Processing device, embedded system, system on chip, and security control method
By setting up multiple security zones in the processing device and configuring secure channels, the problem of low data transmission efficiency between different trusted execution environments is solved, efficient, low power consumption and secure data transmission is achieved, and equipment performance and user experience are improved.
Patent Information
- Application Number
- CN202010348113.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-04-28
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2040-07-22
AI Technical Summary
In electronic devices, data transmission efficiency between different trusted execution environments is low, limiting the performance and response speed of the device.
By setting multiple security areas in the processing device and configuring a secure channel using a storage access controller, data transmission between different security areas is achieved, and processor redirection is avoided.
It improves data transmission efficiency between different trusted execution environments, reduces power consumption, enhances security, and improves device performance and user experience.
Smart Images

Figure CN113569245B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of processors, and more particularly, to a processing device, an embedded system, a system on a chip, and a security control method. Background Art
[0002] With the continuous development of intelligent terminal technology, various application programs (Apps) have brought convenience to users. Subsequently, users' attention has turned to the security of these application programs. For application programs involving some sensitive information (such as identity information, property information, etc., information that users do not want others to obtain), users expect that this sensitive information can be effectively protected.
[0003] Multiple mutually isolated trusted execution environments (TEEs) can be established in an electronic device to provide an execution environment with security protection functions for application programs that need to be protected, enabling different application programs to run in different trusted execution environments.
[0004] In some scenarios, an application program running in a certain TEE needs to transmit information to another TEE, and the transmission efficiency will limit the performance of the electronic device. For example, the first application program running in the first TEE is used to collect sensor data in real time, and the second application program running in the second TEE is used to process the sensor data (such as encoding, encryption). Therefore, after the first application program obtains the sensor data, it needs to continuously provide the sensor data stored in the first TEE to the second TEE. Thus, the data transmission efficiency from the first TEE to the second TEE will limit key performances such as the response speed and data processing ability of the electronic device.
[0005] Therefore, it is desirable to improve the data transmission efficiency between different TEEs while ensuring data security. Summary of the Invention
[0006] In view of this, embodiments of the present disclosure provide a processing device, an embedded system, a system on a chip, and a security control method to solve the above problems.
[0007] To achieve this purpose, in a first aspect, the present disclosure provides a processing device, including: a processor adapted to run a program; a memory coupled to the processor and adapted to provide multiple mutually isolated security areas, one of the multiple security areas being a source security area, and another of the multiple security areas being a target security area, where the source security area and the target security area are respectively used to provide storage spaces required for the operation of corresponding programs. Wherein, the processing device further includes a storage access controller adapted to transmit specified data stored in the source security area to the target security area.
[0008] In some embodiments, the plurality of security zones further includes a runtime security zone different from the source security zone and the target security zone. The runtime security zone is adapted to provide a storage space required for the operation of the control program. The storage access controller is uniquely configured by the control program to transfer specified data stored in the source security zone to the target security zone.
[0009] In some embodiments, the source security zone is adapted to generate a transfer request and send the transfer request to the runtime security zone, so that the control program configures the storage access controller to transfer specified data stored in the source security zone to the target security zone based on the transfer request.
[0010] In some embodiments, the transfer request includes source address information; and before the control program configures the storage access controller to transfer specified data stored in the source security zone to the target security zone, the control program checks whether the source address information points within the source security zone that issued the transfer request. If so, the storage access controller is allowed to transfer the specified data stored in the source security zone to the target security zone.
[0011] In some embodiments, before the control program configures the storage access controller to transfer specified data stored in the source security zone to the target security zone, the control program checks whether the source security zone that issued the transfer request has its transfer function disabled. If not, the storage access controller is allowed to transfer the specified data stored in the source security zone to the target security zone.
[0012] In some embodiments, the transfer request includes data volume information to be transferred. Wherein, before the storage access controller transfers specified data stored in the source security zone to the target security zone, the control program sends an allocation request to the target security zone. The allocation request includes the data volume information, so that the target security zone determines whether the size of the allocable storage space in the target security zone is greater than or equal to the data volume information indicated by the allocation request. If so, a transfer confirmation response is sent to the storage access controller, so that the storage access controller transfers the specified data stored in the source security zone to the target security zone.
[0013] In some embodiments, the transfer confirmation response includes allocation address information that points to a target storage area in the target security zone that is allowed to receive the specified data. The control program provides the allocation address information to the storage access controller, so that the storage access controller transfers the specified data stored in the source security zone to the target storage area in the target security zone.
[0014] In some embodiments, the storage access controller includes: a source address register adapted to store the source address information; a destination address register adapted to store destination address information that points to the destination security area or a specified storage area within the destination security area for receiving the specified data; and a control module adapted to select one of a plurality of channels provided by the storage access controller as a secure channel for transmitting the specified data stored in the source security area to the destination security area.
[0015] In some embodiments, the storage access controller further includes: a status register adapted to provide a status value for each of the channels, the status value being used to indicate whether the corresponding channel is in an available state, so that the control module can select the channel in the available state as the secure channel based on the status value.
[0016] In a second aspect, the present disclosure provides an embedded system including a processing device according to any embodiment of the present disclosure. During the data transmission process between security areas, the embedded system provided by the present disclosure does not need to transfer the specified data to be transmitted via a processor, and can achieve efficient and low-power data transmission on the premise of ensuring data security. Therefore, it has broad application prospects in the low-power, high-security, and high-efficiency embedded field (such as the Internet of Things field).
[0017] In a third aspect, the present disclosure provides a system-on-chip including a processing device according to any embodiment of the present disclosure. Among them, the memory, processor, and storage access controller within the processing device can be coupled and communicate via a system-on-chip bus within the system-on-chip.
[0018] In a fourth aspect, the present disclosure provides a security control method, including: configuring a plurality of mutually isolated security areas in a memory, one of the plurality of security areas being a source security area, and another of the plurality of security areas being a destination security area, the source security area and the destination security area being respectively used to provide storage spaces required for the operation of corresponding programs; configuring a secure channel; and transmitting the specified data stored in the source security area to the destination security area via the secure channel.
[0019] In some embodiments, the plurality of security areas further includes a runtime security area different from the source security area and the destination security area, and the security control method further includes: running a control program in the runtime security area, the control program uniquely configuring the secure channel so that the secure channel can transmit the specified data stored in the source security area to the destination security area.
[0020] In some embodiments, the control program receives a transmission request sent by the source security zone and configures the security channel based on the transmission request, so that the security channel transmits specified data stored in the source security zone to the target security zone.
[0021] In some embodiments, the transmission request includes source address information; and before the control program configures the security channel, the control program checks whether the source address information is within the source security zone that sends the transmission request. If so, it allows the specified data stored in the source security zone to be transmitted to the target security zone.
[0022] In some embodiments, before the control program configures the security channel, the control program checks whether the source security zone that sends the transmission request has its transmission function disabled. If it is not disabled, it allows the specified data stored in the source security zone to be transmitted to the target security zone.
[0023] In some embodiments, the transmission request includes data volume information to be transmitted. Wherein, before transmitting the specified data stored in the source security zone to the target security zone, the control program sends an allocation request to the target security zone, and the allocation request includes the data volume information, so that the target security zone determines whether the size of the allocable storage space in the target security zone is greater than or equal to the data volume information indicated by the allocation request. If so, it sends a transmission confirmation response, so that the security channel transmits the specified data stored in the source security zone to the target security zone.
[0024] In some embodiments, the transmission confirmation response includes allocation address information, and the allocation address information points to a target storage area in the target security zone that allows the specified data to be received. The control program configures the security channel based on the allocation address information, so that the security channel transmits the specified data stored in the source security zone to the target storage area in the target security zone.
[0025] In some embodiments, the step of configuring the security channel includes: selecting one of multiple channels as the security channel based on the source address information and the target address information, so that the security channel transmits the specified data stored in the source security zone to the target security zone pointed to by the target address information or the specified storage area in the target security zone for receiving the specified data.
[0026] Compared with traditional solutions, the processing device, embedded system, system on chip, and security control method provided by the embodiments of the present disclosure can establish a TEE based on multiple security zones. Different programs can run independently in different security zones, and the storage access controller can be configured to transfer specified data stored in the source security zone among multiple security zones to the target security zone, so that there is no need to transfer the specified data to be transmitted via the processor. Since the transmission mechanism provided by the present disclosure does not require the processor to transfer data, compared with the prior art, the embodiments of the present disclosure can improve the communication efficiency between security zones, thereby being able to speed up the response speed of the programs running in the security zones, reduce power consumption, and provide strong support for the performance improvement of electronic devices such as processing devices, embedded systems, and systems on chip and the improvement of user experience.
[0027] In some embodiments, the runtime security zone among multiple security zones provides a trusted execution environment for running the DMA control program, thereby further ensuring that the data transmission process between the source security zone and the target security zone can be carried out with high efficiency on the premise of ensuring data security.
[0028] In some embodiments, the control program running in the runtime security zone can control the data transmission between the source security zone and the target security zone based on various preset control rules, so as to achieve flexible control and optimization of data transmission. For example, the control rules of the control program running in the runtime security zone can determine whether the data transmission direction is legal, so as to prevent sensitive information in a certain security zone from leaking to other security zones by mistake.
