure 5 Schematic diagram of the address mapping structure of a CTR block provided by an embodiment of the present application;

[0041] Figure 6 Schematic diagram of the address mapping structure of a BMT tree provided by an embodiment of the present application;

[0042] Figure 7 Schematic diagram of an address calculation formula provided by an embodiment of the present application;

[0043] Figure 8 Comparison chart of direct encryption and counter mode (MEE plus cache) provided by an embodiment of the present application;

[0044] Figure 9 Comparison chart of the impact of counter mode (MEE without cache) encryption on performance provided by an embodiment of the present application;

[0045] Figure 10 Comparison chart of the access count distribution of different data during counter mode (MEE without cache) encryption provided by an embodiment of the present application;

[0046] Figure 11 Comparison chart of the overflow situation during counter mode (MEE without cache) encryption provided by an embodiment of the present application;

[0047] Figure 12 Comparison chart of the impact of different MEE cache capacities on performance in counter mode provided by an embodiment of the present application;

[0048] Figure 13 Comparison chart of the hit rates of different MEE cache capacities provided by an embodiment of the present application, schematic diagram of the CTR cache hit rates of different MEE cache capacities provided by an embodiment of the present application, schematic diagram of the MAC cache hit rates of different MEE cache capacities provided by an embodiment of the present application, schematic diagram of the MAC cache hit rates of different MEE cache capacities provided by an embodiment of the present application;

[0049] Figure 14A memory access data proportion graph with different MEE cache capacities provided by an embodiment of the present application;

[0050] Figure 14 Among them, (a) is a memory access proportion graph when the MEE cache is 1KB provided by an embodiment of the present application;

[0051] Figure 14 Among them, (b) is a memory access proportion graph when the MEE cache is 2KB provided by an embodiment of the present application;

[0052] Figure 14 Among them, (c) is a memory access proportion graph when the MEE cache is 4KB provided by an embodiment of the present application;

[0053] Figure 15 A performance comparison graph before and after the optimization of OBRW+CCBN2 provided by an embodiment of the present application;

[0054] Figure 16 A comparison graph of the encrypted metadata memory access volume before and after the optimization of OBRW+CCBN2 provided by an embodiment of the present application;

[0055] Figure 17 A comparison graph of the total memory access data volume before and after the optimization of OBRW+CCBN2 provided by an embodiment of the present application;

[0056] Figure 18 A comparison graph of the memory access energy consumption before and after the optimization of OBRW+CCBN2 provided by an embodiment of the present application;

[0057] Figure 19 A structural schematic diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0058] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0059] NPU (Neural-network Processing Unit, neural network processor): A hardware accelerator specifically designed to execute neural network inference tasks, which is particularly good at processing massive multimedia data such as videos and images, and solves the problem of low efficiency of traditional chips in neural network operations.

[0060] CNN (Convolutional Neural Networks): A deep learning model that is particularly good at processing data with grid structures, such as images. CNN has been very successful in computer vision tasks, such as image classification, object detection, and image segmentation.

[0061] TEE (Trusted Execution Environment): Provides an isolated execution environment to protect sensitive operations and data.

[0062] MEE (Memory Encryption Engine): A key component of the TEE, responsible for encrypting data stored in memory to ensure data confidentiality, integrity, and timeliness.

[0063] The architecture of the memory encryption engine system of the neural network processor provided by the embodiments of this application is as Figure 1 shown; this system is respectively connected to the neural network processor, namely the NPU, and the dynamic random access memory, namely the DRAM; this system includes: a controller, a first buffer, a second buffer, a third buffer, and a fourth buffer; the controller is respectively connected to the first buffer, the second buffer, the third buffer, and the fourth buffer;

[0064] The controller is used to receive the data memory access request sent by the neural network processor; if there is no data stored at the target memory access address in the first buffer, then according to the first target memory access address and the configured address mapping rule, generate a second target memory access address; generate a data memory access instruction according to the request type and the second target memory access address, and send the data memory access instruction to the dynamic random access memory to make the dynamic random access memory execute the processing corresponding to the data memory access request;

[0065] The first buffer, namely the LLC, is used to store in plaintext some of the data required when the neural network processor executes data processing tasks; the second buffer, the third buffer, and the fourth buffer are respectively used to store different types of encrypted metadata.

[0066] In an embodiment of this application, the second buffer is used to store encrypted metadata of the MAC type; the third buffer is used to store encrypted metadata of the CTR type; the fourth buffer is used to store encrypted metadata of the BMT type.

[0067] In the embodiments of this application, the request types of the data memory access request include: data access requests and data storage requests.

[0068] In an embodiment of the present application, when the request type is a data storage request, the data memory access request includes: a first target memory access address, a request type, target stored data, the target data attribute of the target stored data, a target ID, and a target data block size; at this time, the first target memory access address is used to indicate the expected storage address of the target stored data in the DRAM, and the first target memory access address is a virtual address; the target data block size is used to indicate the data volume of the target stored data.

