System on Chip
By introducing interconnect circuits and configuration registers into the system-on-chip, using information configuration fragments and verification components, the flexibility and consistency of peripheral access management are solved, and efficient and reliable operation of the system-on-chip is achieved.
Patent Information
- Application Number
- CN202011322375.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-11-22
- Filing Date
- 2020-11-23
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2040-11-23
AI Technical Summary
The prior art is difficult to manage access to peripheral devices and their associated resources flexibly and efficiently in a system-on-chip system, especially in dynamic configuration and low power modes, resulting in difficulty in ensuring reliability and configuration consistency of the system-on-chip system-on-chip.
By introducing interconnect circuits and configuration registers in the system-on-chip, using information configuration fragments and verification components, flexible management of device masters and slave resources can be achieved, ensuring consistency of access permissions and simplification of configuration.
It realizes flexible configuration and efficient management of the system on chip, ensures system reliability and configuration consistency, and supports dynamic adjustment and normal operation in low-power modes.
Smart Images

Figure CN112835846B_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority from French application No. 1913126, filed on November 22, 2019, which is incorporated herein by reference. Technical Field
[0003] Embodiments of the present invention relate to integrated circuits, in particular systems on a chip (SoCs), such as (multi-core or single-core) microcontrollers or microprocessors, and in particular to the management of the operation of such systems on a chip, and more particularly to the management of the configuration of access to peripheral devices of the system on a chip and their associated resources. Background Art
[0004] Resources associated with peripheral devices are elements of the system-on-chip, for example, a clock signal generator, which cooperates with the peripheral devices during operation of the system-on-chip.
[0005] To help ensure the reliability of a system on a chip, it may be necessary to restrict access to specific slave resources by one or more device masters. This feature is designated by those skilled in the art by the term "isolation."
[0006] There is a need to make the management of these access restrictions easy to perform and enforce, especially where the management is dynamic, for example when the management depends on the application being considered for the system on chip, such as on multiple cores of a chip.
[0007] There is also a need to provide a system on a chip, such as a microcontroller or microprocessor, allowing all use cases and all configurations from various users of the system on a chip in a flexible manner, and in particular including low power modes.
[0008] In particular, there is a need to provide management of the configuration of access to peripheral devices and their associated resources (or elements) (for example, but not limited to, generators of clock signals, generators of reset signals for power signals), thereby allowing simplified programming and debugging of the system-on-chip while ensuring consistency of the overall configuration of the system-on-chip. Summary of the Invention
[0009] According to one aspect, a system on a chip, such as a microcontroller, is proposed, which comprises several device masters, for example, when the system is particularly formed as a microcontroller, the system comprises at least one microprocessor and typically comprises several microprocessors, a direct memory access controller (DMA: Direct Memory Access), but without limiting these examples.
[0010] In addition, the SoC includes several dependent resources.
[0011] As a non-limiting example, a dependent resource may belong to a group formed by: at least one peripheral device, e.g., 2 C (“Inter-Integrated Circuit”) type peripherals, SPI (“Serial Peripheral Interface”) type peripherals, UART (“Universal Asynchronous Receiver Transmitter”) type peripherals, or real-time clocks (RTCs); characteristics of peripherals, for example, an alarm line of an RTC peripheral; memory components internal to the system-on-chip; a memory interface that is internal to the system-on-chip and is intended to be coupled to memory components external to the system-on-chip, for example, a DDR (“Double Data Rate”) type memory.
[0012] Furthermore, at least one device master may be controlled by a microprocessor and include an output port capable of issuing transactions and an input port capable of receiving transactions.
[0013] The input ports are then considered slave resources, and the output ports are considered device masters.
[0014] The slave resources include a first specific slave resource coupled to at least one element of the system-on-chip, the elements being intended to cooperate with the first specific slave resource during operation of the system-on-chip.
[0015] Of course, a system on a chip may generally include a plurality of first specific slave resources coupled with a plurality of elements of the system on a chip.
[0016] As a non-limiting example, the first specific slave resource belongs to the group formed by a peripheral device, a feature of a peripheral device, and an input port of a device master capable of being controlled by a microprocessor.
[0017] As a non-limiting example, at least one element belongs to the group formed by a generator of at least one clock signal, a generator of at least one reset signal, a power block, and at least one configurable input / output pin of the system on chip.
[0018] In addition, the system on chip also includes an interconnect circuit (known to those skilled in the art by the name "interconnect"), which is coupled between the device master, the slave resources and the one or more elements, and the interconnect circuit is capable of routing transactions (for example, write or read transactions) between the device master, the slave resources and the one or more elements.
[0019] In addition, the system on chip also includes a processing component, which is configured at least to: allow a user of the system on chip to implement at least one configuration diagram of the system on chip within the system on chip, which configuration diagram is defined by a set of information configuration fragments assigned to a device master, slave resources, and at least one element.
[0020] The set of information configuration fragments is used to define allocating at least one device master to at least some of the slave resources, or to define allocating at least some of the slave resources to at least one device master.
[0021] The information configuration fragment assigned to the at least one element is the same as the information configuration fragment assigned to the first specific dependent resource.
[0022] Thus, for example, all resources or elements of the system on chip used by or associated with the peripheral device have the same access rights as the peripheral device.
[0023] In other words, there is inheritance at each element of the information configuration fragment assigned to the specific slave resource that is coupled to the element and cooperates with it during operation of the integrated circuit.
[0024] Thus, this unique configuration between the slave resource and one or more components coupled to the slave resource simplifies programming, debugging, and ensures configuration consistency of the system-on-chip.
[0025] According to one embodiment, the system comprises:
[0026] a set of configuration registers allocated to each slave resource and each device master, the set of configuration registers allocated to a slave resource being intended to store various pieces of information configuration allocated to that slave resource, and
[0027] - a configuration controller configured to, under control of a first device master, referred to as the device master, update the contents of the set of configuration registers with the set of information configuration fragments.
[0028] According to one embodiment, at least one fragment of configuration information is intended to be attached to each transaction, and the processing component includes a verification component that is configured to verify whether a transaction originating from the device master and intended for an element coupled to the first specific slave resource is authorized to access the element using the at least one fragment of configuration information attached to the transaction and the information configuration fragment assigned to the first specific slave resource.
[0029] The verification component is advantageously configured to perform verification downstream of the interconnection circuitry.
[0030] Indeed, performing verification downstream of the interconnect circuitry rather than upstream allows for homogeneity of implementation and readily allows dependent resources to be added in an easier manner, or even with register or bit-accurate granularity.
[0031] In order to achieve this homogeneity of implementation and this ease of adding subordinate resources when necessary, the verification component advantageously includes: a basic verification module for each subordinate resource, which is configured to access a set of information configuration fragments assigned to the subordinate resource; and a basic verification module for each element, which is configured to access the information configuration fragments assigned to the corresponding first specific subordinate resource.
[0032] Therefore, there is a dispersion of the verification components into localized modules.
[0033] Each basic verification module assigned to a slave resource is connected to the set of configuration registers assigned to the slave resource via a dedicated link, and each basic verification module assigned to an element is connected to the set of configuration registers assigned to the corresponding first specific slave resource via a dedicated link.
[0034] These specific links (eg metal tracks) allow avoiding the use of a bus of the system on chip.
[0035] For example, the set of information configuration segments includes at least one information identification segment assigned to each device master.
[0036] In a very simple case, the set of information configuration fragments may only include information identification fragments assigned to the device master, and these information identification fragments alone allow easy management and definition of the system-on-chip isolation architecture.
[0037] However, the set of information configuration fragments may generally include other information configuration fragments in addition to the information identification fragment, which will allow the isolation architecture to be improved with greater flexibility.
[0038] Therefore, for at least one dependent resource, the set of information configuration fragments of the configuration diagram may further include an information inaccessibility fragment, where the information inaccessibility fragment is intended to indicate that the dependent resource cannot be accessed by any device master.
[0039] According to one embodiment, for each inaccessible dependent resource, the set of information configuration fragments defining the configuration graph also includes an information filtering fragment, which is intended to indicate whether the dependent resource can be accessed by any device master or only by one or more device masters.
[0040] According to one embodiment, for each inaccessible dependent resource, the set of information configuration fragments defining the configuration graph further includes:
[0041] - a first information access fragment, which, if the information filtering fragment indicates that the dependent resource can only be accessed by one or more device masters, is intended to indicate that the dependent resource can be accessed by one or more device masters having the same information identification fragment, and
[0042] - The corresponding information identification fragment.
[0043] According to one embodiment, for each inaccessible dependent resource, the set of information configuration fragments defining the configuration graph further includes:
[0044] - a second information access fragment, which is intended to indicate that the subordinate resource can be accessed by a master component of the device having a different information identification fragment, if the information filtering fragment indicates that the subordinate resource can only be accessed by one or more master components of the device; and
[0045] - A list of information identification fragments of the corresponding device master.
[0046] According to one embodiment, for at least one of the dependent resources accessible by the device master in the list, the set of information configuration fragments defining the configuration graph further includes:
[0047] - a third information segment, intended to indicate that at least one of the slave resources can be accessed by only one device master at a time,
[0048] - A device master wishing to access the slave resource is configured to use a semaphore.
