Methods and apparatuses for kernel and task isolation

By introducing trusted base and memory protection devices in the automotive electronic control system, memory isolation between tasks and kernel is achieved, the problem of insufficient security between kernel and tasks is solved, and the system's security and response speed is improved.

CN113868636BActive Publication Date: 2025-07-08YINWANG INTELLIGENT TECHNOLOGIES CO LTD

Patent Information

Application Number
CN202010611828.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-06-30
Publication Date
2025-07-08
Estimated Expiration
2040-06-30

AI Technical Summary

Technical Problem

In the prior art, the kernel and tasks cannot be effectively isolated in the automotive electronic control system, resulting in the security of the application and the kernel being unable to be guaranteed, especially when trusted applications and the kernel can access each other's memory.

Method used

An independent trusted base is introduced to switch memory access boundaries based on memory switching configuration information through memory protection devices such as MPU or MMU, ensuring memory isolation between tasks and cores and preventing mutual access.

Benefits of technology

It realizes security between tasks and kernel, improves system security and response speed, reduces the overhead of privilege switching, and enhances the real-time and security of on-board equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113868636B_ABST
    Figure CN113868636B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a method and apparatus for kernel and task isolation. By adding a separate trusted base to a computer system, the trusted base is independent of the kernel and tasks, and the trusted base, tasks, and kernel each have independent memory. The tasks and the kernel cannot access each other's memory. When task scheduling is required, the trusted base configures the memory protection device according to the memory switching configuration information stored in the memory of the trusted base. By configuring the memory protection device, the memory access boundary can be switched from the kernel's memory to the task's memory, or from the task's memory to the kernel's memory. The access to the memory of the task and the kernel is achieved through the switching of the memory boundary, thereby ensuring the security of the task and the kernel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a method and device for kernel and task isolation. Background Art

[0002] With the application and development of new technologies such as electronic technology, computer technology, and information technology, automotive electronic control has emerged. The automotive industry has successively proposed specifications such as open systems and the corresponding interfaces for automotive electronics / vehicle distributed executive (OSEK / VDX), automotive open system architecture (AUTOSAR), etc., which have established unified standard specifications for in-vehicle embedded real-time operating systems and related services to achieve an open development platform for automotive electronics, providing high modularity, portability, and reusability, simplifying the development process, and reducing development costs.

[0003] OSEK / VDX does not consider the security and reliability of automotive electronic applications. Based on OSEK / VDX, AUTOSAR has proposed a series of implementation specifications related to isolation protection to ensure the security and reliability of automotive electronic applications. Currently, automotive electronic control is mainly executed by an electronic control unit (ECU). With the improvement of ECU capabilities, for devices equipped with a memory protection unit (MPU), AUTOSAR has proposed a software partition isolation method that divides the storage area of the device into an operating system (OS) partition and an application partition. The kernel, storage software, peripherals, and input / output (I / O) and other basic software of the operating system are located in a trusted operating system partition in privilege mode. Application software is logically divided into trusted applications and ordinary applications. Ordinary applications are divided into an untrusted, non-privilege mode application partition; trusted applications, like the operating system kernel, are in the trusted, privilege mode operating system partition. Among them, data on the data segment between ordinary applications cannot be read or written, and the code cannot be executed. Privilege switching to access system services can only be performed through system calls.

[0004] However, in the above method, the trusted application and the kernel can access each other's memory. Whether the kernel can access the memory of the untrusted application cannot guarantee the security of the application and the kernel. Summary of the Invention

[0005] The embodiments of the present application provide a method and device for isolating the kernel and tasks, which can ensure the security between tasks and the kernel and improve the security of the system.

[0006] The first aspect of the present application provides a method for isolating the kernel and tasks. The method is applied to a computer system on which an OS and applications are running. A kernel is running on the OS, and the applications include one or more tasks. A trusted base is also running on the OS. The method includes:

[0007] The kernel searches for a first task from a task preparation queue; the trusted base searches for first memory switching configuration information of the first task from the memory and configures a memory protection device according to the first memory switching configuration information. The memory protection device is a hardware component for protecting the memory of the computer system. The first memory switching configuration information includes the memory address information and memory operation permissions of the kernel, as well as the memory address information and memory operation permissions of the first task. After configuration, the operation permission of the first task to the kernel's memory is no permission; after configuration, the operation permission of the kernel to the first task's memory is readable; the kernel calls the first task.

[0008] This first memory switching configuration information is used to switch the memory access boundary from the kernel's memory to the first task's memory.

[0009] Among them, the memory operation permissions of the kernel include: the operation permissions of the kernel to its own memory, the operation permissions of the kernel to the memory of tasks, and the operation permissions of the kernel to the memory of the trusted base. The memory operation permissions of the first task include: the operation permissions of the first task to its own memory, the operation permissions of the first task to the kernel's memory, and the operation permissions of the first task to the memory of the trusted base. The memory operation permissions of the trusted base include: the operation permissions of the trusted base to the kernel's memory, the operation permissions of the trusted base to the memory of tasks, and the operation permissions of the trusted base to its own memory.

[0010] The memory operation permissions of the kernel for itself include: the kernel has read, executable, and non-writable permissions for the kernel's code segment; the kernel has read, writable, and non-executable read-write permissions for the kernel's data segment; the kernel has read-only, non-writable, and non-executable permissions for the kernel's read-only segment. The kernel has no permissions for the first task, that is, the kernel has no permissions for the data segment, code segment, and read-only segment of the first task. The memory operation permissions of the kernel for the trusted base include: the kernel has no permissions for the data segment of the trusted base; the kernel has executable, non-readable, and non-writable permissions for the code segment of the trusted base; the kernel has readable, non-writable, and non-executable permissions for the read-only segment of the trusted base.

[0011] The memory operation permissions of the first task for itself include: the first task has read, executable, and non-writable permissions for the code segment of the first task; the first task has read, writable, and non-executable read-write permissions for the data segment of the first task; the first task has read-only, non-writable, and non-executable permissions for the read-only segment of the first task. The first task has no permissions for the kernel, that is, the first task has no permissions for the data segment, code segment, and read-only segment of the kernel. The memory operation permissions of the first task for the trusted base include: the first task has no permissions for the data segment of the trusted base; the first task has executable, non-readable, and non-writable permissions for the code segment of the trusted base; the first task has readable, non-writable, and non-executable permissions for the read-only segment of the trusted base.

