Secure and fast remote procedure calls for guest virtual machines
The solution addresses the challenge of secure and fast RPCs for GVMs by configuring the processor system to directly communicate with hardware components through RPC messages, while implementing selective RPC virtualization for control information to ensure security and reduce latency.
Patent Information
- Application Number
- PCT/CN2023/139116
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-15
- Publication Date
- 2025-06-19
AI Technical Summary
Existing technologies face challenges in providing secure and fast remote procedure calls (RPCs) for guest virtual machines (GVMs), which are essential for accessing hardware components while maintaining security and reducing latency.
The proposed solution involves a processor system configured to generate and send RPC messages from a GVM application to an RPC driver, which then passes the messages to a passthrough to set an interrupt for the hardware component, allowing direct communication with the hardware component while implementing security checks through RPC virtualization for control information.
This approach enables secure and fast RPCs for GVMs by reducing latency for data-related RPCs while maintaining high security standards through selective RPC virtualization for control information, thus ensuring efficient access to hardware components.
Smart Images

Figure CN2023139116_19062025_PF_FP_ABST
Abstract
Description
SECURE AND FAST REMOTE PROCEDURE CALLS FOR GUEST VIRTUAL MACHINESFIELD
[0001] Aspects of the present disclosure generally relate to device security. For example, aspects of the present disclosure relate to secure and fast remote procedure calls for a guest virtual machine (GVM) .
[0002] INTRODUCTION
[0003] Computing devices typically store sensitive data owned by users or enterprises, with firmware or operating system software on the computing devices owned by a computing device or secure module manufacturer. To help secure computing devices, the firmware or software may include security measures to protect against, e.g., removing brute force attack mitigations, disabling secure boot / trust boot, and / or loading other unauthenticated firmware or software on the computing devices. These security measures may extend to encompass the components of the computing device, such as the main processor, such as a central processing unit (CPU) , along with other processors, memories, and / or peripherals of the device.SUMMARY
[0004] The following presents a simplified summary relating to one or more aspects disclosed herein. Thus, the following summary should not be considered an extensive overview relating to all contemplated aspects, nor should the following summary be considered to identify key or critical elements relating to all contemplated aspects or to delineate the scope associated with any particular aspect. Accordingly, the following summary has the sole purpose to present certain concepts relating to one or more aspects relating to the mechanisms disclosed herein in a simplified form to precede the detailed description presented below.
[0005] Disclosed are systems, methods, apparatuses, and computer-readable media for device security. According to at least one illustrative example, an electronic device is provided. The electronic device, includes: a memory system; a hardware component; and a processor system coupled to the memory system and the hardware component. The processor system is configured to:generate, using an application executing on a virtual machine of the electronic device, a first remote procedure call (RPC) message for the hardware component; send, using the application, the first RPC message to an RPC driver of the virtual machine; send, using the RPC driver of the virtual machine, the first RPC message to a first passthrough of the hardware component to set an interrupt for the hardware component; and send the first RPC message to an RPC endpoint of the hardware component; wherein the hardware component is configured to: receive the first RPC message for processing by a hardware component application of the hardware component.
[0006] As another example, method for accessing a hardware component is provided. The method includes: generating, using an application executing on a virtual machine of an electronic device, a first remote procedure call (RPC) message for a hardware component; sending, using the application, the first RPC message to an RPC driver of the virtual machine; sending, using the RPC driver of the virtual machine, the first RPC message to a first passthrough of the hardware component to set an interrupt for the hardware component; sending the first RPC message to an RPC endpoint of the hardware component; and receiving the first RPC message for processing by a hardware component application of the hardware component.
[0007] In another example, a non-transitory computer-readable medium having stored thereon instructions is provided. The instructions, when executed by a processor system, cause the processor system to: generate, using an application executing on a virtual machine of an electronic device, a first remote procedure call (RPC) message for a hardware component; send, using the application, the first RPC message to an RPC driver of the virtual machine; send, using the RPC driver of the virtual machine, the first RPC message to a first passthrough of the hardware component to set an interrupt for the hardware component; send the first RPC message to an RPC endpoint of the hardware component; and receive the first RPC message for processing by a hardware component application of the hardware component.
[0008] As another example, an apparatus for accessing a hardware component is provided. The apparatus includes: means for generating, using an application executing on a virtual machine of an electronic device, a first remote procedure call (RPC) message for a hardware component; means for sending, using the application, the first RPC message to an RPC driver of the virtual machine; means for sending, using the RPC driver of the virtual machine, the first RPC message to a first passthrough of the hardware component to set an interrupt for the hardware component; means for sending the first RPC message to an RPC endpoint of the hardware component; and means for receiving the first RPC message for processing by a hardware component application of the hardware component.
[0009] Aspects generally include a method, apparatus, system, computer program product, non-transitory computer-readable medium, user equipment, base station, wireless communication device, and / or processing system as substantially described herein with reference to and as illustrated by the drawings and specification.
[0010] Aspects generally include a method, apparatus, system, computer program product, non-transitory computer-readable medium, user equipment, base station, wireless communication device, and / or processing system as substantially described herein with reference to and as illustrated by the drawings and specification.
[0011] The foregoing has outlined rather broadly the features and technical advantages of examples according to the disclosure in order that the detailed description that follows may be better understood. Additional features and advantages will be described hereinafter. The conception and specific examples disclosed may be readily utilized as a basis for modifying or designing other structures for carrying out the same purposes of the present disclosure. Such equivalent constructions do not depart from the scope of the appended claims. Characteristics of the concepts disclosed herein, both their organization and method of operation, together with associated advantages, will be better understood from the following description when considered in connection with the accompanying figures. Each of the figures is provided for the purposes of illustration and description, and not as a definition of the limits of the claims.
[0012] While aspects are described in the present disclosure by illustration to some examples, those skilled in the art will understand that such aspects may be implemented in many different arrangements and scenarios. Techniques described herein may be implemented using different platform types, devices, systems, shapes, sizes, and / or packaging arrangements. For example, some aspects may be implemented via integrated chip implementations or other non-module-component based devices (e.g., end-user devices, vehicles, communication devices, computing devices, industrial equipment, retail / purchasing devices, medical devices, and / or artificial intelligence devices) . Aspects may be implemented in chip-level components, modular components, non-modular components, non-chip-level components, device-level components, and / or system-level components. Devices incorporating described aspects and features may include additional components and features for implementation and practice of claimed and described aspects. For example, transmission and reception of wireless signals may include one or more components for analog and digital purposes (e.g., hardware components including antennas, radio frequency (RF) chains, power amplifiers, modulators, buffers, processors, interleavers, adders, and / or summers) . It is intended that aspects described herein may be practiced in a wide variety of devices, components, systems, distributed arrangements, and / or end-user devices of varying size, shape, and constitution.
[0013] Other objects and advantages associated with the aspects disclosed herein will be apparent to those skilled in the art based on the accompanying drawings and detailed description. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. The subject matter should be understood by reference to appropriate portions of the entire specification of this patent, any or all drawings, and each claim.
[0014] The foregoing, together with other features and aspects, will become more apparent upon referring to the following specification, claims, and accompanying drawings.BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The accompanying drawings are presented to aid in the description of various aspects of the disclosure and are provided solely for illustration of the aspects and not limitation thereof.
[0016] FIG. 1 illustrates an example implementation of a system-on-a-chip (SOC) , in accordance with some examples;
[0017] FIG. 2 is a block diagram illustrating a logical organization of process execution on a host device, in accordance with aspects of the present disclosure;
[0018] FIG. 3 is a logical diagram of a code flow for an RPC call for accessing an application executing on a hardware of a host device by an application of a GVM 300, in accordance with aspects of the present disclosure;
[0019] FIG. 4 is a logical diagram of a code flow for an RPC call for accessing an application executing on a hardware of a host device by an application of a GVM 400, in accordance with aspects of the present disclosure;
[0020] FIG. 5 is a flow diagram illustrating an example of a process 500 for communicating with a hardware component of a device, in accordance with aspects of the present disclosure; and
[0021] FIG. 6 is a block diagram illustrating an example of a computing system, in accordance with some examples.DETAILED DESCRIPTION
[0022] Certain aspects of this disclosure are provided below for illustration purposes. Alternate aspects may be devised without departing from the scope of the disclosure. Additionally, well-known elements of the disclosure will not be described in detail or will be omitted so as not to obscure the relevant details of the disclosure. Some of the aspects described herein may be applied independently and some of them may be applied in combination as would be apparent to those of skill in the art. In the following description, for the purposes of explanation, specific details are set forth in order to provide a thorough understanding of aspects of the application. However, it will be apparent that various aspects may be practiced without these specific details. The figures and description are not intended to be restrictive.
