Granular access control for secure memory

By introducing a secure storage architecture and fine-grained access control into the machine learning system, the problem of protecting sensitive data in an untrusted environment in machine learning systems is solved, and secure access control of sensitive data is achieved, protecting user privacy and the rights of content providers.

CN113853594BActive Publication Date: 2026-01-16SYNAPTICS INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080040012.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-05-30
Filing Date
2020-05-21
Publication Date
2026-01-16
Estimated Expiration
2040-05-21

AI Technical Summary

Technical Problem

Existing technologies struggle to protect sensitive data outside of trusted environments, especially in machine learning systems, by preventing malicious code and untrusted hardware from accessing sensitive data.

Method used

It adopts a secure memory architecture, including secure partitions and non-secure partitions, and is configured with a neural network processing unit (NPU) and a memory protection unit (MPU). It filters memory access by address, master identifier and security information in transactions, and realizes fine-grained control over secure partitions.

Benefits of technology

Effectively protect sensitive data from untrusted environments, ensure that only trusted hardware and applications can access it, achieve fine-grained access control over data, and protect user privacy and the rights of content providers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113853594B_ABST
    Figure CN113853594B_ABST
Patent Text Reader

Abstract

A secure processing system includes a memory having a secure partition and a non-secure partition, a neural processing unit (NPU) configured to initiate transactions with the memory, and a memory protection unit (MPU) configured to filter the transactions. Each of the transactions includes at least an address of the memory to access, one of a plurality of first master part identifiers (IDs) associated with the NPU, and security information indicating whether the NPU was in a secure state or a non-secure state when the transaction was initiated. The MPU selectively denies access to the secure partition of the memory based at least in part on the memory address, the first master part ID, and the security information associated with each of the transactions.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] This embodiment relates generally to systems and devices with secure memory. BACKGROUND

[0002] Secure memory architectures provide a high level of security for sensitive data such that only applications and / or hardware residing within a trusted environment can access the sensitive data. As such, secure memory protects sensitive data from any hardware and / or applications (including malicious code) that can be executing outside of the trusted environment. Some processing systems can include various processors and / or other components that need access to certain sensitive data. For example, a neural network processor can be configured to perform machine learning on user input data, biometric data, and / or premium media content data.

[0003] Machine learning is a technique for improving the ability of a computer system or application to perform a particular task. Machine learning can be broken down into two components: training and inference. During the training phase, a machine learning system is provided with “answers” and a large amount of raw data associated with the answers. For example, a machine learning system can be trained to recognize cats by providing the system with a large number of cat photos and / or videos (e.g., raw data) and an indication that the provided media contains a “cat” (e.g., an answer). The machine learning system can then analyze the raw data to “learn” a set of rules that can be used to describe the answer. For example, the system can perform a statistical analysis of the raw data to determine a common set of features (e.g., rules) that can be associated with the term “cat” (e.g., whiskers, claws, fur, four legs, etc.). During the inference phase, the machine learning system can apply the rules to new data to generate answers or inferences about the data. For example, the system can analyze a family photo and determine, based on the learned rules, that the photo includes an image of a cat. SUMMARY

[0004] This summary is provided to introduce a selection of concepts, in a simplified form, that are further described below in the detailed description. This summary is neither intended nor should it be construed to be a key to the identification of the key features of the claimed subject matter, nor should it be construed as an indication of the scope of the claimed subject matter.

[0005] A method and apparatus for secure machine learning are disclosed. One innovative aspect of the subject matter of this disclosure can be implemented in a secure processing system that includes a memory having a secure partition and a non-secure partition, a neural network processing unit (NPU) configured to initiate transactions with the memory, and a memory protection unit (MPU) configured to filter the transactions. Each of the transactions includes at least an address of the memory to be accessed, one of a plurality of first master part identifiers (IDs) associated with the NPU, and security information indicating whether the NPU was in a secure state or a non-secure state when the transaction was initiated. The MPU is to selectively deny access to the secure partition of the memory based at least in part on the memory address, the first master part ID, and the security information associated with each of the transactions.

[0006] Another innovative aspect of the subject matter of this disclosure can be implemented in a memory apparatus that includes a secure partition, a non-secure partition, and a memory protection unit (MPU). The MPU is configured to receive transactions from a neural network processing unit (NPU) and filter the transactions. Each of the transactions includes at least an address of the memory to be accessed, one of a plurality of master part IDs associated with the NPU, and security information indicating whether the NPU was in a secure state or a non-secure state when the transaction was initiated. The MPU is to selectively deny access to the secure partition of the memory based at least in part on the memory address, the first master part ID, and the security information associated with each of the transactions. BRIEF DESCRIPTION OF DRAWINGS

[0007] The present embodiments are illustrated by way of example and not intended to be limited by the figures of the accompanying drawings.

[0008] Figure 1 A block diagram of a machine learning system is shown in accordance with some embodiments.

[0009] Figure 2 A block diagram of a user device is shown in accordance with some embodiments.

[0010] Figure 3 A block diagram of a processing system is shown in accordance with some embodiments.

[0011] Figure 4 An example memory access transaction is shown in accordance with some embodiments.

[0012] Figure 5 A neural network processor with multiple master part IDs is shown in accordance with some embodiments.

[0013] Figure 6 A block diagram of a memory apparatus is shown in accordance with some embodiments.

[0014] Figure 7This is an illustrative flowchart depicting example operations for filtering memory access transactions according to some embodiments.

[0015] Figure 8 This is an illustrative flowchart depicting more detailed operations for filtering memory access transactions according to some embodiments. Detailed Implementation

[0016] In the following description, numerous specific details, such as examples of specific components, circuits, and processes, are set forth to provide a thorough understanding of this disclosure. As used herein, the term "coupled" means a direct connection to or a connection via one or more intermediate components or circuits. Furthermore, specific terminology is set forth in the following description and for purposes of explanation to provide a thorough understanding of aspects of this disclosure. However, it will be apparent to those skilled in the art that practical example embodiments may not require these specific details. In other instances, well-known circuits and devices are illustrated in block diagram form to avoid obscuring this disclosure. Some portions of the following detailed description are presented according to procedures, logic blocks, processes, and other symbolic representations of operations on data bits within computer memory. Interconnections between circuit elements or software blocks may be shown as buses or single signal lines. Each bus may alternatively be a single signal line, and each single signal line may alternatively be a bus, and a single line or bus may represent any one or more of the numerous physical or logical mechanisms used for communication between components.

