IP Library Granted Patent US 11,651,111
Granted Patent B2
US 11,651,111 · App. 17/129,250 · Granted May 16, 2023

Enabling secure state-clean during configuration of partial reconfiguration bitstreams on FPGA

Inventors: Alpa Trivedi (Portland, OR); Scott Weber (Piedmont, CA); Steffen Schulz (Darmstadt, DE); Patrick Koeberl (Alsbach-Haenlein, DE)
Assignee: INTEL CORPORATION
G06F21/85G06F9/30101G06F9/3877G06F9/505G06F11/0709G06F11/0751G06F11/0754G06F11/0793G06F11/3058G06F15/177G06F15/7825G06F15/7867G06F30/331G06F30/398G06N3/04H04L9/0877H04L63/0442H04L63/12H04L63/20G06F11/0772G06F11/3051G06F21/30G06F21/44G06F21/53G06F21/57G06F21/575G06F21/71G06F21/73G06F21/74G06F21/76G06F30/31G06F2111/04G06F2119/12G06F2221/034G06N3/08G06N20/00H04L9/008H04L9/0841
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,651,111
App. No.
17/129,250
Granted
May 16, 2023
Kind
B2
Abstract

An apparatus to facilitate enabling secure state-clean during configuration of partial reconfiguration bitstreams on accelerator devices is disclosed. The apparatus includes a security engine to receive an incoming partial reconfiguration (PR) bitstream corresponding to a new PR persona to configure a region of the apparatus; perform, as part of a PR configuration sequence for the new PR persona, a first clear operation to clear previously-set persona configuration bits in the region; perform, as part of the PR configuration sequence subsequent to the first clear operation, a set operation to set new persona configuration bits in the region; and perform, as part of the PR configuration sequence, a second clear operation to clear memory blocks of the region that became unfrozen subsequent to the set operation, the second clear operation performed using a persona-dependent mask corresponding to the new PR persona.

Claims (36)

1. An apparatus comprising:

a programmable integrated circuit (IC) comprising processing hardware circuitry to:

receive an incoming partial reconfiguration (PR) bitstream corresponding to a PR persona, wherein the incoming PR bitstream is to configure a region of the programmable IC; and

perform an implicit state clean process of the region of the programmable IC as part of a PR configuration sequence for the incoming PR bitstream, the implicit state clean process comprising:

a first clear operation to clear previously-set persona configuration bits in the region;

a set operation, performed subsequent to the first clear operation, to set new persona configuration bits in the region; and

a second clear operation to clear memory blocks of the region that became unfrozen subsequent to the set operation, the second clear operation performed using a persona-dependent mask corresponding to the PR persona.

2. The apparatus of claim 1 , wherein the processing hardware circuitry to implement a security engine to manage the implicit state clean process, and wherein the security engine comprises a configuration manager and security enclave for the programmable IC.

3. The apparatus of claim 1 , wherein the first clear operation is performed using a persona-independent mask that is publicly authenticated.

4. The apparatus of claim 3 , wherein the persona-independent mask is not under control of a tenant of the programmable IC.

5. The apparatus of claim 1 , wherein the second clear operation is performed by loading the memory blocks with zeros.

6. The apparatus of claim 1 , wherein the PR bitstream implements a PR tenant workload.

7. The apparatus of claim 1 , wherein the apparatus comprises a hardware accelerator device comprising the programmable IC.

8. The apparatus of claim 7 , wherein the programmable IC comprises at least one of a field programmable gate array (FPGA), a programmable array logic (PAL), a programmable logic array (PLA), a field programmable logic array (FPLA), an electrically programmable logic device (EPLD), an electrically erasable programmable logic device (EEPLD), a logic cell array (LCA), or a complex programmable logic devices (CPLD).

9. A method comprising:

receiving, by a programmable integrated circuit (IC), an incoming partial reconfiguration (PR) bitstream corresponding to a PR persona, wherein the PR bitstream is to configure a region of the programmable IC; and

performing, by the programmable IC, an implicit state clean process of the region of the programmable IC as part of a PR configuration sequence for the incoming PR bitstream, the implicit state clean process comprising:

a first clear operation to clear previously-set persona configuration bits in the region;

a set operation, performed subsequent to the first clear operation, to set new persona configuration bits in the region; and

a second clear operation to clear memory blocks of the region that became unfrozen subsequent to the set operation, the second clear operation performed using a persona-dependent mask corresponding to the PR persona.

10. The method of claim 9 , wherein the programmable IC to implement a security engine to manage the implicit state clean process, and wherein the security engine comprises a configuration manager and security enclave for the programmable IC.

11. The method of claim 9 , wherein the first clear operation is performed using a persona-independent mask that is publicly authenticated, and wherein the persona-independent mask is not under control of a tenant of the programmable IC.

12. The method of claim 9 , wherein the second clear operation is performed by loading the memory blocks with zeros.

13. The method of claim 9 , wherein the PR bitstream implements a PR tenant workload.

14. The method of claim 9 , wherein the programmable IC comprises at least one of a field programmable gate array (FPGA), a programmable array logic (PAL), a programmable logic array (PLA), a field programmable logic array (FPLA), an electrically programmable logic device (EPLD), an electrically erasable programmable logic device (EEPLD), a logic cell array (LCA), or a complex programmable logic devices (CPLD).

15. A non-transitory machine readable storage medium comprising instructions that, when executed, cause at least one processor to at least:

receive, by a programmable integrated circuit (IC) comprising the at least one processor, an incoming partial reconfiguration (PR) bitstream corresponding to a PR persona, wherein the PR bitstream is to configure a region of the programmable IC; and

perform, by the programmable IC, an implicit state clean process of the region of the programmable IC as part of a PR configuration sequence for the incoming PR bitstream, the implicit state clean process comprising:

a first clear operation to clear previously-set persona configuration bits in the region;

a set operation, performed subsequent to the first clear operation, to set new persona configuration bits in the region; and

a second clear operation to clear memory blocks of the region that became unfrozen subsequent to the set operation, the second clear operation performed using a persona-dependent mask corresponding to the new PR persona.

16. The non-transitory machine readable storage medium of claim 15 , wherein the programmable IC to implement a security engine to manage the implicit state clean process, and wherein the security engine comprises a configuration manager and security enclave for the programmable IC.

17. The non-transitory machine readable storage medium of claim 15 , wherein the first clear operation is performed using a persona-independent mask that is publicly authenticated, and wherein the persona-independent mask is not under control of a tenant of the programmable IC.

18. The non-transitory machine readable storage medium of claim 15 , wherein the second clear operation is performed by loading the memory blocks with zeros.

19. The non-transitory machine readable storage medium of claim 15 , wherein the PR bitstream implements a PR tenant workload.

20. The non-transitory machine readable storage medium of claim 15 , wherein the programmable IC comprises at least one of a field programmable gate array (FPGA), a programmable array logic (PAL), a programmable logic array (PLA), a field programmable logic array (FPLA), an electrically programmable logic device (EPLD), an electrically erasable programmable logic device (EEPLD), a logic cell array (LCA), or a complex programmable logic devices (CPLD).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2021
From: TRIVEDI, ALPA; WEBER, SCOTT; SCHULZ, STEFFEN; KOEBERL, PATRICK
To: INTEL CORPORATION
Reel/Frame 055423/0271 →
Continuity (2)
Provisional Application 63083783 · Sep 25, 2020
Related Publication 20210110069A1 · Apr 15, 2021
Cited By (3)
US 12,287,909 US 12,340,007 US 12,346,489