A method for accessing memory, a system-on-chip, and an electronic device
By setting multiple areas of memory in the system-level chip and restricting access permissions, the problem of low security protection level of traditional system-level chips is solved, achieving higher memory access security and data protection effects.
Patent Information
- Application Number
- CN202010269161.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-04-08
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2040-04-08
AI Technical Summary
Traditional system-level chips have a low security protection level during data processing, and the risk of data leakage is higher.
By setting multiple areas of memory in the system-level chip and restricting access rights to each area, the interfaces and processors of the system-level chip can only access the specified areas and cannot access any area of memory at will.
Improves the security of system-level chips to memory access and reduces the risk of data leakage.
Smart Images

Figure CN113496016B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information technology, and particularly to a method for accessing memory, a system-on-a-chip, and an electronic device. Background Art
[0002] With the continuous development of technology, the application of System-on-a-Chip (SoC) is becoming more and more widespread. For example, in the development of various electronic products such as set-top boxes, mobile phones, and multimedia players, SoC chips are usually used to reduce the development cost of electronic products, shorten the development cycle, and improve the competitiveness of electronic products. With the enhancement of people's awareness of information security, the industry has put forward higher requirements for the security protection of SoC chips during the data processing process. However, the traditional method still has a relatively low level of security protection for data, and the risk of data leakage is still relatively high. Summary of the Invention
[0003] This application provides a method for accessing memory, a system-on-a-chip, and an electronic device.
[0004] In a first aspect, an embodiment of this application provides a method for accessing memory, which is applied to a system-on-a-chip and includes:
[0005] An interface of the system-on-a-chip writes service data into a first area of the memory;
[0006] A device after the interface reads the data to be processed in the corresponding area of the memory by the previous device, processes it, and then writes it into the next area of the memory until the last device reads the data to be processed in the corresponding area of the memory by the previous device, processes it, and obtains feedback data to be written into the first area;
[0007] The interface sends the feedback data;
[0008] Among them, the processor after the interface only has access rights to the first area.
[0009] In a second aspect, an embodiment of this application provides a system-on-a-chip, including: an interface, a device after the interface, and a memory connected by a bus;
[0010] The interface is used to write service data into a first area of the memory;
[0011] The device after the interface reads the data to be processed in the corresponding area of the memory by the previous device, processes it, and then writes it into the next area of the memory until the last device reads the data to be processed in the corresponding area of the memory by the previous device, processes it, and obtains feedback data to be written into the first area;
[0012] The interface sends the feedback data;
[0013] Among them, the processor after the interface only has access rights to the first area.
[0014] In a third aspect, an embodiment of the present application provides an electronic device, including the system-on-chip provided in any embodiment of the present application.
[0015] In the memory access method, system-on-chip, and electronic device provided in the embodiments of the present application, the interface of the system-on-chip writes service data into the first area of the memory. The device after the interface reads the data to be processed in the corresponding area of the memory by the previous device, processes it, and then writes it into the next area of the memory until the last device reads the data to be processed in the corresponding area of the memory by the previous device, processes it to obtain feedback data, writes the feedback data into the first area, and the interface sends the feedback data. Among them, the processor after the interface only has access rights to the first area. During the entire data processing process of the system-on-chip, access rights to each area of the memory are set, so that the interface of the system-on-chip and the device after the interface can only access the specified areas in the memory and cannot access any area of the memory at will. At the same time, the processor of the system-on-chip only has access rights to the first area of the memory and cannot access other areas of the memory except the first area. That is, the access of the interface of the system-on-chip and the device after the interface to the memory is restricted. Compared with the unrestricted memory access method, the security of memory access is improved, thereby reducing the risk of data leakage. Description of the Drawings
[0016] Figure 1 It is a schematic flowchart of a memory access method provided in an embodiment of the present application;
[0017] Figure 2 It is a schematic diagram of the memory access path provided in an embodiment of the present application;
[0018] Figure 3 It is another schematic flowchart of a memory access method provided in an embodiment of the present application;
[0019] Figure 4 It is a schematic structural diagram of a system-on-chip provided in an embodiment of the present application;
[0020] Figure 5 It is another schematic structural diagram of a system-on-chip provided in an embodiment of the present application;
[0021] Figure 6 It is yet another schematic structural diagram of a system-on-chip provided in an embodiment of the present application. Detailed Embodiments
[0022] To make the objectives, technical solutions and advantages of the present application clearer and more understandable, the embodiments of the present application will be described in detail below with reference to the accompanying drawings. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined arbitrarily with each other.
[0023] There are two types of devices involved in the system-on-chip in the embodiments of the present application: a host device and a slave device. Among them, the host device refers to a device in the system-on-chip that can actively issue read and write commands, such as a processor, a device with Direct Memory Access (DMA) built-in, etc.; the slave device refers to a device in the system-on-chip that cannot actively issue read and write commands but can only passively receive read and write commands, such as a memory (main memory), etc.
