On-chip resource protection method based on command queue reordering, electronic equipment and storage medium
By collecting and processing the status signals and threat codes of hardware accelerators at the hardware level, generating a set of priority labels and reordering them, and inserting isolation barriers, the real-time and reliability issues of resource protection in existing technologies are solved, and an efficient and accurate resource protection mechanism is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-02
- Publication Date
- 2026-04-03
AI Technical Summary
Existing technologies struggle to dynamically adapt to the real-time operating status of hardware resources and changes in security threats, resulting in high-risk commands failing to receive timely protection, improper resource allocation, slow response speed of software-level priority comparison logic, difficulty in meeting the real-time requirements of high-speed command scheduling at the chip level, and susceptibility of software log recording to data tampering, all of which reduce the reliability of resource protection.
The on-chip sensor array collects the status signals of the computing units, memory access signals, and bus arbitration signals of the hardware accelerator. Combined with the threat status code output by the hardware security state machine, a priority tag set containing a resource contention identifier field is generated. This priority tag set is then processed by hardware-level logic gates. A command priority comparator is used to match and compare the command priority with the resource sensitivity threshold field stored in the on-chip register group to generate a command priority encoding field. The initial command queue is reordered by a priority encoder, and a parameterized isolation barrier is inserted to achieve precise isolation and protection of high-risk commands. Finally, the execution trajectory status sequence is compared by hardware verification logic to ensure the real-time performance and reliability of resource protection.
It enables multi-dimensional collaborative perception of the operating status and security threats of core chip resources, improves the real-time performance and accuracy of resource competition risk assessment, ensures that high-risk commands are given priority for resource protection, avoids resource waste or insufficient protection, improves resource utilization efficiency and protection reliability, and meets the real-time requirements of high-speed command scheduling at the chip's underlying layer.
Smart Images

Figure FT_1 
Figure FT_2
Abstract
Description
Technical Field
[0001] This application belongs to the field of artificial intelligence technology, specifically relating to an on-chip resource protection method, electronic device and storage medium based on command queue reordering. Background Technology
[0002] On-chip resource protection is a key technology in chip design to ensure the safe and stable operation of core resources such as hardware accelerators, memory units, and bus interfaces. Command queues, as the core carrier of on-chip command scheduling, directly impact resource allocation efficiency and security capabilities through their management. Currently, on-chip resource protection typically reorders command queues using preset fixed priority rules, while relying on software algorithms to collect hardware operation signals and analyze resource contention risks, then generating priority decisions through software-level comparison logic. However, existing technologies struggle to dynamically adapt to the real-time operating status of hardware resources and changes in security threats, resulting in high-risk commands failing to receive timely protection. Fixed isolation barrier parameters cannot adjust the locking period and resource range based on command resource occupancy characteristics, easily leading to resource waste or insufficient protection. Software algorithms experience processing delays in collecting and analyzing hardware signals, and the slow response speed of software-level priority comparison logic fails to meet the real-time requirements of high-speed command scheduling at the chip's underlying level. Furthermore, the execution trajectory verification recorded by software logs is susceptible to data tampering, reducing the reliability of resource protection. Summary of the Invention
[0003] Therefore, the purpose of this application is to provide an on-chip resource protection method, electronic device, and storage medium based on command queue reordering to improve the above-mentioned problems.
[0004] The embodiments of this application are implemented as follows:
[0005] In a first aspect, embodiments of this application provide an on-chip resource protection method based on command queue reordering, including:
[0006] The on-chip sensor array collects the status signals of the computing unit, the access signals of the storage unit, and the bus arbitration signals of the hardware accelerator. Combined with the threat status code output by the hardware security state machine, the set of priority tags containing the resource contention identification field is generated by the logic gate combination processing of the on-chip combinational logic circuit.
[0007] The priority label set is input into the command priority comparator, and a hardware-level matching comparison is performed with the resource sensitivity threshold field stored in the on-chip register group to generate a command priority encoding field. The initial command queue is reordered by the priority encoder to obtain a weighted command queue with priority encoding field.
[0008] Based on the resource occupancy configuration information of commands in the weighted command queue with priority encoding field, the isolation barrier generation circuit is called to convert the arithmetic unit configuration information into lock cycle parameters, and the storage unit configuration information and bus interface configuration information into resource mask parameters. Parameterized isolation barriers are inserted between adjacent commands whose priority encoding field value is equal to the preset highest encoding value of the on-chip configuration register to obtain the isolation protection command queue.
[0009] The on-chip trajectory monitoring register group is started to perform real-time execution trajectory capture on the isolated protection command queue, generating an execution trajectory status sequence containing command execution order signals, arithmetic unit status signals, storage unit read / write signals, and bus transmission signals. The execution trajectory status sequence is compared with the security execution template stored in the on-chip read-only memory through hardware verification logic, and a level signal representing the resource protection status is output.
[0010] Secondly, embodiments of this application provide an on-chip resource protection device, comprising:
[0011] The signal acquisition module is used to acquire the arithmetic unit status signals, storage unit access signals and bus arbitration signals of the hardware accelerator through the on-chip sensor array. Combined with the threat status code output by the hardware security state machine, the signal is processed by the logic gates of the on-chip combinational logic circuit to generate a priority tag set containing a resource contention identifier field.
[0012] The priority encoding module is used to input the priority label set into the command priority comparator, perform hardware-level matching and comparison with the resource sensitivity threshold field stored in the on-chip register group, generate the command priority encoding field, and perform a reordering operation on the initial command queue through the priority encoder to obtain a weighted command queue with priority encoding field.
[0013] The command generation module is used to convert the arithmetic unit configuration information into lock cycle parameters, the storage unit configuration information and the bus interface configuration information into resource mask parameters, and insert parameterized isolation barriers between adjacent commands whose priority encoding field value is equal to the preset highest encoding value of the on-chip configuration register, based on the resource occupancy configuration information of the weighted command queue with priority encoding field.
[0014] The trajectory capture module is used to initiate the on-chip trajectory monitoring register group to perform real-time execution trajectory capture on the isolated protection command queue, generate an execution trajectory status sequence containing command execution sequence signals, arithmetic unit status signals, storage unit read / write signals and bus transmission signals, compare the execution trajectory status sequence with the security execution template stored in the on-chip read-only memory through hardware verification logic, and output a level signal representing the resource protection status.
[0015] Thirdly, embodiments of this application provide an electronic device, including:
[0016] Processor; and
[0017] A memory having a computer program stored thereon and coupled to the processor, wherein when the computer program is executed by the processor, the electronic device performs the method as described above.
[0018] Fourthly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, performs the on-chip resource protection method based on command queue reordering as described above.
[0019] This invention collects status signals from the arithmetic unit, access signals from the storage unit, and bus arbitration signals using an on-chip sensor array. Combined with threat status codes output from a hardware security state machine, these signals are processed by on-chip combinational logic circuits to generate a priority tag set containing a resource contention identifier field. This enables multi-dimensional collaborative perception of the chip's core resource operating status and security threats. Furthermore, hardware-level logic gate processing improves the real-time performance of resource contention risk assessment, providing accurate underlying decision-making basis for queue reordering. The priority tag set is input into a command priority comparator and compared with a resource sensitivity threshold field stored in the on-chip register set at the hardware level. This generates a command priority encoding field, which is then used to reorder the initial command queue using a priority encoder. This hardware-level real-time comparison enables accurate command priority decision-making, avoiding processing delays caused by software-level numerical comparisons, improving the efficiency and accuracy of command queue reordering, and ensuring that high-risk commands receive priority resource protection. The resource occupancy of commands in the weighted command queue with priority encoding fields is configured accordingly. The system uses an isolation barrier generation circuit to convert arithmetic unit configuration information into lock cycle parameters, and storage unit configuration information and bus interface configuration information into resource mask parameters. Parameterized isolation barriers are inserted between adjacent commands whose priority encoding field value equals the highest preset encoding value in the on-chip configuration register. This enables precise isolation protection for high-risk commands. By dynamically adjusting the lock cycle and resource mask of the isolation barriers, resource waste or insufficient protection caused by fixed isolation parameters is avoided, balancing resource protection needs with resource utilization efficiency. The system also initiates real-time execution trajectory capture of the isolation protection command queue using the on-chip trajectory monitoring register group. An execution trajectory status sequence is generated and compared with the secure execution template stored in the on-chip read-only memory using hardware verification logic. A level signal representing the resource protection status is output, enabling hardware-level real-time trajectory verification of the command execution process. This avoids verification delays and data tampering risks associated with software logging, ensuring the reliable operation of the on-chip resource protection mechanism and comprehensively improving the real-time performance, accuracy, and reliability of on-chip resource protection. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly described below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. The above and other objects, features, and advantages of this application will become clearer through the drawings. The same reference numerals indicate the same parts in all the drawings. The drawings are not intentionally drawn to scale to actual size; the focus is on illustrating the main points of this application.
[0021] Figure 1 The illustration shows a flowchart of an on-chip resource protection method based on command queue reordering provided in an embodiment of this application.
[0022] Figure 2 This illustration shows a schematic diagram of an on-chip resource protection device provided in an embodiment of this application. Detailed Implementation
[0023] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0024] It should be noted that similar reference numerals and letters in the following figures denote similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, relational terms such as "first," "second," etc., in the description of this application are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one…" does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0025] Furthermore, the term "and / or" in this application is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.
[0026] Please refer to Figure 1The method provided in this application embodiment may include the following steps S100~S400:
[0027] Step S100: Collect the arithmetic unit status signal, memory unit access signal and bus arbitration signal of the hardware accelerator through the on-chip sensor array, combine them with the threat status code output by the hardware security state machine, and generate a priority tag set containing a resource contention identifier field through the logic gate combination processing of the on-chip combinational logic circuit.