[0029] In some embodiments, the control program running in the runtime security zone can initiate an allocation request to the target security zone that needs to be written based on the transmission request to confirm whether the target security zone has enough storage space to receive the specified data to be transmitted, so as to prevent the valid data in the target security zone from being overwritten. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Through the description of the embodiments of the present disclosure with reference to the following drawings, the above and other objects, features, and advantages of the present disclosure will become clearer. In the drawings:
[0031] Figure 1 A schematic block diagram of an electronic device showing an embodiment of the present disclosure;
[0032] Figure 2 An exemplary application scenario schematic diagram of an electronic device showing an embodiment of the present disclosure;
[0033] Figure 3 A schematic block diagram showing the processing device 1100 of an embodiment of the present disclosure;
[0034] Figure 4It is a system architecture diagram of the embedded system 4000 applied in an embodiment of the present disclosure;
[0035] Figure 5 It is a structural diagram of the embedded processor 401 in an embodiment of the present disclosure;
[0036] Figure 6 It shows a schematic diagram of the software architecture of the processing device in an embodiment of the present disclosure;
[0037] Figure 7 It shows another schematic block diagram of the processing device in an embodiment of the present disclosure;
[0038] Figure 8 It shows a schematic block diagram of the storage access controller in an embodiment of the present disclosure;
[0039] Figure 9 It shows a schematic flow diagram of the security control method in an embodiment of the present disclosure;
[0040] Figure 10 It shows another schematic diagram of an exemplary application scenario in an embodiment of the present disclosure. Detailed implementation manners
[0041] The following describes the present disclosure based on embodiments, but the present disclosure is not limited to these embodiments. In the following detailed description of the present disclosure, some specific details are described in detail. Those skilled in the art can fully understand the present disclosure without the description of these details. In order to avoid obscuring the essence of the present disclosure, well-known methods, processes, and procedures are not described in detail. Additionally, the drawings are not necessarily drawn to scale.
[0042] The following terms are used herein.
[0043] Microcontroller: Microcontroller Unit, abbreviated as MCU, usually refers to a system-on-chip or system-on-a-chip (abbreviated as SoC) based on a processor, memory, and other hardware modules. A microcontroller can run an operating system (abbreviated as OS) and application programs. In the fields of the Internet of Things, artificial intelligence, and some other fields, microcontrollers are widely used due to their significant advantages such as high integration and customization.
[0044] Memory: It can be integrated into the processing device and is a physical structure for storing information. The information stored in the memory includes instruction information and / or data information represented by data signals, such as data provided by the processor, code of application programs, etc., and can also be used to realize the information exchange between the processor and storage devices outside the processing device.
[0045] Application: Mainly used to perform set tasks according to user operations, and can be understood as software composed of one or more computer programs. An application includes code and data, where the code of the application corresponds to a series of instructions that can be executed by a processor. Applications can include, for example, payment applications for implementing property transactions, service applications for providing corresponding services based on the user's personal information, game applications, media applications, and drivers for driving hardware resources, etc. Among them, the data and code included in applications such as payment applications and service applications that involve user privacy information need to be protected to prevent malicious software from stealing the user's privacy information / sensitive information.
[0046] Read and write permissions: A general term for read permission and write permission; if a specified program has read permission for a target storage area, it means that the information (code and / or data) in the target storage area can be read, so that the information in the target storage area can be loaded into the storage area used to run the specified program; if a specified program has write permission for a target storage area, it means that the specified program can modify the information in the target storage area.
[0047] Execution permission: If a specified program has execution permission for a target storage area, it means that the specified program is allowed to execute or call the code stored in the target storage area, but the execution permission does not mean that the specified program is allowed to view or read the code stored in the target storage area.
[0048] DMA (Direct Memory Access), that is, direct memory access or direct memory access, is a technology for quickly transferring data, suitable for implementing data transfer between different storage areas (such as different storage areas within a memory and / or different storage areas between a memory and other storage devices). The advantage of the DMA technology is that the data transfer path can bypass the processor, that is, the data to be transferred does not need to be input into the processor and then transferred to the target storage area by the processor, but is directly written into the target storage area. The data transfer process based on the DMA technology can be called a DMA transfer, and the DMA transfer process is mainly implemented by a DMA controller.
[0049] The embodiments of the present application can be applied to fields such as the Internet and the Internet of Things (IoT for short), such as 5G mobile Internet systems, security identification systems, etc., and can establish a trusted execution environment for protecting sensitive information within a processing device, and use the DMA technology to implement data transfer between different trusted execution environments. However, it should be understood that the application scenarios of the embodiments of the present disclosure are not limited to this, and can also be applied to any scenario where sensitive information needs to be protected within a processing device.
[0050] System Overview
[0051] Figure 1 Schematic block diagram showing an electronic device according to an embodiment of the present disclosure. Figure 2 Schematic diagram of an exemplary application scenario of the electronic device according to an embodiment of the present disclosure. As described above, Figure 2 The shown application scenario is only an illustrative example and is not used to limit the actual application scenario of the electronic device according to the embodiment of the present disclosure.
[0052] Figure 1 The electronic device 1000 shown therein is intended to show at least some components of one or more electronic devices. In other embodiments of the present disclosure, some components shown therein may be omitted Figure 1 Some components shown therein, or the connections between components may be implemented in a different architecture, and may also include Figure 1 Some hardware and / or software modules not shown therein, Figure 1 Two or more components shown therein may also be synthesized into one component in a software system and / or a hardware system.
[0053] In some embodiments, the electronic device 1000 may be a mobile device, a handheld device or an embedded device, such as in a processing platform of a smart car, smart home appliances, a biometric identification system, a bank management system, an Internet of Things device that adopts 5G technology.
[0054] Such as Figure 1 and 2 As shown, the electronic device 1000 may include one or more processing devices 1100. In some embodiments, the processing device 1100 in the electronic device 1000 can be flexibly designed in terms of architecture and function. For example, in scenarios where low power consumption and dedicated functions need to be achieved, the electronic device 1000 according to the embodiment of the present disclosure can be more streamlined and have lower power consumption compared to large computer devices such as personal computers and server terminals, and thus is suitable for various Internet of Things devices, embedded devices, smart terminal devices, etc.
[0055] One or more processing devices 1100 in the electronic device 1000 may be respectively independently packaged chips (such as a microcontroller), or may be implemented by a hardware structure and / or software integrated in a system-on-chip, or may also be implemented by multiple hardware structures and / or software disposed on a printed circuit board (PCB). The processing device 1100 may include a central processing unit, a graphics processing unit, a physical processing unit, etc.
[0056] In some embodiments, the electronic device 1000 may further include one or more coprocessors for executing instructions and data that do not involve sensitive information.
[0057] Such asFigure 1 As shown, the electronic device 1000 further includes a system bus 1200, and the processing device 1100 can be coupled to one or more system buses 1200. The system bus 1200 can be used to transmit signals between the processing device 1100 and other components in the electronic device 1000, such as transmitting address, data, or control signals, etc. The system bus 1200 can include but is not limited to: a bus based on the Peripheral Component Interconnect (PCI) standard, a memory bus, or other types of buses.
[0058] Generally, as Figure 1 shown, the electronic device 1000 may further include one or more storage devices 1300 that communicate with the processing device 1100 via the system bus 1200. The storage device 1300 is used to provide additional storage space for the electronic device, such as for storing data and / or instructions other than sensitive information.
[0059] The electronic device 1000 can also be coupled to the input / output device 1400 via the system bus 1200. In some embodiments, the input / output device 1400 can provide a user interface in response to user operations, and the information provided or collected by the input / output device 1400 based on user operations can be stored in the storage device 1300 and / or the processing device 1100 under the control of the processing device 1100. Generally, the sensitive information provided by the input / output device 1400 (such as fingerprint information, property data, etc.) can be processed in the TEE established by the processing device 1100.
[0060] The input / output device 1400 can include a display device to display information that the user needs to know. The display device is, for example, a Cathode Ray Tube (CRT) display, a Liquid Crystal Display (LCD), or an Organic Light-Emitting Diode (OLED) array display, etc. In some embodiments, the input / output device 1400 can include input devices such as a keyboard, a mouse, a touch panel, etc., for transmitting the information corresponding to the user operation to the processing device 1100 and / or the corresponding coprocessor via the system bus 1200, so that the processing device 1100 and / or the coprocessor can respond to the user operation. In some embodiments, the input / output device 1400 can include a collection device, and the collection device can be coupled to the system bus 1200 to transmit instructions and data related to information such as images / sounds that can be collected. The collection device is, for example, a microphone and / or a device such as a camera or a camcorder for collecting images.
[0061] The electronic device 1000 may include one or more interfaces 1500 integrated within the processing device 1100 or coupled to the processing device 1100 via the system bus 1200, such as a network interface and the like. The electronic device 1000 can access a network via the network interface and the corresponding communication module. The network can be, for example, a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a personal area network (PAN), Bluetooth, a cloud network, a mobile network (such as a Long Term Evolution (LTE) network, a 3G network, a 4G network, or a 5G network, etc.), an intranet, the Internet, etc. The network interface can include a wireless network interface having at least one antenna and / or a wired network interface communicating via a network cable, and the network cable can be an Ethernet cable, a coaxial cable, an optical fiber cable, a serial cable, or a parallel cable.