[0017] Unless otherwise expressly stated (as is evident from the discussion below), it should be understood that throughout this application, discussions using terms such as “access,” “receive,” “send,” “use,” “select,” “determine,” “standardize,” “multiply,” “average,” “monitor,” “compare,” “apply,” “update,” “measure,” and “derive” refer to the actions and processes of a computer system or similar electronic computing device that manipulate and convert data represented as physical (electronic) quantities in the registers and memories of the computer system into other data represented as physical quantities in the memory or registers of the computer system or other such information storage, transmission, or display devices.

[0018] Unless explicitly described as being implemented in a particular manner, the techniques described herein can be implemented in hardware, software, firmware, or any combination thereof. Any feature described as a module or component may also be implemented together in an integrated logic device, or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be implemented at least in part by a non-transitory computer-readable storage medium comprising instructions that, when executed, perform one or more of the methods described above. The non-transitory computer-readable storage medium may form part of a computer program product, which may include encapsulation material.

[0019] A non-transitory processor-readable storage medium can include random access memory (RAM) such as synchronous dynamic random access memory (SDRAM), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, other known flash storage media, or the like. Additionally or alternatively, the technology can be implemented at least in part by a processor-readable communication medium that carries or communicates code in the form of instructions or data structures and that can be accessed, read, and / or executed by a computer or other processor.

[0020] The various illustrative logical blocks, modules, circuits, and instructions described in connection with the embodiments disclosed herein can be executed by one or more processors. The term "processor" as used herein can refer to any general purpose processor, conventional processor, controller, microcontroller, and / or state machine that is capable of executing scripts or instructions of one or more software programs stored in memory.

[0021] Figure 1 A block diagram of a machine learning system 100 is shown in accordance with some embodiments. The system 100 includes a deep learning environment 101 and a user device 110. The deep learning environment 101 can include memory and / or processing resources to generate or train one or more neural network models 102. In some embodiments, the neural network models 102 can be stored and / or implemented (e.g., for inference) on the user device 110. For example, the user device 110 can use the neural network models 102 to generate inferences about a user and / or content that the user is viewing or listening to.

[0022] The deep learning environment 101 can be configured to generate one or more neural network models 102 through deep learning. Deep learning is a form of machine learning in which the training phase is performed over multiple layers, generating a more abstract set of rules in each successive layer. Deep learning architectures are often referred to as artificial neural networks due to the way in which information is processed (e.g., similar to a biological nervous system). For example, each layer of a deep learning architecture can be composed of many artificial neurons. The neurons can be interconnected across the various layers such that input data (e.g., raw data) can be passed from one layer to another. More specifically, each layer of neurons can perform a different type of transformation on the input data, which ultimately results in a desired output (e.g., an answer). The interconnected framework of neurons can be referred to as a neural network model. Thus, the neural network models 102 can include a set of rules that can be used to describe a particular object or feature, such as, for example, a human face, a voice, and / or other features that contain biometric information.

[0023] The deep learning environment 101 can have access to a large amount of raw data and can be trained to identify a set of rules associated with the raw data (e.g., certain objects, features, quality of service, such as quality of received signal or pixel data, and / or other detectable attributes). In some aspects, the deep learning environment 101 can be trained to identify a human face. During a training phase, the deep learning environment 101 can process or analyze a large number of images and / or videos containing human faces. The deep learning environment 101 can also receive an indication that provided media contains a human face (e.g., in the form of user input from a user or operator viewing the media, data, and / or metadata provided with the media). The deep learning environment 101 can then perform a statistical analysis on the images and / or videos to determine a common set of features associated with the human face. In some aspects, the determined features or rules can form an artificial neural network that spans multiple layers of abstraction.

[0024] The deep learning environment 101 can provide the set of rules to the user device 110 (e.g., as a neural network model 102) for inference. In some aspects, one or more neural network models 102 can be provided to the user device 110 at a device manufacturing stage (e.g., stored on the user device 110). For example, the user device 110 can be pre-loaded with the neural network model 102 before being shipped to an end user. In some other aspects, the user device 110 can receive one or more neural network models 102 from the deep learning environment 101 at runtime. For example, the deep learning environment 101 can be communicatively coupled to the user device 110 via one or more intermediary systems and / or networks (not shown for simplicity). Thus, the user device 110 can receive neural network models 102 (including updated neural network models) from the deep learning environment 101 at any time.

[0025] The user device 110 can be any end user or edge device. In some aspects, the user device 110 can be a device capable of providing a customizable user experience (such as a personalized user interface) based on a given user’s preferences, activities, or habits. In some other aspects, the user device 110 can be a device capable of capturing, storing, and / or playing back media content. Example user devices can include, but are not limited to, a set-top box (STB), a computer, a mobile phone, a tablet, a television (TV), a smart speaker, a voice-enabled device, and the like. The user device 110 can include one or more input sources 112, a neural network application 114, and a memory 116. The input sources 112 can be configured to receive user input and / or collect data about a user (e.g., images, videos, audio, and the like). Example suitable input sources can include, but are not limited to, a keyboard, a mouse, a joystick, a camera, a capacitive sensor, a touchpad, a fingerprint sensor, a microphone, an audio recording device, and the like.

[0026] The neural network application 114 can be configured to generate one or more inferences regarding input data captured by the input source 112 and / or media content stored or buffered on the user device 110. For example, in some aspects, the neural network application 114 can analyze the input data and / or media content to infer or identify objects of interest (e.g., faces, voices, logos, destinations, etc.) contained therein. In some embodiments, the neural network application 114 can generate inferences based on the neural network models 102 provided by the deep learning environment 101. For example, during an inference phase, the neural network application 114 can apply the neural network models 102 to new input data and / or media content by traversing artificial neurons in the artificial neural network to infer information about the data.

[0027] In some embodiments, the neural network application 114 can be configured to operate in an offline manner. Specifically, aspects of the present disclosure recognize that it can not be desirable, if not impossible, to send certain types of sensitive data to the deep learning environment 101 for inference. For example, content providers and / or creators can limit the sharing or distribution of premium media content (e.g., TV shows, movies, music, and / or media content authored by third-party content creators or providers). Additionally, users can not want to send their personal information (e.g., input data, biometric data, etc.) to the cloud, which can be accessible by others. By performing inferences locally on the user device 110 itself, the embodiments described herein can be used to perform machine learning in a manner that protects the privacy of users and the rights of content providers.

