Memory access method, CXL controller, computing device and CXL memory device
The CXL controller performs signature verification on the subject of the access request, which solves the problem of CXL memory data leakage and achieves higher security and compatibility.
Patent Information
- Application Number
- CN202510114158.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-07-25
AI Technical Summary
When CXL memory is accessed by an unsafe process or computing device, it is easy to cause data leakage, and the prior art is difficult to effectively prevent this situation.
The CXL controller performs signature verification on the subject that generates the access request. Only the subject that passes the verification can access CXL memory. The pairing mechanism of public and private keys is used to ensure security, and the CXL PCIE physical layer and memory controller can achieve rapid verification.
Effectively avoid unsafe subjects accessing CXL memory, improve data access security, reduce deployment difficulty and improve compatibility.
Smart Images

Figure CN120371737A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computing devices, and in particular, to a memory access method, a CXL controller, a computing device, and a CXL memory device. Background Art
[0002] Compute Express Link (CXL) memory can be connected to a computing device to provide additional memory space for the computing device. CXL memory can enable memory sharing among multiple processes running on the same computing device, and can also enable memory sharing among multiple computing devices.
[0003] When any process of a certain computing device writes data into the CXL memory, other processes of the same computing device or other computing devices can also read the data from the CXL memory. Thus, when the CXL memory is accessed by an insecure process or computing device, data in the CXL memory may be leaked. Summary of the Invention
[0004] Embodiments of this application provide a memory access method, a CXL controller, a computing device, and a CXL memory device, which can effectively prevent data in the CXL memory from being leaked.
[0005] To achieve the above object, the embodiments of this application adopt the following technical solutions:
[0006] In a first aspect, a memory access method is provided, which is applied to a CXL controller. The CXL controller is connected to a computing device, and processes and applications are running in the computing device. The method includes: in response to an access request, obtaining a first signature corresponding to the entity that generates the access request, and verifying the first signature. When the first signature passes the verification, accessing the CXL memory.
[0007] Wherein, the entity that generates the access request includes at least one of the above-mentioned computing device, process, or application.
[0008] It can be seen from the above technical solutions that only the entities (processes, applications, or computing devices) that pass the verification can access the CXL memory. In this way, the phenomenon that an insecure entity accesses the CXL memory can be effectively avoided. Furthermore, the security of CXL memory access can be effectively improved, and data in the CXL memory can be effectively prevented from being leaked.
[0009] In addition, a CXL controller can be connected to multiple computing devices simultaneously. By improving a CXL controller, even if the CXL controller has verification capabilities to verify the entity that generates the access request, it is possible to avoid multiple computing devices (or processes or applications running in multiple computing devices) from directly obtaining plaintext data from the CXL memory at the same time. In this way, the deployment difficulty of this solution can be reduced, and the compatibility and feasibility of this solution can be improved.
[0010] In an alternative embodiment, the verification of the first signature may specifically include: obtaining a verification code and verifying the first signature based on the verification code.
[0011] In this embodiment, the specific process of verifying the first signature is described. In this way, the feasibility of this application can be effectively improved.
[0012] In an alternative embodiment, the access request carries the first signature.
[0013] In this embodiment, it is described that the access request can carry the first signature. In this way, the CXL controller can directly parse the access request to obtain the first signature, which can improve the processing efficiency of the CXL controller.
[0014] In an alternative embodiment, the CXL controller stores the above verification code.
[0015] In this embodiment, it is described that the CXL controller can store the verification code. The CXL controller can obtain the verification code from itself to improve the processing efficiency of the CXL controller.
[0016] In an alternative embodiment, the CXL controller may store a first correspondence relationship, which is used to indicate at least one of: the verification code corresponding to a process allowed to access the CXL memory, the verification code corresponding to an application allowed to access the CXL memory, or the verification code corresponding to a computing device allowed to access the CXL memory. Correspondingly, the above obtaining of the verification code may specifically include: determining the verification code from the first correspondence relationship.
[0017] In this embodiment, it is described that the CXL controller can store different verification codes, such as the verification code corresponding to an entity (process, application, or computing device) allowed to access the CXL memory. In this way, the CXL controller can quickly obtain the verification code from the first correspondence relationship stored in itself to improve the processing efficiency of the CXL controller.
[0018] In an alternative embodiment, the first correspondence is stored in the CXL physical device (PHY) of the CXL controller. The obtaining of the verification code may specifically include: obtaining the first correspondence from the CXL PCIE physical layer and determining the verification code based on the first correspondence. Correspondingly, the verification of the first signature based on the verification code may specifically include: verifying the first signature based on the verification code through the CXL PCIE physical layer.
[0019] In this embodiment, the first correspondence can be stored in the CXL PCIE physical layer of the CXL controller, and the verification operation of the first signature can be implemented through the CXL PCIE physical layer. Among the multiple components included in the CXL controller (such as CXL physical device (PHY), memory controller, etc.), the CXL PCIE physical layer can receive the access request sent by the computing device earlier and verify the entity that generates the access request. In this way, the verification rate of the entity that generates the access request can be improved.
[0020] In addition, by verifying the first signature through the CXL PCIE physical layer, after the verification fails, a response message indicating verification failure (or error) can be promptly returned to the computing device, which can not only increase the response speed of the CXL controller but also reduce the signaling consumption among the various components inside the CXL controller.
[0021] In an alternative embodiment, the first correspondence may be stored in the memory controller of the CXL controller. The obtaining of the verification code may specifically include: obtaining the first correspondence from the memory controller and determining the verification code based on the first correspondence. In addition, the verification of the first signature based on the verification code may specifically include: sending the verification code to the CXL PCIE physical layer of the CXL controller and verifying the first signature based on the verification code through the CXL PCIE physical layer.
[0022] In this embodiment, it is described that the verification code in the memory controller of the CXL controller can be sent to the CXL PCIE physical layer. Subsequently, the first signature can be verified based on the verification code through the CXL PCIE physical layer. Among the multiple components included in the CXL controller, the CXL PCIE physical layer can receive the access request sent by the computing device earlier and verify the entity that generates the access request. In this way, the verification rate of the entity that generates the access request can be improved.
[0023] In an alternative embodiment, the CXL controller can periodically obtain the first correspondence from the computing device.
[0024] In this embodiment, it is described that the CXL controller can update the first correspondence stored in itself based on the first correspondence stored in the computing device, which can avoid the leakage of the check code, further improve the security of CXL memory access, and prevent the data in the CXL memory from being leaked.
[0025] In an alternative embodiment, the above-mentioned verification of the first signature based on the check code may specifically include: determining that the first signature passes the verification when the check code and the first signature match successfully.
[0026] In this embodiment, the process of verifying the first signature based on the check code is described. The CXL controller can match the check code and the first signature when obtaining the check code and the first signature to determine whether the first signature passes the verification. In this way, the verification efficiency of the CXL controller can be improved.
[0027] In an alternative embodiment, the access request can be used to indicate reading the first data. Accordingly, the above-mentioned accessing the CXL memory may specifically include: obtaining the first data from the CXL memory; or, the access request can be used to indicate writing the second data. Accordingly, the above-mentioned accessing the CXL memory may specifically include: writing the second data into the CXL memory.
[0028] In this embodiment, the manner in which the CXL controller responds to the access request is described, which may include two response methods: obtaining data from the CXL memory and writing data into the CXL memory. In this way, the compatibility of the present application can be enhanced.