[0024] It should be noted that the execution subject of the following method embodiments may be a memory access device, and this device may be implemented as part or all of the above-mentioned system-on-chip through software, hardware, or a combination of software and hardware. The following method embodiments are described by taking the execution subject as the system-on-chip as an example.
[0025] Figure 1 FIG. is a schematic flow chart of a memory access method provided for the embodiments of the present application. As Figure 1 shown, this embodiment relates to the specific process of how each host device in the system-on-chip accesses the memory. As Figure 1 shown, the method may include:
[0026] S101. The interface of the system-on-chip writes service data into the first area of the memory.
[0027] Specifically, the interface is used to connect to the external devices of the system-on-chip, and this external device may be an input / output device. For example, the input / output device may be a data acquisition sensor, a touch screen, or a display, etc. In addition, this interface may be an I2C interface, a Mobile Industry Processor Interface (MIPI), an Ethernet interface, or other bus interfaces that can be connected to external devices. When business processing is required, the interface of the system-on-chip can receive the service data sent by the external device and write the service data into the first area of the memory through its built-in DMA module. Among them, the service data is encrypted data to be processed, such as an encrypted video stream. The above-mentioned first area supports access by all host devices of the system-on-chip, that is, the first area is a general area with unrestricted access. Other areas of the memory are access-restricted areas, that is, only the specified host device can access them, and the host devices not specified with access rights cannot access them. Among them, the access to the memory includes a read operation or a write operation on the memory.
[0028] In practical applications, in order to improve the security protection level of data by the system-on-chip, the memory of the system-on-chip can be divided into multiple regions in advance, and the size of each region as well as the start address and end address of each region can be configured according to actual storage requirements. Of course, in order to further improve the security of the system-on-chip, that is, to improve the security protection level of data by the system-on-chip, the processor can divide the memory in a trusted execution environment.
[0029] S102. The device after the interface reads the data to be processed in the corresponding region of the memory of the previous device, processes it, and writes it into the next region of the memory until the last device reads the data to be processed in the corresponding region of the memory of the previous device, processes it, and writes the obtained feedback data into the first region.
[0030] Specifically, the device after the interface mainly refers to the host device of the system-on-chip, which will participate in the process of processing service data, that is, all host devices participating in the processing of service data are devices after the interface. For example, the process of processing service data will involve operations such as encryption / decryption and encoding / decoding. In this regard, the device after the interface can include an encryption / decryption device, an encoding / decoding device, a processor, etc. Of course, if other processing processes are also involved in the process of processing service data, the device after the interface can also include devices with corresponding functions, which are not limited in this embodiment. In addition, for the processor after the interface, the system-on-chip limits that the processor only has the access right to the first region and does not have the access right to other regions in the memory, so as to prevent the software program running in the processor from accessing other regions of the memory, and further prevent data from being leaked.
[0031] In order to prevent the plaintext data from being leaked during the data processing process, the plaintext data is not allowed to be written into the first region (i.e., the ordinary region) and needs to be written into other regions of the memory. And other regions are access-restricted regions, and only specified devices are allowed to access them. For this reason, the access process of the device after the interface to the memory can be: according to the process of processing service data, the first device after the interface reads the data to be processed written into the corresponding region of the memory by the interface, processes it, and writes it into the next region of the memory, and then the next device reads the data to be processed written into the corresponding region of the memory by the first device, processes it, and writes it into the next-next region of the memory until the last device reads the data to be processed in the corresponding region of the memory of the previous device, processes it, and writes the obtained final feedback data into the first region. Among them, the feedback data is the data after the service data is processed by the system-on-chip.
[0032] In one embodiment, the devices after the interface may be a first encryption / decryption device for encryption / decryption operations and a data processing device for data processing. For this case, the process of S102 above may be: the first encryption / decryption device writes the first data obtained by decrypting the service data in the first area into the second area of the memory; the data processing device writes the second data after processing the first data into the third area of the memory; the first encryption / decryption device writes the feedback data after encrypting the second data into the first area of the memory.