[0028] The memory 116 can store input data received via the input source 112 and / or media content received via one or more content delivery networks (not shown for simplicity). In some aspects, the memory 116 can buffer media content for playback and / or display on the user device 110 or a display device (such as a TV) or audio device (such as a speaker) coupled to the user device 110. For example, the memory 116 can operate as a decoded video frame buffer that stores or buffers pixel data (decoded) associated with media content to be presented or displayed by the user device 110. In another example, the memory 116 can operate as a decoded audio buffer that stores or buffers decoded audio data associated with media content to be output or played back by the user device 110.

[0029] In some implementations, the memory 116 can include a secure repository to provide an additional layer of security for certain sensitive data. The secure repository can be virtually and / or physically partitioned from the rest of the user device 110, such that only applications and / or hardware that reside within a trusted environment can access data stored in the secure repository. Any hardware and / or applications operating outside of the trusted environment (e.g., in a rich environment) can be restricted from accessing data stored in the secure repository. Furthermore, hardware and / or applications within the trusted environment can have very limited, if any, communication with the outside world. The separation between the environments protects the secure repository from any malicious code and / or applications that can be executed in the rich environment. Thus, it can be desirable to store protected data (e.g., input data, premium media content, etc.) in the secure repository.

[0030] In some embodiments, the neural network application 114 can reside within a trusted environment of the user device 110. Placing the neural network application 114 in the trusted environment enables the neural network application 114 to perform machine learning on input data and / or media content in a secure manner, while also protecting the privacy of the user and the rights of the content provider. For example, input data and / or media content used in inference can be stored in the secure repository of the memory 116 and thus protected from hacking from the rich environment. Furthermore, certain types of media content (e.g., premium media content) can only be stored in the secure repository. Thus, placing the neural network application 114 within the trusted environment enables inference to be performed on protected data that would otherwise be inaccessible from the rich environment.

[0031] Figure 2 A block diagram of a user device 200 is shown in accordance with some embodiments. The user device 200 can be an example embodiment of the user device 110 Figure 1 The user device 200 includes a hardware platform 230 and a software execution environment 201. The hardware platform 230 can include any hardware of the user device 200 (e.g., processors, memory, communication interfaces, etc.). The software execution environment 201 includes any software or instructions (e.g., kernels, operating systems, applications, etc.) that execute on the hardware platform 230.

[0032] In some embodiments, the software execution environment 201 may be divided into an enrichment environment 210 and a trusted environment 220. The enrichment environment 210 may include one or more user applications 212, a rich neural network application 214, and a Trusted Execution Environment (TEE) client application programming interface (API) 216. The trusted environment 220 may include one or more trusted applications 222, a trusted neural network application 224, and a TEE kernel 226. As described above, the trusted environment 220 may be physically and / or virtually separated (e.g., isolated or separated) from the enrichment environment 210. More specifically, only software or instructions executing in the trusted environment 220 may access the secure hardware (HW) resources 232 residing on the hardware platform 230.

[0033] For the purposes of this discussion, any hardware resource capable of executing or processing instructions on behalf of trusted applications 222-226 may be referred to as residing in and / or operating within trusted environment 220. Depending on the application being executed, such hardware resources may be configured to operate in a secure or insecure state. On the other hand, hardware resources that cannot execute or process instructions on behalf of any trusted applications 222-226 may be referred to as residing in and / or operating within rich environment 210. Such hardware resources are configured to operate only in an insecure state.

[0034] In some embodiments, the security hardware resource 232 may include a secure storage library or memory (such as...) for storing protected data. Figure 1 The protected data may include (or at least a portion thereof) memory 116. In some aspects, the protected data may include high-quality content (e.g., television programs, movies, music, etc.) or other media content that is protected by digital rights management (DRM), copyright, or other laws and / or regulations. In some other aspects, the protected data may include user input data (e.g., search input, content selection, biometric input, etc.) or other data that may include or reveal personal information about the user. Due to the confidentiality and / or sensitivity of the protected data, software and / or hardware outside the trusted environment 220 may not be able to access the secure hardware resource 232. Furthermore, applications within the trusted environment 220 (such as trusted application 222 and trusted neural network application 224) may be restricted from transmitting information associated with the protected data to the enrichment environment 210.

[0035] In some embodiments, user equipment 200 can perform machine learning on input data and / or media content stored on hardware platform 230. In some aspects, user equipment 200 can utilize deep learning environments (such as...) Figure 1The hardware platform 230 can receive one or more neural network models from the deep learning environment 101, which can be used to generate inferences regarding input data and / or media content stored on the hardware platform 230. In some other aspects, the user device 200 (e.g., the rich neural network application 214 and / or the trusted neural network application 224) can train or generate at least some neural network models locally based on input data and / or media content stored on the hardware platform 230.

[0036] The rich neural network application 214 can apply neural network models to unprotected data stored on the hardware platform 230 (e.g., in a non-secure partition of the hardware platform 230). However, the rich neural network application 214 can not have access to protected data stored in the secure hardware resource 232. In some embodiments, the trusted neural network application 224 can also receive neural network models from the deep learning environment (e.g., via the TEE client API 216) and can apply the neural network models to protected data stored in the secure hardware resource 232. In some aspects, the trusted neural network application 224 can also have access to unprotected data stored on the hardware platform 230.

[0037] Aspects of the present disclosure recognize that, while the trusted environment 220 provides broad blanket protection from all software and / or hardware operating in the rich environment 210, it can be desirable to provide more fine-grained access control to data stored in the trusted environment 220 (e.g., within the secure hardware resource 232). For example, inference processes can reveal private and / or personal information about users and / or media. Thus, in some embodiments, the secure hardware resource 232 can be configured to further restrict access to data stored therein on a need-to-know basis. For example, the trusted application 222 can be prevented from accessing user input data stored in the secure hardware resource 232. Further, input processing hardware (not shown for simplicity) can be prevented from accessing neural network models. Still further, neither the trusted application 222 nor the input processing hardware are permitted to access inferences generated by the trusted neural network application 214 (including any intermediate inferences).