[0029] In an alternative embodiment, the first signature is a private key and the check code is a public key.
[0030] In this embodiment, the first signature and the check code are described. The first signature and the check code can be a paired public key and private key. The private key has uniqueness and confidentiality, which can ensure that the first signature of the secure entity (process, application, or computing device) will not be leaked, and further improve the security of CXL memory access.
[0031] In an alternative embodiment, the CXL controller is connected to the first computing device and the second computing device; the entity generating the access request is the target process, and the target process runs in the first computing device or the target process runs in the second computing device. Or, the entity generating the access request is the target application, and the target application runs in the first computing device or the target application runs in the second computing device.
[0032] In this embodiment, the entity that generates the access request is described. The entity can be a process or application running in the first computing device, or a process or application running in the second computing device. In this way, the compatible scenarios of this application can be expanded.
[0033] In an alternative embodiment, the above access request may include a flag bit, and the flag bit is used to indicate the verification result of the verification of the first signature.
[0034] In a second aspect, a memory access device is provided. The device includes: functional units for performing any one of the methods provided in the first aspect, and the actions performed by each functional unit are implemented by hardware or by hardware executing corresponding software. For example, the memory access device may include: an acquisition unit, a verification unit, and an access unit. Among them, the acquisition unit is used to obtain the first signature corresponding to the entity that generates the access request in response to an access request for the CXL memory. The verification unit is used to verify the first signature. The access unit is used to respond to the access request when the first signature passes the verification.
[0035] In a third aspect, a CXL controller is provided, including a processor. The processor is coupled to a memory, and the memory is used to store programs or instructions. When the programs or instructions are executed by the processor, the CXL controller is caused to execute any one of the methods provided in the first aspect.
[0036] In a fourth aspect, a chip is provided. The chip includes: a processor and an interface circuit; the interface circuit is used to receive code instructions and transmit them to the processor; the processor is used to run the code instructions to execute any one of the methods provided in the first aspect above.
[0037] In a fifth aspect, a computer-readable storage medium is provided, storing computer-executable instructions. When the computer-executable instructions run on a computer, the computer is caused to execute any one of the methods provided in the first aspect above.
[0038] In a sixth aspect, a computer program product is provided, including computer-executable instructions. When the computer-executable instructions run on a computer, the computer is caused to execute any one of the methods provided in the first aspect above.
[0039] In a seventh aspect, a computing device is provided, including a CXL controller, a CXL memory, and a processor. The CXL controller, the CXL memory, and the processor are coupled. The CXL controller is used to execute any one of the methods provided in the first aspect.
[0040] In an eighth aspect, a CXL memory device is provided, including a CXL controller and a CXL memory. The CXL controller and the CXL memory are coupled. The CXL controller is used to execute any one of the methods provided in the first aspect.
[0041] Among them, for the technical effects brought by any one of the second to eighth aspects, reference may be made to the technical effects brought by different implementation manners in the first aspect, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 It is a schematic diagram of CXL memory shared between server CXL244 and server CXL248;
[0043] Figure 2 It is a schematic diagram of the architecture of a computing cluster provided by an embodiment of the present application;
[0044] Figure 3 It is another schematic diagram of the architecture of a computing cluster provided by an embodiment of the present application;
[0045] Figure 4 It is another schematic diagram of the architecture of a computing cluster provided by an embodiment of the present application;
[0046] Figure 5 It is a schematic diagram of the process of a memory access method provided by an embodiment of the present application;
[0047] Figure 6 It is a schematic diagram of a CXL PCIE physical layer and a memory controller provided by an embodiment of the present application;
[0048] Figure 7 It is another schematic diagram of a CXL PCIE physical layer and a memory controller provided by an embodiment of the present application;
[0049] Figure 8 It is another schematic diagram of the architecture of a computing cluster provided by an embodiment of the present application;
[0050] Figure 9 It is a schematic diagram of the structure of a memory access device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] Next, the technical solutions in the embodiments of the present application will be described with reference to the drawings in the embodiments of the present application.
[0052] Among them, in the description of the present application, unless otherwise specified, " / " means that the objects associated before and after are in an "or" relationship. For example, A / B may represent A or B; "and / or" in the present application is only a description of the association relationship of the associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. Among them, A and B may be singular or plural.
[0053] Also, in the description of the present application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of a single item or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or plural.
[0054] In addition, for the convenience of clearly describing the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and terms such as "first" and "second" do not necessarily mean different. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner for easy understanding.
[0055] Hereinafter, the terms related to the embodiments of the present application will be introduced.
[0056] CXL: It is a high-speed interconnection technology standard designed specifically for high-performance data center computers, which can perform fast and reliable data transmission between different components inside a computing device, such as: various components including a central processing unit (CPU), an accelerator, a memory, a smart network interface card (Smart NIC), etc. CXL is built on the physical and electrical interfaces of the peripheral component interconnect express (PCIe). The CXL protocol can include an input / output protocol (CXL.io), a cache access protocol (CXL.cache), and a memory access protocol (CXL.mem).
[0057] Direct Access (DAX) Device: DAX technology is a technology that enables an application (hereinafter simply referred to as an app) to directly access a persistent memory device without reading and writing to the persistent memory device through the block input / output (I / O) operations of the file system, thereby effectively reducing the latency of data access. When accessing CXL memory based on DAX technology, the CXL memory can be created as a DAX device (or referred to as a CXL-DAX device).
[0058] The following introduces the application scenarios of the embodiments of this application.
[0059] With the rapid development of technologies such as big data, artificial intelligence, and cloud computing, traditional interconnection technologies have become difficult to meet the growing data transmission and data processing requirements. Compared with traditional interconnection technologies, CXL can provide higher bandwidth, lower latency, and stronger expansion capabilities, thereby meeting the efficient interconnection between components such as processors (e.g., CPUs), memories, and accelerators. In future data centers, high-performance computing, and edge computing and other fields, CXL will become one of the key technologies for achieving high-performance and low-latency data processing.
[0060] CXL memory refers to a memory device connected to a computing device through the CXL protocol. When accessing CXL memory based on DAX technology, the CXL memory can be created as a DAX device. The DAX device can include two application modes, one is the system memory mode at the operating system (OS) control level, and the other is the direct access device (device DAX) mode at the application control level.
[0061] In the system memory mode at the operating system control level, the CXL memory can be used as an extension of the system memory and is controlled and managed by the operating system, that is: the control right of the CXL memory is concentrated at the operating system end. In this mode, the operating system can uniformly schedule the resource allocation of the CXL memory. For example: the operating system decides how much memory space to allocate to each process (or service) in the CXL memory, etc. Thus, flexible allocation of the CXL memory cannot be achieved.
[0062] In the direct access device mode at the application control level, an app is allowed to access the data stored in the CXL memory without operating through the operating system. The following will describe the process of an app accessing the CXL memory in the direct access device mode at the application control level.
[0063] CXL memory can enable memory sharing among multiple processes running on the same computing device, and can also enable memory sharing among multiple computing devices. Exemplarily, Figure 1 is a schematic diagram of CXL memory sharing between server CXL244 and server CXL248. As Figure 1 shown, process A and process B are running on server CXL244, and process C is running on server CXL248. In this way, CXL memory can be shared among process A, process B, and process C. On this basis, assume that process A is the writeCXLMemPattern process, and process A is used to store natural numbers in the CXL memory based on the CXL.mem protocol. After process A writes natural numbers in the CXL memory, both process B running in server CXL244 and process C running in server CXL248 can obtain the natural numbers stored by process A in the CXL memory from the CXL memory.