[0033] Among them, the access rights of the first area, the second area, and the third area are different. The first area is an area with unrestricted access, that is, the first area is a normal area; the second area and the third area are access-restricted areas of the memory. In practical applications, the access rights of the second area and the third area can be configured according to the processing flow of service data. Optionally, the second area can be configured to only support the write operation of the first encryption / decryption device and the read operation of the data processing device, and the third area can be configured to only support the write operation of the data processing device and the read operation of the first encryption / decryption device. Among them, the first area, the second area, and the third area are not adjacent to each other. They are only used to distinguish different areas of the memory. Of course, the access rights of the first area, the second area, and the third area can also be configured according to other access methods. In this regard, during the processing of service data, the interface, the first encryption / decryption device, and the data processing device need to access the corresponding areas according to the configured area access rights. The encryption and decryption algorithms that can be implemented in the above first encryption / decryption device include international algorithm symmetric encryption (AES), asymmetric encryption (DES), public key algorithm (RSA), elliptic curve cryptography (ECC), hash algorithm (HASH), national cipher algorithm SM2 / 3 / 4, and random numbers, etc. The data processing device is used to implement data processing, such as the encoding and decoding of audio and video streams or the processing of packets, etc.
[0034] To further improve the security of the system-on-chip, in one embodiment, before the interface of the system-on-chip writes service data into the first area of the memory, the processor of the system-on-chip needs to configure the access rights of the first area, the second area, and the third area in the trusted execution environment.
[0035] Among them, when the system-on-chip is powered on and initialized, the system-on-chip can control the processor to run in the trusted execution environment, and configure the access permissions for the first area, the second area, and the third area in this environment. For example, configure the first area to support access by all host devices of the system-on-chip, the second area to support only the write operation of the first encryption / decryption device and the read operation of the data processing device, and the third area to support only the write operation of the data processing device and the read operation of the first encryption / decryption device. In this way, the configuration of the memory access permission parameters only needs to be performed once during system initialization, and there is no need for the processor to frequently switch from the normal execution environment to the trusted execution environment to configure the access permission parameters, which not only improves the security of the system-on-chip but also avoids the degradation of system performance caused by repeated switching of the execution environment.
[0036] In addition, the first encryption / decryption device is built-in with a (One Time Programmable, OTP) memory, and the key used for decryption or encryption operations by the first encryption / decryption device is stored in the OTP memory. This key is written into the OTP memory by the processor in the trusted execution environment and cannot be changed after being written. At the same time, this key can only be read by the first encryption / decryption device and can only be used inside the first encryption / decryption device, and cannot be accessed by software programs. In this regard, when the first encryption / decryption device decrypts the service data, it needs to read the key from its own internal OTP memory and use this key to decrypt the service data to obtain the first data. Correspondingly, when the first encryption / decryption device encrypts the second data, it also needs to read the key from its own internal OTP memory and use this key to encrypt the second data to obtain the feedback data.
[0037] S103. The interface sends the feedback data.
[0038] Specifically, the interface reads the processed feedback data from the first area and sends the feedback data to the external device of the system-on-chip to complete the processing process of the service data.
[0039] From the perspective of the above-mentioned entire service data processing flow of the system-on-chip, as Figure 2 shown, the data transmission paths implemented by the system-on-chip include: 1. From the interface to the first area of the memory; 2. From the first area to the first encryption / decryption device; 3. From the first encryption / decryption device to the second area of the memory; 4. From the second area of the memory to the data processing device; 5. From the data processing device to the third area of the memory; 6. From the third area of the memory to the first encryption / decryption device; 7. From the first encryption / decryption device to the first area of the memory; 8. From the first area of the memory to the interface.
[0040] For the first path, since the service data itself is encrypted, this path is a trusted path; for the second path, since the key used by the first encryption / decryption device to decrypt the service data is directly read from its internal OTP memory, and external hardware and software programs cannot access it, the security of the decryption process is ensured; for the third path, the second area is configured to only support the write operation of the first encryption / decryption device and the read operation of the data processing device, and other host devices and software programs cannot access this area, ensuring that this path is dedicated and trusted; for the fourth path, the second area is configured to only allow the data processing device to perform read operations, which also ensures that this path is dedicated and trusted, and ensures the security of the plaintext data during the processing; for the fifth path, the third area is configured to only support the write operation of the data processing device and the read operation of the first encryption / decryption device, and other host devices and software programs cannot access this area, ensuring that this path is dedicated and trusted; for the sixth path, since the key used by the first encryption / decryption device to encrypt the plaintext data is directly read from its internal OTP memory, and external hardware and software programs cannot access it, the security of the plaintext data encryption process is ensured; for the seventh path, since the feedback data obtained after encryption is itself encrypted, it can be stored in the first area; for the eighth path, the interface also reads the encrypted feedback data from the first area, so this path is a trusted path.
[0041] During the trusted processing of the entire service data, the processor only configures the access permission parameters of the first area, the second area, and the third area, and cannot participate in the trusted path, that is, the processor cannot access the plaintext data in the memory. Thus, it isolates the possibility of software programs accessing the trusted path and obtaining plaintext data, and further improves the security protection level of the system-on-chip for data.
