A neural network acceleration circuit and in-situ encryption circuit based on a memory array
Patent Information
- Application Number
- CN202610704642.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-21
- Publication Date
- 2026-09-11
AI Technical Summary
[0005]但是在实际实现的过程中,第一种方式的弊端在于在于三维异质集成的难度较高,且加密过程在本质上,还是需要密钥、原文在不同层的电路中进行通信,并不是完全的原位加密,且这种通信依然存在被侧信道攻击的风险;第二种方式的优势在于加密过程中,密钥和原文之间不存在数据通信,因此加密过程更加可靠,但其加密放在仅将本征的权重取相反值,因此加密的强度不够高,容易被攻击者通过穷举方式破解权重情况,影响芯片或数据安全
[0017] The beneficial effects of this embodiment are as follows: Each weight unit in this embodiment is connected in series with two switching transistors and is connected to its own current loop or an adjacent current loop through a control signal. This allows the neural network acceleration circuit to automatically encrypt the true weights when it does not receive the correct control signal. When an attacker uses a randomly guessed key to perform CIM operations, the equivalent weights obtained will differ greatly from the true weights, and the true results cannot be obtained. However, when the correct key is received, the key automatically and in its original position controls each weight unit to correctly connect to the corresponding current loop, thus achieving decryption on its own. Real-time weight calculation can be achieved without data communication and software assistance, resulting in higher encryption security and better data security.
Smart Images

Figure CN122733784A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of in-memory computing technology, and in particular to a neural network acceleration circuit based on a memory array, an in-situ encryption circuit, a driving method, and an electronic device. Background Technology
[0002] With the advent of the digital intelligence era, artificial intelligence technology has developed rapidly. The emergence of large language models has brought about innovative strategic applications such as generative artificial intelligence, general artificial intelligence, embodied intelligence, and brain-computer interfaces. However, behind this is the support of massive amounts of data that have enabled the popularization of artificial intelligence technology.
[0003] For artificial intelligence applications, data privacy and security have become crucial and pressing issues. Whether it's user's personal data or the weight parameters of AI models, both require specialized encryption protection. Common data encryption involves generating a root of trust in hardware, combined with software algorithms implemented offline. This method is inefficient, and both encryption and decryption processes are relatively cumbersome, hindering energy-efficient AI applications. Furthermore, this approach requires designing additional circuit modules in the chip hardware, such as encryption protocol circuits, key generation circuits, and key storage circuits, consuming significant on-chip resources and negatively impacting the integration and miniaturization of AI chips.
[0004] Existing implementation methods for on-chip in-situ encryption / decryption circuits mainly include three-dimensional heterogeneous stacking and planar heterogeneous integration. Figure 1 This diagram illustrates the structure of an in-situ encryption chip employing a three-dimensional heterogeneous stacking approach. It designs the key generation circuit (IGZO Gain Cell PUF), the artificial intelligence acceleration circuit (RRAM CIM Core), and the general-purpose logic control circuit (SiCMOS) using three separate hardware foundations. These are then integrated in three dimensions to form a complete 3D chip. The encryption of the acceleration circuit weights is achieved through inter-layer communication protocol circuits and the lowest-level general-purpose logic circuit. The in-situ encryption chip, with its planar heterogeneous integration design, incorporates a PUF array (physically unclonable) and a CIM array (in-memory computation) within the memory array. The encryption principle is as follows: in the CIM circuit, each storage weight cell is configured with a complementary cell. During encryption, the weights of the CIM circuit are selectively read using the key generated by the PUF array. When the key is 1, the intrinsic weight is read; when the key is 0, its complementary value is read. This method encrypts the intrinsic weights in the CIM.
[0005] However, in actual implementation, the first method has the disadvantage of being difficult to integrate in three dimensions, and the encryption process still requires the key and the original text to communicate in different layers of the circuit, which is not a completely in-situ encryption, and this communication is still at risk of being attacked by side channels. The advantage of the second method is that there is no data communication between the key and the original text during the encryption process, so the encryption process is more reliable. However, its encryption only takes the opposite value of the intrinsic weight, so the encryption strength is not high enough, and it is easy for attackers to crack the weight situation by exhaustive methods, which affects the security of the chip or data. Summary of the Invention
[0006] The purpose of this disclosure is to provide a neural network acceleration circuit, an in-situ encryption circuit, a driving method, and an electronic device based on a storage array, in order to solve the problems existing in the prior art.