[0012] The memory operation permissions of the trusted base for the first task include: the trusted base has read, executable, and non-writable permissions for the code segment of the first task; the trusted base has read, writable, and non-executable read-write permissions for the data segment of the first task; the trusted base has read-only, non-writable, and non-executable permissions for the read-only segment of the first task. The memory operation permissions of the trusted base for the kernel include: the trusted base has read, executable, and non-writable permissions for the code segment of the kernel; the trusted base has read, writable, and non-executable read-write permissions for the data segment of the kernel; the trusted base has read-only, non-writable, and non-executable permissions for the read-only segment of the kernel. The memory operation permissions of the trusted base for its own memory include: the trusted base has no permissions for the data segment of the trusted base; the trusted base has executable, non-readable, and non-writable permissions for the code segment of the trusted base; the trusted base has readable, non-writable, and non-executable permissions for the read-only segment of the trusted base.

[0013] From the memory operation permissions of the above kernel, the memory operation permissions of the first task, and the memory operation permissions of the trusted base, it can be seen that before the memory access boundary is switched, or in other words, before the memory protection device is configured, the first task and the kernel cannot access each other. That is, the first task cannot access the memory of the kernel, and the kernel cannot access the memory of the first task. Therefore, in the embodiments of the present application, when the first task needs to be called, the task boundary needs to be switched first. That is, according to the first memory switching configuration information, the memory access boundary is switched from the memory of the kernel to the memory of the first task.

[0014] Correspondingly, after the configuration, the first task has no permission to operate on the memory of the kernel, that is, the first task has no permission to access the data segment, code segment, and read-only segment of the kernel. Therefore, after the configuration is completed, the first task cannot access the memory of the kernel.

[0015] After the configuration, the kernel can access the memory of the first task. Correspondingly, after the configuration, the access permission of the kernel to the memory of the first task is readable. Among them, the operation permissions of the kernel to the memory of the first task specifically include: the kernel has the permissions of readable, writable, and non-executable for the data segment of the first task, the kernel has the permissions of readable, executable, and non-writable for the code segment of the first task, and the kernel has the permissions of readable, non-writable, and non-executable for the read-only segment of the first task.

[0016] Before and after the configuration, the access permissions of the task and the kernel to the memory of the trusted base have not changed. The operation permissions of the kernel or the first task to the memory of the trusted base include, for example: the kernel or the first task has no permission to access the data segment of the trusted base, the kernel or the first task has the permissions of executable, non-readable, and non-writable for the code segment of the trusted base, and the kernel or the first task has the permissions of readable, non-writable, and non-executable for the read-only segment of the trusted base.

[0017] Among them, the first memory switching configuration information is stored in the read-only segment of the trusted base. The first task or the kernel has the permissions of readable, non-writable, and non-executable for the read-only segment of the trusted base. The memory operation permissions of the trusted base enable only the trusted base to complete the configuration of the memory protection device, while the kernel cannot configure the memory protection device.

[0018] In the prior art, when the first task is a task of a general application, the kernel needs to perform a privilege switch, that is, a context switch from the kernel to the user. After the privilege switch, the kernel can access the memory of the application, but the application cannot access the memory of the kernel. When the first task is a task of a trusted application, both are in the privileged layer and can access each other's memory. It can be seen that the method of the prior art cannot guarantee the security between the kernel and the task. In the method of the embodiment of the present application, regardless of whether the first task is a task of a general application or a task of a trusted application, when the memory access boundary is located in the kernel's memory, if the first task is to be called, since the kernel and the first task do not have access rights to each other, the trusted base needs to configure the memory protection device according to the first memory switch configuration information of the first task. By configuring the memory protection device, the memory access boundary is switched. After the configuration is completed, the first task has no permission to access the kernel's memory, and the kernel has the read operation permission for the memory of the first task, that is, the first task cannot access the kernel's memory, but the kernel can access the memory of the first task, thus completing the switch of the memory access boundary from the kernel's memory to the memory of the first task, realizing the memory isolation between the kernel and the task, and ensuring the security between the kernel and the task.

[0019] Optionally, before the trusted base searches for the first memory switch configuration information of the first task in the memory, the trusted base closes the interrupt. After the trusted base configures the memory protection device according to the first memory switch configuration information, the trusted base opens the interrupt.

[0020] During the configuration process of the memory protection device, the trusted base first reads the first memory switch configuration information from the memory into the general register, and then reads the first memory switch configuration information in the general register into the register corresponding to the memory protection device. Among them, the first memory switch configuration information in the general register may be modified by an interrupt operation, and the modification of the memory switch configuration information in the general register may cause the data in the memory of the task and the kernel to be leaked, thus unable to guarantee the security of the task and the kernel during the system call process. In the embodiment of the present application, the trusted base can open the interrupt before configuring the memory protection device and then open the interrupt after the configuration is completed. After closing the interrupt, the interrupt will not modify the value in the general register, thus ensuring the security between the kernel and the task.

[0021] Not only will the interrupt operation modify the first memory switching configuration information in the general register, but JOP or ROP attacks will also tamper with the first memory switching configuration information in the general register. Therefore, in the embodiments of the present application, before the kernel calls the first task, the trusted base may further compare whether the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory. If the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory, it is determined that the first memory switching configuration information is legal. In the case where the first memory switching configuration information is legal, the trusted base calls the first task, thereby being able to prevent JOP or ROP attacks and ensure the security between the kernel and the task.

[0022] Alternatively, before the trusted base enables the interrupt, it compares whether the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory. If the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory, the trusted base determines that the first memory switching configuration information is legal. In the case where the first memory switching configuration information is legal, the trusted base enables the interrupt. This method can not only prevent the interrupt from modifying the first memory switching configuration information in the general register, but also avoid JOP or ROP from modifying the first memory switching configuration information in the general register.

[0023] Optionally, if the first memory switching configuration information stored in the register is not the same as the first memory switching configuration information stored in the memory, the trusted base determines that the first memory switching configuration information is illegal. In the case where the first memory switching configuration information is illegal, the kernel shuts down the OS and / or terminates the first task.

[0024] Optionally, both the OS and the application are in the privileged layer. When all applications are in the privileged layer, no privilege switching is required when a normal application makes a system call, reducing the overhead of privilege switching and thus improving the response speed of the application.