[0069] When the request type is a data access request, the data access request includes: a first target memory access address, a request type, the target data attribute of the target access data, and a target ID; at this time, the first target memory access address is the virtual address of the data row where the target access data is located in the corresponding buffer and the dynamic random access memory.

[0070] Figure 1 In, Access represents access; Output Interface represents output interface; MEEC controller represents controller; LLC is the first buffer; AES engine represents the Advanced Encryption Standard engine; MAC engine represents the message authentication code engine; Check engine represents the verification engine; BMT unit represents the binary Merkle tree unit; Encrypted metadata cache unit represents the encrypted metadata cache unit; Buffer represents buffer; CTR cache represents the counter cache, i.e., the third buffer; BMT cache represents the binary Merkle tree cache, i.e., the fourth buffer; MAC cache represents the message authentication code cache, i.e., the second buffer.

[0071] In an embodiment of the present application, when the neural network processor needs a certain data, it does not simply generate a data memory access request for the data, but calculates the virtual address of the data, i.e., the target access data, and determines the virtual address of the data row where the target access data is located in the corresponding buffer and the dynamic random access memory according to the virtual address of the target access data; uses the virtual address of the data row as the first target memory access address, so that the corresponding buffer and the dynamic random access memory do not simply return a piece of data when returning, but return an entire row of data, that is, the neural network processor adopts a prefetch mechanism, will send a memory access request for one row of the matrix to the system at one time, and store the data row returned by the system in the buffer of the neural network processor, as Figure 2 shown, when needed next time, the neural network processor does not need to send a memory access request to the system again.

[0072] In practical applications, when the buffer of the neural network processor is full and new data needs to be written, the original data is cyclically overwritten sequentially from the starting position because the data at the initial position is basically no longer involved in the operation at this time. Figure 2 In Figure 2 , STONNE represents an open-source simulator.

[0073] In the embodiments of the present application, the target data attribute includes a first attribute and a second attribute; when the target stored data or the target accessed data is the weight data of the neural network, the corresponding target data attribute is the first attribute; when the target stored data or the target accessed data is the non-weight data of the neural network, the corresponding target data attribute is the second attribute.

[0074] In practical applications, the weight data of the neural network are the parameters or connection strengths in the neural network, including weights and biases; the weight data of the neural network are used to determine how the input data is transmitted through the network layer and converted into output; the non-weight data of the neural network covers all data that does not belong to the weight data, including input data, label / target data, activation values, gradient information, and other hyperparameters.

[0075] In the embodiments of the present application, the encrypted metadata is generated when encrypting the plaintext, and the encrypted metadata generated when encrypting the plaintext with different data attributes is different; specifically, different types of encrypted metadata are pre-configured for different target data attributes, and a comparison table of different target data attributes and different types of encrypted metadata is generated; among them, when the target data attribute is the first attribute, the types of encrypted metadata corresponding to the target data attribute include: MAC type; when the target data attribute is the second attribute, the types of encrypted metadata corresponding to the target data attribute include: MAC type, CTR type, and BMT type.

[0076] In the embodiments of the present application, the storage encryption engine system counter cache block of the neural network processor adopts non-power-of-two mapping (CCBN2), which compresses the overflow upper limit of the counter.

[0077] The preferred embodiments of the present application are described below with reference to the accompanying drawings of the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application and are not used to limit the present application, and in the case of no conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0078] Figure 3 It is a schematic flowchart of a storage encryption control method for a neural network processor provided by an embodiment of the present application. As Figure 3 shown, the method may include:

[0079] Step S310: Receive a data memory access request sent by a neural network processor. If there is no data stored at the target memory access address in the first buffer, generate a second target memory access address according to the first target memory access address and the configured address mapping rule.

[0080] Step S320: Generate a data memory access instruction according to the request type and the second target memory access address, and send the data memory access instruction to the dynamic random access memory to make the dynamic random access memory perform the processing corresponding to the data memory access request.

[0081] In the embodiment of the present application, the address mapping rule adopts a non - power - of - two mapping method.

[0082] In the embodiment of the present application, after the system receives a data access request sent by a neural network processor, it will first search whether there is data stored at the first target memory access address in the first buffer. If there is data stored at the first target memory access address in the first buffer, that is, a hit in the first buffer, the data stored at the target memory access address will be sent to the NPU (the data stored in the first buffer is in plaintext, so it can be directly sent to the NPU) for the NPU to execute tasks;

[0083] If the first buffer misses, that is, there is no data stored at the first target memory access address in the first buffer, generate a second target memory access address according to the first target memory access address and the configured address mapping rule; extract the encryption metadata corresponding to the target access data from the corresponding encryption metadata buffer according to the second cache address;

[0084] Generate a data access instruction according to the second storage address, and send the data access instruction to the dynamic random access memory DRAM to make the DRAM extract the ciphertext of the target access data stored at the second storage address of the DRAM and send it to the controller; the controller decrypts the ciphertext of the target access data and sends it to the NPU and receives the ciphertext of the target access data returned by the dynamic random access memory in response to the data access instruction.

