Isolated address region assignment updating instruction

The isolated address region assignment updating instruction in the ISA simplifies software development and improves scalability by allowing updates to access control information without tracking specific storage locations, addressing inefficiencies in managing complex memory topologies.

WO2025210329A1PCT designated stage Publication Date: 2025-10-09ARM LTD

Patent Information

Application Number
PCT/GB2025/050334
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-02
Filing Date
2025-02-21
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

Existing processor architectures face challenges in efficiently managing isolated address region assignments due to complex memory topologies, requiring software to track specific physical addresses for updating access control information, which is inefficient and not scalable across different systems.

Method used

Incorporating an isolated address region assignment updating instruction into the instruction set architecture (ISA) that specifies a target physical address and an updated assignment, allowing the processing circuitry to trigger updates to access control information without needing to track specific storage locations, thereby simplifying software development and improving scalability.

Benefits of technology

This approach simplifies software management of address region isolation, reduces latency and power consumption, and enhances compatibility across various memory topologies by allowing a single piece of software to execute efficiently on different processing systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure GB2025050334_09102025_PF_FP_ABST
    Figure GB2025050334_09102025_PF_FP_ABST
Patent Text Reader

Abstract

In response to instruction decoding circuitry decoding an isolated address region assignment updating instruction specifying a target physical address and an updated isolated address region assignment for the target physical address, at least one memory system request is issued to request an update to isolated address region assignment information which defines access control information for controlling access to the target physical address, to set the isolated address region assignment information to indicate one of a plurality of isolated address region assignments selected based on the updated isolated address region assignment specified by the instruction. The plurality of isolated address region assignments include at least one more secure isolated address region assignment for which associated data is to be isolated from being observable by program code associated with at least one less secure isolated address region assignment.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] ISOLATED ADDRESS REGION ASSIGNMENT UPDATING INSTRUCTION

[0002] The present technique relates to the field of data processing.

[0003] Some processor architectures may support address region isolation, to enable data and address associated with access to one region of memory to be isolated from being observable by program code associated with another address region.

[0004] At least some examples of the present technique provide an apparatus comprising: instruction decoding circuitry to decode instructions according to an instruction set architecture; and processing circuitry to perform processing operations in response to decoded instructions decoded by the instruction decoding circuitry; in which: in response to the instruction decoding circuitry decoding an isolated address region assignment updating instruction specifying a target physical address and an updated isolated address region assignment for the target physical address, the processing circuitry is configured to trigger issuing of at least one memory system request to request an update to isolated address region assignment information which defines access control information for controlling access to the target physical address; the update comprises setting the isolated address region assignment information for the target physical address to indicate one of a plurality of isolated address region assignments selected based on the updated isolated address region assignment specified by the isolated address region assignment updating instruction; and the plurality of isolated address region assignments include at least one more secure isolated address region assignment for which data associated with the at least one more secure isolated address region assignment is to be isolated from being observable by program code associated with at least one less secure isolated address region assignment.

[0005] At least some examples of the present technique provide computer-readable code for fabrication of an apparatus as described above. The computer-readable code may be stored on a storage medium. The storage medium may be a non-transitory storage medium.

[0006] At least some examples of the present technique provide a method comprising: decoding instructions according to an instruction set architecture; and performing processing operations in response to the decoded instructions; in which: in response to the instruction decoding circuitry decoding an isolated address region assignment updating instruction specifying a target physical address and an updated isolated address region assignment for the target physical address, at least one memory system request is issued to request an update to isolated address region assignment information which defines access control information for controlling access to the target physical address; the update comprises setting the isolated address region assignment information for the target physical address to indicate one of a plurality of isolated address region assignments selected based on the updated isolated address region assignment specified by the isolated address region assignment updating instruction; and the plurality of isolated address region assignments include at least one more secure isolated address region assignment for which data associated with the at least one more secure isolated address region assignment is to be isolated from being observable by program code associated with at least one less secure isolated address region assignment.

[0007] At least some examples provide a computer program for controlling a host data processing apparatus to provide an instruction execution environment for execution of target program code, the computer program comprising: instruction decoding program logic to control the host data processing apparatus to decode instructions of the target program code according to a simulated instruction set architecture; and processing program logic to control the host data processing apparatus to perform processing operations in response to the decoded instructions; in which: in response to decoding of an isolated address region assignment updating instruction specifying a target simulated physical address and an updated isolated address region assignment for the target simulated physical address, the processing program logic is configured to request an update to isolated address region assignment information which defines access control information for controlling access to the target simulated physical address; the update comprises setting the isolated address region assignment information for the target simulated physical address to indicate one of a plurality of isolated address region assignments selected based on the updated isolated address region assignment specified by the isolated address region assignment updating instruction; and the plurality of isolated address region assignments include at least one more secure isolated address region assignment for which data associated with the at least one more secure isolated address region assignment is to be isolated from being observable by program code associated with at least one less secure isolated address region assignment.

[0008] The computer program may be stored on a storage medium. The storage medium may be a non-transitory storage medium.

[0009] Further aspects, features and advantages of the present technique will be apparent from the following description of examples, which is to be read in conjunction with the accompanying drawings, in which:

[0010] Figure 1 illustrates an example of an apparatus comprising instruction decoding circuitry and processing circuitry;

[0011] Figure 2 illustrates an example of assignment of isolated address regions;

[0012] Figure 3 illustrates a data processing system;

[0013] Figure 4 illustrates use of requester-side isolated address region assignment information according to one example;

[0014] Figure 5 illustrates an example where the isolated address region assignments indicate an association with one of a plurality of physical address spaces;

[0015] Figure 6 illustrates an example of a point of physical aliasing;

[0016] Figure 7 illustrates an example of use of completer-side isolated address region assignment information, in this example used by a device that communicates with a host apparatus according to a device interface protocol such as Compute Express Link (CXL); Figure 8 illustrates steps for processing an isolated address region assignment updating instruction;

[0017] Figure 9 illustrates a first example of the isolated address region assignment updating instruction;

[0018] Figure 10 illustrates steps performed in response to the isolated address region assignment updating instruction including mapping from a first request defined according to a host memory system protocol to a second request according to the device interface protocol;

[0019] Figure 11 illustrates handling of the first request in a case where the target physical address does not correspond to any memory system location for which access is controlled by completer-side access control circuitry;

[0020] Figure 12 illustrates handling of the first request in a case where an updated isolated address region assignment specified by the isolated address region assignment updating instruction is not supported by the completer-side access control circuitry which controls access to the target physical address;

[0021] Figure 13 illustrates a second example of the isolated address region assignment updating instruction;

[0022] Figure 14 illustrates another example of steps for processing an isolated address region assignment updating instruction; and

[0023] Figure 15 illustrates a simulation example.

[0024] An apparatus comprises instruction decoding circuitry to decode instructions according to an instruction set architecture (ISA); and processing circuitry to perform processing operations in response to decoded instructions decoded by the instruction decoding circuitry. For supporting trusted computing or other use cases involving processing of sensitive data or program code, it can be helpful to provide support for isolating data associated with one address region of memory from observation by program code associated with another address region. Hence, a given address region may be associated with isolated address region assignment information which defines access control information for controlling access to that region. The isolated address region assignment may be selected from one of a number of supported isolated address region assignments, including at least one more secure isolated address region assignment for which data associated with the at least one more secure isolated address region assignment is to be isolated from being observable by program code associated with at least one less secure isolated address region assignment.

[0025] Typically, an ISA may not have any dedicated instruction for setting the isolated address region assignment information for a given address. Often, the isolated address region assignment information may be stored in a memory-based table structure accessed by load / store instructions executed by processing circuitry, and updated by executing a general purpose store instruction which specifies as its target physical address the address of the memory system location actually storing the isolated address region assignment information (rather than the address of the memory system location whose access is controlled using that isolated address region assignment information).

[0026] However, with increasingly complex memory topologies in use within modern processing systems, it can be increasingly onerous for software to keep track of the particular memory system locations storing isolated address region assignment information, so that corresponding store instructions can be executed specifying the addresses corresponding to the storage locations of the isolated address region assignment information when a change of address region assignment is needed.

[0027] In examples discussed below, the instruction decoding circuitry and processing circuitry support an ISA which includes within its instruction set an isolated address region assignment updating instruction specifying a target physical address and an updated isolated address region assignment for the target physical address. In response to the isolated address region assignment updating instruction being decoded by the instruction decoding circuitry, the processing circuitry triggers issuing of at least one memory system request to request an update to isolated address region assignment information which defines access control information for controlling access to the target physical address. The update comprises setting the isolated address region assignment information for the target physical address to indicate one of the supported set of isolated address region assignments. The particular isolated address region assignment to be set for the target physical address is selected based on the updated isolated address region assignment specified by the isolated address region assignment updating instruction.

[0028] Hence, with this approach, the isolated address region assignment updating instruction specifies the address of the memory system location whose access is to be controlled using the updated isolated address region assignment, rather than specifying the storage location of the isolated address region assignment information itself. This simplifies software development as the software does not necessarily need to track the specific physical addresses at which the isolated address region assignment for a given physical address is stored. This approach can allow a single piece of software to be more scalable to being executed on different memory topologies involved in different processing system implementations, as there is less need for software to execute implementation-specific sets of load / store operations for managing specific isolation region assignment information structures in use for particular portions of the memory topology.

[0029] The instruction decoding circuitry and processing circuitry may support one or more variants of the isolated address region assignment updating instruction. Some examples may only support one of the variants mentioned below. Other examples may support more than one variant. Variants of instructions may be distinguished by their instruction opcode and / or by other parameters such as an operand or control parameter specified by the instruction and / or by control information stored in a control register or other storage location which may influence how a given instruction encoding is interpreted. It is possible for a single implemented instruction type to serve as more than one of the variants described below, for example by having a single instruction opcode which for a given encoding causes two or more of the variants of behaviours described below. In some cases, a given instruction type having a given opcode may be treated as always having one or more behaviours according to the one or more variants discussed below. In other examples, a given instruction type having a given opcode may be variably selected to behave as one variant or another, e.g. by providing a parameter specified by the instruction or specified in a control register which controls which behaviour is triggered by the instruction. Hence, it will be appreciated that variants of the instruction could be distinguished in a wide range of ways and any one implementation may support a wide variety of combinations of one or more of these variants.

[0030] Some implementations may implement specific completer-side access control checks for given regions of system address space, which enforce access control for a given address at a point of the system local to the “completer” of the memory access to the given address (the component that acts upon the requested memory access). For example, the completer may be a memory controller associated with a particular memory storage unit, or could be a device coupled to a host system comprising a CPU via a device port. Such completer-side access control checks may contrast with “requester-side” access control checks which may be performed at the requester that issued the memory access, such as by a central processing unit (CPU), graphics processing unit (GPU) or input / output memory management unit (IOMMU) which manages memory access on behalf of devices such as input / output devices and hardware accelerators. Completer-side access control checks can allow more specialized access control schemes for specific address regions (e.g. for regions used by input / output devices) than would be practical if all access control checks were implemented on the requester-side. However, in implementations supporting such completer-side access control checks, the address mappings used to identify location storing particular items of address region assignment information can be particularly complex, depending on the specific memory topology in use. Also, some variants of completers may require commands to be generated in a specific protocol, which can be difficult to drive from the requester side with general purpose store instructions.

