IP Library › Granted Patent US 11,956,220
Granted Patent B2
US 11,956,220 · App. 17/518,259 · Granted Apr 9, 2024

Logic repository service using encrypted configuration data

Inventors: Islam Mohamed Hatem Abdulfattah Mohamed Atta (Vancouver, CA); Christopher Joseph Pettey (Cedar Park, TX); Nafea Bshara (San Jose, CA); Asif Khan (Cedar Park, TX); Mark Bradley Davis (Austin, TX); Prateek Tandon (Issaquah, WA)
Assignee: Amazon Technologies, Inc.
H04L63/0428G06F9/50G06F15/7871H04L9/3247H04L2209/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,956,220
App. No.
17/518,259
Granted
Apr 9, 2024
Kind
B2
Abstract

The following description is directed to a logic repository service. In one example, a method of a logic repository service can include receiving a first request to generate configuration data for configurable hardware using a specification for application logic of the configurable hardware. The method can include generating the configuration data for the configurable hardware. The configuration data can include data for implementing the application logic. The method can include encrypting the configuration data to generate encrypted configuration data. The method can include signing the encrypted configuration data using a private key. The method can include transmitting the signed encrypted configuration data in response to the request.

Claims (28)

1. A method, comprising:

storing, in a database of a compute service provider, integrated hardware data including host logic of the compute service provider integrated with a hardware design received from a third-party developer, wherein the integrated hardware data is configured to be programmed into a field-programmable gate array (FPGA) on a server computer;

receiving a request to launch a virtual machine instance in the compute service provider, wherein the request includes an identifier to the integrated hardware data;

retrieving the integrated hardware data in response to the request to launch the virtual machine instance; and

transmitting the integrated hardware data to the server computer to configure the FPGA in conjunction with launching the virtual machine instance on the server computer.

2. The method of claim 1 , further including receiving a request to generate the integrated hardware data, wherein the request includes fields for specifying metadata about the hardware design, user information and access privileges for the hardware design.

3. The method of claim 1 , further including encrypting the integrated hardware data and storing an encrypted bitstream associated with the encrypted integrated hardware data in a database.

4. The method of claim 3 , further comprising verifying, on the server computer, a signature of the encrypted bitstream using a public key.

5. The method of claim 1 , further including generating the integrated hardware data comprising synthesizing the hardware design to generate a netlist compatible with the FPGA.

6. The method of claim 1 , wherein the request to launch the virtual machine instance includes a request for a particular central processing unit (CPU) to be executing in the server computer and in communication with the FPGA.

7. The method of claim 6 , wherein the host logic controls bus transactions between the hardware design programmed into the FPGA and the CPU.

8. The method of claim 1 , further including executing verification tests to determine that the hardware design fits into the FPGA on the server computer and is compatible with the host logic.

9. The method of claim 1 , further including analyzing whether the hardware design includes prohibited logic functions.

10. The method of claim 9 , wherein a prohibited function includes a ring oscillator.

11. A computer system, comprising:

one or more processors that execute instructions to:

store data associated with hardware logic designed to be programmed into a field-programmable gate array (FPGA) on a server computer;

encrypt the data to generate encrypted data associated with the hardware logic;

sign the encrypted data with a private key and store the signed encrypted data in a database;

receive a request to launch a virtual machine instance in association with the hardware logic;

in response to the request to launch the virtual machine instance, retrieve the signed encrypted data from the database and transmit the signed encrypted data to the server computer designated to launch the virtual machine instance;

using the server computer, decrypt the signed encrypted data to retrieve the hardware design and program the FPGA using the hardware design; and

launch the virtual machine instance on the server computer.

12. The computer system of claim 11 , wherein the server computer is a first server computer and wherein the encrypting and signing occur on a second server computer, different than the first server computer.

13. The computer system of claim 11 , wherein the one or more processors further execute the instructions to perform verification tests to determine that the hardware logic fits into the FPGA.

14. The computer system of claim 11 , wherein the one or more processors further execute the instructions to analyze whether the hardware logic includes prohibited logic functions on the server computer.

15. The computer system of claim 11 , wherein the hardware logic is provided to the computer system from a third-party developer and wherein the computer system executes instructions to integrate host logic with the hardware logic, wherein the host logic limits access by the hardware logic to the one or more processors on the server computer.

16. The computer system of claim 15 , wherein the host logic controls bus transactions between the hardware design programmed into the FPGA and the CPU.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2021
From: ATTA, ISLAM MOHAMED HATEM ABDULFATTAH MOHAMED; PETTEY, CHRISTOPHER JOSEPH; BSHARA, NAFEA; KHAN, ASIF; DAVIS, MARK BRADLEY; TANDON, PRATEEK
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 058011/0599 →
Continuity (4)
Continuation 17017970 · Sep 11, 2020
Continuation 16287973 · Feb 27, 2019
Continuation 15280677 · Sep 29, 2016
Related Publication 20220060454A1 · Feb 24, 2022
Cited By (1)
US 12,204,481