[0049] According to one embodiment, for each inaccessible slave resource, the set of information configuration fragments defining the configuration graph further includes an information security fragment intended to indicate whether the slave resource can be accessed by the device master in security mode.
[0050] According to one embodiment, for each inaccessible slave resource, the set of information configuration fragments defining the configuration graph further includes an information privilege fragment, which is intended to indicate whether the slave resource can be accessed by the device master in privileged mode.
[0051] The concepts of secure mode or privileged mode are well known to those skilled in the art. In the above, one or more elements cooperate with, for example, a single dependent resource.
[0052] However, the system on chip may comprise other slave resources, referred to herein as second specific slave resources, such as channels of a DMA controller, which can be accessed by several device masters, but share at least the same elements.
[0053] For example, a single clock signal generator and a single reset signal generator may be assigned to a DMA controller and thus shared by all DMA channels.
[0054] In particular, for security reasons it is highly preferred to select one of the device masters which will have access to these generators in order to eg disable a master of the device with a lower security level from controlling these clock and reset signal generators.
[0055] Therefore, according to one embodiment, the slave resources include several second specific slave resources, which are coupled to at least the same element of the system on chip and can be accessed by several device masters, and the processing component includes a selection component, which is configured to select the device master that is authorized to access at least one same element.
[0056] The selection means may comprise at least one selection register configured to store pieces of information identifying the device masters which are authorized to access at least one identical element.
[0057] The configuration controller is advantageously also configured to update the contents of one or more selection registers.
[0058] The verification means are advantageously further configured to verify, using at least one fragment of configuration information appended to the transaction and the content of one or more selection registers, whether a transaction originating from the device master and intended for at least one identical element is authorized to access this identical element.
[0059] According to one embodiment, the authentication means comprise, for each identical element, a basic authentication module configured to access the content of one or more selection registers.
[0060] And the basic authentication module is advantageously connected to one or more selection registers via specific links.
[0061] According to another aspect, a method for managing operation of a system-on-chip is provided, the system-on-chip comprising: a plurality of device masters; a plurality of slave resources, the slave resources including a first specific slave resource coupled to at least one element of the system-on-chip, the elements cooperating with the first specific slave resource during operation of the system-on-chip; and interconnect circuitry coupled between the device masters and the slave resources and one or more elements, the interconnect circuitry being capable of routing transactions between the device masters, the slave resources, and the one or more elements, the method comprising:
[0062] -Configuration phase, including:
[0063] At least one configuration diagram is defined by a set of information configuration fragments assigned to a device master, information configuration fragments assigned to slave resources, and information configuration fragments assigned to at least one element, the set of information configuration fragments allowing definition of assigning at least one device master to at least some of the slave resources, the information configuration fragment assigned to the at least one element being the same as the information configuration fragment assigned to the first specific slave resource, and
[0064] implementing at least one configuration diagram within the system-on-chip, and
[0065] - The operation phase, which consists in addressing dependent resources without configuring a collection of fragments using this information.
[0066] According to one embodiment, the method includes coupling a plurality of first specific slave resources to a plurality of elements of a system-on-chip.
[0067] According to one embodiment,
[0068] - the dependent resource belongs to the group formed by at least: a peripheral device, a feature of a peripheral device, a memory component internal to the system-on-chip, a memory interface internal to the system-on-chip and intended to be coupled to a memory component external to the system-on-chip,
[0069] at least one device master controllable by a microprocessor and comprising an output port capable of issuing transactions and an input port capable of receiving transactions, the input port being considered a slave resource and the output port being considered a device master,
[0070] - the first specific slave resource belongs to the group formed by: a peripheral device, a feature of a peripheral device, and an input port of a device master that can be controlled by a microprocessor, and
[0071] - at least one element belongs to the group formed by: a generator of at least one clock signal, a generator of at least one reset signal, a power block and at least one configurable input / output pin of the system on chip.
[0072] According to one embodiment, the method comprises updating, under the control of a first device master referred to as a device master manager, an information configuration fragment assigned to each slave resource and each device master.
[0073] According to one embodiment, at least one fragment of configuration information is attached to each transaction, and the operation phase comprises verifying whether a transaction originating from a device master and intended for an element coupled to a first specific slave resource is authorized to access the element, the verification comprising using the at least one fragment of configuration information attached to the transaction and the information configuration fragment assigned to the first specific slave resource.
[0074] According to one embodiment, verification is performed downstream of the interconnect circuitry.
[0075] According to one embodiment, the verification comprises a local verification performed at the slave resources according to information configuration snippets respectively assigned to these slave resources and at each element according to information configuration snippets assigned to the corresponding first specific slave resource.
[0076] According to one embodiment, the set of information configuration segments includes at least one information identification segment assigned to each device master.
[0077] According to one embodiment, for at least one dependent resource, the set of information configuration fragments of the configuration graph further includes an information inaccessibility fragment, which indicates whether the dependent resource is inaccessible to any device master.
[0078] According to one embodiment, for each inaccessible dependent resource, the set of information configuration fragments defining the configuration graph also includes an information filtering fragment indicating whether the dependent resource is accessible by any device master or only by one or more device masters.
[0079] According to one embodiment, for each inaccessible dependent resource, the set of information configuration fragments defining the configuration graph further includes:
[0080] a first information access fragment, wherein, in the case where the information filtering fragment indicates that the dependent resource can only be accessed by one or more device masters, the first information access fragment indicates that the dependent resource can be accessed by one or more device masters having the same information identification fragment, and
[0081] - The corresponding information identification fragment.
[0082] According to one embodiment, for each inaccessible dependent resource, the set of information configuration fragments defining the configuration graph further includes:
[0083] a second information access fragment, which, if the information filtering fragment indicates that the dependent resource can only be accessed by one or more device masters, indicates that the dependent resource can be accessed by a device master having a different information identification fragment, and
[0084] - A list of information identification fragments of the corresponding device master.
[0085] According to one embodiment, for at least one of the dependent resources accessible by the device master in the list, the set of information configuration fragments defining the configuration graph further includes:
[0086] - a third information segment indicating that at least one of the slave resources can be accessed by only one device master at a time,
[0087] - A device master wishing to access the slave resource uses a semaphore during the operation phase.
[0088] According to one embodiment, for each inaccessible slave resource, the set of information configuration fragments defining the configuration graph further includes an information security fragment indicating whether the slave resource can be accessed by the device master in secure mode.
[0089] According to one embodiment, for each inaccessible slave resource, the set of information configuration fragments defining the configuration graph further includes an information privilege fragment indicating whether the slave resource can be accessed by the device master in privileged mode.
[0090] According to one embodiment, the slave resources include several second specific slave resources that are coupled to at least the same element of the system on chip and can be accessed by several device masters, and the configuration phase includes selecting a device master that is authorized to access at least one same element.
[0091] According to one embodiment, the method comprises storing pieces of information identifying the device masters that are authorized to access at least one identical component.
[0092] According to one embodiment, the verification further comprises: using at least one fragment of configuration information attached to the transaction and an information identification fragment of a device master that is authorized to access at least one element, additionally verifying that a transaction originating from the device master and intended for at least one same element is authorized to access the same element.
[0093] According to one embodiment, additional verification is performed locally at each identical element.
[0094] According to one embodiment, the system on chip forms a microcontroller or a microprocessor. BRIEF DESCRIPTION OF THE DRAWINGS
[0095] Other advantages and features of the present description will become apparent upon examination of the detailed description of the non-limiting embodiments and the accompanying drawings:
[0096] Figure 1 The diagram illustrates a system on a chip;
[0097] Figure 2 The processing components of the system on a chip are illustrated;
[0098] Figure 3 illustrates a static implementation of a configuration diagram;
[0099] Figure 4illustrates a dynamic implementation of a configuration diagram;
[0100] Figure 5 The diagram illustrates the main management components of the device implementing the initial configuration diagram;
[0101] Figure 6 The diagram illustrates that a specific device master can be fixed during production of a system on a chip;
[0102] Figure 7 illustrates user programming of a specified register for a specified device master;
[0103] Figure 8 The diagram illustrates that when the first device master is in its booting phase, all other device masters are rendered inoperative;
[0104] Figure 9 The diagram illustrates the installation components used to implement the initial configuration diagram;
[0105] Figure 10 An installation component is illustrated, the installation component being configured to: render all other device masters inoperative during a boot phase of an initial device master and a boot phase of a new device master;
[0106] Figure 11 Illustrated is the process of changing a device master during execution of a user program after implementing a configuration diagram;
[0107] Figure 12 An example of a collection of information configuration fragments defining a configuration graph is illustrated;
[0108] Figure 13 The diagram illustrates that the device master controls the updating of the configuration map through the configuration controller, which in turn updates the contents of the set of registers;
[0109] Figure 14 An example of the content of a transaction is illustrated;
[0110] Figure 15 An adding component is illustrated, the adding component being configured to: add an information identification segment of the device master to each transaction issued by the device master;
[0111] Figure 16 illustrates a verification component configured to perform verification downstream of the interconnect circuit;
[0112] Figure 17 The diagram illustrates a secondary verification module that verifies that transactions arriving at the configuration controller are initiated by the device master;
[0113] Figure 18 The diagram shows a main device having a slave port and a master port;
[0114] Figure 19 An authentication component is illustrated, the authentication component including a basic authentication module for an element, the basic authentication module being configured to access information configuration fragments assigned to an associated peripheral device;
[0115] Figure 20 illustrates transactions intended for elements being analyzed during an operational phase of a system-on-chip;
[0116] Figure 21 A single reset signal generator is illustrated, which is assigned to the DMA controller and is therefore shared by all DMA channels designated as second slave resources; and
[0117] Figure 22 A verification component is illustrated which is configured to verify, during an operational phase, whether a transaction originating from a device master and intended for a component is authorized to access the component. DETAILED DESCRIPTION
[0118] exist Figure 1 , reference symbol MCU designates a system on chip forming a microcontroller here, but this example is not limitative.