[0031] Hence, in some examples, the ISA may support a completer-side-update-variant of the isolated address region assignment updating instruction. In response to the completer-side- update variant, the processing circuitry may trigger issuing of at least one memory system request to request said update to be applied to completer-side isolated address region assignment information used by completer-side access control circuitry to control access to the target physical address by a completer-side memory system component associated with the completer-side access control circuitry. Providing ISA support for a completer-side variant of the isolated address region assignment updating instruction can be particularly useful, as this can greatly simplify software management of address region isolation implemented using completer-side access control checks. For example, the completer-side memory system component may comprise a device which shares access to a memory system of said apparatus and communicates with said apparatus over a device interface according to a device interface protocol. Such protocols support the device being able to implement a form of completer-side isolated address region assignment information, which is to be set using a specific message type according to the device interface protocol. However, if tables of isolated address region assignment information were to be set using conventional store instructions not distinguished in the ISA from regular store instructions used for standard data write operations, it may be harder to provide circuit logic for causing the device interface to issue the specific message type for updating the completer-side isolated address region assignment information according to the device interface protocol. The micro-architectural design of specific circuit designs for the device interface can be greatly simplified by providing at an architectural level an ISA-supported instruction for requesting updates to completer-side isolated address region assignment information (for example this may reduce the need for a device interface to track specific addresses relating to completer-side isolated address region assignment information, which would otherwise consume power and incur latency in looking up address structures at the device interface).

[0032] For example, the device interface protocol may comprise Compute Express Link (CXL), which is a protocol for supporting coherent devices which have caches which are to be subject to the coherency protocol used by the host system to which the device is connected via the device interface. The CXL protocol supports a feature called CXL-TSP (CXL TEE Security Protocol, where TEE stands for Trusted Execution Environment), which provides support for devices to be used in conjunction with Trusted Execution Environments (TEEs) and other use cases requiring data for one application to be isolated from being observable by another application. The CXL- TSP protocol enables a given physical address to be assigned a TEE Exclusive State (TE State, for short), which can be used to isolate data associated with addresses having a more secure TE state from being observed by processes which generate memory access requests associated with a less secure TE state.

[0033] Hence, in some examples, the completer-side isolated address region assignment information comprises information indicative of a TEE Exclusive State associated with the target physical address according to CXL-TSP. Hence, supporting the completer-side-update variant of the isolated address region assignment updating instruction in ISA may be particularly useful to simplify development of software to execute on a host processing system which includes an interface to CXL-TSP-compatible devices, as well as enabling more efficient design of the device interface circuitry of the host system when supporting CXL-TSP.

[0034] It will be appreciated that other device interface protocols may also be provided which have a similar feature to the TEE Exclusive State of CXL-TSP, and so the completer-side-update variant of the isolated address region assignment updating instruction could also be applicable to other device interface protocols. Also, in some cases, a memory system component which is part of the host memory system, rather than being an external device coupled via a device interface, could itself have a completer-side access control checking unit which implements localized access control based on a corresponding set of completer-side isolated address region assignment information. Hence, the completer-side-update variant of the isolated address region assignment updating instruction is not restricted to use with devices, and could also be used to set isolated address region assignment information associated with completer-side access control circuitry within the host processing system.

[0035] In some examples, in response to the completer-side-update-variant of the isolated address region assignment updating instruction, the at least one memory system request issued by the processing circuitry may comprise a first request defined according to a host memory system protocol. The first request may represent a request that, if the first request is routed based on the target physical address to the device interface, the device interface generates a second request to be sent to the device according to the device interface protocol. The second request may comprise a request for the device to update the completer-side isolated address region assignment information associated with the target physical address. Hence, the completer-side- update-variant of the isolated address region assignment updating instruction may drive the hardware to remap the first request according to the host memory system protocol into a second request according to the device interface protocol. This would be much less efficient to implement for system designers in systems where updates to isolated address region assignment information are performed using regular store instructions which are not distinguished architecturally from store instructions used for regular data write operations, as without a dedicated completer-side-update variant of the instruction the only information available for detecting an update to completer-side isolated address region assignment information would be the physical address, so this would require a structure to be implemented at the device interface for tracking the addresses allocated for storing completer-side isolated address region assignment information. Looking up such a structure would incur a significant latency and power cost for every store operation, which would be undesirable. This can be avoided by providing the dedicated isolated address region assignment updating instruction, which can drive the generation of the second request based on the first request. For example, the first request may be a request according to the internal memory system bus protocol of the apparatus, while the second request may be a TEUpdate command according to CXL-TSP defined in the CXL specification (version 3.0 or later).

[0036] In some examples, the first request generated in response to the isolated address region assignment updating instruction may indicate that cache entries of at least one cache that specify data associated with the target physical address are to be invalidated. The at least one cache could include one or more host caches of the host apparatus and / or one or more device caches of the device. Invalidating stale entries from host and / or device caches can in some cases be important to maintain security after updating the isolated address region assignment information. Hence, as well as triggering the update of isolated address region assignment updating instruction, the completer-side-update-variant of the isolated address region assignment updating instruction may also trigger invalidation of stale cache entries corresponding to the target physical address. This can reduce the need for software to separately trigger such cache invalidations using a separately executed ISA instruction from the instruction triggering the update of isolated address region assignment information, and so such a combined update / invalidate instruction can simplify software development and improve processing performance by reducing the total number of instructions needed to be executed.

[0037] In some examples, in response to the completer-side-update-variant of the isolated address region assignment updating instruction, when the target physical address does not correspond to any memory system location for which access is controlled by completer-side access control circuitry, the processing circuitry may permit continued execution of instructions without applying said update to the completer-side isolated address region assignment information corresponding to the target physical address. One might expect that, for a variant of the instruction for updating completer-side isolated address region assignment information, then if the instruction is executed specifying an address which is not subject to access control on the completer-side then an error should be flagged (e.g. a fault raised to interrupt program execution) as the update cannot be actioned. However, in practice, it may be more efficient to allow the requested update to simply be ignored so that program execution of the processing circuitry to continue without being interrupted, in the event that the completer-side-update-variant of the isolated address region assignment updating instruction is executed specifying a target physical address mapped to a location that is not subject to completer-side access control. The operation may behave architecturally as a no-operation (NOP) instruction if there is no completer-side access control circuitry configured in a given system to provide access control functions associated with the target physical address. This may allow scalable software to be developed which is agnostic as to whether or not there is actually completer-side access control circuitry provided for controlling access to a given physical address, so that the same software could execute across a variety of physical platform designs.

[0038] In some examples, the isolated address region assignment updating instruction specifies, as the updated isolated address region assignment, one of a plurality of requester-side isolated address region assignments defined according to the instruction set architecture. The requesterside isolated address region assignments may specify a given set of options for encoding the isolated address region assignment. It is not essential that all of these options are necessarily supported in the completer-side isolated address region assignment information. In some cases, only a subset of the supported requester-side isolated address region assignments may have a corresponding setting for the completer-side isolated address region assignments. To support development of platform-agnostic program code, it may be helpful for the updated isolated address region assignment to be identified using a given requester-side isolated address region assignment, even if the instruction is intended to cause updating of a corresponding item of completer-side isolated address region assignment information. This allows the same software to be scalable to different forms of completer which might implement different combinations of options for the completer-side isolated address region assignment information. There may be a particular mapping between the requester-side isolated address region assignment information and completer-side isolated address region assignment information, which may be used by the device interface to convert between the first request and second request.

[0039] Hence, in some examples, in response to the completer-side-update-variant of the isolated address region assignment updating instruction, when the target physical address corresponds to a memory system location for which access is controlled by completer-side access control circuitry which does not support any completer-side isolated address region assignment corresponding to the one of the plurality of requester-side isolated address region assignments specified as the updated isolated address region assignment by the completer-side-update- variant of the isolated address region assignment updating instruction: the processing circuitry is configured to permit continued execution of instructions without applying said update to the completer-side isolated address region assignment information corresponding to the target physical address. This means that if the requester that executes the isolated address region assignment updating instruction is requesting an update to a setting not supported by the completer, the update can simply be ignored and there is no need to signal a fault or error which causes interruption of processing. Again, this helps make software scalable to multiple different system implementations so that the same software can be compatible with devices even if the device does not necessarily support the full range of options supported by the requester-side checks.

[0040] In some examples, the ISA supports a requester-side-update-variant of the isolated address region assignment updating instruction. This could be supported in addition to the completer-side-update-variant, or instead of the completer-side-update variant. In some examples, the completer-side-update-variant and requester-side-update variant could be the same type of instruction (either permanently behaving as both variants, or with a parameter of the instruction or stored in a control register selecting whether the instruction behaves as the completer-side-update-variant, the requester-side-update variant or both variants for a given instance of executing the instruction).

[0041] In response to the requester-side-update-variant of the isolated address region assignment updating instruction, the processing circuitry triggers issuing of at least one memory system request to request that the update is applied to requester-side isolated address region assignment information to be used by requester-side access control circuitry to control access to the target physical address by the processing circuitry. Hence, this allows memory-based control structures used by requester-side access control circuitry to be updated more efficiently than using general purpose store instructions. The intent expressed by the isolated address region assignment updating instruction allows the memory system to distinguish updates of requesterside access control information from regular memory write operations, which can be helpful for allowing more efficient processing (such as implementing additional cleaning and / or scrubbing if desired in response to the same instruction, and / or selecting caching policy based on the type of instruction).

[0042] Some examples may support a requester-and-completer-side-update variant of the isolated address region assignment updating instruction, in response to which the processing circuitry is configured to trigger issuing of at least one memory system request to request corresponding updates to be applied to both completer-side isolated address region assignment information used by completer-side access control circuitry to control access to the target physical address by a completer-side memory system component associated with the completer-side access control circuitry; and requester-side isolated address region assignment information to be used by requester-side access control circuitry to control access to the target physical address by the processing circuitry. This can be useful because often, when changing isolated address region assignments, it may be desirable to request corresponding changes to both requester-side and completer-side isolated address region assignment information, so a combined instruction that can request both types of information to be updated can reduce the total number of instructions to be executed.

[0043] In some examples, in response to an invalidating variant of the isolated address region assignment updating instruction, the processing circuitry is configured to trigger invalidation of cache entries corresponding to the target physical address. The invalidating variant can be helpful to allow stale cache entries for the target physical address to be eliminated in response to the same instruction that also triggers the update of the isolated address region assignment. For example, the entries to be invalidated may comprise cache entries corresponding to the target physical address which are associated with a previous isolated address region assignment, and / or cache entries corresponding to the target physical address which are associated with the updated isolated address region assignment (which might still be resident in the cache from a previous time the target physical address was associated with the updated isolated address region assignment). Providing an invalidating variant can reduce the need to execute separate cache maintenance instructions in addition to the isolated address region assignment updating instruction. Invalidation of a cache entry triggered by the invalidating variant may also include cleaning the cache entry, by writing back the data from the cache entry to a subsequent cache or memory if the cached data is dirty.

[0044] In some examples, the completer-side-update-variant, requester-side-update variant and / or requester-and-completer-side-update variant of the instruction could also behave by default as the invalidating variant, so that an invalidation of any stale cache entries (if there are any) is triggered on any update. In other examples, a parameter of the instruction or a parameter stored in a control register could select whether a given instance of the completer-side-update- variant, requester-side-update variant and / or requester-and-completer-side-update variant of the instruction should also behave as the invalidating variant.

[0045] In some examples, in response to a scrubbing variant of the isolated address region assignment updating instruction, the processing circuitry may trigger issuing of at least one memory system request to request that a memory system location identified by the target physical address is set to a predetermined value, as well as updating said isolated address region assignment information. For some use cases, when switching the isolated address region type assigned to a given target physical address, it may also be desirable to overwrite any previous data stored in the corresponding memory location. For example, when switching a region of memory from a more secure isolated address region assignment to a less secure isolated address region assignment, it may be desired to perform a “scrubbing” process to ensure that sensitive information previously stored in the more secure regions of memory address space are not accessible to a less secure process executing using that region of memory after the update to the isolated address region assignment. Hence, by providing ISA support for a scrubbing variant of the instruction that updates the isolated address region assignment and also clears the memory system location identified by the target physical address to a predetermined value (e.g. 0), this can reduce the number of instructions needed to execute the update and scrubbing operations, helping to improve performance.