[0064] In this scenario, the embodiments of the present application provide a memory access method applied to a CXL controller. The CXL controller is connected to a computing device, and processes and applications are running in the computing device. The CXL controller can respond to an access request for the CXL memory, obtain a first signature corresponding to the entity that generates the access request, and verify the first signature. In the case where the first signature verification passes, access the CXL memory. Among them, the entity that generates the access request includes at least one of a computing device connected to the CXL controller, a process or an application running in the computing device.
[0065] It can be seen from the above technical solution that only the entities (processes, applications, or computing devices) that pass the verification can access the CXL memory. In this way, the phenomenon that an insecure entity accesses the CXL memory can be effectively avoided. Furthermore, the security of CXL memory access can be effectively improved, and the data in the CXL memory can be effectively prevented from being leaked.
[0066] In addition, a CXL controller can be connected to multiple computing devices at the same time. By improving a CXL controller, even if the CXL controller has the verification ability to verify the entity that generates the access request, it can avoid multiple computing devices (or processes or applications running in multiple computing devices) directly obtaining plaintext data from the CXL memory at the same time. In this way, the deployment difficulty of this solution can be reduced, and the compatibility and feasibility of this solution can be improved.
[0067] Next, an exemplary introduction to the system architecture of the embodiments of the present application will be given.
[0068] Figure 2 is a schematic diagram of the architecture of a computing cluster provided by the embodiments of the present application. As Figure 2As shown, the computing cluster includes at least one computing device (which can also be referred to as a host) 100 and a CXL memory device 200. Exemplarily, Figure 2 Three computing devices are shown, namely the first computing device 101, the second computing device 102, and the third computing device 103.
[0069] The CXL memory device 200 communicates with the computing device 100 based on the CXL protocol.
[0070] The CXL memory device 200 may include a CXL controller 201 and a CXL memory 202 connected to the CXL controller.
[0071] It should be noted that the CXL controller 201, also known as the CXL chip, can connect the CXL memory 202 to at least one computing device 100 based on CXL technology to increase the memory capacity of the computing device 100.
[0072] The CXL memory 202 can be a storage particle (such as a dynamic random access memory (DRAM) flash particle), or a memory module (such as a dual in-line memory module (DIMM) memory module), or other types of memory. The embodiments of the present application do not limit this.
[0073] The computing device 100 may include a processor and a memory.
[0074] The processor can be a CPU or other components with processing capabilities. Among them, the CPU, as the operation and control core of the computing device, is the final execution unit for information processing and program operation. The CPU is a very large-scale integrated circuit composed of an arithmetic unit, a controller, registers, etc., and its main task is to process and handle various data.
[0075] The memory can be a hard disk or other memories that store data and do not lose data after power-off.
[0076] It should also be noted that the computing devices provided in the embodiments of the present application (such as the first computing device 101, the second computing device 102, and the third computing device 103) can be network devices or terminal devices. Network devices can include servers, etc. Among them, the server can be a physical server, or two or more physical servers sharing different responsibilities and collaborating with each other to implement the various functions of the server, or a virtual server (which can also be referred to as a virtual machine) running in a physical server.
[0077] Exemplarily, the server may be a blade server, a high-density server, a rack server, a tower server, etc. The terminal device may include a personal digital assistant (PDA), an ultra-mobile personal computer (UMPC), a laptop computer, a netbook, a desktop computer, an all-in-one computer, etc.
[0078] In the embodiments of the present application, the relationship between the CXL memory device 200 and the computing device 100 is not limited. In one example, the CXL memory device 200 may be a memory device independent of the computing device 100, such as Figure 2 shown in (a) of Figure 2 In another example, the CXL memory device 200 may be integrated within the computing device 100. As shown in (b) of
[0079] In the case where the CXL memory device 200 is a memory device independent of the computing device 100, in the embodiments of the present application, the connection manner between the CXL memory device 200 and the computing device 100 is not limited.
[0080] The following will be introduced by A. The CXL memory device 200 and the computing device 100 are connected through a CXL multi-head controller (CXL multihead expander) (which may also be referred to as CXL MH), and B. The CXL memory device 200 and the computing device 100 are connected through a CXL switch (switch, SW).
[0081] A. The CXL memory device 200 and the computing device 100 are connected through a CXL multi-head controller.
[0082] In this embodiment, the above CXL controller 201 may be implemented as a CXL multi-head controller so that the CXL controller can be directly connected to multiple computing devices. For example, the CXL controller may be connected to three computing devices through three ports (ports). For another example, the CXL controller may be connected to four computing devices through four ports. For still another example, the CXL controller may be connected to eight computing devices through eight ports.
[0083] Figure 3 This is a schematic diagram of the architecture of another computing cluster provided by the embodiments of the present application.
[0084] As Figure 3 shown, the computing cluster includes at least one computing device 100 and a CXL memory device 200.
[0085] The CXL memory device 200 includes a CXL controller 201 and a CXL memory 202 connected to the CXL controller.
[0086] The CXL controller 201 includes multiple ports, at least one cache coherence maintenance (Home Directory Management, HDM) decoder, and a memory controller. Exemplarily, Figure 3 Three HDM decoders are shown, namely HDM decoder 201-A, HDM decoder 201-B, and HDM decoder 201-C. The HDM decoder 201-A is connected to the first computing device 101. The HDM decoder 201-B is connected to the second computing device 102. The HDM decoder 201-C is connected to the second computing device 103.
[0087] The memory controller is connected to the CXL memory 202 for accessing the CXL memory 202. Exemplarily, the memory controller fetches a certain data from the CXL memory 202, or the memory controller writes a certain data to the CXL memory 202.
[0088] For each computing device, the computing device can connect its root port (RP) to a port of the CXL controller 201 based on the CXL protocol to form a CXL link. When the computing device intends to fetch or write a certain data (hereinafter referred to as the target data) in the CXL memory, the computing device can send a read / write instruction for the CXL memory (such as the read data instruction or write data instruction in this application) to the corresponding HDM decoder through the CXL link. After receiving the read / write instruction, the HDM decoder can determine the storage location of the target data in the CXL memory, and the HDM decoder can send the storage location to the memory controller. The memory controller can fetch or write the target data in the CXL memory based on the storage location.
[0089] Among them, the CXL protocol can include CXL.io, CXL.cache, and CXL.mem.
[0090] Exemplarily, taking the first computing device 101 and the target data being data q as an example, when the first computing device 101 intends to obtain data q from the CXL memory, it can generate a read data instruction requesting to obtain data q from the CXL memory. The first computing device 101 can send this read data instruction to the HDM decoder 201-A through the CXL link. After receiving the read data instruction, the HDM decoder 201-A can parse the read data instruction to obtain the storage location of data q in the CXL memory. The HDM decoder 201-A can send the storage location of data q to the memory controller, and the memory controller can read data q from the CXL memory based on this storage location.
[0091] B. The CXL memory device 200 and the computing device 100 are connected through a CXL switch.
[0092] The CXL switch is a switch that follows the CXL protocol.
[0093] The CXL memory device 200 can be connected to the computing device 100 through the CXL switch based on the CXL protocol.
[0094] Figure 4 This is another schematic diagram of the architecture of the computing cluster provided by the embodiments of the present application.