[0062] For example, the network interface can provide access to a LAN according to the IEEE 802.11b and / or 802.11g standards, can also provide access to a personal area network according to the Bluetooth standard, and can also support other wireless network interfaces and / or protocols, including existing communication standards and future communication standards. The network interface can also utilize time division multiple access (TDMA) protocols, global system for mobile communications (GSM) protocols, code division multiple access (CDMA) protocols, and / or other types of wireless communication protocols, etc.
[0063] It should be noted that the above text and Figure 1 are only used for an exemplary description of the electronic device 1000 and are not used to limit the specific implementation manner of the electronic device 1000. The electronic device 1000 may also include other components, such as a Digital Signal Processor (DSP), etc.; each part of the electronic device 1000 described above may also be appropriately omitted in actual applications.
[0064] As an example, Figure 1 the illustrated electronic device 1000 is, for example, Figure 2 the illustrated refrigerator 1000'. In Figure 2In the provided example, the input / output device 1400 includes, for example, a display touch screen, an image acquisition device, etc. The processing device 1100 can obtain the facial image data of the user collected by the image acquisition device based on the image acquisition program, run the facial recognition program based on the image data obtained by the image acquisition device, and then run the push program based on the facial recognition result to push information related to the historical record of the current user (such as frequently purchased food ingredients and related purchase links, etc.) to the display touch screen. The user can obtain the information provided by the network 3000 by operating the display touch screen, or can directly configure the processing device 1100 in the refrigerator 1000' through the mobile terminal device 2000 (such as a smart phone) or configure the processing device 1100 in the refrigerator 1000' through the network 3000, and can also view the information returned by the processing device 1100 to the mobile terminal device 2000.
[0065] In Figure 2 the example, the processing device 1100 can also run the face recognition payment program to complete the online payment process according to the facial image data obtained by the image acquisition program and the facial recognition result determined by the facial recognition program.
[0066] In some application scenarios, application programs involving sensitive information need to transmit data to other application programs so that the subsequent application programs can continue to implement corresponding functions according to the received data. For example, in Figure 2 the example, the image acquisition program needs to provide facial image data containing sensitive information to the facial recognition program, and the facial recognition program needs to provide the facial recognition result involving sensitive information to the face recognition payment program and / or the push program. In scenarios involving sensitive information, the data transmission process between different application programs needs to have high security and efficiency, so as to protect sensitive information from being stolen while meeting performance requirements.
[0067] Processing Device
[0068] The processing device 1100 of the embodiments of the present disclosure is used to establish and control multiple TEEs that can provide security protection functions. For each TEE, instructions not permitted by it cannot access the TEE, and the programs running in the TEE can be not interfered by the conventional operating system and / or other TEEs, so that the instructions and / or data running in different TEEs can be independently protected in the corresponding TEEs to have high security, privacy and integrity.
[0069] Figure 3A schematic block diagram of a processing device 1100 according to an embodiment of the present disclosure is shown. It should be noted that, in the example described in this embodiment, at least a part of the processing device 1100 is integrated in a system-on-chip (or single chip), and is implemented by the collaborative work of a hardware architecture and a software architecture. However, the processing device 1100 according to the embodiment of the present disclosure may further include other parts coupled to the system-on-chip, that is, the processing device 1100 is not limited to being implemented by a single chip or a system-on-chip, and may also be implemented by multiple devices coupled by cables and / or lines on a PCB.
[0070] As Figure 3 shown, the processing device 1100 may include a processor 100 for processing data and instructions. The processor 100 may include one or more processor cores 10. A specific instruction set may be integrated within each processor core 10. In some embodiments, the instruction set may support, for example, Complex Instruction Set Computing (CISC), Reduced Instruction Set Computing (RISC), or computing based on Very Long Instruction Word (VLIW). Different processor cores 10 may process different instruction sets respectively. In some embodiments, one or more of the processor cores 10 may also be other processing modules, such as a digital signal processor, etc.
[0071] In some embodiments, the processor 100 may include one or more caches 13. According to different architectures, the cache 13 may include a single or multi-level cache located inside and / or outside each processor core 10, or may include a cache shared by various components (such as different processor cores 10) in the processor 100. On the other hand, the cache 13 may include an instruction cache for instructions and a data cache for data.
[0072] Each processor core 10 may execute instructions based on an instruction pipeline. The instruction pipeline is a way of processing instructions for improving efficiency, mainly by dividing the processing process of an instruction into multiple levels of instruction operations such as Fetch, Decode, Execute, Memory Access, and Retire. Each level of instruction operation is implemented by a dedicated unit. As Figure 3As shown, to process instructions, each processor core 10 may include an instruction pipeline structure 11 implemented by software and hardware cooperation. The instruction pipeline structure 11 may include: an instruction fetch unit for obtaining instructions, a decoding unit for decoding instructions into an executable format, an execution unit for executing instructions, a memory access unit for accessing a corresponding storage area according to instructions (which can also be regarded as a kind of execution unit), and a retirement unit for removing relevant scheduling processes after the instruction execution is completed, etc. In some embodiments, the instruction pipeline structure implements instruction operations at the 2nd level or above. For example, the instruction processing can be achieved only through the instruction fetch unit and the execution unit, or can be achieved through parts such as the instruction fetch unit, the decoding unit, and the execution unit.
[0073] In some embodiments, each processor core 10 may further include a register file 12 and an on-core interconnect structure 14. The register file 12 may include one or more physical registers, and the information stored in each physical register may indicate: one or more data types (e.g., scalar integer, scalar floating-point, packed integer, packed floating-point, vector integer, vector floating-point, etc.), status (e.g., access permission information), address (e.g., a pointer or address for fetching instructions), etc. Inside each processor core 10, the on-core interconnect structure 14 can implement the interconnection between components within the processor core 10 (e.g., the register file 112 can provide a pointer for fetching instructions to the instruction fetch unit via the on-core interconnect structure 14), and can also couple the components within the processor core 10 to the bus structure 300 outside the processor core 10.
[0074] It should be noted that the present disclosure only gives an exemplary description of one of the processors 100 and does not limit the specific implementation manner of the processor 100. Each part of the processor 100 described above can also be appropriately omitted in actual applications. In some embodiments, other processors not shown may also be integrated in the processing device 1100.
[0075] As an example of the processing device 1100, Figure 3 the processor core 10 shown in may be used to run an application program. The processor core 10 is implemented, for example, based on the RISC-V instruction set architecture and may also support some extended instruction sets for specified functions. However, the embodiments of the present disclosure are not limited thereto. Each processor core 10 integrated in the processing device 1100 may be implemented based on other instruction set architectures that can establish and control multiple TEEs through a memory protection mechanism, and the processing device 1100 may include one or more processor cores 10, and different processor cores 10 may be implemented based on different instruction set architectures.
[0076] Furthermore, as Figure 3As shown, the processing device 1100 further includes a memory 200 for storing data information and code information. The memory 200 may include storage structures such as random access memory and read-only memory (ROM). Among them, the random access memory in the memory 200 can be used to run programs, such as non-volatile random access memory (NVRAM), and may also include volatile dynamic random access memory (DRAM) and / or static random access memory (SRAM) and other storage structures; the ROM in the memory is implemented by structures such as flash memory, and is mainly used to store code information and instruction information. As an example, the processor 100 can access the ROM to obtain code information and instruction information, and realize data storage and / or reading and writing by accessing the random access memory, so that the processor 100 can realize the operation of the program based on the storage space provided by the memory 200.
[0077] In some alternative embodiments, the memory 200 may further include MMIO (Memory-mapped I / O), which is used to couple with a storage device external to the processing device 1100, so that the storage device and the memory 200 can jointly provide a storage space accessible by the processor 100.
[0078] For the convenience of description, the storage space accessible by the processor 100 in this disclosure is collectively referred to as the storage unit of the processing device 1100. As described above, the storage unit of the processing device 1100 can be physically implemented by the memory 200 integrated in the processing device and / or a storage device coupled to the processing device 1100 via MMIO. In some embodiments, the respective storage addresses corresponding to the storage unit of the processing device 1100 may belong to the same addressing space for the processor 100 to access.
[0079] In the embodiments of this disclosure, the storage unit may include a plurality of mutually isolated security zones 20 (which may be referred to as Enclave, Secure Enclave, or may also be referred to as partitions, trusted zones, enclaves, enclosures, or secure environments), and each security zone is equivalent to an independent trusted execution environment TEE. It should be noted that although Figure 1 and 3The respective security zones shown in the figure are drawn inside the memory 200. However, as described above, in some alternative embodiments, at least a part of one or some of the security zones 20 may also be implemented by a storage device 1300 coupled to the MMIO.
[0080] The physical structure on which each security zone 20 is based can be implemented by any one or more storage structures in the storage unit. For example, the security zone 20 for running a certain program may include: a first storage area provided by the ROM in the storage unit for storing the code of the program, a second storage area provided by the NVRAM in the storage unit for storing the data required by the program, and / or a third storage area mapped by the MMIO, etc.
[0081] As Figure 3 shown, the processing device 1100 further includes a bus structure 300, enabling the memory 200 to communicate with the processor 100 via the bus structure 300. The bus structure 300 is, for example, an SoC bus and can be implemented based on bus protocols such as AXI (Advanced eXtensible Interface).