[0028] In this embodiment of the invention, the on-chip sensor array is a device integrated on the chip for sensing the states of different parts of the hardware accelerator, capable of acquiring real-time status information of key components of the hardware accelerator. The hardware accelerator is a hardware circuit designed to improve the execution efficiency of specific computing tasks, significantly accelerating the system's computation speed. The arithmetic unit status signal reflects the working status of the arithmetic unit, allowing the system to clearly understand whether the arithmetic unit is currently active and whether the computation task has been completed. The memory unit access signal indicates the operation status of the memory unit, including whether a read or write operation is being performed and whether the target address of the operation has been selected. The bus arbitration signal coordinates the competition for bus usage rights among multiple devices, ensuring that bus resources are reasonably allocated to each device that needs them. The hardware security state machine is a mechanism for detecting and assessing security threats faced by the hardware accelerator; the output threat status code represents the type of security threat currently faced by the hardware accelerator, such as arithmetic unit threats, memory unit threats, bus interface threats, and combined threats. The on-chip combinational logic circuit consists of logic gates used to perform logical operations and processing on various input signals. The resource contention flag field measures the likelihood of a command competing for resources with other commands during execution. The priority label set is a collection formed by binding the resource contention identifier field with the command index field. The command index field is used to uniquely identify the position of a command in the initial command queue.
[0029] Specifically, the on-chip sensor array begins operation, acquiring status signals related to the hardware accelerator's arithmetic units, memory units, and bus arbitration. For example, in a data encryption hardware accelerator, when an encryption task begins, the sensors acquire the arithmetic unit's enable and completion signals. If the enable signal is high, it indicates that the arithmetic unit has been activated and has begun executing encryption operations. During the operation, the sensors continuously monitor the completion signal, which goes high when the operation is complete. For memory unit access signals, when an encryption key needs to be read from the memory unit, the read enable signal goes high, and the address strobe signal goes high according to the key's address; the sensors acquire these signals. For bus arbitration signals, when multiple devices simultaneously request to use the bus, the request signal goes high, and the bus arbitrator arbitrates according to certain rules. If a device gains bus access, the authorization and response signals change accordingly; the sensors also acquire these signals.
[0030] Meanwhile, the hardware security state machine outputs a threat status code based on the operating status of the hardware accelerator. Next, the collected arithmetic unit status signals, memory access signals, bus arbitration signals, and threat status codes are input into the on-chip combinational logic circuit. In the on-chip combinational logic circuit, logical operations are performed on these signals through combinations of logic gates, such as AND gates, OR gates, and XOR gates, ultimately generating a resource contention flag field. Finally, the generated resource contention flag field is bound to the corresponding command index field to generate a priority tag set containing the resource contention flag field. For example, the resource contention flag field and the command index field can be combined by concatenating fields to form priority tags, which are then written sequentially to consecutive memory cells in the on-chip static random access memory according to the command index field order, thus obtaining the priority tag set.
[0031] Specifically, step S100 may include the following steps S110 to S160:
[0032] Step S110: Acquire the status signals of the computing units of the hardware accelerator through the on-chip sensor array. The computing unit status signals include computing enable signals and computing completion signals. The computing enable signal indicates whether the computing unit is in an active state, and the computing completion signal indicates whether the computing unit has completed the current computing operation.
[0033] For example, the on-chip sensor array focuses on acquiring the status signals of the computing units in the hardware accelerator. The computing unit is the core part of the hardware accelerator that performs specific computational operations. The computing enable signal is a key signal controlling the start of the computing unit's operation. When this signal is high, the computing unit is activated and begins computation according to a preset algorithm and data; when this signal is low, the computing unit is idle. The computation completion signal is used to inform the system whether the computing unit has completed the current computational task. When this signal is high, it indicates that the computation has ended; when this signal is low, it indicates that the computation is still in progress.
[0034] In practice, the sensors in the on-chip sensor array establish connections with the control circuit and status feedback circuit of the computing unit. When the hardware accelerator receives a computing task, the control circuit of the computing unit sets the computing enable signal to a high level. At this time, the sensor immediately detects the change in this signal and acquires it. During the computing unit's execution of the operation, the sensor continuously monitors the computing completion signal. For example, in a hardware accelerator for image edge detection, when edge detection is required for an image, the computing enable signal goes high, and the computing unit begins processing the image data. The sensor continuously checks the computing completion signal. When the computing unit completes the edge detection operation for all pixels, the computing completion signal goes high, and the sensor acquires this signal, thus completing the acquisition of the computing unit's status signal.
[0035] Step S120: Acquire the memory cell access signals of the hardware accelerator through the on-chip sensor array. The memory cell access signals include read enable signal, write enable signal and address strobe signal. The read enable signal indicates whether the memory cell performs a read operation, the write enable signal indicates whether the memory cell performs a write operation, and the address strobe signal indicates whether the target address of the memory cell is selected.
[0036] In this embodiment of the invention, the on-chip sensor array collects access signals from the memory cells of the hardware accelerator. The memory cell is a component in the hardware accelerator used to store data, and read / write operations on the memory cell are very frequent during the hardware accelerator's workflow. The read enable signal controls whether the memory cell performs a read operation. When this signal is high, the memory cell begins reading data from a specified address; when this signal is low, the memory cell does not perform a read operation. The write enable signal controls whether the memory cell performs a write operation. When this signal is high, the memory cell writes data to a specified address; when this signal is low, the memory cell does not perform a write operation. The address strobe signal determines the target address for the memory cell operation. When this signal is high, it indicates that the target address has been selected and read / write operations can be performed; when this signal is low, the target address has not been selected.
[0037] Specifically, the sensors in the on-chip sensor array are connected to the control circuitry and address decoding circuitry of the memory cells. For example, when audio data needs to be read from the memory cell for processing, the read enable signal goes high, and the address decoding circuit sets the corresponding address strobe signal high according to the storage address of the audio data. The sensors will detect these changes in both signals. When the processed audio data needs to be written back to the memory cell, the write enable signal goes high, and the address strobe signal changes accordingly based on the storage address. The sensors will also detect these signals. By acquiring these signals, the sensors can accurately obtain the access status information of the memory cells.
[0038] Step S130: Acquire the bus arbitration signal of the hardware accelerator through the on-chip sensor array. The bus arbitration signal includes a request signal, an authorization signal and a response signal. The request signal indicates whether the device requests the right to use the bus, the authorization signal indicates whether the bus arbitrator allows the device to use the bus, and the response signal indicates whether the device has received the bus authorization.
[0039] In this embodiment of the invention, the on-chip sensor array focuses on acquiring bus arbitration signals from the hardware accelerator. The bus is a communication channel connecting multiple devices. Multiple devices may simultaneously request to use the bus, thus requiring a bus arbitration mechanism for coordination. The request signal is a signal sent by a device to the bus arbitrator requesting to use the bus. When a device needs to use the bus for data transmission, the request signal goes high. The authorization signal is a signal from the bus arbitrator that determines whether a device is allowed to use the bus according to certain arbitration rules. If allowed, this signal goes high. The response signal is a signal fed back by the device after receiving authorization information from the bus arbitrator. If the device receives authorization, the response signal goes high.
[0040] The specific operation involves connecting the sensors in the on-chip sensor array to the device's bus request circuit, bus arbitrator, and bus response circuit. For example, in a multi-processor hardware accelerator system, when multiple processors simultaneously need to exchange data with external storage devices via the bus, each processor sets its request signal high. Upon receiving these request signals, the bus arbitrator arbitrates according to a preset arbitration algorithm (such as a priority algorithm). If a processor gains bus access, the bus arbitrator sends an authorization signal to that processor, which then sets its response signal high upon receiving the authorization signal. The sensors continuously monitor the changes in the request, authorization, and response signals to obtain relevant information about the bus arbitration.
[0041] Step S140: Call the hardware security state machine to output the threat status code. The threat status code represents the type of security threat currently faced by the hardware accelerator, including computing unit threats, storage unit threats, bus interface threats, and combined threats.
[0042] In this embodiment of the invention, the system invokes a hardware security state machine to output threat status codes. The hardware security state machine is a hardware-based state monitoring and evaluation mechanism that continuously monitors the operating status of the hardware accelerator and analyzes potential security threats. Threat status coding is a method of representing the type of security threat currently faced by the hardware accelerator; different coding values correspond to different threat types. A computation unit threat indicates potential attacks or abnormal situations that the computation unit may be subjected to, such as illegal instruction injection or incorrect computation results. A storage unit threat indicates potential security problems that the storage unit may face, such as data leakage or data tampering. A bus interface threat indicates potential attacks that the bus interface may be subjected to, such as bus eavesdropping or unauthorized device access. A composite threat indicates the simultaneous presence of multiple types of security threats.
[0043] Specifically, the hardware security state machine contains a series of monitoring and logic judgment circuits. For example, it monitors whether the input instructions of the arithmetic unit are legal; if an illegal instruction is detected, it determines that there is a threat to the arithmetic unit. It monitors whether the data read and write operations of the storage unit comply with security rules; if abnormal read and write behavior is found, it determines that there is a threat to the storage unit. It monitors whether there are any abnormalities in the communication data of the bus interface; if abnormal communication traffic or data format is detected, it determines that there is a threat to the bus interface. When the hardware security state machine detects a security threat, it generates and outputs a corresponding threat state code based on the threat type. For example, if an arithmetic unit threat is detected, the output is the code value representing the arithmetic unit threat; if both an arithmetic unit threat and a storage unit threat are detected simultaneously, the output is the code value representing the combined threat.
[0044] Step S150: Input the arithmetic unit status signal, memory unit access signal, bus arbitration signal and threat status code to the on-chip combinational logic circuit, and generate a resource contention flag field by sequentially performing logical multiplication operation of AND gate execution signal, logical addition operation of OR gate execution signal, and logical XOR operation of XOR gate execution signal. The resource contention flag field represents the degree of risk of resource contention between the command and other commands during the execution process.
[0045] For example, the on-chip combinational logic circuit receives arithmetic unit status signals, memory access signals, bus arbitration signals, and threat status codes as inputs. AND gates, OR gates, and XOR gates are basic logic gates used to perform logical multiplication, logical addition, and logical XOR operations, respectively. The resource contention flag field, obtained after logical operations on these input signals, measures the likelihood of a command competing with other commands for hardware resources (such as arithmetic units, memory units, buses, etc.) during execution.
[0046] In practice, various input signals are first fed into the on-chip combinational logic circuit. For example, in a video encoding hardware accelerator, the operation enable signal of the arithmetic unit and the arithmetic unit threat signal from the threat status encoding are input into an AND gate for logical multiplication. If the operation enable signal is high and an arithmetic unit threat exists, the AND gate outputs a high level, yielding an intermediate result. Next, the write enable signal of the memory unit and the memory unit threat signal from the threat status encoding are input into another AND gate for logical multiplication. Then, the bus arbitration request signal and the bus interface threat signal from the threat status encoding are input into a third AND gate for logical multiplication. The outputs of these three AND gates are input into an OR gate for logical addition, yielding a composite intermediate result. This composite intermediate result is then XORed with the composite threat signal from the threat status encoding into an XOR gate to obtain the core bit of the resource contention flag field. Simultaneously, the operation completion signal from the arithmetic unit status signal is inverted by a NOT gate and multiplied with the address strobe signal from the memory unit access signal into a fourth AND gate for logical multiplication, yielding the extended bit of the resource contention flag field. Ultimately, the resource contention identifier field consists of a core bit and an extension bit.