[0038] Figure 3 A block diagram of a processing system 300 is shown in accordance with some embodiments. The processing system 300 can be an example embodiment of the user device 200 Figure 2 Although not shown (for simplicity), the processing system 300 can be physically and / or virtually partitioned into a rich environment and a trusted environment (such as the rich environment 210 and the trusted environment 220, respectively, of the user device 200). Figure 2rich environment 210 and a trusted environment 220). The processing system 300 includes an application processing unit (ACPU) 310, a neural processing unit (NPU) 320, an input processing unit (IPU) 330, and a memory device 340.

[0039] The ACPU 310 can include one or more general-purpose processors configured to execute one or more applications and / or an operating system. The ACPU 310 can include a rich execution environment (REE) 312 and a trusted execution environment (TEE) 314. The REE 312 can be consistent with a rich environment of the processing system 300 and the TEE 314 can be consistent with a trusted environment. Thus, the ACPU 310 can execute one or more trusted applications (such as the trusted application 221) in the TEE 314 and can execute one or more rich applications (such as the user application 212) in the REE 312. In some embodiments, the ACPU 310 can be configured to operate in a secure state and a non-secure state. For example, the ACPU 310 can operate in the secure state when executing applications and / or processes from the TEE 314 and can operate in the non-secure state when executing applications and / or processes from the REE 312.

[0040] The NPU 320 can include one or more processors configured to accelerate neural network inference. For example, the hardware architecture of the NPU 320 can be specifically designed to be faster and / or more efficient at traversing neural networks than a general-purpose processor (such as the ACPU 310). In some embodiments, the ACPU 310 can invoke the NPU 320 to execute a trusted neural network application (such as the trusted neural network application 224). Thus, in some embodiments, the NPU 320 can also be configured to operate in a secure state. For example, the NPU 320 can reside in a trusted environment of the processing system 300. When operating in the secure state, the NPU 320 can communicate with and have access to software and / or hardware resources (such as the secure HW resources 232) that reside in the trusted environment.

[0041] IPU 330 can include hardware resources configured to process user input 305 (e.g., by filtering, analyzing, encoding, etc.) for storage or other use by processing system 300. User input 305 can include text-based input provided by a user, selection-based input, and / or biometric input. User input 305 can be received and / or detected by one or more input devices 335. Example input devices can include, but are not limited to, a keyboard, a mouse, a joystick, a camera, a capacitive sensor, a touchpad, a fingerprint sensor, a microphone, an audio recording device, etc. In some embodiments, one or more input devices 335 can reside in a trusted environment of processing system 300. In some implementations, ACPU 310 can configure IPU 330 to process user input 305 related to a trusted neural network application. Accordingly, IPU 330 can also reside in the trusted environment and can be configured to operate in a secure state. When operating in the secure state, IPU 330 can communicate with and have access to software and / or hardware resources residing in the trusted environment, such as secure HW resources 232.

[0042] ACPU 310, NPU 320, and IPU 330 can initiate memory access transactions 301-303 with memory device 340, respectively. For example, each of transactions 301-303 can include a read transaction (e.g., reading data from memory device 340) or a write transaction (e.g., writing data to memory device 340). The initiator of a transaction can be referred to as a “master,” and the recipient of a transaction can be referred to as a “slave.” Accordingly, for discussion purposes, ACPU 310, NPU 320, and IPU 330 can generally be referred to herein as a plurality of masters. Although processing system 300 is shown as including 3 masters 310-330, in some embodiments, processing system 300 can include fewer or more masters than those depicted in FIG. 3. Figure 3 In some embodiments, processing system 300 can include a single master that is configured to initiate transactions with memory device 340. In some embodiments, processing system 300 can include a plurality of masters that are configured to initiate transactions with memory device 340. In some embodiments, processing system 300 can include a plurality of masters that are configured to initiate transactions with memory device 340 and a plurality of slaves that are configured to receive transactions from memory device 340.

[0043] Memory device 340 includes a memory protection unit (MPU) 350, a secure partition 360, and a non-secure partition 370. Secure partition 360 and non-secure partition 370 can be physically and / or virtually separated from one another. In some embodiments, memory partitions 360 and 370 can each include different address spaces of a shared memory device (e.g., DRAM). In some other embodiments, memory partitions 360 and 370 can be implemented on separate memory devices. Non-secure partition 370 permanently resides in the rich environment and thus can be configured to store any data that needs to be accessed by REE 312 and other software and / or hardware resources operating from the rich environment. In contrast, secure partition 360 permanently resides in the trusted environment and thus can be configured to store data that will only be accessible to TEE 314 and other software and / or hardware resources operating from the trusted environment, such as NPU 320 and / or IPU 330.

[0044] In some embodiments, secure partition 360 can be further subdivided into a plurality of secure memory regions or zones 362-366. Each of secure memory zones 362-366 can span one or more physical and / or virtual memory addresses of secure partition 360. In some aspects, each of secure memory zones 362-366 can be configured to store data for a different subset of software and / or hardware resources operating in the trusted environment. For example, a first secure memory zone 362 can store data for TEE 314 (e.g., ACPU 310 when operating in a secure state), a second secure memory zone 364 can store data for NPU 320, and a third secure memory zone 366 can store data for IPU 330.

[0045] MPU 350 can be configured to filter memory access transactions 301-303 from master sections 310-330, respectively. More specifically, MPU 350 can operate as an access control agent between memory device 340 and master sections 310-330. For example, MPU 350 can ensure that software and / or hardware operating in the rich environment can access data stored in non-secure partition 370 but not in secure partition 360. In some embodiments, MPU 350 can be configured to provide finer-grained access control to data stored within secure partition 360. For example, in some aspects, MPU 350 can include a plurality of filters 352-366 to act as separate access control agents for secure memory zones 362-366, respectively.

[0046] The first filter 352 can selectively reject or allow transactions for the first secure memory region 362. For example, the first filter 352 can ensure that only the TEE 314 (or the ACPU 310 when operating in a secure state) can access data stored in the first secure memory region 362. The second filter 354 can selectively reject or allow transactions for the second secure memory region 364. For example, the second filter 354 can ensure that only the NPU 320 when operating in a secure state can access data stored in the second secure memory region 364. The third filter can selectively reject or allow transactions for the third secure memory region 366. For example, the third filter 356 can ensure that only the IPU 330 when operating in a secure state can access data stored in the third secure memory region 366.