[0082] As Figure 3 shown, the processing device 1100 further includes a storage access controller 500, which is used to directly access the storage unit to obtain the information (data and / or code) stored therein and manage the data transmission inside the electronic device. The storage access controller 500 is coupled to the bus structure 300, so that both the processor 100 and the memory 200 can be coupled to the storage access controller 500 via the bus structure 300. The processor 100 can initialize the storage access controller 500 so that the storage access controller 500 can obtain the control right of the bus structure 300 in response to a transmission request. Subsequently, the storage access controller 500 can establish the information transmission path indicated by the transmission request by issuing read and write commands, etc., enabling information transmission between various parts within the processing device 1100, such as each processor core 10 and each storage area in the storage unit, under the premise of permission, and returning the control right of the bus structure to the processor 100 after the information transmission is completed and waiting for the next initialization. In some specific embodiments, the storage access controller 500 can be a DMA controller, a controller including a DMA controller, or other controllers that can provide an information transmission path independently of the processor control.
[0083] The processing device 1100 may further include: a bridge for bridging the bus structure 300 and the system bus 1200 of the electronic device, a Power Management Unit (PMU) 600, a non-volatile memory for providing additional storage space, a random access memory, and an interface module for connecting to peripheral devices such as disks and sensors. It may also include various analog components (such as analog-to-digital converters, digitally controlled amplifiers, phase-locked loops, transmit / receive modules, radio frequency modules, etc.) and various digital components (such as image processors, audio processors, and accelerators, etc.), which are hardware components described or not described above.
[0084] As described above, since the processing of instructions and information is implemented by the processor 100, the user can control the operating system by using an application program, enabling the processor 100 to obtain corresponding instructions and information from the storage unit under the control of the operating system and complete the processing of the instructions and information. The processing results can also be stored in the storage unit.
[0085] Figure 4 A system architecture diagram of an embedded system 4000 showing an embodiment of the present disclosure. The embedded system 4000 may implement the processing device of each embodiment of the present disclosure.
[0086] Although the functions, appearance interfaces, operations, etc. of various specific embedded systems are different, even very different, the basic hardware structures are similar, and there is a high similarity with the hardware system of general-purpose computers. However, the characteristics of the application of embedded systems result in significant differences in the composition and implementation form of the hardware between embedded systems and general-purpose computer systems.
[0087] First, to meet the requirements of the embedded system 4000 in terms of speed, volume, and power consumption, data that needs to be stored long-term, such as the operating system, application software, and special data, usually does not use storage media such as disks that have a large capacity but a slow speed, but mostly uses a random access memory 402 or a flash memory 403, as Figure 4 shown. Based on the description of any embodiment of the present disclosure, the flash memory 403 is, for example, used as a cache in the processing device, and the random access memory 402 is, for example, a storage unit including multiple security zones in the embodiment of the present disclosure.
[0088] In addition, in the embedded system 4000, A / D (analog / digital conversion) interfaces 405 and serial interfaces 406 are required for measurement and control purposes, which are rarely used in general-purpose computers. The A / D interface 405 mainly completes the conversion of analog signals to digital signals and the conversion of digital signals to analog signals required during testing. Embedded system 4000 often needs to be tested when applied to industrial production. Since the single-chip microcomputer generates digital signals, analog signals need to be converted for testing during testing. Therefore, different from general-purpose computers, the A / D interface 405 is required to complete the relevant conversion. In addition, in industry, multiple embedded systems often need to be connected in series to complete relevant functions. Therefore, a serial interface 406 for connecting multiple embedded systems in series is required, while this is mostly not needed in general-purpose computers.
[0089] In addition, as a basic processing unit, the embedded system 4000 often needs to connect multiple embedded systems 4000 into a network in industrial design. Therefore, a network interface 407 for connecting the embedded system 4000 to the network is required. This is mostly not needed in general-purpose computers either. In addition, according to different actual applications and scales, some embedded systems 4000 need to adopt a bus 404 (such as implemented by the bus structure and / or system bus in the above embodiments). With the rapid expansion of the application fields of the embedded system 4000, the embedded system 4000 is becoming more and more personalized, and the types of buses adopted according to its own characteristics are also increasing. In addition, in order to test the internal circuit of the embedded processor 401, the boundary scan test technology is generally adopted for the processor chip. In order to adapt to this test, a debug interface 408 is adopted.
[0090] The processing core of the embedded system 4000 is the embedded processor 401 (used to implement the processor in the processing device in the embodiments of the present disclosure). Figure 5 It is a structural diagram of the embedded processor 401 according to an embodiment of the present disclosure. The embedded processor 401 includes an arithmetic logic unit (ALU) 411, registers 421, and a control unit 431. The arithmetic logic unit 411 completes actual arithmetic processing. The registers 421 are used to store instructions and intermediate results during arithmetic processing, etc. The control unit 431 completes the control of accessing the external RAM 402 (used as the memory for providing multiple security zones disclosed in the above embodiments) and the flash memory 403 (used as the cache disclosed in the above embodiments).
[0091] When executing an instruction to be executed, the ALU 411 transfers the instruction to be executed from the random access memory 402 or the flash memory 403 to the register 421, and receives the next instruction fetch address or calculates the next instruction fetch address according to the instruction fetch algorithm. The instruction fetch algorithm includes, for example: incrementing or decrementing the address according to the instruction length.
[0092] After fetching the instruction, ALU 411 enters the instruction decoding stage, and decodes the fetched instruction according to the predetermined instruction format to obtain the operand acquisition information required by the fetched instruction, thereby preparing for the execution of the instruction. The operand acquisition information, for example, points to the address in the random access memory 402 or the flash memory 403. After decoding, ALU obtains the operand stored in the random access memory 402 or the flash memory 403 according to the operand acquisition information and performs processing.
[0093] When executing certain instructions (such as memory access instructions), ALU 411 needs to access random access memory 402 or flash memory 403 to obtain information stored therein or provide data that needs to be written into random access memory 402 or flash memory 403.
[0094] After the memory access instruction is obtained by ALU 411, ALU 411 can decode the memory access instruction so that the source operand of the memory access instruction can be obtained. ALU 411 can perform corresponding operations on the source operand of the memory access instruction (for example, the arithmetic logic unit performs operations on the source operand stored in the register) to obtain the address information corresponding to the memory access instruction, and initiate corresponding requests according to the address information, such as address translation requests, write access requests, etc.
[0095] The source operand of the memory access instruction usually includes an address operand. ALU 411 operates on the address operand to obtain the virtual address corresponding to the memory access instruction. ALU 411 initiates an address translation request to the control unit 431 according to the virtual address, and the address translation request includes the virtual address corresponding to the address operand of the memory access instruction. Control unit 431 responds to the address translation request and converts the virtual address in the address translation request into a physical address according to the table entry matching the virtual address, so that ALU 411 can access random access memory 402 or flash memory 403 according to the translated physical address.
[0096] Depending on the function, the memory access instruction may include a load instruction and a store instruction. The execution process of the load instruction usually does not need to modify the information in the random access memory 402 or the flash memory 403. The ALU 411 only needs to read the data stored in the random access memory 402 or the flash memory 403 or the external storage device according to the address operand of the load instruction.
[0097] Different from the load instruction, the source operand of the store instruction includes not only the address operand but also the data information. The execution process of the store instruction usually requires modification of the random access memory 402 or the flash memory 403. The data information of the store instruction can point to the write data, and the source of the write data can be the execution result of the operation instruction, the load instruction and other instructions, or the data in the register 421, or the immediate value.
[0098] Based on an embodiment of the present disclosure, the embedded system 4000 further includes a storage access controller 409 according to any embodiment of the present disclosure. The storage access controller 409 is used to directly access the storage unit to obtain the information stored therein and manage the data transmission inside the embedded system. The storage access controller 409 is coupled to the bus 404 of the embedded system, for example, so that both the embedded processor 401 and the random access memory 402 can be coupled to the storage access controller 409 through the bus 404. The embedded processor 401 can initialize and configure the storage access controller 409, and the configured storage access controller 409 can establish a secure channel between different security zones, so that the data transmission process between different security zones does not need to be relayed by the embedded processor 401, reducing the power consumption during the data transmission process between security zones, ensuring that the data transmitted between security zones is not stolen, and improving the data transmission efficiency between security zones.
[0099] It should be noted that Figure 4 and Figure 5 are only a possible example of the embedded system of the embodiments of the present disclosure. In some other examples, the embedded system of the present disclosure may further include some parts not shown (such as sensors, etc.), and the shown parts may also be omitted (for example, in applications that do not require networking, the network interface can be omitted).
[0100] Figure 6 The software architecture diagram of the processing device according to the embodiments of the present disclosure is shown.
[0101] Based on the above hardware architecture, the operating system can be executed on the processing device 1100 provided by the embodiments of the present disclosure. The operating system can be used to: control, manage, and arrange access to the hardware resources in the electronic device (including memory, processor, storage device, and / or other external devices, etc.); provide corresponding interfaces (such as system call interfaces, System Call Interface) for various application programs, so that users and / or application programs can initiate access to the operating system through the corresponding interfaces to request the operating system to provide corresponding service support (such as implementing control of the hardware architecture), so that the processing device 1100 can execute different tasks based on various application programs.
[0102] In the embodiments of the present disclosure, the instruction set (such as the RISC-V instruction set) architecture on which the processor 100 is based can define multiple privilege modes (also called privileged modes, Privileged Mode), at least including: user mode (User Mode, which can be abbreviated as U-mode) and machine mode (Machine Mode, which can be abbreviated as M-mode, and can also be called kernel mode).
