Network-on-chip with reconfigurable routing for secure shared computing
The NoC architecture in the host computing device addresses secure resource sharing by segmenting circuit components and enabling quick mode switches, ensuring data security, reliability, and availability in collaborative edge computing.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-19
- Publication Date
- 2026-03-26
AI Technical Summary
Existing NoC architectures face challenges in securely sharing resources among non-mutually trusted devices, ensuring data security, reliability, and availability, which hinders the widespread adoption of collaborative edge computing.
A host computing device with a network-on-chip (NoC) that includes routing elements and a configuration component to selectively route flow control units, allowing secure sharing of circuit components by segmenting them into accessible and inaccessible subsets based on OS notifications and reconfiguration requests from external devices.
Ensures data security by keeping internal and external data separate, improves reliability by migrating critical processes, and enhances availability by enabling quick switching between sharing and non-sharing modes, maintaining stability and resource availability.
Smart Images

Figure EP2024076336_26032026_PF_FP_ABST
Abstract
Description
NETWORK-ON-CHIP WITH RECONFIGURABLE ROUTING FOR SECURE SHARED COMPUTINGTECHNICAL FIELD
[0001] The present disclosure relates to a host computing device comprising a network interface, a network on chip (NoC) comprising a set of circuit components, and routing elements configured to selectively route flow control units between the circuit components and between the network interface and the circuit components, and a method of a host computing device.BACKGROUND
[0002] Collaborative edge computing (CEC) is an emerging paradigm enabling sharing of coupled data, computation, and networking resources among heterogeneous geo-distributed edge nodes. Collaborative edge compute can refer to an edge deployment where both fixed and mobile equipment can contribute computing resources used for their respective compute.
[0003] Another technology relates to Network-on-chip (NoC) which is an emerging concept within chip communication where routing elements are used to utilize many short buses instead of the classical structure containing fixed busses with multiple consumers.
[0004] The benefit of using NoC architectures is decreased risk for saturation when several components are utilizing the same bus. NoC architectures also require less busses than a so- called crossbar solution wherein every component is connected by direct busses.
[0005] NoC can be utilized to send information between different components and not being committed to a certain path while doing so. This can either be done by performing packet routing (which may be similar to IP protocol) or circuit routing (which may be similar to P2P -protocols.)
[0006] The NoC architecture includes tiles, sometimes called cores or routing elements, which functionally operate as routing points for traffic. The tiles can contain one or several buffers, several ports / busses to other tiles and packet routing logic. Each routing element maintains a “routing table” which is used to keep track of which packets to send and in which direction. Routing elements may further contain lists of allowed and disallowed senders and / or receivers.P111499WO01
[0007] Some tiles have electronic components ("components") connected to them, such as a CPU, GPU, memory, etc. A component may have several tiles connected to it, forming different ingress and egress points to the component, which may be used to facilitate parallel data flows.
[0008] Information sent between nodes in a NoC can be binary packets, which are divided into “flits” (flow control units), which may or may not be configured similar to frames in ethernet or WiFi. A flit may include a header, a body and a tail which is passed through the same route.
[0009] Some NoC’s are divided into a data NoC and a service NoC, where all meta-traffic is sent on the service NoC. The service NoC may be distributed for use of all tiles and components or used by specific management components.
[0010] The network-on-chip architecture is not necessarily only built-up by traditional busses but may also contain wireless communication for, e.g., longer-range transfers such as from one section of the chip to another. NoC’s which are configured with circuitry for wireless transfers can be called “wireless network-on-chip” or “WiNoC”.
[0011] Some literature makes a distinction between static NoC and programmable NoCs, i.e., where the routing logic are statically programmed to behave a certain way or where it can be re-programmed to adapt to different scenarios and contexts. Programmable NoCs are also known as Software-defined Network-on-chip (SDNoC).
[0012] This disclosure is mainly directed to NoCs configured to allow programmability of the routing logic, and so the term programmable NoC is also referred to as “NoC” for brevity.
[0013]
[0014] Where compute continuum is the desired paradigm, e.g., being able to utilize computational power and components from devices and edge installments in proximity, the availability of low-latency solutions to utilize these resources is important.
[0015] The use cases which require, and therefore have the need of, collaborative edge compute is growing. A key component is to achieve this low-latency scenario is to be able to identify nearby, available capabilities, which are suitable for the current needs of the users.
[0016] Making components of NoCs available externally appears to be an undeveloped area.
[0017] Reference [1] describes Direct Extension of On-chip Interconnects (DEOI), which is a protocol to extend hardware to other servers in the same rack, e.g., in a cloud server hall. The reconfigurable routing structure within a device can address external resources by using these DEOI interfaces.P111499WO01
[0018] Some papers describe approaches to protect the NoC from malicious tasks [2] and how to isolate applications in NoCs by introducing secure zones [3], However, the computation isolation occurs by only mapping tasks of the same application at each processing element. The communication isolation is supported by the SDNoC paradigm, which establishes dedicating paths for secure applications.
[0019] Potential problems that can arise with these and other prior technologies are now discussed.
[0020] Sharing of idle resources in user devices which are not mutually trusted is uncommon because of problems that arise, which can include:• Finding resources, how to find and effectively use the idle resources?• Device security, how can we ensure that allowing others to use idle resources is secure?• Data security, how can we ensure that external and internal data is handled separately, and that any data sent to an untrusted device is removed when that device is no longer used?• Reliability & availability - How can we ensure that the device lending components is not affected negatively and is available for usage when needed by owner?
[0021] These and other problems can hinder widespread adoption of collaborative compute deployments which would otherwise enable a device's compute power to be increased when needed and to enable better utilization of idle devices.SUMMARY
[0022] Some embodiments disclosed herein are directed to providing sharing of resources of a NoC architecture while providing security, reliability, and availability of resources.