[0025] Optionally, after enabling the interrupt, the method further includes:

[0026] When an interrupt request is received, the trusted base queries the interrupt vector table, which includes a normal interrupt service function and an interrupt service function of the trusted base;

[0027] The trusted base enters the interrupt service function of the trusted base according to the interrupt vector table;

[0028] The trusted base obtains the return address of the interrupt and determines whether the return address of the interrupt belongs to a preset address range;

[0029] When the return address of the interrupt belongs to the preset address range, the trusted base determines that the interrupt is an illegal interrupt and takes resilience protection;

[0030] When the return address of the interrupt does not belong to the preset address range, the trusted base determines that the current interrupt is a legal interrupt and calls the normal interrupt service function.

[0031] By setting the interrupt service function of the trusted base, when an interrupt request is received, it is determined whether the interrupt is a legal interrupt, which can avoid illegal interrupt attacks and further improve the security of the kernel and tasks.

[0032] Optionally, it further includes: the trusted base initializes the interrupt vector table, and the interrupt vector table is stored in the read-only segment of the trusted base. During the system startup process, the trusted base initializes the interrupt vector table.

[0033] Optionally, during the startup process of the computer system, the trusted base performs I / O privilege scanning on the code segments of the OS and the tasks. According to the scanning results, specific operations in non-privileged tasks, partially privileged tasks, and privileged tasks are replaced with exception instructions, and then the OS is started. By replacing specific operations in non-privileged tasks, partially privileged tasks, and privileged tasks with exception instructions, access to these specific operations by the kernel is avoided.

[0034] Optionally, the specific operations of the non-privileged tasks include: IRQ register operation instructions, I / O status register query instructions, serial port register operations, timer register operations, system register operations, and memory protection device register operations; the specific operations of the partially privileged tasks include: system register operations and memory protection device register operations; the specific operations of the privileged tasks include memory protection device register operations.

[0035] Optionally, the memory protection device is a memory protection unit MPU, the memory address information includes the memory start address and the address length, and the memory start address is a physical address.

[0036] Optionally, the memory protection device is a memory management unit MMU, and the memory address information includes the memory start address, the address length, and the mapping table between the virtual address and the physical address.

[0037] The second aspect of the present application provides a method for kernel and task isolation. The method is applied to a computer system on which an operating system OS and an application are running. The kernel is running on the OS, and the application includes one or more tasks. A trusted base is also running on the OS. The method includes:

[0038] When a second task needs to call the system service application programming interface API, the trusted base saves the task number of the second task;

[0039] The trusted base searches for second memory switching configuration information corresponding to the second task in the memory, and configures the memory protection device according to the second memory switching configuration information. The memory protection device is a hardware component for protecting the memory of the computer system. The second memory switching configuration information includes the memory address information of the kernel and the memory operation permissions of the kernel, as well as the memory address information of the second task and the memory operation permissions of the second task. After configuration, the operation permission of the kernel for the memory of the second task is no permission, and after configuration, the operation permission of the second task for the memory of the kernel is readable;

[0040] The kernel calls the second task;

[0041] The kernel calls the system service;

[0042] After the system service is completed, the trusted base retrieves the task number of the second task and switches the memory access boundary from the memory of the kernel to the memory of the second task;

[0043] The kernel calls the second task to obtain the return result of the system service.

[0044] When the second task needs to call the system service, two memory boundary switches are required. Before the system call, the memory access boundary is located in the memory of the second task. Therefore, it is necessary to first switch the memory access boundary from the memory of the second task to the memory of the kernel according to the second memory switching configuration information. After switching the memory access boundary to the memory of the kernel, the system call can be made. After the system call is completed, it is necessary to switch the memory access boundary from the memory of the kernel to the memory of the second task. At this time, the memory access boundary is switched according to the third memory switching configuration information and switched back to the memory of the second task. The method realizes the system call through two memory boundary switches during the system call process, which can ensure the memory isolation between the second task and the kernel.

[0045] The second memory switching configuration information is used to switch the memory access boundary from the memory of the second task to the memory of the kernel. After configuration, the kernel has no permission to operate on the memory of the second task, that is, the kernel has no permission to access the data segment, code segment, and read-only segment of the second task, and the kernel cannot access the memory of the second task.

[0046] After configuration, the second task has read permission to the memory of the kernel, that is, after configuration, the second task can access the memory of the kernel. The operation permissions of the second task to the memory of the kernel can include: the second task has read, write, and non-executable permissions to the data segment of the kernel; the second task has read, executable, and non-write permissions to the code segment of the kernel; the second task has read, non-write, and non-executable permissions to the read-only segment of the kernel.

[0047] Optionally, before and after configuration, the operation permissions of the kernel and the second task to the memory of the trusted base do not change. The operation permissions of the kernel or the second task to the memory of the trusted base include, for example: the kernel or the second task has no permission to the data segment of the trusted base; the kernel or the second task has executable, non-readable, and non-write permissions to the code segment of the trusted base; the kernel or the second task has read, non-write, and non-executable permissions to the read-only segment of the trusted base. The second memory switching configuration information is stored in the read-only segment of the trusted base.

[0048] Optionally, before the trusted base searches for the second memory switching configuration information corresponding to the second task in the memory, the trusted base closes the interrupt; after the trusted base configures the memory protection device according to the second memory switching configuration information, the trusted base opens the interrupt.

[0049] When the second memory switching configuration information in the general register is modified, it may cause the data in the memories of the task and the kernel to be leaked, thus unable to ensure the security of the task and the kernel during system calls. In the embodiments of the present application, the trusted base can open the interrupt before configuring the memory protection device and then open the interrupt after the configuration is completed. After closing the interrupt, the interrupt will not modify the value in the general register, thereby ensuring the security between the kernel and the task.

[0050] Optionally, before the kernel calls the second task, the trusted base compares whether the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory; if the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory, the trusted base determines that the second memory switching configuration information is legal; in the case where the second memory switching configuration information is legal, the trusted base calls the second task.

[0051] Alternatively, before the trusted base opens the interrupt, the trusted base compares whether the second memory switching configuration information stored in the register and the second memory switching configuration information stored in the memory are the same; if the second memory switching configuration information stored in the register and the second memory switching configuration information stored in the memory are the same, the trusted base determines that the second memory switching configuration information is legal; in the case where the second memory switching configuration information is legal, the trusted base opens the interrupt.