[0023] The ensuing description provides example aspects only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the example aspects will provide those skilled in the art with an enabling description for implementing an example aspect. It should be understood that various changes may be made in the function and arrangement of elements without departing from the scope of the application as set forth in the appended claims.
[0024] Aspects of the present disclosure address techniques to protect security for a common trusted application. In some cases, a trusted application may be accessed by multiple other client applications. For example, a trusted application may be accessed by a back-end application (e.g., a server application being executed by a server computing device) and multiple client applications may send requests to the back-end application. In some cases, trusted applications may be sand-boxed such that clients from other virtual machines (VMs) may not be able to directly access the trusted application. Instead, other applications may access the trusted application via a back-end application that may be running on a primary VM (PVM) or host computer. For example, the back-end application may be executing a separate VM and one or more client applications may be executing in other VMs.
[0025] In some examples, a first application executing in a VM, such as a GVM, may access a hardware component of a device to perform certain tasks. For example, an application may access a hardware component, such as digital signal processor (DSP) , neural processing unit (NPU) , graphic processing unit (GPU) , etc. to execute a machine learning (ML) model as the hardware component may be able to execute the ML model faster than a more general processor, such as a central processing unit (CPU) . In some cases, the application may use remote procedure call (RPC) messages to access the hardware component. Remote procedure calls may be a communications protocol that allows an application to access another application and / or hardware and RPC messages may operate using a client / server model.
[0026] In some cases, to increase security, the hardware component may be protected against potential malicious attacks. For example, applications executing in a GVM may be less trusted as compared to other applications executing on the host directly and RPC calls from an application executing in the GVM may be virtualized such that the RPC calls are passed, via a logical RPC address, into the host system via a hypervisor. This allows the hypervisor to inspect the RPC call for potential attacks. This RPC virtualization may result in some additional latency for the RPC calls and this latency can add up for certain applications executing on the hardware component, such as a ML model, which may use RPC to pass a substantial amount of data into the ML model for analysis by the ML model.
[0027] Systems, apparatuses, processes (also referred to as methods) , and computer-readable media (collectively referred to as “systems and techniques” ) are described herein for providing a secure and fast RPC for guest virtual machines. For example, a GVM, such as an operating system (OS) of a GVM, may include a GVM RPC driver for interfacing with an RPC system of a host device. A GVM application may pass an RPC message for a hardware component to the GVM RPC driver. The GVM RPC driver may then pass the RPC message to a passthrough of the host device (e.g., of the hardware component) . The passthrough may set an interrupt for the hardware component to alert the hardware component that an RPC message has arrived. The hardware component may then accept the RPC message from the passthrough. In some cases, the lower layer driver and / or GVM RPC driver may perform certain checks on the RPC message, such as consistency checks, buffer length checks, etc. In some cases, passing an RPC message directly from the GVM RPC driver to the passthrough may decrease latency as compared to the RPC virtualization. However, checking the RPC message using software of the GVM (e.g., GVM RPC driver) may offer less security as compared to security checks from software outside of the GVM, such as by a hypervisor, via the RPC virtualization.
[0028] To allow for both increased speed and a high level of security, it may be useful to recognize that not all RPC messages are as vulnerable to attack / have the same consequences if attacked. For example, RPC messages which include control information may be used by a hardware component to configure the hardware component. For example, the control information may direct the hardware component to initialize the hardware component, pass the ML model to the hardware component for execution, and / or initialize / deinitialize the ML model. As the control information may be used by the hardware component, the control information may be more vulnerable to attack and the consequences of such an attack may be more severe. In contrast, RPC messages which include data to be used by a hardware component application (e.g., application, such as a ML model, executing on the hardware component) may be less vulnerable to attack, with less severe consequences, as such data is passed to the hardware component application for use. In some cases, it may be useful to apply more security to RPC messages including control information such as by using RPC virtualization for RPC message including control information. For example, the GVM application may send an RPC message including control information to a first RPC virtualization layer of the RPC driver. The first RPC virtualization layer may then send the RPC message to a hypervisor associated with the virtual machine, and the hypervisor may send the RPC message to a host RPC endpoint via a second RPC virtualization layer to send the second RPC message to the passthrough associated with the hardware component.
[0029] As RPC messages with data may be less vulnerable to attack, it may be useful to pass the RPC message directly from the GVM RPC driver to the passthrough to allow for decreased latency. For example, an application executing on a GVM may generate an RPC message including data for an application executing on DSP. The RPC message may be sent via a GVM RPC interface to an RPC driver of the GVM. The RPC driver may send the RPC message to a lower layer multi-processor driver, which may write the RPC message to a shared memory location accessible to DSP. The lower layer multi-processor driver may also set an interrupt for the DSP. Once the interrupt is acknowledged by the DSP multi-processor driver, the driver on DSP may access the shared memory location to obtain the RPC message. The driver may then pass the RPC message to the RPC driver on DSP for processing the algorithm of the application.
[0030] As used herein, the phrase “based on” shall not be construed as a reference to a closed set of information, one or more conditions, one or more factors, or the like. In other words, the phrase “based on A” (where “A” may be information, a condition, a factor, or the like) shall be construed as “based at least on A” unless specifically recited differently.
[0031] The term “mobile device” is used herein to refer to any one or all of cellular telephones, smartphones, Internet-of-things (IOT) devices, personal or mobile multi-media players, laptop computers, tablet computers, ultrabooks, palm-top computers, wireless electronic mail receivers, multimedia Internet enabled cellular telephones, wireless gaming controllers, smart cars, autonomous vehicles, and similar electronic devices which include a programmable processor, a memory and circuitry for sending and / or receiving wireless communication signals to / from wireless communication networks. While the various embodiments are particularly useful in mobile devices, such as smartphones and tablets, the embodiments are generally useful in any electronic device that includes secure boot circuitry for securing access to the electronic device.
[0032] Various aspects of the techniques described herein will be discussed below with respect to the figures. FIG. 1. FIG. 1 illustrates an example implementation of a system-on-a-chip (SOC) 100, which may include a central processing unit (CPU) 102 or a multi-core CPU, configured to perform one or more of the functions described herein. Parameters or variables (e.g., neural signals and synaptic weights) , system parameters associated with a computational device (e.g., neural network with weights) , delays, frequency bin information, task information, among other information may be stored in a memory block associated with a neural processing unit (NPU) 108, in a memory block associated with a CPU 102, in a memory block associated with a graphics processing unit (GPU) 104, in a memory block associated with a digital signal processor (DSP) 106, in a memory block 118, and / or may be distributed across multiple blocks. Instructions executed at the CPU 102 may be loaded from a program memory associated with the CPU 102 or may be loaded from a memory block 118.
[0033] In some cases, the SOC 100 may be based on an ARM instruction set. The SOC 100 may also include additional processing blocks tailored to specific functions, such as a GPU 104, a DSP 106, a connectivity block 110, which may include fifth generation (5G) connectivity, fourth generation long term evolution (4G LTE) connectivity, Wi-Fi connectivity, USB connectivity, Bluetooth connectivity, and the like, and a multimedia processor 112 that may, for example, detect and recognize gestures. In one implementation, the NPU is implemented in the CPU 102, DSP 106, and / or GPU 104. The SOC 100 may also include a sensor processor 114, image signal processors (ISPs) 116, and / or a secure hardware module 120. The secure hardware module 120 may include fuses, replay protected memory block (RPMB) , secure bits, secure flags, security enabled hardware, secure memory, or hardware, software, or firmware used to implement a secure portion of the operating system, a secure operating system (SOS) , a trusted execution environment (TEE) , etc.
[0034] In some cases, virtual machines (VM) may be used to distribute computing resources to help enhance security by isolating one or more applications into a sandbox for execution. Additionally, VMs can be used to more efficiently utilize available computing resources. A VM may be a software version of a computer which can operate like a physical computer to run operating systems and other programs. In some cases, the VM may be allocated physical compute resources, such as from a physical computer and a single physical computer may run multiple VMs. In some examples, one or more VMs may be controlled by a hypervisor. The hypervisor may be software which runs and controls VMs.