[0023] Some embodiments are directed to a host computing device that includes a network interface, routing elements, a configuration component, and a NoC including a set of circuit components. The network interface is configured to communicate through at least one network with an external computing device. The routing elements are configured to selectively route flow control units between the circuit components and between the network interface and the circuit components. The configuration component is configured to control, based on a present routing configuration, the selective routing by the routing elements of flow control units between the circuit components. The configuration component is configured to receive, via the network interface from the external computing device, a re-configurationP111499WO01request requesting a change from the present routing configuration that results in a new routing configuration which when switched-to will render a subset of the circuit components of the NoC inaccessible to an operating system (OS) of the host computing device but accessible to the external computing device.
[0024] The configuration component is configured to respond to the request, by identifying to the OS the subset of the circuit components of the NoC that will become inaccessible. Responsive to an indicated completion by the OS of removal or discontinued use of data and / or instructions from the subset of the circuit components, the configuration component switches from the present routing configuration to the new routing configuration by controlling, based on the new routing configuration, the routing by the routing elements of flow control units between the subset of the circuit components and the external computing device via the network interface, and further controlling, based on the new routing configuration, the routing by the routing elements of flow control units between the circuit components accessible to the OS.
[0025] Some other related embodiments are directed to a method by a host computing device comprising a network interface, a NoC, and routing elements. The method includes controlling, based on a present routing configuration, selective routing by the routing elements of flow control units between the circuit components. The method includes receiving, via the network interface from the external computing device, a re-configuration request requesting a change from the present routing configuration that results in a new routing configuration which when switched-to will render a subset of the circuit components of the NoC inaccessible to an OS of the host computing device but accessible to the external computing device. The method includes, responsive to the request, identifying to the OS the subset of the circuit components of the NoC that will become inaccessible. Responsive to an indicated completion by the OS of removal or discontinued use of data and / or instructions from the subset of the circuit components, the method includes switching from the present routing configuration to the new routing configuration by controlling, based on the new routing configuration, the routing by the routing elements of flow control units between the subset of the circuit components and the external computing device via the network interface, and further controlling, based on the new routing configuration, the routing by the routing elements of flow control units between the circuit components accessible to the OS.
[0026] As will be explained in further detail below, a potential advantage provided by these and other embodiments is that data security can be accomplished by ensuring that data and / or instructions belonging to processes in the first device are kept separate from external dataP111499WO01and / or processes from the second device, through segmentation of the circuit components with the respective routing paths kept separate. Reliability can be improved by classifying processes in the first device and ensuring that processes satisfying a criteria are migrated to non-sharable hardware components prior to activating sharing mode, which can ensure stability and reliability of those processes in the first device. Availability can be improved by allowing quick switching between “sharing” and “non-sharing” modes to ensure availability of resources of the first device by keeping alive the processes that satisfied the criteria.
[0027] Other host computing devices and related methods and computer program products according to embodiments will be or become apparent to one with skill in the art upon review of the following drawings and detailed description. It is intended that all such host computing devices and related methods and computer program products be included within this description, be within the scope of the present disclosure, and be protected by the accompanying claims. Moreover, it is intended that all embodiments disclosed herein can be implemented separately or combined in any way and / or combination.BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Aspects of the present disclosure are illustrated by way of example and are not limited by the accompanying drawings. In the drawings:
[0029] Figure 1 illustrates a second (external) computing device using virtual circuit components corresponding to shared circuit components of a NoC in a first (host) computing device according to some embodiments of the present disclosure;
[0030] Figure 2 illustrates a flowchart of operations by the first (host) computing device to switch from a present routing configuration to a new routing configuration that enables the second (external) computing device to use the sharable circuit components in the first (host) computing device according to some embodiments of the present disclosure;
[0031] Figure 3 illustrates example components of the first (host) computing device when configured with a present routing configuration for routing flow control units when no sharable circuit components are made available for sharing with the second (external) computing device according to some embodiments of the present disclosure;
[0032] Figure 4 illustrates the example components of the first (host) computing device when configured with a new routing configuration for routing flow control units to make sharable circuit components useable by the second (external) computing device according to some embodiments of the present disclosure; andP111499WO01
[0033] Figure 5 illustrates a flowchart of more general operations by a host computing device to switch from a present routing configuration to a new routing configuration that enables an external computing device to use a subset of circuit components in the host computing device according to some embodiments of the present disclosure.DETAILED DESCRIPTION
[0034] Inventive concepts will now be described more fully hereinafter with reference to the accompanying drawings, in which examples of embodiments of inventive concepts are shown. Inventive concepts may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of various present inventive concepts to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. Components from one embodiment may be tacitly assumed to be present / used in another embodiment.
[0035] Various embodiments of the present disclosure are directed to enabling circuit components of a NoC of a first (host) computing device (also “first (host) device” and “first device”) to be temporarily used through activation of a sharing mode by a second (external) computing device (also “second (external) device” and “second device”) in a virtualized manner similar to if the shared circuit components were physically located in the second device. Such sharing of circuit components provides a collaborative (shared) compute solution whereby processors (e.g., discrete processors, multi-core processors, hardware accelerators, etc.), memories (e.g., discrete memories, addressable partitions in a same memory, etc.), sensors, etc. of the NoC of the first device can be temporarily used by one or more other devices. The first device can maintain some of the circuit components of the NoC for its own use while other circuit components are used by the second device.
[0036] The sharing may either be invoked forcefully, i.e., without regard for the current state of the first device or when the first device is not utilizing some of its circuit components. Alternatively, the sharing is allowed when the first device is in a certain state, e.g., based on determining it has unused (idle) circuit components or detecting that a user is no longer present in proximity to the first device. In some embodiments, the time needed for an intended or ongoing computing task of the second device, wanting to utilize the first device’s shared resources through the sharing mode, may also be taken into consideration before activating the sharing mode.P111499WO01
[0037] Generally, the sharing mode can be enabled by operation of a configuration component in the first device that responds to a reconfiguration request from the second device by reconfiguring the routing paths within the first device to segment a set of circuit components into two subsets, one for local usage by the first device and one for external usage by the second device. The configuration component informs the OS of the first device what subset of circuit components for external usage that will become inaccessible by the OS, which can trigger the OS to remove or discontinue use of data and / or instructions of processes, e.g., move to run on the local subset (non-shared subset) of circuit components.