[0046] Again, in some examples, the completer-side-update-variant, requester-side-update variant, requester-and-completer-side-update variant and / or invalidating variant of the instruction could also behave by default as the scrubbing variant, so that scrubbing of the memory system location associated with the target physical address is triggered on any update. In other examples, a parameter of the instruction or a parameter stored in a control register could select whether a given instance of the completer-side-update-variant, requester-side-update variant, requester-and-completer-side-update variant and / or invalidating variant of the instruction should also behave as the scrubbing variant.

[0047] In some examples, the processing circuitry is configured to signal a fault in response to an attempt to execute the isolated address region assignment updating instruction when the processing circuitry is in an operating state with less than a threshold level of privilege. Hence, the isolated address region assignment updating instruction may be restricted to be executable only in particular operating states considered privileged enough to justify being allowed to change isolated address region assignments. This prevents less privileged software being able to circumvent the security protections provided by the isolated address region assignments by updating the isolated address region assignment information. For example, the threshold level of privilege may be the maximum level of privilege supported. There can be a number of ways in which the isolated address region assignment associated with a given physical address can be used to control how memory accesses to that physical address are handled.

[0048] In some examples, the apparatus may comprise access control circuitry to control whether access to a given physical address region by a given memory access request is allowed based on whether a combination of a requested isolated address region type specified by the given memory access request and the isolated address region assignment specified by the isolated address region assignment information associated with the given physical address is an allowed combination of said selected isolated address region and the isolated address region assignment. For example, this can help enforce access restrictions to prevent requests associated with a less secure isolated address region assignment being able to access memory regions assigned a more secure isolated address region assignment. The access control circuitry could include requester-side access control circuitry and / or completer-side access control circuitry as discussed above.

[0049] In some examples, the apparatus may comprise at least one memory system component configured to treat aliasing physical addresses associated with different isolated address region assignments as if they specify different memory system resources even when the aliasing physical addresses actually correspond to the same memory system resource. This can be helpful for reducing risk of leakage of side-channel information about address access patterns of more secure software by an attacker. Hence, in some cases the isolation of data associated with a more secure isolated address region assignment from being observable by program code associated with a less secure isolated address region assignment may not merely be enforced by restricting the ability to read or write the data having the more secure isolated address region assignment, but also in preventing the less secure program code being able to learn side-channel information about which addresses have been accessed by program code associated with the more secure isolated address region assignment.

[0050] In some examples, the apparatus may comprise memory encryption circuitry to encrypt or decrypt data associated with a given physical address based on a key selected based on information verified based on the isolated address region assignment specified by the isolated address region assignment information for the given physical address. Hence, by selecting different encryption keys based at least partly on information validated using the isolated address region assignment information for the given physical address, isolation can be enforced between software workloads provided by different mutually distrusting parties, as the use of different encryption keys provides confidentiality for the corresponding data stored in the regions having different isolated address region assignments.

[0051] In some examples, the apparatus may comprise a general purpose central processing unit (CPU) which comprises the instruction decoding circuitry and the processing circuitry. Hence, the isolated address region assignment updating instruction may be supported by a general purpose application CPU (the general purpose application CPU may be distinct from a specialized security processor or hardware accelerator). By bringing support for updates of isolated address region assignment information into the ISA used by a general purpose CPU, this can be helpful for simplifying software development of software for managing trusted computing workloads on a processing system, as well as permitting more efficient circuit implementation of the memory system hardware (e.g. circuitry at device interfaces).

[0052] In some examples, in response to the isolated address region assignment updating instruction, the processing circuitry may issue the at least one memory system request to a memory system bus interface configured to control routing of the at least one memory system request based on the target physical address specified by the isolated address region assignment updating instruction. Hence, the target physical address specified by the instruction can be used for routing control just like the target physical address of a regular memory access, even though the location which will be updated will not be the location actually identified by that target physical address, but instead is the location storing the access control information for controlling accesses to that target physical address.

[0053] The techniques discussed above may be implemented within an apparatus which has hardware circuitry provided for implementing the instruction decoding circuitry and processing circuitry discussed above. However, the same technique can also be implemented within a computer program which executes on a host data processing apparatus to provide an instruction execution environment for execution of target code. Such a computer program may control the host data processing apparatus to simulate the architectural environment which would be provided on a hardware apparatus which actually supports target code according to a certain instruction set architecture, even if the host data processing apparatus itself does not support that architecture. The computer program may have instruction decoding program logic and processing program logic which emulates functions of the instruction decoding circuitry and processing circuitry discussed above. The instruction decoding program logic may map the claimed isolated address region assignment updating instruction onto a corresponding set of instructions defined according to the host instruction set architecture supported by the host data processing apparatus.

[0054] Such a simulation program can be useful, for example, when legacy code written for one instruction set architecture is being executed on a host processor which supports a different instruction set architecture. Also, the simulation can allow software development for a newer version of the instruction set architecture to start before processing hardware supporting that new architecture version is ready, as the execution of the software on the simulated execution environment can enable testing of the software in parallel with ongoing development of the hardware devices supporting the new architecture.

[0055] References to a “register” (when made in the context of a hardware supported embodiment) may, in the context of a software-based simulation, be understood as referring to a simulated register of the target instruction set architecture which is mapped by the simulator program onto host storage resources (e.g. registers and / or memory) provided by the host apparatus. Similarly, references to a “physical address” or a “physical address space” made in the context of the hardware supported embodiment may be understood for the simulated embodiment as referring to a simulated physical address or simulated physical address space respectively, which may similarly be mapped onto host storage resources (registers and / or memory) of the host apparatus.

[0056] The simulation program may be stored on a storage medium, which may be a non- transitory storage medium.

[0057] Figure 1 schematically illustrates an example of an apparatus 6, which may for example be a processing element, such as a central processing unit (CPU), graphics processing unit (GPU) or other kind of processor. In some examples, the CPU may for example be a general purpose CPU supporting general purpose arithmetic, logical and load / store instructions, rather than a specialized processor such as a security processor.

[0058] The apparatus 6 includes instruction fetch circuitry 103 for fetching program instructions (defined according to a particular instruction set architecture (ISA) supported by the apparatus 6) from an instruction cache and / or other parts of a memory system. The instructions fetched by the instruction fetch circuitry 103 are passed to instruction decoding circuitry 104 which decodes the instructions to generate micro-operations (decoded instructions) which are passed to processing circuitry 105. The micro-operations control the processing circuitry 105 to perform corresponding processing operations. The processing circuitry 105 has access to various registers 106, which may provide operands for executed processing operations, store results of the processing operations performed by the processing circuitry 105, and / or provide control information which controls how the processing circuitry 105 processes certain types of operations. When a load / store instruction is decoded by the instruction decoding circuitry 104, the processing circuitry 105 generates one or more memory system requests which are issued to the memory system to request that data is loaded from the memory system to the registers 106 or stored from the registers 106 to the memory system, and the processing circuitry 105 processes any responses received from the memory system.

[0059] As shown in Figure 2, the system physical address space (the address space that identifies specific hardware storage locations of the system comprising the apparatus 6) may be logically divided into a number of isolated address regions, such that a given physical address may be associated with isolated address region assignment information which defines one of a set of supported isolated address region assignments selected for that region. The isolated address region assignment information is used as access control information for controlling access to the corresponding physical address. The isolated address region assignments supported include at least one more secure isolated address region assignment and at least one less secure isolated address region assignment, for which data associated with the at least one more secure isolated address region assignment is to be isolated from being observable by program code associated with at least one less secure isolated address region assignment. Example mechanisms for enforcing this isolation are described in more detail below. However, in general the ability to define various isolated address region types can be helpful for security in systems where the developer of one piece of software coexisting on the same hardware platform as a second piece of software does not trust the second piece of software, and so it is desired to be able to prevent the second piece of software being able to access the data associated with the first piece of software and / or being able to gain any visibility on the patterns of address accesses requested by the first piece of software. Some examples may support only two types of isolated address region assignment (one more secure isolated address region assignment and one less secure isolated address region assignment). However, as shown in the example of Figure 2, other implementations may support more than two types of isolated address region assignment (e.g. in Figure 2 at least four different isolated address region assignments are supported, labelled isolated address region 0, isolated address region 1, isolated address region 2 and isolated address region X). As shown in Figure 2, it is possible that the physical address regions associated with a particular isolated address region assignment may be non-contiguous (e.g. Figure 2 shows an example showing two discontiguous regions both assigned isolated address region type 0). It will be appreciated that the particular isolation scheme may vary depending on design goals and so the number of isolated address region assignments and the rules governing the relative permissions and security protocols associated with each type of isolated address region assignment can vary. However, in general such an isolation scheme can be helpful to allow confidential computing applications to be supported on a physical platform that may be shared with other untrusted software.

[0060] As shown in Figure 2, the isolated address region assignments may be tracked using a table of isolated address region assignment information which is stored at memory system locations corresponding to a given set of physical addresses. While Figure 2 for ease of understanding shows a single continuous block of addresses allocated within isolated address region X for the table of isolated address region assignment information, it is not essential for the table to be contiguous in the physical address space. In some examples, a multi-level table structure can be used in which an entry selected from an initial-level table based on a given physical address contains a pointer to a further-level table used to provide the region assignment information for that physical address or providing yet another pointer to a still further level of table. In a multi-level structure, the tables at subsequent levels could be discontiguous in the memory address space. Multi-level structures can be helpful for reducing memory footprint associated with a table that describes a given region of memory address space, to avoid the need to reserve a single large contiguous block of physical memory for a single linear table of size commensurate with the size of the address region to be described by the table. When a table structure defining isolated address region assignment information is stored in the memory system, one would expect that normally the mechanism for updating that table structure would be for software to execute a general purpose store instruction (e.g. STR shown in Figure 2) specifying an address operand which identifies (either directly, or possibly based on at least one stage of address translation) a physical address PAy in the region allocated for storing the table structure. With this type of instruction, page tables can be set by software with access permissions ensuring that processes without sufficient privilege to update the isolated address region assignment information cannot successfully execute a store to physical address PAy.

[0061] As shown in Figure 2, in examples discussed below, an ISA-defined isolated address region assignment updating instruction is supported by the instruction decoding circuitry 104 and processing circuitry 105. The instruction specifies as its address operand a value identifying (again, either directly or indirectly via at least one stage of address translation) a physical address PAz which identifies the data item or memory system location for which the associated item of isolated address region assignment information used to control access to physical address PAz is to be updated. In response to the instruction specifying physical address PAz, the hardware of the processing system may identify the location PAy of the corresponding item of isolated address region assignment information in the table, and trigger an update of the isolated address region assignment information at address PAy that controls access to memory for memory access requests specifying address PAz.

[0062] This simplifies software development as there is less need for software to track the relation between a given data address and the address of the corresponding item of isolated address region assignment information. Also, such an isolated address region assignment updating instruction can better support address isolation schemes in use in more complex memory system topologies, e.g. where devices such as input / output (peripheral) devices, hardware accelerators or external memory storage may be associated with their own form of isolated address region enforcement. If general purpose store instructions were used for such table updates, this might otherwise require relatively complex system-specific pieces of software code to manage the table structures used local to a device to control address region isolation, whereas with the isolated address region assignment updating instruction the software can be more agnostic to the particular details of a specific system.

[0063] Also, when a specific instruction type is used to trigger updates to the isolated address region assignment information, rather than using general purpose store operations, it becomes possible for other related operations associated with the updating of the isolated address region assignment information (such as cache invalidations and / or scrubbing of the associated physical address controlled by the isolated address region assignment information) to be triggered by the same instruction, as the ISA-supported update instruction indicates software’s intent to specifically update isolated address region assignment information (distinguished from regular stores of arbitrary data other than the isolated address region assignment information), which would not be possible with a general purpose store instruction. Hence, depending on the additional options supported in the ISA for the isolated address region assignment updating instruction, this can make associated operations around the update of isolated address region assignment information more efficient as this can reduce the need for software to execute other separate instructions to trigger cache invalidations, scrubbing, or any other associated operations which might be required at the time of the update of isolated address region assignment information.