[0035] In some cases, a hypervisor may be a type 1 hypervisor which does not need to be installed on a host operating system (OS) . In some cases, the hypervisor may be integrated with components typically found in an OS, such as those for interacting with hardware components. In some cases, the hypervisor may include a virtualized OS, referred to as a primary VM (PVM) , that may be used to access and / or control the hypervisor, or perform other operations. In some examples, the PVM may then host other VMs, such as guest VMs (GVMs) , as a hosted hypervisor. A VM executing on a computer, aside from the PVM, may be referred to as a guest VM (GVM) and the physical computer may be referred to as a host machine or device.
[0036] FIG. 2 is a block diagram illustrating a logical organization of process execution on a host device 200, in accordance with aspects of the present disclosure. As shown in FIG. 2, the host device 200 may include multiple processors including a CPU 202, and another processor, such as a DSP 204. Other processor examples may include a GPU, NPU, sensor processor, ISP, etc. The CPU 202 may include firmware 206 and possibly a secure monitor, such as a trusted execution environment, secure element, etc. The firmware 206 and secure element (if included) may operate at a highest privilege level (e.g., EL 3 in this example) of the CPU 202. The CPU 202 may also execute a host OS 208 at a next highest privilege level (e.g., EL2 in this example) . The host OS 208 may control a host application 214, which may execute at a relatively low privilege level (e.g., EL0 in this example) .
[0037] The host OS 208 may include a hypervisor 210, which may execute at a same or similar privilege level as the host OS 208. In some cases, the hypervisor 210 may control one or more VMs. In FIG. 4, the hypervisor 210 controls N GVMs, GVM 1 212A…GVM N 212N (collectively GVMs 212) . In some cases, the GVMs 212 may operate at a lower privilege level as compared to the hypervisor 210. The GVMs 212 may include a GVM OS, GVM OS 1 216A…GVM OS N 216N (collectively GVM OSs 216) . The GVM OSs 216 may be an OS local to a particular GVM and the GVM OSs 216 may control GVM applications, GVM 1 application 218A.... GVM application N 218N (collectively GVM applications 218) . In some cases, the GVM OSs 216 may execute at a privilege level (e.g., EL1 in this example) lower than the hypervisor 210, but greater than that of GVM applications 218. In some cases, the GVM applications 218 may execute at the same privilege level as the host application 214 (e.g., EL0 in this example) .
[0038] In some cases, the GVM applications 218 and / or host application 214 may access certain hardware, such as the DSP 204, of the host device to perform certain tasks. As an example, the host application 214 may execute a DSP application 220 on the DSP 204 in the context of a real time OS / firmware 222 of the DSP 204. Similarly, GVM application 1 218A may execute a DSP application 1 224 on the DSP 204, and GVM application N 218N may also execute a DSP application N 226 on the DSP 204. In some cases, a DSP application, such as DSP application 220 may be instructions and / or data that may be provided to and / or executed on the DSP 204. For example, the GVM application 218 may provide a machine learning (ML) model and data to the DSP 204. The DSP 204 may then execute the ML mode using the data provided by the GVM application 218 and then return results of the ML model. In some examples, the DSP 204 may be single threaded and execute a single application at a time. In some cases, the GVM applications 218 and / or host application 214 may access certain hardware of the host, such as the DSP 204, using remote procedure calls (RPCs) . An RPC may be a software communications protocol that allows software, such as a GVM 1 application 218A, to call other software and / or hardware of the host device 200, such as the DSP application 224 and / or DSP 204. In some cases, RPC may operate using a client / server model. While discussed in the context of the DSP 204, it should be understood that the DSP 204 is an example of hardware of a device that may be accessed by a CPU of the device using RPC messages and the techniques discussed herein may be applied to any other hardware of the host device that may be accessed using RPC calls.
[0039] In some cases, the GVMs 212, and associated GVM OSs 216 and GVM applications 218, may be considered at attack vector. Further, attacks on hardware of the host device via the GVMs 212 may prevent use of the hardware under attack by another applications. For example, if the DSP 204 is attacked via the GVM 1 application 218A and the DSP application 1 224, the DSP 204 may not be available for use by the host applications 214 and other GVM applications.
[0040] To help provide security to the hardware of the host device, such as the DSP 204, and to avoid potential limitations due to a shortage of interrupts, RPC virtualization may be used. For RPC virtualization, a GVM application, such as GVM 1 application 218A may place an RPC call with a GVM RPC system (not shown) to perform a task on hardware (e.g., DSP) of the host device using an application, such as the DSP application 1 224. The GVM RPC system may pass the RPC call to an RPC virtualization layer endpoint, which may virtualize certain RPC resources of the host device. The RPC virtualization layer may pass the RPC call to the hypervisor 210 which may then pass the RPC call to another RPC virtualization endpoint for the host device. The RPC cell from the RPC virtualization endpoint for the host device may then be received by an RPC system of the host device. The RPC system may indicate to a passthrough and / or inter-processor communications controller (IPCC) to send an interrupt to the DSP RPC system to indicate to the DSP that there is an RPC call for the DSP. In some cases, the passthrough / IPCC may write messages, such as the RPC call to a shared memory space and the IPCC may send the interrupt to the DSP RPC system to alert the DSP that there is a message for it in the shared memory space. After the DSP RPC picks up the RPC call, the RPC call may be passed to the DSP application 1 224. However, RPC virtualization may introduce latency issues as compared to RPC calls to the same non-CPU hardware from the host application 214 executing on the host OS 208. In some cases, a technique to reduce the latency for RPC calls to host hardware from a GVM application may be useful.
[0041] FIG. 3 is a logical diagram of a code flow for an RPC call for accessing an application executing on a hardware of a host device by an application of a GVM 300, in accordance with aspects of the present disclosure. In FIG. 3, a GVM application 302 may attempt to access the DSP using RPC calls to, for example, to execute (e.g., load, run, control, provide data to, etc. ) a DSP application 304, such as a ML model of the GVM application 302, on the DSP. In some cases, the GVM application 302 may send an RPC message to a GVM RPC interface 306. In some cases, the GVM RPC interface 306 may be an RPC interface accessible to applications executing in the GVM. The GVM RPC interface 306 may send the RPC request to a GVM RPC driver 308. In some cases, the GVM RPC driver 308 may be a driver executing as a part of an OS of the GVM and interfacing with the GVM RPC interface 306. For example, the GVM RPC driver 308 may execute in a kernel space (e.g., as a part of a kernel) of the GVM OS and the GVM RPC driver 308 may receive RPC messages via the GVM RPC interface 306, which executes in application space (e.g., at a privilege level for non-OS applications executing on the GVM) . The GVM RPC driver 308 may interface with a passthrough / IPCC 310 of the DSP RPC endpoint 312 and pass through the RPC request. The passthrough / IPCC 310 may then send an interrupt to the DSP RPC endpoint 312 to indicate to the DSP that there is an RPC call for the DSP. The DSP RPC endpoint 312 may then pass the RPC message to the appropriate procedure of the DSP, such as the DSP application 304. A process for sending RPC messages from the DSP application 304 to the GVM application 302 may be the reverse of sending an RPC message from the GVM application 302 to the DSP application 304.
[0042] In FIG. 3, RPC messages may be sent by the GVM application 302 to the DSP via the GVM RPC driver 308 without visualizing RPC resources, allowing for increased performance though reduced latency as RPC messages are not routed through the virtualization layer. However, RPC virtualization may allow RPC messages to be passed through to the host device via the hypervisor, allowing the RPC messages to inspected by the hypervisor to help avoid malicious RPC messages. In some cases, it may be useful to combine the use of the GVM RPC driver 308 with RPC virtualization to provide increased performance while maintaining security.