[0047] For example, step S151 may specifically include:
[0048] Step S151: Input the operation enable signal in the operation unit status signal and the operation unit threat signal in the threat status code into the first AND gate, perform logical multiplication operation, and output the operation threat intermediate signal.
[0049] This step involves inputting the operation enable signal from the operation unit status signal and the operation unit threat signal from the threat status code into the first AND gate. The logic of the AND gate is that the output signal is high only when both input signals are high. The operation enable signal indicates whether the operation unit is active, and the operation unit threat signal indicates whether the operation unit faces a security threat. By performing a logical multiplication operation on these two signals, it can be determined whether a threat exists simultaneously when the operation unit is active.
[0050] Specifically, in a hardware accelerator for graphics rendering, when a graphics rendering task begins, the operation enable signal goes high. If the hardware security state machine detects a threat to the arithmetic unit at this time, and the arithmetic unit threat signal is also high, then the output of the first AND gate, the intermediate arithmetic threat signal, will be high. If the operation enable signal is high, but there is no threat to the arithmetic unit, and the arithmetic unit threat signal is low, then the intermediate arithmetic threat signal will be low.
[0051] Step S152: Input the write enable signal in the storage cell access signal and the storage cell threat signal in the threat status code into the second AND gate, perform a logical multiplication operation, and output the storage threat intermediate signal.
[0052] In this embodiment of the invention, the write enable signal from the memory cell access signal and the memory cell threat signal from the threat status code are input into a second AND gate. The write enable signal controls whether the memory cell performs a write operation, and the memory cell threat signal indicates whether the memory cell faces a security threat. Through the logical multiplication operation of the AND gate, it can be determined whether a memory cell threat exists simultaneously when the memory cell performs a write operation.
[0053] For example, in a hardware accelerator for data storage, when new data needs to be written to a storage cell, the write enable signal goes high. If the hardware security state machine detects a threat to the storage cell at this time, such as a potential risk of data tampering, the storage cell threat signal goes high, and the output of the second AND gate, the storage threat intermediate signal, will also go high. If the write enable signal is high, but there is no storage cell threat, the storage cell threat signal goes low, and the storage threat intermediate signal will also go low.
[0054] Step S153: Input the request signal in the bus arbitration signal and the bus interface threat signal in the threat status code into the third AND gate, perform a logical multiplication operation, and output the bus threat intermediate signal.
[0055] This step involves inputting the request signal from the bus arbitration signal and the bus interface threat signal from the threat state code into the third AND gate. The request signal indicates whether a device requests to use the bus, and the bus interface threat signal indicates whether the bus interface faces a security threat. Through the logical multiplication operation of the AND gate, it can be determined whether a bus interface threat exists simultaneously when a device requests to use the bus. For example, in a multi-device communication hardware accelerator system, when a device needs to communicate with other devices via the bus, the request signal goes high. If the hardware security state machine detects a threat to the bus interface at this time, such as a potential risk of bus eavesdropping, the bus interface threat signal will be high, and the bus threat intermediate signal output by the third AND gate will be high; if the request signal is high but there is no bus interface threat, the bus interface threat signal will be low, and the bus threat intermediate signal will be low.
[0056] Step S154: Input the computational threat intermediate signal, the storage threat intermediate signal, and the bus threat intermediate signal into the OR gate, perform a logical addition operation, and output the composite threat intermediate signal.
[0057] This step inputs the previously obtained intermediate threats from the computation unit, storage unit, and bus interface into an OR gate. The logic of an OR gate is that if any one of the input signals is high, the output signal will also be high. Through the addition operation of the OR gate, the threat situations of the computation unit, storage unit, and bus interface can be comprehensively considered to obtain a composite threat intermediate signal. For example, in a hardware accelerator system, the computation unit may be threatened, resulting in a high-level computation threat intermediate signal, while the storage unit and bus interface may not be threatened, resulting in low-level storage and bus threat intermediate signals. In this case, the composite threat intermediate signal output by the OR gate will be high. The composite threat intermediate signal is high as long as any one of the three intermediate signals is high; it is low only when all three intermediate signals are low.
[0058] Step S155: Input the composite threat intermediate signal and the composite threat signal in the threat status code into the XOR gate, perform a logical XOR operation, and output the core bit of the resource contention identification field.
[0059] This step inputs the composite threat intermediate signal and the composite threat signal from the threat status code into an XOR gate. The logic of the XOR gate is that when the two input signals are different, the output signal is high; when the two input signals are the same, the output signal is low. The composite threat intermediate signal is a signal obtained by combining the threat situations from the arithmetic unit, storage unit, and bus interface. The composite threat signal in the threat status code represents the composite threat situation detected by the hardware security state machine. Through the XOR operation, the comprehensive situation of the composite threat can be further analyzed, and the core bit of the resource contention identification field can be output.
[0060] Step S156: The operation completion signal in the operation unit status signal is inverted by the NOT gate and input to the fourth AND gate along with the address strobe signal in the memory unit access signal. Logical multiplication is performed, and the extended bit of the resource contention identifier field is output. The resource contention identifier field consists of core bits and extended bits.
[0061] This step first inverts the operation completion signal from the arithmetic unit's status signals using a NOT gate. Then, the inverted signal and the address strobe signal from the memory access signal are input to the fourth AND gate. The NOT gate inverts the input signals, while the AND gate outputs a high signal only when both input signals are high. The operation completion signal indicates whether the arithmetic unit has completed its operation, and the address strobe signal indicates whether the target address of the memory unit has been selected. Through this logical operation, the extended bits of the resource contention flag field can be obtained. These extended bits, together with the core bits, constitute the resource contention flag field.
[0062] For example, in a data processing hardware accelerator, when the arithmetic unit has not yet completed its computation task, the computation completion signal is low, which becomes high after being inverted by a NOT gate. If the target address of the memory cell is selected at this time, the address strobe signal is high, and the extended bit of the resource contention flag field output by the fourth AND gate will be high. When the arithmetic unit completes its computation task, the computation completion signal is high, which becomes low after being inverted; regardless of the address strobe signal state, the extended bit remains low. Through the combination of the core bit and the extended bit, the resource contention flag field can more comprehensively reflect the risk of resource contention during command execution.
[0063] Step S160: Bind the resource contention identifier field with the corresponding command index field to generate a priority label set containing the resource contention identifier field. The command index field represents the position identifier of the command in the initial command queue.
[0064] In this embodiment of the invention, the previously generated resource contention identifier field needs to be bound to the command index field. The command index field is used to uniquely identify the position of a command in the initial command queue, which helps the system accurately locate each command. Through the binding operation, the resource contention risk of a command can be associated with the command itself, forming a priority tag set, which facilitates subsequent priority sorting and processing of commands.
[0065] In practice, the method for obtaining the command index field must first be clarified. In a hardware accelerator system, the initial command queue is typically stored in an on-chip command buffer. When reading commands from the on-chip command buffer, each command has a corresponding index field. For example, in an image processing hardware accelerator, the initial command queue contains a series of image processing commands, such as filtering, sharpening, and edge detection. Each command has a unique index, starting from 0 and incrementing sequentially.
[0066] Next, the resource contention flag field is bound to the command index field. This can be achieved through on-chip combinational logic circuitry. For example, the resource contention flag field can be used as the first field of the priority tag, and the command index field as the second field. Through circuit connections and signal processing, the two fields are combined to form a complete priority tag. Finally, the generated priority tags are written sequentially to contiguous storage cells in the on-chip static random access memory (SRAM) according to the order of the command index fields. The on-chip SRAM features fast read and write capabilities, meeting the system's data storage and access requirements. Storing priority tags in the order of the command index fields facilitates subsequent quick retrieval and processing of the corresponding priority tags by the system, thereby generating a set of priority tags containing the resource contention flag field.
[0067] For example, step S160 may specifically include the following steps:
[0068] Step S161: Read the command index field from the initial command queue from the on-chip command buffer. The command index field is used to uniquely identify each command in the initial command queue.
[0069] The on-chip command buffer is an area used to temporarily store the initial command queue. Command index fields are identifiers used to distinguish different commands in the initial command queue. When the hardware accelerator starts operating, these command index fields are first retrieved from the on-chip command buffer.
[0070] Specifically, the on-chip command buffer typically consists of multiple storage units, each storing a command and its related information, including a command index field. The hardware system reads the command index field from the command buffer in a specific order using dedicated read circuitry.
[0071] Step S162: The resource contention identifier field and the command index field are concatenated by the on-chip combinational logic circuit to obtain the priority label. The first field of the priority label is the resource contention identifier field, and the second field is the command index field.
[0072] On-chip combinational logic circuits are used to perform logical operations and combinations on input signals. In this embodiment of the invention, their function is to concatenate the resource contention identifier field and the command index field together to form a priority label.
[0073] In practice, the on-chip combinational logic circuit receives the resource contention flag field and the command index field as input. Internally, the circuit uses a series of logic gates and signal processing units to concatenate the two fields in a prescribed order. For example, the resource contention flag field is placed first as the first field of the priority label, representing the degree of resource contention risk of the command; the command index field is placed last as the second field of the priority label, indicating the command's position in the initial command queue.
[0074] Step S163: Write the priority tags sequentially into the contiguous storage cells of the on-chip static random access memory in the order of the command index field to obtain a priority tag set containing the resource contention identifier field.
[0075] On-chip static random access memory (SRAM) is a high-speed storage device used to store priority tags. In this embodiment of the invention, the previously concatenated priority tags need to be written sequentially into consecutive storage cells of the SRAM according to the order of the command index field.
[0076] In practice, the system sorts the priority tags according to the size of the command index field. For example, a priority tag with a command index field of 0 is written to the first memory cell of the SRAM, a priority tag with a command index field of 1 is written to the second memory cell, and so on. Based on this, a set of priority tags stored contiguously in the SRAM is formed.