[0064] Also, device interfaces can be simplified in their hardware design (and be associated with lower latency of processing updates of completer-side isolated address region assignment information), if the fact that a given write request relates to an update of isolated address region assignment information can be detected based on instruction type rather than needing a physical address to be compared against information defining which addresses are used for the table of isolated address region assignment information.

[0065] While the isolated address region assignment updating instruction could be used for a wide variety of use cases involving assignment of isolated address region information to particular physical addresses, one particular example use case is now discussed with respect to Figures 3 onwards.

[0066] Figure 3 schematically illustrates an example of a data processing system 2 which may include the apparatus 6 shown in Figure 1. The data processing system 2 comprises a host system 4, which could be implemented as a system-on-chip or as a set of multiple interconnected chiplets. The host system 4 comprises one or more processing elements (processors) 6. Each processor 6 could, for example, be a central processing unit (CPU, e.g. a general purpose CPU), graphics processing unit (GPU), neural processing unit (NPU), or any other processor capable of instruction execution. Any one or more of the processors 6 shown in Figure 3 may have the circuitry 103, 104, 105, 106 according to the apparatus 6 as shown in Figure 1.

[0067] As shown in Figure 3, each processing element 6 may include at least one private cache 8 for caching data obtained from memory storage 12 via an interconnect 10. Each memory storage unit 12 has an associated memory controller 14 for mapping requests made according to the bus protocol used by the interconnect 10 onto the specific protocols for addressing the particular kind of memory storage implemented in the corresponding storage unit 12 (e.g. the storage units 12 could include volatile or non-volatile storage, according to various kinds of memory storage technology). The interconnect 10 may include a system cache 34 which acts as a shared cache accessible to each processing element 6.

[0068] Hence, a number of processing elements 6 may each have access to shared memory 12 within the host system 4. However, in addition to the processing elements 6 themselves, another source of memory access requests to shared memory 12 can be from devices 20, 22 coupled to the host system via corresponding root ports 26. Each root port 26 acts as a gateway to the host system for a corresponding device or group of devices. Although Figure 3 shows each device 20, 22 having a separate root port 26, it is also possible for a group of devices to share a single root port. The devices 20, 22 may for example include any one or more of: an I / O (input / output) device for controlling interaction between the host system and the user or the outside world (e.g. a network controller, display controller, user input device, etc.); a hardware accelerator for performing certain bespoke processing functions (e.g. neural network processing, cryptographic functions, etc.) in a more efficient manner than could be performed in software using a general purpose processor 6; and / or external memory storage provided to provide additional storage capacity beyond the capacity provided in the memory storage 12 of the host system 4. The devices 20, 22 accesses shared memory 12 via a system memory management unit (SMMU, also known as Input / Output memory management unit or IOMMU) 30, which performs address translation and access permission checks for requests made by the devices 20, 22 in a similar manner to a memory management unit within a processing element 6, such translation and permissions checks being based on address mappings and access permissions defined in translation table structures (page table structures) stored in the memory system 12 and configured by software executing on the processing elements 6.

[0069] The interconnect 10 may be associated with home node circuitry 32 which is responsible for maintaining coherency between cached data held at private caches 8, 24 of a number of caching agents of the data processing system 2. The caching agents can include the processing elements 6 as well as any coherent devices 22 which have their own coherent private cache 24 (other devices 20 may be non-caching devices (or “I / O coherent” devices) which do not have a private cache that needs to remain coherent with the host device). For example, a coherent device 22 could be a device for which the interface between the device 22 and host system 4 is compatible with a given device interface protocol, such as the CXL (Compute Express Link) standard.

[0070] The home node circuitry 32 implements a given coherency protocol, which defines a set of request types and response protocols associated with those request types. Each address may, with respect to a particular caching agent, be considered to be held in that caching agent’s private cache in a particular coherency state. For example, the coherency state may specify, with respect to a given address and a given caching agent 6, 22, whether valid data for that address is held at the given caching agent’s private cache 24, and if valid data is held, whether that data is clean or dirty, and / or is held in a unique or shared state (unique data being held exclusively in that caching agent’s cache, and not in other caching agent’s caches, and shared data being capable of also being held in other caching agent’s caches). The coherency protocol may require that certain request types or responses to such requests may be associated with certain transitions of coherency state for cached items of data associated with the target address of the request. When a read / write request is received from one of the caching agents 6, 22 or an I / O coherent device 20 requesting a read / write operation to a given physical address, the home node circuitry 32 issues snoop requests to one or more other caching agents that could potentially hold valid cached data for that physical address. A snoop request may query the current coherency state of the cached data for a specified address at a corresponding caching agent, and / or trigger changes in coherency state at the caching agent (e.g. invalidating cached data if the requester of the original read / write request requires the data to be cached in the unique state in its cache, and / or causing return of dirty data held in a snooped caching agent’s cache 8 so that the dirty data can be made accessible to the requester which sent the read / write request).

[0071] As shown in Figure 3, the home node circuitry 32 may be associated with a snoop filter 36 for tracking (at least partially) which data addresses are cached at certain caching agents 6, 22. The snoop filter 36 can be used to reduce snoop traffic by allowing the coherent interconnect 10 to determine when data is not cached at a particular requester. In the absence of snoop filtering, when one requester 6, 20, 22 issues a read or write transaction to data which could be shared with other caching agents 6, 22, the coherent interconnect 10 may trigger snoop requests to be issued to each other caching agent which could have a cached copy of the data from the same address. However, if there are a lot of caching agents, then this approach of broadcasting snoops to all cached requesters can be complex and result in a large volume of coherency traffic being exchanged within the system 2. By providing a snoop filter 36 which can at least partially track which addresses are cached at the respective caching agents 6, 22, this can help to reduce the volume of snoop traffic, enabling more efficient use of available request bandwidth and improving system performance. With the number of caching agents present in a modern system, it can be infeasible to implement a precise snoop filter scheme exactly tracking the addresses stored at each caching agent 6, 22, as such precision may be unacceptably expensive in terms of the storage and bandwidth cost. Therefore, the snoop filter 36 may track the content of the caches imprecisely. Provided there are no false snoop suppression instances where data actually held at a given private cache 8, 24 is mistakenly identified as not present so that snoops to that given private cache 8, 24 are incorrectly suppressed, it can be permitted to use a less precise tracking scheme which permits cases where the snoop request is issued to a given caching agent but (due to lack of precise information) that caching agent actually does not hold a valid copy of the data for the address specified in the snoop request. In some examples the system cache 34 and snoop filter 36 may be combined, with a single structure looked up based on an address providing both cached data and snoop filter information associated with that address. In some instances, further snoop filtering circuitry 142 (see Figure 7 described below) can be provided at the root port 26 (device interface) associated with at least one coherent device 24, and / or within the device itself to provide for further filtering of snoop requests targeting that device.

[0072] As shown in Figure 3, the host system 4 may also include memory encryption / decryption circuitry 50 for encrypting / decrypting data written to the memory storage 12 or read from the memory storage 12. Providing an on-board encryption engine can be useful for improving security in confidential computing scenarios. The encryption / decryption applied by the memory encryption / decryption circuitry 50 may depend on key information 52 accessible to the memory encryption / decryption circuitry 50. The key information 52 to use for encrypting / decrypting data for a given memory request may be selected based on a physical address space identifier (PASID) and / or memory encryption context identifier (MECID) associated with the memory request, which will be described further below. The MECID distinguishes between two or more different memory encryption context associated with the same physical address space, so that respective portions of mutually distrusting software having access to portions of the same physical address space can have their data be subject to different encryption regimes (e.g. different encryption keys) to help preserve each other’s confidentiality.

[0073] Figure 4 illustrates a more detailed example of circuitry provided at a processing element 6. As mentioned earlier with respect to Figure 1 , the processing element 6 includes instruction fetch circuitry 103, instruction decoding circuitry 104, processing circuitry 105 and registers 106 (the fetch circuitry 103 and some of the registers 106 being omitted in Figure 4 for conciseness). The registers 106 of Figure 4 may include some control registers 62 for storing control state information. The processing element 6 may also include a memory management unit (MMU) 106, comprising a translation lookaside buffer (TLB), for controlling access to memory by the processing element 6 based on address translation mappings and access permissions information defined in translation table structures stored in the memory 12. The TLB caches translation table information derived from the translation table structures (also known as page table structures). The control registers 62 in this example include an indication of a current security state 64 and a current exception level 66, and a set of MECID registers 68 used for assignment of MECIDs to requests issued in a current operating state.

[0074] The processing element 6 also includes requester-side access control circuitry 108 for performing access control functions based on requester-side isolated address region assignment information (an example of the isolated address region assignment information described with respect to Figure 2). For example, the requester-side isolated address region assignment information may comprise a granule protection table which associates each physical address described by the table with a corresponding physical address space assignment, selected from among multiple architectural physical address spaces supported in the ISA supported by the processing element 6.

[0075] As shown in Figure 5, in this example a processing element 6 supports multiple distinct architectural physical address spaces 84 which can be used to address the memory system. Data processing systems may support use of virtual memory, where address translation circuitry (e g. the MMU 106) is provided to translate a virtual address specified by a memory access request from a virtual address space 80 into a physical address associated with a location in a memory system to be accessed. The mappings between virtual addresses and physical addresses may be defined in one or more page table structures. The page table entries within the page table structures could also define some access permission information which may control whether a given software process executing on the processing circuitry is allowed to access a particular virtual address. For some translation regimes, the translation may involve two stages of address translation. If a two-stage translation is used then mapping from a virtual address space 80 to a physical address space 84 is via an intermediate address space 82 based on two separate sets of translation table structures, one for stage 1 (virtual-to-intermediate address translation) and one for stage 2 (intermediate-to-physical address translation).

[0076] In some processing systems, all virtual addresses may be mapped by the address translation circuitry onto a single physical address space which is used by the memory system to identify locations in memory to be accessed. In such a system, control over whether a particular software process can access a particular address is provided solely based on the page table structures used to provide the virtual-to-physical address translation mappings. However, such page table structures may typically be defined by an operating system and / or a hypervisor. If the operating system or the hypervisor is compromised then this may cause a security leak where sensitive information may become accessible to an attacker.

[0077] Therefore, for some systems where there is a need for certain processes to execute securely in isolation from other processes, the system may support operation in a number of security states (domains) and a number of distinct architectural physical address spaces 84 may be supported, where for at least some components of the memory system (e.g. caches 8, interconnects 10, devices 20, 22 and / or certain structures within the SMMU 30), memory access requests whose virtual addresses are translated into physical addresses in different architectural physical address spaces 84 are treated as if they were accessing completely separate addresses in memory, even if the physical addresses in the respective physical address spaces actually correspond to the same location in memory. By isolating accesses from different domains of operation of the processing circuitry into respective distinct physical address spaces as viewed for some memory system components, this can provide a stronger security guarantee which does not rely on the page table permission information set by an operating system or hypervisor.

[0078] In this example, the processing circuitry 105 can execute instructions in one of four security states: a non-secure security state, a secure security state, a realm security state and a root security state. The current security state indication 64 in the control registers 62 designates which security state is currently being used. Each of the four security states is associated with a corresponding architectural physical address space (PAS) 84. Hence, there are four architectural PASs: a non-secure PAS, secure PAS, realm PAS and root PAS.

[0079] The root state is the most privileged state, and is used for executing software which controls transitions to / from the other security states. The root state is able to have its virtual addresses translated from the virtual address space 80 to any of the four architectural physical address spaces 84. Information (NSE, NS) specified in the page table structures used to control the virtual address (VA) to physical address (PA) mapping is used to control which architectural PAS is selected for a given memory access request issued in the root security state. The non-secure state is the least privileged security state, and its memory accesses are translated by default into physical addresses in the non-secure PAS (potentially via two stages of address translation from virtual address space 80 to intermediate address space 82 and from intermediate address space to the non-secure physical address space 84). Instructions executed in the non-secure state are not allowed to cause access requests to be generated specifying physical addresses in the secure PAS, realm PAS and root PAS.