[0043] FIG. 4 is a logical diagram of a code flow for an RPC call for accessing an application executing on a hardware of a host device by an application of a GVM 400, in accordance with aspects of the present disclosure. As indicated in FIG. 4, RPC calls may be categorized based on a likelihood the RPC call can be used as an attack vector and how often the RPC call is made. For example, RPC calls for passing data that may be used by a process, such as a ML model, executing on a DSP may be relatively difficult to use as an attack vector for the DSP. For example, data for a ML model may be passed to the ML model for processing (e.g., as opposed to adjust settings of the DSP itself, initializing / uninitializing sessions, etc. ) and relatively simple cyclic redundancy checks (CRC) and buffer / length checks may be sufficient to provide security for data consumed by the process executing on the DSP. For example, the DSP and / or GVM RPC driver may perform CRC checks on the data before passing the data to the DSP application for use. Additionally, RPC calls for passing data may be sent very often and may make up nearly all transactions used for executing the process as compared to control information.
[0044] Control information may refer to RPC calls that may be used to configure a process on the DSP. For example, the RPC call may open / initialize the process on the DSP, close / uninitialize the process, and / or control (e.g., settings of) the process. For example, for a process such as a executing a ML model, the RPC messages including control information may be used to configure the DSP. For example, the control information may direct the DSP to initialize the DSP and / or pass the ML model to the DSP for execution. In some cases, such as for continuous object recognition / detection, an ML model may be initialized once and then data, such as images, may be continually streamed to and from the DSP using RPC messages so long the ML model is being used. Additionally, control information may be more likely to be an attack vector as the control information may be used directly by the DSP, for example, to set up the process, configure settings of the process and / or DSP, initialize a session, etc. In some cases, it may be useful to allow the control information to be more closely inspected by the host device (e.g., the hypervisor) for potentially malicious information.
[0045] In some cases, RPC calls for passing control information may be virtualized and passed through the host device (e.g., via the hypervisor) , while RPC calls for passing data may be passed by the GVM directly to an interface of the hardware of the host device. As an example, a GVM application 402 may generate an RPC control message including control information to setup a DSP application 420 for use by the GVM application 402. The GVM application 402 may pass the RPC control message to the GVM RPC interface 404. The GVM RPC interface 404 may determine that the RPC control message includes control information (e.g., based on the particular procedure being called) and pass the RPC control message to a first RPC virtualization layer 406 of a hybrid GVM RPC driver 408. The first RPC virtualization layer 406 may then pass the RPC control message to a hypervisor 410. The hypervisor 410 may be executing in the host system (e.g., in the host OS) or another VM (e.g., PVM) . In some cases, the hypervisor 410 may inspect the RPC control message for potentially malicious information. For example, the hypervisor 410 may perform one or more security verifications / checks on the RPC control message to help ensure that the RPC control message is not malicious. The hypervisor 410 may pass the RPC control message to a second RPC virtualization layer 412, which acts as a virtual RPC interface into the host device (e.g., a shared memory space and interrupt to a CPU) . The second RPC virtualization layer 412 may pass the RPC control message onto the host RPC endpoint 414 (e.g., an RPC endpoint of a CPU of the host device) . The host RPC endpoint 414 may pass the RPC control message to an interface / IPCC 2 416 (e.g., second interface) . In some cases, the host RPC endpoint 414 may pass the RPC control message via low level software driver (not shown for clarity) . For example, the host RPC endpoint 414 may send the RPC control message to the low level software driver, which may write the RPC control message to a shared memory and then the software driver may set an interrupt for the IPCC 2 416 to access the shared memory. The IPCC 2 416 may receive the RPC control message and pass the RPC control message including the control information to a DSP RPC endpoint 418 via another low level software driver, shared memory, and interrupt as described above (not shown for clarity) and on to the DSP. The DSP may use the control information to setup the DSP application 420 for the GVM application 402. Responding to the RPC control message by the DSP to the GVM application 402 may be the reverse of sending the RPC control message from the GVM application 420 to the DSP.
[0046] In some cases, RPC calls for passing data from the GVM application 402 to the DSP application 420 may be performed in a manner similar to that described above with respect to FIG. 3. For example, a GVM application 402 may generate an RPC data message for passing data, such as data to be used by a ML model, to the DSP application 420. The GVM application 402 may pass the RPC data message to the GVM RPC interface 404. The GVM RPC interface 404 may determine that the RPC data message includes data for the DSP application 420 (e.g., based on the particular procedure being called) and pass the RPC data message to a GVM RPC driver 422 of the hybrid GVM RPC driver 408. The GVM RPC driver 422 may pass the RPC data message from the GVM space to a passthrough / IPCC 424, via a low level software driver, shared memory, and interrupt as described above (not shown for clarity) . The passthrough / IPCC 424 may receive the RPC data message and the passthrough / IPC 424 may pass the RPC data message including the data (e.g., data for the ML model) to the DSP RPC 418 via another low level software driver, shared memory, and interrupt as described above (not shown for clarity) and on to the DSP application 420 (e.g., which may have been set up using RPC control message (s) ) . The DSP application 420 may receive the data and process the data. Responding to the RPC data message by the DSP application 420 to the GVM application 402 may be the reverse of sending the RPC data message from the GVM application 420 to the DSP application 420.
[0047] FIG. 5 is a flow diagram illustrating an example of a process 500 for communicating with a hardware component of a device, in accordance with aspects of the present disclosure. The process 500 may be performed by a wireless device or by a component (e.g., SOC 100 of FIG. 1, processor 610 of FIG. 6) or system (e.g., a chipset) of the wireless device (e.g., host device 200 of FIG. 2, computing system 600 of FIG. 6) . The electronic device may be a wireless device, such as computing system 600, or a UE (e.g., a mobile device such as a mobile phone, a network-connected wearable such as a watch, an extended reality device such as a virtual reality (VR) device or augmented reality (AR) device, a vehicle or component or system of a vehicle, or other type of UE) or other type of network node. In some examples, the process 500 may be performed by a UE. The operations of the process 500 may be implemented, in part, as software components that are executed and run on one or more processors (e.g., CPU 102 of FIG. 1, processor 510 of FIG. 6 or other processor (s) ) .
[0048] At block 502, the computing device (or component thereof) may generate, using an application (e.g., ML model, GVM 1 App 218A…GVM N App 218N of FIG. 2, GVM App 302 of FIG. 3, GVM App 402 of FIG. 4, etc. ) executing on a virtual machine (e.g., GVM 1 212A…GVM N 212N of FIG. 2) of the electronic device (e.g., host device 200 of FIG. 2) , a first remote procedure call (RPC) message for a hardware component (e.g., GPU 104, DSP 106, NPU 108 of FIG. 1, DSP 204 of FIG. 2, etc. ) . In some cases, the hardware component comprises hardware of the electronic device which is accessible by the processor system using RPC messages. In some examples, the hardware component comprises one of a digital signal processor (DSP) , neural processing unit (NPU) , or a graphics processing unit (GPU) . In some cases, the first RPC message comprises data for processing by the hardware component application. In some examples, the computing device (or component thereof) may generate, using the application, a second RPC message for the hardware component, the second RPC message including control information; send the second RPC message to a virtualized RPC resource (e.g., RPC virtualization layer 1 406 of FIG. 4) of the electronic device; and send, using the virtualized RPC resource, the second RPC message to a second interface of the hardware component to set an interrupt for the hardware component; and the hardware component is configured to: receive the second RPC message; and configure the hardware component application based on the control information in the second RPC message. In some cases, the control information comprises an RPC message, and the computing device (or component thereof) may at least initialize the hardware component application, uninitialize the hardware component application, or adjust a setting of the hardware component application. In some examples, the computing device (or component thereof) may send the second RPC message to the virtualized RPC resource by sending, using the application, the second RPC message to a first RPC virtualization layer (e.g., RPC virtualization layer 1 406 of FIG. 4) of the RPC driver; sending, using the first RPC virtualization layer, the second RPC message to a hypervisor (e.g., hypervisor 210 of FIG. 2, hypervisor 410 of FIG. 4, etc. ) associated with the virtual machine; and sending, using the hypervisor, the second RPC message to a host RPC endpoint (e.g., host RPC endpoint 414 of FIG. 4) via a second RPC virtualization layer, wherein the host RPC endpoint is configured to send the second RPC message to the second interface. In some cases, the hypervisor is configured to inspect the second RPC message for malicious information.
[0049] At block 504, the computing device (or component thereof) may send, using the application, the first RPC message to an RPC driver (e.g., GVM RPC Driver 308 of FIG. 3, hybrid GVM RPC Driver 408 of FIG. 4, etc. ) of the virtual machine. In some examples, the computing device (or component thereof) may perform a cyclic redundancy check on data in the first RPC message.