[0007] The embodiments of this disclosure adopt the following technical solution: a neural network acceleration circuit based on a memory array, comprising: M*N memory cells, N input lines and M output lines; wherein M and N are both positive integers; each memory cell includes a weighting unit, a first switch and a second switch, one end of the weighting unit is connected to the input line corresponding to its row, the other end of the weighting unit is connected to the first electrode of the first switch and the second switch, the second electrode of the first switch is connected to the output line corresponding to its column, the second electrode of the second switch is connected to the output line corresponding to its adjacent column, the gate of the first switch is connected to a first control signal, the gate of the second switch is connected to a second control signal, and the first control signal and the second control signal are complementary signals.
[0008] In some embodiments, the system further includes: an M+1th column auxiliary storage cell and an M+1th output line, each of the auxiliary storage cells including a weighted auxiliary cell and a third transistor, one end of the weighted auxiliary cell being connected to the input line corresponding to its row, the other end of the weighted auxiliary cell being connected to the first electrode of the third transistor, the second electrode of the third transistor being connected to the M+1th output line, and the gate of the third transistor being connected to a third control signal.
[0009] In some embodiments, the first The second terminal of the second switch in the column storage cell is connected to the first On the output line, .
[0010] In some embodiments, the third switch is kept in the normally open state.
[0011] In some embodiments, the first switch, the second switch, and the third switch are all N-type transistors.
[0012] In some embodiments, the weighting unit and the weighting auxiliary unit are any one of ferroelectric transistors, magnetic tunnel junctions, and resistive switching memory units.
[0013] This disclosure also provides an in-situ encryption circuit, comprising at least: a key generation circuit for generating correct key information; a key readout circuit for generating an M*N bit first control signal sequence based on the correct key information, and generating a second control signal sequence based on the first control signal sequence; and a neural network acceleration circuit based on a storage array as described above, for adjusting the access status of each storage unit based on the first control signal sequence and the second control signal sequence to output the correct weight mapping relationship.
[0014] In some embodiments, the key generation circuit includes M*N arrayed physically non-clonable function units.
[0015] This disclosure also provides a driving method for the in-situ encryption circuit as described above, including: when decryption is required, driving the key generation circuit to output correct key information so that the neural network acceleration circuit outputs the correct weight mapping relationship according to the first control signal sequence and the second control signal sequence.
[0016] This disclosure also provides an electronic device that includes at least the in-situ encryption circuit described above.
[0017] The beneficial effects of this embodiment are as follows: Each weight unit in this embodiment is connected in series with two switching transistors and is connected to its own current loop or an adjacent current loop through a control signal. This allows the neural network acceleration circuit to automatically encrypt the true weights when it does not receive the correct control signal. When an attacker uses a randomly guessed key to perform CIM operations, the equivalent weights obtained will differ greatly from the true weights, and the true results cannot be obtained. However, when the correct key is received, the key automatically and in its original position controls each weight unit to correctly connect to the corresponding current loop, thus achieving decryption on its own. Real-time weight calculation can be achieved without data communication and software assistance, resulting in higher encryption security and better data security. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in one or more embodiments of this specification or in the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1This is a schematic diagram of an in-situ encryption chip structure using a three-dimensional heterogeneous stacking method in the prior art; Figure 2 This is a schematic diagram illustrating the relationship between the input and output of a fully connected neural network. Figure 3 This is a schematic diagram of the mapping circuit for a fully connected neural network. Figure 4 This is a circuit diagram of a neural network acceleration circuit based on a storage array in the first embodiment of this disclosure; Figure 5 This is a schematic diagram of the in-situ encryption circuit in the second embodiment of this disclosure. Detailed Implementation
[0020] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of this document.