[0095] As Figure 4 shown, the computing cluster includes at least one computing device 100, at least one CXL memory device 200, and a CXL switch 300. Exemplarily, Figure 4 it shows three computing devices (the first computing device 101, the second computing device 102, and the third computing device 103 respectively) and two CXL memory devices 200 (the CXL memory device 203 and the CXL memory device 204 respectively).
[0096] Each CXL memory device 200 includes a CXL controller and a CXL memory connected to the CXL controller. The CXL controller includes an HDM decoder, a memory controller, and a port.
[0097] The CXL switch 300 includes a plurality of upstream ports (upstream switch port, USP) and a plurality of downstream ports (downstream switch port, DSP). Exemplarily, Figure 4 it shows three upstream ports (the upstream port 301, the upstream port 302, and the upstream port 303 respectively) and three downstream ports (the downstream port 304, the downstream port 305, and the downstream port 306 respectively).
[0098] Each upstream port is used to connect a computing device 100. Correspondingly, the CXL switch 300 communicates with the computing device 100 through the upstream port. Exemplarily, as Figure 4 shown, the CXL switch 300 can receive read and write instructions sent by the first computing device 101 through the upstream port 301, and can also send data to the first computing device 101 through the upstream port 301.
[0099] Each downstream port is used to connect a CXL memory device 200. Correspondingly, the CXL switch 300 communicates with the CXL memory device 200 through the downstream port. Exemplarily, as Figure 4 shown, the CXL switch 300 can send read and write instructions to the CXL memory device 203 through the downstream port 304, and can also receive data sent by the CXL memory device 203 through the downstream port 304.
[0100] Virtual channel signaling (VCS) can be deployed between the upstream port and the downstream port of the CXL switch 300. The VCS can send the instructions received from the upstream port (such as the read data instruction or the write data instruction in this application) to the downstream port. Exemplarily, Figure 4 shows three VCSs, namely VCS1, VCS2, and VCS3. VCS1 can send the instructions received from the upstream port 301 to the downstream port 304. VCS2 can send the instructions received from the upstream port 302 to the downstream port 305. VCS3 can send the instructions received from the upstream port 303 to the downstream port 306.
[0101] In the embodiment of this application, after receiving an access request for the CXL memory, the CXL controller can obtain the first signature corresponding to the entity that generates the access request and verify the first signature. When the first signature verification passes, the CXL controller can access the CXL memory.
[0102] The following takes the Figure 3 shown architecture schematic diagram as an example to introduce in detail the memory access method provided in the embodiment of this application.
[0103] Figure 5 is a schematic flow diagram of a memory access method provided in the embodiment of this application. As Figure 5 shown, this method includes S501 - S503.
[0104] S501, in response to an access request for the CXL memory, obtain the first signature corresponding to the entity that generates the access request.
[0105] Among them, the access request is used to request to read data from the CXL memory or the access request is used to request to write data to the CXL memory.
[0106] The embodiment of the present application does not specifically limit the entity that generates the access request (hereinafter simply referred to as the first entity). The CXL controller can be connected to a computing device, and processes and applications can run in the computing device. On this basis, the first entity can be at least one of a computing device connected to the CXL controller, a process running in the computing device connected to the CXL controller, or an application running in the computing device connected to the CXL controller.
[0107] The embodiment of the present application does not limit the number of computing devices connected to the CXL controller. For example, the number of computing devices connected to the CXL controller can be 1, 2, 4, or more.
[0108] In the case where the number of computing devices connected to the CXL controller includes multiple ones, the processes running in the computing devices connected to the CXL controller include the processes running in each computing device connected to the CXL controller, and the applications running in the computing devices connected to the CXL controller include the applications running in each computing device connected to the CXL controller.
[0109] The embodiment of the present application does not limit the number of processes running in each computing device connected to the CXL controller. For example, the number of processes running in each computing device connected to the CXL controller can be several, hundreds, or thousands, etc.
[0110] The embodiment of the present application does not limit the number of applications running in each computing device connected to the CXL controller. For example, the number of applications running in each computing device connected to the CXL controller can be several, hundreds, or thousands, etc.
[0111] In the embodiment of the present application, the process can be a process started during the running of a certain application installed in the computing device (such as a game application, a browser application, or a video playback application, etc.), that is, an application process. It can also be a process started during the running of the operating system of the computing device, that is, a system process. It can also be a process related to the kernel of the operating system, that is, a kernel process.
[0112] Taking the computing device connected to the CXL controller including Figure 2Taking the first computing device and the second computing device shown as examples, when the first entity is a computing device, the first entity can be the first computing device or the second computing device. When the first entity is a process (hereinafter referred to as the target process), the target process can run in the first computing device or in the second computing device. When the first entity is an application (hereinafter referred to as the target application), the target application can run in the first computing device or in the second computing device.
[0113] The embodiments of the present application do not specifically limit the first signature corresponding to the first entity. In one example, the first signature can be a key (such as a private key) corresponding to the first entity. In another example, the first signature can be the entity identifier of the first entity. For example, when the entity generating the access request is a process, the first signature can be the process identifier (identifier, ID) or process name of the process, etc. When the entity generating the access request is an application, the first signature can be the application ID or application name of the application, etc. When the entity generating the access request is a computing device, the first signature can be the device ID or device name of the computing device, etc.
[0114] The embodiments of the present application do not specifically limit the manner in which the CXL controller obtains the first signature corresponding to the first entity. The following will respectively introduce: one, obtaining the first signature from the access request; and two, obtaining the first signature from multiple signatures stored in the CXL controller.
[0115] One, obtaining the first signature from the access request.
[0116] In this embodiment, the access request may carry the first signature. Correspondingly, after receiving the access request, the CXL controller can parse the access request to obtain the first signature corresponding to the first entity.
[0117] Two, obtaining the first signature from multiple signatures stored in the CXL controller.
[0118] In this embodiment, the CXL controller may store a signature correspondence relationship, and the signature correspondence relationship is used to indicate at least one of the signatures corresponding to different processes, the signatures corresponding to different applications, or the signatures corresponding to different computing devices.
[0119] The embodiments of the present application do not specifically limit the storage form of the signature correspondence relationship. For example, the signature correspondence relationship can be stored in the CXL controller in the form of a table or in the form of a function.
[0120] Signatures corresponding to different processes may include: signatures corresponding to multiple processes running in a computing device connected to a CXL controller. For example, taking a computing device connected to a CXL controller including a first computing device and a second computing device as an example, the decoding parameters corresponding to different processes include: signatures corresponding to multiple processes running in the first computing device, and signatures corresponding to multiple processes running in the second computing device.
[0121] Assume that the processes running in the first computing device include Process A and Process B, and the processes running in the second computing device include Process 1 and Process 2. Then, the signatures corresponding to different processes may include: the signature corresponding to Process A, the signature corresponding to Process B, and the signature corresponding to Process 1, and the signature corresponding to Process 2.
[0122] It should be noted that the signatures corresponding to different processes may be the same or different.
[0123] The applications in the embodiments of this application may include applications installed in any computing device connected to a CXL controller. For example, taking a computing device connected to a CXL controller including a first computing device and a second computing device as an example, the signatures corresponding to different applications may include: signatures corresponding to multiple applications installed in the first computing device, and signatures corresponding to multiple applications installed in the second computing device.