[0085] In the embodiment of the present application, the second target memory access address includes: a second cache address and a second storage address; wherein, the second cache address is the physical address of the data row where the encryption metadata corresponding to the target data (target access data or target storage data) is located in the corresponding encryption metadata buffer; the second storage address is the physical address of the data row where the ciphertext of the target data is located in the DRAM.

[0086] In the embodiment of the present application, extracting the encryption metadata corresponding to the target access data from the corresponding encryption metadata buffer according to the second cache address includes:

[0087] Match the target type of the encryption metadata corresponding to the target data attribute from the configured comparison tables of different target data attributes and different types of encryption metadata; match the target buffer area corresponding to the target type from the configured comparison tables of different target types and different buffer areas; obtain the encryption metadata stored at the second buffer address of the target buffer area.

[0088] In the embodiment of the present application, the encryption metadata row contains a key identifier; when the target data (target access data and target storage data) is the weight data of the neural network, its corresponding key identifier is stored in the corresponding MAC class encryption metadata; when the target data (target access data and target storage data) is the non-weight data of the neural network, its corresponding key identifier can be stored in the MAC class encryption metadata, CTR class encryption metadata, and BMT class encryption metadata at the same time, or can be stored in any one type of encryption metadata only. For example, it can be stored only in the MAC class encryption metadata.

[0089] In the embodiment of the present application, the BMT class encryption metadata contains a block ID; the CTR class encryption metadata contains an initial count value and a counter increment rule.

[0090] In an embodiment of the present application, when the target access data is the non-weight data of the neural network, that is, the target data attribute in the data access request received by the controller is the second attribute. At this time, the target types of the encryption metadata corresponding to the second attribute are the MAC class, CTR class, and BMT class; assume that the second buffer area stores the MAC class encryption metadata; the third buffer area stores the CTR class encryption metadata; the fourth buffer area stores the BMT class encryption metadata. Then, according to the first target memory access address and the configured address mapping rule, generate the second buffer address and the second storage address; respectively extract the data at the second buffer address corresponding to the second buffer area, the third buffer area, and the fourth buffer area to obtain the encryption metadata (including MAC encryption metadata, CTR encryption metadata, and BMT encryption metadata); based on the second storage address, generate the target storage address, and extract the ciphertext from the target storage address of the DRAM; verify the ciphertext according to the target data attribute and the obtained encryption metadata. After the verification passes, decrypt the ciphertext to obtain the plaintext; among them, the obtained plaintext contains the plaintext of the target access data; send the obtained plaintext to the neural network processor for the neural network processor to execute the data processing task.

[0091] In the embodiment of the present application, each buffer area contains multiple blocks, and the capacity of each block is the same; the address mapping rule further includes: the block capacity of each buffer area block and the encryption metadata capacity corresponding to any one block; where the encryption metadata capacity corresponding to any one block is used to represent the number of encryption metadata that can be stored in the block.

[0092] In an embodiment of the present application, generating a second storage address according to a first target memory access address and a configured address mapping rule includes:

[0093] For any cache area, based on the configured block capacity corresponding to the cache area and the first target memory access address, determine a first block number; according to the first block number and the encryption metadata capacity corresponding to the cache area, obtain a second block number; where the second block number is the block number within the corresponding cache area; according to the second block number and the block capacity, determine the position of the first block number within the corresponding cache area; calculate an offset according to the block capacity of the cache area; according to the position and the offset, obtain the second storage address corresponding to the cache area; based on the second storage addresses corresponding to different cache areas, obtain the second storage address.

[0094] In an embodiment of the present application, the second storage address corresponding to the BMT cache area can be obtained according to the second storage address corresponding to the CTR cache area, the first target memory access address, and the configured address mapping rule.

[0095] In an embodiment of the present application, verifying the ciphertext according to the target data attribute and the obtained encryption metadata includes:

[0096] Extract a key identifier from the obtained encryption metadata, and match the key corresponding to the key identifier from the configured different key identifiers and different key comparison tables; use the key and the configured encryption algorithm to calculate the MAC data of the obtained ciphertext; if the MAC data of the ciphertext is consistent with the obtained MAC encryption metadata, it indicates that the ciphertext has not been tampered with; extract the block ID in the obtained BMT encryption metadata, and compare the extracted block ID with the target ID in the data access request; if they are consistent, it indicates that the ciphertext is complete and authentic; read the initial count value and the counter increment rule from the obtained CTR data; verify the ciphertext according to the initial count value and the counter increment; if the verification passes, it indicates that the ciphertext has not been damaged.