[0052] Not only will the interrupt operation modify the second memory switching configuration information in the general register, but JOP or ROP attacks will also tamper with the second memory switching configuration information in the general register. In the embodiments of the present application, by verifying the legality of the second memory switching configuration information, JOP or ROP attacks can be prevented, and the security between the kernel and the task can be guaranteed.

[0053] Optionally, if the second memory switching configuration information stored in the register and the second memory switching configuration information stored in the memory are different, the trusted base determines that the second memory switching configuration information is illegal; in the case where the second memory switching configuration information is illegal, the kernel closes the OS and / or terminates the second task.

[0054] Optionally, the switching of the memory access boundary from the memory of the kernel to the memory of the second task includes:

[0055] The trusted base searches for the third memory switching configuration information of the second task in the memory, and configures the memory protection device according to the third memory switching configuration information. The third memory switching configuration information includes: the memory address information of the kernel and the memory operation permission of the kernel, as well as the memory address information of the second task and the memory operation permission of the second task. After configuration, the second task has no permission to operate on the memory of the kernel, and after configuration, the kernel has the permission to read the memory of the second task.

[0056] This third memory switching configuration information is used to switch the memory access boundary from the memory of the kernel to the memory of the second task. After configuration, the second task has no permission to operate on the memory of the kernel, that is, the second task has no permission to access the data segment, code segment, and read-only segment of the kernel. Therefore, after the configuration is completed, the second task cannot access the memory of the kernel.

[0057] After configuration, the kernel has read permission for the memory of the second task, that is, the configured kernel can access the memory of the second task. For example, the kernel's permission for the memory of the second task to be readable may include: the kernel has read, write, and non-executable permissions for the data segment of the second task; the kernel has read, executable, and non-writable permissions for the code segment of the second task; the kernel has read, non-writable, and non-executable permissions for the read-only segment of the second task.

[0058] Before and after configuration, the access permissions of the second task and the kernel to the memory of the trusted base do not change. For example, the operating permissions of the kernel or the second task for the memory of the trusted base include: the kernel or the second task has no permission for the data segment of the trusted base; the kernel or the second task has executable, non-readable, and non-writable permissions for the code segment of the trusted base; the kernel or the second task has read, non-writable, and non-executable permissions for the read-only segment of the trusted base.

[0059] Optionally, before the trusted base searches for the third memory switching configuration information of the second task in the memory, the trusted base turns off the interrupt. After the trusted base configures the memory protection device according to the third memory switching configuration information, the trusted base turns on the interrupt.

[0060] Optionally, before the kernel calls the second task to obtain the return result of the system service, the trusted base compares whether the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory; if the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory, the trusted base determines that the third memory switching configuration information is legal; in the case where the third memory switching configuration information is legal, the kernel calls the second task to obtain the return result of the system service.

[0061] Alternatively, before the trusted base turns on the interrupt, it compares whether the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory; if the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory, the trusted base determines that the third memory switching configuration information is legal; in the case where the third memory switching configuration information is legal, the trusted base turns on the interrupt.

[0062] Optionally, it further includes:

[0063] If the third memory switching configuration information stored in the register is not the same as the third memory switching configuration information stored in the memory, the trusted base determines that the third memory switching configuration information is illegal;

[0064] In the case where the third memory switching configuration information is illegal, the kernel shuts down the OS and / or terminates the second task.

[0065] Optionally, the OS and all applications on the computer system are in the privileged layer.

[0066] Optionally, after the interrupt is enabled, the method further includes:

[0067] When an interrupt request is received, the trusted base queries the interrupt vector table, which includes a normal interrupt service function and an interrupt service function of the trusted base;

[0068] The trusted base enters the interrupt service function of the trusted base according to the interrupt vector table;

[0069] The trusted base obtains the return address of the interrupt and determines whether the return address of the interrupt belongs to a preset address range;

[0070] When the return address of the interrupt belongs to the preset address range, the trusted base determines that the interrupt is an illegal interrupt and takes resilience protection;

[0071] When the return address of the interrupt does not belong to the preset address range, the trusted base determines that the interrupt is a legal interrupt and calls the normal interrupt service function.

[0072] Optionally, it further includes: the trusted base initializes the interrupt vector table, and the interrupt vector table is stored in the read-only segment of the trusted base.

[0073] Optionally, during the startup process of the computer system, the trusted base performs an I / O privilege scan on the OS code segment and the code segments of tasks, and according to the scan results, replaces specific operations of non-privileged tasks, partially privileged tasks, and privileged tasks with exception instructions, and then starts the OS.

[0074] Optionally, the specific operations of the non-privileged tasks include: IRQ register operation instructions, I / O status register query instructions, serial port register operations, timer register operations, system register operations, and memory protection device register operations;

[0075] The specific operations of the partially privileged tasks include: system register operations and memory protection device register operations;

[0076] The specific operation of the privileged task includes memory protection device register operation.

[0077] A third aspect of the present application provides a computer system, on which an operating system OS and applications are running, a kernel is running on the OS, the applications include one or more tasks, and a trusted base is also running on the OS;

[0078] The kernel is used to find a first task from a task preparation queue;

[0079] The trusted base is used to find first memory switching configuration information of the first task from memory, and configure a memory protection device according to the first memory switching configuration information. The memory protection device is a hardware component for protecting the memory of the computer system; the first memory switching configuration information includes the memory address information and memory operation permissions of the kernel, as well as the memory address information and memory operation permissions of the first task. After configuration, the first task has no permission to operate on the memory of the kernel; after configuration, the kernel has read permission to the memory of the first task.

[0080] The kernel also calls the first task.

[0081] Optionally, the trusted base is further used to: close the interrupt before finding the first memory switching configuration information of the first task from memory, and open the interrupt after completing the configuration of the memory protection device according to the first memory switching configuration information.

[0082] Optionally, the trusted base is further used to: compare whether the first memory switching configuration information stored in a register is the same as the first memory switching configuration information stored in the memory; if the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory, it is determined that the first memory switching configuration information is legal. The kernel is further used to: call the first task when the first memory switching configuration information is legal.

[0083] Optionally, the trusted base is further used to: if the first memory switching configuration information stored in the register is different from the first memory switching configuration information stored in the memory, it is determined that the first memory switching configuration information is illegal; the kernel is further used to: close the OS and / or terminate the first task when the first memory switching configuration information is illegal.

[0084] Optionally, the OS and all applications on the computer system are in the privileged layer.