[0103] In some alternative embodiments, the processing device 1100 may further include modes such as a supervisor mode (abbreviated as S-mode for short) and a hypervisor mode (abbreviated as H-mode for short), etc., to implement different functions according to different scenarios.
[0104] In some embodiments, the processing device 1100 includes, for example, a mode status register (such as being located in the register bank 12, or may also be implemented by other registers within the processing device), which is used to provide operation codes corresponding to different privilege modes. The processing device 1100 can determine whether the current instruction can be executed in the current privilege mode by checking these operation codes, so as to implement functions such as task processing, task protection, hardware abstraction, and virtualization under different privilege modes.
[0105] To prevent phenomena such as untrusted applications obtaining sensitive information, various applications can only run in a protected user mode, thus not affecting the operation of the operating system and not having the privilege to affect various configurations of the machine mode; the operating system can manage and control the software and hardware resources within the application and other various electronic devices. The operating system runs at least in the application mode, and in some alternative embodiments, the operating system can also run in the machine mode.
[0106] The machine mode can be understood as a trusted mode. In the machine mode, the processing device 1100 can run a trusted secure monitor (abbreviated as SM) in a specified storage area of the storage unit (different from the storage area where the operating system is stored). The code of the secure monitor is usually defaulted to be trusted code (which can be stored in the read-only memory within the memory), and can access each part within the electronic device such as the operating system trustworthily, so as to be able to control the storage unit, the input / output interface, and the underlying functions necessary for the startup and configuration processes of some electronic devices. Since application programs usually include untrusted code, application programs cannot run in the machine mode, and neither the operating system nor the application programs have the right to access the secure monitor.
[0107] In the embodiments of the present disclosure, the secure monitor can implement a physical memory protection (abbreviated as PMP) mechanism, which is used to specify the storage address space that the user mode can access in the machine mode, and grant or deny permissions such as read permission, write permission, and execution permission.
[0108] Based on the PMP mechanism, in the machine mode, the secure monitor can create multiple mutually isolated security zones 20 (such as Figure 1 、 3Configure corresponding storage address spaces as shown in FIGS. 6. All or part of the application can be loaded into a corresponding secure area 20 to isolate it from other applications and / or information. When the processor 100 needs to run a certain application, it can obtain the code and / or data stored in the corresponding secure area 20 through one or more authorization methods (such as verification, signature, etc.), and return the generated information to the secure area 20 to achieve the independent operation of the application.
[0109] For example, in Figure 2 the example shown: The image acquisition program can run independently in the first secure area, and the image acquisition device returns the acquired facial image data to the first secure area; the facial recognition program can run independently in the second secure area, and the first secure area needs to transmit the facial image data to the second secure area so that the facial recognition program can calculate the facial recognition result based on the facial image data; the face recognition payment program can run independently in the third secure area, and the second secure area needs to transmit the facial recognition result to the third secure area so that the face recognition payment program can complete the payment operation based on the facial recognition result. It can be seen that in some application scenarios, data may need to be transmitted between applications running in different secure areas. The embodiments of the present disclosure can implement an efficient and secure data transmission process between different secure areas based on the storage access controller 500.
[0110] In some embodiments, the security monitoring system is also used to implement process switching between programs running in each secure area 20, and can also be used to implement process switching between programs running in each secure area 20 and other programs (such as the operating system). For example, when the code in a certain secure area is run to completion by the corresponding processor core, the secure area can hand over the control right to the security monitoring system, and the security monitoring system then hands over the control right to the code running in another secure area to start running another application.
[0111] The different secure areas of the embodiments of the present disclosure will be described below.
[0112] Safe Area
[0113] As Figure 3 and Figure 6 shown, in the processing device of the embodiments of the present disclosure, the processor 100 divides different functional secure areas in the address space of the storage unit, including but not limited to: multiple application - type secure areas (Application Enclave, abbreviated as AE, or can be named other names) AE for applications and non - application - type secure areas for implementing security control.
[0114] The different secure areas defined in the embodiments of the present disclosure will be described separately below.
[0115] Application class security zone AE: It is used to encapsulate corresponding application programs (usually designated as application programs involving sensitive information and / or untrusted application programs), so as to isolate the application program from other programs / information in user mode. The application class security zone AE stores, for example, the executable code of the application program and the data that can be obtained or generated by the application program. Different application programs (which may be all or part of the main application program and / or supplementary application program) run in different application class security zones AE.
[0116] Non-application class security zone: In the storage address space of the embodiments of the present disclosure, a non-application class security zone can be set for securely controlling the data transmission between different security zones. For the convenience of description, the present disclosure refers to this non-application class security zone as the Runtime Enclave (abbreviated as RE). However, this name "Runtime Enclave" should not limit the functions and roles of the non-application class security zone, that is, the non-application class security zone can also be called other names. In some embodiments, the non-application class security zone may further include a security zone for running other security control programs and / or a security zone with other functions. For example, the non-application class security zone may further include a cryptographic security zone, which is used to provide the storage space required for running password-related programs.
[0117] The control program running in the Runtime Enclave RE can be used to securely control the data transmission process between different security zones. In some embodiments, the Runtime Enclave RE can also be used to store shared information (such as shared programs and / or common drivers) that can be called by different application programs to save storage space. The shared information includes, for example, shared libraries and / or shared drivers. In some embodiments, the shared library includes, for example, a common Runtime Library, which is used to support the development and operation of the operating system (such as providing library functions, initialization code, error handling code, and / or exit code that can be called by various application programs). Thus, different application programs can call the shared libraries stored in the Runtime Enclave RE to run different application programs without repeatedly storing the same information in the storage unit, saving storage space. In some embodiments, the shared driver includes, for example, a CommonRuntime Driver, which is used to drive and configure the initialization, error handling, exit, etc. programs of different application programs.
[0118] To ensure the security performance of the processing device 1100, corresponding permissions can be set (granted / denied) for different security zones. As an example, the permission information for each security zone can be stored in the corresponding permission register (e.g., implemented by the register bank 12 specified within the processor 100, or can also be implemented by other registers located within the processing device 1100) or in a specified area within the storage unit.
[0119] In the embodiments of the present disclosure, the application programs running in the application class security zone AE do not have read and write permissions for non-application class security zones, thereby preventing the information in the non-application class security zones from being tampered with or affected by the application programs, and ensuring that the information stored in the non-application class security zones is highly confidential and remains intact. At the same time, the application programs running in the application class security zone AE can have execution permissions for non-application class security zones, that is, the application programs running in the application class security zone AE can only implement corresponding functions by calling the information (data and / or programs) in the non-application class security zones.
[0120] In addition, in some embodiments, each application class security zone AE does not have the permission to read other application class security zones, thereby ensuring that the information stored in each application class security zone AE cannot be actively read by other application class security zones to ensure information security.
[0121] In some scenarios (such as the example described above), since the application programs running in different application class security zones may need to transfer necessary data, the application programs running in the application class security zone AE can actively request to write necessary data into the available storage space of another application class security zone.
[0122] In some embodiments, the non-application class security zone can have access permissions for the application class security zone AE, that is: the program running in the non-application class security zone (such as a certain security driver) can perform read operations, write operations, and execution operations on the application class security zone AE.
[0123] Thanks to the above PMP mechanism, in an alternative embodiment, the storage address ranges of each security zone can be stored as an item list in the set area of the storage unit and / or the specified register (e.g., implemented by the register bank 12 specified within the processor 100, or can also be implemented by other registers located within the processing device 1100), and the item list can only be accessed by the security monitoring system. The processor 100 can implement the address allocation of the security zone by configuring each entry in the item list.
[0124] Each entry may have a set data structure. In some alternative embodiments, each entry may include, in addition to an address tag (which may be stored in an address register) for indicating the storage address range of the corresponding security zone, a category tag for indicating the category information of the security zone (for indicating that the security zone is an application - type security zone, a non - application - type security zone, a runtime security zone, or a cryptographic security zone) and / or a permission tag for indicating the above - mentioned permission information, etc. In some embodiments, each entry may also be used to indicate auxiliary information such as the number of the security zone.
[0125] Each entry may be stored in a designated protected area in the storage unit and may be copied into a designated register within the processing device 1100 (for example, implemented by a register bank designated in the processor 100, or may also be implemented by other registers located within the processing device).
[0126] Based on the PMP mechanism, the processing device 1100 can protect each security zone at the physical level. For example, if an access request (initiated by an external device, for example) does not have the permission to access a certain security zone, the processing device indicates that the access request refers to a non - existent storage address, so that the access request cannot be executed. Another example is that before the processing device 1100 fetches an instruction or performs a load / store operation based on a certain access address, it can first compare the access address with the storage address ranges indicated by each entry in the entry list, and decide whether the access address is allowed according to the comparison result. If so, the processing device 1100 can continue to perform the corresponding operation based on the access address; if not, an access exception will be triggered.