[0077] Step S200: Input the priority tag set into the command priority comparator, perform hardware-level matching and comparison with the resource sensitivity threshold field stored in the on-chip register group, generate the command priority encoding field, and perform a reordering operation on the initial command queue through the priority encoder to obtain a weighted command queue with priority encoding field.
[0078] In this embodiment of the invention, the command priority comparator is a hardware circuit used to compare a priority label set and a resource sensitivity threshold field. An on-chip register set stores the resource sensitivity threshold fields, which represent the maximum allowed resource contention risk value for different resources. The priority of each command can be determined through hardware-level matching and comparison. The priority encoder then reorders the initial command queue based on the comparison results, generating a weighted command queue with priority encoding fields.
[0079] Specifically, the previously generated priority label set is first input to the parallel data input of the command priority comparator. Simultaneously, the resource sensitivity threshold field is read from the on-chip register set. For example, in a data processing hardware accelerator, the resource sensitivity threshold field includes arithmetic unit sensitivity thresholds, memory unit sensitivity thresholds, and bus interface sensitivity thresholds.
[0080] The command priority comparator compares the resource contention flag field in the priority tag set with these sensitivity thresholds. If the value of the resource contention flag field is greater than a certain sensitivity threshold, it indicates that the command has a high risk of contention on the corresponding resource and needs to be given a higher priority. Based on the comparison result, a command priority encoding field is generated, which represents the resource protection priority of the command.
[0081] The priority encoder reorders the initial command queue based on the command priority encoding field. It rearranges the commands in the initial command queue according to their priority levels, from highest to lowest, as represented by the priority encoding field. For example, commands with higher priority levels are placed first, and commands with lower priority levels are placed later. Finally, a corresponding command priority encoding field is appended to the storage location of each command, forming a weighted command queue with priority encoding fields.
[0082] For example, step S200 may specifically include the following steps:
[0083] Step S210: Read the priority tag set from the on-chip static random access memory, extract the resource contention identifier field from each priority tag, and input it to the parallel data input terminal of the command priority comparator.
[0084] The on-chip static random access memory (SRAM) stores the previously generated set of priority tags. In this embodiment of the invention, it is necessary to read these priority tag sets from the SRAM and extract the resource contention identifier field from them.
[0085] In practice, the system reads priority tags sequentially from consecutive SRAM memory cells using a specific read circuit. Then, using the circuit's signal processing capabilities, it extracts the resource contention flag from the priority tags. For example, in an image recognition hardware accelerator, the priority tag might be "110002," where "110" is the resource contention flag and "002" is the command index flag. The system would extract "110."
[0086] The extracted resource contention flag field is input to the parallel data input of the command priority comparator. The command priority comparator can receive multiple resource contention flag fields simultaneously for comparison, improving comparison efficiency. In this way, the necessary data is provided for subsequent hardware-level matching comparisons.
[0087] Step S220: Read the resource sensitivity threshold field from the on-chip register group. The resource sensitivity threshold field includes the arithmetic unit sensitivity threshold, the storage unit sensitivity threshold, and the bus interface sensitivity threshold. The arithmetic unit sensitivity threshold represents the maximum allowed resource contention risk value of the arithmetic unit, the storage unit sensitivity threshold represents the maximum allowed resource contention risk value of the storage unit, and the bus interface sensitivity threshold represents the maximum allowed resource contention risk value of the bus interface.
[0088] The on-chip register set is an area used to store system configuration information, including resource sensitivity threshold fields. These threshold fields correspond to different hardware resources and are used to measure the maximum allowable contention risk for those resources.
[0089] Specifically, the computation unit sensitivity threshold is set based on the performance and stability of the computation unit. If the resource contention flag field of a command exceeds this threshold in terms of the computation unit, it indicates a high risk of contention on the computation unit, which may affect its normal operation. For example, in a high-performance computing hardware accelerator, the computation unit sensitivity threshold may be set lower to ensure stable operation of the computation unit.
[0090] Storage cell sensitivity thresholds are set based on storage cell usage. If the resource contention flag field of a command exceeds this threshold for a storage cell, it may lead to data conflicts or access delays. For example, in a hardware accelerator for big data storage, the storage cell sensitivity threshold is set appropriately based on the storage cell's capacity and read / write speed. Bus interface sensitivity thresholds are set to ensure normal communication on the bus interface. If the resource contention flag field of a command exceeds this threshold for the bus interface, it may lead to bus communication congestion or data loss. For example, in a hardware accelerator system with multi-device communication, the bus interface sensitivity threshold is adjusted based on the bus bandwidth and load.
[0091] Step S230: The command priority comparator performs hardware-level matching comparisons between the resource contention identifier field and the arithmetic unit sensitivity threshold, the storage unit sensitivity threshold, and the bus interface sensitivity threshold, respectively, to generate a command priority encoding field, which represents the resource protection priority of the command.
[0092] The command priority comparator is a key hardware circuit whose main function is to compare the resource contention flag field with the resource sensitivity threshold. Through hardware-level matching and comparison, the contention risk of each command on different resources can be accurately determined, and the corresponding command priority encoding field can be generated.
[0093] The specific comparison process is as follows: For each resource contention flag field, the command priority comparator compares it with the computation unit sensitivity threshold, storage unit sensitivity threshold, and bus interface sensitivity threshold, respectively. For example, in a hardware accelerator for artificial intelligence computing, suppose the resource contention flag field is "1011", the computation unit sensitivity threshold is "0100", the storage unit sensitivity threshold is "1000", and the bus interface sensitivity threshold is "0110".
[0094] When the value of the resource contention flag field is greater than the computation unit sensitivity threshold, it indicates that the command has a high risk of contention on the computation unit, and the command priority comparator will output that the computation priority flag is valid. In the example above, "1011" is greater than "0100", so the computation priority flag will become valid.
[0095] When the value of the resource contention flag field is greater than the storage unit sensitivity threshold, the storage priority flag becomes valid. In this example, "1011" is greater than "1000", so the storage priority flag also becomes valid.
[0096] When the value of the resource contention flag field is greater than the bus interface sensitivity threshold, the bus priority flag will become valid. In this example, "1011" is greater than "0110", so the bus priority flag will also become valid.
[0097] Finally, the operation priority flag, storage priority flag, and bus priority flag are combined to form the command priority encoding field. Different combinations represent different priority levels, and the system can use this encoding field to sort commands according to resource protection priorities.
[0098] For example, step S230 may specifically include the following steps:
[0099] Step S231: When the value of the resource contention identifier field is greater than the sensitivity threshold of the arithmetic unit, the command priority comparator outputs the arithmetic priority identifier as valid.
[0100] In this embodiment of the invention, the command priority comparator compares the resource contention flag field and the computational unit sensitivity threshold. The computational unit sensitivity threshold is preset and represents the maximum allowed resource contention risk value for the computational unit.
[0101] Specifically, the command priority comparator contains a comparison circuit that compares the values of two input signals. For example, in a scientific computing hardware accelerator, the resource contention flag might be a binary value, such as "110," and the computational unit sensitivity threshold might be "100." The comparison circuit would determine that "110" is greater than "100," at which point the command priority comparator would set the computation priority flag to a valid state, typically represented by a high level. When the computation priority flag is valid, it indicates a high risk of resource contention on the computational unit, requiring higher priority protection. This ensures stable operation of the computational unit when processing the command, preventing computational errors or performance degradation due to resource contention.
[0102] Step S232: When the value of the resource contention identifier field is greater than the storage unit sensitivity threshold, the command priority comparator outputs the storage priority identifier bit as valid.
[0103] In this step, the command priority comparator compares the resource contention flag field with the storage cell sensitivity threshold. The storage cell sensitivity threshold is set based on the performance and usage requirements of the storage cell and represents the maximum allowable resource contention risk value for the storage cell.
[0104] For example, in a hardware accelerator for data storage and processing, the resource contention flag field is "1010," and the storage unit sensitivity threshold is "0111." The command priority comparator's comparison circuit determines that "1010" is greater than "0111," and at this point, it sets the storage priority flag to a valid state. When the storage priority flag is valid, it indicates that the command has a high risk of resource contention on the storage unit. The storage unit may face problems such as data conflicts and read / write latency; therefore, a higher priority needs to be given to the command to ensure the normal operation of the storage unit and the security of the data.
[0105] Step S233: When the value of the resource contention flag field is greater than the bus interface sensitivity threshold, the command priority comparator outputs that the bus priority flag is valid.
[0106] In this embodiment of the invention, the command priority comparator compares the resource contention flag field and the bus interface sensitivity threshold. The bus interface sensitivity threshold is set to ensure normal communication of the bus interface and represents the maximum allowable resource contention risk value for the bus interface.
[0107] For example, in a multi-device interconnected hardware accelerator system, the resource contention flag field is "111", and the bus interface sensitivity threshold is "101". The command priority comparator's comparison circuit will determine that "111" is greater than "101", thus setting the bus priority flag to a valid state. When the bus priority flag is valid, it indicates that the command has a high risk of resource contention on the bus interface. The bus may experience communication congestion, data loss, and other problems; therefore, a higher priority needs to be given to this command to ensure stable communication and reliable data transmission on the bus interface.
[0108] Step S234: Combine the operation priority flag bit, storage priority flag bit and bus priority flag bit into a command priority encoding field. Different combinations of the command priority encoding field represent different priority levels.
[0109] In the preceding steps, we have obtained the operation priority flag, the storage priority flag, and the bus priority flag. In this embodiment of the invention, these three flags need to be combined to form a command priority encoding field.
[0110] The specific combination method can be to arrange these three flag bits together in a certain order. For example, the operation priority flag bit can be placed in the highest bit, the storage priority flag bit in the middle bit, and the bus priority flag bit in the lowest bit. Based on this, different combinations represent different priority levels.
[0111] In a complex hardware accelerator system, assuming the computation priority flag is "1", the storage priority flag is "0", and the bus priority flag is "1", the combined command priority encoding field is "101". Different encoding values correspond to different priorities; for example, "111" might represent the highest priority, and "000" might represent the lowest priority. The system can sort commands and allocate resources based on this command priority encoding field, ensuring that high-priority commands are processed first, thereby improving the overall system's resource utilization efficiency and stability.
[0112] Step S240: Input the command priority encoding field into the priority encoder. The priority encoder performs a reordering operation on the commands in the initial command queue according to the command priority encoding field to generate a weighted command queue with priority encoding field.