[0021] For a fully connected neural network, the relationship between its input and output is as follows: Figure 2 As shown, where In is the input signal, O is the output signal, and wij is the weight value between neurons, the following weight mapping relationship can be obtained: O1 = In1 × w11 + In2 × w21; O2 = In1 × w12 + In2 × w22; O3 = In1 × w13 + In2 × w23; Mapping this neural network to a circuit is as follows Figure 3 The CIM circuit shown represents an input voltage V and an output current I. Using Kirchhoff's laws, the output current and the neural network output have the same mathematical relationship as follows: I1 = V1 / R11 + V2 / R21; I2 = V1 / R1² + V2 / R2²; I3 = V1 / R13 + V2 / R23; Therefore, the weights wij in a neural network are mapped to the reciprocal of the resistance in a circuit, i.e., the conductance, and there is a one-to-one correspondence. For an artificial intelligence model, the weights in the neural network represent its entire privacy and require encryption protection at the hardware level.
[0022] To address the problems of the prior art, the first embodiment of this disclosure provides a neural network acceleration circuit based on a memory array, namely a CIM circuit. This circuit includes M*N weight units, N input lines, and M output lines, where M and N are both positive integers. Figure 4 This diagram illustrates a specific implementation of the circuit in this embodiment, where M is 3 and N is 2, comprising a total of 6 memory cells 10, 2 input lines V1 and V2 arranged vertically, and 3 output lines I1 to I3 arranged horizontally. Specifically, each memory cell 10 includes a weighting unit R, a first switch M1, and a second switch M2. One end of the weighting unit R is connected to the input line corresponding to its row, and the other end of the weighting unit R is connected to the first electrode of the first switch M1 and the second switch M2. The second electrode of the first switch M1 is connected to the output line corresponding to its column, and the second electrode of the second switch M2 is connected to the output line corresponding to its adjacent column. The gate of the first switch M1 is connected to a first control signal G, and the gate of the second switch M2 is connected to a second control signal G'. The first control signal G and the second control signal G' are complementary signals.
[0023] In this embodiment, weight units R represent different weight values through different resistance settings, mapping the input value for weight calculation to an input voltage. The output result obtained by the weight mapping of the neural network is output from the output line in the form of current. For the CIM circuit of this embodiment, each weight unit R connects its output current to its own output line or an adjacent output line through complementary first control signal G and second control signal G', so that each weight unit can only output the correct weight mapping relationship when it receives the correct control signal sequence. When the front-end key generation circuit does not generate the correct key, even if an attacker can directly obtain the resistance value of each weight unit in the CIM circuit, they cannot know the correct mapping relationship between resistance and weight, resulting in a large difference between the obtained equivalent weight and the real weight, and thus failing to obtain the true network calculation result.
[0024] In some embodiments, the CIM circuit further includes an (M+1)th column auxiliary memory cell and an (M+1)th output line, wherein the auxiliary memory cell includes only a weighted auxiliary cell and its corresponding third transistor, such as Figure 4 As shown in Figures R14 and M14, one end of R14 is connected to the input line corresponding to its row, i.e., V1, and the other end of R14 is connected to the first terminal of M14. The second terminal of M14 is connected to the (M+1)th output line, i.e., I4, and the gate of M14 is connected to the third control signal G14. In actual implementation, the auxiliary storage unit can be a fixed-value resistor device with a fixed resistance value that is not controlled by the key; that is, the third transistor is normally kept in the on state.
[0025] Furthermore, considering the design of the auxiliary storage unit, and to facilitate weight mapping, this embodiment may limit the first... The second terminal of the second switch in the column storage cell is connected to the first On the output line, ,like Figure 4 The second electrode of M13' in the third column is connected to I4. If no edge auxiliary memory cell design is performed, the second electrode of the second switch transistor of the memory cell located at the boundary can be connected to the output line of its adjacent column. Each weighting unit and weight auxiliary unit in this embodiment can be implemented using any of the following devices, including but not limited to ferroelectric transistors, magnetic tunnel junctions, and resistive switching memory cells. In actual use, the resistance value of each weighting unit can be designed according to the connection of each transistor in the memory cell and the actual weight requirements, and the resistance value can be fixed by writing the resistance value using the corresponding type of device. Normally, the resistance value of the weighting unit remains unchanged after being fixed, but it can also be rewritten under specific circumstances according to actual needs to satisfy a new weight mapping relationship.