[0127] Data Transmission Process between Safe Areas
[0128] In the following description, mainly the data transfer process between two application - type security zones (hereinafter exemplarily referred to as the first application - type security zone AE1 and the second application - type security zone AE2 among multiple security zones) is taken as an example for illustration. The first application - type security zone AE1 serves as the source security zone for running the first application App1, and the second application - type security zone AE2 serves as the target security zone for running the second application App2. Moreover, in this example, at least one non - application - type security zone includes a runtime security zone RE (for running a control program) for controlling the data transfer process between the source security zone and the target security zone. However, as explained above, the embodiments of the present disclosure are not limited thereto. The storage address space can be configured with multiple non - application - type security zones to implement multiple runtime security zones and / or other non - application - type security zones with other functions. The runtime security zone RE may not only be suitable for running and storing the control program, but also for running and / or storing some other information. In some embodiments, the source security zone for providing specified data can be an application - type security zone or a cryptographic - type security zone or other non - application - type security zones, and the target security zone for receiving the specified data can be an application - type security zone or a cryptographic - type security zone or other non - application - type security zones.
[0129] Figure 7 Another schematic block diagram of the processing device according to the embodiments of the present disclosure is shown. Figure 8 A schematic block diagram of the storage access controller according to the embodiments of the present disclosure is shown. To more clearly show how the processing device according to the embodiments of the present disclosure realizes data transfer, one or some software / hardware components of the processing device 1100 are not shown in Figure 7 and one or some software / hardware components of the storage access controller 500 are not shown in Figure 8 either. Figure 7 The embodiments shown can be implemented based on Figure 8 the storage access controller shown or its variations.
[0130] As Figure 7 and Figure 8 shown, when the first application App1 running in the first application - type security zone AE1 needs to transfer data to the second application - type security zone AE2, it provides a transfer request. The transfer request includes source address information of the specified data to be transferred (for example, the starting physical address of the data to be transferred), target address information of the specified data to be transferred (for pointing to the second application - type security zone, and the target address information is, for example, the label, number or starting physical address of the second application - type security zone AE2 that needs to receive the data), and data volume information of the data to be transferred (for example, the number of bytes of the data to be transferred).
[0131] The control program running within the runtime security area RE can initiate an allocation request (including at least the information on the amount of data to be transmitted) to the second application program App2 running within the second application class security area AE2 based on a transmission request.
[0132] In some embodiments, the initiators of the transmission requests received by the control program are likely to be inconsistent. Therefore, the control program can verify the legitimacy of the transmission requests based on preset control rules to avoid active read operations between different application class security areas, thereby ensuring that the information within each application class security area is not leaked. If the control program determines that the transmission request is legal, the control program further generates an allocation request according to the transmission request; if the control program determines that the transmission request is illegal, the control program rejects the transmission request to terminate the data transmission indicated by the transmission request.
[0133] The control rules of the control program can include: determining whether the storage address corresponding to the source address information indicated by the transmission request is within the source security area (such as the first application class security area AE1). If so, it means that the program running within the source security area (such as the first application program App1) is the initiator of the transmission request, that is, the transmission request is not for reading / executing information in other security areas, and at this time the transmission request is legal; if not, it means that the initiator of the transmission request is not the program running within the source security area, that is, the transmission request is for accessing the data stored within the source security area from outside the source security area, which may cause the sensitive information stored within the source security area to be maliciously obtained. Therefore, the control program in the embodiments of the present disclosure determines that the transmission request is illegal at this time.
[0134] In some alternative embodiments, the control program running within the runtime security area RE can preset one or more control rules, not limited to the above control rules. For example, one of the control rules of the control program can include: for the transmission requests initiated by the programs running within a specified one or some security areas, the control program can directly reject them without judging the transmission direction. Another example is that one of the control rules of the control program can include: the control program prohibits the application programs running within a specified one or some security areas from initiating transmission requests. For example, the control program can prohibit the application class security area for running payment application programs from initiating transmission requests to ensure the security protection of payment information.
[0135] After the control program initiates an allocation request to the target security area (such as the second application class security area AE2) where it is running, the allocation request initiated by the control program is sent to the target security area (such as the second application class security area AE2) pointed to by the transfer request. Subsequently, the program running in the target security area (such as the second application program App2) will determine based on the allocation request whether the size of the allocable address space in the target security area can accommodate the data volume information indicated by the allocation request. If so, the second application program App2 returns an allocation success notification (transfer confirmation response) to the control program. The allocation success notification at least includes allocation address information (such as address information like the starting physical address of the free storage area in the target security area, and this free storage area serves as the target storage area for storing the specified data of this transfer) indicating that the target security area is available for storing the transferred data; if not, the program running in the target security area returns an allocation failure notification to the control program, causing the control program to terminate this transfer in response to this allocation failure notification.
[0136] After the control program receives the allocation success notification, it will provide initialization information to the storage access controller based on the allocation success notification to complete the initialization settings of the storage access controller. The initialization information at least includes the source address information and data volume information indicated by the transfer request, the allocation address information indicated by the allocation success notification, etc.
[0137] The initialized storage access controller 500 can establish a secure channel for unidirectional transfer based on the initialization information to transfer (which can be understood as copying) the specified data stored in the source security area (corresponding to the source address information and the data volume information to be transferred indicated by the transfer request) to the target storage area in the target security area (corresponding to the allocation address information indicated by the allocation success notification).
[0138] In addition, since the processor 100 and the storage access controller 500 cannot control the bus structure 300 simultaneously, the fact that the processor 100 provides the initialization information to the storage access controller 500 means that the control right of the bus structure 300 needs to be transferred from the processor 100 to the storage access controller 500.
[0139] In some embodiments, after receiving the initialization information, the storage access controller 500 may initiate a takeover request to the processor 100. Thus, after the processor 100 returns a takeover permission signal to the storage access controller 500, the storage access controller 500 may obtain the control right of the bus structure 300. In other embodiments, the processor 100 may also release the control right of the bus structure 300 when providing the initialization information (or within a period of time after or before providing the initialization information) (at this time, the bus structure 300 presents a high-impedance state to the processor 100, for example), so that the storage access controller 500 can establish a data transmission channel via the bus structure 300. The storage access controller 500 may determine whether the current transmission is completed, and when it is determined that the current transmission is completed, return the control right of the bus structure 300 to the processor 100 again.
[0140] To implement the above functions, as Figure 8 shown, the storage access controller 500 may include: a register group 510, a control module 520, and at least one channel 530.
[0141] In some embodiments, the register group 510 may include a source address register 511 and a destination address register 512. After the storage access controller 500 completes the initialization settings: the source address register 511 is used to store the source address information provided by the initialization information to indicate the location of the specified data to be transmitted in the source security area; the destination address register 512 is used to store the allocated address information indicated by the allocation success notification (i.e., the address information to be written to the destination security area) to indicate the storage location (i.e., the destination storage area) of the specified data to be transmitted in the destination security area during the current transmission.
[0142] The control module 520 is used to select an available channel in at least one channel 530 as a secure channel. The secure channel is coupled to the hardware structure for implementing the storage unit via a specified interface and the bus structure 300. Thus, the specified data to be transmitted stored in the source security area can be transmitted to the target storage area in the destination security area via the secure channel to achieve the purpose of the transmission request.
[0143] In some embodiments, the register group 510 further includes a status register 513, which is used to provide status values corresponding to the respective channels 530 to indicate whether the respective channels 530 are in an available state. Based on the status values provided by the status register 513, the control module 520 may select one of the channels 530 in the available state as the secure channel and update the status value of the secure channel to the occupied state to prevent transmission conflicts.
[0144] In some embodiments, the memory access controller 500 may further include a transmission counter 540, and the register bank 510 further includes a data volume register 514. After the memory access controller 500 completes the initialization settings, the data volume register 514 stores the data volume information provided by the initialization information to indicate the data length to be transmitted in this data transmission. The data length is, for example, the number of bytes to be transmitted. The transmission counter 540 is used to count the data that has been transmitted during this data transmission process to obtain the cumulative transmission length. Thus, when the cumulative transmission length is equal to the data length indicated by the data volume register 514, the transmission counter 540 and / or the control module 520 can know that the data to be transmitted this time has been transmitted.
[0145] After completing the data transmission, the control module 520 may send a transmission end notification to the processor via the bus structure 300 to restore the control right of the processor over the bus structure 300.
[0146] In some embodiments, the memory access controller 500 may further include some parts not shown, such as several counters, registers, and / or calculation modules. For example, each byte of the data to be transmitted needs to be written to consecutive addresses in the target security area. Therefore, the memory access controller 500 may further include a calculation module for calculating the address to which the next byte needs to be written and updating the allocated address information stored in the target address register 512 based on the calculated address, so that the address information stored in the target address register 512 points to the next writable byte unit in the target memory area. Another example is that the memory access controller 500 may further include an interface unit matching the bus structure 300, so that structures such as the control module 520 and the channel 530 can interact correctly with the bus structure 300.
[0147] According to the various embodiments described above, the processing device and the electronic device provided by the present disclosure can allocate mutually isolated security areas to different programs, so that different programs can run independently in different security areas, and the memory access controller can establish a one-way data transmission channel between the source security area and the target security area. Thus, the data transmission process between the source security area and the target security area does not require the participation of the processor, realizing an efficient and secure data transmission process. In some embodiments, the control program running in the runtime security area can specify one of the channels in the memory access controller as a security channel. The specified security channel can be used to achieve one-way data transmission between the source security area and the target security area, further ensuring the security of the data transmission process between different security areas.
[0148] Figure 9 The flowchart of the security control method according to the embodiments of the present disclosure is shown. Figure 9 The shown security control method may be based on Figures 1 to 8The shown solution or variant implementation exemplarily includes the following steps.