[0113] A priority encoder is a hardware circuit used to reorder commands. It rearranges the commands in an initial command queue according to the input command priority encoding field to generate a weighted command queue with priority encoding fields.
[0114] The specific operation process is as follows: The priority encoder first receives the command priority encoding field. For example, in a multi-tasking hardware accelerator, there are multiple commands and their corresponding command priority encoding fields, such as "101", "010", "110", etc.
[0115] The priority encoder has internal decoding logic that generates a command selection signal based on the command priority encoding field. This signal indicates the order of commands in the initial command queue. For example, a command with a priority encoding field of "110" might be considered a high-priority command, and the priority encoder will generate a corresponding command selection signal to indicate that this command will be placed at the front of the reordered queue.
[0116] Then, commands are selected from the initial command queue based on the command selection signal. The selected commands are written to the on-chip First-In-First-Out (FIFO) memory in descending order of priority level as represented by the command priority encoding field. During the FIFO writing process, a corresponding command priority encoding field is appended to the storage location of each command.
[0117] Finally, a weighted command queue with a priority encoding field is formed in the on-chip FIFO. The commands in this queue are arranged from high to low priority, which facilitates the subsequent system to process and execute commands according to priority, thereby improving the system's resource protection and utilization efficiency.
[0118] For example, step S240 may specifically include the following steps:
[0119] Step S241: The priority encoder receives the command priority encoding field and generates a command selection signal through decoding logic. The command selection signal is used to indicate the order of the pending commands in the initial command queue.
[0120] The decoding logic of the priority encoder is one of its core functions. After receiving the command priority encoding field, it parses and processes these encodings to generate a command selection signal.
[0121] Specifically, the command priority encoding field is a binary code, with different encoded values representing different priority levels. The decoding logic inside the priority encoder determines the priority order of each command based on the magnitude and combination of the encoded values. For example, in a multimedia processing hardware accelerator, the command priority encoding field might be "100", "010", or "110". The decoding logic would determine that "110" has the highest priority and "010" has the lowest priority.
[0122] Based on this priority determination, the decoding logic generates corresponding command selection signals. These signals can be a set of binary signals indicating the order of commands to be selected in the initial command queue. For example, a command selection signal might be "001" for selecting the first command, "010" for selecting the second command, and "100" for selecting the third command. In this way, the priority encoder can accurately control the selection order of commands in the initial command queue, providing a basis for subsequent reordering operations.
[0123] Step S242: Select a command from the initial command queue according to the command selection signal, and write it into the on-chip first-in-first-out memory in descending order of priority level represented by the command priority encoding field.
[0124] In this embodiment of the invention, a corresponding command is selected from the initial command queue based on the command selection signal generated by the priority encoder. The initial command queue is stored in a certain storage area on the chip, and each command has its corresponding storage location.
[0125] For example, in a graphics processing hardware accelerator, the initial command queue contains multiple graphics processing commands, such as drawing triangles, drawing circles, drawing rectangles, etc. Based on the command selection signal, the system sequentially selects commands from the queue.
[0126] After a command is selected, it is written to the on-chip First-In-First-Out (FIFO) memory in descending order of priority level as indicated by the command priority encoding field. An on-chip FIFO is a storage device with first-in-first-out characteristics, ensuring that commands are processed sequentially in the order they are written.
[0127] Assume that commands with a priority encoding field of "110" have the highest priority, and commands with a priority encoding field of "010" have the lowest priority. The system will first write the commands with a priority encoding field of "110" to the first storage location of the FIFO, then write the next highest priority commands to the second storage location, and so on, until all commands have been written to the FIFO. Based on this, a command queue is formed in the FIFO, arranged from highest to lowest priority.
[0128] Step S243: Attach a corresponding command priority encoding field to each command storage location in the on-chip first-in-first-out memory to generate a weighted command queue with priority encoding fields.
[0129] After writing commands to the on-chip First-In-First-Out (FIFO) memory, a corresponding command priority encoding field needs to be appended to the storage location of each command. This is done so that subsequent processing units can clearly understand the priority information of each command.
[0130] In practice, when writing a command to the FIFO, the command priority encoding field corresponding to that command is also written to the adjacent storage area. For example, in a hardware accelerator for network data processing, each storage unit of the FIFO can be divided into two parts: one part is used to store the command itself, and the other part is used to store the command priority encoding field.
[0131] When the command "draw lines" is written to a storage cell in the FIFO, its corresponding command priority code field "011" is written to the adjacent location of that storage cell. Based on this, a weighted command queue with priority code fields is formed in the FIFO. Subsequent processing units, when reading commands from the FIFO, can obtain not only the specific content of the command but also its priority information, thereby processing and scheduling the commands appropriately according to their priority, improving the system's resource utilization efficiency and processing performance.
[0132] Step S300: Based on the resource occupancy configuration information of the commands in the weighted command queue with priority encoding field, call the isolation barrier generation circuit to convert the arithmetic unit configuration information into lock cycle parameters, convert the storage unit configuration information and bus interface configuration information into resource mask parameters, and insert parameterized isolation barriers between adjacent commands whose priority encoding field value is equal to the preset highest encoding value of the on-chip configuration register to obtain the isolation protection command queue.
[0133] In this embodiment of the invention, the weighted command queue with a priority encoding field contains the priority information and specific content of each command, as well as the resource usage configuration information of the command. The resource usage configuration information describes how the command occupies different resources, including the computing unit, storage unit, and bus interface.
[0134] The isolation barrier generation circuit is a dedicated hardware circuit for generating isolation barrier parameters. It processes the resource usage configuration information of commands, converting the arithmetic unit configuration information into a lock period parameter. The lock period parameter represents the duration of the isolation barrier, ensuring that resources are not occupied by other commands during that time period. It also converts the storage unit configuration information and bus interface configuration information into resource mask parameters. These resource mask parameters represent the range of hardware resources that the isolation barrier needs to lock, i.e., which resources cannot be accessed by other commands during the isolation period.
[0135] The on-chip configuration register stores a preset highest code value, which represents the highest priority command. The system selects commands whose priority code field value equals the preset highest code value as commands to be isolated. Parameterized isolation barriers containing lock cycle parameters and resource mask parameters are inserted between adjacent commands to be isolated. This avoids resource conflicts between high-priority commands, resulting in an isolated and protected command queue, improving system stability and resource utilization efficiency.
[0136] For example, step S300 may specifically include the following steps:
[0137] Step S310: Read the resource usage configuration information of each command from the weighted command queue with priority encoding field. The resource usage configuration information includes arithmetic unit configuration information, storage unit configuration information and bus interface configuration information. The arithmetic unit configuration information represents the command's usage of the arithmetic unit, the storage unit configuration information represents the command's usage of the storage unit, and the bus interface configuration information represents the command's usage of the bus interface.
[0138] The weighted command queue with a priority encoding field stores detailed information for each command, including resource usage configuration information. In this embodiment of the invention, the system reads the resource usage configuration information for each command from the queue.
[0139] The computation unit configuration information describes how a command uses the computation unit. For example, a command might need to continuously occupy the computation unit for multiple operations, or it might only need to use the computation unit for a specific time period. In a hardware accelerator for image filtering, a filtering command might require the computation unit to continuously perform filtering operations for a period of time; the computation unit configuration information records this time period and the specific requirements of the operation.
[0140] Storage unit configuration information describes how commands access storage units. A command may need to read data from a storage unit, write processed data to a storage unit, or perform both read and write operations simultaneously. In a hardware accelerator for data storage and processing, a data processing command may need to read data from a specific address in a storage unit, process it, and then write the result to another address. The storage unit configuration information records these addresses and the operation methods.
[0141] The bus interface configuration information describes how commands use the bus interface. A command may need to transmit data with external devices via the bus interface or exchange data between multiple internal modules. In a hardware accelerator system with multi-device communication, a communication command may need to transmit data with external sensors using the bus interface within a specific time period. The bus interface configuration information records this time period and the amount of data transmitted, among other information.
[0142] By reading this resource usage configuration information, the system can gain a comprehensive understanding of how each command uses different resources, providing a basis for generating subsequent isolation barrier parameters.
[0143] Step S320: Call the on-chip configuration register to read the preset highest encoding value, and filter out the commands in the weighted command queue with priority encoding field whose command priority encoding field value is equal to the preset highest encoding value as the commands to be isolated.
[0144] The on-chip configuration register stores a preset maximum encoding value, which is pre-set according to the system design and requirements, representing the highest priority command. In this embodiment of the invention, the system calls the on-chip configuration register to read this preset maximum encoding value.
[0145] The system then iterates through the weighted command queue with priority encoding fields, filtering out commands whose priority encoding field values equal the preset highest encoding value. These commands are considered to be of the highest priority, and to avoid resource conflicts between them, they need to be isolated; therefore, they are treated as commands to be isolated.
[0146] For example, in a complex multitasking hardware accelerator, the default highest encoding value is "111". The system checks the priority encoding field of each command in the weighted command queue and filters out commands with the encoding field "111". These commands may be critical commands that have a significant impact on system performance and stability, such as real-time data processing commands or emergency task processing commands. By filtering out these commands to be isolated, isolation barriers can be strategically inserted to ensure their stable execution without interference from other commands.
[0147] Step S330: Call the isolation barrier generation circuit, input the configuration information of the arithmetic unit of the command to be isolated into the lock cycle counter, and generate the lock cycle parameter of the parameterized isolation barrier. The lock cycle parameter represents the duration of the isolation barrier.
[0148] The isolation barrier generation circuit is a hardware circuit specifically designed for generating isolation barrier parameters. In this embodiment of the invention, the configuration information of the arithmetic unit for the command to be isolated is input into the lock cycle counter.
[0149] The lock cycle counter is a hardware module used to calculate time. The arithmetic unit configuration information of the command to be isolated contains information such as the time the command occupies the arithmetic unit. For example, an arithmetic command to be isolated may require the arithmetic unit to work continuously for 10 clock cycles. After this arithmetic unit configuration information is input into the lock cycle counter, the counter will generate lock cycle parameters based on this information.
[0150] The lock period parameter represents the duration of the isolation barrier. During this period, the computing unit is locked and cannot be used by other commands, ensuring the stable execution of the isolated command. In a high-performance computing hardware accelerator, for a critical scientific computing command, the computing unit configuration information indicates that the computing unit needs to operate continuously for 20 clock cycles. The lock period counter generates a lock period parameter lasting for 20 clock cycles based on this information. During these 20 clock cycles, the computing unit is isolated, and other commands cannot be used, thus ensuring the accuracy and stability of the command's computation result.
