Chiplet CPU Security Agent for Instant Accelerator Firmware Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern server systems face limitations with Peripheral Component Interconnect Express (PCIe) connections, such as limited shared address space between CPUs and accelerators, high bandwidth and low latency requirements, and restricted number of ports and lanes, which affect efficiency and balance in CPU-accelerator ratios.
Innovation Solution
Implementing a system-on-chip (SoC) with a uniform memory access tunneling system that allows accelerators to directly access shared memory via a die-to-die interface using a high-speed, low-latency protocol like Chiplet Data Exchange (CDX), bypassing the need for accelerator memory during processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If PCIe connections are used to connect accelerators to CPUs, then accelerators can be attached to the system, but the number of accelerators is limited due to restricted port and lane counts
Solution Approach 1:
The patent segments the accelerator interface into multiple die-to-die interfaces within a single SoC package. Instead of relying on external PCIe lanes, the system uses internal chiplet interconnects to provide multiple parallel communication paths, effectively increasing the number of accelerators that can be attached without being limited by external port counts
Solution Approach 2:
The patent transitions from external PCIe connectivity to internal die-to-die connectivity within the SoC architecture. This dimensional shift from external to internal connections enables unlimited accelerator attachment by utilizing the three-dimensional chiplet stacking and interconnect architecture of modern SoCs
2Speed
If PCIe connections are used for accelerator communication, then accelerators can access memory, but bandwidth is limited and latency increases
Solution Approach 1:
The patent introduces a unified memory space as an intermediary that bridges the CPU and accelerators. This shared memory space allows direct memory access without PCIe protocol overhead, enabling high-speed data transfer and eliminating the latency associated with PCIe transaction processing
Solution Approach 2:
The patent replaces the mechanical PCIe physical layer with a virtualized memory access mechanism. Instead of relying on physical PCIe lanes and their associated electrical signaling, the system uses a unified memory space abstraction that enables direct access with minimal latency
3Adaptability or versatility
If PCIe is used for accelerator connections, then accelerators can be integrated, but shared address space access is restricted
Solution Approach 1:
The patent creates a universal memory space that serves both the CPU and accelerators with a single unified address space. This multi-functional memory architecture eliminates the need for separate address spaces and PCIe configuration mechanisms, providing universal access to all memory resources through a consistent addressing paradigm
4Productivity
If limited PCIe ports are used, then system complexity is reduced, but the ability to balance CPU-to-accelerator ratios is compromised
Solution Approach 1:
The patent segments the accelerator interface into multiple die-to-die interfaces within the SoC, allowing multiple accelerators to be connected through internal chiplet interconnects rather than being limited by external PCIe port counts. This enables flexible configuration of CPU-to-accelerator ratios
Solution Approach 2:
The patent implements a dynamic resource allocation mechanism where the unified memory space and die-to-die interfaces can be dynamically assigned to different accelerators based on workload requirements. This dynamic configuration allows the system to adapt the CPU-to-accelerator ratio in real-time without being constrained by fixed PCIe port allocations
Data Source
AI summary
In some embodiments, a computer-implemented method includes receiving, at a security agent of a host central processing unit (CPU), accelerator firmware from flash memory; determining, at the security agent, whether the accelerator firmware includes a critical accelerator firmware component or a non-critical accelerator firmware component; authenticating, at the security agent, the critical accelerator firmware component instantaneously upon a determination that the accelerator firmware is the critical accelerator firmware component, wherein authenticating the critical accelerator firmware component yields an authenticated critical accelerator firmware component; and providing the authenticated critical accelerator firmware component to an accelerator via a sideband bus for execution at the accelerator.