[0038] Potential advantages provided by these and other embodiments include that all or important processes and / or data (e.g., satisfying a criteria) can be migrated from the sharable subset of circuit components that will become inaccessible (to the OS) to the local non- sharable subset of circuit components and / or other circuit components that will remain accessible to the OS. Operation of the first device can thereby remain stable during and after reconfiguring of the routing paths to enable external use of the sharable subset of circuit components by the second device. Moreover, data security and reliability are ensured by the OS being notified and able to move processes and / or data before the sharable subset of circuit components are made accessible to the second device and become inaccessible to the OS. The switched-to routing configuration can similarly prevent access by the second device to data and / or processes in the non-sharable subset of circuit components that remain accessible to the OS.
[0039] Operation of the first device can thereby remain stable and functional while enabling the sharable subset of circuit component to be used be the second device. Operations may enable quick reversing of the routing configuration, returning the first device to its original state (before switching) and terminating access by the second device. A user of the first device can thereby regain the original functionality and availability of circuit component resources.
[0040] Operations enable the first device to be reconfigured to enable unused or underutilized circuit components to be used by other (external) computing device(s), which enables improved usage and availability of unused compute capabilities without compromising data security or availability in the first device.
[0041] By allowing the switch to be performed on a hardware level, the circuit components can receive data and instruction directly from the other (external) computing device(s), without involvement of the OS of the first device. As will be explained in further details below, the first device can support a plurality of routing configurations which control routingP111499WO01of flow control units between the circuit components. One of the routing configurations may preclude another computing device from accessing any of the circuit components of the first device, and another one of the routing configurations may all allow the other computing device to access a subset of the circuit components.
[0042] Figure 1 illustrates a second (external) device 120 (also “second device”) using virtual circuit components 122 corresponding to shared circuit components 102 of a NoC in a first (host) device 100 (also “first device”) according to some embodiments of the present disclosure.
[0043] Referring to Figure 1, the first device 100 includes a NoC including a set of circuit components 102, routing elements 108, a configuration component 110, and a network interface 112. The second device 120 includes non-virtual circuit components 124 and a network interface 126. The network interface 112 of the the first device 100 is configured to communicate through at least one network (e.g., private and / or public network) with the network interface 126 of the second device 120.
[0044] The routing elements 108 are configured to selectively route flow control units between the circuit components 102 and between the network interface 112 and the circuit components 102. The circuit components 102 and 124 may include, without limitation, processors (e.g., discrete processors, multi-core processors, hardware accelerators, general purpose processors, special purpose processors, etc.), memories (e.g., discrete memories, addressable partitions in a same memory, etc.), sensor devices that output sensor data in flow control units and / or user output interface devices that generate a visual, audible, and / or tactile output responsive to data in flow control units, etc.
[0045] The circuit components 102 of the first device 100 can be divided into a non-sharable subset which is not made accessible to the second device 120 and into a sharable subset which is made accessible to the second device 120 as virtual components 122 that can be used by an OS and non-virtual circuit components 124 of the second device 120 for computing, data storage, etc. The virtual components 122 thereby increase the hardware resources available to the second device 120.
[0046] Figure 5 illustrates a flowchart of more general operations by the first device 100 to switch from a present routing configuration to a new routing configuration that enables the second device 120 to use a sharable subset 106 of circuit components in the first device 100 according to some embodiments of the present disclosure.
[0047] Referring to Figures 1 and 5, the configuration component 110 is configured to control 500, based on a present routing configuration, the selective routing by the routingP111499WO01elements 108 of flow control units between the circuit components 102. The configuration component 110 receives 502, via the network interface 112 from the second device 120, a reconfiguration request requesting a change from the present routing configuration that results in a new routing configuration which when switched-to will render sharable subset 106 of circuit components inaccessible to an OS of the first device 100 but accessible to the second device 120. Responsive to the request, the configuration component 110 identifies 504 to the OS the sharable subset 106 of circuit components that will become inaccessible (e.g., the OS will become unable to read / write and / or otherwise access data and / instructions to that subset of the circuit components). Responsive to an indicated completion by the OS of removal or discontinued use of data and / or instructions from the sharable subset 106 of circuit components, the configuration component 110 switches from the present routing configuration to the new routing configuration including by controlling 506, based on the new routing configuration, the routing by the routing elements 108 of flow control units between the sharable subset 106 of circuit components and the second device 120 via the network interface 112. The sharable subset 106 of circuit components thereby become usable by the second device 120 as virtual components 122. The configuration component 110 further controls 508, based on the new routing configuration, the routing by the routing elements 108 of flow control units between the circuit components (non-sharable subset 104) accessible to the OS.
[0048] The sharable 106 and non-sharable 104 subsets of the NoC circuit components 102 can be made exclusive of each other, i.e., no overlap of circuit components, in order to ensure that the second device 120 cannot access data and / or instructions in the non-sharable subset 104 of circuit components used by the OS of the first device 100 for operation and, vice-versa, the OS cannot access data and / or instructions in the sharable subset 106 of circuit components used as virtual components 122 by the second device 120.
[0049] In one embodiment, the sharable subset 106 of circuit components becomes inaccessible to the OS when the new routing configuration is switched-to, by the configuration component 110 operating to control the routing elements 108 to terminate an ability of the OS to access data and / or instructions of an executable process residing on the subset of the circuit components.
[0050] In another embodiment, the configuration component 110 is configured to maintain a plurality of routing configurations, one of the routing configurations defines a first subset of the circuit components between which flow control units are allowed to be routed, and another of the routing configurations defines a second subset of the circuit components andP111499WO01the network interface between which flow control units are allowed to be routed. The first and second subsets are mutually exclusive.
[0051] In another embodiment, the OS is configured to respond to the configuration component 110 identifying 504 the sharable subset 106 of circuit components that will become inaccessible to the OS by removing or discontinuing use of data and / or instructions residing in the sharable subset 106 of circuit components that will become inaccessible to the OS (e.g., to the non-sharable subset 104 of circuit components that will be accessible to the OS). The OS can then indicate to the configuration component 110 when removal or discontinued use of the data and / or instructions is completed.