[0151] For example, step S330 may specifically include the following steps:
[0152] Step S331: Extract the operation execution cycle information from the operation unit configuration information of the command to be isolated. The operation execution cycle information represents the execution time of the command on the operation unit.
[0153] The configuration information of the computing unit for the command to be isolated includes multiple aspects, among which the computing execution cycle information is a crucial component. In this embodiment of the invention, the system extracts the computing execution cycle information from the computing unit configuration information.
[0154] The computation execution cycle information represents the time required for a command to be executed on the computation unit. For example, in a hardware accelerator for image processing, an image sharpening command may require the computation unit to perform a series of convolution operations, which take a certain amount of time to complete. This time is recorded in the computation unit configuration information and is extracted by the system.
[0155] The execution cycle information can be extracted by parsing specific fields of the computation unit configuration information. For example, the computation unit configuration information might be a binary code, where certain bits are specifically used to represent the computation execution cycle. The system will extract the computation execution cycle information from this code according to pre-defined rules. Based on this, the execution duration of the command to be isolated on the computation unit can be accurately determined, providing accurate data for subsequently generating lock cycle parameters.
[0156] Step S332: Load the operation execution cycle information into the initial value register of the locked cycle counter, and the locked cycle counter starts counting down from the initial value.
[0157] The initial value register of the locked cycle counter is a register used to store the initial count value. In this embodiment of the invention, the system loads the previously extracted operation execution cycle information into the initial value register.
[0158] For example, in a hardware accelerator for data encryption, the computation cycle information indicates that an encryption command requires the arithmetic unit to execute 15 clock cycles. The system loads this "15" into the initial value register of the lock cycle counter.
[0159] After being initialized, the lock cycle counter begins counting down from that initial value. The counter decrements by 1 every clock cycle. This allows the counter to accurately record the passage of time, providing a basis for generating accurate lock cycle parameters. By decrementing the count, the system can monitor the duration of the isolation barrier in real time, ensuring that the processing unit is locked within the specified time, preventing interference from other commands.
[0160] Step S333: When the count value of the lock cycle counter decreases to zero, the lock cycle end signal is output. The time interval from loading the initial value to outputting the lock cycle end signal is the lock cycle parameter of the parameterized isolation barrier.
[0161] The lock period counter continuously updates its count value as it decrements from its initial value. When the count value reaches zero, it indicates that the preset execution time has been reached.
[0162] At this point, the lock cycle counter outputs a lock cycle end signal. This signal indicates that the duration of the isolation barrier has ended, and the arithmetic unit can be used by other commands. The time interval from loading the initial value to outputting the lock cycle end signal is the lock cycle parameter of the parameterized isolation barrier.
[0163] For example, in a video encoding hardware accelerator, the initial value register loads an execution cycle information of 20, and the lock cycle counter decrements from 20. When the count reaches 0, a lock cycle end signal is output. These 20 clock cycles from loading the initial value "20" to outputting the end signal constitute the lock cycle parameter of the parameterized isolation barrier. This parameter ensures that the arithmetic unit is locked within these 20 clock cycles, allowing isolated commands to be executed stably, thus improving system resource protection and utilization efficiency.
[0164] Step S340: Input the storage unit configuration information and bus interface configuration information of the command to be isolated into the resource mask generator to generate the resource mask parameters of the parameterized isolation barrier. The resource mask parameters represent the range of hardware resources that the isolation barrier needs to lock.
[0165] The resource mask generator is a hardware circuit used to generate resource mask parameters. In this embodiment of the invention, it receives the storage unit configuration information and bus interface configuration information of the command to be isolated.
[0166] The storage cell configuration information for the command to be isolated describes the access method and scope of the storage cell for that command. For example, a command may need to access a specific address range of the storage cell, and the storage cell configuration information records these address ranges. The bus interface configuration information describes the usage method and scope of the bus interface for the command, such as using the bus interface for data transfer within a specific time period.
[0167] The resource mask generator generates resource mask parameters based on this information. A resource mask parameter is a binary code representing the range of hardware resources that the isolation barrier needs to lock. For example, a single bit of the resource mask parameter might correspond to a memory address. If that bit is "1", it means the memory address is locked during isolation and cannot be accessed by other commands; if that bit is "0", it means the memory address can be accessed by other commands. Similarly, other bits of the resource mask parameter might correspond to different channels or time periods of the bus interface. Through different combinations of codes, the range of hardware resources that the isolation barrier needs to lock can be precisely controlled, ensuring that the command to be isolated is not interfered with by the resources of other commands during execution.
[0168] Step S350: Insert parameterized isolation barriers containing locking cycle parameters and resource mask parameters between adjacent commands to be isolated to obtain an isolation protection command queue.
[0169] In the preceding steps, locking cycle parameters and resource mask parameters have been generated. In this embodiment of the invention, the system inserts parameterized isolation barriers containing these parameters between adjacent commands to be isolated.
[0170] For example, in a multitasking hardware accelerator, command A and command B to be isolated are two adjacent high-priority commands. After command A is executed, the system inserts a parameterized isolation barrier, which includes locking period parameters and resource mask parameters generated based on the resource usage configuration information of command A.
[0171] Within the time specified by the lock period parameters, corresponding hardware resources, such as arithmetic units, storage units, and bus interfaces, are locked according to the resource mask parameters. Based on this, during the isolation period, other commands cannot access these locked resources, thus avoiding resource conflicts.
[0172] By inserting parameterized isolation barriers between adjacent commands to be isolated, an isolated protection command queue is formed in the command queue. Commands in this queue are separated by isolation barriers, ensuring that high-priority commands can be executed stably, thus improving the resource protection and processing efficiency of the entire system.
[0173] Step S400: Start the on-chip trajectory monitoring register group to perform real-time execution trajectory capture on the isolation protection command queue, generate an execution trajectory status sequence containing command execution sequence signals, arithmetic unit status signals, storage unit read / write signals and bus transmission signals, compare the execution trajectory status sequence with the safe execution template stored in the on-chip read-only memory through hardware verification logic, and output a level signal representing the resource protection status.
[0174] The on-chip trajectory monitoring register group is a hardware module used for real-time monitoring of command execution trajectories. In this embodiment of the invention, the system activates this register group to capture the real-time execution trajectory of the isolated and protected command queue.
[0175] Command execution sequence signals record the order in which commands are executed in the queue, helping the system understand whether the command execution flow meets expectations. Arithmetic unit status signals reflect the working status of the arithmetic unit during command execution, such as whether it is in operation or whether the operation is complete. Memory unit read / write signals record the read / write operations of the memory unit during command execution, including the address and data being read / written. Bus transmission signals record the data transmission status of the bus during command execution, such as the amount of data transmitted and the transmission time.
[0176] By capturing these signals, an execution trajectory state sequence is generated. Hardware verification logic is a circuit used to compare the execution trajectory state sequence with the secure execution template. The on-chip ROM stores the secure execution template, which is a pre-defined command execution trajectory reference sequence without resource conflict risks.
[0177] The hardware verification logic compares the execution trajectory state sequence with the safe execution template. If the match meets preset conditions, it indicates that the command execution process complies with safety requirements, and the hardware verification logic outputs a high-level resource protection status signal. If the match does not meet preset conditions, it indicates that there may be resource conflicts or other security issues during command execution, and the hardware verification logic outputs a low-level resource protection status signal. In this way, the system can monitor the resource protection status in real time, ensuring stable system operation.
[0178] For example, step S400 may specifically include the following steps:
[0179] Step S410: Start the on-chip trajectory monitoring register group to collect in real time the command execution sequence signal, arithmetic unit status signal, storage unit read / write signal and bus transmission signal of the isolated protection command queue. The command execution sequence signal represents the actual execution order of the commands, the arithmetic unit status signal represents the state change of the arithmetic unit during command execution, the storage unit read / write signal represents the timing of the read / write operation of the storage unit during command execution, and the bus transmission signal represents the change of the bus transmission flow during command execution.
[0180] The on-chip trajectory monitoring register group is a hardware module specifically designed for monitoring and recording command execution trajectories. In this embodiment of the invention, the system activates this register group to begin operation.
[0181] For command execution order signals, the register set records the actual execution order of commands in the isolated command queue in real time. For example, in a multi-tasking hardware accelerator, if there are commands A, B, and C in the command queue, the register set records their actual execution order, such as executing command A first, then command B, and finally command C.
[0182] Regarding the arithmetic unit status signals, the register bank monitors the status changes of the arithmetic unit during command execution. When a command begins to use the arithmetic unit, the arithmetic unit status signal indicates that the arithmetic unit is in the operation state; when the operation is completed, the status signal indicates that the arithmetic unit is in the idle state. In a data processing hardware accelerator, when a data computation command begins execution, the arithmetic unit status signal changes from idle to operation state, and returns to idle state after the operation is completed. The register bank records these status changes.
[0183] The read / write signals of the storage unit record the timing of read and write operations during command execution. For example, when a command needs to read data from the storage unit for processing, the register set records the address and time of the data read; after processing, when the command needs to write the result back to the storage unit, the register set records the address and time of the data write.
[0184] Bus transmission signals record changes in bus throughput during command execution. When a command needs to transmit data via the bus, the bus transmission signals show an increase in bus throughput; when the transmission is complete, the throughput decreases. In a hardware accelerator system for multi-device communication, when a communication command transmits data to an external device via the bus, the bus transmission signals reflect the changes in throughput in real time. By acquiring these signals in real time, the on-chip trajectory monitoring register set can comprehensively record the execution trajectory of the isolated and protected command queue.
[0185] Step S420: The acquired command execution sequence signal, arithmetic unit status signal, storage unit read / write signal and bus transmission signal are sequentially written into the on-chip shift register group in chronological order to generate the execution trajectory status sequence.
[0186] An on-chip shift register set is a hardware circuit used for storing and transmitting data. In this embodiment of the invention, the system sequentially writes the previously acquired command execution sequence signal, arithmetic unit status signal, memory unit read / write signal, and bus transmission signal into the shift register set in chronological order.
[0187] Writing data in chronological order ensures that the execution trajectory state sequence accurately reflects the actual command execution process. For example, in a real-time data processing hardware accelerator, the command execution sequence signal is first acquired, indicating that command A has begun execution. Next, the arithmetic unit status signal is acquired, showing that the arithmetic unit has begun processing command A. Then, the memory unit read / write signal is acquired, recording the operation of command A reading data from the memory unit. These signals are written to the shift register group sequentially in chronological order.