[0119] The system-on-chip MCU here includes several main device components CPU1, CPU2, LM3...LMj...LMk.
[0120] In this example, the device masters CPU1 and CPU2 are microprocessors, and the other device masters could be, for example, direct memory access type (DMA) device masters, or, for example, USB controllers or even PCI Express type device masters, but this list of examples is not exhaustive.
[0121] The system-on-chip MCU also includes several slave resources IMM1, IMTM2, PH3, PH4, PH5, PH60 and PH61.
[0122] Typically, dependent resources belong to a group formed by at least: a peripheral device, a feature of a peripheral device, a memory component internal to the system-on-chip MCU, a memory interface internal to the system-on-chip and intended to be coupled to a memory component external to the system-on-chip.
[0123] Thus, in the example shown, the dependent resource IMM1 is a memory component for a system on a chip.
[0124] The term "memory component" is to be understood here in a general manner and encompasses, for example, the entire memory or, for example, one or more memory areas.
[0125] The slave resource IMTM2 is here an internal memory interface intended to be coupled to an external memory component EXMM, for example a DRAM memory.
[0126] The slave resources PH3, PH4 and PH5 are peripheral devices, for example, UART type peripheral devices, I 2 C controller or SPI controller.
[0127] Reference PH6 designates here a real-time clock (RTC) device comprising, for example, a module PH60 intended to provide a clock signal and a module PH61 intended, for example, to provide an alarm.
[0128] In this case, the modules PH60 and PH61 that are characteristic of the real-time clock device PH6 are considered as slave resources.
[0129] The structure of the device master and the structure of the subordinate resources are conventional and known per se.
[0130] Furthermore, the system on chip MCU comprises an interconnect circuit INTC capable of routing transactions between the device master and the slave resources.
[0131] The structure of such interconnects, which are typically multi-layer interconnects, and the protocols that allow transactions to be switched and routed within the interconnects are well known to those skilled in the art.
[0132] For example, this may refer specifically to:
[0133] - Venkateswara Rao et al.: "A Framework on AMBA bus-based Communication Architecture to improve the Real Time Computing Performance in MPSoC," International Journal of Computer Applications (0975-8887), Vol. 91-N 5, April 2014, or
[0134] A general introduction to these interconnect circuits by A. Gerstlauer, 2015, available on the Internet at the following address: http: / / users.ece.utexas.edu / ~gerstl / ee382v_f14 / lectures / lecture_12.pdf.
[0135] Furthermore, by way of indication but not limitation, for example, the interconnection circuit sold by the company ARM under the reference NIC-400 (version R0p3) may be used.
[0136] The system on chip also comprises a set of configuration registers associated with each device master and each slave resource, the set of configuration registers comprising several configuration registers intended to respectively store configuration pieces of information, the meaning of which will be explained in more detail below.
[0137] Reference RGCM1 designates a set of configuration registers associated with the device main CPU1.
[0138] Reference RGCM2 designates a set of configuration registers associated with the device main CPU2.
[0139] Reference RGCM3 designates a set of configuration registers allocated to the device main LM3.
[0140] Reference RGCMj designates a set of configuration registers allocated to the device master LMj.
[0141] Furthermore, the system on chip here includes a device master LMk, for example, a USB controller that can be controlled by a microprocessor (eg, microprocessor CPU1), and the device master LMk includes an output port PS capable of issuing transactions and an input port PE capable of receiving transactions.
[0142] The input port PE is then considered as a slave resource and the output port PS is then considered as a device master.
[0143] Reference numeral RGCMk thus designates a set of configuration registers allocated to the device master PS.
[0144] Reference sign RGCS1 designates a set of configuration registers allocated to the slave resource IMM1 .
[0145] Reference numeral RGCS2 designates a configuration register set associated with the slave resource IMTM2.
[0146] Reference RGSC3 designates a set of configuration registers associated with the peripheral device PH3.
[0147] Reference RGCS4 designates a set of configuration registers allocated to the peripheral device PH4.
[0148] Reference RGCS5 designates a set of configuration registers allocated to the peripheral device PH5.
[0149] Reference numeral RGCS60 designates a set of configuration registers assigned to feature PH60 .
[0150] And, reference numeral RGCS61 designates a set of configuration registers allocated to feature PH61.
[0151] Furthermore, in this example, a register RDS referred to as a designation register is provided, the characteristics of which will be discussed in more detail, but it may have been indicated that this register RDS is used to designate a device master having the properties of a device master.
[0152] Furthermore, a register RGG, known as the device master register, the characteristics of which will also be discussed in more detail below, is used to specify the current device master, which, as will be seen in more detail below, may be modified during operation of the system-on-chip MCU (here, i.e., during execution of a user program).
[0153] Here, various sets of configuration registers are shown within the controller RIFC.
[0154] However, these sets of configuration registers may be located external to the controller.
[0155] The system-on-chip MCU also includes basic management units RIMU1, RIMU2, RIMU3, RIMUj, and RIMUk associated with each device master.
[0156] The structure and characteristics of these basic management units can be discussed in more detail, but it can be said that these basic management units are part of the addition component that is intended to add an information identification fragment CID and optionally an information security fragment and / or an information privilege fragment to any transaction issued by the device master.
[0157] The system on chip also includes basic verification modules RISU1, RISU2, RISU3, RISU4, RISU5, RISU60 and RISU61 associated with each slave resource, and the structure and characteristics of these basic verification modules will also be discussed in more detail below.
[0158] It can already be said that these basic authentication modules are part of an authentication component intended to verify whether a transaction intended for a subordinate resource is authorized to access this subordinate resource.
[0159] Each basic management unit RIMU and each basic verification module RISU is respectively connected to a corresponding set of configuration registers through a specific link (eg, a metal track).
[0160] Although Figure 1, the basic authentication module RISUi is shown to be external to the corresponding peripheral device, but it is quite possible to provide one or more peripheral devices whose corresponding basic authentication modules are integrated into the peripheral device itself.
[0161] In addition to what has just been described, among the dependent resources, in this example, the peripheral PH4 is coupled to an element EL4 intended to cooperate with the peripheral PH4 during operation of the system on chip.
[0162] Such a dependent resource is designated hereinafter by the term "first specific dependent resource".
[0163] Of course, although only one first specific slave resource PH4 is shown for the sake of simplifying the drawing, some or all of the slave resources may be regarded as first specific slave resources.
[0164] The element EL4 is, for example, a clock signal generator or a reset signal generator, without these two examples being limiting and exhaustive.
[0165] The peculiarities of this coupling between an element and a first specific subordinate resource may be discussed in more detail later, but it can already be said that an information configuration fragment is assigned to such an element and is identical to the information configuration fragment assigned to the first specific subordinate resource cooperating with the element.
[0166] In this respect, the system-on-chip further comprises a basic verification module RISUL4 associated with the element EL4, the structure and features of which will also be discussed in more detail below.
[0167] It can already be said that here, too, the basic authentication module is part of the authentication component intended to verify whether a transaction intended for the component is authorized to access the component.
[0168] In this respect, the basic verification module RISUL4 is connected by specific links (for example metal tracks) to the set RGCS4 of configuration registers assigned to the peripheral device PH4.
[0169] Now, if we refer more specifically to Figure 2 , the system on chip MCU includes a processing unit MT, which is particularly distributed in the reference Figure 1 The various elements described, and the processing means MT are configured to: during a configuration phase PHCFG (step 20), allow a user of the system-on-chip to implement a configuration map SCH within the system-on-chip, the configuration map SCH being defined by a set of information configuration fragments to be stored in various sets of configuration registers.
[0170] Before discussing the composition of these information configuration fragments in more detail, it may already be noted that the user has the possibility of implementing a static configuration or a dynamic configuration.
[0171] More specifically, if Figure 3 As shown in , the processing means are configured to allow a user of the system-on-chip to implement (step 20 ) an initial configuration map SCHI which will form the configuration map SCH.
[0172] In other words, according to this variant, once the initial configuration map has been implemented, it remains valid during the use or operation phase of the system-on-chip.
[0173] Alternatively, Figure 4 As shown in , during the configuration phase PHCFG, the user can implement (step 200) an initial configuration diagram via the processing component MT, which has an initial set of information configuration fragments, and then modify (step 201) the initial configuration diagram via the processing component by modifying, for example, the value of at least one fragment of the configuration information of the initial set, so as to obtain a set of information configuration fragments defining a new configuration diagram SCH.