[0052] In another embodiment, the OS is configured to respond to the configuration component 110 identifying 504 the sharable subset 106 of circuit components that will become inaccessible to the OS by moving data and / or instructions residing in, processed by, and / or scheduled to be processed by the sharable subset 106 of circuit components that will become inaccessible to the OS, to the other of the circuit components (non-sharable subset 104) that will remain accessible to the OS after the new routing configuration is switched-to. The OS can then indicate to the configuration component 110 when movement of the data and / or instructions is completed.
[0053] The OS can decide which data and / or instructions to move based on defined criteria.
[0054] For example, in one embodiment the OS is further configured to respond to the configuration component 110 identifying the sharable subset 106 of circuit components that will become inaccessible to the OS, by deciding to perform operations to move the data and / or instructions based on determining that the data and / or instructions satisfy a criteria for importance to operation of the host computing device. In this manner, high priority or operationally critical related data and / or instructions can be selected for removal while other data and / or instructions are either left unchanged or deleted from the sharable subset 106 of circuit components.
[0055] The OS may make the determination based on at least one of: metadata logically associated with the data and / or instructions, a process number logically associated with the instructions, a hash value generated from combination of values of the instructions, a process privilege logically associated with the instructions, a process execution level logically associated with the instructions.
[0056] In one scenario, the second device 120 may send individual flow control units for routing to the sharable subset 106 of circuit components for processing and / or storage. The network interface 112 of the first device 100 can be configured to receive the individual flowP111499WO01control units and to individually pass them to the routing elements 108 for routing under control of the configuration component 110.
[0057] In another scenario, the second device 120 sends data structures containing bundled instructions and / or data for routing to the sharable subset 106 of circuit components for processing and / or storage. The network interface 112 is further configured, while the new routing configuration is switched-to, to receive a data structure containing an address and a set of instructions to be operated on, translate the address into a local routing address of at least one of the sharable subset 106 of circuit components, divide the set of instructions into a plurality of flow control units each containing one of the instructions and the local routing address, and pass the flow control units to the routing elements 108 for routing under control of the configuration component 110.
[0058] Some further embodiments are directed to approaches for isolating the non-sharable subset 104 from the sharable subset 106 of circuit components.
[0059] In one approach, the configuration component 110 is configured to control, based on an active routing configuration, the selective routing by the routing elements 108 of flow control units between the circuit components 102, by operations including to determine at least one routing restriction based on the active routing configuration, and to send the at least one routing restriction to the routing elements 108. The routing elements 108 are configured to use the at least one routing restriction to selectively perform at least one of: a) only route flow control units in a one-way direction defined by the at least one routing restriction; b) only route flow control units to addresses listed in an address set defined by the at least one routing restriction; c) only route flow control units to a single address defined by the at least one routing restriction; and d) require routing elements to allow bidirectional routing of flow control units. The routing restriction may define or be adapted based on which direction a flow control unit arrives (e.g., incoming from which circuit component of the first device 100 and / or second device 120.
[0060] In another approach, the configuration component 110 is configured to control, based on an active routing configuration, the selective routing by the routing elements 108 of flow control units between the circuit components 102, by operations including to determine at least one routing restriction based on the active routing configuration, and send the at least one routing restriction to the routing elements 108. The routing elements 108 are configured to use the at least one routing restriction to selectively perform at least one of: a) only route to the network interface flow control units that arrive from a circuit component listed in a subset of components defined by the at least one routing restriction; and b) only route flow controlP111499WO01units that arrive at the network interface 112 flow control units to the circuit components defined by the at least one routing restriction.
[0061] The second device 120 may indicate in its request a requested type of task (e.g., type of process, characteristics of the process such as graphics processing, etc.) and / or characteristics of the circuit components (e.g., processor in general or more specific type of processor, etc.). The configuration component 110 can thereby be configured to determine from an indication contained in the reconfiguration request at least one type of circuit component that is to be configured for use by the second device 120. The configuration component 110 may be configured to create a routing configuration that controls the routing elements 108 to allow routing of flow control units to at least one circuit component corresponding to the determined type of circuit component to become available for use by the second device 120.
[0062] Some further embodiments are directed to approaches for returning the sharable subset 106 of circuit components back the OS of the first device 100 for use.
[0063] In one approach, the configuration component 110 is further configured to, following the switch from the present routing configuration to the new routing configuration, to then receive, via the network interface 112 from the second device 120, a release request indicating the second device 120 no longer needs use of the sharable subset 106 of the circuit components. Responsive to the release request, the configuration component 110 switches to a routing configuration that controls the routing elements 108 to render the sharable subset 106 of circuit components accessible to the OS and which renders the sharable subset 106 of circuit components no longer accessible to the second device 120, and identifies to the OS the sharable subset 106 of circuit components that has become accessible to the OS. Additionally, second device 120 may, for example, be informed by the first device that in X seconds the sharable subset 106 of circuit components will become inaccessible.
[0064] The configuration component 110 may switch back and forth between two or more routing configurations to alternately provide sharing and then non-sharing of circuit components for external device(s). The switching may be performed periodically or based on one or more defined conditions becoming satisfied.
[0065] In another approach, the configuration component 110 is further configured to, following the switch from the present routing configuration to the new routing configuration, receive from the OS an indicated need to revert to the routing configuration that was active before the switch to the new routing configuration. Responsive to the indicated need to revert, the configuration component 110 informs the second device 120 of the need to revertP111499WO01configuration. Responsive to an acknowledgement received from the second device 120 and / or expiration of a threshold time duration since informing the second device 120, the configuration component 110 then switches from the new routing configuration to the routing configuration that was active before the switch to the new routing configuration.
[0066] The first device 100 may perform security operations to validate the second device 120 and / or validate the flow control units. In one embodiment, responsive to receipt of the request, the configuration component 110 validates that the second device 120 is allowed by an access policy to access the NoC circuit components 102. In another embodiment, the routing elements 108 and / or the configuration component 110 is further configured to validate flow control units received from the second device 120 via the network interface 112 as a condition for routing based on the new routing configuration to the sharable subset 106 of circuit components.