[0097] In an embodiment of the present application, the order of verifying the ciphertext by the above encryption metadata can be adjusted or can be performed synchronously.

[0098] In an embodiment of the present application, the ciphertext in the DRAM will be split into multiple data blocks of a fixed size, namely ciphertext blocks. The ciphertext blocks are in order and each ciphertext block corresponds to a unique block number; each ciphertext block can be encrypted and decrypted independently; the controller verifies the ciphertext according to the initial count value and the counter increment rule, including:

[0099] Taking the initial count value as a starting point, generate a corresponding counter increment sequence according to the counter increment rule; where each counter increment in the counter increment sequence corresponds to a block number;

[0100] For the initial ciphertext block, i.e., the first ciphertext block, a pseudo-random sequence E is generated according to the initial counter value; the generated pseudo-random sequence E is XORed with the initial ciphertext block to obtain the initial plaintext block; if the initial plaintext block meets the expected format or integrity requirements, then according to the initial counter value, the block number corresponding to the initial ciphertext block, and the counter increment corresponding to the corresponding block number, the counter value of the next ciphertext block is generated; the next ciphertext block is verified based on the counter value, and this is executed sequentially. If all ciphertext blocks can be successfully decrypted and the results are reasonable, then the verification passes; if any ciphertext block cannot be correctly decrypted or the decryption result is abnormal, it may mean data corruption or tampering.

[0101] In another embodiment of the present application, different additional data may also be configured for different key identifiers or keys; when performing MAC verification, the controller calculates the MAC data of the ciphertext, key, and additional data using the MAC algorithm, and obtains the MAC verification result by comparing whether the MAC data is exactly the same as the MAC data extracted from the MAC buffer.

[0102] In an embodiment of the present application, decrypting the ciphertext to obtain the plaintext includes: decrypting the ciphertext using the matched key to obtain the plaintext.

[0103] In another embodiment of the present application, when the target access data is the weight data of a neural network, that is, the target data attribute in the data access request received by the controller is the first attribute, and at this time the target type of the encrypted metadata corresponding to the first attribute is of the MAC type; assuming that the second buffer stores the encrypted metadata of the MAC type; then according to the first target memory access address and the configured address mapping rule, a second buffer address and a second storage address are generated; the data at the second buffer address corresponding to the second buffer is extracted respectively to obtain the MAC encrypted metadata; based on the second storage address, a target storage address is generated, and the data at the target storage address of the DRAM is extracted to obtain the ciphertext; according to the target data attribute and the obtained encrypted metadata, the ciphertext is verified, and after the verification passes, the ciphertext is decrypted to obtain the plaintext; wherein, the obtained plaintext contains the plaintext of the target access data; the obtained plaintext is sent to the neural network processor for the neural network processor to execute the data processing task.

[0104] In other embodiments of the present application, after obtaining the encrypted metadata stored at the second buffer address of the target buffer, the MAC encrypted metadata may also be verified first, and after the verification passes, a data access instruction is generated to obtain the corresponding ciphertext; specifically, the configured MAC data is obtained, and if the configured MAC data is exactly the same as the MAC encrypted metadata in the obtained MAC buffer, then the MAC encrypted metadata passes the verification.

[0105] In an embodiment of the present application, after receiving a data storage request sent by a neural network processor, the controller first searches whether data is stored at a first target memory access address in a first buffer. If data already exists at the first target memory access address in the first buffer, i.e., a hit occurs in the first buffer, the data stored at the first target memory access address in the first buffer is updated to the target storage data; if the first buffer misses, the controller writes the target storage data into the DRAM.

[0106] In an embodiment of the present application, when updating the data at the target storage address in the first buffer to the target storage data, the target storage data can be directly written into the DRAM, or written into the DRAM when the cache line where the target storage data is located is replaced.

[0107] In an embodiment of the present application, when data is written into the DRAM, the controller encrypts the target storage data according to a configured encryption algorithm to obtain the ciphertext of the target storage data; and generates different encryption metadata according to different target data attributes of the target storage data; stores the ciphertext of the target storage data in a corresponding buffer area in the DRAM; stores the encryption metadata of the target storage data in a corresponding second buffer area, third buffer area or fourth buffer area according to the type of the encryption metadata.