[0174] The processing component includes an installation component including a first device master referred to as a first device master management component from the device master.
[0175] like Figure 5 As shown in , the first device master management component EMG is configured to: in response to a first boot 50 or cold boot of the system on chip, perform a boot phase, and at the end of the boot phase, the first device master management component EMG is configured to allow at least implementation 51 of the initial configuration map SCHI.
[0176] like Figure 6 As schematically illustrated in FIG, the designation of the first device master EMG may be fixed during production of the 60 system-on-chip MCU, for example, by hard coding.
[0177] Alternatively, the user may use a programmable designation register RDS which allows designation of the first device master EMG.
[0178] More specifically, if Figure 7 As shown in , during provision 70 of the system-on-chip MCU, the user can program 71 the specified register RDS, for example by programming or not programming a series of OTP type memories forming the specified register RDS, so as to specify the device master management component EMG, for example, in this example, the device master management component EMG is the microprocessor CPU1.
[0179] In particular, to avoid conflicts, e.g. Figure 8As shown in , the installation component is also configured to temporarily make all other device masters LM2, LM3, LMj, LMk, CPU2 inoperative (step 81) as long as the first device master EMG (here, microprocessor CPU1) has not completed its boot phase 80.
[0180] When the main component of the device is a microprocessor, the microprocessor can be made inoperative by, for example, forcing a reset signal to 0. Forcing the reset signal to 0 keeps the microprocessor in a standby state.
[0181] When other main components of the device are components of the device controlled by a microprocessor, they will of course not operate as long as the processor itself does not operate.
[0182] As an example, Figure 9 As shown in , in addition to the device master management component EMG, the installation component also includes a boot memory (boot ROM) BMM, which is configured to store a boot program BPR in a storage step 91. The boot program BPR can be executed by the first device master management component CPU1 only during the first boot or cold boot of the system on chip (steps 90 and 92).
[0183] Furthermore, the installation component comprises an input INP ( Figure 1 ). For example, the user program may be stored on an SD card that cooperates with the input INP.
[0184] In step 94, the user program UPR is received from the input INP ( Figure 9 ) and stores (step 95) the user program UPR in the program memory PMM.
[0185] The user program UPR contains at least instructions representing the initial configuration diagram SCHI.
[0186] The processing means then comprise allocation means allowing the implementation of the initial configuration diagram.
[0187] In this example, the allocation means comprise a first device master (eg microprocessor CPU1 ) configured to execute (step 93 ) a user program UPR at the end of its boot phase in order to implement the initial configuration map.
[0188] Although a microprocessor (eg, microprocessor CPU1 ) has been described herein as the first device master EMG, it is likely that the first device master includes a hardware logic circuit, alternatively.
[0189] Although only a single device master is described during the configuration phase PHCFG, Figure 10As schematically illustrated in , the device master management component can be modified during this configuration phase.
[0190] More specifically, the installation component then includes a device master component (e.g., microprocessor CPU1) from the device master component, referred to as an initial device master management component, which is configured to perform a boot phase during the first boot of the system on chip, and at the end of the boot phase, the initial device master management component is configured to authorize the booting of another device master component (e.g., microprocessor CPU2) designated as the new device master management component.
[0191] This new device master then forms a first device master configured to allow at least the implementation of the initial configuration map at the end of its boot phase.
[0192] The initial device host may include a microprocessor, and the new device host may include another microprocessor.
[0193] Alternatively, the initial device master may include hardware logic circuitry and the new device master may include a microprocessor.
[0194] Furthermore, the installation component is here again configured to temporarily render all other device masters inoperative as long as the boot phase of the initial device master and the boot phase of the new device master are not completed.
[0195] As Figure 10 An example is shown in , in which respect the installation means comprises a boot memory BMM configured to store (step 100 ) a boot program BPR1 which can be executed by the initial device main management component CPU1 only during a first boot or cold boot of the system-on-chip MCU.
[0196] The installation means also comprise a program memory PMM configured to store a boot program BPR2 of the new device main management means CPU2.
[0197] The boot program BPR2 and the user program UPR are then received, for example via the input INP, and these two programs are stored (step 104 ) in the program memory PMM.
[0198] During a cold boot 101 , the initial device master CPU1 executes its boot program BPR1 (step 102 ) and then authorizes the booting of the microprocessor CPU2 as the new device master.
[0199] The microprocessor CPU2 executes its boot program PBR2 in step 105 and then executes the user program UPR (step 106) to implement the initial configuration diagram SCHI.
[0200] Of course, as described above, in step 107, the other equipment main parts LM2, LM3, LMj and LMk do not operate.
[0201] Although we have seen that it is possible to change the device master during the configuration phase, Figure 11 As shown in , the device master can also be changed during the operating phase PHF of the system-on-chip (ie, during user program execution after the configuration map has been implemented).
[0202] More specifically, in Figure 11 In the embodiment, the microprocessor CPU1 is the first device master. Also, during the execution 110 of the user program UPR, the processing unit MT modifies (step 111) the device master EMG, which in this case becomes the new device master CPU2.
[0203] Of course, the new device master CPU2 can again designate (step 112) a new device master and then lose its property as a device master. As an example, the new device master can again be the microprocessor CPU1.
[0204] In this respect, only the device master can designate a new device master, and this is accomplished, for example, by the current device master writing an information identification fragment of the new device master into the manager register RGG.
[0205] From that moment on, the old device master loses its nature as a device master.
[0206] Now more specifically refer to Figure 12 , to illustrate an example of a set of information configuration fragments defining a configuration graph SCH.
[0207] For each device, the set of information configuration fragments includes an information identification fragment CID that allows identification of the device master from a list of device masters.
[0208] The information identification fragment CID may be, for example, a digital word.
[0209] The set of information configuration fragments of the device master may further include an information security fragment SEC (eg, one bit), which indicates whether the device master is configured to be in a security mode according to a logic value of the bit.
[0210] The set of information configuration fragments of the device master may further include an information privilege fragment PRV (eg, one bit), which indicates whether the device master is configured to be in a privileged mode according to a logic value of the bit.
[0211] If several levels of privileged modes are provided, the privileged fragment of information may include several bits.
[0212] Finally, an information lock fragment LKM (e.g., one or more bits) can be provided, which indicates whether at least one information configuration fragment (e.g., information configuration fragment SEC and PRV, or information identification fragment CID) in the information configuration fragment can be modified based on the logical value of the one or more bits.
[0213] One or more lock bits may also be provided which allow locking of the content of the manager register RGG, the content of which specifies an information identification segment of the device master manager.
[0214] These information configuration fragments associated with the device master are stored (step 120) in the corresponding set RGMCi of configuration registers.
[0215] Regarding a slave resource, the set of information configuration fragments associated therewith may include, for example, an information inaccessibility fragment INAC (e.g., one bit), which is intended to indicate, according to the logic value of the bit, that the slave resource cannot be accessed by any device master.
[0216] For inaccessible slave resources, the configuration diagram SCH also includes an information filtering fragment IFLT (e.g., one bit), which is intended to indicate only based on the information identification fragment CID of the device master whether the slave resource can be accessed by any device master or only by one or more device masters.
[0217] Thus, for example, if the information filtering segment has a logical value of "0", this means that no filtering is applied to the information identification segment and, therefore, the dependent resource can be accessed by any device master, subject to other access restrictions as will be seen in more detail below.
[0218] In practice, these collections of information configuration fragments allow at least one device master to be assigned to a slave resource.
[0219] It should be noted that several device masters may have the same information identification fragment CID.
[0220] For example, when these equipment masters comprise a microprocessor and one or more equipment masters that can be controlled by the microprocessor, this is exactly the case. In this case, a division specified by the information identification fragment CID is formed.
[0221] All device masters of the partition can then, for example, access the same memory resources.
[0222] For security reasons, a device master controlled by a microprocessor may not have the same information identification segment as the microprocessor. This is the case, for example, for PCI-E devices. In this case, this allows limiting access to some memory resources of the PCI-E device master.
[0223] For inaccessible subordinate resources, the set of information configuration fragments defining the configuration diagram may also include a first information access fragment IAC1. When the information filtering fragment IFLT (for example, IFLT=1) indicates that the subordinate resource under consideration can only be accessed by one or more device masters, the first information access fragment IAC1 is intended to indicate that the subordinate resource can be accessed by one or more device masters having the same information identification fragment CID.
[0224] Of course, in this case, the set of information configuration fragments includes the corresponding information identification fragment CID.
[0225] As mentioned above, the information identification segment CID may relate to a single device master or to several device masters in the same partition.
[0226] For the inaccessible dependent resource, the set of information configuration fragments defining the configuration diagram SHC may further include a second information access fragment IAC2. When the information filter fragment IFLT (IFLT=1) indicates that the dependent resource is accessible only by one or more device masters, the second information access fragment IAC2 is intended to indicate that the dependent resource is accessible by device masters having different information identification fragments CID. Furthermore, in this case, the set of information configuration fragments for the dependent resource includes, for example, a list CID1...CID4 of information identification fragments corresponding to the device masters.
[0227] Such a slave resource, which can be accessed sequentially or simultaneously by several device masters, can be, for example, a memory component.