[0067] Various embodiments have been described above in a more general nature with regard to Figures 1 and 5. More detailed operations are now described as extensions or alternatives one or more of these embodiments with further reference to Figures 2-4.
[0068] Figure 2 illustrates a flowchart of operations by the first (host) device to switch from a present routing configuration to a new routing configuration that enables a second (external) device to use the sharable circuit components in the first (host) device according to some embodiments of the present disclosure.
[0069] Referring to Figure 2, as an optional pre-requisite, the first device may obtain 200 an indication that it is available to enter sharing mode, e.g., after having a subset of circuit components that remain idle or are underutilized for a predetermined amount of time or after the first device is put in a standby mode. As a result, the first device may indicate, by broadcast or by informing a compute sharing service that it is ready to enter sharing mode. If a compute sharing service is used, the first device may register its location therewith to enable determining if a second device is close enough in proximity for sharing of circuit components to be beneficial.
[0070] In Figure 2, the first device receives 202 an indication that the sharing mode should be activated. The configuration component itself or the OS may receive the request from the second device. The message may further include a request indicating at least one requested type of hardware component (e.g., central processing unit (CPU), graphics processing unit (GPU), field-programmable gate array (FPGA), memory, camera, sensor, etc.).
[0071] The first device validates 204 that the message and / or the second device is allowed to access shared components according to a defined policy. The validation may be done inP111499WO01various different ways, such as by validating a signature of a private key belonging to a trusted party (e.g., the second device) or by validating an access token in the message.
[0072] If allowed by the validation, the configuration component selects 206 a subset of components to be made available for access and use by the second device.
[0073] The configuration component further informs 208 the OS regarding the components in the subset of sharable components becoming unavailable.
[0074] The OS responds 210 to the notification from the configuration component by pausing and / or terminating processes marked as non-vital or not satisfying a criteria. Other processes marked as vital or satisfying the criteria are instead scheduled to be run on the non-sharable remaining components. The vital processes may be identified, e.g., according to process metadata, process id, process privileges, hash value of process, execution level of process.
[0075] When finished, the OS sends 212 a completion indication to the configuration component that the vital processes have been migrated.
[0076] The configuration component sends 214 an instruction to at least one routing element to reconfigure the NoC for routing according to an updated configuration in order to segment the sharable and non-sharable components. The routing element may receive instructions to perform at least one of the following: only allow flits from or to a certain direction; only allow flits from or to a certain source or destination; only allow flits from or to a certain routing element; only allow flits having a certain payload; and only allow flits having passed at least one specific routing element on its path.
[0077] The configuration component further connects the sharable components to the network interface by specifying specific address-port pairs (or other constructs to address a specific component, e.g., separate Transmission Control Protocol (TCP) connections). Optionally, the configuration component resets sharable resources during this process. Optionally, the first device sends a proof-of-configuration to the second device or another device.
[0078] The network interface of the first device may obtain 216 instructions to alter the routing configuration to reroute incoming flit traffic, e.g., of a certain type, to one or more components in the subset of shared components.
[0079] The second device receives 218 at least one address-port pair from the first device indicating how to communicate with the subset of shared components. The second device sets up a local, virtual component, which serves as an interface to the resource in the first device. This may be embodied as a driver or other software component interfacing the OS.P111499WO01
[0080] The network interface of the first device receives 220 traffic (flits) comprising data and / or instructions from the second device, and forwards the flits to at least one component in the subset of sharable components. For example, upon receiving packets on a specific address-port pair, the network interface marks the packet (e.g., the flits the packet is divided into) with the relevant component identifier. The subset of sharable components receives external instructions and data by the second device, sent via the virtual component, the first device returns computation results by the network interface mapping packets comprising flits from the shared components to the address of the second device.
[0081] At a later time, the configuration component determines 222 that it has received an indication to exit the sharing mode. The configuration component may make that determination 222 based on a message received from the second device indicating to stop sharing mode, based on the OS indicating it has insufficient resources available in the non- sharable components to continue stable operation, and / or based on the OS indicating imminent user interaction, e.g., sensing user presence through sensor signaling or detecting user interaction with a user interface.
[0082] Responsive to the determination, the configuration component re-applies 224 the first configuration which was used before switching configurations. The OS re-starts any non- vital processes which were stopped and not migrated to the non-sharable components. The network interface removes the earlier reroute instructions.
[0083] The first device can support more than one collaborative configuration. In some embodiments, the configuration component stores more than two different routing configurations to enable the configuration component to give access to different subsets of components. This may be done on a per-device basis, where different external devices, possibly with different trust levels or requesting different components, may be given access to a different set of components. In some embodiments, the configuration may be created upon request by an external device, i.e., a second device requests a set of components, and the configuration is created to fulfill said request.
[0084] Some embodiments are directed to providing dynamically alterable sharable and non- sharable subsets of components. In some embodiments, the subset of sharable components may be dependent on the current status of the device. For example, some vital software processes may be run intermittently and require extra components such as computing and / or storage resources while doing so. This may cause parts of the sharable set of components to become part of the non-sharable subset and vice versa. Furthermore, this approach can be used for graceful shutdown of collaborative mode where components are moved to the non-P111499WO01sharable subset as the external processes that utilizes them are migrated to an external device or shut down
[0085] As was discussed above, some embodiments are directed to providing time-based sharable components. In some embodiments, some components may be utilized by both the first and second device in time separated slots. In such an embodiment, the configuration component alternates between two different routing paths configurations which are used to access the shareable components in the time separated slots.
[0086] Some further embodiments are directed to providing bundling and / or address translation in the communication between the second device and the first device.
[0087] In some embodiments, the first device may comprise a bundling / de-bundling component which translates network packets into flits and vice versa. The component may also perform address translation.
[0088] If the second device also has a NoC-architecture, the flits may be addressed locally for the second device. Example operations according to a further embodiment are now described for a scenario where the first device has a sharable component with local address Bl and the second device has a virtual CPU with local address Al. Flits sent to Al need to be translated to destination address Bl when arriving in the first device. Furthermore, a host process requesting the computations on the first device is present at a hardware component having address A2. The network interface on the first device has address B2.