[0050] At block 506, the computing device (or component thereof) may send, using the RPC driver of the virtual machine, the first RPC message to a first passthrough (e.g., passthrough / IPCC 310 of FIG. 3, passthrough / IPCC 424 of FIG. 4, etc. ) of the hardware component to set an interrupt for the hardware component.
[0051] At block 508, the computing device (or component thereof) may send the first RPC message to an RPC endpoint (e.g., DSP RPC endpoint 312 of FIG. 3, DSP RPC endpoint 418 of FIG. 4, etc. ) of the hardware component.
[0052] At block 510, the computing device (or component thereof) may receive the first RPC message for processing by a hardware component application (e.g., DSP App for GVM 1 App 224…DSP App for GVM N App 226 of FIG. 2, DSP application 304 of FIG. 3, DSP application 420 of FIG. 4, etc. ) of the hardware component.
[0053] In some cases, the devices or apparatuses configured to perform the operations of the process 500 and / or other processes described herein may include a processor, microprocessor, microcomputer, or other component of a device that is configured to carry out the steps of the process 500 and / or other process. In some examples, such devices or apparatuses may include one or more sensors configured to capture image data and / or other sensor measurements. In some examples, such computing device or apparatus may include one or more sensors and / or a camera configured to capture one or more images or videos. In some cases, such device or apparatus may include a display for displaying images. In some examples, the one or more sensors and / or camera are separate from the device or apparatus, in which case the device or apparatus receives the sensed data. Such device or apparatus may further include a network interface configured to communicate data.
[0054] The components of the device or apparatus configured to carry out one or more operations of the process 500 and / or other processes described herein can be implemented in circuitry. For example, the components can include and / or can be implemented using electronic circuits or other electronic hardware, which can include one or more programmable electronic circuits (e.g., microprocessors, graphics processing units (GPUs) , digital signal processors (DSPs) , central processing units (CPUs) , and / or other suitable electronic circuits) , and / or can include and / or be implemented using computer software, firmware, or any combination thereof, to perform the various operations described herein. The computing device may further include a display (as an example of the output device or in addition to the output device) , a network interface configured to communicate and / or receive the data, any combination thereof, and / or other component (s) . The network interface may be configured to communicate and / or receive Internet Protocol (IP) based data or other type of data.
[0055] The process 500 is illustrated as a logical flow diagram, the operations of which represent sequences of operations that can be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, the operations represent computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations. Generally, computer-executable instructions include routines, programs, objects, components, data structures, and the like that perform particular functions or implement particular data types. The order in which the operations are described is not intended to be construed as a limitation, and any number of the described operations can be combined in any order and / or in parallel to implement the processes.
[0056] Additionally, the processes described herein (e.g., the process 500 and / or other processes) may be performed under the control of one or more computer systems configured with executable instructions and may be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) executing collectively on one or more processors, by hardware, or combinations thereof. As noted above, the code may be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program including a plurality of instructions executable by one or more processors. The computer-readable or machine-readable storage medium may be non-transitory.
[0057] In some examples, the processes described herein (e.g., process 500, and / or other process described herein) may be performed by a computing device or apparatus (e.g., a network node such as a UE, base station, a portion of a base station, etc. ) . For example, as noted above, one or more of the processes described herein (e.g., the process 500, and / or other process described herein) may be performed by a UE.
[0058] In some cases, the computing device or apparatus may include various components, such as one or more input devices, one or more output devices, one or more processors, one or more microprocessors, one or more microcomputers, one or more cameras, one or more sensors, and / or other component (s) that are configured to carry out the steps of processes described herein. In some examples, the computing device may include a display, one or more network interfaces configured to communicate and / or receive the data, any combination thereof, and / or other component (s) . The one or more network interfaces may be configured to communicate and / or receive wired and / or wireless data, including data according to the 3G, 4G, 5G, and / or other cellular standard, data according to the WiFi (802.11x) standards, data according to the BluetoothTM standard, data according to the Internet Protocol (IP) standard, and / or other types of data.
[0059] The components of the computing device may be implemented in circuitry. For example, the components may include and / or may be implemented using electronic circuits or other electronic hardware, which may include one or more programmable electronic circuits (e.g., microprocessors, graphics processing units (GPUs) , digital signal processors (DSPs) , central processing units (CPUs) , and / or other suitable electronic circuits) , and / or may include and / or be implemented using computer software, firmware, or any combination thereof, to perform the various operations described herein.
[0060] The process 500 is illustrated as a logical flow diagram, the operation of which represent a sequence of operations that may be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, the operations represent computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the recited operations. Generally, computer-executable instructions include routines, programs, objects, components, data structures, and the like that perform particular functions or implement particular data types. The order in which the operations are described is not intended to be construed as a limitation, and any number of the described operations may be combined in any order and / or in parallel to implement the processes.
[0061] Additionally, process 500 and / or other process described herein may be performed under the control of one or more computer systems configured with executable instructions and may be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) executing collectively on one or more processors, by hardware, or combinations thereof. As noted above, the code may be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program comprising a plurality of instructions executable by one or more processors. The computer-readable or machine-readable storage medium may be non-transitory.
[0062] FIG. 6 is a diagram illustrating an example of a system for implementing certain aspects of the present technology. In particular, FIG. 6 illustrates an example of computing system 600, which may be for example any computing device making up internal computing system, a remote computing system, a camera, or any component thereof in which the components of the system are in communication with each other using connection 605. Connection 605 may be a physical connection using a bus, or a direct connection into processor 610, such as in a chipset architecture. Connection 605 may also be a virtual connection, networked connection, or logical connection.
[0063] In some aspects, computing system 600 is a distributed system in which the functions described in this disclosure may be distributed within a datacenter, multiple data centers, a peer network, etc. In some aspects, one or more of the described system components represents many such components each performing some or all of the function for which the component is described. In some aspects, the components may be physical or virtual devices.
[0064] Example computing system 600 includes at least one processing unit (CPU or processor) 610 and connection 605 that communicatively couples various system components including system memory 625, such as read-only memory (ROM) 620 and random access memory (RAM) 625 to processor 610. Computing system 600 may include a cache 615 of high-speed memory connected directly with, in close proximity to, or integrated as part of processor 610.
[0065] Processor 610 may include any general-purpose processor and a hardware service or software service, such as services 632, 634, and 636 stored in storage device 630, configured to control processor 610 as well as a special-purpose processor where software instructions are incorporated into the actual processor design. Processor 610 may essentially be a completely self-contained computing system, containing multiple cores or processors, a bus, memory controller, cache, etc. A multi-core processor may be symmetric or asymmetric.
[0066] To enable user interaction, computing system 600 includes an input device 645, which may represent any number of input mechanisms, such as a microphone for speech, a touch-sensitive screen for gesture or graphical input, keyboard, mouse, motion input, speech, etc. Computing system 600 may also include output device 635, which may be one or more of a number of output mechanisms. In some instances, multimodal systems may enable a user to provide multiple types of input / output to communicate with computing system 600.
[0067] Computing system 600 may include communications interface 640, which may generally govern and manage the user input and system output. The communication interface may perform or facilitate receipt and / or transmission wired or wireless communications using wired and / or wireless transceivers, including those making use of an audio jack / plug, a microphone jack / plug, a universal serial bus (USB) port / plug, an AppleTM LightningTM port / plug, an Ethernet port / plug, a fiber optic port / plug, a proprietary wired port / plug, 3G, 4G, 5G and / or other cellular data network wireless signal transfer, a BluetoothTM wireless signal transfer, a BluetoothTM low energy (BLE) wireless signal transfer, an IBEACONTM wireless signal transfer, a radio-frequency identification (RFID) wireless signal transfer, near-field communications (NFC) wireless signal transfer, dedicated short range communication (DSRC) wireless signal transfer, 802.11 Wi-Fi wireless signal transfer, wireless local area network (WLAN) signal transfer, Visible Light Communication (VLC) , Worldwide Interoperability for Microwave Access (WiMAX) , Infrared (IR) communication wireless signal transfer, Public Switched Telephone Network (PSTN) signal transfer, Integrated Services Digital Network (ISDN) signal transfer, ad-hoc network signal transfer, radio wave signal transfer, microwave signal transfer, infrared signal transfer, visible light signal transfer, ultraviolet light signal transfer, wireless signal transfer along the electromagnetic spectrum, or some combination thereof. The communications interface 640 may also include one or more Global Navigation Satellite System (GNSS) receivers or transceivers that are used to determine a location of the computing system 600 based on receipt of one or more signals from one or more satellites associated with one or more GNSS systems. GNSS systems include, but are not limited to, the US-based Global Positioning System (GPS) , the Russia-based Global Navigation Satellite System (GLONASS) , the China-based BeiDou Navigation Satellite System (BDS) , and the Europe-based Galileo GNSS. There is no restriction on operating on any particular hardware arrangement, and therefore the basic features here may easily be substituted for improved hardware or firmware arrangements as they are developed.