[0228] On the other hand, for the slave resource that can be accessed by the device masters in the list, it is possible that: the set of information configuration fragments includes a third information fragment IAC3, which is intended to indicate that the slave resource can only be accessed by one device master at a time, and the device master that wishes to access the slave resource is configured to use the semaphore SMP.
[0229] This is the case, for example, when a dependent resource can be accessed by two microprocessors. Only the microprocessor that uses the semaphore can access the dependent resource, and the other microprocessor cannot access the dependent resource until the microprocessor releases the semaphore. Only when it is the microprocessor's turn to use the semaphore SMP can the microprocessor access the dependent resource.
[0230] For the slave resource, the set of information configuration fragments defining the configuration graph SCH may further include an information security fragment ISEC (eg, one bit), which is intended to indicate whether the slave resource can be accessed by the security master of the device.
[0231] Likewise, for the slave resource, the set of information configuration segments may include an information privilege segment IPRV (eg, one bit), which is intended to indicate whether the slave resource can be accessed by the device master in privileged mode.
[0232] And, here again, an information lock segment LKS may also be used, which is intended to indicate whether the information configuration segment of the subordinate resource can be modified.
[0233] All these information configuration fragments assigned to the slave resources are stored (step 121 ) in the corresponding set of configuration registers RGSCi.
[0234] Here, it should be noted that the first device host (eg, microprocessor CPU1) is configured to be in a secure mode and a privileged mode at the end of its boot phase.
[0235] As described above, the allocation component that allows the implementation of a configuration diagram, in particular an initial configuration diagram, includes a set of configuration registers allocated to each slave resource and each device master, and a configuration controller RIFC, which is configured to: under the control of the first device master management component, update the contents of the set of configuration registers using a set of information configuration fragments.
[0236] This is Figure 13 Schematically illustrated in FIG.
[0237] More specifically, the device main management element CPU1 controls (step 130) the updating of the configuration map SCH performed by the configuration controller RIFC, which updates the contents of the sets of registers RGMCi and RGCSi (step 131).
[0238] Furthermore, only the device master having the property of the device master management component is configured to modify the configuration diagram.
[0239] Now, more specifically referring to Figure 14An example of the content of transaction TR is described below.
[0240] Typically, each transaction TR issued by the device master comprises an addressing field ADR, the content of which is intended to address the slave resource receiving the transaction.
[0241] However, the content of the addressing field ADR does not belong to the set of information configuration fragments.
[0242] In other words, the contents of the addressing fields are not used, alone or in combination, to define the assignment of device masters to slave resources.
[0243] More specifically, if Figure 14 As shown in , each transaction TR includes: an information identification segment CID of the device master that issues the transaction, an information security segment SEC, an indication EXE intended to indicate whether the transaction contains an execution instruction, an information privilege segment PRV, information RW indicating whether the transaction is a read transaction or a write transaction, an addressing field ADR, and a data field DATA.
[0244] The processing component of the system on chip includes an adding component configured to add at least an information identification fragment CID of the device master to each transaction issued by the device master, the information identification fragment CID not belonging to the addressing field ADR of the transaction.
[0245] The adding component is further configured to add the information security fragment SEC and / or the information privilege fragment to each transaction issued by the device master if these two fragments of information are not already present in the transaction issued by the device master.
[0246] like Figure 15 As shown in , these additional components comprise, for each equipment master EMi, an associated basic management unit RIMUi linked to a corresponding set of configuration registers RGCMi via a specific link LDMi.
[0247] The basic management unit RIMUi therefore completes the initial transaction TRI issued by the equipment master EMi by adding (step 150) the information identification fragment CID and optionally the information SEC and PRV to this initial transaction TR, the complete transaction TR then being provided on the bus linked to the interconnection circuit INTC.
[0248] Essentially, the basic management unit RIMUi may include logic circuits.
[0249] The processing component MT may also include a verification component, which is configured to: use at least the information configuration fragment attached to the transaction, and typically use at least some of the other information configuration fragments of the set of information configuration fragments assigned to the slave resource, to verify whether the transaction TR originating from the device master and intended for the slave resource is authorized to access the slave resource.
[0250] More specifically, if Figure 16 As shown in , the verification components are configured to perform verification downstream of the interconnection circuit INTC, and these verification components include a basic verification module RISUi for each slave resource, which basic verification module RISUi is configured to access a set of information configuration fragments, which are assigned to the slave resource and stored in a corresponding set of configuration registers RGCSi via a specific link LDSi.
[0251] In step 160 , access authorization verification is performed.
[0252] This verification allows defining in step 161 whether access to the transaction TR intended for the slave resource RSSi is authorized or not.
[0253] This is the case, for example, if the filtering indication IFLT is enabled and the slave resource can only be accessed by one or more device masters having the same information identification segment, and the information identification segment contained in the transaction TR does not correspond to the information identification segment stored in the set of registers RGCSi.
[0254] The verification component then determines whether the rejected transaction is a read transaction (step 163).
[0255] If this is the case, the basic management unit RISUi returns (step 164) an access rejection indication IR, for example 0, to the device master EMi that issued the rejected transaction.
[0256] In parallel, the basic verification module RISUi returns (step 165) an illegal access notification NIAC to the device master management component EMG, which contains: the identifier IDRSSi of the slave resource RSSi, the information identification fragment CIDi of the device master component EMI at the source of the rejected transaction, and the transaction type (here, read type).
[0257] If the rejected transaction is a write transaction, the transaction is completely and simply ignored (step 167), but the basic verification module RISUi still returns an illegal access notification to the device master management component EMG, which again contains: the identifier IDRSSi, the information identification fragment CIDi of the device master component EMI at the source of the rejected transaction, and the type of the rejected transaction (here, write type).
[0258] Structurally, the basic verification module RISU may include logic circuits.
[0259] We have seen previously that only the device master can send transactions to the configuration controller, for example to update configuration registers.
[0260] Therefore, in this regard, it is necessary to verify that the transactions arriving at the configuration controller are indeed issued by the device master.
[0261] This is the task assigned to the auxiliary verification module RISUC of the configuration controller RIFC ( Figure 17 ).
[0262] In this regard, when a transaction TRC - in particular, the transaction TRC contains the information identification segment CID of the device master at the source of the transaction TRC - is provided (step 170) to the auxiliary verification module RISUC, the auxiliary verification module RISUC - the auxiliary verification module RISUC is connected to the manager register RGG containing the information identification segment CID of the current manager device (for example, microprocessor CPU1) - verifies that the information identification segment CID contained in the transaction TRC does correspond to the information identification segment CID1 (step 171).
[0263] If this is not the case, access to the controller RIFC is denied (step 173 ).
[0264] On the other hand, if there is a match between the two information identification fragments, the transaction TRC is indeed provided to the configuration controller RIFC (step 172).
[0265] It has been seen before that among the device masters there may be at least one device master having a slave port and a master port.
[0266] For example, for a device master LMk having an input port PE (slave port) and an output port PS (master port), Figure 18 ) is the case.
[0267] Such a device master may be, for example, a USB controller which may be controlled by a microprocessor, but may also be controlled by another microprocessor during execution of a user program.
[0268] Such a device master may also be a direct memory access controller (DMA).
[0269] The slave port PE is associated with a basic authentication module RISUk connected to a corresponding set of configuration registers RGCSk, and the master port PS is associated with a basic management unit RIMUk connected to a corresponding set of configuration registers RGCMk and also to a corresponding set of configuration registers RGCSk.
[0270] It is initially assumed that the device main unit LMk is controlled by the microprocessor CPU1.
[0271] In this case, the set of configuration registers RGCSk linked to the basic authentication module RISUk contains: the information identification fragment CID1 of the microprocessor 1 and the privileged information fragment and the information security fragment corresponding to the privileged information fragment and the information security fragment of the microprocessor CPU1.
[0272] The register set RGCMk also includes the information identification fragment CID1 of the microprocessor CPU1 and the corresponding information security fragment and information privilege fragment.
[0273] Then, the processing component includes the inheritance component MINH( Figure 18 ), the inheritance component MINH is configured to: when controlling and by taking into account the inheritance rules, replace at least some of the information configuration fragments assigned to the master port with homologous information configuration fragments assigned to the slave port, or retain the information configuration fragments assigned to the master port.
[0274] Thus, when another microcontroller controls such a device master LMk, the inheritance component can, by simple switching - and if the inheritance rules allow it - give to the master port the information configuration fragment of the slave port corresponding to the information configuration fragment of the other microcontroller.
[0275] However, if the device master controlling the inheritance rules is not itself in secure mode, the inheritance rules prohibit, for example, defining a port for a peripheral device in secure mode.
[0276] More specifically, these inheritance means MINH comprise a set of controllable switches SW, produced for example in the form of hardware, selectively connected to a set of registers RGMk and to a set of registers RGCSk.
[0277] The inheritance means MINH also comprise an MCM control means produced, for example, in the form of software within the microprocessor CPU1 and capable of issuing control signals CSP intended to control the set of switches SW taking into account the inheritance rules.
[0278] As long as the device master LMk is controlled by the microprocessor CPU1, the control member MCM places the switch SW in position A in order to add the information identification fragment CID1 and the corresponding information privilege fragment and information security fragment to the transactions issued by the primary port PS.