[0089] In this scenario, operations by the second device include to send flits from the host process on component A2 to the virtual component on Al . The flits may be bundled into a network package and sent.
[0090] Responsive operations by the first device can include to receive the network package and, when bundled, operate to de-bundle the network package into the flits. The first device translates flit source addresses to network interface address B2 (indicating that they were received externally) and the flit destination address is changed to the local addresses of the shared component Bl. Flits are received by shared components (e.g., processor, memory, or sensor). Data and instructions are processed or executed. Results are used to generate flits which are sent from the component Bl to the network interface B2. The flits may be bundled into a network package and sent to the second device
[0091] Further responsive actions by the second device can include to receive the network package and, when bundled, operate to de-bundle the network package into the flits. The flit source addresses are translated to virtual component address Al and the flit destinationP111499WO01address is changed to the local address A2 where the hosting process resides. The flits are received by the hosting process.
[0092] Figure 3 illustrates example components of a first device 100 when configured with a present routing configuration for routing flow control units when no sharable circuit components are made available for sharing with a second device 120 according to some embodiments of the present disclosure. Figure 4 illustrates the example components of the first device 100 when configured with a new routing configuration for routing flow control units to make sharable circuit components useable by the second (external) device 120 according to some embodiments of the present disclosure.
[0093] Referring initially to Figure 3, the first device 100 includes a graphic processing unit (GPU) 300 and three memory circuits 302, 304, and 306 each storing an OS and data. The first device 100 further includes four central processing units (CPU) 310, 312, 314, and 316 each storing an OS and data. The first device 100 further includes routing elements 320, a network interface 330, and a configuration component 340 storing a routing setup normal configuration 350.
[0094] The network interface 330 is configured to communicate through at least one network with the second (external) device 120. The configuration component configured to control, based on the routing setup normal configuration 350, selective routing by the routing elements 320 of flow control units between the circuit components 300-316. In this routing configuration none of the circuit components 300-316 are sharable with the second (external) device 120, so the routing elements 320 do not route flow control units between the circuit components 300-316 and the network interface 330.
[0095] Referring now to Figure 4, the configuration component 340 has configured the routing elements 320 to make a sharable subset of the circuit components 304, 306, 314, and 316, available for use by the second (external) device.
[0096] More particularly, the configuration component 340 receives, via the network interface 330 from the second (external) device 120, a reconfiguration request requesting a change from the routing setup normal configuration 350 that results in a routing setup sharing configuration 360 which when switched-to will render the sharable subset of the circuit components 304, 306, 314, and 316 inaccessible to an OS of the first (host) device 100 but accessible to the second (external) device 120. Responsive to the request, the configuration component 340 identifies to the OS the sharable subset of the circuit components 304, 306, 314, and 316, that will become inaccessible.P111499WO01
[0097] Responsive to an indicated completion by the OS of removal or discontinued use of data and / or instructions from the sharable subset of the circuit components 304, 306, 314, and 316, the configuration component 340 switches from the routing setup normal configuration 350 to the routing setup sharing configuration 360 by controlling based on the routing setup sharing configuration 360 the routing by the routing elements 320 of flow control units between the sharable subset of the circuit components 304, 306, 314, and 316 and the second (external) device 120 via the network interface 330, and further controlling based on the routing setup sharing configuration 360 the routing by the routing elements 320 of flow control units between the circuit components 300, 302, 310, and 312 accessible to the OS.
[0098] Potential advantages that may be provided by one or more of the embodiments disclosed here are now described in further detail regarding data security, availability, and reliability.
[0099] Data security can be accomplished by ensuring that data and / or instructions belonging to processes in the first device are kept separate from external data and / or processes from the second device, through segmentation of the circuit components with the respective routing paths kept separate.
[0100] Reliability can be improved by classifying system vital (or other criteria) processes in the first device and ensuring that those processes are migrated to non-sharable hardware components prior to activating sharing mode, which can ensure stability and reliability of those processes in the first device. Furthermore, upon detecting sharing mode being deactivated, switched away from, (e.g., due to a user of first device starting or resuming interaction), the second device is informed on the imminent switch and allowed to perform migration of ongoing processes prior to revoking access of the second device to the shared circuit components of the first device.
[0101] Availability can be improved by allowing quick switching between “sharing” and “non-sharing” modes, so that first device can quickly switch between the modes. This ensures availability of resources of the first device in a situation where it is currently in sharing mode, as the switch back to non-sharing mode is quick and the vital (or other criteria) processes of the first device have been kept alive.
[0102] Further definitions and embodiments are now explained below.
[0103] In the above description of various embodiments of present inventive concepts, it is to be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of present inventive concepts. UnlessP111499WO01otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which present inventive concepts belongs. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of this specification and the relevant art and will not be interpreted in an idealized or overly formal sense expressly so defined herein.
[0104] When an element is referred to as being "connected", "coupled", "responsive", or variants thereof to another element, it can be directly connected, coupled, or responsive to the other element or intervening elements may be present. In contrast, when an element is referred to as being "directly connected", "directly coupled", "directly responsive", or variants thereof to another element, there are no intervening elements present. Like numbers refer to like elements throughout. Furthermore, "coupled", "connected", "responsive", or variants thereof as used herein may include wirelessly coupled, connected, or responsive. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. Well-known functions or constructions may not be described in detail for brevity and / or clarity. The term "and / or" includes any and all combinations of one or more of the associated listed items.
[0105] It will be understood that although the terms first, second, third, etc. may be used herein to describe various elements / operations, these elements / operations should not be limited by these terms. These terms are only used to distinguish one element / operation from another element / operation. Thus, a first element / operation in some embodiments could be termed a second element / operation in other embodiments without departing from the teachings of present inventive concepts. The same reference numerals or the same reference designators denote the same or similar elements throughout the specification.