[0047] In some embodiments, the MPU 350 can filter each of the transactions 301-303 based at least in part on information included within each transaction. For example, with reference to Figure 4 The memory access transaction 400 can include a transaction type 410, a memory address 420, security information 430, and a master identifier (ID) 440. The transaction type 410 indicates whether the transaction 400 is calling a read operation or a write operation. The memory address 420 indicates a physical or virtual location at which data is to be read from or written to memory. The security information 430 indicates a security state of the master that initiated the transaction 400. In some implementations, the security information 430 can be a single bit of data indicating whether the master was in a secure state or a non-secure state when the transaction 400 was initiated. The security information 430 of some masters, such as those that are permanently resident in a rich environment, can be hard-coded to reflect a non-secure state, while other masters, such as the ACPU 310, can toggle their security information 430 based on whether they are in a trusted environment or a rich environment at any given time.

[0048] The master ID 440 is a unique identifier assigned to a particular master or group of masters. In some embodiments, each master ID can be associated with only one master and cannot be reused. In some other embodiments, multiple masters (or groups of masters) can be associated with the same master ID. During a secure boot process, security software and / or firmware executing in the processing system can assign one or more master IDs to each master in the processing system. Alternatively, each master in the processing system can be hard-coded to one or more master IDs. For example, with reference to Figure 3, the ACPU 310 can have a unique master ID (Master ID ACPU) that can be used to identify transactions initiated by the ACPU 310, the NPU 320 can have a unique master ID (Master ID NPU) that can be used to identify transactions initiated by the NPU 320, and the IPU 330 can have a unique master ID (Master ID IPU) that can be used to identify transactions initiated by the IPU 330. In some embodiments, one or more masters (such as the NPU 320) can have multiple master IDs to enable access to multiple secure memory regions (e.g., as described in more detail below with respect to FIG. 4). Figure 5 and 6 more detail).

[0049] The MPU 350 can filter each transaction 400 based at least in part on the memory address 420, the security information 430, and the master ID 440. In some aspects, the MPU 350 can allow any transaction that targets the non-secure partition 370. For example, the MPU 350 can allow the transaction 400 regardless of the security information 430 or the master ID 440 so long as the memory address 420 points to a location within the non-secure partition 370. However, if the memory address 420 points to a location within the secure partition 360, the MPU 350 can further analyze the security information 430 and the master ID 440 to determine whether to allow the transaction 400. For example, the MPU 350 can broadly reject any transaction that targets the secure partition 360 that is not initiated from a secure state (e.g., the security information 430 indicates a non-secure state). If the transaction 400 is initiated from a secure state, the MPU 350 can further analyze the master ID 440 to determine whether a particular master is permitted to access a desired region of the secure partition 360 (e.g., a particular secure memory region).

[0050] For example, the first filter 352 can reject any transaction 400 that attempts to access the first secure memory region 362 where the master ID 440 is not included in a subset of master IDs (e.g., Master ID ACPU) that are permitted to access the first secure memory region 362. Similarly, the second filter 354 can reject any transaction 400 that attempts to access the second secure memory region 364 where the master ID 440 is not included in a subset of master IDs (e.g., Master ID NPU) that are permitted to access the second secure memory region 364. Still further, the third filter 356 can reject any transaction 400 that attempts to access the third secure memory region 366 where the master ID 440 is not included in a subset of master IDs (e.g., Master ID IPU) that are permitted to access the third secure memory region 366.

[0051] In some embodiments, MPU 350 can further filter each transaction 400 based at least in part on transaction type 410. More specifically, certain masters can only be permitted a particular type of access to a given memory location. In some aspects, some masters can only be given read access to a secure memory region. For example, NPU 320 can only be permitted to read input data from an input data storage location of secure partition 360. In other aspects, some masters can only be given write access to a secure memory region. For example, IPU 330 can only be permitted to write input data to an input data storage location of secure partition 360. Still further, in some aspects, one or more masters can be given both read and write access to a secure memory region. For example, NPU 320 can be permitted to both read and write a neural network model storage location of secure partition 360 (e.g., to load and / or update an existing neural network model).

[0052] Thus, for each transaction 400, MPU 350 can determine not only whether a master is permitted to access a target secure memory region (e.g., based on master ID 440), but also whether the desired type of transaction is allowed for that master for the target secure memory region (e.g., based on transaction type 410). Unless transaction 400 satisfies all three criteria for the target memory region (e.g., transaction type 410, security information 430, and master ID 440), MPU 350 can deny transaction 400 or otherwise deny access to the identified memory address 420 for the corresponding master.

[0053] As noted above, master IDs can provide more fine-grained memory access control on a per-master basis. More specifically, each master ID can be used to access a particular one of secure memory regions 362-366. For example, the master ID of ACPU 310 can be used to access only first secure memory region 362, while the master ID of IPU 330 can be used to access only third secure memory region 366. However, some masters can need to access multiple secure memory regions. For example, NPU 320 can need to access data stored in first secure memory region 362 (e.g., neural network model data) as well as data stored in third secure memory region 366 (e.g., input data). However, for security reasons, it can not be desirable to allow NPU 320 to access both secure memory regions 362 and 366 using the same master ID (e.g., Master_ID_NPU). Thus, in some embodiments, one or more masters can be assigned multiple master IDs.

[0054] Figure 5 A neural network processor (NPU) 500 with multiple master IDs is shown in accordance with some embodiments. NPU 500 can be similar to NPU 320 of FIG. 3.Figure 3 An example embodiment of the NPU 320 is provided. Therefore, the NPU 500 may include one or more processors configured to accelerate neural network inference. In some aspects, the NPU 500 may be provided by an application processor (such as...) Figure 3 The NPU driver controls and / or calls are executed on the ACPU 310. For example, the NPU driver can use the NPU control signal 501 to activate the NPU 500 to execute neural network applications.

[0055] When executing neural network applications, the NPU 500 can first access secure partitions of memory (such as...) Figure 3 The NPU 500 retrieves one or more neural network models 502 from a secure partition 360. In some embodiments, the NPU 500 may further retrieve user input data 504 from the secure partition (e.g., where the neural network application needs to perform inference on the user input data 504). The NPU 500 can then apply the neural network models 502 to the user input data 504 to generate one or more inferences about the user and / or content that the user is viewing, listening to, or otherwise interacting with. During the inference process, the NPU 500 may generate one or more intermediate inferences 506 (e.g., at one or more convolutional layers), which may be stored in a secure partition of memory. When the inference process is complete, the NPU 500 may store the inference result 508 in a secure partition of memory.