[0085] Optionally, after the trusted base opens the interrupt, the trusted base is further configured to: when receiving an interrupt request, query an interrupt vector table, where the interrupt vector table includes a normal interrupt service function and an interrupt service function of the trusted base; enter the interrupt service function of the trusted base according to the interrupt vector table; obtain a return address of the interrupt, and determine whether the return address of the interrupt belongs to a preset address range; when the return address of the interrupt belongs to the preset address range, determine that the current interrupt is an illegal interrupt and take resilience protection; when the return address of the interrupt does not belong to the preset address range, determine that the current interrupt is a legal interrupt and call the normal interrupt service function.

[0086] Optionally, the trusted base is further configured to: initialize the interrupt vector table by the trusted base, and the interrupt vector table is stored in the read-only segment of the trusted base.

[0087] Optionally, the trusted base is further configured to: during the startup process of the computer system, perform input / output (I / O) privilege scanning on the code segment of the kernel and the code segments of tasks; according to the scanning results, replace specific operations in non-privileged tasks, partially privileged tasks, and privileged tasks with exception instructions; start the OS.

[0088] Optionally, the specific operations of the non-privileged tasks include: IRQ register operation instructions, I / O status register query instructions, serial port register operations, timer register operations, system register operations, and memory protection device register operations; the specific operations of the partially privileged tasks include: system register operations and memory protection device register operations; the specific operations of the privileged tasks include memory protection device register operations.

[0089] A fourth aspect of the present application provides a computer system, on which an operating system (OS) and an application are running, a kernel is running on the OS, the application includes one or more tasks, and a trusted base is also running on the OS;

[0090] The trusted base is configured to save the task number of a second task when the second task needs to call a system service application programming interface (API).

[0091] The trusted base is further configured to find second memory switching configuration information of the second task from the memory, and configure a memory protection device according to the second memory switching configuration information. The memory protection device is a hardware component for protecting the memory of the computer system. The second memory switching configuration information includes the memory address information and memory operation permissions of the kernel, as well as the memory address information and memory operation permissions of the second task. After configuration, the kernel has no permission to operate on the memory of the second task, and after configuration, the second task has read permission to the memory of the kernel.

[0092] The kernel is configured to call the second task and the system service.

[0093] The trusted base is further configured to, after the system service is completed, obtain the task number of the second task, and switch the memory access boundary from the memory of the kernel to the memory of the second task.

[0094] The kernel is further configured to call the second task to obtain the return result of the system service.

[0095] Optionally, the trusted base is further configured to: close the interrupt before finding the second memory switching configuration information corresponding to the second task from the memory; and open the interrupt after the configuration of the memory protection device according to the second memory switching configuration information is completed.

[0096] Optionally, the trusted base is further configured to: compare whether the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory; if the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory, determine that the second memory switching configuration information is legal; the kernel is further configured to: call the second task when the second memory switching configuration information is legal.

[0097] Optionally, the trusted base is further configured to: if the second memory switching configuration information stored in the register is different from the second memory switching configuration information stored in the memory, determine that the second memory switching configuration information is illegal; the kernel is further configured to: close the OS and / or terminate the second task when the second memory switching configuration information is illegal.

[0098] Optionally, the trusted base switches the memory access boundary from the memory of the kernel to the memory of the second task, including: looking up the third memory switching configuration information of the second task in the memory, and configuring the memory protection device according to the third memory switching configuration information. The third memory switching configuration information includes: the memory address information of the kernel and the memory operation permissions of the kernel, as well as the memory address information of the second task and the memory operation permissions of the second task. After configuration, the second task has no permission to operate on the memory of the kernel, and after configuration, the kernel has the permission to read the memory of the second task.

[0099] Optionally, the trusted base is further configured to: close the interrupt before looking up the third memory switching configuration information of the second task in the memory, and open the interrupt after completing the configuration of the memory protection device according to the third memory switching configuration information.

[0100] Optionally, the trusted base is further configured to: compare whether the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory; if the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory, determine that the third memory switching configuration information is legal; the kernel is further configured to: when the third memory switching configuration information is legal, call the second task to obtain the return result of the system service.

[0101] Optionally, the trusted base is further configured to: if the third memory switching configuration information stored in the register is different from the third memory switching configuration information stored in the memory, determine that the third memory switching configuration information is illegal; the kernel is further configured to: when the third memory switching configuration information is illegal, close the OS and / or terminate the second task.

[0102] Optionally, the OS and all applications on the computer system are in the privileged layer.

[0103] Optionally, after opening the interrupt, the trusted base is further configured to:

[0104] When receiving an interrupt request, query the interrupt vector table, where the interrupt vector table includes a normal interrupt service function and an interrupt service function of the trusted base;

[0105] Enter the interrupt service function of the trusted base according to the interrupt vector table;

[0106] Obtain the return address of the interrupt, and determine whether the return address of the interrupt belongs to a preset address range;

[0107] When the return address of the interrupt belongs to the preset address range, determine that the interrupt is an illegal interrupt and take resilience protection;

[0108] When the return address of the interrupt does not belong to the preset address range, determine that the interrupt is a legal interrupt and call the normal interrupt service function.

[0109] Optionally, the trusted base is further configured to: initialize the interrupt vector table, and the interrupt vector table is stored in the read-only segment of the trusted base.

[0110] Optionally, the trusted base is further configured to: during the startup process of the computer system, perform I / O privilege scanning on the OS code segment and the code segments of tasks, and according to the scanning results, replace specific operations of non-privileged tasks, partially privileged tasks, and privileged tasks with exception instructions;

[0111] Start the OS.

[0112] Optionally, the specific operations of the non-privileged tasks include: IRQ register operation instructions, I / O status register query instructions, serial port register operations, timer register operations, system register operations, and memory protection device register operations;

[0113] The specific operations of the partially privileged tasks include: system register operations and memory protection device register operations;

[0114] The specific operation of the privileged task includes memory protection device register operation.

[0115] A fifth aspect of the present application provides a computer system, including: a processor, a memory, and a memory protection device. The memory includes an internal memory. An operating system OS and an application are running on the processor. A kernel is running on the OS. The application includes one or more tasks. A trusted base is also running on the OS. The memory is used to store instructions, and the processor is used to execute the instructions stored in the memory so that the processor executes the method according to the first aspect or any optional implementation manner of the first aspect of the present application.