[0149] Step S101: When the corresponding program running in the source security area (for example, the first application program App1 running in the first application - type security area) needs to transmit specified data to the target security area (for example, the second application - type security area AE2), it initiates a transmission request. The transmission request includes the source - address information of the data to be transmitted (for example, the starting physical address of the specified data to be transmitted), the target - address information of the data to be transmitted (used to point to the target security area, and the target - address information is, for example, the label, number, or starting physical address of the target security area that needs to receive the specified data), and the data - volume information to be transmitted (for example, the number of bytes of the data to be transmitted).
[0150] Step S102: The control program receives the transmission request and determines whether the transmission direction indicated by the transmission request is legal according to the control rules. If it is, step S103 is executed; if not, step S104 is executed.
[0151] In this embodiment, since the initiators of the transmission requests received by the control program are likely to be inconsistent, the control program can verify the legality of the requests based on preset control rules to avoid active read operations between different security areas, thereby ensuring that the information in each security area is not leaked.
[0152] The control rules of the control program for the transmission request may include: determining whether the storage address corresponding to the source - address information indicated by the transmission request is within the source security area. If it is, it means that the source security area is the initiator of the transmission request, that is, the transmission request is not used to read / call / execute information provided by other security areas, and at this time the transmission request is legal; if not, it means that the initiator of the transmission request is not the source security area, that is, the transmission request is used to access the data stored in the source security area from outside the source security area, which may cause the sensitive information stored in the source security area to be maliciously obtained. Therefore, the control program in the embodiments of the present disclosure determines that the transmission request is illegal at this time.
[0153] In some alternative embodiments, the control program may preset one or more control rules, not limited to the above - mentioned control rules. For example, one of the control rules of the control program may include: for a transmission request initiated by a program running in a specified one or some security areas (for example, a certain application - type security area), the control program may directly reject it without judging the transmission direction. Another example is that one of the control rules of the control program may include: the control program prohibits programs running in a specified one or some security areas from initiating transmission requests.
[0154] Step S104: If the control program determines in step S102 that the transfer request is illegal, the control program rejects the transfer request to terminate the data transfer process initiated by the source security zone.
[0155] Step S103: The control program further generates an allocation request (including at least the data volume information to be transferred) according to the transfer request, and sends the allocation request to the target security zone pointed to by the transfer request.
[0156] In some other embodiments, step S102 can be skipped and step S103 can be directly executed.
[0157] The program running in the target security zone (for example, the second application program App2 running in the second application class security zone AE2) determines based on the allocation request whether the size of the storable space allocable in the target security zone is greater than or equal to the data volume indicated by the allocation request. If not, step S120 is executed, and the second application program App2 returns an allocation failure notice to the runtime security zone RE, so that the control program terminates the current data transfer in step S121 in response to the allocation failure notice; if so, step S110 is executed, and the target security zone returns an allocation success notice to the runtime security zone RE.
[0158] The allocation success notice includes at least allocation address information (such as the start physical address of the target storage area free in the second application class security zone AE2, etc.) for indicating the storage area allocable in the target security zone for storing the specified data to be transferred.
[0159] Step S111: When the control program receives the allocation success notice, it will provide initialization information to the storage access controller based on the allocation success notice. The initialization information includes at least the source address information and data volume information indicated by the transfer request, the allocation address information indicated by the allocation success notice, etc.
[0160] Step S112: The storage access controller 500 completes the initialization settings according to the received initialization information. The initialized storage access controller 500 can establish a secure channel based on the initialization information. This secure channel is used to transfer (which can be understood as copying) the specified data stored in the source security zone (corresponding to the source address information and data volume information indicated by the transfer request) to the target storage area in the target security zone (corresponding to the allocation address information indicated by the allocation success notice).
[0161] In step S112, the storage access controller that has completed the initialization settings can initiate a takeover request to the processor. After the processor returns a takeover permission signal to the storage access controller, the storage access controller 500 can obtain the control right of the bus structure (at this time, the bus structure presents a high-impedance state to the processor, for example). The storage access controller that has obtained the bus control right can provide a selected channel as a secure channel.
[0162] Step S113: The source security area transfers the specified data to be transmitted to the secure channel established in step S108.
[0163] Step S114: The storage access controller transfers the specified data provided by the source security area in step S113 to the target storage area within the target security area based on the secure channel established in step S112.
[0164] In step S114, the storage access controller can determine whether the current data transfer has been completed. For example, in some embodiments, the storage access controller can detect the amount of data that has been transferred in the current data transfer and compare the detected amount of data with the data amount information indicated by the initialization information. If the detected amount of data is consistent with the total data amount indicated by the data amount information in the initialization information, it indicates that the data to be transferred this time has been transferred. If the detected amount of data does not reach the total data amount indicated by the data amount information, it indicates that there is still data that has not been transferred (i.e., the current data transfer is not completed).
[0165] In step S114, if the storage access controller determines that the current transfer has been completed, it ends the current transfer and restores the processor's control right over the bus structure; if the storage access controller determines that the current transfer is not completed, it continues to transfer the specified data.
[0166] In some traditional solutions, the data transfer process between different trusted execution environments is implemented based on the programs executed by the processor. The data to be transferred in the memory needs to be first stored in the processor, and then the processor provides the data to be transferred to the target memory space. The data transfer speed is relatively low, which limits the efficiency of electronic devices implemented based on trusted execution environments. For another example, in some traditional technologies, the data transfer process between different trusted execution environments needs to be implemented by calling functional functions. Therefore, this technology still requires the participation of the processor to complete the data transfer between two trusted execution environments. Compared with these traditional solutions, in the embodiments of the present disclosure, the processing device can establish a data transfer channel between two security areas through the storage access controller without affecting the security performance. During the data transfer process between different security areas, it does not require the participation of the processor, but directly realizes the data transfer between two security areas in the storage unit through the secure channel, thereby improving the data transfer speed between security areas and improving the performance of the electronic device such as the operation speed and response speed.
[0167] In some traditional solutions, an electronic device is divided into two parts: a secure part and a normal part. All trusted applications run in the secure part. Each application running in the entire secure part has the possibility of being attacked. Therefore, the more applications running in the secure part, the greater the risk of being attacked, and different applications running in the secure part will also interfere with each other. In contrast, in the embodiments of the present disclosure, each program that needs to be protected / trusted runs in different and isolated secure areas respectively. Therefore, it can be ensured that the data in each application is securely and independently protected in different secure areas, preventing the leakage of sensitive information and enhancing security.
[0168] In some traditional solutions, the required data and code (such as static link libraries and dynamic link libraries) are default loaded in the trusted execution environment for running applications. Therefore, there is no need to transfer data between different trusted execution environments, and no technical inspiration related to the purpose of "implementing the data transfer process between different trusted execution environments" is provided.
[0169] In summary, compared with traditional solutions, the processing device, embedded system, system-on-chip, and security control method provided by the embodiments of the present disclosure can establish a TEE based on multiple secure areas. Different programs can run independently in different secure areas, and the storage access controller can be configured to establish a secure channel for unidirectional data transfer between the source secure area and the target secure area in multiple secure areas. Since the data transfer process of the present disclosure does not require the participation of the processor, therefore, compared with the prior art, the embodiments of the present disclosure can improve the communication efficiency between secure areas and reduce power consumption on the premise of ensuring information security, thereby being able to speed up the response speed of the programs running in the secure areas and providing strong support for the performance improvement of the processing device, electronic device, embedded system, and system-on-chip and the improvement of user experience.
[0170] In some embodiments, the runtime secure area in multiple secure areas provides a trusted execution environment for running control programs, thereby further ensuring that the data transfer process between the source secure area and the target secure area can be carried out efficiently on the premise of ensuring data security.
[0171] In some embodiments, the control program running in the runtime secure area can control the data transfer between the source secure area and the target secure area based on various preset control rules, thereby realizing flexible control and optimization of the data transfer process. For example, the control rules of the control program can judge whether the direction of data transfer is legal, thereby preventing sensitive information in a certain secure area from being wrongly leaked to other secure areas.
[0172] In some embodiments, the control program running in the runtime security zone may initiate an allocation request to the target security zone to be written based on the transmission request to confirm whether the target security zone has sufficient storage space to receive the specified data to be transmitted, so as to prevent the valid data in the target security zone from being overwritten.
[0173] It should be understood that the above are only the preferred embodiments of the present disclosure and are not used to limit the present disclosure. For those skilled in the art, there are many variations in the embodiments of this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present disclosure shall be included within the protection scope of the present disclosure.
[0174] It should be noted that Figure 2 Only one possible application scenario of the embodiments of the present disclosure is shown. The embodiments of the present disclosure can also be applied to other application scenarios, especially those strongly associated with user sensitive information.
[0175] For example, Figure 10 shows another possible application scenario of the embodiments of the present disclosure. The devices of the embodiments of the present disclosure can implement user identity authentication using an electronic Subscriber Identification Module (SIM for short), so as to allow the user to download the files required by the user identity identification module to the terminal device through the public network without a physical SIM card, and use the management platform at the network end ( Figure 10 with the label 6000) to manage the user identity identification module in the terminal device, so that the user can directly access the network services provided by the communication operator without a physical SIM card. The user identity identification module is, for example, an Embedded Subscriber Identification Module (eSIM for short) or a TEE SIM.