[0106] As used herein, the terms "comprise", "comprising", "comprises", "include", "including", "includes", "have", "has", "having", or variants thereof are open-ended, and include one or more stated features, integers, elements, steps, components or functions but does not preclude the presence or addition of one or more other features, integers, elements, steps, components, functions or groups thereof. Furthermore, as used herein, the common abbreviation "e.g.", which derives from the Latin phrase "exempli gratia," may be used to introduce or specify a general example or examples of a previously mentioned item and is not intended to be limiting of such item. The common abbreviation "i.e.", which derives from the Latin phrase "id Est," may be used to specify a particular item from a more general recitation.P111499WO01
[0107] Example embodiments are described herein with reference to block diagrams and / or flowchart illustrations of computer-implemented methods, apparatus (systems and / or devices) and / or computer program products. It is understood that a block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by computer program instructions that are performed by one or more computer circuits. These computer program instructions may be provided to a processor circuit of a general purpose computer circuit, special purpose computer circuit, and / or other programmable data processing circuit to produce a machine, such that the instructions, which execute via the processor of the computer and / or other programmable data processing apparatus, transform and control transistors, values stored in memory locations, and other hardware components within such circuitry to implement the functions / acts specified in the block diagrams and / or flowchart block or blocks, and thereby create means (functionality) and / or structure for implementing the functions / acts specified in the block diagrams and / or flowchart block(s).
[0108] These computer program instructions may also be stored in a tangible computer- readable medium that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable medium produce an article of manufacture including instructions which implement the functions / acts specified in the block diagrams and / or flowchart block or blocks. Accordingly, embodiments of present inventive concepts may be embodied in hardware and / or in software (including firmware, resident software, micro-code, etc.) that runs on a processor such as a digital signal processor, which may collectively be referred to as "circuitry," "a module" or variants thereof.
[0109] It should also be noted that in some alternate implementations, the functions / acts noted in the blocks may occur out of the order noted in the flowcharts. For example, two blocks shown in succession may in fact be executed substantially concurrently or the blocks may sometimes be executed in the reverse order, depending upon the functionality / acts involved. Moreover, the functionality of a given block of the flowcharts and / or block diagrams may be separated into multiple blocks and / or the functionality of two or more blocks of the flowcharts and / or block diagrams may be at least partially integrated. Finally, other blocks may be added / inserted between the blocks that are illustrated, and / or blocks / operations may be omitted without departing from the scope of inventive concepts. Moreover, although some of the diagrams include arrows on communication paths to show aP111499WO01primary direction of communication, it is to be understood that communication may occur in the opposite direction to the depicted arrows.
[0110] Many variations and modifications can be made to the embodiments without substantially departing from the principles of the present inventive concepts. All such variations and modifications are intended to be included herein within the scope of present inventive concepts. Accordingly, the above disclosed subject matter is to be considered illustrative, and not restrictive, and the appended examples of embodiments are intended to cover all such modifications, enhancements, and other embodiments, which fall within the spirit and scope of present inventive concepts. Thus, to the maximum extent allowed by law, the scope of present inventive concepts is to be determined by the broadest permissible interpretation of the present disclosure including the following examples of embodiments and their equivalents and shall not be restricted or limited by the foregoing detailed description.
[0111] A listing of references that are cited herein follows:[1] Yisong Chang; Ke Zhang; Sally A. McKee; Lixin Zhang; Mingyu Chen; Liqiang Ren; Zhiwei Xu, "Extending On-chip Interconnects for rack-level remote resource access", in IEEE 34th International Conference on Computer Design, pp. 56-63, 2016[2] M. Ruaro, L. Caimi, F. Moraes, "SDN-Based Secure Application Admission and Execution for Many-Cores”, IEEE Access, vol. 8, pp. 177296-177306, 2020[3] M. Ruaro, L. Caimi, F. Moraes, "A Systemic and Secure SDN Framework for NoC-Based Many-Cores”, IEEE Access, vol. 8, pp. 105997-106008, 2020P111499WO01
Claims
CLAIMS:
1. A host computing device comprising: a network interface configured to communicate through at least one network with an external computing device; a network on chip, NoC, comprising a set of circuit components; routing elements configured to selectively route flow control units between the circuit components and between the network interface and the circuit components; and a configuration component configured to: control, based on a present routing configuration, the selective routing by the routing elements of flow control units between the circuit components; receive, via the network interface from the external computing device, a reconfiguration request requesting a change from the present routing configuration that results in a new routing configuration which when switched-to will render a subset of the circuit components of the NoC inaccessible to an operating system, OS, of the host computing device but accessible to the external computing device; responsive to the request, identify to the OS the subset of the circuit components of the NoC that will become inaccessible; and responsive to an indicated completion by the OS of removal or discontinued use of data and / or instructions from the subset of the circuit components, switch from the present routing configuration to the new routing configuration by controlling, based on the new routing configuration, the routing by the routing elements of flow control units between the subset of the circuit components and the external computing device via the network interface, and further controlling, based on the new routing configuration, the routing by the routing elements of flow control units between the circuit components accessible to the OS.
2. The host computing device of Claim 1, wherein: the subset of the circuit components becomes inaccessible to the OS when the new routing configuration is switched-to, by the configuration component operating to control the routing elements to terminate an ability of the OS to access data and / or instructions of an executable process residing on the subset of the circuit components.P111499WO013. The host computing device of any of Claims 1 to 2, wherein: the configuration component is configured to maintain a plurality of routing configurations, one of the routing configurations defines a first subset of the circuit components between which flow control units are allowed to be routed, and another of the routing configurations defines a second subset of the circuit components and the network interface between which flow control units are allowed to be routed.
4. The host computing device of Claim 3, wherein the first and second subsets are exclusive to each other.
5. The host computing device of any of Claims 1 to 4, wherein: the circuit components comprise processors and memories.
6. The host computing device of any of Claims 1 to 5, wherein: the circuit components comprise a sensor device that outputs sensor data in a flow control unit and / or a user output interface device that generates a visual, audible, and / or tactile, output responsive to data in a flow control unit.
7. The host computing device of any of Claims 1 to 6, further comprising the OS, wherein the OS is configured to: respond to the configuration component identifying the subset of the circuit components that will become inaccessible to the OS, remove or discontinue use of data and / or instructions residing in the subset of the components that will become inaccessible to the OS; and indicate to the configuration component when removal or discontinued use of the data and / or instructions is completed.