[0116] A sixth aspect of the present application provides a computer system, including: a processor, a memory, and a memory protection device. The memory includes an internal memory. An operating system OS and an application are running on the processor. A kernel is running on the OS. The application includes one or more tasks. A trusted base is also running on the OS. The memory is used to store instructions, and the processor is used to execute the instructions stored in the memory so that the processor executes the method according to the second aspect or any optional implementation manner of the second aspect of the present application.

[0117] For the technical effects corresponding to each computer system, refer to the technical effects corresponding to the methods provided in the first aspect and the second aspect, which will not be elaborated here.

[0118] The embodiments of the present application provide a method and device for kernel and task isolation. By adding a separate trusted base on a computer system, the trusted base is independent of the kernel and tasks. The trusted base, tasks, and the kernel each have independent memory, and tasks and the kernel cannot access each other's memory. When task scheduling is required, the trusted base configures the memory protection device according to the memory switching configuration information stored in the memory of the trusted base. By configuring the memory protection device, the memory access boundary can be switched from the kernel's memory to the task's memory, or from the task's memory to the kernel's memory. Through the switching of the memory boundary, the access to the memory of both the task and the kernel is realized, thus ensuring the security of the task and the kernel. BRIEF DESCRIPTION OF THE DRAWINGS

[0119] Figure 1 It is a schematic diagram of the architecture of a computer system applicable to the embodiments of the present application;

[0120] Figure 2 It is a schematic diagram of the architecture of software partitioning in the existing AUTOSAR OS;

[0121] Figure 3 It is a schematic diagram of the architecture of a new software partitioning applicable to the present application;

[0122] Figure 4 It is a schematic diagram of a functional module of the trusted base;

[0123] Figure 5 It is a flowchart of the method for kernel and task isolation provided in Embodiment 1 of the present application;

[0124] Figure 6 It is a schematic diagram of a memory boundary access table provided by the present application;

[0125] Figure 7 It is a flowchart of the method for kernel and task isolation provided in Embodiment 2 of the present application;

[0126] Figure 8 It is a flowchart of the method for kernel and task isolation provided in Embodiment 3 of the present application;

[0127] Figure 9 It is a flowchart of the method for kernel and task isolation provided in Embodiment 4 of the present application;

[0128] Figure 10 It is a flowchart of the method for kernel and task isolation provided in Embodiment 5 of the present application;

[0129] Figure 11Flowchart of the method for kernel and task isolation provided in Embodiment 6 of this application;

[0130] Figure 12 Schematic diagram of the hardware and software architecture of the vehicle-mounted device applicable to this embodiment;

[0131] Figure 13 Schematic diagram of the process for the airbag system to feedback collision detection;

[0132] Figure 14 Schematic diagram of the structure of the computer system provided in Embodiment 8 of this application;

[0133] Figure 15 Schematic diagram of the structure of the computer system provided in Embodiment 9 of this application;

[0134] Figure 16 Schematic diagram of the structure of the computer system provided in Embodiment 10 of this application. Detailed implementation manners

[0135] Embodiments of this application provide a method for kernel and task isolation, which can be applied to a computer system adopting the automotive open system architecture (AUTOSAR) standard. This computer system can be deployed on a vehicle, or can be deployed far away from the vehicle and communicate with the vehicle wirelessly, for example, deployed on a server communicatively connected to the vehicle. The computer system deployed on the vehicle can be called a vehicle-mounted device. The vehicle can specifically be a car, a truck, a motorcycle, a bus, a ship, an airplane, a helicopter, a lawn mower, a recreational vehicle, a playground vehicle, a construction device, a tram, a golf cart, a train, and a trolley, etc., and the embodiments of the present invention do not make special limitations.

[0136] Figure 1 Schematic diagram of the architecture of a computer system applicable to the embodiments of this application, as Figure 1As shown, computer system 100 includes a processor 101, which is coupled to a system bus 102. The processor 101 can be one or more processors, and each processor can include one or more processor cores. A video adapter 103, which can drive a display 104, and the display 104 is coupled to the system bus 102. The system bus 102 is coupled to an input / output (I / O) bus through a bus bridge 105. An I / O interface 106 is coupled to the I / O bus. The I / O interface 106 communicates with a variety of I / O devices, such as an input device 107 (e.g., keyboard, mouse, touch screen, etc.), a media tray 108 (e.g., CD-ROM, multimedia interface, etc.), a transceiver 109 (which can send and / or receive radio communication signals), a camera 110 (which can capture still and dynamic digital video images), and an external USB interface 111. Optionally, the interface connected to the I / O interface 106 can be a USB interface.

[0137] Among them, the processor 101 can be any conventional processor, including a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, or a combination of the above. Optionally, the processor can be a dedicated device such as an application-specific integrated circuit (ASIC). Optionally, the processor 101 can be a neural network processor or a combination of a neural network processor and the above conventional processors.

[0138] Optionally, in various embodiments described in this application, the computer system 100 can be located away from the autonomous vehicle and can communicate wirelessly with the autonomous vehicle. In other aspects, some of the processes described in this application are executed on a processor disposed within the autonomous vehicle, and others are executed by a remote processor, including taking actions required to perform a single maneuver.

[0139] The computer system 100 can communicate with a software deployment server 113 through a network interface 112. The network interface 112 is a hardware network interface, such as a network card. The network 114 can be an external network, such as the Internet, or an internal network, such as an Ethernet or a virtual private network (VPN). Optionally, the network 114 can also be a wireless network, such as a WiFi network, a cellular network, etc.

[0140] The hard disk drive interface 115 is coupled to the system bus 102. The hard disk drive interface 115 is connected to the hard disk drive 116. The system memory 117 is coupled to the system bus 102. The data running in the system memory 117 may include the operating system 118 and application programs 119 of the computer system 100.

[0141] The operating system 118 includes a shell 120 and a kernel 121. The shell 120 is an interface between the user and the kernel of the operating system. The shell is the outermost layer of the operating system. The shell manages the interaction between the user and the operating system: waits for the user's input, interprets the user's input to the operating system, and processes various output results of the operating system.

[0142] The kernel 121 consists of those parts in the operating system that are used to manage memory, files, peripherals, and system resources. Interacting directly with the hardware, the operating system kernel usually runs processes and provides inter-process communication, provides CPU time slice management, interrupts, memory management, IO management, etc.