[0056] In some embodiments, each of the inputs (502 and 504) and outputs (506 and 508) of the NPU 500 can be stored in a different secure memory area within a secure partition of the memory. For example, the neural network model 502 can be stored in a secure memory area that can only be accessed by the NPU 500 and an ACPU (such as...). Figure 3 The user input data 504 can be stored in a secure location accessible only by the NPU 500 and IPU (such as the ACPU 310), while the user input data 504 can be stored in a secure location accessible only by the NPU 500 and IPU (such as the ACPU 310). Figure 3 The intermediate inference 506 and / or inference result 508 can be stored in a secure location accessible only by the NPU 500 (and inaccessible by either the ACPU or the IPU).

[0057] To facilitate this level of granularity of security within a secure enclave, aspects of the present disclosure can assign multiple master IDs to the NPU 500. For example, the NPU 500 can use a first master ID (Master ID NPU1) to access a secure memory region in which the neural network model 502 is stored, a second master ID (Master ID NPU2) to access a secure memory region in which the intermediate inference 506 is stored, a third master ID (Master ID NPU3) to access a secure memory region in which the inference result 508 is stored, and a fourth master ID (Master ID NPU4) to access a secure memory region in which the user input data 504 is stored. In some embodiments, if the NPU 500 initiates a transaction using an incorrect master ID for the region (such as attempting to access the neural network model 502 using Master ID NPU2, Master ID NPU3, or Master ID NPU4), the NPU 500 can be denied access to the secure memory region.

[0058] Figure 6 A block diagram of a memory device 600 is shown in accordance with some embodiments. The memory device 600 can be an example embodiment of the memory device 340 of Figure 3 FIG. 1. The memory device 600 includes an MPU 610 and a memory 620. In some embodiments, the memory 620 can be implemented using dynamic random access memory (DRAM). In other embodiments, the memory 620 can be implemented using various other forms of volatile or non-volatile storage devices.

[0059] Although not shown, for simplicity, the memory 620 can include a secure enclave (such as the secure enclave 360 of FIG. 1) and a non-secure enclave (such as the non-secure enclave 370 of FIG. 1). As described above with respect to FIG. 1, the secure enclave and the non-secure enclave can be physically and / or virtually separated from one another. For example, in some aspects, the secure enclave and the non-secure enclave can reside on separate memory devices. In some other aspects, the secure enclave and the non-secure enclave can reside in different regions of the same memory device. More specifically, the secure enclave can reside within a trusted environment of a corresponding processing system, while the non-secure enclave can reside within a rich environment of the processing system. Figure 3 Figure 3 In some embodiments, the memory 620 can include a plurality of secure memory regions 622-628. The secure memory regions 622-628 can be physically and / or virtually separated from one another. For example, in some aspects, the secure memory regions 622-628 can reside on separate memory devices. In some other aspects, the secure memory regions 622-628 can reside in different regions of the same memory device. More specifically, the secure memory regions 622-628 can reside within a trusted environment of a corresponding processing system, while the non-secure enclave can reside within a rich environment of the processing system.

[0060] In some embodiments, the memory 620 can include a plurality of secure memory regions 622-628. The secure memory regions 622-628 can be physically and / or virtually separated from one another. For example, in some aspects, the secure memory regions 622-628 can reside on separate memory devices. In some other aspects, the secure memory regions 622-628 can reside in different regions of the same memory device. More specifically, the secure memory regions 622-628 can reside within a trusted environment of a corresponding processing system, while the non-secure enclave can reside within a rich environment of the processing system. Figure 3 ​example embodiments of the secure memory regions 362-366. Thus, each of the secure memory regions 622-628 can span one or more physical and / or virtual memory addresses within the secure partition of the memory 620. In some aspects, each of the secure memory regions 622-628 can be configured to store data for different subsets of software and / or hardware resources operating in the trusted environment. For example, the first secure memory region 622 can store one or more neural network models, the second secure memory region 624 can store one or more intermediate inferences, the third secure memory region 626 can store one or more inference results, and the fourth secure memory region 628 can store user input data.

[0061] The MPU 610 can be configured to filter memory access transactions 602-606 intended for the memory 620. In Figure 6 example, the transactions 602-606 can be initiated by the A CPU, the NPU, and the IPU, respectively. The MPU 610 can be an example embodiment of the MPU 350 of Figure 3 Thus, the MPU 610 can operate as an access control agent between the memory 620 and multiple masters of the processing system. In some embodiments, the MPU 600 can include multiple region filters 612-618 to selectively deny or allow transactions for the secure memory regions 622-628. For example, the first region filter 612 can only allow the A CPU and / or the NPU to access data stored in the first secure memory region 622; the second region filter 614 and the third region filter 616 can only allow the NPU to access data stored in the second secure memory region 624 and the third secure memory region 626, respectively; and the fourth region filter 618 can only allow the IPU or the NPU to access data stored in the fourth secure memory region 628.

[0062] For example, with reference to Figure 4Based on the memory address 420, the security information 430, the master ID 440, and / or the transaction type 410, the MPU 610 can filter each transaction 400. In some aspects, each of the zone filters 612-618 can be configured to deny access to its respective secure memory zone 622-628 if the transaction does not include the correct master ID. For example, the zone filters 612-618 can outright reject any transaction that is not initiated from a secure state. Further, the first zone filter 612 can reject any transaction that does not include the master ID of the ACPU (Master ID ACPU) or the first master ID of the NPU (Master ID NPU1); the second zone filter 614 can reject any transaction that does not include the second master ID of the NPU (Master ID NPU2); the third zone filter 616 can reject any transaction that does not include the third master ID of the NPU (Master ID NPU3), and the fourth zone filter 618 can reject any transaction that does not include the master ID of the IPU (Master ID IPU) or the fourth master ID of the NPU (Master ID NPU4).

[0063] In some other aspects, each of the zone filters 612-618 can also be configured to deny access to its respective secure memory zone 622-628 if the transaction type (e.g., a read or write operation) is not permitted for the associated master ID. More specifically, the zone filters 612-618 can limit access to the secure memory zones 622-628 on a per-master, per-transaction type basis. For example, the first zone filter 612 can only permit write access transactions when using the master ID of the ACPU, and only read access transactions when using the first master ID of the NPU; the second zone filter 614 and the third zone filter 616 can permit both read access transactions and write access transactions when using the second and third master IDs of the NPU, respectively; and the fourth zone filter 618 can only permit write access transactions when using the master ID of the IPU, and only read access transactions when using the fourth master ID of the NPU.