[0124] Assume that the applications installed in the first computing device include Application C and Application D, and the applications installed in the second computing device include Application 3 and Application 4. Then, the signatures corresponding to different applications may include: the signature corresponding to Application C, the signature corresponding to Application D, and the signature corresponding to Application 3, and the signature corresponding to Application 4.
[0125] It should be noted that the signatures corresponding to different applications may be the same or different. The signatures corresponding to the same application installed in different computing devices may be the same or different. For example, assume that Application C is installed in both the first computing device and the second computing device. Then, the signature corresponding to Application C installed in the first computing device and the signature corresponding to Application C installed in the second computing device may be the same or different.
[0126] Signatures corresponding to different computing devices may include: signatures corresponding to any computing device connected to a CXL controller. For example, taking a computing device connected to a CXL controller including a first computing device and a second computing device as an example, the signatures corresponding to different computing devices may include: the signature corresponding to the first computing device and the signature corresponding to the second computing device.
[0127] Assume that the signature corresponding to the first computing device is 001 and the signature corresponding to the second computing device is 002. Then, the signatures corresponding to different computing devices may include 001 and 002.
[0128] It should be noted that the signatures corresponding to different computing devices can be the same or different.
[0129] Specifically, taking the first entity as the first computing device as an example, when the first computing device intends to read data from the CXL memory or intends to write data to the CXL memory, it can generate an access request for the CXL memory and send the access request to the CXL controller based on the CXL.mem protocol. After receiving the access request sent by the first computing device, the CXL controller can determine the device identifier of the first computing device, and then determine the signature corresponding to the first computing device from the signature correspondence stored in itself, which is the first signature.
[0130] In an alternative embodiment, the CXL controller may include a transceiver module, a CXL PCIE physical layer, and a memory controller. The transceiver module is used to communicate with the computing device. The CXL PCIE physical layer is used to determine the memory address of the encoded target data. The memory controller is used to read the encoded target data from the CXL memory. Among them, the CXL PCIE physical layer is the physical layer of CXL PCIe, which refers to the bottom layer of the data link and is responsible for the transceiver and processing of physical signals.
[0131] The transceiver module may include at least one transmit module (TX) and at least one receive module (RX). Exemplarily, Figure 6 shows two transmit modules (transmit module A and transmit module B respectively) and two receive modules (receive module A and receive module B respectively). The transmit module can be connected to the computing device through a lane to send the data read from the CXL memory to the computing device through the lane. The receive module can be connected to the computing device 100 through a lane to receive the access request sent by the computing device through the lane.
[0132] The following takes the first entity as the first computing device and the access request carries the first signature as an example to illustrate the above S501 through the interaction between the first computing device, the receive module, the CXL PCIE physical layer, the memory controller, and the CXL memory.
[0133] As Figure 6As shown, after the first computing device generates an access request for CXL memory, it can send the access request to the receiving module of the CXL controller through a link. After the receiving module of the CXL controller receives the access request, it can send the access request to the CXL PCIe physical layer through the mail-box (MB) channel. After the CXL PCIe physical layer receives the access request, it can parse the access request to obtain the first signature corresponding to the first computing device. Alternatively, after the CXL PCIe physical layer receives the access request, it can send the access request to the memory controller, and the memory controller can parse the access request to obtain the first signature corresponding to the first computing device.
[0134] S502, verify the first signature.
[0135] Specifically, the CXL controller can obtain a verification code and verify the first signature based on the verification code.
[0136] In an alternative embodiment, the verification code can be stored in the CXL controller. Accordingly, the above verification of the first signature can be replaced with: the CXL controller can obtain the verification code stored in itself and verify the first signature based on the verification code stored in itself.
[0137] The embodiments of the present application do not specifically limit the number of verification codes stored in the CXL controller. For example, the number of verification codes stored in the CXL controller can be several, hundreds, or thousands, etc.
[0138] Taking the number of verification codes stored in the CXL controller as 1 as an example, after the CXL controller obtains the verification code, it can verify the first signature based on the verification code.
[0139] Taking the number of verification codes stored in the CXL controller as multiple as an example, after the CXL controller obtains multiple verification codes stored in itself, it can verify the first signature respectively using each of the multiple verification codes.
[0140] In an alternative embodiment, a first correspondence can be stored in the CXL controller, and the first correspondence is used to indicate at least one of the verification codes corresponding to the processes allowed to access the CXL memory, the verification codes corresponding to the applications allowed to access the CXL memory, or the verification codes corresponding to the computing devices allowed to access the CXL memory. Accordingly, the above obtaining of the verification code by the CXL controller can be replaced with: obtaining the verification code from the first correspondence.
[0141] It can be understood that in the case where the above first correspondence is used to indicate multiple items among the verification codes corresponding to the process allowed to access the CXL memory, the verification code corresponding to the application allowed to access the CXL memory, or the verification code corresponding to the computing device allowed to access the CXL memory, the verification codes corresponding to the multiple items may be the same or different. For example, taking the above first correspondence as an example to indicate the verification code corresponding to the process allowed to access the CXL memory, the verification code corresponding to the application allowed to access the CXL memory, and the verification code corresponding to the computing device allowed to access the CXL memory, the verification code corresponding to the process allowed to access the CXL memory, the verification code corresponding to the application allowed to access the CXL memory, and the verification code corresponding to the computing device allowed to access the CXL memory may be the same or different.
[0142] The embodiments of the present application do not make specific limitations on the verification code. In one example, the verification code may include a key (such as a public key) corresponding to the entity (process, application, or computing device, hereinafter simply referred to as the second entity) allowed to write data in the CXL memory. In another example, the first signature may include the entity identifier of the second entity. For example, when the second entity is a process, the verification code may include the process identifier (ID) or process name of the process, etc. When the second entity is an application, the verification code may include the application ID or application name of the application, etc. When the second entity is a computing device, the verification code may include the device ID or device name of the computing device, etc.
[0143] The embodiments of the present application do not make specific limitations on the storage form of the first correspondence. For example, the first correspondence may be stored in the CXL controller in the form of a table or in the form of a function.
[0144] The verification code corresponding to the process allowed to access the CXL memory includes: the verification code corresponding to the process allowed to perform read and write operations (such as writing data to the CXL memory or reading data from the CXL memory) in the CXL memory among the computing devices connected to the CXL controller. Taking the computing devices connected to the CXL controller including a first computing device and a second computing device as an example, the verification code corresponding to the process allowed to access the CXL memory includes the verification code corresponding to the process allowed to perform read and write operations in the CXL memory in the first computing device, and the verification code corresponding to the process allowed to perform read and write operations in the CXL memory in the second computing device.
[0145] Suppose the processes that allow read and write operations in the CXL memory in the first computing device include Process A and Process B, and the processes that allow read and write operations in the CXL memory in the second computing device include Process 1 and Process 2. Then the check codes corresponding to the processes allowed to access the CXL memory may include: the check code corresponding to Process A, the check code corresponding to Process B, and the check code corresponding to Process 1, and the check code corresponding to Process 2.
[0146] It should be noted that the check codes corresponding to different processes allowed to access the CXL memory may be the same or different.
[0147] The check codes corresponding to the applications allowed to access the CXL memory may include: the check codes corresponding to the applications that allow read and write operations in the CXL memory in the computing devices connected to the CXL controller. Continuing with the example where the computing devices connected to the CXL controller include the first computing device and the second computing device, the check codes corresponding to the applications allowed to access the CXL memory include the check codes corresponding to the applications that allow read and write operations in the CXL memory in the first computing device, and the check codes corresponding to the applications that allow read and write operations in the CXL memory in the second computing device.