[0080] The secure state and realm state are orthogonal security states which are not able to access each other’s physical address spaces or the root physical address space, but which are able to select whether they access their own respective PAS (realm PAS for the realm state and secure PAS for the secure state) or whether they should access the non-secure PAS. Hence, information (NS) specified in the page table structures used to control address translation can be used to select whether a given memory access request has its address translated into the non- secure or secure PAS (when the request is issued from the secure security state) or into the non- secure or real PAS (when the request is issued from the realm security state).

[0081] As shown in Figure 6, the memory system may include a point of physical aliasing (PoPA) 94, which is a point within the memory system at which aliasing physical addresses from different architectural physical address spaces 84 which correspond to the same memory system resource are mapped to a single physical address uniquely identifying that memory system resource in a hardware physical address space 86 used by downstream memory system components (e.g. memory controllers 14 and memory storage 12). Although more complicated mappings between aliasing addresses are possible (e.g. based on a mapping table tracking which values in the PASs 84 map to the same hardware physical address), it can be simplest if the addresses of the respective architectural PASs 84 which are considered to alias to the same location in the hardware physical address space 86 are those addresses which have the same physical address value (e.g. PA=X in the secure PAS and PA=X in the non-secure PAS are considered aliasing addresses). The location of the PoPA 94 could vary, e.g. it could be either upstream or downstream of the interconnect 10. In the example of Figure 3, the PoPA 94 is downstream of the interconnect 10 (and upstream of the memory controllers 14) so that the system cache 34 is prior to the PoPA, but other examples could provide the PoPA 94 upstream of the interconnect 10. Also, while Figure 6 shows an example with at least one cache 98 downstream of the PoPA 94, this is not essential and other examples may not have any further caches downstream of the PoPA 94 (e.g. Figure 3 does not show any post-PoPA cache).

[0082] Pre-PoPA memory system components, such as caches 8, 34 in the example of Figures 3 and 6 (or other cache-like structures such as a translation lookaside buffer within the MMU 106 or SMMU 30), may treat aliasing physical addresses of different PASs 84 as if they correspond to different memory system resources, even if they ultimately map to the same memory system location in the system physical address space 86 used by underlying memory 12 beyond the PoPA 94. For example, the pre-PoPA caches 8, 34 may cache data, program code or address translation information for the aliasing physical addresses in separate entries, so that if the same memory system resource is requested to be accessed from different physical address spaces, then the accesses will cause separate cache or TLB entries to be allocated. Also, the pre-PoPA memory system component could include the home node circuitry 32 and snoop filter 36, which may separately track coherency states of data held at respective caching agents 6, 22 for the aliasing addresses in different architectural physical address spaces 84. Hence, the aliasing physical addresses are treated as separate addresses for the purpose of maintaining coherency even if they do actually correspond to the same underlying memory system resource. As shown in Figure 6, one way to ensure that aliasing addresses from different architectural PASs 84 are treated as separate addresses can be to include a PAS identifier (PASID) 96, which distinguishes which architectural PAS 84 is associated with a given memory access request, as additional address bits in the representation of physical addresses used to look up these pre-PoPA memory system components. Also, a PAS tag value identifying the architectural PAS associated with a given cache entry may be specified in the given cache entry, and lookups of pre-PoPA caches may depend on a comparison of a PAS tag associated with a memory access request causing the cache lookup (derived from the page table information and / or current security state 64 that is used to select which PAS to specify for a given request) with a PAS tag of a cache entry (derived from the requester-side isolated address region assignment information associated with the corresponding physical address).

[0083] Regardless of the form of the pre-PoPA memory system component, it can be useful for such a PoPA memory system component to treat the aliasing physical addresses of the respective architectural address spaces 84 as if they correspond to different memory system resources, as this provides hardware-enforced isolation between the accesses issued to different physical address spaces so that information associated with one domain cannot be leaked to another domain by features such as cache timing side channels or side channels involving changes of coherency triggered by the coherency control circuitry.

[0084] In contrast, once requests pass beyond the PoPA 94, the aliasing addresses from the respective architectural PASs 84 are mapped to a single unique physical address in the hardware PAS 86. For example, if the aliasing physical addresses in the architectural PASs 84 are simply those having the same physical address value, the mapping to the hardware PAS (system PAS) 86 can be carried out simply by stopping using the PASID as additional address bits when looking up storage structures. As shown in Figure 6, for example, a post-PoPA cache 98 may, for its lookups, no longer use the PASID as part of the address lookup information and no longer tag its cache entries with a PASID 96, unlike the pre-PoPA caches 98 which do use the PASID 96 for address lookups and cache tagging.

[0085] The hardware physical address space 86 may be partitioned to enable access to certain physical memory system locations only within certain architectural PASs. This could be based either on a static mapping (e.g. memory regions assigned to certain devices 20, 22 could be statically reserved only to be accessible to a certain architectural PAS) for some regions of the system physical address space. However, for other regions a dynamic mapping can be defined in a control structure looked up by the requester-side access control circuitry 108 to determine whether, for a memory access request which has caused translation of the virtual address specified by the request into a particular target physical address in a target architectural PAS 84, that target physical address is allowed to be accessed from within that target architectural PAS 84. This control structure (also known as a granule protection table or GPT, for supporting a granule protection check, or GPC) is an example of requester-side isolated address region assignment information used by a requester to control memory access as described earlier. Each entry of the GPT may specify, for a given region of physical addresses, which of the architectural PASs is assigned to that physical address as being allowed to give access to that physical address (some examples may also support GPT settings which permit more than one, or even all, of the architectural PASs to enable access to the corresponding physical address in the system physical address space).

[0086] As shown in Figure 4, the requester-side access control circuitry 108 may have one or more caches for caching portions of the GPT (or information derived from the GPT). While Figure 4 shows such GPT caches as separate from the corresponding TLBs in the MMU 106, in other examples a combined caching structure could cache information from both the page tables (translation table structures) used for address translation and the GPT used for the granule protection check. Similarly, while the MMU 106 and requester-side access control circuitry 108 are shown as separate in Figure 4, in other examples a single circuit unit could perform both functions.

[0087] The use of multiple architectural PASs 86 for addressing some pre-PoPA memory system components such as caches 8, 34 can be useful for improving security for some use cases, to enable software operating in the Realm or Secure state to be isolated (by a hardware-enforced mechanism) from untrusted software running in the Non-Secure state. However, nevertheless a given architectural PAS (e.g. the realm PAS) may support a number of pieces of software which are mutually distrusting and which may not trust the operating system or hypervisor setting the translation table structures to set access permissions to prevent inappropriate access to its data by other software sharing the same architectural PAS 84. Therefore, as shown in Figure 4, it can be useful, for at least some of the architectural PASs 84 (e.g. for the Realm PAS), to provide support for MECIDs (memory encryption context identifiers) which distinguish different encryption contexts within the same architectural PAS 84.

[0088] As shown in Figure 4, the processing element 6 may comprise MECID registers 68 which can be used by software to configure which MECID values should be assigned to the memory requests issued by the processing circuitry 60 at a given time. For example, some approaches could simply provide a single MECID register 68 which indicates the MECID currently in use (which can be updated by privileged software on a context switch between one encryption context and another). It is also possible to provide multiple items of MECID-identifying state (e.g. in different fields within a single MECID register 68 or in different MECID registers 68), each item of MECID-identifying state being associated with a respective operating state (e g. exception level or privilege level) of the processing element 6, so that, based on the current exception level indication 66 or another indication of the current operating state, the appropriate MECID for that operating state can be selected. By supporting MECIDs being defined simultaneously for multiple operating states (e.g. exception levels), this can reduce the amount of reprogramming of MECID registers needed when transitioning back and forth between different operating states (e.g. such frequent transitions can be common when handling exceptions). Also, it may be possible to define multiple items of MECID-defining state which may apply to different classes of memory access operations. For example, which item of MECID-defining state is used to provide the MECID to be used for a given memory access request may depend on the type of load / store instruction executed to cause that memory access request to be issued. Hence, it will be appreciated that there are a wide variety of architectural mechanisms by which software-configured state in control registers 62 can be specified to influence assignment of MECIDs to particular memory access requests.

[0089] Hence, as shown in Figure 4, when a given memory access request is issued by the processing element 6 to the memory system 8, 10, 12, the request may specify, in addition to the physical address translated from a virtual address by the MMU 70 and the PAS ID identifying a target architectural PAS 84, a ECID which distinguishes a selected memory encryption context associated with the request from other memory encryption contexts of the target architectural PAS. The memory encryption / decryption circuitry 50 can select between different items of key information depending on the combination of PASID and MECID, so that different pieces of software within the same architectural PAS (as well as different pieces of software within different architectural PASs) can use different encryption keys to ensure mutual privacy of each other’s data. While Figure 4 shows an example of registers 68 defined at the processing element 6 and information derived from translation table structures to control assignment of PASID and MECIDs to memory access requests, requests sent to the memory system by devices 20, 22 may similarly be tagged with MECIDs. Software executing on the processing elements 6 may configure state information associated with a given device 20, 22 which specifies which PASID and MECID to assign to device-originating memory system requests from that device.

[0090] It will be appreciated that support for MECIDs is not essential, and other examples may select key information for encryption / decryption of data stored in the memory system based solely on the PASID specified by a given memory access request. The PASID is an example of information verified using the isolated address region assignment specified by the isolated address region assignment information for the given physical address, since the GPC checks performed by requester-side access control circuitry 108 use the isolated address region assignment information (GPT entry) for the given physical address to determine whether the requests associated with the architectural PAS specified by the PASID are allowed to access the given physical address.

[0091] The GPT described above is an example of requester-side isolated address region assignment information, used to enforce requester-side access control checks at the point when a requester entity requesting access to a memory system issues the corresponding memory access requests. If the requester-side access control checks fail, a fault may be signalled and the memory access request may be prevented from successfully accessing the associated memory system location.

[0092] However, as shown in Figure 7, it is also possible to implement completer-side access control checks based on completer-side isolated address region assignment information, closer to the “completer” entity which responds to a given memory access request by performing the associated load / store operation or other operation represented by the memory access request. The completer-side isolated address region assignment information could be in a different format to the requester-side isolated address region assignment information.

[0093] For example, the completer could be a device 20, 22 or memory storage unit 12. In the specific example of Figure 7 (which shows a subset of elements of the system shown in Figure 3), the completer is cached device 22 supporting the CXL standard, but other examples could provide other kinds of completer device which support completer-side access control checks based on completer-side isolated address region assignment information.

[0094] Hence, Figure 7 shows another example of a host system 4 comprising various processing elements 6 and host caches 8, 34 caching information from main memory 12 associated with the host 4, which also has a host port 26 (device interface) which is responsible for communications via a CXL switch 140 to one or more devices 22 supporting CXL. Figure 7 shows a subset of the features of the host system, but it will be appreciated that the other features discussed with respect to Figures 3 to 6 may also be provided in the host system 4.

[0095] The devices 22 have their own device caches 24 and may have one or more snoop filters 142 for filtering lookups to the device caches 24. In other examples a snoop filter 142 for a particular device could be located at the host port 26 instead of, or in addition to, providing a snoop filter internal to the device. In this example, the CXL supporting devices are associated with external memory storage 144. While CXL is used as one example of a coherent device protocol, other protocols could also be used.

[0096] In some use cases, where a confidential computing application is associated with certain regions of host memory 12 which are assigned, by the requester-side isolated address region assignment information to the Realm architectural PAS 84 to isolate data and program code for that application from both access and observation by program code provided by other parties, that confidential computing application may also benefit from use of certain devices 22 accessible via the host port 26 and CXL switch 140. Hence, to preserve the same guarantees of confidentiality, tampering prevention and inability to observe side-channel information on patterns of address access, a given device 22 may itself support a scheme to assign isolated address region assignment information to particular physical addresses used by that device, which can be used to control access to, and caching of, data associated with those physical addresses (addresses that are within the overall system physical address space used by the host 4).