[0042] The memory access method provided by the embodiment of the present application is that the interface of the system-on-chip writes service data into the first area of the memory. The device after the interface reads the data to be processed in the corresponding area of the memory by the previous device, processes it and writes it into the next area of the memory until the last device reads the data to be processed in the corresponding area of the memory by the previous device, processes it to obtain feedback data and writes it into the first area, and the interface sends the feedback data. Among them, the processor after the interface only has the access right to the first area. During the entire data processing process of the system-on-chip, the access rights of each area of the memory are set, so that the interface of the system-on-chip and the devices after the interface can only access the specified areas in the memory and cannot access any area in the memory at will. At the same time, the processor of the system-on-chip only has the access right to the first area of the memory and cannot access other areas in the memory except the first area. That is, the access of the interface of the system-on-chip and the devices after the interface to the memory is restricted. Compared with the unrestricted memory access method, the security of memory access is improved, thereby reducing the risk of data leakage.
[0043] In practical applications, in order to further improve the security of the system-on-chip, before accessing the restricted areas of the memory (such as the second area and the third area mentioned above), it is also possible to use a memory isolation device to determine whether the currently visiting host device has the access right to the restricted area, and only allow the host device to access after it has the access right to the restricted area. In one embodiment, as Figure 3 shown, the device after the interface in S102 reads the data to be processed in the corresponding area of the memory by the previous device, processes it and writes it into the next area of the memory may include:
[0044] S201. The device after the interface reads the data to be processed in the corresponding area of the memory by the previous device, and processes it to obtain the processed data.
[0045] S202. The memory isolation device receives the access request sent by the device after the interface, where the access request includes the identity identifier of the device after the interface and the current access type.
[0046] S203. After the memory isolation device determines that the device after the interface has the write permission for the next area of the memory according to the identity identifier, the current access type, and the currently stored access mapping relationship, the device after the interface writes the processed data into the next area, where the access mapping relationship includes the corresponding relationship between different areas of the memory and the identity identifiers of the access devices with area access rights, and the corresponding relationship between different areas and the access types of the access devices with area access rights.
[0047] Exemplarily, taking the device after the interface as the first encryption / decryption device as an example, since the first area is an ordinary area with unrestricted access, the first encryption / decryption device directly reads the data to be processed from the first area of the memory, decrypts the data to be processed using the key stored in the OTP memory to obtain decrypted data. When the first encryption / decryption device writes the decrypted data into the second area, the first encryption / decryption device sends an access request to the memory isolation device. At this time, the access request carries the identity identifier of the first encryption / decryption device and the current access type. Among them, the current access type includes a read operation or a write operation. Since the first encryption / decryption device is writing data into the second area at this time, the current access type is a write operation. After receiving the access request, the memory isolation device compares the identity identifier and the current access type with the access mapping relationship stored in itself. If the comparison is successful, it is determined that the first encryption / decryption device has the write permission for the second area and allows the first encryption / decryption device to write the decrypted data into the second area. If the comparison fails, it is determined that the first encryption / decryption device does not have the write permission for the second area and does not allow the first encryption / decryption device to write the decrypted data into the second area. Among them, the above access mapping relationship can be pre-configured in the memory isolation device, or when the system-on-chip is initialized, the processor can configure this access mapping relationship into the memory isolation device in the trusted execution environment.
[0048] Of course, when the device after the interface reads the data to be processed in the corresponding area of the memory of the previous device, the memory isolation device will also receive the read request sent by the device after the interface. This read request carries the identity identifier of the device after the interface and the current access type (read operation). After the memory isolation device determines that the device after the interface has the read permission for the corresponding area of the memory according to the identity identifier, the current access type, and the currently stored access mapping relationship, the device after the interface reads the data to be processed from the corresponding area of the memory. If it is determined that the device after the interface does not have the read permission for the corresponding area of the memory, it is not allowed to read the data to be processed from the corresponding area of the memory.
[0049] Of particular concern is that when the device after the interface is a processor, the processor will also issue an access request to the memory. At this time, since the processor does not have the access permission for other areas of the memory, when the processor issues an access request to the second area or the third area of the memory, after the memory isolation device compares the identity identifier of the processor and the current access type with the access mapping relationship stored in itself, it is determined that the processor does not have the access permission for the second area and the third area. At this time, the memory isolation device will reject the processor's access to the second area and the third area of the memory.
[0050] In this embodiment, when the device after the interface accesses the restricted area in the memory, the memory isolation device can be used to determine whether it has the access right to the restricted area. Only after having the access right to the restricted area is the device after the interface allowed to access, thereby further improving the security of the system-on-chip and further reducing the risk of data leakage.