[0279] On the other hand, if at a given moment there is a modification of the configuration diagram, so that, for example, the microprocessor CPU2 must control the device main part LMk, then:
[0280] - on the one hand, updating the set of configuration registers RGCSk with the new information identification fragment CID2 of the microprocessor CPU2 and with the corresponding information privilege fragment and information security fragment, and
[0281] On the other hand, the switch SW is switched to position B in order to automatically append the information identification fragment CID2 of the microprocessor CPU2 and the corresponding information privilege fragment and information security fragment to the transaction issued by the master port PS to the interconnection circuit INTC.
[0282] In other words, there is no need to completely reprogram the system on chip; by simply switching, the new information assigned to the slave port will be automatically inherited to the master port.
[0283] Now more specifically refer to Figure 19 and Figure 20 The following situation is described: the first specific slave resource PH4 is coupled to the element EL4 and cooperates with the element EL4 during operation of the system-on-chip MCU.
[0284] Of course, several elements of different nature may be coupled to the peripheral device.
[0285] Each element may be, for example, a generator of at least one clock signal, a generator of at least one reset signal, a power block, or at least one configurable input / output pin of a system on chip.
[0286] This element can receive transactions TR of the write type.
[0287] In the case of a clock signal generator, a transaction may, for example, include an instruction to modify the frequency of one or more clock signals or an instruction to stop the generator.
[0288] In the case of a reset signal generator, the transaction may, for example, include instructions intended to control the generator so that it effectively provides the reset signal.
[0289] In the case of a power block, a transaction may for example comprise an instruction aimed at stopping or starting the booting of the control block.
[0290] In the case of configurable input / output pins of a system-on-chip, a transaction may, for example, be intended to write one or more bits into a register, which is typically associated with the pin and is intended to configure the (input, output) pin or the routing of the pin within the system-on-chip.
[0291] As described above, the information configuration fragment assigned to the element EL4 is the same as the information configuration fragment assigned to the first specific slave resource PH4.
[0292] Thus, and more generally, all resources or elements of the system-on-chip, for example, used by a peripheral device, have the same access rights as the peripheral device.
[0293] In other words, there is inheritance at each element of the information configuration fragment assigned to a specific slave resource that is coupled to the element and cooperates with it during operation of the integrated circuit.
[0294] Thus, this unique configuration between the slave resource and one or more components coupled thereto simplifies programming, debugging, and ensures configuration consistency of the system-on-chip.
[0295] More specifically, and as Figure 19 As shown in FIG, the authentication means advantageously comprise, for the element EL4, a basic authentication module RISUL4, for example having a structure similar to that of the basic authentication module RISU and being configured to access an information configuration fragment assigned to the peripheral device PH4.
[0296] In this respect, the basic verification module RISUL4 is connected via a dedicated link LDSL4 to a set of configuration registers RGCS4 assigned to the peripheral device PH4.
[0297] During the operating phase PHF of the system on chip, the transaction TR intended for the element EL4 is analyzed by the module RISUL4 using the information configuration fragment contained in the transaction TR and the information configuration fragment contained in the set RGCS4 of configuration registers assigned to the peripheral device PH4. Figure 20 ).
[0298] This allows to verify the access authorization of the transaction TR to the element EL4 in step 260 and subsequently execute, for example, a similar Figure 16 Steps 161 to 167.
[0299] exist Figure 19 In a project, one or more components collaborate with a single dependent resource.
[0300] However, the system on chip may include other slave resources (referred to herein as second specific slave resources), such as channels of a DMA controller, which are accessible to several device masters but share at least one common element.
[0301] For example, Figure 21 As shown in FIG, a single reset signal generator EL10 is assigned to the DMA controller and is therefore shared by all DMA channels CH101 to CH108, which are designated here as second special slave resources.
[0302] Of course, other elements can be shared by all DMA channels.
[0303] Basic verification modules RISU101 to RISU108 are allocated to DMA channels CH101 to CH108 respectively, and the basic verification modules RISU101 to RISU108 are coupled to corresponding configuration registers RGCS101 to RGCS108 respectively.
[0304] Here, at least two of the DMA channels can be accessed by different device masters, for example, the microprocessor CPU1 having the information identification segment CID1 and the microprocessor CPU2 having the information identification segment CID2.
[0305] And in particular, for security reasons, it is very preferred to select one of the device masters that can access the generator, so as to, for example, prohibit a device master with a lower security level from controlling the generator EL10.
[0306] Thus, for example, it is desirable that only the microprocessor can access element EL10.
[0307] In this respect, it is advantageously provided that the processing means comprise selection means configured to select a device master which is authorized to access the same element EL10 .
[0308] Here, the selection means comprises at least one selection register RGSEL configured to store information identification fragments CID1 of device masters that are authorized to access the same element EL10.
[0309] Advantageously, the configuration controller RIFC is further configured to update the content of one or more RGSEL selection registers.
[0310] For the same element EL10 , the verification means comprise a basic verification module RISUL10 configured to access the content of one or more selection registers RGSEL.
[0311] Furthermore, the basic verification module RISUL10 is advantageously connected to one or more selection registers RGSEL via a specific link LDSL10.
[0312] like Figure 22 As shown in , the verification means are also advantageously configured to verify, during the operating phase PHF, using at least one fragment of configuration information attached to the transaction and the content of one or more selection registers RGSEL, whether a transaction TR originating from the device master and intended for the same element EL10 is authorized to access this same element.
[0313] More specifically, during the configuration phase PHCFG, a device master that is authorized to access the element EL10 is selected (step 2100 ), and its information identification fragment CID1 is stored in the register RGSEL.
[0314] It should be noted that this selection may be fixed and not modifiable or programmable.
[0315] In the operation phase PHF, the module RISUL10 analyses the transaction TR (step 2102) using the information identification fragment CID contained in the transaction TR and the CID1 contained in the selection register RGSEL.
[0316] In case of a match, access to element EL10 is granted (step 2103), otherwise access is denied (step 2104).
[0317] It should be noted that the present invention is compatible with the invention described in the French patent application filed on the same day as the present application on behalf of STMicroelectronics (Alps) SAS and STMicroelectronics (Grand Ouest) SAS and having the title “Method for managing the operation of a system on a chip, for example forming a microcontroller, and corresponding system on a chip”.
[0318] Example embodiments of the invention are summarized here. Other embodiments can be understood from the overall description and claims submitted here.
[0319] Example 1. A system on chip, comprising: a plurality of device masters; a plurality of slave resources, the plurality of slave resources including a first specific slave resource (PH4) coupled to at least one element (EL4) of the system on chip, the at least one element (EL4) being intended to cooperate with the first specific slave resource during operation of the system on chip; an interconnect circuit (INTC) coupled between the device masters, the slave resources and the one or more elements and capable of routing transactions between the device masters, the slave resources and the one or more elements; and a processing unit (MT) configured at least to: allow a user of the system on chip to implement at least one configuration diagram (SCH) of the system within the system on chip (MCU), the at least one configuration diagram (SCH) being defined by a set of information configuration fragments assigned to the device masters, information configuration fragments assigned to the slave resources, and information configuration fragments assigned to the at least one element; the set of information configuration fragments being used to define the assignment of at least one device master to at least some of the slave resources; the information configuration fragments assigned to the at least one element being the same as the information configuration fragments assigned to the first specific slave resource.
[0320] Example 2. The system on chip of Example 1, comprising a plurality of first specific slave resources coupled to a plurality of elements of the system on chip (MCU).
[0321] Example 3. A system on a chip according to any one of Examples 1 or 2, wherein
[0322] - a dependent resource belongs to a group formed by at least: a peripheral device (PH3), a feature (PH60) of a peripheral device (PH6), a memory component (IMM1) internal to the system-on-chip, a memory interface (INTM2) internal to the system-on-chip and intended to be coupled to a memory component (EXMM) external to the system-on-chip;
[0323] at least one device master (LMk) capable of being controlled by a microprocessor and comprising an output port (PS) capable of issuing transactions and an input port (PE) capable of receiving transactions, the input port being considered a slave resource and the output port being considered a device master;
[0324] - the first specific slave resource belongs to the group formed by: a peripheral device, a feature of a peripheral device, and an input port of a device master capable of being controlled by a microprocessor; and
[0325] - said at least one element (EL4) belongs to the group formed by: a generator of at least one clock signal, a generator of at least one reset signal, a power block and at least one configurable input / output pin of said system-on-chip.
[0326] Example 4. A system-on-chip according to any of the preceding examples, comprising:
[0327] a set of configuration registers allocated to each slave resource and to each device master, said set of configuration registers allocated to a slave resource being intended to store various pieces of information configuration allocated to this slave resource; and
[0328] - a configuration controller (RFIC) configured to, under the control of a first device master, referred to as the device master, update the contents of said set of configuration registers with said set of information configuration fragments.
[0329] Example 5. A system on chip according to any of the preceding examples, wherein at least one fragment of configuration information is intended to be attached to each transaction, and the processing unit (MT) includes a verification unit (RISUL4), which is configured to verify whether a transaction originating from a device master and intended for an element coupled to a first specific slave resource is authorized to access the element by using the at least one fragment of configuration information attached to the transaction and the information configuration fragment assigned to the first specific slave resource.