[0108] In an embodiment of the present application, when the target storage data is non-weight data of a neural network, i.e., the target data attribute in the data storage request received by the controller is a second attribute, at this time, the target types of the encryption metadata corresponding to the second attribute are MAC type, CTR type and BMT type; assume that the second buffer stores the encryption metadata of the MAC type; the third buffer stores the encryption metadata of the CTR type; the fourth buffer stores the encryption metadata of the BMT type, then according to the first target memory access address and the configured address mapping rule, a second buffer address and a second storage address are generated;

[0109] Encrypt the target storage data to obtain the ciphertext of the target storage data and the corresponding MAC encryption metadata, CTR encryption metadata and BMT encryption metadata; store the MAC encryption metadata, CTR encryption metadata and BMT encryption metadata at the second buffer address in the second buffer area, third buffer area and fourth buffer area respectively; store the ciphertext of the target storage data at the second storage address in the DRAM.

[0110] In another embodiment of the present application, when the target stored data is the weight data of a neural network, that is, the target data attribute in the data storage request received by the controller is the first attribute, at this time, the target type of the encryption metadata corresponding to the first attribute is of the MAC type; assume that the second buffer stores the encryption metadata of the MAC type; then, according to the first target memory access address and the configured address mapping rule, a second buffer address and a second storage address are generated; the target stored data is encrypted to obtain the ciphertext of the target stored data and the corresponding MAC encryption metadata; the MAC encryption metadata is stored at the second buffer address of the second buffer; the ciphertext of the target stored data is stored at the second storage address of the DRAM, and that's it.

[0111] In the embodiments of the present application, the system does not pre-store a large number of keys or encryption algorithms, but obtains the required keys from the key management system (KMS) through the security interface or dynamically obtains the keys from the hardware trust root; in other embodiments of the present application, the controller can also temporarily generate keys for a specific session or task and destroy them after the task is completed; for example, when the NPU executes a specific task, a key corresponding to the task is generated, and for the encryption of all data involved in the task, the key corresponding to the task is used for encryption and decryption.

[0112] In the embodiments of the present application, multiple blocks are set in each buffer; for example, multiple MAC blocks are set in the MAC buffer.

[0113] As Figure 4 shown, taking the block size of all stored data as 64B as an example, the determination of the second target memory access address includes:

[0114] (1) For the second buffer address of the MAC encryption metadata, that is, the MAC data, a data block (i.e., Figure 4 the Regulardata in it) is hashed and compressed into an 8B MAC value, and one MAC block can store 8 MAC values;

[0115] (2) For the second buffer address of the CTR encryption metadata, that is, the CTR data, a data block corresponds to a 7b CTR value, and one CTR block can store 64 CTR values;

[0116] (3) For the second buffer address of the BMT encryption metadata, a CTR block is hashed and compressed into an 8B BMT value, and one BMT block can store 8 BMT values. Since it is a tree structure, starting from the second level, the BMT value of each level is obtained according to the block of the previous level.

[0117] Figure 4In it, BMT data level 1 represents the first level of the binary Merkle tree; BMT data level 2 represents the second level of the binary Merkle tree.

[0118] Such as Figure 5 , each CTR block size is set to 64B. Assume that currently 4G of target data is protected. The main counter (Main) is shared by a 4K DRAM block. Each DRAM block contains 64 data blocks, that is, each DRAM block corresponds to 64 minor counters. Each minor counter has a bit width of 7b, and a total of 64 minor counters are required. Each minor counter records the number of write operations for the same data block. Whenever there is a write operation request for the DRAM, the minor counter will perform a "+1" operation. 7b means the increment upper limit of the minor counter is 2 to the power of 7. After exceeding the increment upper limit, an overflow will occur, and the system needs to consume additional operating cycles to handle the overflow. The ratio of the storage space occupied by the target data and the CTR encryption metadata is 64, so the CTR needs to occupy 64MB (= 4G / 64) of storage space.

[0119] Figure 5 In it, DRAM_general data represents the general data in the DRAM; Chunk_0_4K represents Area 0_4 kilobytes; Counter cache line represents the counter cache line; Major counter represents the main counter; Minorcounter represents the minor counter; Shared within a 4kb memory chunk means shared within a 4-kilobyte memory chunk; Covering 64lines of… means covering 64 lines of general data; The ratio between general means the ratio of general data and counter data is 64, and all counter data occupies an external storage space of 64 megabytes.

[0120] Such as Figure 6 , the CTR encryption metadata, that is, CTRdata, occupies 64MB of storage space, and the BMT encryption metadata needs to occupy 9.2MB of memory space. The BMT nodes at level L1 (i.e., the first level) are obtained by hashing and compressing the CTR block data according to 8:1; starting from level L2, the BMT nodes in subsequent levels are all obtained by hashing and compressing the BMT nodes in the previous level according to 8:1, and finally a 6-level 8-way hash tree can be constructed; Figure 6 In it, Root represents the root node.

[0121] The hashing algorithm of MAC is consistent with that of BMT, and also uses a compression ratio of 8:1. MAC needs to cover all 4GB of regular data, so MAC occupies 512MB (=4GB / 8) of storage space.