[0188] Within the shift register set, data is shifted sequentially to form a continuous sequence. This generates an execution trajectory state sequence. This sequence contains information about each critical step in the command execution process, providing a basis for subsequent comparison with the safe execution template. By writing these signals into the shift register set in chronological order, the system can accurately record and save the command execution trajectory, facilitating subsequent analysis and verification.
[0189] Step S430: Read the secure execution template from the on-chip read-only memory. The secure execution template is a pre-stored command execution trajectory reference sequence without resource conflict risk.
[0190] On-chip read-only memory (ROM) is a storage device used to store fixed data. In this embodiment of the invention, the system reads a secure execution template from the on-chip ROM.
[0191] A safe execution template is a command execution trajectory reference sequence pre-stored in ROM, representing an ideal execution scenario without the risk of resource conflicts. This template is developed during the system design phase based on the performance and resource usage rules of the hardware accelerator.
[0192] For example, in a complex multitasking hardware accelerator, a secure execution template specifies the execution order of different commands, the usage time and method of arithmetic units, the timing of read and write operations on memory units, and the bus throughput. It is a carefully designed and verified sequence to ensure that no resource conflicts occur when commands are executed according to this template.
[0193] The system reads the safe execution template, providing a standard for subsequent comparison with the execution trajectory status sequence. By comparing the actual execution trajectory with this standard, it can determine whether the command execution process meets safety requirements, thereby promptly detecting and handling potential resource conflict issues.
[0194] Step S440: The execution trajectory state sequence is compared with the safe execution template by the state comparator in the hardware verification logic. When the matching degree between the execution trajectory state sequence and the safe execution template meets the preset conditions, a high-level resource protection status signal is output; when the matching degree does not meet the preset conditions, a low-level resource protection status signal is output.
[0195] The state comparator in the hardware verification logic is a key circuit used to compare the execution trajectory state sequence with the safe execution template. In this embodiment of the invention, the state comparator performs a detailed comparison of these two sequences.
[0196] The state comparator compares the execution trajectory state sequence bit by bit with the corresponding bits in the safe execution template. For example, it compares various components such as command execution sequence signals, arithmetic unit status signals, memory unit read / write signals, and bus transmission signals. During the comparison, the degree of match between the two is calculated.
[0197] Preset conditions are predetermined based on the system's security requirements and performance indicators. For example, preset conditions may stipulate that the matching rate between the execution trajectory state sequence and the safe execution template must reach more than 90% to be considered to meet the matching requirements.
[0198] When the matching degree between the execution trajectory state sequence and the safe execution template meets the preset conditions, it indicates that the command execution process complies with safety requirements and no obvious resource conflict has occurred. At this time, the state comparator will output a high-level resource protection status signal, indicating that the system's resource protection status is good.
[0199] When the matching degree does not meet the preset conditions, it indicates that there may be resource conflicts or other security issues during the command execution process. The status comparator will output a low-level resource protection status signal to remind the system to take corresponding measures, such as readjusting the command execution order or adding isolation barriers, to ensure the system's resource security and stable operation. In this way, the system can monitor the resource protection status in real time and promptly detect and handle potential security risks.
[0200] Please refer to Figure 2 This is a schematic diagram of the structure of the on-chip resource protection device 20 provided in this application, which may include:
[0201] The signal acquisition module 21 is used to acquire the arithmetic unit status signal, storage unit access signal and bus arbitration signal of the hardware accelerator through the on-chip sensor array, and combine them with the threat status code output by the hardware security state machine. The signal is then processed by the logic gate combination of the on-chip combinational logic circuit to generate a priority tag set containing a resource contention identifier field.
[0202] The priority encoding module 22 is used to input the priority label set into the command priority comparator, perform hardware-level matching and comparison with the resource sensitivity threshold field stored in the on-chip register group, generate the command priority encoding field, and perform a reordering operation on the initial command queue through the priority encoder to obtain a weighted command queue with priority encoding field.
[0203] The command generation module 23 is used to call the isolation barrier generation circuit to convert the arithmetic unit configuration information into lock cycle parameters, the storage unit configuration information and the bus interface configuration information into resource mask parameters, and insert parameterized isolation barriers between adjacent commands whose priority encoding field value is equal to the preset highest encoding value of the on-chip configuration register, so as to obtain an isolation protection command queue.
[0204] The trajectory capture module 24 is used to start the on-chip trajectory monitoring register group to perform real-time execution trajectory capture on the isolated protection command queue, generate an execution trajectory status sequence containing command execution sequence signals, arithmetic unit status signals, storage unit read / write signals and bus transmission signals, compare the execution trajectory status sequence with the security execution template stored in the on-chip read-only memory through hardware verification logic, and output a level signal representing the resource protection status.
[0205] The operating principle of the on-chip resource protection device 20 can be referred to the aforementioned method description, and will not be repeated here.
[0206] Another aspect of the present invention provides an electronic device for implementing embodiments of the present invention, which may include a bus, and a processor, memory, input devices (such as keyboard, mouse, sensor, etc.), output devices (such as display, printer, speaker, etc.), communication interfaces (such as parallel port, serial port, modem, network card, etc.) and other devices (such as detachable devices, drive devices, etc.) coupled to the bus.
[0207] The memory (such as ROM, PROM, EEPROM, RAM, SRAM, etc.) is used to store data and computer instructions or programs, including computer instructions or programs for implementing the methods described above. The processor is used to execute a series of actions specified by the computer instructions or programs, such as executing computer instructions or programs stored in the memory. When the processor executes the computer instructions or programs stored in the memory, it enables the computer system to implement embodiments of the methods described above, including... Figure 1 The steps are shown in the figure.
[0208] Another aspect of the present invention provides a computer-readable medium, including but not limited to: floppy disks, hard disks, magnetic tapes, other magnetic media, CD-ROMs, CDRWs, DVDs, other optical media, punched cards, other physical media, ROMs, PROMs, EEPROMs, RAMs, SRAMs, or other computer-readable media, as well as transmission media (such as coaxial cables, fiber optic cables, carrier waves, etc.). The computer-readable medium can be included in the aforementioned computer system or can be a separate, uninstalled medium. The computer-readable medium is used to carry computer instructions or programs, including computer instructions or programs for implementing the methods described above. When the computer instructions or programs in the computer-readable medium are read and executed by a processor (e.g., a processor in the aforementioned computer system), embodiments of the methods described above can be implemented (e.g., causing the aforementioned computer system to implement), including... Figure 1 The steps are shown in the figure.
[0209] Although the present invention has been described by way of preferred embodiments, it should be understood that the present invention is not limited to the embodiments described above and shown in the accompanying drawings, and those skilled in the art can make various changes and modifications without departing from the scope of the present invention.
Claims
1. A method for protecting on-chip resources based on command queue reordering, characterized in that, include: The on-chip sensor array collects the status signals of the computing unit, the access signals of the storage unit, and the bus arbitration signals of the hardware accelerator. Combined with the threat status code output by the hardware security state machine, the set of priority tags containing the resource contention identification field is generated by the logic gate combination processing of the on-chip combinational logic circuit. The priority label set is input into the command priority comparator, and a hardware-level matching comparison is performed with the resource sensitivity threshold field stored in the on-chip register group to generate a command priority encoding field. The initial command queue is reordered by the priority encoder to obtain a weighted command queue with priority encoding field. Based on the resource occupancy configuration information of commands in the weighted command queue with priority encoding field, the isolation barrier generation circuit is called to convert the arithmetic unit configuration information into lock cycle parameters, and the storage unit configuration information and bus interface configuration information into resource mask parameters. Parameterized isolation barriers are inserted between adjacent commands whose priority encoding field value is equal to the preset highest encoding value of the on-chip configuration register to obtain the isolation protection command queue. The on-chip trajectory monitoring register group is started to perform real-time execution trajectory capture on the isolated protection command queue, generating an execution trajectory status sequence containing command execution order signals, arithmetic unit status signals, storage unit read / write signals, and bus transmission signals. The execution trajectory status sequence is compared with the security execution template stored in the on-chip read-only memory through hardware verification logic, and a level signal representing the resource protection status is output.
2. The method as described in claim 1, characterized in that, The process involves acquiring the operational unit status signals, storage unit access signals, and bus arbitration signals of the hardware accelerator via an on-chip sensor array. This data, combined with the threat status code output by the hardware security state machine, is then processed by the logic gates of the on-chip combinational logic circuit to generate a priority tag set containing a resource contention identifier field. This set includes: The on-chip sensor array collects the status signals of the computing units of the hardware accelerator. The computing unit status signals include computing enable signals and computing complete signals. The computing enable signal indicates whether the computing unit is in an active state, and the computing complete signal indicates whether the computing unit has completed the current computing. The memory cell access signals of the hardware accelerator are acquired by an on-chip sensor array. The memory cell access signals include a read enable signal, a write enable signal, and an address strobe signal. The read enable signal indicates whether the memory cell is performing a read operation, the write enable signal indicates whether the memory cell is performing a write operation, and the address strobe signal indicates whether the target address of the memory cell is selected. The bus arbitration signal of the hardware accelerator is acquired by an on-chip sensor array. The bus arbitration signal includes a request signal, an authorization signal and a response signal. The request signal indicates whether the device requests bus access rights, the authorization signal indicates whether the bus arbitrator allows the device to use the bus, and the response signal indicates whether the device has received bus authorization. The hardware security state machine is invoked to output a threat status code, which represents the type of security threat currently faced by the hardware accelerator, including threats to computing units, storage units, bus interfaces, and combined threats. The arithmetic unit status signal, memory unit access signal, bus arbitration signal and threat status code are input to the on-chip combinational logic circuit. The logic multiplication operation of the AND gate execution signal, the logic addition operation of the OR gate execution signal, and the logic XOR operation of the XOR gate execution signal are sequentially passed to generate a resource contention identification field. The resource contention identification field represents the degree of risk of a command competing for resources with other commands during the execution process. The resource contention identifier field is bound to the corresponding command index field to generate a priority label set containing the resource contention identifier field. The command index field represents the position identifier of the command in the initial command queue.