[0148] Suppose the applications installed in the first computing device include Application C and Application D, and Application C allows read and write operations in the CXL memory. The applications installed in the second computing device include Application 3 and Application 4, and Application 4 allows read and write operations in the CXL memory. Then the check codes corresponding to the applications allowed to access the CXL memory may include: the check code corresponding to Application C and the check code corresponding to Application 4.
[0149] It should be noted that the check codes corresponding to different applications allowed to access the CXL memory may be the same or different. The check codes corresponding to the same application installed in different computing devices may be the same or different. For example, suppose Application C is installed in both the first computing device and the second computing device. Then the check code corresponding to Application C installed in the first computing device and the check code corresponding to Application C installed in the second computing device may be the same or different.
[0150] The check codes corresponding to the computing devices allowed to access the CXL memory may include: the check codes corresponding to the computing devices that allow read and write operations in the CXL memory in the computing devices connected to the CXL controller. Continuing with the example where the computing devices connected to the CXL controller include the first computing device and the second computing device, the check codes corresponding to the computing devices allowed to access the CXL memory include the check codes corresponding to the computing devices that allow read and write operations in the CXL memory in the first computing device and / or the second computing device.
[0151] Assume that the first computing device allows read and write operations on the CXL memory, and the second computing device does not allow read and write operations on the CXL memory. Then, the check code corresponding to the computing device allowed to access the CXL memory includes the check code corresponding to the first computing device.
[0152] It should be noted that the check codes corresponding to different computing devices allowed to access the CXL memory can be the same or different.
[0153] After obtaining the check code in the above manner, the CXL controller can match the check code with the first signature. When the check code and the first signature match successfully, the CXL controller can determine that the first signature passes the verification.
[0154] The embodiments of the present application do not specifically limit the conditions for successful matching between the check code and the first signature. Specifically, the conditions for successful matching between the check code and the first signature may include any one of the following (1), (2), and (3).
[0155] (1) The check code is consistent with the first signature. In one example, assume that the check code is 001x and the first signature is 001x. Then, the check code and the first signature match successfully. In another example, assume that the check code is 001x and the first signature is 002y. Then, the check code and the first signature do not match successfully.
[0156] (2) The check code contains the first signature. In one example, assume that the check code includes 001x, 002y, and 003z, and the first signature is 001x. At this time, the check code contains the first signature, so the check code and the first signature match successfully. In another example, assume that the check code includes 001x, 002y, and 003z, and the first signature is 004l. At this time, the check code does not contain the first signature, so the check code and the first signature do not match successfully.
[0157] (3) The check code and the first signature are paired keys. For example, the check code can be a public key and the first signature is a private key. At this time, if the first signature and the check code are paired public and private keys, the check code and the first signature match successfully.
[0158] Specifically, taking the first signature including the private key corresponding to the first computing device and the first corresponding relationship including the public key corresponding to the computing device allowed to write data in the CXL memory as an example, after the CXL controller obtains the private key corresponding to the first computing device, it can obtain the public key corresponding to the computing device allowed to write data in the CXL memory from the first corresponding relationship, and compare the private key corresponding to the first computing device with the public key corresponding to any computing device allowed to write data in the CXL memory. When the private key corresponding to the first computing device and the public key corresponding to any computing device allowed to write data in the CXL memory are a pair of paired public and private keys, the CXL controller can determine that the first signature passes the verification.
[0159] Through the above technical solution, when verifying the first signature, it is possible to verify not only based on keys (such as public keys and private keys), but also based on the principal identifier of the principal (process, application, or device) that generates the write data instruction. In this way, when the principal that generates the write data instruction is a process, the security of different processes of the same computing device accessing the CXL memory can be guaranteed. When the principal that generates the write data instruction is an application, the security of different applications of the same computing device accessing the CXL memory can be guaranteed. When the principal that generates the write data instruction is a device, the security of different computing devices accessing the CXL memory can be guaranteed.
[0160] In addition, only the principal that passes the verification can access the CXL memory. In this way, it is possible to effectively avoid the phenomenon of an insecure principal accessing the CXL memory. Further improve the security of CXL memory access and effectively avoid the leakage of data in the CXL memory.
[0161] From the foregoing, it can be seen that the CXL controller may include a CXL PCIE physical layer and a memory controller. Correspondingly, the above first corresponding relationship may be stored in the CXL PCIE physical layer or in the memory controller.
[0162] When the first corresponding relationship is stored in the memory controller, the above CXL controller obtaining the verification code may be replaced with: obtaining the first corresponding relationship from the memory controller and determining the verification code based on the first corresponding relationship.
[0163] When the first corresponding relationship can be stored in the CXL PCIE physical layer, the above CXL controller obtaining the verification code may be replaced with: obtaining the first corresponding relationship from the CXL PCIE physical layer and determining the verification code based on the first corresponding relationship.
[0164] In the above technical solution, the first corresponding relationship can be stored in different locations. In this way, the compatibility of the present application can be expanded and the feasibility of the present application can be improved.
[0165] In an alternative embodiment, the CXL controller may include a check code management module (which may be referred to as a keymana ger or a security module), and the check code management module is used to store the first correspondence. Correspondingly, the check code management module may be located in the CXL PCIE physical layer of the CXL controller or in the memory controller of the CXL controller.
[0166] In an alternative embodiment, both the CXL PCIE physical layer and the memory controller in the CXL controller may verify the first signature based on the check code. Figure 6 FIG. is a schematic diagram of the CXL PCIE physical layer verifying the first signature. Figure 7 FIG. is a schematic diagram of the memory controller verifying the first signature.
[0167] When the CXL PCIE physical layer verifies the first signature, the CXL PCIE physical layer may include a first verification module (which may also be referred to as a first FCK module), such as Figure 6 the first verification module 601 shown. Correspondingly, the CXL PCIE physical layer verifying the first signature may be replaced with: the CXL PCIE physical layer verifies the first signature through the first verification module.
[0168] It can be understood that the first verification module and the above-mentioned check code management module may be the same software module or different software modules.
[0169] When the memory controller verifies the first signature, the memory controller may include a second verification module (which may also be referred to as a second FCK module), such as Figure 7 the second verification module 701 shown. Correspondingly, the memory controller verifying the first signature may be replaced with: the memory controller verifies the first signature through the second verification module.
[0170] It can be understood that the second verification module and the above-mentioned check code management module may be the same software module or different software modules.
[0171] Compared with the memory controller, the CXL PCIE physical layer is closer to the upstream port of the CXL controller, that is, the CXL PCIE physical layer can receive the access request sent by the computing device earlier. Therefore, verifying the first signature through the CXL PCIE physical layer can improve the verification rate of the first signature. Therefore, in the embodiments of the present application, preferably, the CXL PCIE physical layer in the CXL controller verifies the first signature based on the check code. On this basis, after the check code is determined in the memory controller, it is also necessary to send the check code to the CXL PCIE physical layer.
[0172] S503, access the CXL memory when the first signature verification passes.
[0173] Specifically, when the first signature verification passes, it indicates that the first entity is allowed to read and write the CXL memory. At this time, the CXL controller can perform read and write operations on the CXL memory.