[0068] Storage device 630 may be a non-volatile and / or non-transitory and / or computer-readable memory device and may be a hard disk or other types of computer readable media which may store data that are accessible by a computer, such as magnetic cassettes, flash memory cards, solid state memory devices, digital versatile disks, cartridges, a floppy disk, a flexible disk, a hard disk, magnetic tape, a magnetic strip / stripe, any other magnetic storage medium, flash memory, memristor memory, any other solid-state memory, a compact disc read only memory (CD-ROM) optical disc, a rewritable compact disc (CD) optical disc, digital video disk (DVD) optical disc, a blu-ray disc (BDD) optical disc, a holographic optical disk, another optical medium, a secure digital (SD) card, a micro secure digital (microSD) card, a Memory card, a smartcard chip, a EMV chip, a subscriber identity module (SIM) card, a mini / micro / nano / pico SIM card, another integrated circuit (IC) chip / card, random access memory (RAM) , static RAM (SRAM) , dynamic RAM (DRAM) , read-only memory (ROM) , programmable read-only memory (PROM) , erasable programmable read-only memory (EPROM) , electrically erasable programmable read-only memory (EEPROM) , flash EPROM (FLASHEPROM) , cache memory (e.g., Level 1 (L1) cache, Level 2 (L2) cache, Level 3 (L3) cache, Level 4 (L4) cache, Level 5 (L5) cache, or other (L#) cache) , resistive random-access memory (RRAM / ReRAM) , phase change memory (PCM) , spin transfer torque RAM (STT-RAM) , another memory chip or cartridge, and / or a combination thereof.
[0069] The storage device 630 may include software services, servers, services, etc., that when the code that defines such software is executed by the processor 610, it causes the system to perform a function. In some aspects, a hardware service that performs a particular function may include the software component stored in a computer-readable medium in connection with the necessary hardware components, such as processor 610, connection 605, output device 635, etc., to carry out the function. The term “computer-readable medium” includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other mediums capable of storing, containing, or carrying instruction (s) and / or data. A computer-readable medium may include a non-transitory medium in which data may be stored and that does not include carrier waves and / or transitory electronic signals propagating wirelessly or over wired connections. Examples of a non-transitory medium may include, but are not limited to, a magnetic disk or tape, optical storage media such as compact disk (CD) or digital versatile disk (DVD) , flash memory, memory or memory devices. A computer-readable medium may have stored thereon code and / or machine-executable instructions that may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or program statements. A code segment may be coupled to another code segment or a hardware circuit by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc., may be passed, forwarded, or transmitted via any suitable means including memory sharing, message passing, token passing, network transmission, or the like.
[0070] Specific details are provided in the description above to provide a thorough understanding of the aspects and examples provided herein, but those skilled in the art will recognize that the application is not limited thereto. Thus, while illustrative aspects of the application have been described in detail herein, it is to be understood that the inventive concepts may be otherwise variously embodied and employed, and that the appended claims are intended to be construed to include such variations, except as limited by the prior art. Various features and aspects of the above-described application may be used individually or jointly. Further, aspects may be utilized in any number of environments and applications beyond those described herein without departing from the broader scope of the specification. The specification and drawings are, accordingly, to be regarded as illustrative rather than restrictive. For the purposes of illustration, methods were described in a particular order. It should be appreciated that in alternate aspects, the methods may be performed in a different order than that described.
[0071] For clarity of explanation, in some instances the present technology may be presented as including individual functional blocks comprising devices, device components, steps or routines in a method embodied in software, or combinations of hardware and software. Additional components may be used other than those shown in the figures and / or described herein. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the aspects in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the aspects.
[0072] Further, those of skill in the art will appreciate that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the aspects disclosed herein may be implemented as electronic hardware, computer software, or combinations of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.
[0073] Individual aspects may be described above as a process or method which is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations may be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed, but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination may correspond to a return of the function to the calling function or the main function.
[0074] Processes and methods according to the above-described examples may be implemented using computer-executable instructions that are stored or otherwise available from computer-readable media. Such instructions may include, for example, instructions and data which cause or otherwise configure a general purpose computer, special purpose computer, or a processing device to perform a certain function or group of functions. Portions of computer resources used may be accessible over a network. The computer executable instructions may be, for example, binaries, intermediate format instructions such as assembly language, firmware, source code. Examples of computer-readable media that may be used to store instructions, information used, and / or information created during methods according to described examples include magnetic or optical disks, flash memory, USB devices provided with non-volatile memory, networked storage devices, and so on.
[0075] In some aspects the computer-readable storage devices, mediums, and memories may include a cable or wireless signal containing a bitstream and the like. However, when mentioned, non-transitory computer-readable storage media expressly exclude media such as energy, carrier signals, electromagnetic waves, and signals per se.
[0076] Those of skill in the art will appreciate that information and signals may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof, in some cases depending in part on the particular application, in part on the desired design, in part on the corresponding technology, etc.
[0077] The various illustrative logical blocks, modules, and circuits described in connection with the aspects disclosed herein may be implemented or performed using hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof, and may take any of a variety of form factors. When implemented in software, firmware, middleware, or microcode, the program code or code segments to perform the necessary tasks (e.g., a computer-program product) may be stored in a computer-readable or machine-readable medium. A processor (s) may perform the necessary tasks. Examples of form factors include laptops, smart phones, mobile phones, tablet devices or other small form factor personal computers, personal digital assistants, rackmount devices, standalone devices, and so on. Functionality described herein also may be embodied in peripherals or add-in cards. Such functionality may also be implemented on a circuit board among different chips or different processes executing in a single device, by way of further example.
[0078] The instructions, media for conveying such instructions, computing resources for executing them, and other structures for supporting such computing resources are example means for providing the functions described in the disclosure.
[0079] The techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices such as general purposes computers, wireless communication device handsets, or integrated circuit devices having multiple uses including application in wireless communication device handsets and other devices. Any features described as modules or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be realized at least in part by a computer-readable data storage medium comprising program code including instructions that, when executed (e.g., by a processor, one or more processors, a processor system, etc. ) , performs one or more of the methods, algorithms, and / or operations described above. The computer-readable data storage medium may form part of a computer program product, which may include packaging materials. The computer-readable medium and / or memory system may comprise any memory or data storage media, such as random access memory (RAM) such as synchronous dynamic random access memory (SDRAM) , read-only memory (ROM) , non-volatile random access memory (NVRAM) , electrically erasable programmable read-only memory (EEPROM) , FLASH memory, magnetic or optical data storage media, and the like and the computer-readable medium / memory system may include multiple memories or data storage media. The techniques additionally, or alternatively, may be realized at least in part by a computer-readable communication medium that carries or communicates program code in the form of instructions or data structures and that may be accessed, read, and / or executed by a computer, such as propagated signals or waves.
[0080] The program code may be executed by a processor system, which may include one or more processors, such as one or more digital signal processors (DSPs) , general purpose microprocessors, an application specific integrated circuits (ASICs) , field programmable logic arrays (FPGAs) , or other equivalent integrated or discrete logic circuitry. Such a processor system may be configured to perform any of the techniques described in this disclosure. A general-purpose processor may be a microprocessor; but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor system may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Accordingly, the term “processor” and / or “processor system, ” as used herein may refer to any of the foregoing structure, any combination of the foregoing structure, or any other structure or apparatus suitable for implementation of the techniques described herein.