[0097] In particular, the CXL specification supports the ability to define a “TEE Exclusive” state (TE state) for particular physical addresses, using a device-managed table structure (an example of the completer-side isolated address region assignment information) stored at a given region of the host physical memory address space (typically a region mapped to the memory storage 144 of the device 22) which assigns to each physical address described by the table one of the following TE states:

[0098] TE state = 0: non-TEE-exclusive.

[0099] TE state = 1 : TEE exclusive.

[0100] Similar to the requester-side access control circuitry 108 at the processing element 6, the device 22 supporting the TE state has TE state checking circuitry 150 as shown in Figure 7, which, for a memory access sent to the device 22 which does not hit in the device’s cache 24, looks up the completer-side isolated address region assignment information for the corresponding physical address to identify whether that physical address is TEE exclusive or non-TEE exclusive. The host port 26 may specify for requests sent to the device 22 an indication of whether the request is associated with TE state = 0 or TE state = 1 . The TE state specified by the request is compared with any indication of the TE state defined in the completer-side isolated address region assignment information for the corresponding physical address, and requests specifying TE state = 0 (non-TEE exclusive) are prevented by the TE state checking circuitry 150 from accessing physical addresses indicated by the completer-side isolated address region assignment information as being given a TEE-exclusive region assignment. When data is cached in the device cache 24 of such a device 22, the cache entry is tagged with the corresponding TE state indication from the completer-side isolated address region assignment information, and on subsequent lookups in the cache, the cache lookup is qualified based on the TE state specified by the request sent via the host port 26 and CXL switch 140, so that a request specifying TE state = 0 cannot hit against an entry reserved for TE state = 1 and vice versa.

[0101] The TE state defined in the CXL specification may nominally be mapped to the architectural PASs supported by the ISA of the processing element 6 as follows: Hence, in this example, the requester-side isolated address region assignment information supports a greater number of types of region assignment than the completer-side isolated address region assignment information. The completer-side checks support states corresponding to only a limited subset of the states supported by the requester-side checks. At the host port 26, if the memory access request routed to the host port specifies a PASID specifying the secure PAS or the root PAS, the request can be rejected as there is no equivalent TE state at the device 22. If the memory access request received at the host port specifies the non-secure or realm PAS using its PASID, this PASID is mapped to the corresponding setting of the TE state in the request sent over the CXL device interface to device 22 (i.e. setting TE state to 0 if the PASID indicated the non-secure PAS or to 1 if the PASID indicated the Realm PAS).

[0102] In a system supporting a device 22 which offers such completer-side address region isolation such as the TE state checking 150 supported in the CXL protocol, it can be particularly inefficient for software executing on a processing element 6 in the host system 4 to update the assignments of isolated address regions for particular physical addresses in both the requesterside tables of isolated address region assignment information (e.g. the GPT) and the completerside tables of isolated address region assignment information (e.g. the device-managed table defining the TE state associated with particular physical addresses). This is particularly the case for the completer-side isolated address region assignment information, because the specific table structures used by particular devices 22 to manage their definition of TE state may be extremely implementation-dependent, and it can be difficult for software to manage this in a platformagnostic way. Also, operations at the host port 26 and device 22 may be less efficient if general purpose store instructions are used to trigger updates of completer-side isolated address region assignment information, because it can be difficult for this circuitry to distinguish whether a given write memory access request triggered by a general purpose store instruction relates to an update of the completer-side isolated address region assignment information, rather than any other data. Also, if general purpose instructions are used to manage the table updates, associated operations such as cleaning of device caches 24 may require separate software-managed invalidation operations, which may be prone to over-invalidation causing knock on loss of performance.

[0103] Hence, particularly in modern processing systems which may increasingly support such completer-side checks, it can be beneficial to provide, in the ISA supported by the processing element 6, support for an isolated address region assignment updating instruction which expresses the specific intent to update isolated address region assignment information, and which specifies as its target physical address the address of the location whose access is controlled by the isolated address region assignment information, rather than the address storing the isolated address region assignment information itself. The target physical address specified by that instruction can be used to control routing of the corresponding access requests issued in response to the instruction across the host system 6, via any interconnects 10 and host ports 26, to ensure that device actions to update control tables and / or trigger cache invalidations may be triggered if necessary. As the instruction does not directly identify the address of the memory system location that stores the actual control structure comprising the isolated address region assignment information to be updated, the hardware of system 2 may include circuitry for mapping the target physical address PAz of the isolated address region assignment updating instruction to a physical address PAy representing the actual storage location of the information to be updated in response to that instruction. In practice, the requester-side access control circuitry 108 and / or completer-side access control circuitry 150 may already have such circuitry for carrying out such address mappings from PAz to PAy, as this may already be used for looking up the table structures providing the isolated address region assignment information and when performing access control checks in response to general load / store memory access requests, so this circuitry can be reused when an isolated address region assignment updating instruction is executed by a given processing element 6.

[0104] Figure 8 illustrates steps for processing isolated address region assignment updating instruction. At step 200, the instruction decoding circuitry 104 decodes an isolated address region assignment updating instruction. At step 202, in response to the isolated address region assignment updating instruction being decoded, the instruction decoding circuitry 104 controls the processing circuitry 105 to issue at least one memory system request requesting an update to (requester-side and / or completer-side) isolated address region assignment information which defines access control information for controlling access to the target physical address specified by the isolated address region assignment updating instruction.

[0105] For example, when the requester-side isolated address region assignment information is to be updated in response to the instruction, the target physical address specified based on an operand of the instruction could be mapped to a corresponding physical address of the location storing the isolated address region assignment information to be updated, based on the same mapping functions used by the requester-side access control circuitry 108 to identify the isolated address region assignment information corresponding to the target physical address when performing granule protection checks. For example, a base register defining a table base address may be combined with a portion of the target physical address to generate one or more memory system requests which traverse a table structure to identify the location of the isolated address region assignment information to be updated. Hence, in this case, the instruction specifying an address of the location whose access is controlled using the isolated address region assignment information may cause the generation (at the CPU 6 or other requester) of a memory system access request which specifies the physical address of the location storing the isolated address region assignment information that is to be updated.

[0106] On the other hand, when the completer-side isolated address region assignment information is to be updated in response to the instruction, the issued memory system request may specify as its target request the target physical address specified by the instruction itself, so that the existing routing circuitry used by the interconnect 10 and host port 26 to route the request to the corresponding device 22 can be used, the same as any other load / store request specifying that target physical address. A parameter of the memory system request issued over the interconnect 10 may distinguish that this request represents an update of completer-side isolated address region assignment information, rather than a regular store request. When the host port 26 and / or device 22 receives the request, this may trigger a mapping from the target physical address to the physical address at which the corresponding item of completer-side isolated address region assignment information is stored, and hence the completer-side isolated address region assignment information can be updated.

[0107] Regardless of whether requester-side and / or completer-side isolated address region assignment information is being updated, the isolated address region assignment information may be updated to a value which is selected based on a parameter of the instruction indicating an updated isolated address region assignment for the target physical address. The updated isolated address region assignment may be indicated according to the requester-side isolated address region assignment scheme, regardless of whether the information to be updated is the requester-side and / or completer-side isolated address region assignment information. If the information to be updated is the completer-side isolated address region assignment information but the completer does not support a completer-side state (e.g. TE state) which corresponds to the particular requester-side state (e.g. PAS) specified by the updated isolated address region assignment parameter of the instruction, the requested update can be ignored without triggering a fault.

[0108] Figure 9 illustrates a first example of an isolated address region assignment updating instruction, which in this example is restricted to triggering updates only of the completer-side isolated address region assignment information, and does not support updates to the requesterside isolated address region assignment information. The isolated address region assignment updating instruction (referred to as STPAS, or set PAS, instruction in this example) has an encoding specifying an opcode which distinguishes the instruction type as being an isolated address region assignment updating instruction, as opposed to another type of instruction, and a register field identifying a register identifier Xt which identifies one of the registers 106 that stores a register operand providing other parameters of the instruction. The register operand specifies the target physical address for which the corresponding item of completer-side isolated address region assignment information is to be updated, and also specifies an updated isolated address region assignment parameter used to indicate the state to which that item of completer-side isolated address region assignment information should be updated in response to the STPAS instruction.

[0109] In this example, the updated isolated address region assignment parameter is specified using two bits NSE, NS encoded as follows to select one of the four architectural PASs 84 described earlier. It will be appreciated that this is just one example encoding, and other encodings could also be used. When the target physical address corresponds to a location associated with a device 22 supporting a CXL version supporting TE state checking 150 as discussed earlier, then the respective values of the NSE, NS bits may trigger corresponding updates to the corresponding item of completer-side isolated address region assignment information (TE state) as follows:

[0110] Also, if the target physical address specified by the STPAS instruction does not actually correspond to any device 22 (routing of the memory access request specifying the target physical address would not reach any host port 26), or corresponds to a device 22 which does not support TE state checking circuitry 150 (e.g. a device not supporting CXL or supporting a version of CXL that does not support CXL-TSP), then again the requested update may be ignored altogether and no update of isolated address region assignment information is performed in response to the instruction. There is no need to generate a fault.

[0111] Figure 10 illustrates an example of operations which may be triggered by the STPAS instruction according to the variant of Figure 9. Initially (indicated by arrow 1 in Figure 10), the processing of the STPAS instruction causes the processing element 6 that executed the STPAS instruction to issue a memory system request, indicated as a STPAS request as distinct from a general store request, which specifies as its target address the target physical address identified by the register operand of the STPAS instruction. The STPAS request may also specify the PAS identified by the updated isolated address region assignment parameter of the STPAS instruction.

[0112] If the target physical address is mapped to a particular system location within a device 22, that memory access request will be routed based on the target physical address (according to conventional memory system routing mechanisms of the interconnect 10), so that the STPAS arrives at the host port 26 associated with the device 22 that is mapped to the target physical address. As shown by arrow 2, the host port 26 may trigger a lookup of a snoop filter 36 of the host system 4 to determine whether any pre-PoPA host cache 8, 34 has cached entries associated with the target physical address that are tagged with a different PAS state to the PAS indicated by the updated isolated address region assignment parameter of the STPAS instruction. If any such entries exist, the snoop filter 36 may (as indicated by arrow 3) issue one or more cache maintenance operations to the host caches 8, 34 to trigger invalidation (and cleaning if necessary because the data is dirty) of cache entries caching data for the target physical address associated with a previous PAS assignment for that target physical address. As shown by arrow 4, if cleaning is required, this may trigger writeback of dirty data back to the underlying storage location in device 22 that corresponds to the target physical address. Once the host port 26 has established that there can no longer be any stale copies of data for the target physical address associated with the previous address region assignment remaining valid in host caches 8, 34, the host port 26 can then map the STPAS request (defined according to the internal memory system protocol used by the host memory system) to a TEUpdate command (defined according to the device interface protocol, e.g. CXL, used by the device 22), and forward the TEUpdate command to the device 22 to request that the device updates the TE state associated with the location identified by the target physical address. The updated PAS indicated by the STPAS request is mapped to the updated TE state according to the example in the table above. While Figure 10 illustrates cleaning of host caches 8, 34, in some examples similar cleaning operations may be performed on device caches 24 in response to the STPAS request.

[0113] As shown in Figure 11 , if the STPAS request sent from the processing element 6 in response to the STPAS instruction is determined by the interconnect 10 to specify a target physical address which does not correspond to any device 22, the request can simply be dropped / ignored, without triggering any external abort or other kind of fault.

[0114] Similarly, as shown in Figure 12, if the STPAS request specifies a PAS that does not correspond to any TE state supported by the device 22 (e.g. the Secure or Root PAS is specified using the NSE, NS bits as shown above), then again the STPAS request can be dropped / ignored without triggering a fault, and so execution of subsequent instructions after the STPAS instruction may continue uninterrupted.