[0143] The application program 122 includes programs 123 related to controlling the automatic driving of a vehicle, such as programs for managing the interaction between the self-driving vehicle and road obstacles, programs for controlling the route or speed of the self-driving vehicle, and programs for controlling the interaction between the self-driving vehicle and other self-driving vehicles on the road. The application program 122 also exists on the system of the software deployment server 113. In one embodiment, when the application program 122 needs to be executed, the computer system 100 can download the application program 122 from the software deployment server 113.

[0144] The sensor 124 is associated with the computer system 100. The sensor 124 is used to detect the environment around the computer system 100. For example, the sensor 124 can detect animals, vehicles, obstacles, and crosswalks, etc. Further, the sensor can also detect the environment around the above-mentioned animals, vehicles, obstacles, and crosswalks, such as: the environment around an animal, for example, other animals appearing around the animal, weather conditions, the brightness of the surrounding environment, etc. Optionally, if the computer system 100 is located in a self-driving vehicle, the sensor can be a camera, an infrared sensor, a chemical detector, a microphone, etc.

[0145] In the prior art, for in-vehicle devices with MPU capabilities, AUTOSAR OS proposed a software partition isolation method. Figure 2 For the schematic diagram of the software partition architecture in the existing AUTOSAR OS, as Figure 2As shown, the kernel of the OS and trusted applications are in privileged mode (or called privileged layer), and ordinary applications (or called non-trusted applications) are in non-privileged mode (also called non-privileged layer or User Mode). In addition, basic software such as storage software, peripherals, and I / O is also in privileged mode. Figure 2 is not shown in

[0146] In the ARM system, the working modes of the processor include the following seven: User Mode, System Mode, General Interrupt Mode, Fast Interrupt Mode, Supervisor Mode, Abort Mode, and Undefined Instruction Mode. All modes except User Mode are privileged modes.

[0147] The mode of the processor can be understood as the current working state of the processor. For example, if the current operating system is executing a user program, then the current working mode of the CPU is User Mode. At this time, if there is data arriving on the network card and an interrupt signal is generated, the processor automatically switches to General Interrupt Mode to process the network card data. After processing the network card data, it returns to User Mode to continue executing the user program.

[0148] User Mode is the working mode of user programs. It runs in the user state of the operating system. It has no permission to operate other hardware resources. It can only process its own data and cannot switch to other modes. To access hardware resources or switch to other modes, it can only do so through software interrupts or exceptions.

[0149] Privileged modes can freely switch the working mode of the processor. ARM internal registers and some on-chip and off-chip peripherals are designed to only allow (or optionally only allow) access in privileged modes.

[0150] such as Figure 2As shown in the figure, the kernel data includes data (also called data segment) and code (also called code segment), and the application (including ordinary applications and trusted applications) data includes data, code and one or more tasks, and the data of each task includes data and stack. Applications will occupy a certain amount of memory. The data segment usually refers to a memory area used to store initialized global variables in the program; the code segment usually refers to a memory area used to store program execution code. The stack segment usually refers to a memory area that works in a stack manner. When a program is executed, the program may add its execution status to the top of the stack; when the program ends, it must pop the status data at the top of the stack. The heap is used to store the memory segment that is dynamically allocated during the process. Its size is not fixed and can be dynamically expanded or reduced. Stack: The stack is also called a stack, which is a local variable temporarily created by the user for the program. In addition, when a function is called, its parameters will also be pushed into the stack that initiated the call, and after the call ends, the return value of the function will also be stored back in the stack. Due to the first-in, last-out feature of the stack, the stack is particularly convenient for saving / restoring calls. In this sense, the stack can be regarded as a memory area for storing and exchanging temporary data. Among them, the stack segment can also belong to the data segment.

[0151] In the prior art, ordinary applications cannot read or write data in each other's data segments, and cannot execute programs in each other's data segments. Ordinary applications can only access system services after switching privileges through system calls. However, since trusted applications and the kernel are both in the privileged layer, trusted applications can directly access the kernel's data and services. Therefore, trusted applications and the kernel form the AUTOSAR Trusted Computing Base (TCB).

[0152] MPU is a hardware resource commonly used for memory protection in embedded systems. Embedded systems use multi-task operations and control. The system must provide a mechanism to ensure that the running task does not destroy the operation of other tasks, that is, to prevent system resources and other tasks from being illegally accessed.

[0153] The MPU uses regions or protected regions to manage the address space of the memory. A region is an attribute associated with the address space of the memory. The number of regions in the MPU is usually 8, numbered from 0 to 7. The size and starting address of the region can be stored in register c6 of the coprocessor CP15. The size of the region can be any power of 2 from 4KB to 4GB, and the starting address of the region must be a multiple of its size.

[0154] The operating system can configure access permissions for the domains of the MPU. The operating system can set the access permissions of a domain to read, read-only, or inaccessible, etc., based on the current working mode of the processor.

[0155] When the processor accesses a domain of memory, the MPU compares the access permission attributes of the domain with the current working mode of the processor. If the access request of the processor conforms to the access permission of the domain, the MPU allows the kernel to read and write the memory; if the access request of the processor does not conform to the access permission of the domain, an exception signal is generated.

[0156] In an embedded system, the memory management unit (MMU) can provide a more powerful memory protection mechanism than the MPU. The MPU usually only provides memory protection, while the MMU can also provide functions such as mapping from virtual addresses to physical addresses, in addition to providing memory protection.

[0157] Most machines using the MMU adopt a paging mechanism. The operating system can set the access permission for each page table in the page table. Some page tables are not accessible, some page tables can only be accessed in privileged mode, and some page tables can be accessed in both user mode and privileged mode. At the same time, the access permissions are divided into three types: readable, writable, and executable. After such settings, when the processor wants to access a virtual address (VA), the MMU will check whether the processor is currently in user mode or privileged mode, and the purpose of accessing the memory is to read data, write data, or fetch an instruction for execution: if it conforms to the permissions set by the operating system, access is allowed, and the VA is converted into a physical address (PA); otherwise, execution is not allowed, and an exception is generated.

[0158] The processing mechanisms of exceptions and interrupts are similar. The difference is that interrupts are generated by external devices (such as hardware errors, input errors), while exceptions are generated inside the processor. The generation of interrupts has nothing to do with the instruction currently being executed by the processor, while exceptions are caused by problems with the instruction currently being executed.