[0330] Example 6. The system on chip of Example 5, wherein the verification component is configured to perform the verification downstream of the interconnect circuit (INTC).
[0331] Example 7. The system-on-chip of any of Examples 5 or 6, wherein the verification component comprises:
[0332] a basic authentication module (RISUi) for each subordinate resource, configured to access said set of information configuration fragments assigned to this subordinate resource; and
[0333] The basic authentication module (RISUL4) for each element (EL4) is configured to access said information configuration fragment assigned to the corresponding first specific slave resource.
[0334] Example 8. A system on a chip according to Example 7, wherein each basic verification module (RISUi) assigned to a slave resource is connected to the set of configuration registers (RGCSi) assigned to the slave resource via a dedicated link (LDSi), and each basic verification module (RISUL4) assigned to an element is connected to the set of configuration registers (RGCS4) assigned to the corresponding first specific slave resource (PH4) via a dedicated link (LDSL4).
[0335] Example 9. The system on chip of any preceding example, wherein the set of information configuration segments includes at least one information identification segment (CID) assigned to each device master.
[0336] Example 10. A system on chip according to Example 9, wherein for at least one slave resource, the set of information configuration fragments of the configuration diagram also includes an information inaccessibility fragment (INAC), and the information inaccessibility fragment (INAC) is intended to indicate that the slave resource cannot be accessed by any device master.
[0337] Example 11. A system on a chip according to any of Examples 9 or 10, wherein for each inaccessible slave resource, the set of information configuration fragments defining the configuration diagram also includes an information filtering fragment (IFLT), wherein the information filtering fragment (IFLT) is intended to indicate whether the slave resource can be accessed by any device master or only by one or more device masters.
[0338] Example 12. The system on chip of Example 11, wherein for each inaccessible dependent resource, the set of information configuration fragments defining the configuration map further comprises:
[0339] a first information access fragment (IAC1), which, when the information filtering fragment indicates that the subordinate resource can only be accessed by one or more device masters, is intended to indicate that the subordinate resource can be accessed by one or more device masters having the same information identification fragment; and
[0340] - The corresponding information identification fragment (CID).
[0341] Example 13. The system on chip of Example 12, wherein for each inaccessible dependent resource, the set of information configuration fragments defining the configuration map further comprises:
[0342] a second information access fragment (IAC2) which, when the information filtering fragment indicates that the dependent resource can only be accessed by one or more device masters, is intended to indicate that the dependent resource can be accessed by device masters having different information identification fragments; and
[0343] - List of information identification fragments of the corresponding device master (CID1...CID4).
[0344] Example 14. A system on chip according to Example 13, wherein, for at least one of the slave resources that can be accessed by the device master of the list, the set of information configuration fragments defining the configuration diagram also includes a third information fragment (IAC3), and the third information fragment (IAC3) is intended to indicate that the at least one of the slave resources can only be accessed by one device master at a time, and the device master that wishes to access the slave resource is configured to use a semaphore.
[0345] Example 15, a system on a chip according to any one of Examples 9 to 14, wherein for each inaccessible slave resource, the set of information configuration fragments defining the configuration diagram also includes an information security fragment (ISEC), and the information security fragment (ISEC) is intended to indicate whether the slave resource can be accessed by a device master in a secure mode.
[0346] Example 16. A system on a chip according to any one of Examples 9 to 15, wherein for each inaccessible slave resource, the set of information configuration fragments defining the configuration diagram also includes an information privilege fragment (IPRV), wherein the information privilege fragment (IPRV) is intended to indicate whether the slave resource can be accessed by a device master in privileged mode.
[0347] Example 17. A system on chip according to any of the preceding examples, wherein the slave resources include several second-specific slave resources (CH101 to CH108), the several second-specific slave resources are coupled to at least the same element (EL10) of the system on chip and can be accessed by several device masters, and the processing component includes a selection component, which is configured to select the device master that is authorized to access at least one same element.
[0348] Example 18. The system on chip of Examples 9 and 17, wherein the selection component comprises at least one selection register (RGSEL) configured to store the information identification fragment (CID) of the device master that is authorized to access the at least one same element.
[0349] Example 19. The system on chip of Examples 4 and 18, wherein the configuration controller (RIFC) is further configured to update the contents of one or more selection registers.
[0350] Example 20, a system on a chip according to any one of Examples 18 or 19 in combination with Example 5, wherein the verification component is further configured to: verify whether a transaction originating from a device master and intended for at least one same element is authorized to access the same element (EL10) by using at least one fragment of the configuration information attached to the transaction and the contents of one or more selection registers.
[0351] Example 21. The system on chip of Example 20, wherein for each identical element, the verification component comprises a basic verification module (RISUL10) configured to access the content of the one or more selection registers.
[0352] Example 22. The system on chip of Example 21, wherein the basic authentication module is connected to the one or more selection registers via a specific link (LDSL10).
[0353] Example 23. A system on a chip according to any of the preceding examples, forming a microcontroller (MCU) or a microprocessor.
[0354] Example 24. A method for managing operation of a system-on-chip, the system-on-chip comprising: a plurality of device masters; a plurality of slave resources, the plurality of slave resources including a first specific slave resource coupled to at least one element of the system-on-chip, the at least one element cooperating with the first specific slave resource during operation of the system-on-chip; and interconnect circuitry coupled between the device masters and the slave resources and the one or more elements and capable of routing transactions between the device masters, the slave resources, and the one or more elements, the method comprising:
[0355] a configuration phase (PHCFG), comprising: defining at least one configuration graph by means of a set of information configuration fragments assigned to the device master, information configuration fragments assigned to the slave resources, and information configuration fragments assigned to the at least one element, the set of information configuration fragments allowing definition of assignment of at least one device master to at least some of the slave resources, the information configuration fragment assigned to the at least one element being identical to the information configuration fragment assigned to the first specific slave resource, and implementing the at least one configuration graph within the system-on-chip; and
[0356] - An operational phase (PHF) consisting in addressing said dependent resources without using a set of these information configuration fragments.
[0357] Example 25. The method of Example 24, comprising coupling a first plurality of specific slave resources to a plurality of elements of the system-on-chip.
[0358] Example 26. A method according to any one of Examples 24 or 25, wherein
[0359] - a dependent resource belongs to a group formed at least by: a peripheral device (PH3), a feature of a peripheral device (PH60, PH61), a memory component internal to the system-on-chip, a memory interface internal to the system-on-chip and intended to be coupled to a memory component external to the system-on-chip;
[0360] at least one device master (LMk) capable of being controlled by a microprocessor and comprising an output port (PS) capable of issuing transactions and an input port (PE) capable of receiving transactions, the input port being considered a slave resource and the output port being considered a device master;
[0361] - the first specific slave resource belongs to the group formed by: a peripheral device, a feature of a peripheral device, and an input port of a device master capable of being controlled by a microprocessor; and
[0362] - the at least one element belongs to the group formed by: a generator of at least one clock signal, a generator of at least one reset signal, a power block and at least one configurable input / output pin of the system-on-chip.
[0363] Example 27. The method of any one of Examples 24 to 26, comprising updating the information configuration fragments assigned to each slave resource and each device master under the control of a first device master referred to as a device master manager (EMG).
[0364] Example 28. A method according to any one of Examples 24 to 27, wherein at least one fragment of configuration information is attached to each transaction, and the operation phase (PHF) includes verifying whether a transaction originating from a device master and intended for an element (EL4) coupled to a first specific slave resource (PH4) is authorized to access the element, the verification including using the at least one fragment of the configuration information attached to the transaction and the information configuration fragment assigned to the first specific slave resource.
[0365] Example 29. The method of Example 28, wherein the verifying is performed downstream of the interconnect circuit (INTC).
[0366] Example 30. A method according to any one of Examples 28 to 29, wherein the verification includes local verification (RISUi), which is performed at the subordinate resources according to the information configuration fragments assigned to these subordinate resources respectively, and is performed at each element according to the information configuration fragments assigned to the corresponding first specific subordinate resource.
[0367] Example 31. The method of any one of Examples 24 to 30, wherein the set of information configuration segments includes at least one information identification segment (CID) assigned to each device master.
[0368] Example 32. A method according to Example 31, wherein for at least one slave resource, the set of information configuration fragments of the configuration diagram also includes an information inaccessibility fragment (INAC), and the information inaccessibility fragment (INAC) indicates whether the slave resource cannot be accessed by any device master.
[0369] Example 33. A method according to any one of Examples 31 to 32, wherein for each inaccessible subordinate resource, the set of information configuration fragments defining the configuration diagram also includes an information filtering fragment (IFLT), and the information filtering fragment (IFLT) indicates whether the subordinate resource can be accessed by any device master component or only by one or more device masters.
[0370] Example 34. The method of example 33, wherein for each inaccessible dependent resource, the set of information configuration fragments defining the configuration graph further comprises:
[0371] a first information access fragment (IAC1), wherein, in the case where the information filtering fragment indicates that the dependent resource can only be accessed by one or more device masters, the first information access fragment (IAC1) indicates that the dependent resource can be accessed by one or more device masters having the same information identification fragment; and
[0372] - The corresponding information identification fragment.