[0064] Accordingly, aspects of the present disclosure can provide even higher security and more granular memory access control for data stored within the secure partitions of the memory 620. For example, at a high level, data stored in any of the secure memory zones 622-628 is broadly protected from software and / or hardware operating in the rich environment of the processing system. Moreover, even within the trusted environment, data stored in each of the secure memory zones 622-628 can only be accessed by the appropriate hardware and / or software applications (e.g., on a need-to-know basis).

[0065] Figure 7 is a illustrative flowchart depicting example operations 700 for filtering memory access transactions according to some embodiments. For example reference Figure 3 , example operations 700 can be performed by MPU 350 to selectively reject or allow access to secure memory regions 362-366 of secure partition 360.

[0066] MPU 350 can receive transactions from NPU (710). For example reference Figure 4 Each transaction can include at least transaction type 410, memory address 420, security information 430, and master ID 440. Memory address 420 indicates a physical or virtual location at which data is to be read from or written to memory. Security information 430 indicates a security state of the master that initiated the transaction. In some implementations, security information 430 can be a single data bit indicating whether the master was in a secure state or a non-secure state at the time the transaction 400 was initiated. In some embodiments, NPU can be assigned multiple master IDs. Thus, master ID 440 can be any one of the multiple master IDs assigned to NPU, depending on the memory region to be accessed. In some implementations, each master ID can be associated with only one master and can not be reused. In some other implementations, master ID 440 can uniquely identify a group of masters.

[0067] MPU 350 can filter transactions by selectively rejecting access to secure memory partitions based at least in part on the memory address, master ID, and security information (720). For example, MPU 350 can outright reject any transaction targeting a secure partition that was not initiated from a secure state (e.g., security information 430 indicates a non-secure state). If the transaction was initiated from a secure state, MPU 350 can further analyze master ID 440 to determine whether the particular master is permitted to access the desired region of the secure partition (e.g., a secure memory region). For example, MPU 350 can reject any transaction attempting to access a first secure memory region where master ID 440 is not included in a subset of master IDs that are permitted to access the first secure memory region. Similarly, MPU 350 can reject any transaction attempting to access a second secure memory region where master ID 440 is not included in a subset of master IDs that are permitted to access the second secure memory region.

[0068] In some embodiments, the MPU 350 can further filter transactions based on transaction type. For example, certain master IDs can only be permitted a particular type of access to a given memory location. In some aspects, one or more master IDs can only be given read access to a secure memory region. In some other aspects, one or more master IDs can only be given write access to a secure memory region. Still further, in some aspects, one or more master IDs can be given both read and write access to a secure memory region.

[0069] Figure 8 is an illustrative flowchart depicting more detailed operations 800 for filtering memory access transactions according to some embodiments. For example reference Figure 3 , the example operations 800 can be performed by the MPU 350 to selectively deny or allow access to the secure memory regions 362-366 of the secure partition 360.

[0070] The MPU 350 receives a memory access transaction from a corresponding master (810). The transaction can correspond to a read or write operation to be performed in the memory device. For example reference Figure 4 , each transaction can include at least a transaction type 410, a memory address 420, security information 430, and a master ID 440.

[0071] The MPU 350 first determines whether the memory address associated with the transaction points to a location in the secure partition (820). For example, the MPU 350 can identify the location to be accessed based on the memory address 420 included within the transaction. If the memory address does not point to a location in the secure partition (as tested at 820), but rather a location in the non-secure partition, the MPU 350 can allow access to the target memory address (860).

[0072] If the memory address points to a location in the secure partition (820), the MPU 350 can further determine whether the corresponding master was in a secure state at the time the transaction was initiated (830). For example, the MPU 350 can identify the secure state of the master based on the security information 430 included within the transaction. If the master was not in a secure state at the time the transaction was initiated (as tested at 830), the MPU 350 can deny access to the target memory address (870).

[0073] If the master is in a secure state at the time the transaction is initiated (as tested at 830), the MPU 350 can further determine whether the corresponding master ID is permitted to access the secure memory region in which the target memory address is located (840). For example, the MPU 350 can identify the master ID from the master ID 440 included within the transaction. If the master ID is not permitted to access the secure memory region (as tested at 840), the MPU 350 can deny access to the target memory address (870).

[0074] If the master ID is permitted to access the secure memory region (as tested at 840), the MPU 350 can further determine whether the desired transaction type is permitted for the given master ID (850). For example, the MPU 350 can identify whether the transaction is calling for a read operation or a write operation based on the transaction type 410 included within the transaction. If the transaction type is not permitted for the given master ID (as tested at 850), the MPU 350 can deny access to the target memory address (870).

[0075] If the transaction type is permitted for the given master ID (as tested at 850), the MPU 350 can allow access to the target memory address (860). In accordance with the example operation 800, it is noted that the MPU 350 can only allow access to a memory address located in a secure partition if multiple conditions 830-850 are satisfied. Thus, aspects of the present disclosure can provide even higher security and more granular memory access control for data stored within a secure partition of memory.

[0076] Those skilled in the art will appreciate that information and signals can be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that can be referenced throughout the above description can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0077] Further, those skilled in the art will appreciate that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the aspects disclosed herein can be implemented as electronic hardware, computer software, or combinations of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans can implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.

[0078] The methods, sequences, or algorithms described in connection with the aspects disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and can write information to, the storage medium. In the alternative, the storage medium can be integral to the processor.

[0079] In the foregoing specification, embodiments have been described with reference to specific examples thereof. It would be apparent, however, to one of ordinary skill in the art that various modifications and changes can be made thereto without departing from the broader spirit and scope of the disclosure as set forth in the appended claims. The Specification and drawings are, accordingly, to be regarded in an illustrative rather than a restrictive sense.​

Claims

1. A processing system comprising: a memory having a secure partition and a non-secure partition, wherein the secure partition is subdivided into a plurality of secure memory regions; a neural processing unit (NPU) configured to initiate transactions with the memory, each of the transactions including at least an address of the memory to be accessed, one of a plurality of first master part identifiers (IDs) associated with the NPU, and security information indicating whether the NPU was in a secure state or a non-secure state when the transaction was initiated; and a memory protection unit (MPU) configured to filter the transactions by selectively denying access to the secure partition of the memory based at least in part on the memory address, the first master part ID, and the security information associated with each of the transactions; wherein the MPU is configured to filter the transactions by: determining that the memory address of at least one of the transactions corresponds to one of the secure memory regions; determining whether the first master part ID associated with the at least one transaction is permitted to access the corresponding secure memory region; and denying access to the secure memory region if the at least one transaction was initiated from the non-secure state or the first master part ID associated with the at least one transaction is not permitted to access the secure memory region.