[0051] In practical applications, the services that need to be processed by the system-on-chip may include services with memory protection requirements and services without memory protection requirements. Among them, the services with memory protection requirements refer to the services with limited memory access during the service processing, and the services without memory protection requirements refer to the services with unlimited memory access during the service processing. For example, the processing of paid videos can be considered as a service with memory protection requirements, and the processing of free videos can be considered as a service without memory protection requirements. When the service to which the service data received by the interface belongs is a service without memory protection requirements, in order to improve the processing performance of the system-on-chip, the data encryption and decryption processing can be performed by calling the second encryption and decryption device. And the above-mentioned first encryption and decryption device is dedicated to processing services with memory protection requirements, that is, the system-on-chip provides independent computing resources for different services. In view of this situation, the method may further include: the second encryption and decryption device obtains the key from the first encryption and decryption device, and writes the third data obtained after decrypting the service data with the key into the first area of the memory.
[0052] Among them, for the services without memory protection requirements, during the entire data processing process, the interface, the second encryption and decryption device, and the data processing device of the system-on-chip all access the first area of the memory, that is, the second encryption and decryption device reads the service data without memory protection requirements from the first area of the memory and obtains the key from the first encryption and decryption device (the key is directly read from the OTP memory by the first encryption and decryption device and passed to the second encryption and decryption device, or a new key is derived after the first encryption and decryption device directly reads from the OTP memory and passed to the second encryption and decryption device), decrypts the service data with the key to obtain the third data, and writes the third data into the first area of the memory. Correspondingly, when encrypting with the second encryption and decryption device, the second encryption and decryption device also needs to obtain the key from the first encryption and decryption device and encrypt the data to be processed with the key and then write it into the first area of the memory. At the same time, the key is only used inside the second encryption and decryption device and cannot be accessed by the software program, which also improves the security of the system-on-chip. In addition, the second encryption and decryption device is built with DMA, so that the second encryption and decryption device can directly read the service data to be processed from the first area of the memory for processing, without the need for the processor to move the data, avoiding the frequent switching of the trusted execution environment by the processor and reducing the risk of data leakage during the switching process.
[0053] In addition, the second encryption / decryption device in this embodiment can only access the ordinary area (i.e., the first area) of the memory and cannot access the restricted areas (i.e., the second area and the third area) of the memory. The above-mentioned first encryption / decryption device can not only access the ordinary area of the memory but also access the restricted areas of the memory. That is, during the access process of the memory by the first encryption / decryption device, the security protection level of the data can be improved.
[0054] In this embodiment, when the service to which the service data received by the interface belongs is a service without memory protection requirements, the system-on-chip can also perform encryption / decryption operations through the second encryption / decryption device, and the first encryption / decryption device is dedicated to the encryption / decryption operations of services with memory protection requirements. That is, it is equivalent that the system-on-chip provides independent computing resources for different services, thereby improving the system performance of the system-on-chip.
[0055] Figure 4 It is a schematic structural diagram of a system-on-chip provided by an embodiment of the present application. As Figure 4 shown, the system-on-chip includes: an interface 10 connected by a bus, a device 11 after the interface, and a memory 12;
[0056] Among them, the interface 10 is used to write service data into the first area of the memory 12;
[0057] The device 11 after the interface reads the data to be processed in the corresponding area of the memory by the previous device, processes it and writes it into the next area of the memory 12 until the last device reads the data to be processed in the corresponding area of the memory by the previous device, processes it to obtain feedback data and writes it into the first area;
[0058] The interface 10 sends the feedback data;
[0059] Among them, the processor 13 after the interface only has the access right to the first area.
[0060] The system-on-chip provided by the embodiments of the present application. The interface of the system-on-chip writes service data into the first area of the memory. The device after the interface reads the data to be processed in the corresponding area of the memory by the previous device, processes it, and then writes it into the next area of the memory until the last device reads the data to be processed in the corresponding area of the memory by the previous device, processes it to obtain feedback data, writes the feedback data into the first area, and the interface sends the feedback data. Among them, the processor after the interface only has the access right to the first area. During the entire data processing process of the system-on-chip, the access rights of each area of the memory are set, so that the interface of the system-on-chip and the devices after the interface can only access the specified areas in the memory and cannot access any area of the memory at will. At the same time, the processor of the system-on-chip only has the access right to the first area of the memory and cannot access other areas of the memory except the first area. That is, the access of the interface of the system-on-chip and the devices after the interface to the memory is restricted. Compared with the unrestricted memory access method, the security of memory access is improved, thereby reducing the risk of data leakage.
[0061] In one embodiment, as Figure 5 shown, the device after the interface further includes a first encryption / decryption device 11 and a data processing device 14;
[0062] The first encryption / decryption device 11 writes the first data obtained by decrypting the service data in the first area into the second area of the memory 12;
[0063] The data processing device 14 writes the second data obtained by processing the first data into the third area of the memory 12;
[0064] The first encryption / decryption device 11 writes the feedback data obtained by encrypting the second data into the first area of the memory 12.