[0174] When the first signature verification fails, it indicates that the first entity is not allowed to read and write the CXL memory. The CXL controller can return an error instruction to the first entity, and this error instruction is used to indicate that the first entity is not allowed to access the CXL memory. Alternatively, when the first signature verification fails, the CXL controller can return a preset character to the first entity.
[0175] The present application embodiment does not limit the preset character. For example, the preset character can be FF or XXXX.
[0176] In an alternative embodiment, the CXL controller may include an access module (which can also be referred to as the MUX module). The access module can receive the verification result sent by the verification module (such as the above-mentioned first verification module or second verification module), and perform read and write operations on the CXL memory when the verification result passes, and return an error instruction or a preset character to the first entity when the verification result fails.
[0177] Wherein, the verification result refers to the verification result of verifying the first signature.
[0178] In the embodiments of the present application, the representation method of the verification result is not limited. In one example, the access request can be sent in the form of a data frame (flit). Correspondingly, the flit may include a flag bit (bit, which can also be referred to as the trusted domain) for indicating the verification result of verifying the first signature. At this time, the verification module can represent the verification result through the trusted domain in the flit. Exemplarily, taking 1 representing verification pass and 0 representing verification failure as an example. When the verification result passes, the verification module can set the trusted domain in the flit to 1 to represent that the first signature verification passes, and when the verification result fails, the trusted domain in the flit can be set to 0 to represent that the first signature verification fails.
[0179] In an alternative embodiment, when the above access request is used to indicate obtaining the first data from the CXL memory, the above CXL controller accessing the CXL memory can be replaced with: obtaining the first data from the CXL memory.
[0180] In the case where the above access request is used to indicate writing second data into the CXL memory, the above CXL controller accessing the CXL memory can be replaced with: writing second data into the CXL memory.
[0181] As can be seen from the above technical solution, only the entities (processes, applications, or computing devices) that pass the verification can access the CXL memory. In this way, the phenomenon of insecure entities accessing the CXL memory can be effectively avoided. Furthermore, the security of CXL memory access can be effectively improved, and the data in the CXL memory can be effectively prevented from being leaked.
[0182] In addition, a CXL controller can be connected to multiple computing devices at the same time. By improving a CXL controller, even if the CXL controller has the verification ability to verify the entity that generates the access request, it is possible to simultaneously prevent multiple computing devices (or processes or applications running in multiple computing devices) from directly obtaining plaintext data from the CXL memory. In this way, the deployment difficulty of this solution can be reduced, and the compatibility and feasibility of this solution can be improved.
[0183] In an optional implementation manner, the CXL controller can periodically obtain the first correspondence from the computing devices connected to itself.
[0184] Specifically, in some embodiments, the CXL controller can obtain the second correspondence from the computing devices connected to itself according to a period through the I2C (which can also be called IRC) interface or the I3C interface in the config interface.
[0185] In other embodiments, the CXL controller can obtain the second correspondence from the computing devices connected to itself according to a period through the transceiver module.
[0186] The embodiments of the present application do not limit the period for the CXL controller to obtain the first correspondence from the computing devices. For example, the period can be 5 days, that is, the CXL controller can obtain the first correspondence from the computing devices once every 5 days. Another example is that the period can be 1 day, that is, the CXL controller can obtain the first correspondence from the computing devices once every 1 day.
[0187] In the embodiments of the present application, the computing device storing the first correspondence is not limited. For example, the computing device storing the first correspondence can be Figure 2 the first computing device or the second computing device shown. Another example is that the computing device storing the first correspondence can be Figure 8 the management computing device 800 shown. The management computing device 800 is used to manage multiple computing devices, such as Figure 8The first computing device 101, the second computing device 102, and the third computing device 103 shown in
[0188] As Figure 8 shown, the management computing device 800 may include a processor and a memory. The processor may be a CPU or other components with processing capabilities. Among them, the CPU, as the operation and control core of the computing device, is the final execution unit for information processing and program operation. The CPU is a very large-scale integrated circuit composed of an arithmetic unit, a controller, registers, etc., and its main task is to process and handle various data. The memory may be a disk or other memories that store data and do not lose data after power-off.
[0189] Through the above technical solution, the CXL controller can update the first correspondence stored in itself based on the first correspondence stored in the computing device, which can avoid the leakage of the check code in the first correspondence, can further improve the security of CXL memory access, and avoid the leakage of data in the CXL memory.
[0190] The above mainly introduces the memory access method provided by the embodiments of the present application from the perspective of the method. To implement the above functions, the memory access device includes the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of the examples described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0191] The embodiments of the present application can, according to the above method, exemplarily divide the function modules of the memory access device. For example, the memory access device may include each function module corresponding to each function division, or two or more functions may be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of a software function module. It should be noted that the division of modules in the embodiments of the present application is illustrative, only a logical function division, and there may be other division methods in actual implementation.
[0192] Exemplarily, Figure 9 shows a possible structural schematic diagram of the memory access device (denoted as memory access device 900) involved in the above embodiments. The memory access device 900 includes an acquisition unit 901, a verification unit 902, and an access unit 903.
[0193] Among them, the obtaining unit 901 is configured to obtain a first signature corresponding to the subject that generates the access request in response to the access request. The subject that generates the access request includes at least one of a process, an application, or a computing device.
[0194] The verification unit 902 is configured to verify the first signature.
[0195] The access unit 903 is configured to access the CXL memory when the first signature passes the verification.
[0196] Optionally, the verification unit 902 is specifically configured to: obtain a verification code and verify the first signature based on the verification code.
[0197] Optionally, the first signature is carried in the access request.
[0198] Optionally, a first correspondence is stored in the CXL controller, and the first correspondence is used to indicate at least one of the verification codes corresponding to the processes allowed to access the CXL memory, the verification codes corresponding to the applications allowed to access the CXL memory, or the verification codes corresponding to the computing devices allowed to access the CXL memory. Correspondingly, the obtaining unit 901 is specifically configured to: determine the verification code from the first correspondence.
[0199] Optionally, the first correspondence is stored in the CXL PCIE physical layer of the CXL controller. The obtaining unit 901 is specifically configured to: obtain the first correspondence from the CXL PCIE physical layer and determine the verification code based on the first correspondence. Correspondingly, the verification unit 902 is specifically configured to: verify the first signature based on the verification code through the CXL PCIE physical layer.
[0200] Optionally, the first correspondence is stored in the memory controller of the CXL controller. The obtaining unit 901 is specifically configured to: obtain the first correspondence from the memory controller and determine the verification code based on the first correspondence. Correspondingly, the verification unit 902 is specifically configured to: send the verification code to the CXL PCIE physical layer of the CXL controller and verify the first signature based on the verification code through the CXL PCIE physical layer.
[0201] Optionally, when the first computing device is started, the obtaining unit 901 is further configured to: periodically obtain the first correspondence from the computing device.
[0202] Optionally, the verification unit 902 is specifically configured to: determine that the first signature passes the verification when the verification code and the first signature match successfully.
[0203] Optionally, when the access request is used to indicate reading the first data, the access unit 903 is specifically configured to: obtain the first data from the CXL memory; or, when the access request is used to indicate writing the second data, the access unit 903 is specifically configured to: write the second data to the CXL memory.
[0204] Optionally, the first signature is a private key, and the check code is a public key.
[0205] Optionally, the CXL controller connects the first computing device and the second computing device. The subject of the generated access request is a target process that runs in the first computing device or the second computing device. Or, the subject of the generated access request is a target application that runs in the first computing device or the second computing device.