[0122] The specific address mapping calculation formula is as Figure 7 shown in Table 1:

[0123] Table 1 Encryption Metadata Address Mapping Calculation Formula

[0124]

[0125] Among them, addr mac represents the second storage address corresponding to the MAC buffer, addr req represents the first target memory access address in the data memory access request. Shift it to the right by 6 (=log2 64) bits to obtain the first block number bn, then shift it to the right by 3 (=log2 8) bits to calculate the bn of MAC (i.e., the second block number), shift it to the left by 6 bits to restore the position of the first block number bn in the MAC buffer, and similarly calculate the offset and then splice to obtain the second storage address corresponding to the MAC buffer.

[0126] addr ctr represents the second storage address corresponding to the CTR buffer, addr req represents the first target memory access address. Shift it to the right by 6 bits to obtain bn, then shift it to the right by 6 (=log2 64) bits to calculate the bn of the CTR buffer, shift it to the left by 6 bits to restore the position of bn in the CTR buffer, and similarly calculate the offset and then splice to obtain the second storage address corresponding to the CTR buffer.

[0127] addr bmt[1] represents the memory access address of the first-level BMT, addr ctr represents the second storage address corresponding to the CTR buffer. Shift it to the right by 6 bits to obtain bn, then shift it to the right by 3 (=log2 8) bits to calculate the bn of BMT, shift it to the left by 6 bits to restore the position of bn in the CTR buffer, and similarly calculate the offset and then splice to obtain the second storage address corresponding to the BMT buffer, addr bmt[i] represents the memory access address of the i-th level of BMT.

[0128] Figure 7Among them, Request address represents the request address, that is, the first target memory access address in the data memory access request; CTR address represents the counter data address, that is, the second storage address corresponding to the CTR buffer; MAC address represents the message authentication code data address, that is, the second storage address corresponding to the MAC buffer; BMT address represents the binary Merkle tree data address, that is, the memory access address of BMT; Level 1 represents the first layer; Block num represents the block number; Bn_off represents the block offset; Offset represents the offset.

[0129] The technical effects of the present application are further verified through specific experiments below.

[0130] In the present application, by setting a first buffer in the system, the amount of memory access for regular data is reduced, effectively reducing the generation of encrypted data, hereinafter referred to as LLC optimization; during the inference process of the neural network, the weight data has a read-only property. Therefore, for this part of the weight data, there is no need to generate encrypted data of the counter (CTR) type. Furthermore, the integrity verification of this part of the counter is not necessary either. Therefore, the present application generates different types of encrypted metadata for target data with different data attributes, hereinafter referred to as OBRW optimization, that is, memory access optimization based on the read-only property of weight data; the present application also compresses the overflow upper limit of the counter and adopts a non-power-of-two mapping of the counter cache block to map more counter values to the same address block, thereby optimizing the locality of the counter memory access address, hereinafter referred to as CCBN2 optimization.

[0131] Such as Figure 8 When the MEE cache capacity is set to 2KB, direct encryption and CTR mode encryption are compared. In direct encryption, MT needs to cover all regular data (4GB), so an 8-level octal hash tree needs to be constructed. Due to the relatively large depth of the hash tree, direct encryption usually has more serious performance losses compared to counter mode encryption. This also confirms that considering both system security and actual performance, counter mode encryption is the preferred solution. Figure 8 Among them, A_M represents AlexNet_MAERI; AlexNet is the abbreviation of the network model, and MAERI is the abbreviation of the neural network processor architecture; the network models include AlexNet, LeNet, ResNet, MobileNet, and Yolo4-tiny; the architectures include MAERI, SIGMA, and TPU; Baseline represents the baseline / control group.

[0132] Figure 9This is the performance comparison before and after encryption in counter mode without adding a small cache. It can be seen that encryption will have a serious performance impact on the system, because in addition to regular data, encrypted metadata such as CTR, BMT, and MAC also need to be accessed, and the system cannot withstand a significant increase in memory access. Under different combination configurations, without the support of MEE cache, there is an average additional performance loss of about 2268%.

[0133] At this time, the different data access proportions counted from the DRAM access port are as follows: Figure 10 As shown. Figure 4 The address mapping structure clearly shows that the memory access amount of the target data regular data and the two encryption metadata CTR and MAC is in a 1:1 relationship, that is, in the case of encryption, in order to ensure data security, each regular data memory access requires a corresponding CTR and MAC memory access demand; because BMT is a 6-level 8-way hash tree, the access to a bottom-level BMT node involves the memory access of all BMT data on the entire path of the 6 levels where the node is located, so the memory access amount of BMT data is the largest. The large increase in encrypted data memory access eventually caused serious performance degradation.