[0373] Example 35. The method of example 34, wherein for each inaccessible dependent resource, the set of information configuration fragments defining the configuration graph further comprises:
[0374] - A second information access fragment (IAC2), in which, when the information filtering fragment indicates that the subordinate resource can only be accessed by one or more device masters, the second information access fragment (IAC2) indicates that the subordinate resource can be accessed by device masters having different information identification fragments; and a list of information identification fragments of corresponding device masters.
[0375] Example 36. A method according to Example 35, wherein, for at least one of the slave resources that can be accessed by the device master of the list, the set of information configuration fragments defining the configuration diagram also includes a third information fragment (IAC3), and the third information fragment (IAC3) indicates that the at least one of the slave resources can only be accessed by one device master at a time, and the device master that wishes to access the slave resource uses a semaphore (SMP) during the operation phase.
[0376] Example 37. A method according to any one of Examples 31 to 36, wherein for each inaccessible slave resource, the set of information configuration fragments defining the configuration diagram also includes an information security fragment (ISEC), and the information security fragment (ISEC) indicates whether the slave resource can be accessed by a device master in a secure mode.
[0377] Example 38. A method according to any one of Examples 31 to 37, wherein for each inaccessible slave resource, the set of information configuration fragments defining the configuration diagram also includes an information privilege fragment (IPRV), and the information privilege fragment (IPRV) indicates whether the slave resource can be accessed by a device master in privileged mode.
[0378] Example 39. A method according to any one of Examples 24 to 38, wherein the slave resources include several second-specific slave resources (CH101 to CH108), the several second-specific slave resources are coupled to at least the same element (EL10) of the system on chip and can be accessed by several device masters, and the configuration stage includes selecting the device master that is authorized to access at least one same element.
[0379] Example 40. The method of Examples 31 and 39, comprising storing the information identification fragment (CID1) of the device master that is authorized to access at least one same component.
[0380] Example 41. A method according to any one of Examples 39 or 40 in combination with Example 28, wherein the verification further comprises: using at least one fragment of the configuration information attached to the transaction and the information identification fragment (CID1) of the device master that is authorized to access at least one identical component, to additionally verify that: the transaction originating from the device master and intended for at least one identical component is authorized to access the same component.
[0381] Example 42. The method of Example 41, wherein additional verification is performed locally at each identical element (EL10).
[0382] Example 43. A method according to any one of Examples 24 to 42, wherein the system on chip forms a microcontroller (MCU) or a microprocessor.
Claims
1. A system on a chip, comprising: a plurality of device masters located on the system-on-chip; a plurality of slave resources located on the system-on-chip, including a first particular slave resource coupled to at least one element of the system-on-chip, the at least one element being intended to cooperate with the first particular slave resource during operation of the system-on-chip, the at least one element being selected from a generator of at least one clock signal, a generator of at least one reset signal, a power block, or at least one configurable input / output pin of the system-on-chip; an interconnect circuit located on the system-on-chip, coupled between the plurality of device masters, the plurality of slave resources, and the at least one component, the interconnect circuit being configured to: route transactions between the plurality of device masters, the plurality of slave resources, and the at least one component; as well as The processing circuitry on the system-on-chip is configured to: allowing a user of the system-on-chip to implement at least one configuration diagram of the system within the system-on-chip, the at least one configuration diagram being defined by a collection of information configuration fragments assigned to the plurality of device masters, information configuration fragments assigned to the plurality of slave resources, and information configuration fragments assigned to the at least one component; as well as allowing a user of the system-on-chip to implement the initial configuration diagram forming the configuration diagram within the system-on-chip, wherein the processing circuit includes an installation unit, the installation unit including a first device master from the plurality of device masters, the first device master being configured to: in response to a first boot of the system-on-chip, perform a boot phase, at the end of which the first device master is configured to allow at least the initial configuration map to be implemented, and temporarily render all other device masters inoperative as long as the first device master has not completed the boot phase; wherein said set of information configuration fragments is configured to define assignment of at least one device master to at least some of said plurality of slave resources; The information configuration fragment allocated to the at least one element is the same as the information configuration fragment allocated to the first specific subordinate resource.
2. The system on chip according to claim 1, comprising: A plurality of first specific slave resources are coupled to a plurality of elements of the system on chip.
3. The system on chip according to claim 1, wherein: Each dependent resource belongs to a group formed by at least: a peripheral device, a feature of the peripheral device, a first memory internal to the system-on-chip, and a memory interface internal to the system-on-chip and intended to be coupled to a second memory external to the system-on-chip; at least one device master capable of being controlled by a microprocessor, and comprising an output port configured to issue transactions and an input port configured to receive transactions, the input port being considered a slave resource and the output port being considered a device master; The first specific slave resource belongs to the group formed by: the peripheral device, the feature of the peripheral device, and the input port of the one device master that can be controlled by the microprocessor.
4. The system on chip according to claim 1, comprising: a set of configuration registers allocated to each slave resource and each device master, said set of configuration registers allocated to a slave resource being intended to store said information configuration fragment allocated to said one slave resource; as well as A configuration controller is configured to, under the control of the first device master, update the contents of the set of configuration registers using the set of information configuration fragments.
5. The system on chip of claim 1 , wherein at least one piece of configuration information is intended to be appended to each transaction, and the processing circuitry comprises a verification module configured to verify whether a transaction originating from a device master and intended for a component coupled to a first specific slave resource is authorized to access the component by using the at least one piece of configuration information appended to the transaction and the information configuration piece assigned to the first specific slave resource. 6 . The system on chip of claim 5 , wherein the verification module is configured to perform the verification downstream of the interconnect circuit.
7. The system on chip according to claim 5, wherein the verification module comprises: a basic authentication module for each subordinate resource, configured to access said set of information configuration fragments assigned to the subordinate resource; as well as The basic verification module for each element is configured to access the information configuration fragment allocated to the corresponding first specific subordinate resource.
8. A system on chip according to claim 7, wherein each basic verification module assigned to a slave resource is connected to the set of configuration registers assigned to the one slave resource through a dedicated link, and each basic verification module assigned to an element is connected to the set of configuration registers assigned to the corresponding first specific slave resource through a dedicated link.
9. The system on chip according to claim 1, wherein the set of information configuration segments includes at least one information identification segment allocated to each device master.
10. The system on chip according to claim 9, wherein for at least one slave resource, the set of information configuration fragments of the configuration diagram further includes an information inaccessibility fragment, the information inaccessibility fragment being intended to indicate that the at least one slave resource cannot be accessed by any device master.
11. The system on chip according to claim 9, wherein for each inaccessible slave resource, the set of information configuration fragments defining the configuration diagram also includes an information filtering fragment, wherein the information filtering fragment is intended to indicate whether the slave resource can be accessed by any device master or only by one or more device masters.
12. The system on chip according to claim 9, wherein for each inaccessible slave resource, the set of information configuration fragments defining the configuration map further includes an information security fragment, the information security fragment being intended to indicate whether the slave resource can be accessed by a device master in a secure mode.
13. The system on chip according to claim 9, wherein, for each inaccessible slave resource, the set of information configuration fragments defining the configuration map further includes an information privilege fragment, the information privilege fragment being intended to indicate whether the slave resource can be accessed by a device master in privileged mode.
14. The system on chip of claim 1 , wherein the plurality of slave resources include a plurality of second-specific slave resources coupled to at least the same element of the system on chip and configured to be accessed by the plurality of device masters, and the processing circuit includes a selection module configured to select one device master that is authorized to access at least one of the same elements.
15. The system on chip according to claim 14, wherein said set of information configuration segments comprises at least one information identification segment assigned to each device master; and The selection module includes at least one selection register, and the at least one selection register is configured to store the information identification segment of the one device master that is authorized to access at least one of the same components.
16. The system on chip according to claim 15, A set of configuration registers is allocated to each slave resource and each device master, said set of configuration registers allocated to one slave resource being intended to store said information configuration fragment allocated to said one slave resource; The configuration controller is configured to: under the control of the first device master, update the contents of the set of configuration registers using the set of information configuration fragments; and Wherein the configuration controller is further configured to update the content of the at least one selection register.
17. The system on chip according to claim 15, comprising: wherein at least one fragment of configuration information is intended to be attached to each transaction, and the processing circuit comprises a verification module configured to verify, by using the at least one fragment of configuration information attached to the transaction and the information configuration fragment assigned to the first specific slave resource, whether a transaction originating from a device master and intended for a component coupled to the first specific slave resource is authorized to access the component; and The verification module is further configured to verify whether a transaction originating from a device master and intended for at least one of the same components is authorized to access the same component by using at least one fragment of the configuration information attached to the transaction and the content of the at least one selection register. 18 . The system on chip according to claim 17 , wherein, for each identical element, the authentication module comprises a basic authentication module configured to access the content of the at least one selection register.
19. The system on chip according to claim 18, wherein the basic authentication module is connected to the at least one selection register through a specific link.
20. The system on chip according to claim 1, wherein the system on chip is a microcontroller or a microprocessor.
Citation Information
Patent Citations
Microprocessor Systems
US20160283408A1
System and Method for Configuring an Information Handling System
US20190179645A1