[0176] As Figure 10 shown, inside the terminal device 5000 (such as implemented based on the electronic devices and / or embedded systems of the embodiments of the present disclosure), the user identity identification module 502 can be associated with the processing devices of the above embodiments ( Figure 10communicate with the component numbered 501), so that the processing device can run an authentication program (authenticate the legality of received data based on user information), an encryption / decryption program (perform encryption / decryption processing on data that has been verified as legal), etc. based on the information provided by the user identity module 502; in some examples not shown, the user identity module can also be integrated inside the processing device as a software module, a hardware module, or a module combining software and hardware. Since programs such as the authentication program and the encryption / decryption program used to support the user identity module involve sensitive information such as user identity, they need to run in different secure areas isolated from each other inside the processing device; in some cases, these programs running in different secure areas also need to rely on data provided by other secure areas. Based on various embodiments of the present disclosure, the processing device supporting the user identity module can establish a secure channel between different secure areas, so that the source secure area for running a certain program (such as the authentication program) can directly transmit specified data (such as the authentication result generated by the authentication program) to the target secure area that needs to receive the specified data (such as for running the encryption / decryption program) via the corresponding secure channel, without first storing the specified data in the processor and then transmitting it to the target secure area by the processor, which not only ensures the security of data transmission between secure areas (ensuring that the sensitive information being transmitted is not stolen), but also improves the data transmission efficiency between secure areas, enhances the product performance and user experience.
[0177] For another example, the devices of the above embodiments can be applied to devices such as intelligent vehicles, intelligent vending machines, and intelligent robots. These devices can run a first program (such as a program involving user identity information) in a certain secure area provided by the processing device, and directly transmit the specified data provided by the first program to another secure area of the processing device through the configured secure channel, so that the program running in the other secure area (such as a payment program, a recommendation algorithm program, etc.) can process based on the specified data provided by the secure channel.
[0178] It can be seen that since the device provided by the embodiments of the present disclosure has a streamlined structure and does not need to be relayed by the processor during the data transmission process between secure areas, it has high data transmission efficiency, data processing efficiency, and low power consumption, and has broad application prospects in various low-power and embedded application scenarios.
[0179] It should be understood that the embodiments in this specification are all described in a progressive manner. The same or similar parts between the embodiments can be referred to each other, and the key points of each embodiment are the differences from other embodiments. In particular, for the method embodiments, since they are basically similar to the methods described in the device and system embodiments, the description is relatively simple, and the relevant parts can refer to the partial descriptions of other embodiments.
[0180] It should be understood that the above description has been made of specific embodiments of the present specification. Other embodiments are within the scope of the claims. In some cases, the acts or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0181] It should be understood that an element described herein in the singular or shown only in one of the figures is not meant to limit the quantity of that element to one. Additionally, modules or elements described or shown herein as separate may be combined into a single module or element, and a module or element described or shown herein as a single one may be split into multiple modules or elements.
[0182] It should also be understood that the terms and expressions used herein are for the purpose of description only, and one or more embodiments of the present specification should not be limited to these terms and expressions. The use of these terms and expressions does not mean excluding any equivalent features of the illustration and description (or parts thereof), and it should be recognized that various modifications that may exist should also be included within the scope of the claims. Other modifications, variations, and substitutions may also exist. Accordingly, the claims should be regarded as covering all such equivalents.
Claims
1. A processing device for improving the data transmission efficiency between different TEEs while ensuring data security, characterized in that: include: a processor, suitable for running programs; a memory, coupled to the processor, adapted to provide a plurality of mutually isolated security zones, the plurality of security zones comprising: a source security zone, a target security zone, and a runtime security zone; the source security zone and the target security zone are respectively used to provide storage space required for the operation of corresponding programs; and the control program running in the runtime security zone is used to securely control the data transmission process; Wherein, the processing device also includes a storage access controller; the control program uniquely configures the storage access controller so that the storage access controller transfers the specified data stored in the source security area to the target security area.
2. The processing device according to claim 1, characterized in that The runtime security zone is different from the source security zone and the target security zone The runtime safety area is suitable for providing a storage space required for the execution of the control program.
3. The processing device according to claim 2, characterized in that The source security zone is suitable for generating a transfer request and sending the transfer request to the runtime security zone so that the control program configures the storage access controller to transfer the specified data stored in the source security zone to the target security zone based on the transfer request.
4. The processing device according to claim 3, characterized in that The transmission request includes source address information; and Before the control program configures the storage access controller to transfer the specified data stored in the source security zone to the target security zone, the control program checks whether the source address information points to the source security zone that issued the transfer request. If so, the storage access controller is allowed to transfer the specified data stored in the source security zone to the target security zone.
5. The processing device according to claim 3, characterized in that Before the control program configures the storage access controller to transfer the specified data stored in the source security zone to the target security zone, the control program checks whether the transmission function of the source security zone that issues the transfer request is disabled. If it is not disabled, the storage access controller is allowed to transfer the specified data stored in the source security zone to the target security zone.
6. The processing device according to claim 3, characterized in that The transfer request includes information about the amount of data to be transferred, wherein, before the storage access controller transfers the specified data stored in the source security zone to the target security zone, the control program sends an allocation request to the target security zone, and the allocation request includes the data amount information, so that the target security zone can determine whether the size of the allocatable storage space in the target security zone is greater than / equal to the data amount information indicated by the allocation request, and if so, send a transfer confirmation response to the storage access controller so that the storage access controller can transfer the specified data stored in the source security zone to the target security zone.
7. The processing device according to claim 6, characterized in that The transmission confirmation response includes allocation address information, and the allocation address information points to a target storage area in the target security area that is allowed to receive the specified data. The control program provides the allocation address information to the storage access controller so that the storage access controller transfers the designated data stored in the source security area to the target storage area in the target security area.
8. The processing device according to claim 4, characterized in that The storage access controller comprises: A source address register, adapted to store the source address information; a target address register, adapted to store target address information, the target address information pointing to the target security zone or a designated storage area within the target security zone for receiving the designated data; and The control module is adapted to select one of the plurality of channels provided by the storage access controller as a secure channel for transmitting designated data stored in the source security zone to the target security zone.
9. The processing device according to claim 8, characterized in that The storage access controller further comprises: The status register is adapted to provide a status value of each of the channels, wherein the status value is used to indicate whether the corresponding channel is in an available state, so that the control module selects the channel in an available state as the safety channel based on the status value.
10. An embedded system, comprising the processing device according to any one of claims 1 to 9.
11. A system on chip, comprising the processing device according to any one of claims 1 to 9.
12. A safety control method, characterized in that: include: A plurality of mutually isolated security zones are configured in a memory, wherein the plurality of security zones include: a source security zone, a target security zone, and a runtime security zone; the source security zone and the target security zone are respectively used to provide storage space required for the operation of corresponding programs; and the control program running in the runtime security zone is used to securely control the data transmission process; Configure secure channels; The control program uniquely configures the secure channel and transmits the designated data stored in the source secure zone to the target secure zone via the secure channel.
13. The safety control method according to claim 12, characterized in that: The runtime security zone is different from the source security zone and the target security zone, and the security control method further includes: The control program runs in the runtime safety zone.
14. The safety control method according to claim 13, characterized in that: The control program receives a transfer request from the source security zone, and configures the security channel based on the transfer request so that the security channel transfers designated data stored in the source security zone to the target security zone.
15. The safety control method according to claim 14, characterized in that: The transmission request includes source address information; and Before the control program configures the secure channel, the control program checks whether the source address information is within the source security zone that issues the transfer request, and if so, allows the specified data stored in the source security zone to be transferred to the target security zone.
16. The safety control method according to claim 14, characterized in that: Before the control program configures the secure channel, the control program checks whether the transmission function of the source security zone that issues the transmission request is disabled. If it is not disabled, the specified data stored in the source security zone is allowed to be transferred to the target security zone.
17. The safety control method according to claim 14, characterized in that: The transfer request includes information about the amount of data to be transferred, wherein, before transferring the specified data stored in the source security zone to the target security zone, the control program sends an allocation request to the target security zone, and the allocation request includes the data amount information, so that the target security zone can determine whether the size of the allocatable storage space in the target security zone is greater than / equal to the data amount information indicated by the allocation request, and if so, send a transfer confirmation response so that the secure channel can transfer the specified data stored in the source security zone to the target security zone.
18. The safety control method according to claim 17, characterized in that: The transmission confirmation response includes allocation address information, and the allocation address information points to a target storage area in the target security area that is allowed to receive the specified data. The control program configures the secure channel based on the allocated address information so that the secure channel transfers designated data stored in the source secure area to the target storage area in the target secure area.
19. The safety control method according to claim 15, characterized in that: The steps of configuring the secure channel include: Based on the source address information and the target address information, one of the multiple channels is selected as the secure channel so that the secure channel transfers the specified data stored in the source security zone to the target security zone pointed to by the target address information or to a specified storage area in the target security zone for receiving the specified data.
Citation Information
Patent Citations
Systems and Methods for Providing Levels of Access and Action Control Via an SSL VPN Appliance
US20070245409A1
Trusted packet processing for multi-domain separatization and security
US20180114012A1
Abstract enclave identity
US20180211035A1
Processing apparatus, embedded system, system-on-chip, and security control method
US20210334361A1