[0026] For ease of control, all switching transistors in this embodiment are implemented using N-type transistors. For example... Figure 4 The circuit shown can be encrypted using a 6-bit key, assuming the key is 110011. At this time, G11 (the first control signal in the first row, first column memory cell) is high, M11 (the first switch in the first row, first column memory cell) is turned on, and M11' (the second switch in the first row, first column memory cell) is turned off. R11 (the weight cell in the first row, first column memory cell) is connected to the I1 current loop. Similarly, R12, R21, and R22 are connected to the I2 current loop, R23 is connected to the I3 current loop, and R13, R14, and R24 are connected to the I4 current loop. The current expressions for the four output lines are then: I1 = V1 / R11; I2 = V1 / R1² + V2 / R2² + V2 / R2²; I3 = V2 / R23; I4 = V1 / R13 + V1 / R14 + V2 / R24; This relationship is used as the mapping relationship for the actual weights of the neural network. When the key circuit works correctly, the key automatically and in-situ controls the CIM circuit, thus achieving decryption on its own. Therefore, real-time encryption / decryption can be achieved without data communication or software assistance. When an attacker uses an incorrect key to operate the CIM circuit, they cannot obtain the correct calculation result. At the same time, the key is available immediately upon acquisition; the key circuit does not generate a key when power is off. Therefore, even if an attacker can directly obtain all the resistance values in the CIM circuit, they cannot know the correct mapping relationship between the resistance and the weights, thus providing encryption protection.
[0027] In this embodiment, each weight unit is connected in series with two switching transistors and is connected to its own current loop or an adjacent current loop via a control signal. This allows the neural network acceleration circuit to automatically encrypt the true weights when it does not receive the correct control signal. When an attacker uses a randomly guessed key to perform CIM operations, the equivalent weights obtained will differ greatly from the true weights, making it impossible to obtain the true results. However, when the correct key is received, the key automatically and in its original position controls each weight unit to correctly connect to the corresponding current loop, thus achieving decryption on its own. Real-time weight calculation can be achieved without data communication or software assistance, resulting in higher encryption security and better data security.
[0028] The second embodiment of this disclosure provides an in-situ encryption circuit, the schematic diagram of which is shown below. Figure 5 As shown, it includes at least: a key generation circuit 100 for generating correct key information; a key reading circuit 200 for generating an M*N bit first control signal sequence based on the correct key information, and generating a second control signal sequence based on the first control signal sequence; and a neural network acceleration circuit 300 based on a storage array provided in the first embodiment of this disclosure, for adjusting the access status of each storage unit according to the first control signal sequence and the second control signal sequence to output the correct weight mapping relationship.
[0029] Specifically, the key generation circuit 100 includes M*N arrayed Physically Unclonable Function (PUF) units, which output the correct key information, such as sequence 110011, when decryption is required. The key reading circuit 200 can be a voltage output type key reading circuit. It compares the key information output by the key generation circuit 100 with a preset threshold. If the level value corresponding to the current key information is greater than the preset threshold, it is considered that the key sequence outputs 1, and a first control signal is output to enable the first switch to conduct. If the level value corresponding to the current key information is less than the preset threshold, it is considered that the key sequence outputs 0, and a first control signal is output to keep the first switch off, forming a first control signal sequence. Based on the complementary relationship between the first control signal and the second control signal, a second control signal sequence that is inversely related to the first control signal sequence is formed. The neural network acceleration circuit 300 turns the corresponding switch on or off according to the level of the first control signal sequence and the second control signal sequence to achieve the correct mapping output of the weight value and complete the decryption.
[0030] It should be noted that the key generation circuit 100 and the key reading circuit 200 can be implemented based on conventional PUF circuits and comparison circuits. This embodiment does not limit their specific circuit design. As long as they can meet the corresponding functions, they can be used as the key generation circuit 100 and the key reading circuit 200 in this embodiment.