[0115] Hence, the STPAS instruction provides a convenient way for software to, in one instruction, trigger both the update of completer-side isolated address region assignment information (TE state) and any associated cache invalidation operations, as well as making it simpler for the host port 26 to determine when it is needed to generate the TEUpdate command according to the CXL device interface protocol. In the example of Figure 9, the STPAS instruction does not also support updates of requester-side isolated address region assignment information, so a separate instruction (which could be a general purpose store instruction) would need to be executed if the requester-side PAS assignments are also to be updated in a corresponding manner. Nevertheless, a completer-side variant of the isolated address region assignment instruction can be extremely useful to simplify both hardware system implementation and software development in systems which need to manage completer-side tables of isolated address region assignment instruction according to CXL or other similar protocols.

[0116] However, as shown in Figure 13 it is also possible to provide a more flexible instruction which can also support updates of requester-side isolated address region assignment information (either instead of, or in addition to a corresponding update of completer-side isolated address region assignment information). For example, the STPAS instruction in Figure 13 specifies the following parameters (in this example, again using a register operand, but it will be appreciated that some of the parameters other than PA could also be specified directly in the instruction encoding):

[0117] PA - target physical address of the location for which the corresponding item of requester / completer-side isolated address region assignment information is to be updated;

[0118] PAS - the updated PAS to be specified for the location, which can be used to determine the value to which the updated item of requester / completer-side isolated address region assignment information is to be updated;

[0119] C&l - Whether a Clean And Invalidate of caches is required;

[0120] GPT - Whether the requester-side isolated address region assignment information (e.g. the GPT entry corresponding to the target physical address) should be updated to reflect the updated PAS; Scrub - indicates whether the location should be explicitly scrubbed by the instruction (that is, the storage location corresponding to the target PA should be set to a specific predetermined value, such as 0);

[0121] CXL - Whether the instruction should generate a TEUpdate command for updating the CXL-side TE state table (an example of completer-side isolated address region assignment information).

[0122] Hence, this example of the instruction could serve as any of:

[0123] • a requester-side-update variant (if GPT parameter is set to request a corresponding GPT update),

[0124] • a completer-side-update variant (if the CXL parameter is set to request a corresponding CXL-side TE state table update)

[0125] • if supported, a requester-and-completer-side update variant (if both the GPT, CXL fields are set to request the corresponding updates). Some examples may not support the ability to update both types of table in one instruction, in which case encodings with both GPT and CXL fields set to request the corresponding updates may be regarded as undefined and trigger a fault. Wth this approach, while to save encoding space a single opcode may be shared between GPT and CXL updates, any given instance of the instruction would request only one of the requester-side and completer-side updates of isolated address region assignment information. Other examples may support the ability to atomically update both the GPT and CXL-side table in a single instruction, which can be helpful for reducing the number of instructions to be executed by the software as a whole to enforce particular changes of address region assignment for both requester-side and completerside checks.

[0126] • scrubbing variant of the instruction, if the Scrub parameter is set to request scrubbing.

[0127] • invalidating variant of the instruction, if the C&l parameter is set to request invalidation.

[0128] It will be appreciated that while Figure 13 shows a variant with all of the C&l, GPT, Scrub and CXL parameters supported, to enable any arbitrary combination of values for these parameters, other implementations may not support all of these options, and may be treated by default as having a particular value for one of these parameters (e.g. scrubbing by default, or non-scrubbing by default, to avoid incurring encoding space in encoding a specific scrub parameter). Also, in some examples, the ISA may support multiple opcodes, corresponding to different variants of the STPAS that correspond to different combinations of the control parameters shown in Figure 13, rather than offering a single opcode that is configurable to select the particular variant of the instruction.

[0129] Hence, Figure 14 shows another example of steps for processing of an isolated address region assignment updating instruction, such as the example of Figure 9 (restricted by ISA design to be a completer-side-update variant by default), the example of Figure 13 (giving more flexibility to support different variants of the instruction), or any other implementation of the instruction that supports one or more of the variants described in Figure 14. It will be appreciated that some instances of the instruction may behave as more than one of the variants shown in Figure 14 (e.g. the example of Figure 13 supports a single instruction being a requester-side update variant and / or a completer-side update variant and / or a scrubbing variant and / or an invalidating variant).

[0130] At step 300, instruction decoding circuitry 104 within a processing element 6 decodes the isolated address region assignment updating instruction. In response to the decoding of the instruction, the processing circuitry 105 is controlled to perform the subsequent steps of Figure 14. At step 302, the processing circuitry 105 determines (e.g. based on the indication of current exception level 66) whether a current operating state has sufficient privilege to be able to execute the isolated address region assignment updating instruction. For example, in some implementations, the ability to execute this type of instruction may be restricted to cases where the current exception level 66 is the most privileged exception level . If the current operating state has insufficient privilege, then at step 304 a fault is signalled by the processing circuitry 105 and the update requested by the instruction is not carried out.

[0131] If the current operating state has sufficient privilege to be able to execute the instruction, then subsequent processing depends on the particular variant of the instruction indicated by the instance of the instruction currently decoded at step 300.

[0132] If the decoded instruction is a completer-side update variant (yes at step 306), then at step 308, the processing circuitry 105 determines that one or more memory system requests should be issued to request an update to completer-side isolated address region assignment information which controls access to the target physical address specified by the instruction.

[0133] If the decoded instruction is a requester-side update variant (yes at step 310), then at step 312, the processing circuitry 105 determines that one or more memory system requests should be issued to request an update to requester-side isolated address region assignment information which controls access to the target physical address specified by the instruction.

[0134] If the decoded instruction is the scrubbing variant (yes at step 314), then at step 316, the processing circuitry 105 also determines that one or more memory system requests should be issued triggering setting of the memory system location identified by the target physical address to a predetermined value (such as zero or another arbitrary value). This can be helpful for security purposes to ensure that data stored in regions previously designated as relating to a more secure isolated address region assignment can no longer be read once the physical address has been reassigned a less secure isolated address region assignment.

[0135] If the decoded instruction is the invalidating variant (yes at step 318), then at step 320, the processing circuitry 105 also determines that one or more issued memory system requests should also trigger invalidation (and if necessary, cleaning) of cache entries corresponding to the target physical address (e.g. entries that are associated with the previous isolated address region assignment or the updated isolated address region assignment).

[0136] At step 324, the processing circuitry 105 issues the required memory access requests identified as being needed at one or more of steps 308, 312, 316, 320. It will be appreciated that in some cases the same memory system request may serve more than one of the various purposes indicated at steps 308, 312, 316, 320.

[0137] While Figure 14 shows a sequential series of steps, it will be appreciated that the same steps could be implemented in a different order or at least partially in parallel. Also, while Figure 14 indicates support for each of the variants checked at steps 306, 310, 314, 318, some implementations might not support each of these variants, so the steps for the non-supported variant could be omitted. Similarly, in some implementations, the isolated address region assignment updating instruction might behave, by default, as a particular variant on each instance of executing the instruction, without ability to select whether the instruction behaves as that variant or not, so in this case the corresponding one of steps 306, 310, 314, 318 would cause the “yes” outcome to be performed each time, without the ability to follow the “no” branch following that step.

[0138] While Figures 9 and 13 show two examples of a completer-side-only variant of the instruction and an instruction implementation that could act as either completer-side or requesterside update variants (and possibly also a requester-and-completer-side-update variant), it will be appreciated that a requester-side-only-update variant could also be supported which does not support updates of completer-side isolated address region assignment information.

[0139] The examples above describe an isolated address region assignment updating instruction which specifies a single target physical address.

[0140] However, it is also possible to provide an isolated address region assignment updating instruction which is capable of specifying multiple target physical addresses, for which the update to the isolated address region assignment information (and if specified, any other associated operations such as cache invalidation and / or scrubbing) can be applied to each of those target physical addresses. In this case, any one or more of those target physical addresses may be regarded as the “target physical address” defined in the claims. For example, the instruction may specify size information that indicates a size of a range of addresses for which the update of the isolated address region assignment information is to be applied. In that case, the “target physical address” may be considered to be any address within a range of addresses of the specified size starting from an address determined based on the target address operand of the instruction.

[0141] Concepts described herein may be embodied in computer-readable code for fabrication of an apparatus that embodies the described concepts. For example, the computer-readable code can be used at one or more stages of a semiconductor design and fabrication process, including an electronic design automation (EDA) stage, to fabricate an integrated circuit comprising the apparatus embodying the concepts. The above computer-readable code may additionally or alternatively enable the definition, modelling, simulation, verification and / or testing of an apparatus embodying the concepts described herein.

[0142] For example, the computer-readable code for fabrication of an apparatus embodying the concepts described herein can be embodied in code defining a hardware description language (HDL) representation of the concepts. For example, the code may define a register-transfer-level (RTL) abstraction of one or more logic circuits for defining an apparatus embodying the concepts. The code may define a HDL representation of the one or more logic circuits embodying the apparatus in Verilog, SystemVerilog, Chisel, or VHDL (Very High-Speed Integrated Circuit Hardware Description Language) as well as intermediate representations such as FIRRTL. Computer-readable code may provide definitions embodying the concept using system-level modelling languages such as SystemC and SystemVerilog or other behavioural representations of the concepts that can be interpreted by a computer to enable simulation, functional and / or formal verification, and testing of the concepts.

[0143] Additionally or alternatively, the computer-readable code may define a low-level description of integrated circuit components that embody concepts described herein, such as one or more netlists or integrated circuit layout definitions, including representations such as GDSII. The one or more netlists or other computer-readable representation of integrated circuit components may be generated by applying one or more logic synthesis processes to an RTL representation to generate definitions for use in fabrication of an apparatus embodying the invention. Alternatively or additionally, the one or more logic synthesis processes can generate from the computer-readable code a bitstream to be loaded into a field programmable gate array (FPGA) to configure the FPGA to embody the described concepts. The FPGA may be deployed for the purposes of verification and test of the concepts prior to fabrication in an integrated circuit or the FPGA may be deployed in a product directly.

[0144] The computer-readable code may comprise a mix of code representations for fabrication of an apparatus, for example including a mix of one or more of an RTL representation, a netlist representation, or another computer-readable definition to be used in a semiconductor design and fabrication process to fabricate an apparatus embodying the invention. Alternatively or additionally, the concept may be defined in a combination of a computer-readable definition to be used in a semiconductor design and fabrication process to fabricate an apparatus and computer- readable code defining instructions which are to be executed by the defined apparatus once fabricated.

[0145] Such computer-readable code can be disposed in any known transitory computer- readable medium (such as wired or wireless transmission of code over a network) or non- transitory computer-readable medium such as semiconductor, magnetic disk, or optical disc. An integrated circuit fabricated using the computer-readable code may comprise components such as one or more of a central processing unit, graphics processing unit, neural processing unit, digital signal processor or other components that individually or collectively embody the concept.

[0146] Figure 15 illustrates a simulator implementation that may be used. Whilst the earlier described embodiments implement the present invention in terms of apparatus and methods for operating specific processing hardware supporting the techniques concerned, it is also possible to provide an instruction execution environment in accordance with the embodiments described herein which is implemented through the use of a computer program. Such computer programs are often referred to as simulators, insofar as they provide a software based implementation of a hardware architecture. Varieties of simulator computer programs include emulators, virtual machines, models, and binary translators, including dynamic binary translators. Typically, a simulator implementation may run on a host processor 730, optionally running a host operating system 720, supporting the simulator program 710. In some arrangements, there may be multiple layers of simulation between the hardware and the provided instruction execution environment, and / or multiple distinct instruction execution environments provided on the same host processor. Historically, powerful processors have been required to provide simulator implementations which execute at a reasonable speed, but such an approach may be justified in certain circumstances, such as when there is a desire to run code native to another processor for compatibility or re-use reasons. For example, the simulator implementation may provide an instruction execution environment with additional functionality which is not supported by the host processor hardware, or provide an instruction execution environment typically associated with a different hardware architecture. An overview of simulation is given in “Some Efficient Architecture Simulation Techniques”, Robert Bedichek, Winter 1990 USENIX Conference, Pages 53 - 63.