[0206] Optionally, the above access request may include a flag bit, and the flag bit is used to indicate the verification result of the verification of the first signature.
[0207] For the specific descriptions of the above optional manners, reference may be made to the foregoing method embodiments, which will not be elaborated herein. In addition, the explanations and beneficial effects descriptions of any of the above provided memory access devices may refer to the corresponding method embodiments above, which will not be elaborated.
[0208] An embodiment of this application further provides a CXL controller. The computing device includes a processor and a memory. The processor is connected to the memory. The memory stores computer-executable instructions. When the processor executes the computer-executable instructions, the memory access method in the foregoing embodiments is implemented.
[0209] The embodiments of the present application do not impose any restrictions on the specific form of the computing device. For example, the computing device may specifically be a terminal device or a network device. Among them, the terminal device may be referred to as: terminal, user equipment (UE), terminal device, access terminal, user unit, user station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication device, user agent, or user device, etc. The terminal device may specifically be a mobile phone, an augmented reality (AR) device, a virtual reality (VR) device, a tablet computer, a laptop computer, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), etc. The network device may specifically be a server, etc. Among them, the server may be a physical or logical server, or may be two or more physical or logical servers sharing different responsibilities and cooperating with each other to implement the various functions of the server.
[0210] The embodiments of the present application also provide a computer-readable storage medium, on which a computer program is stored. When the computer program runs on a computer, the computer is caused to execute the method performed by any of the computer devices provided above.
[0211] For the explanations and descriptions of the beneficial effects of the relevant content in any of the above-provided computer-readable storage media, reference may be made to the corresponding embodiments above, and details are not repeated here.
[0212] The embodiments of the present application also provide a chip. The chip integrates a control circuit for implementing the functions of the above computer device and one or more ports. Optionally, the functions supported by the chip may refer to the above, and details are not repeated here. Those of ordinary skill in the art can understand that all or part of the steps for implementing the above embodiments can be completed by instructing relevant hardware through a program. The said program can be stored in a computer-readable storage medium. The storage medium mentioned above may be a read-only memory, a random access memory, etc. The above processing unit or processor may be a central processing unit, a general-purpose processor, an application specific integrated circuit (ASIC), a digital signal processor (DSP), a field programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof.
[0213] The embodiments of the present application also provide a computer program product including instructions. When the instructions run on a computer, the computer is caused to execute any one of the methods in the above embodiments. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are fully or partially generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by the computer or a data storage device such as a server or data center that includes one or more integrated media. The available medium may be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as an SSD), etc.
[0214] The embodiments of the present application also provide a computing device. The computing device includes a CXL controller, a CXL memory, and a processor. The CXL controller, the CXL memory, and the processor are coupled. The CXL controller is used to implement the memory access method in the above embodiments.
[0215] The embodiments of the present application also provide a CXL memory device. The CXL memory device includes a CXL controller and a CXL memory. The CXL controller and the CXL memory are coupled. The CXL controller is used to implement the memory access method in the above embodiments.
[0216] It should be noted that the devices for storing computer instructions or computer programs provided in the embodiments of the present application, such as but not limited to, the above-mentioned memory, computer-readable storage medium, and communication chip, etc., are all non-transitory.
[0217] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, a computer, a server, or a data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, a data center, etc. that contains one or more media integrated therein. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.
[0218] Although the present application has been described in conjunction with various embodiments, however, in the process of implementing the claimed present application, those skilled in the art can understand and implement other variations of the disclosed embodiments by viewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality. A single processor or other unit can implement several functions recited in the claims. Certain measures are recited in mutually different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0219] Although the present application has been described in conjunction with specific features and their embodiments, it is obvious that various modifications and combinations can be made without departing from the spirit and scope of the present application. Accordingly, the present specification and the drawings are merely exemplary illustrations of the present application defined by the appended claims, and are considered to have covered any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.
Claims
1. A memory access method, characterized in that, Applied to a Compute Express Link (CXL) controller for connecting to a computing device in which processes and applications are running, the method includes: In response to an access request for CXL memory, obtaining a first signature corresponding to the entity that generated the access request, where the entity that generated the access request includes at least one of the computing device, the process, or the application, and there are one or more computing devices; Verifying the first signature; When the verification of the first signature passes, accessing the CXL memory.
2. The method according to claim 1, wherein The verifying of the first signature includes: Obtaining a verification code; Based on the verification code, verifying the first signature.
3. The method according to claim 2, wherein The access request carries the first signature.
4. The method according to claim 2, characterized in that A first correspondence is stored in the CXL controller, and the first correspondence is used to indicate at least one of the following: The verification code corresponding to a process allowed to access the CXL memory; The verification code corresponding to an application allowed to access the CXL memory; The verification code corresponding to a computing device allowed to access the CXL memory; The obtaining of the verification code includes: Determining the verification code from the first correspondence.
5. The method according to claim 4, wherein The first correspondence is stored in the CXL PCIe physical layer of the CXL controller. The obtaining of the verification code includes: Obtaining the first correspondence from the CXL PCIe physical layer; Based on the first correspondence, determining the verification code; The verifying of the first signature based on the verification code includes: Through the CXL PCIE physical layer, verifying the first signature based on the verification code.
6. The method according to claim 4, characterized in that, The first correspondence is stored in the memory controller of the CXL controller. The obtaining of the verification code includes: Obtaining the first correspondence from the memory controller; Based on the first correspondence, determining the verification code; The verifying of the first signature based on the verification code includes: Sending the verification code to the CXL PCIE physical layer of the CXL controller; Through the CXL PCIE physical layer, verifying the first signature based on the verification code.
7. The method according to claim 4 or 5, characterized in that, The method further includes: Periodically obtaining the first correspondence from the computing device.
8. The method according to any one of claims 2-6, characterized in that The verifying of the first signature based on the verification code includes: When the verification code and the first signature match successfully, determining that the verification of the first signature passes.
9. The method according to claim 1, wherein The access request is used to indicate reading of first data, and the accessing of the CXL memory includes: obtaining the first data from the CXL memory; or, The access request is used to indicate writing of second data, and the accessing of the CXL memory includes: writing the second data to the CXL memory.
10. The method according to claim 2, wherein The first signature is a private key, and the verification code is a public key.
11. The method according to claim 1, characterized in that The CXL controller is connected to a first computing device and a second computing device; The entity that generated the access request is a target process; the target process runs in the first computing device, or the target process runs in the second computing device; or, The subject that generates the access request is the target application; The target application runs in the first computing device, or the target application runs in the second computing device.
12. The method according to claim 1, wherein The access request includes a flag bit, and the flag bit is used to indicate the verification result of verifying the first signature.
13. A CXL controller, characterized in that, It includes a processor, and the processor is coupled to a memory. The memory is used to store programs or instructions. When the programs or instructions are executed by the processor, the CXL controller is caused to execute the method according to any one of claims 1-12.
14. A computing device, characterized in that, It includes: A CXL controller, a CXL memory, a memory, and a processor, and the CXL controller, the CXL memory, the memory, and the processor are coupled; The CXL controller is used to execute the method according to any one of claims 1-12.
15. A CXL memory device, characterized in that, It includes: A CXL controller and a CXL memory, and the CXL controller and the CXL memory are coupled; the CXL controller is used to execute the method according to any one of claims 1-12.