[0065] In one embodiment, the first area supports the access of all host devices of the system-on-chip, the second area only supports the write operation of the first encryption / decryption device 11 and the read operation of the data processing device 14, and the third area only supports the write operation of the data processing device 14 and the read operation of the first encryption / decryption device 11.
[0066] In one embodiment, the processor 13 configures the access rights of the first area, the second area, and the third area in a trusted execution environment.
[0067] In one embodiment, the first encryption / decryption device 11 stores the keys used for decryption or encryption.
[0068] In one embodiment, the system-on-chip further includes: a memory isolation device 15 connected by a bus;
[0069] The device after the interface reads the data to be processed in the corresponding area of the memory of the previous device, and obtains the processed data after processing;
[0070] The memory isolation device 15 receives the access request sent by the device after the interface, where the access request includes the identity identifier of the device after the interface and the current access type;
[0071] After the memory isolation device 15 determines that the device after the interface has the write permission for the next area of the memory according to the identity identifier, the current access type, and the currently stored access mapping relationship, the device after the interface writes the processed data into the next area, where the access mapping relationship includes the correspondence between different areas of the memory and the identity identifiers of the access devices with area access permissions, and the correspondence between different areas and the access types of the access devices with area access permissions.
[0072] In one embodiment, during the initialization of the system-on-chip, the processor 13 configures the access mapping relationship into the memory isolation device 15 in the trusted execution environment.
[0073] In one embodiment, the system-on-chip further includes: a second encryption and decryption device 16 connected by a bus, and the service to which the service data belongs includes a service with memory protection requirements or a service without memory protection requirements;
[0074] When the service to which the service data belongs is a service without memory protection requirements, the second encryption and decryption device 16 obtains the key from the first encryption and decryption device 11, and writes the third data obtained by decrypting the service data with the key into the first area of the memory 12.
[0075] In one embodiment, DMA is provided in each of the first encryption and decryption device 11, the data processing device 14, and the second encryption and decryption device 16.
[0076] In practical applications, the first encryption and decryption device, the data processing device, the memory isolation device, and the second encryption and decryption device in the above system-on-chip can all be implemented by an application-specific integrated circuit (ASIC) or a field-programmable gate array (FPGA).
[0077] For the convenience of understanding by those skilled in the art, taking Figure 6 as an example, the system-on-chip described in the embodiments of the present application is specifically introduced. Refer to Figure 6, the system-on-chip may include an interface 20, a data processing device 21, a processor 22, a memory isolation device 23, a memory 24, a second encryption / decryption device 25 (i.e., a general encryption / decryption device for processing services without memory protection requirements), and a first encryption / decryption device 26 (i.e., a trusted encryption / decryption device for processing services with memory protection requirements), which are connected by a bus. Among them, the second encryption / decryption device 25 may include a second encryption / decryption unit 251 and a second DMA 252, and the first encryption / decryption device 26 may include a first encryption / decryption unit 261, a first DMA 262, and an OTP 263.
[0078] Among them, the interface 20 is used to receive encrypted data outside the system-on-chip, such as encrypted audio and video streams, store them in the ordinary area (i.e., the first area) of the memory, and send the processed data to the outside of the system-on-chip.
[0079] The data processing device 21 is used to implement data processing, such as the encoding and decoding of audio and video streams or the processing of packets.
[0080] The processor 22 is used to run the software program of the system-on-chip and can support a trusted execution environment TEE and a normal execution environment REE.
[0081] The memory isolation device 23 is used to divide the memory 24 into an ordinary area (i.e., the first area) and a restricted area (i.e., the second area and the third area). The ordinary area can be read and written by any access, including ordinary access and trusted access. The restricted area can only be read and written by specified trusted access and rejects ordinary access.
[0082] The memory 24 is used to store data in real time when the system-on-chip is running.
[0083] The bus is used to connect each host device and slave device of the system-on-chip to realize the transmission of data and control signals.
[0084] The above OTP 263 stores information such as keys required by the second encryption / decryption unit or the first encryption / decryption unit, and realizes the storage and management of sensitive information such as keys on the internal hardware of the first encryption / decryption device to ensure a higher level of security. The OTP 263 can only be read and written by the first encryption / decryption unit, and the key is only written into the OTP 263 in the trusted execution environment and cannot be changed after being written. The information such as keys required by the first encryption / decryption unit is directly read from the OTP by the first encryption / decryption unit and can only be used inside the first encryption / decryption unit and cannot be accessed by software. The information such as keys required by the second encryption / decryption unit is read from or derived from the OTP by the first encryption / decryption unit and then passed to the second encryption / decryption unit, and can only be used inside the second encryption / decryption unit and cannot be accessed by software.