[0147] To the extent that embodiments have previously been described with reference to particular hardware constructs or features, in a simulated embodiment, equivalent functionality may be provided by suitable software constructs or features. For example, particular circuitry may be implemented in a simulated embodiment as computer program logic. Similarly, memory hardware, such as a register or cache, may be implemented in a simulated embodiment as a software data structure. In arrangements where one or more of the hardware elements referenced in the previously described embodiments are present on the host hardware (for example, host processor 730), some simulated embodiments may make use of the host hardware, where suitable. The simulator program 710 may be stored on a computer-readable storage medium (which may be a non-transitory medium), and provides a program interface (instruction execution environment) to the target code 700 (which may include applications, operating systems and a hypervisor) which is the same as the interface of the hardware architecture being modelled by the simulator program 710. Thus, the program instructions of the target code 700 described above, may be executed from within the instruction execution environment using the simulator program 710, so that a host computer 730 which does not actually have the hardware features of the apparatus 6 or 2 discussed above can emulate these features.

[0148] For example, the simulator code 710 may comprise instruction decoding program logic 712 and processing program logic 714 which simulates decoding and processing of instructions in an equivalent manner to the functionality offered by the instruction decoding circuitry 104 and processing circuitry 105 described above. The instruction decoding program logic 712 comprises conditional logic (e.g. if / then clauses) for decoding instructions of the target code 700, and the processing program logic 714 comprises the sequences of instructions (defined in the native instruction set supported by the host apparatus 730) that are selected for execution by the instruction decoding program logic 712 corresponding to particular instructions decoded by the instruction decoding program logic 712. When the target code 700 includes an isolated address region assignment updating instruction, the instruction decoding program logic 712 may select part of the processing program logic 714 which when executed causes the host apparatus 730 to update isolated address region assignment information in a corresponding way to the examples discussed above. Device simulating program logic 716 simulates the behaviour of one or more devices 22, and may include instructions for enforcing completer-side access control checks such as those described above, based on the completer-side isolated address region assignment information which may be maintained based on the completer-side variant of the updating instruction as discussed above. Host storage mapping program logic 718 maps accesses to simulated registers or simulated memory (requested by the target code 700 according to the target ISA supported by the target code 700) onto host storage resources (e.g. registers and / or memory) provided in hardware in the host apparatus 730. For example, where an operation requested by the target code 700 requires access to a given register, the register access may be mapped onto a register simulating data structure maintained in host memory by the host storage mapping program logic 718 of the simulation program 710, while when an operation requested by the target code 700 requires an access to an address in simulated physical memory, this is mapped onto host virtual addresses in the host virtual address space by the host storage mapping program logic 718. These host virtual addresses may themselves be translated into host physical addresses using the address translation mechanisms supported by the host (the translation of host virtual addresses to host physical addresses being outside the scope of what is controlled by the simulator program 710). In the present application, the words “configured to...” are used to mean that an element of an apparatus has a configuration able to carry out the defined operation. In this context, a “configuration” means an arrangement or manner of interconnection of hardware or software. For example, the apparatus may have dedicated hardware which provides the defined operation, or a processor or other processing device may be programmed to perform the function. “Configured to” does not imply that the apparatus element needs to be changed in any way in order to provide the defined operation.

[0149] In the present application, lists of features preceded with the phrase “at least one of’ mean that any one or more of those features can be provided either individually or in combination. For example, “at least one of: [A], [B] and [C]” encompasses any of the following options: A alone (without B or C), B alone (without A or C), C alone (without A or B), A and B in combination (without C), A and C in combination (without B), B and C in combination (without A), or A, B and C in combination.

[0150] Although illustrative embodiments of the invention have been described in detail herein with reference to the accompanying drawings, it is to be understood that the invention is not limited to those precise embodiments, and that various changes and modifications can be effected therein by one skilled in the art without departing from the scope of the invention as defined by the appended claims.

Claims

CLAIMS1. An apparatus comprising: instruction decoding circuitry to decode instructions according to an instruction set architecture; and processing circuitry to perform processing operations in response to decoded instructions decoded by the instruction decoding circuitry; in which: in response to the instruction decoding circuitry decoding an isolated address region assignment updating instruction specifying a target physical address and an updated isolated address region assignment for the target physical address, the processing circuitry is configured to trigger issuing of at least one memory system request to request an update to isolated address region assignment information which defines access control information for controlling access to the target physical address; the update comprises setting the isolated address region assignment information for the target physical address to indicate one of a plurality of isolated address region assignments selected based on the updated isolated address region assignment specified by the isolated address region assignment updating instruction; and the plurality of isolated address region assignments include at least one more secure isolated address region assignment for which data associated with the at least one more secure isolated address region assignment is to be isolated from being observable by program code associated with at least one less secure isolated address region assignment.

2. The apparatus according to claim 1, in which, in response to a completer-side-update- variant of the isolated address region assignment updating instruction, the processing circuitry is configured to trigger issuing of at least one memory system request to request said update to be applied to completer-side isolated address region assignment information used by completer-side access control circuitry to control access to the target physical address by a completer-side memory system component associated with the completer-side access control circuitry.

3. The apparatus according to claim 2, in which the completer-side memory system component comprises a device which shares access to a memory system of said apparatus and communicates with said apparatus over a device interface according to a device interface protocol.

4. The apparatus according to claim 3, in which the device interface protocol comprises Compute Express Link (CXL).

5. The apparatus according to any of claims 3 and 4, in which the completer-side isolated address region assignment information comprises information indicative of a TEE Exclusive State associated with the target physical address according to CXL-TSP.

6. The apparatus according to any of claims 3 to 5, in which in response to the completer- side-update-variant of the isolated address region assignment updating instruction, the at least one memory system request issued by the processing circuitry comprises a first request defined according to a host memory system protocol and requesting that, if the first request is routed based on the target physical address to said device interface, the device interface generates a second request to be sent to the device according to the device interface protocol, the second request comprising a request for the device to update the completer-side isolated address region assignment information associated with the target physical address.

7. The apparatus according to claim 6, in which the first request indicates that cache entries of at least one cache that specify data associated with the target physical address are to be invalidated.

8. The apparatus according to any of claims 2 to 7, in which in response to the completerside-update-variant of the isolated address region assignment updating instruction, when the target physical address does not correspond to any memory system location for which access is controlled by completer-side access control circuitry, the processing circuitry is configured to permit continued execution of instructions without applying said update to the completer-side isolated address region assignment information corresponding to the target physical address.

9. The apparatus according to any of claims 2 to 8, in which the isolated address region assignment updating instruction specifies, as the updated isolated address region assignment, one of a plurality of requester-side isolated address region assignments defined according to the instruction set architecture; and in response to the completer-side-update-variant of the isolated address region assignment updating instruction, when the target physical address corresponds to a memory system location for which access is controlled by completer-side access control circuitry which does not support any completer-side isolated address region assignment corresponding to the one of the plurality of requester-side isolated address region assignments specified as the updated isolated address region assignment by the completer-side-update-variant of the isolated address region assignment updating instruction: the processing circuitry is configured to permit continued execution of instructions without applying said update to the completer-side isolated address region assignment information corresponding to the target physical address.

10. The apparatus according to any preceding claim, in which, in response to a requester- side-update-variant of the isolated address region assignment updating instruction, the processing circuitry is configured to trigger issuing of at least one memory system request to request said update to be applied to requester-side isolated address region assignment information to be used by requester-side access control circuitry to control access to the target physical address by the processing circuitry.

11. The apparatus according to any preceding claim, in which, in response to a requester- and-completer-side-update variant of the isolated address region assignment updating instruction, the processing circuitry is configured to trigger issuing of at least one memory system request to request corresponding updates to be applied to both: completer-side isolated address region assignment information used by completer-side access control circuitry to control access to the target physical address by a completer-side memory system component associated with the completer-side access control circuitry; and requester-side isolated address region assignment information to be used by requester-side access control circuitry to control access to the target physical address by the processing circuitry.

12. The apparatus according to any preceding claim, in which, in response to an invalidating variant of the isolated address region assignment updating instruction, the processing circuitry is configured to trigger invalidation of cache entries corresponding to the target physical address.

13. The apparatus according to any preceding claim, in which, in response to a scrubbing variant of the isolated address region assignment updating instruction, the processing circuitry is configured to trigger issuing of at least one memory system request to request that a memory system location identified by the target physical address is set to a predetermined value, as well as updating said isolated address region assignment information.

14. The apparatus according to any preceding claim, in which the processing circuitry is configured to signal a fault in response to an attempt to execute the isolated address region assignment updating instruction when the processing circuitry is in an operating state with less than a threshold level of privilege.

15. The apparatus according to any preceding claim, comprising access control circuitry to control whether access to a given physical address region by a given memory access request is allowed based on whether a combination of a requested isolated address region type specifiedby the given memory access request and the isolated address region assignment specified by the isolated address region assignment information associated with the given physical address is an allowed combination of said selected isolated address region and the isolated address region assignment.

16. The apparatus according to any preceding claim, comprising at least one memory system component configured to treat aliasing physical addresses associated with different isolated address region assignments as if they specify different memory system resources even when the aliasing physical addresses actually correspond to the same memory system resource.

17. The apparatus according to any preceding claim, comprising memory encryption circuitry to encrypt or decrypt data associated with a given physical address based on a key selected based on information verified based on the isolated address region assignment specified by the isolated address region assignment information for the given physical address.

18. The apparatus according to any preceding claim, comprising a general purpose CPU, central processing unit; the general purpose CPU comprising the instruction decoding circuitry and the processing circuitry.

19. The apparatus according to any preceding claim, in which, in response to the isolated address region assignment updating instruction, the processing circuitry is configured to issue the at least one memory system request to a memory system bus interface configured to control routing of the at least one memory system request based on the target physical address specified by the isolated address region assignment updating instruction.

20. A computer-readable code for fabrication of the apparatus according to any preceding claim.

21. A method comprising: decoding instructions according to an instruction set architecture; and performing processing operations in response to the decoded instructions; in which: in response to the instruction decoding circuitry decoding an isolated address region assignment updating instruction specifying a target physical address and an updated isolated address region assignment for the target physical address, at least one memory system request is issued to request an update to isolated address region assignment information which defines access control information for controlling access to the target physical address;the update comprises setting the isolated address region assignment information for the target physical address to indicate one of a plurality of isolated address region assignments selected based on the updated isolated address region assignment specified by the isolated address region assignment updating instruction; and the plurality of isolated address region assignments include at least one more secure isolated address region assignment for which data associated with the at least one more secure isolated address region assignment is to be isolated from being observable by program code associated with at least one less secure isolated address region assignment.

22. A computer program for controlling a host data processing apparatus to provide an instruction execution environment for execution of target program code, the computer program comprising: instruction decoding program logic to control the host data processing apparatus to decode instructions of the target program code according to a simulated instruction set architecture; and processing program logic to control the host data processing apparatus to perform processing operations in response to the decoded instructions; in which: in response to decoding of an isolated address region assignment updating instruction specifying a target simulated physical address and an updated isolated address region assignment for the target simulated physical address, the processing program logic is configured to request an update to isolated address region assignment information which defines access control information for controlling access to the target simulated physical address; the update comprises setting the isolated address region assignment information for the target simulated physical address to indicate one of a plurality of isolated address region assignments selected based on the updated isolated address region assignment specified by the isolated address region assignment updating instruction; and the plurality of isolated address region assignments include at least one more secure isolated address region assignment for which data associated with the at least one more secure isolated address region assignment is to be isolated from being observable by program code associated with at least one less secure isolated address region assignment.

23. A storage medium storing the computer-readable code of claim 20 or the computer program of claim 22.

Citation Information

Patent Citations

  • Apparatus and method using plurality of physical address spaces

    US20230132695A1

Cited By

  • Storage device switching method, system, device, medium and product

    CN121957996A