2. The processing system of claim 1, wherein the secure partition and the NPU reside in a trusted environment of the processing system, and the non-secure partition resides in a rich environment of the processing system.

3. The processing system of claim 1, wherein the MPU is further configured to filter the transactions by: determining a transaction type associated with the at least one transaction, the transaction type invoking one of a read operation or a write operation; and denying access to the memory address if the transaction type is not permitted for the corresponding first master part ID.

4. The processing system of claim 1, wherein the MPU is configured to permit each of the first master part IDs to access a different one of the secure memory regions.

5. The processing system of claim 1, wherein the NPU is configured to generate one or more inferences for a neural network application in the secure state, and wherein the plurality of secure memory regions includes: a first secure memory region configured to store the one or more inferences from the neural network application; a second secure memory region configured to store a neural network model associated with the neural network application; and a third secure memory region configured to store user input data for the neural network application, wherein the MPU is configured to permit each of the first master part IDs to access a respective one of the first, second, and third secure memory regions.

6. The processing system of claim 5, further comprising: ​ ​ An application processing unit (ACPU) having a second master-part ID and configured to execute the neural network application in the secure state, wherein the MPU is configured to permit the second master-part ID to access the second secure memory region while preventing the second master-part ID from accessing the first and third memory regions.

7. The processing system of claim 5, further comprising: an input device residing in a trusted environment of the processing system and configured to receive one or more user inputs; and an input processing unit (IPU) having a third master-part ID and configured to process the user inputs of the neural network application in the secure state, wherein the MPU is configured to permit the third master-part ID to access the third secure memory region while preventing the third master-part ID from accessing the first and second memory regions.

8. The processing system of claim 5, wherein the plurality of secure memory regions further comprises: a fourth secure memory region configured to store one or more intermediate inferences from the neural network application, wherein the MPU is configured to grant exclusive access to the fourth secure memory region to one of the first master-part IDs.

9. A method of controlling access to a memory having secure partitions and non-secure partitions, comprising: receiving transactions from a neural processing unit (NPU), each of the transactions including at least an address of the memory to be accessed, one of a plurality of first master-part identifiers (IDs) associated with the NPU, and security information indicating whether the NPU was in a secure state or a non-secure state when the transaction was initiated; and filtering the transactions by selectively denying access to the secure partitions of the memory based at least in part on the memory address, the first master-part ID, and the security information associated with each of the transactions, wherein the filtering further comprises: determining that the memory address of at least one of the transactions corresponds to one of a plurality of secure memory regions within the secure partitions; determining whether the first master-part ID associated with the at least one transaction is permitted to access the corresponding secure memory region; and denying access to the secure memory region if the at least one transaction was initiated from the non-secure state or the first master-part ID associated with the at least one transaction is not permitted to access the secure memory region.

10. The method of claim 9, wherein the filtering further comprises: determining a transaction type associated with the at least one transaction, the transaction type invoking one of a read operation or a write operation; and denying access to the memory address if the transaction type is not permitted for the corresponding first master-part ID.

11. The method of claim 9, wherein the plurality of secure memory regions comprises: a first secure memory region configured to store the one or more inferences from the neural network application; a second secure memory region configured to store a neural network model associated with the neural network application; and ​ ​ a third secure memory region configured to store user input data for the neural network application; and a fourth secure memory region configured to store one or more intermediate inferences from the neural network application.

12. The method of claim 11, further comprising: permitting each of the first master-part IDs to access a respective one of the first, second, third, and fourth secure memory regions, respectively, wherein the NPU is configured to generate the one or more inferences for the neural network application in the secure state.

13. The method of claim 11, further comprising: permitting a second master-part ID to access the second secure memory region, wherein the second master-part ID belongs to an application processing unit (ACPU) configured to execute the neural network application in the secure state; and preventing the second master-part ID from accessing the first and third memory regions.

14. The method of claim 11, further comprising: permitting a third master-part ID to access the third secure memory region, wherein the third master-part ID belongs to an input processing unit (IPU) configured to process user input for the neural network application in the secure state; and preventing the third master-part ID from accessing the first and second memory regions.

15. A memory device, comprising: a secure partition, wherein the secure partition is subdivided into a plurality of secure memory regions; a non-secure partition; and a memory protection unit (MPU) configured to: receive transactions from a neural network processing unit (NPU), each of the transactions including at least an address of the memory to be accessed, one of a plurality of first master-part identifiers (IDs) associated with the NPU, and security information indicating whether the NPU was in a secure state or a non-secure state when the transaction was initiated; and filter the transactions by selectively denying access to the secure partition of the memory based at least in part on the memory address, the first master-part IDs, and the security information associated with each of the transactions; wherein the MPU filters the transactions by: determining that the memory address of at least one of the transactions corresponds to one of the secure memory regions; determining whether the first master-part ID associated with the at least one transaction is permitted to access the corresponding secure memory region, wherein different subsets of master-part IDs are permitted to access each of the secure memory regions; and denying access to the secure memory region if the at least one transaction was initiated from the non-secure state or the first master-part ID associated with the at least one transaction is not permitted to access the secure memory region.

16. The memory device of claim 15, wherein the MPU is further configured to filter the transactions by: determining a transaction type associated with the at least one transaction, the transaction type invoking one of a read operation or a write operation; and denying access to the memory address if the transaction type is not permitted for the corresponding first master-part ID.

17. The memory device of claim 15, wherein the NPU is configured to generate one or more inferences for a neural network application in the secure state, and wherein the plurality of secure memory regions comprises: a first secure memory region configured to store the one or more inferences from the neural network application; a second secure memory region configured to store a neural network model associated with the neural network application; and a third secure memory region configured to store user input data for the neural network application, wherein the MPU is configured to permit each of the first master IDs to access a respective one of the first, second, and third secure memory regions. ​

Citation Information

Patent Citations

  • Artificial neural network

    EP3471005A1

  • Method and apparatus for secure execution using a secure memory partition

    US20110131402A1