[0134] The distribution of CTR overflow value at this time is as follows Figure 11 As shown, when CTR is greater than 127, an overflow will occur, and the system needs to consume extra time to handle the overflow. At this time, a large number of overflows occur. Since the system platform does not model overflow processing, this application needs to try to optimize the system structure to avoid overflows.

[0135] In view of the fact that memory access encryption generates a large amount of encryption metadata, this application adds a cache module to MEE in the experiment. The three types of encryption metadata, CTR, BMT, and MAC, have corresponding CTR cache, BMT cache, and MAC cache.

[0136] like Figure 12 (The legend indicates cache capacity) Performance comparison after adding small cache to MEE Figure 9The performance loss has been qualitatively improved. By comparing the average performance of different cache capacities (1KB, 2KB, 4KB), it is found that when the MEE cache capacity is 1KB, the system performance is the lowest; after increasing the MEE cache to 2KB, the system has a performance improvement of about 12.5%; as the cache capacity continues to increase, the performance improvement effect is about 20%. At this time, the cache hit rate is already at a relatively high level, and the capacity of the MEE cache is sufficient to meet the system requirements. Considering both performance and hardware, this application selects a MEE cache capacity of 2KB as the basic specification for this experiment.

[0137] As Figure 13 , from the perspective of cache hit rate, the MAC cache performs the most significantly. When the MEE cache is only 1KB, the average hit rate of the MAC cache is about 92%. After increasing the MEE cache capacity to 4KB, the CTR cache hit rate is as high as over 97%; the low hit rate of the BMT cache is related to its address mapping method because the BMT values of each layer are not in the same data block. Figure 13 In , LLC_0KB_MEE_1KB indicates that the last-level cache capacity is 0KB and the storage encryption engine cache capacity is 1KB.

[0138] The memory access ratio at this time is as Figure 14 . It can be seen that a large amount of encrypted metadata is filtered and optimized by the cache, and the directly accessed encrypted metadata is significantly reduced. Moreover, as the MEE cache capacity increases, the amount of encrypted metadata accessed decreases significantly (such as R_S).

[0139] As Figure 15 , it is a comparison of various optimization schemes. Based on the first cache area LLC and continuing to optimize, there is no significant performance change in terms of memory access cycles, but the actual specific memory access ratio distribution is as Figure 16 ; Figure 16 In , CCBN2 represents the non-power-of-two mapping of the counter cache block; OBRW represents the memory access optimization based on the read-only characteristic of weighted data; LLC represents when only LLC is optimized; LLC_CCBN2 represents when LLC and CCBN2 are optimized; MEEC represents when LLC, CCBN2, and OBRW are optimized; it can be seen that in the case of LLC, the combined optimization strategy of OBRW + CCBN2 can reduce more memory access amounts. The memory access comparison of all data is as Figure 17 .

[0140] As Figure 18 , although the reduction of the memory access amount cannot effectively reduce the memory access cycle, at this time, the memory access amount is reduced more, and the optimization effect of the memory access energy consumption of DRAM is more obvious.

[0141] The present application also provides an electronic device, such as Figure 19 , including a processor 1910 , a communication interface 1920 , a memory 1930 and a communication bus 1940 , wherein the processor 1910 , the communication interface 1920 , and the memory 1930 communicate with each other through the communication bus 1940 .

[0142] The memory 1930 is used to store computer programs. The processor 1910 is used to implement the following steps when executing the program stored in the memory 1930:

[0143] Receive a data access request sent by a neural network processor; wherein the data access request includes: a first target access address and a request type; the neural network processor is connected to a dynamic random access memory through a system; if no data is stored at the target access address in the first cache area, a second target access address is generated according to the first target access address and a configured address mapping rule; a data access instruction is generated according to the request type and the second target access address, and the data access instruction is sent to the dynamic random access memory, so that the dynamic random access memory executes processing corresponding to the data access request.

[0144] The communication bus mentioned above can be a peripheral component interconnect standard (PCI) bus or an extended industrial standard architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus. The communication interface is used for communication between the above-mentioned electronic device and other devices. The memory can include a random access memory (RAM) and can also include a non-volatile memory (NVM), such as at least one disk storage. Optionally, the memory can also be at least one storage device located away from the aforementioned processor.

[0145] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The implementation methods and beneficial effects of the various components of the electronic device in the above-mentioned embodiments to solve the problems can be found in Figure 3 Therefore, the specific working process and beneficial effects of the electronic device provided by the embodiment of the present application will not be repeated here.

[0146] In another embodiment provided by the present application, there is also provided a computer-readable storage medium storing instructions, which when run on a computer, cause the computer to execute the storage encryption control method of the neural network processor in any one of the above embodiments.

[0147] In another embodiment provided by the present application, there is also provided a computer program product containing instructions, which when run on a computer, cause the computer to execute the storage encryption control method of the neural network processor in any one of the above embodiments.