3. The method as described in claim 2, characterized in that, The process involves inputting the arithmetic unit status signal, memory unit access signal, bus arbitration signal, and threat status code to the on-chip combinational logic circuit. These signals are then sequentially multiplied using AND gates, added using OR gates, and XORed using XOR gates to generate a resource contention flag field, including: The operation enable signal in the operation unit status signal and the operation unit threat signal in the threat status code are input into the first AND gate to perform a logical multiplication operation and output the operation threat intermediate signal; The write enable signal in the memory cell access signal and the memory cell threat signal in the threat status code are input into the second AND gate, and a logical multiplication operation is performed to output the memory threat intermediate signal. The request signal in the bus arbitration signal and the bus interface threat signal in the threat status code are input into the third AND gate, a logical multiplication operation is performed, and the bus threat intermediate signal is output. The computational threat intermediate signal, the storage threat intermediate signal, and the bus threat intermediate signal are input into an OR gate, a logical addition operation is performed, and the composite threat intermediate signal is output. The composite threat intermediate signal and the composite threat signal in the threat status code are input into an XOR gate to perform a logical XOR operation and output the core bit of the resource contention identification field. The operation completion signal in the operation unit status signal is inverted by the NOT gate and input to the fourth AND gate along with the address strobe signal in the memory unit access signal. A logical multiplication operation is performed, and the extended bits of the resource contention identifier field are output. The resource contention identifier field consists of core bits and extended bits.
4. The method as described in claim 3, characterized in that, The process of binding the resource contention identifier field with the corresponding command index field to generate a priority tag set containing the resource contention identifier field includes: Read the command index field from the initial command queue from the on-chip command buffer. The command index field is used to uniquely identify each command in the initial command queue. The resource contention identifier field and the command index field are concatenated by on-chip combinational logic circuits to obtain a priority label. The first field of the priority label is the resource contention identifier field, and the second field is the command index field. Priority tags are written sequentially to contiguous storage cells in the on-chip static random access memory according to the order of the command index field, resulting in a priority tag set containing a resource contention identifier field.
5. The method as described in claim 1, characterized in that, The process of inputting a set of priority labels into a command priority comparator, performing a hardware-level matching comparison with a resource sensitivity threshold field stored in the on-chip register set to generate a command priority encoding field, and then performing a reordering operation on the initial command queue through a priority encoder to obtain a weighted command queue with priority encoding fields includes: Read the priority tag set from the on-chip static random access memory, extract the resource contention identifier field from each priority tag, and input it to the parallel data input terminal of the command priority comparator; The resource sensitivity threshold field is read from the on-chip register group. The resource sensitivity threshold field includes the arithmetic unit sensitivity threshold, the storage unit sensitivity threshold, and the bus interface sensitivity threshold. The arithmetic unit sensitivity threshold represents the maximum allowable resource contention risk value of the arithmetic unit, the storage unit sensitivity threshold represents the maximum allowable resource contention risk value of the storage unit, and the bus interface sensitivity threshold represents the maximum allowable resource contention risk value of the bus interface. The command priority comparator performs hardware-level matching and comparison between the resource contention identifier field and the arithmetic unit sensitivity threshold, the storage unit sensitivity threshold, and the bus interface sensitivity threshold, respectively, to generate a command priority encoding field, which represents the resource protection priority of the command. The command priority encoding field is input into the priority encoder. The priority encoder performs a reordering operation on the commands in the initial command queue according to the command priority encoding field, generating a weighted command queue with priority encoding field.
6. The method as described in claim 5, characterized in that, The command priority comparator performs hardware-level matching comparisons between the resource contention identifier field and the arithmetic unit sensitivity threshold, the storage unit sensitivity threshold, and the bus interface sensitivity threshold, respectively, to generate a command priority encoding field, including: When the value of the resource contention flag field is greater than the sensitivity threshold of the arithmetic unit, the command priority comparator outputs the arithmetic priority flag as valid; When the value of the resource contention flag field is greater than the storage unit sensitivity threshold, the command priority comparator outputs that the storage priority flag is valid. When the value of the resource contention flag field is greater than the bus interface sensitivity threshold, the command priority comparator outputs the bus priority flag as valid. The operation priority flag, storage priority flag, and bus priority flag are combined into a command priority encoding field. Different combinations of the command priority encoding field represent different priority levels.
7. The method as described in claim 6, characterized in that, The step of inputting the command priority encoding field into the priority encoder, and the priority encoder performing a reordering operation on the commands in the initial command queue according to the command priority encoding field to generate a weighted command queue with priority encoding fields, includes: The priority encoder receives the command priority encoding field and generates a command selection signal through decoding logic. The command selection signal is used to indicate the order of the pending commands in the initial command queue. Commands are selected from the initial command queue according to the command selection signal and written to the on-chip first-in-first-out memory in descending order of priority level represented by the command priority encoding field. A corresponding command priority encoding field is attached to each command storage location in the on-chip first-in-first-out memory to generate a weighted command queue with priority encoding fields.
8. The method as described in claim 1, characterized in that, The process involves using the resource occupancy configuration information of commands in the weighted command queue with priority encoding fields. This includes calling an isolation barrier generation circuit to convert arithmetic unit configuration information into lock cycle parameters, and storage unit configuration information and bus interface configuration information into resource mask parameters. A parameterized isolation barrier is then inserted between adjacent commands whose priority encoding field value equals the preset highest encoding value of the on-chip configuration register, resulting in an isolated protection command queue. The resource usage configuration information of each command is read from the weighted command queue with priority encoding field. The resource usage configuration information includes arithmetic unit configuration information, storage unit configuration information and bus interface configuration information. The arithmetic unit configuration information represents the command's usage of the arithmetic unit, the storage unit configuration information represents the command's usage of the storage unit, and the bus interface configuration information represents the command's usage of the bus interface. The on-chip configuration register is called to read the preset highest encoding value, and commands whose command priority encoding field value is equal to the preset highest encoding value in the weighted command queue with priority encoding field are selected as commands to be isolated; The isolation barrier generation circuit is invoked, and the configuration information of the arithmetic unit of the command to be isolated is input into the lock cycle counter to generate the lock cycle parameter of the parameterized isolation barrier. The lock cycle parameter represents the duration of the isolation barrier. The storage unit configuration information and bus interface configuration information of the command to be isolated are input into the resource mask generator to generate the resource mask parameters of the parameterized isolation barrier. The resource mask parameters represent the range of hardware resources that the isolation barrier needs to lock. A parameterized isolation barrier containing locking cycle parameters and resource mask parameters is inserted between adjacent commands to be isolated to obtain an isolation protection command queue.
9. The method as described in claim 8, characterized in that, The isolation barrier generation circuit inputs the configuration information of the arithmetic unit of the command to be isolated into the lock cycle counter to generate the lock cycle parameters of the parameterized isolation barrier, including: Extract the execution cycle information from the configuration information of the computing unit of the command to be isolated. The execution cycle information represents the execution time of the command on the computing unit. The operation execution cycle information is loaded into the initial value register of the locked cycle counter, and the locked cycle counter starts counting down from the initial value; When the lock cycle counter counts down to zero, a lock cycle end signal is output. The time interval from loading the initial value to outputting the lock cycle end signal is the lock cycle parameter of the parameterized isolation barrier.
10. The method as described in claim 1, characterized in that, The on-chip trajectory monitoring register group performs real-time execution trajectory capture on the isolated protection command queue, generating an execution trajectory status sequence containing command execution order signals, arithmetic unit status signals, storage unit read / write signals, and bus transmission signals. The execution trajectory status sequence is compared with the secure execution template stored in the on-chip read-only memory using hardware verification logic, and a level signal representing the resource protection status is output, including: The on-chip trajectory monitoring register group is started to collect command execution sequence signals, arithmetic unit status signals, storage unit read / write signals and bus transmission signals in real time from the isolated protection command queue. The command execution sequence signal represents the actual execution order of the commands, the arithmetic unit status signal represents the state changes of the arithmetic unit during command execution, the storage unit read / write signal represents the timing of read / write operations of the storage unit during command execution, and the bus transmission signal represents the changes in bus transmission flow during command execution. The acquired command execution sequence signal, arithmetic unit status signal, storage unit read / write signal and bus transmission signal are sequentially written into the on-chip shift register group in chronological order to generate the execution trajectory status sequence; Read a secure execution template from the on-chip read-only memory. The secure execution template is a pre-stored command execution trajectory reference sequence without resource conflict risk. The execution trajectory state sequence is compared with the safe execution template by the state comparator in the hardware verification logic. When the matching degree between the execution trajectory state sequence and the safe execution template meets the preset conditions, a high-level resource protection status signal is output; when the matching degree does not meet the preset conditions, a low-level resource protection status signal is output.
11. An on-chip resource protection device, characterized in that, include: The signal acquisition module is used to acquire the arithmetic unit status signals, storage unit access signals and bus arbitration signals of the hardware accelerator through the on-chip sensor array. Combined with the threat status code output by the hardware security state machine, the signal is processed by the logic gates of the on-chip combinational logic circuit to generate a priority tag set containing a resource contention identifier field. The priority encoding module is used to input the priority label set into the command priority comparator, perform hardware-level matching and comparison with the resource sensitivity threshold field stored in the on-chip register group, generate the command priority encoding field, and perform a reordering operation on the initial command queue through the priority encoder to obtain a weighted command queue with priority encoding field. The command generation module is used to convert the arithmetic unit configuration information into lock cycle parameters, the storage unit configuration information and the bus interface configuration information into resource mask parameters, and insert parameterized isolation barriers between adjacent commands whose priority encoding field value is equal to the preset highest encoding value of the on-chip configuration register, based on the resource occupancy configuration information of the weighted command queue with priority encoding field. The trajectory capture module is used to initiate the on-chip trajectory monitoring register group to perform real-time execution trajectory capture on the isolated protection command queue, generate an execution trajectory status sequence containing command execution sequence signals, arithmetic unit status signals, storage unit read / write signals and bus transmission signals, compare the execution trajectory status sequence with the security execution template stored in the on-chip read-only memory through hardware verification logic, and output a level signal representing the resource protection status.
12. An electronic device, characterized in that, include: processor; as well as A memory having a computer program stored thereon and coupled to the processor, wherein when the computer program is executed by the processor, the electronic device performs the method as described in any one of claims 1-10.
13. A computer-readable storage medium, characterized in that, It stores a computer program, which, when executed by a processor, performs the on-chip resource protection method based on command queue reordering as described in any one of claims 1-10.