[0031] The in-situ encryption circuit proposed in this embodiment automatically encrypts the real weights when the key generation circuit is not working. When the key generation circuit is working, the key is automatically and in-situ controlled by the CIM circuit through the key reading circuit, thus achieving decryption on its own. Therefore, real-time encryption / decryption can be achieved without data communication and software assistance, ensuring the secure encryption of weight data while simplifying the chip structure.
[0032] Based on the same inventive concept, the third embodiment of this disclosure provides a driving method for the in-situ encryption circuit as described in the second embodiment, mainly including: when decryption is required, driving the key generation circuit to output the correct key information so that the neural network acceleration circuit outputs the correct weight mapping relationship according to the first control signal sequence and the second control signal sequence; and when decryption is not required, keeping the key generation circuit powered off, so that the real weight is automatically encrypted, so that when an attacker uses a randomly guessed key to perform decryption, the equivalent weight obtained by the attacker is greatly different from the real weight, and the real result cannot be obtained.
[0033] Based on the same inventive concept, the fourth embodiment of this disclosure provides an electronic device, which includes at least the in-situ encryption circuit described in the second embodiment of this disclosure.
[0034] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this disclosure, and are not intended to limit them. Although this disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this disclosure.
Claims
1. A memory array based neural network acceleration circuit, comprising: include: It has M*N storage units, N input lines, and M output lines; where M and N are both positive integers. Each of the memory cells includes a weighting unit, a first switching transistor, and a second switching transistor. One end of the weighting unit is connected to the input line corresponding to its row, and the other end of the weighting unit is connected to the first terminals of the first and second switching transistors. The second terminal of the first switching transistor is connected to the output line corresponding to its column, and the second terminal of the second switching transistor is connected to the output line corresponding to its adjacent column. The gate of the first switching transistor is connected to a first control signal, and the gate of the second switching transistor is connected to a second control signal. The first control signal and the second control signal are complementary signals.
2. The neural network acceleration circuit according to claim 1, characterized in that, Also includes: The M+1th column auxiliary storage cell and the M+1th output line, each of the auxiliary storage cells includes a weighted auxiliary cell and a third transistor. One end of the weighted auxiliary cell is connected to the input line corresponding to its row, and the other end of the weighted auxiliary cell is connected to the first electrode of the third transistor. The second electrode of the third transistor is connected to the M+1th output line, and the gate of the third transistor is connected to a third control signal.
3. The neural network acceleration circuit according to claim 2, characterized in that, No. The second terminal of the second switch in the column storage cell is connected to the first On the output line, .
4. The neural network acceleration circuit according to claim 2, characterized in that, The third switch is kept in the normally open state.
5. The neural network acceleration circuit according to claim 2, characterized in that, The first switch, the second switch, and the third switch are all N-type transistors.
6. The neural network acceleration circuit according to any one of claims 2 to 5, characterized in that, The weighting unit and the weighting auxiliary unit are any one of ferroelectric transistors, magnetic tunnel junctions, and resistive switching memory units.
7. An in-situ encryption circuit, characterized in that, At least including: A key generation circuit is used to generate correct key information; A key readout circuit is used to generate an M*N bit first control signal sequence based on the correct key information, and to generate a second control signal sequence based on the first control signal sequence. The neural network acceleration circuit based on a storage array as described in any one of claims 1 to 6 is used to adjust the access status of each storage cell according to the first control signal sequence and the second control signal sequence in order to output the correct weight mapping relationship.
8. The in-situ encryption circuit according to claim 7, characterized in that, The key generation circuit includes M*N arrayed physically non-clonable function units.
9. A driving method for an in-situ encryption circuit as described in claim 7 or 8, characterized in that, include: When decryption is required, the key generation circuit is driven to output the correct key information so that the neural network acceleration circuit can output the correct weight mapping relationship according to the first control signal sequence and the second control signal sequence.
10. An electronic device, characterized in that, It includes at least the in-situ encryption circuit as described in claim 7 or 8.