[0081] One of ordinary skill will appreciate that the less than ( “<” ) and greater than ( “>” ) symbols or terminology used herein may be replaced with less than or equal to ( “≤” ) and greater than or equal to ( “≥” ) symbols, respectively, without departing from the scope of this description.
[0082] Where components are described as being “configured to” perform certain operations, such configuration may be accomplished, for example, by designing electronic circuits or other hardware to perform the operation, by programming programmable electronic circuits (e.g., microprocessors, or other suitable electronic circuits) to perform the operation, or any combination thereof.
[0083] The phrase “coupled to” or “communicatively coupled to” refers to any component that is physically connected to another component either directly or indirectly, and / or any component that is in communication with another component (e.g., connected to the other component over a wired or wireless connection, and / or other suitable communication interface) either directly or indirectly.
[0084] Claim language or other language reciting “at least one of” a set and / or “one or more” of a set indicates that one member of the set or multiple members of the set (in any combination) satisfy the claim. For example, claim language reciting “at least one of A and B” or “at least one of A or B” means A, B, or A and B. In another example, claim language reciting “at least one of A, B, and C” or “at least one of A, B, or C” means A, B, C, or A and B, or A and C, or B and C, A and B and C, or any duplicate information or data (e.g., A and A, B and B, C and C, A and A and B, and so on) , or any other ordering, duplication, or combination of A, B, and C. The language “at least one of” a set and / or “one or more” of a set does not limit the set to the items listed in the set. For example, claim language reciting “at least one of A and B” or “at least one of A or B” may mean A, B, or A and B, and may additionally include items not listed in the set of A and B. The phrases “at least one” and “one or more” are used interchangeably herein.
[0085] Claim language or other language reciting “at least one processor configured to, ” “at least one processor being configured to, ” “one or more processors configured to, ” “one or more processors being configured to, ” or the like indicates that one processor or multiple processors (in any combination) can perform the associated operation (s) . For example, claim language reciting “at least one processor configured to: X, Y, and Z” means a single processor can be used to perform operations X, Y, and Z; or that multiple processors are each tasked with a certain subset of operations X, Y, and Z such that together the multiple processors perform X, Y, and Z; or that a group of multiple processors work together to perform operations X, Y, and Z. In another example, claim language reciting “at least one processor configured to: X, Y, and Z” can mean that any single processor may only perform at least a subset of operations X, Y, and Z.
[0086] Where reference is made to one or more elements performing functions (e.g., steps of a method) , one element may perform all functions, or more than one element may collectively perform the functions. When more than one element collectively performs the functions, each function need not be performed by each of those elements (e.g., different functions may be performed by different elements) and / or each function need not be performed in whole by only one element (e.g., different elements may perform different sub-functions of a function) . Similarly, where reference is made to one or more elements configured to cause another element (e.g., an apparatus) to perform functions, one element may be configured to cause the other element to perform all functions, or more than one element may collectively be configured to cause the other element to perform the functions.
[0087] Where reference is made to an entity (e.g., any entity or device described herein) performing functions or being configured to perform functions (e.g., steps of a method) , the entity may be configured to cause one or more elements (individually or collectively) to perform the functions. The one or more components of the entity may include at least one memory, at least one processor, at least one communication interface, another component configured to perform one or more (or all) of the functions, and / or any combination thereof. Where reference to the entity performing functions, the entity may be configured to cause one component to perform all functions, or to cause more than one component to collectively perform the functions. When the entity is configured to cause more than one component to collectively perform the functions, each function need not be performed by each of those components (e.g., different functions may be performed by different components) and / or each function need not be performed in whole by only one component (e.g., different components may perform different sub-functions of a function) .
[0088] Illustrative aspects of the disclosure include:
[0089] Aspect 1. An electronic device, comprising: a memory system; a hardware component; and a processor system coupled to the memory system and the hardware component, wherein the processor system is configured to: generate, using an application executing on a virtual machine of the electronic device, a first remote procedure call (RPC) message for the hardware component; send, using the application, the first RPC message to an RPC driver of the virtual machine; send, using the RPC driver of the virtual machine, the first RPC message to a first passthrough of the hardware component to set an interrupt for the hardware component; and send the first RPC message to an RPC endpoint of the hardware component; wherein the hardware component is configured to: receive the first RPC message for processing by a hardware component application of the hardware component.
[0090] Aspect 2. The electronic device of Aspect 1, wherein the hardware component comprises hardware of the electronic device which is accessible by the processor system using RPC messages.
[0091] Aspect 3. The electronic device of any of Aspects 1-2, wherein the first RPC message comprises data for processing by the hardware component application.
[0092] Aspect 4. The electronic device of any of Aspects 1-3, wherein: the processor system is configured to: generate, using the application, a second RPC message for the hardware component, the second RPC message including control information; send the second RPC message to a virtualized RPC resource of the electronic device; and send, using the virtualized RPC resource, the second RPC message to a second interface of the hardware component to set an interrupt for the hardware component; and the hardware component is configured to: receive the second RPC message; and configure the hardware component application based on the control information in the second RPC message.
[0093] Aspect 5. The electronic device of Aspect 4, wherein control information comprises an RPC message, and wherein the hardware component is configured to: based on the RPC message, at least one of initialize the hardware component application, uninitialize the hardware component application, or adjust a setting of the hardware component application.
[0094] Aspect 6. The electronic device of any of Aspects 4-5, wherein, to send the second RPC message to the virtualized RPC resource, the processor system is configured to: send, using the application, the second RPC message to a first RPC virtualization layer of the RPC driver; send, using the first RPC virtualization layer, the second RPC message to a hypervisor associated with the virtual machine; and send, using the hypervisor, the second RPC message to a host RPC endpoint via a second RPC virtualization layer, wherein the host RPC endpoint is configured to send the second RPC message to the second interface.
[0095] Aspect 7. The electronic device of Aspect 6, wherein the hypervisor is configured to inspect the second RPC message for malicious information.
[0096] Aspect 8. The electronic device of any of Aspects 1-7, wherein the hardware component application comprises a machine learning model.
[0097] Aspect 9. The electronic device of any of Aspects 1-8, wherein the processor system is configured to perform a cyclic redundancy check on data in the first RPC message.
[0098] Aspect 10. The electronic device of any of Aspects 1-9, wherein the hardware component comprises one of a digital signal processor (DSP) , neural processing unit (NPU) , or a graphics processing unit (GPU) .
[0099] Aspect 11. A method for accessing a hardware component, comprising: generating, using an application executing on a virtual machine of an electronic device, a first remote procedure call (RPC) message for a hardware component; sending, using the application, the first RPC message to an RPC driver of the virtual machine; sending, using the RPC driver of the virtual machine, the first RPC message to a first passthrough of the hardware component to set an interrupt for the hardware component; sending the first RPC message to an RPC endpoint of the hardware component; and receiving the first RPC message for processing by a hardware component application of the hardware component.
[0100] Aspect 12. The method of Aspect 11, wherein the hardware component comprises hardware of the electronic device which is accessible by a processor system using RPC messages.
[0101] Aspect 13. The method of any of Aspects 11-12, wherein the first RPC message comprises data for processing by the hardware component application.
[0102] Aspect 14. The method of any of Aspects 11-13, further comprising: generating, using the application, a second RPC message for the hardware component, the second RPC message including control information; sending the second RPC message to a virtualized RPC resource of the electronic device; sending, using the virtualized RPC resource, the second RPC message to a second interface of the hardware component to set an interrupt for the hardware component; receiving the second RPC message by the hardware component; and configuring the hardware component application based on the control information in the second RPC message.
[0103] Aspect 15. The method of Aspect 14, wherein control information comprises an RPC message, and further comprising: based on the RPC message, at least one of initializing the hardware component application, uninitializing the hardware component application, or adjusting a setting of the hardware component application.
[0104] Aspect 16. The method of any of Aspects 14-15, wherein sending the second RPC message to the virtualized RPC resource comprises: sending, using the application, the second RPC message to a first RPC virtualization layer of the RPC driver; sending, using the first RPC virtualization layer, the second RPC message to a hypervisor associated with the virtual machine; and sending, using the hypervisor, the second RPC message to a host RPC endpoint via a second RPC virtualization layer, wherein the host RPC endpoint is configured to send the second RPC message to the second interface.
[0105] Aspect 17. The method of Aspect 16, wherein the hypervisor is configured to inspect the second RPC message for malicious information.