[0085] The trusted path in the data processing process of the system-on-chip is as follows:
[0086] 1. From the interface to the general area of the memory: The interface of the system-on-chip receives encrypted data from the outside, such as encrypted audio and video, message data, etc., and stores it in the general area of the memory (i.e., the first area). All host devices can access the general area. Since the data itself is encrypted, it can be stored in the general area.
[0087] 2. From the general area of the memory to the first encryption / decryption device: The first DMA in the first encryption / decryption device reads the encrypted service data from the general area of the memory, sends it to the internal first encryption / decryption unit for decryption processing to obtain plaintext data. The decryption key is directly read from the internal OTP, and external hardware and software programs cannot access it. The decryption process is completed inside the first encryption / decryption device, ensuring security.
[0088] 3. From the first encryption / decryption device to the restricted area 1 of the memory (i.e., the second area): The first DMA writes the plaintext data into the restricted area 1 of the memory. The memory isolation device restricts the restricted area 1 of the memory to be writable only by the first DMA and readable only by the data processing device, and other host devices and software programs cannot access this area. In this way, it is ensured that this path is dedicated and trusted.
[0089] 4. From the restricted area 1 of the memory to the data processing device: The data processing device reads the plaintext data from the restricted area 1 of the memory and performs data processing such as encoding / decoding and message packet processing. Only the data processing device can read the restricted area 1, ensuring the security of the plaintext data.
[0090] 5. From the data processing device to the restricted area 2 of the memory (i.e., the third area): The data processing device writes the processed data into the restricted area 2 of the memory. The memory isolation device restricts the restricted area 2 of the memory to be writable only by the data processing device and readable only by the first DMA, and other host devices and software programs cannot access this area. In this way, it is ensured that this path is dedicated and trusted.
[0091] 6. From the restricted area 2 of the memory to the first encryption / decryption device: The first DMA of the first encryption / decryption device reads the plaintext data from the restricted area 2 of the memory, sends it to the internal first encryption / decryption unit for encryption processing to obtain the encrypted feedback data. The encryption key is directly read from the OTP, and external hardware and software programs cannot access it. The encryption process is completed inside the trusted part, ensuring security.
[0092] 7. From the first encryption / decryption device to the general area of the memory: The first DMA writes the encrypted feedback data into the general area of the memory. Since the data itself is encrypted, it can be stored in the general area.
[0093] 8. From the general area of the memory to the interface: The interface reads the encrypted feedback data from the general area of the memory and sends it to the device outside the system-on-chip.
[0094] In one embodiment, an electronic device is further provided, and the electronic device includes the system-on-chip described in any of the above embodiments.
[0095] Among them, the electronic device can be, for example, a set-top box with audio and video processing functions, a high-density digital video disc (DVD), a mobile phone, etc.
[0096] As described above, it is only an exemplary embodiment of the present application and is not used to limit the protection scope of the present application.
[0097] Those skilled in the art should understand that the term user terminal covers any suitable type of wireless user equipment, such as a mobile phone, a portable data processing device, a portable network browser, or a vehicle-mounted mobile station.
[0098] Generally speaking, various embodiments of the present application can be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. For example, some aspects can be implemented in hardware, while other aspects can be implemented in firmware or software that can be executed by a controller, a microprocessor, or other computing devices, although the present application is not limited thereto.
[0099] The embodiments of the present application can be implemented by a data processor of a mobile device executing computer program instructions, for example, in a processor entity, or by hardware, or by a combination of software and hardware. The computer program instructions can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages.
[0100] Any block diagram of a logical process in the drawings of the present application can represent program steps, or can represent interconnected logical circuits, modules, and functions, or can represent a combination of program steps and logical circuits, modules, and functions. The computer program can be stored in a memory. The memory can have any type suitable for the local technical environment and can be implemented using any suitable data storage technology, such as but not limited to read-only memory (ROM), random access memory (RAM), optical memory devices and systems (digital versatile disc DVD or CD disc), etc. The computer-readable medium can include a non-transitory storage medium. The data processor can be any type suitable for the local technical environment, such as but not limited to a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), and a processor based on a multi-core processor architecture.
[0101] By way of example and not limitation, detailed descriptions of exemplary embodiments of the present application have been provided above. However, upon consideration of the accompanying drawings and the claims, various modifications and adaptations of the above embodiments will be apparent to those skilled in the art without departing from the scope of the invention. Accordingly, the proper scope of the invention will be determined in accordance with the claims.