8. The host computing device of any of Claims 1 to 7, further comprising the OS, wherein the OS is configured to: respond to the configuration component identifying the subset of the circuit components that will become inaccessible to the OS, move data and / or instructions residing in, processed by, and / or scheduled to be processed by, the subset of the circuit components that will become inaccessible to the OS, toP111499WO01the other of the circuit components that will remain accessible to the OS after the new routing configuration is switched-to; and indicate to the configuration component when movement of the data and / or instructions is completed.
9. The host computing device of Claim 8, wherein the OS is further configured to respond to the configuration component identifying the subset of the circuit components that will become inaccessible to the OS, by further operations to: perform movement of the data and / or instructions based on determining that the data and / or instructions satisfy a criteria for importance to operation of the host computing device.
10. The host computing device of Claim 9 wherein the determination that the data and / or instructions satisfy the criteria for importance to operation of the host computing device, is performed using at least one of: metadata logically associated with the data and / or instructions, a process number logically associated with the instructions, a hash value generated from combination of values of the instructions, a process privilege logically associated with the instructions, a process execution level logically associated with the instructions.
11. The host computing device of any of Claims 1 to 10, wherein the network interface is further configured to: receive individual flow control units from the external computing device and to pass the individual flow control units to the routing elements for routing under control of the configuration component.
12. The host computing device of any of Claims 1 to 10, wherein the network interface is further configured, while the new routing configuration is switched-to, to: receive, from the external communication device, a data structure containing an address and a set of instructions to be operated on; translate the address into a local routing address of at least one of the subset of the circuit components; divide the set of instructions into a plurality of flow control units each containing one of the instructions and the local routing address; andP111499WO01pass the flow control units to the routing elements for routing under control of the configuration component.
13. The host computing device of any of Claims 1 to 12, wherein: the configuration component is configured to control, based on an active routing configuration, the selective routing by the routing elements of flow control units between the circuit components, by operations to: determine at least one routing restriction based on the active routing configuration, and send the at least one routing restriction to the routing elements; and the routing elements are configured to use the at least one routing restriction to selectively perform at least one of: a) only route flow control units in a one-way direction defined by the at least one routing restriction; b) only route flow control units to addresses listed in an address set defined by the at least one routing restriction; c) only route flow control units to a single address defined by the at least one routing restriction; and d) require routing elements to allow bidirectional routing of flow control units.
14. The host computing device of any of Claims 1 to 13, wherein: the configuration component is configured to control, based on an active routing configuration, the selective routing by the routing elements of flow control units between the circuit components, by operations to: determine at least one routing restriction based on the active routing configuration, and send the at least one routing restriction to the routing elements; and the routing elements are configured to use the at least one routing restriction to selectively perform at least one of: a) only route to the network interface flow control units that arrive from a circuit component listed in a subset of components defined by the at least one routing restriction; and b) only route flow control units that arrive at the network interface flow control units to the circuit components defined by the at least one routing restriction.
15. The host computing device of any of Claims 1 to 14, wherein:P111499WO01the configuration component is configured to determine from an indication contained in the reconfiguration request at least one type of circuit component that is to be configured for use by the external computing device.
16. The host computing device of Claim 15, wherein: the configuration component is configured to create a routing configuration that controls the routing elements to allow routing of flow control units to at least one circuit component corresponding to the determined type of circuit component to become available for use by the external computing device.
17. The host computing device of any of Claims 1 to 16, wherein the configuration component is further configured to, following the switch from the present routing configuration to the new routing configuration: receive, via the network interface from the external computing device, a release request indicating the external computing device no longer needs use of the subset of the circuit components; and responsive to the release request, switch to a routing configuration that controls the routing elements to render the subset of the circuit components accessible to the OS and which renders the subset of the circuit components no longer accessible to the external computing device, and identify to the OS the subset of the circuit components that has become accessible to the OS.
18. The host computing device of any of Claims 1 to 17, wherein the configuration component is further configured to, following the switch from the present routing configuration to the new routing configuration: receive from the OS an indicated need to revert to the routing configuration that was active before the switch to the new routing configuration; responsive to the indicated need to revert, inform the external computer device of the need to revert configuration; and responsive to an acknowledgement received from the external computer device and / or expiration of a threshold time duration since informing the external computer device, switch from the new routing configuration to the routing configuration that was active before the switch to the new routing configuration.P111499WO0119. The host computing device of any of Claims 1 to 18, wherein the configuration component is further configured to: responsive to receipt of the request, validate that the external computing device is allowed by an access policy to access circuit components of the NoC.
20. The host computing device of any of Claims 1 to 19, wherein the routing elements and / or the configuration component is further configured to: validate flow control units received from the external computing device via the network interface as a condition for routing based on the new routing configuration to the subset of the circuit components.
21. A method by a host computing device comprising a network interface configured to communicate through at least one network with an external computing device, a network on chip, NoC, comprising a set of circuit components, and routing elements configured to selectively route flow control units between the circuit components and between the network interface and the circuit components, the method comprising: controlling (500), based on a present routing configuration, the selective routing by the routing elements of flow control units between the circuit components; receiving (502), via the network interface from the external computing device, a reconfiguration request requesting a change from the present routing configuration that results in a new routing configuration which when switched-to will render a subset of the circuit components of the NoC inaccessible to an operating system, OS, of the host computing device but accessible to the external computing device; responsive to the request, identifying (504) to the OS the subset of the circuit components of the NoC that will become inaccessible; and responsive to an indicated completion by the OS of removal or discontinued use of data and / or instructions from the subset of the circuit components, switching from the present routing configuration to the new routing configuration including by controlling (506), based on the new routing configuration, the routing by the routing elements of flow control units between the subset of the circuit components and the external computing device via the network interface, and further controlling (508), based on the new routing configuration, the routing by the routing elements of flow control units between the circuit components accessible to the OS.P111499WO01
Citation Information
Patent Citations
Secure utilization of external hardware
WO2023247038A1