[0148] Those skilled in the art should understand that the embodiments in the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the embodiments in the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments in the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0149] The embodiments in the present application are described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products in the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0150] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the specified functions in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0151] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide for implementing the specified functions in the process Figure 1Steps of one or more processes and / or boxes Figure 1 Steps of the functions specified in one or more boxes.

[0152] Although the preferred embodiments in the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the embodiments of the present application.

[0153] Obviously, those skilled in the art can make various changes and modifications to the embodiments in the embodiments of the present application without departing from the spirit and scope of the embodiments in the embodiments of the present application. Thus, if these modifications and variations of the embodiments in the embodiments of the present application fall within the scope of the claims of the embodiments of the present application and their equivalent technologies, the embodiments in the present application are also intended to include these changes and modifications.

Claims

1. A storage encryption engine system for a neural network processor, characterized in that, The neural network processor is connected to the dynamic random access memory through the system; The dynamic random access memory is used to encrypt and store the data required when the neural network processor executes data processing tasks; The system includes: a controller and a first buffer; The controller is connected to the first buffer; The controller is configured to receive a data access request sent by the neural network processor; Wherein, the data access request includes: a first target access address and a request type; If no data is stored at the target access address in the first buffer, a second target access address is generated according to the first target access address and the configured address mapping rule; A data access instruction is generated according to the request type and the second target access address, and the data access instruction is sent to the dynamic random access memory to cause the dynamic random access memory to execute the processing corresponding to the data access request; The first buffer is used to store in plaintext part of the data required when the neural network processor executes data processing tasks.

2. The system according to claim 1, wherein The data access request further includes: a target data attribute; Wherein, the target data attribute includes a first attribute and a second attribute; The request types of the data access request include: a data access request and a data storage request; When the request type is a data storage request, the data access request further includes: target stored data; The second target access address includes: a second cache address and a second storage address.

3. The system according to claim 2, wherein When the request type is a data storage request, the controller is further configured to: Match the target type of the encryption metadata corresponding to the target data attribute from the configured comparison table of different target data attributes and different types of encryption metadata; Encrypt the target stored data to obtain the ciphertext of the target stored data and the encryption metadata of the corresponding target type; Match the target buffer corresponding to the target type from the configured comparison table of different target types and different buffers; Store the encryption metadata at the second cache address of the target buffer; Generate a data storage instruction according to the ciphertext and the second storage address, and send the data storage instruction to the dynamic random access memory to cause the dynamic random access memory to store the ciphertext of the target stored data at the second storage address of the dynamic random access memory.

4. The system according to claim 3, wherein, When the request type is a data access request, the controller is specifically configured to: Match the target type of the encryption metadata corresponding to the target data attribute from the configured comparison table of different target data attributes and different types of encryption metadata; Match the target buffer corresponding to the target type from the configured comparison table of different target types and different buffers; Obtain the encryption metadata stored at the second cache address of the target buffer; Generate a data access instruction according to the second storage address, and receive the ciphertext of the target access data returned by the dynamic random access memory in response to the data access instruction; If the obtained encryption metadata passes the verification, the ciphertext of the target access data is decrypted and then sent to the neural network processor.

5. The system according to claim 4, wherein When the target stored data or target accessed data is the weight data of a neural network, the corresponding target data attribute is the first attribute; When the target stored data or target accessed data is the non-weight data of a neural network, the corresponding target data attribute is the second attribute; When the target data attribute is the first attribute, the types of encryption metadata corresponding to the target data attribute include: MAC type; When the target data attribute is the second attribute, the types of encryption metadata corresponding to the target data attribute include: MAC type, CTR type, and BMT type.

6. The system according to claim 5, characterized in that, The system further includes: a second buffer, a third buffer, and a fourth buffer; the controller is connected to the second buffer, the third buffer, and the fourth buffer; The second buffer, the third buffer, and the fourth buffer are respectively used to store different types of encryption metadata.

7. The system according to claim 1, wherein The address mapping rule adopts a non-power-of-two mapping method.

8. A storage encryption control method for a neural network processor, characterized in that, Applied to the controller of the storage encryption engine system of a neural network processor, the system further includes a first buffer; the method includes: Receiving a data access request sent by a neural network processor; wherein, the data access request includes: a first target access address and a request type; the neural network processor is connected to a dynamic random access memory through the system; If no data is stored at the target access address in the first buffer, a second target access address is generated according to the first target access address and the configured address mapping rule; A data access instruction is generated according to the request type and the second target access address, and the data access instruction is sent to the dynamic random access memory to make the dynamic random access memory execute the processing corresponding to the data access request.

9. An electronic device, characterized in that, The electronic device includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory complete communication with each other through the communication bus; The memory is used to store a computer program; The processor, when executing the program stored on the memory, implements the method according to claim 8.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the method according to claim 8 is implemented.