Claims
1. A method for accessing memory, characterized in that, applied to a system-on-chip, including: The interface of the system-on-chip writes service data into the first area of the memory; The first encryption / decryption device writes the first data obtained by decrypting the service data in the first area into the second area of the memory; The data processing device writes the second data after processing the first data into the third area of the memory; The first encryption / decryption device writes the feedback data after encrypting the second data into the first area of the memory; The interface sends the feedback data; Wherein, the processor after the interface only has the access right to the first area, the first area supports the access of all host devices of the system-on-chip, the second area only supports the write operation of the first encryption / decryption device and the read operation of the data processing device, and the third area only supports the write operation of the data processing device and the read operation of the first encryption / decryption device.
2. The method according to claim 1, characterized in that, Before the interface of the system-on-chip writes service data into the first area of the memory, it further includes: The processor configures the access rights of the first area, the second area and the third area in a trusted execution environment.
3. The method according to claim 1, characterized in that, The first encryption / decryption device stores the key used for decryption or encryption.
4. The method according to any one of claims 1-3, characterized in that, The device after the interface reads the data to be processed in the corresponding area of the memory by the previous device, and writes it into the next area of the memory after processing, including: The device after the interface reads the data to be processed in the corresponding area of the memory by the previous device, and obtains the processed data after processing; The memory isolation device receives the access request sent by the device after the interface, wherein the access request includes the identity identifier of the device after the interface and the current access type; After the memory isolation device determines that the device after the interface has the write permission for the next area of the memory according to the identity identifier, the current access type and the currently stored access mapping relationship, the device after the interface writes the processed data into the next area, wherein the access mapping relationship includes the correspondence between different areas of the memory and the identity identifiers of the access devices with area access rights, and the correspondence between different areas and the access types of the access devices with area access rights.
5. The method according to claim 4, characterized in that, It further includes: During the initialization of the system-on-chip, the processor configures the access mapping relationship into the memory isolation device in a trusted execution environment.
6. The method according to claim 3, characterized in that, The service to which the service data belongs includes a service with memory protection requirements or a service without memory protection requirements. When the service to which the service data belongs is a service without memory protection requirements, the method further includes: The second encryption / decryption device obtains the key from the first encryption / decryption device, and writes the third data obtained by decrypting the service data using the key into the first area of the memory.
7. A system-on-chip, characterized in that, including: An interface connected via a bus, a first encryption / decryption device, a data processing device, a processor, and a memory; The interface is used to write service data into a first area of the memory; The first encryption / decryption device writes first data obtained by decrypting the service data in the first area into a second area of the memory; The data processing device writes second data obtained by processing the first data into a third area of the memory; The first encryption / decryption device writes feedback data obtained by encrypting the second data into the first area of the memory; the interface sends the feedback data; Wherein, the processor only has access rights to the first area, the first area supports access by all host devices of the system-on-chip, the second area only supports write operations by the first encryption / decryption device and read operations by the data processing device, and the third area only supports write operations by the data processing device and read operations by the first encryption / decryption device.
8. The system-on-chip according to claim 7, characterized in that, The processor configures the access rights of the first area, the second area, and the third area in a trusted execution environment.
9. The system-on-chip according to claim 7, characterized in that, The first encryption / decryption device stores the keys used during decryption or encryption.
10. The system-on-chip according to any one of claims 7-9, characterized in that, further comprising: A memory isolation device connected via a bus; The device after the interface reads the data to be processed in the corresponding area of the memory by the previous device, and obtains the processed data after processing; The memory isolation device receives an access request sent by the device after the interface, wherein the access request includes the identity identifier of the device after the interface and the current access type; After the memory isolation device determines that the device after the interface has the write permission for the next area of the memory according to the identity identifier, the current access type, and the currently stored access mapping relationship, the device after the interface writes the processed data into the next area, wherein the access mapping relationship includes the correspondence between different areas of the memory and the identity identifiers of the access devices having area access rights, and the correspondence between different areas and the access types of the access devices having area access rights.
11. The system-on-chip according to claim 10, characterized in that, During the initialization of the system-on-chip, the processor configures the access mapping relationship into the memory isolation device in a trusted execution environment.
12. The system-on-chip according to claim 9, characterized in that, further comprising: A second encryption / decryption device connected via a bus, where the service to which the service data belongs includes a service with memory protection requirements or a service without memory protection requirements; When the service to which the service data belongs is a service without memory protection requirements, the second encryption / decryption device obtains the key from the first encryption / decryption device, and writes third data obtained by decrypting the service data using the key into the first area of the memory.
13. The system-on-chip according to claim 12, characterized in that, Direct Memory Access (DMA) is provided in the first encryption / decryption device, the data processing device, and the second encryption / decryption device.
14. An electronic device, characterized in that, it includes a system-on-chip as described in any one of claims 7-13.
Citation Information
Patent Citations
Image processing apparatus and control method thereof
CN105245949A
Script processing method and script processing computer
JP2005202845A