[0106] Aspect 18. The method of any of Aspects 11-17, wherein the hardware component application comprises a machine learning model.
[0107] Aspect 19. The method of any of Aspects 11-18, further comprising performing a cyclic redundancy check on data in the first RPC message.
[0108] Aspect 20. The method of any of Aspects 11-19, wherein the hardware component comprises one of a digital signal processor (DSP) , neural processing unit (NPU) , or a graphics processing unit (GPU) .
[0109] Aspect 21. A non-transitory computer-readable medium having stored thereon instructions that, when executed by a processor system, cause the processor system to: generate, using an application executing on a virtual machine of an electronic device, a first remote procedure call (RPC) message for a hardware component; send, using the application, the first RPC message to an RPC driver of the virtual machine; send, using the RPC driver of the virtual machine, the first RPC message to a first passthrough of the hardware component to set an interrupt for the hardware component; send the first RPC message to an RPC endpoint of the hardware component; and receive the first RPC message for processing by a hardware component application of the hardware component.
[0110] Aspect 22. The non-transitory computer-readable medium of Aspect 21, wherein the hardware component comprises hardware which is accessible by the processor system using RPC messages.
[0111] Aspect 23. The non-transitory computer-readable medium of any of Aspects 21-22, wherein the first RPC message comprises data for processing by the hardware component application.
[0112] Aspect 24. The non-transitory computer-readable medium of any of Aspects 21-23, wherein the instructions cause the processor system to: generate, using the application, a second RPC message for the hardware component, the second RPC message including control information; send the second RPC message to a virtualized RPC resource of the electronic device; send, using the virtualized RPC resource, the second RPC message to a second interface of the hardware component to set an interrupt for the hardware component; receive the second RPC message; and configure the hardware component application based on the control information in the second RPC message.
[0113] Aspect 25. The non-transitory computer-readable medium of Aspect 24, wherein control information comprises an RPC message, and wherein the instructions further cause the processor system to: based on the RPC message, at least one of initialize the hardware component application, uninitialize the hardware component application, or adjust a setting of the hardware component application.
[0114] Aspect 26. The non-transitory computer-readable medium of any of Aspects 24-25, wherein, to send the second RPC message to the virtualized RPC resource, the instructions cause the processor system to: send, using the application, the second RPC message to a first RPC virtualization layer of the RPC driver; send, using the first RPC virtualization layer, the second RPC message to a hypervisor associated with the virtual machine; and send, using the hypervisor, the second RPC message to a host RPC endpoint via a second RPC virtualization layer, wherein the host RPC endpoint is configured to send the second RPC message to the second interface.
[0115] Aspect 27. The non-transitory computer-readable medium of Aspect 26, wherein the hypervisor is configured to inspect the second RPC message for malicious information.
[0116] Aspect 28. The non-transitory computer-readable medium of any of Aspects 21-27, wherein the hardware component application comprises a machine learning model.
[0117] Aspect 29. The non-transitory computer-readable medium of any of Aspects 21-28, wherein the instructions further cause the processor system to perform a cyclic redundancy check on data in the first RPC message.
[0118] Aspect 30. The non-transitory computer-readable medium of any of Aspects 21-29, wherein the hardware component comprises one of a digital signal processor (DSP) , neural processing unit (NPU) , or a graphics processing unit (GPU) .
[0119] Aspect 31. An apparatus for accessing a hardware component, comprising one or more means for performing operations according to any of Aspects 11-20.
Claims
1.An electronic device, comprising:a memory system;a hardware component; anda processor system coupled to the memory system and the hardware component, wherein the processor system is configured to:generate, using an application executing on a virtual machine of the electronic device, a first remote procedure call (RPC) message for the hardware component;send, using the application, the first RPC message to an RPC driver of the virtual machine;send, using the RPC driver of the virtual machine, the first RPC message to a first passthrough of the hardware component to set an interrupt for the hardware component; andsend the first RPC message to an RPC endpoint of the hardware component; wherein the hardware component is configured to:receive the first RPC message for processing by a hardware component application of the hardware component.2.The electronic device of claim 1, wherein the hardware component comprises hardware of the electronic device which is accessible by the processor system using RPC messages.3.The electronic device of claim 1, wherein the first RPC message comprises data for processing by the hardware component application.4.The electronic device of claim 1, wherein:the processor system is configured to:generate, using the application, a second RPC message for the hardware component, the second RPC message including control information;send the second RPC message to a virtualized RPC resource of the electronic device; andsend, using the virtualized RPC resource, the second RPC message to a second interface of the hardware component to set an interrupt for the hardware component; andthe hardware component is configured to:receive the second RPC message; andconfigure the hardware component application based on the control information in the second RPC message.5.The electronic device of claim 4, wherein control information comprises an RPC message, and wherein the hardware component is configured to:based on the RPC message, at least one of initialize the hardware component application, uninitialize the hardware component application, or adjust a setting of the hardware component application.6.The electronic device of claim 4, wherein, to send the second RPC message to the virtualized RPC resource, the processor system is configured to:send, using the application, the second RPC message to a first RPC virtualization layer of the RPC driver;send, using the first RPC virtualization layer, the second RPC message to a hypervisor associated with the virtual machine; andsend, using the hypervisor, the second RPC message to a host RPC endpoint via a second RPC virtualization layer, wherein the host RPC endpoint is configured to send the second RPC message to the second interface.7.The electronic device of claim 6, wherein the hypervisor is configured to inspect the second RPC message for malicious information.8.The electronic device of claim 1, wherein the hardware component application comprises a machine learning model.9.The electronic device of claim 1, wherein the processor system is configured to perform a cyclic redundancy check on data in the first RPC message.10.The electronic device of claim 1, wherein the hardware component comprises one of a digital signal processor (DSP) , neural processing unit (NPU) , or a graphics processing unit (GPU) .11.A method for accessing a hardware component, comprising:generating, using an application executing on a virtual machine of an electronic device, a first remote procedure call (RPC) message for a hardware component;sending, using the application, the first RPC message to an RPC driver of the virtual machine;sending, using the RPC driver of the virtual machine, the first RPC message to a first passthrough of the hardware component to set an interrupt for the hardware component;sending the first RPC message to an RPC endpoint of the hardware component; andreceiving the first RPC message for processing by a hardware component application of the hardware component.12.The method of claim 11, wherein the hardware component comprises hardware of the electronic device which is accessible by a processor system using RPC messages.13.The method of claim 11, wherein the first RPC message comprises data for processing by the hardware component application.14.The method of claim 11, further comprising:generating, using the application, a second RPC message for the hardware component, the second RPC message including control information;sending the second RPC message to a virtualized RPC resource of the electronic device;sending, using the virtualized RPC resource, the second RPC message to a second interface of the hardware component to set an interrupt for the hardware component;receiving the second RPC message by the hardware component; andconfiguring the hardware component application based on the control information in the second RPC message.15.The method of claim 14, wherein control information comprises an RPC message, and further comprising:based on the RPC message, at least one of initializing the hardware component application, uninitializing the hardware component application, or adjusting a setting of the hardware component application.16.The method of claim 14, wherein sending the second RPC message to the virtualized RPC resource comprises:sending, using the application, the second RPC message to a first RPC virtualization layer of the RPC driver;sending, using the first RPC virtualization layer, the second RPC message to a hypervisor associated with the virtual machine; andsending, using the hypervisor, the second RPC message to a host RPC endpoint via a second RPC virtualization layer, wherein the host RPC endpoint is configured to send the second RPC message to the second interface.17.The method of claim 16, wherein the hypervisor is configured to inspect the second RPC message for malicious information.18.The method of claim 11, wherein the hardware component application comprises a machine learning model.19.The method of claim 11, further comprising performing a cyclic redundancy check on data in the first RPC message.20.The method of claim 11, wherein the hardware component comprises one of a digital signal processor (DSP) , neural processing unit (NPU) , or a graphics processing unit (GPU) .
Citation Information
Patent Citations
Paravirtualized virtual GPU
CN103034524A
Virtualization operations for directly assigned devices
CN111213127A
Remote application automation system based on RPC
CN113176957A
Cross-security-region resource access method in cloud computing system, and electronic equipment
CN113467970A
Cross-security-region resource access method in cloud computing system and electronic equipment
CN114710366A