[0159] Under normal circumstances, the processor executes user programs in user mode (such as Figure 1For untrusted applications, when an interruption or exception occurs, the processor switches to the privileged mode to execute the kernel program, and after processing the interruption or exception, it returns to the user mode to continue executing the user program. Usually, the operating system divides the virtual address space into a user space and a kernel space. For example, the virtual address space range of the Linux system on the x86 platform is 0x0000 0000 to 0xffff ffff. The first 3G of the space is the user space, and the last 1G of the space is the kernel space. The user program is loaded into the user space, and the kernel program is loaded into the kernel space. The user program cannot access the data in the kernel, nor can it jump to the kernel space to execute. This can protect the kernel. If a process accesses an illegal address, the process may crash, but it will not affect the stability of the kernel and the system. When an interruption or exception occurs in the system, not only will it jump to execute in the interruption service function or exception service function, but it will also switch from the user mode to the privileged mode and jump from the interruption service program or exception service program to execute in the kernel code.

[0160] Trusted Computing Base: Also known as the trusted base, it is a collection of all security protection mechanisms for implementing computer system security protection. These security protection mechanisms can appear in the form of hardware, firmware, and software. Once a component of the trusted computer base has a program error or security risk, it will pose a hazard to the security of the entire system. On the contrary, if other parts outside the trusted computing base have problems, it only leaks the relevant permissions granted to them by the system security policy. These permissions are generally relatively low, so reducing the trusted computing base is crucial for the overall security of the system.

[0161] System call: The main functions of the operating system are to manage hardware resources and provide a good environment for application developers to make applications more compatible. To achieve this goal, the kernel provides a series of multi-kernel functions with predefined functions and presents them to users through a set of interfaces called system calls. The system call passes the application's request to the kernel, calls the corresponding kernel function to complete the required processing, and returns the processing result to the application.

[0162] Figure 2 In the architecture shown, ordinary applications run in the non-privileged layer. When ordinary applications handle operations such as task scheduling, system service requests, and I / O access, they need to perform privilege switching, switching from the non-privileged mode to the privileged mode, and the privilege switching takes a relatively long time. Exemplarily, when an ordinary application requests a service that requires higher privileges to run from the kernel, such as access to privileged I / O (priviledge I / O), inter-process communication, etc., the ordinary application cannot directly access the system service and needs to perform privilege switching through a system call.

[0163] The instructions of the processor are divided into ordinary instructions and privileged instructions. Only the kernel can execute privileged instructions, and only ordinary instructions can be executed in user mode. The I / O access of the computer system includes privileged I / O access and normal I / O access. Among them, privileged I / O refers to I / O that only the kernel can access, and normal I / O can only be accessed by applications. When a task in an application needs to access privileged I / O, it needs to access privileged I / O through system calls.

[0164] Specifically, when a user task in a common application initiates a system service request to the system call handler (syscallhandler), the following behaviors will occur: the processor will generate a synchronous exception (Trap), refresh the pipeline, save the CPU register of the user task, read the exception vector table, and switch the MPU protection domain. Each system call needs to go through a context switch from the user task to the kernel. Next, the syscall handler will call the application programming interface (API) of the system service. After completing the user task, it also needs to go through a context switch from the kernel to the user task. The above context switch from the user task to the kernel or from the kernel to the user task is a privilege switch.

[0165] During a system call, two context switches (or two privilege switches) are required, and the clock overhead of each context switch is about 300 instruction cycles. Although memory allocation, I / O access, and mutually exclusive resources are common operations in tasks, since resources or I / O belong to the privileged layer, they must be accessed through system calls. Memory allocation and I / O access occur frequently in the system, resulting in excessive privilege switching overhead for ordinary applications. Excessive privilege switching overhead will lead to untimely response of applications, which may lead to error transmission or task scheduling exceptions.

[0166] Among vehicle-mounted equipment, autonomous emergency braking (AEB) is an active safety technology that detects the road ahead through radar, cameras and other equipment, and takes emergency braking when the distance is less than the safe distance. Therefore, AEB has extremely high requirements for real-time performance and system response.

[0167] in addition, Figure 1 In the partition architecture shown, trusted applications and the kernel form a trusted base. When the number of trusted applications is too large, the trusted base will be too large and pose a security risk. Once a trusted task or kernel vulnerability is exploited, user data and kernel data will be completely exposed, posing a security risk.

[0168] The security threats faced by automotive electronic systems include: remote intrusion and physical contact attacks. For the in-vehicle entertainment system with security vulnerabilities, the exploitation of the vulnerabilities only causes the leakage of user privacy and does not cause personal safety losses; while for the steering assist system, if there are security vulnerabilities, it will lead to personal safety risks after being remotely controlled by cracking.

[0169] It can be seen that in in-vehicle devices, real-time performance and security are crucial. To meet the real-time performance and security requirements of in-vehicle devices, the embodiments of the present application provide a new partitioning architecture. Figure 3 It is a schematic diagram of the new software partitioning architecture applicable to the present application, as Figure 3 shown. In this new partitioning architecture, ordinary applications are divided into the privileged layer, that is, the OS and applications (including ordinary applications and trusted applications in the prior art) are both in the privileged layer. Since ordinary applications and the kernel are both in the privileged layer, the task scheduling, system service requests, etc. in ordinary applications do not require the overhead of privilege switching, thus improving the response speed of the applications.

[0170] Different from the prior art, a trusted base is also added in this new partitioning architecture.

[0171] However, considering the security of in-vehicle devices, it is necessary to ensure memory isolation between the kernel and tasks. This memory isolation means that tasks and the kernel cannot arbitrarily access each other's memory. In the embodiments of the present application, a trusted protection unit is added and used as the trusted base, as Figure 3 shown. This trusted base is independent of the kernel and tasks. Figure 2 In the partitioning architecture shown, trusted applications and the kernel together form the trusted base. Therefore, the trusted base in the embodiments of the present application is different from the trusted base in the prior art.

[0172] This trusted base is used to handle memory isolation. This trusted protection unit is also called the Protected Environment Keystone for MCU (PEKM). The trusted base is equivalent to an API gateway to realize the connection between tasks and the kernel. In the embodiments of the present application, all system calls and task scheduling need to perform memory boundary switching and authentication by this trusted base to ensure the security of tasks and the kernel in the privileged layer.

[0173] It can be understood that when the processor of a vehicle-mounted device is in different working modes, the memory space it can access is limited. The range of the memory space that the processor can access in different working modes is called the memory boundary. For example, the memory spaces that the processor can access when working in the privileged mode and the user mode are different. When the working mode of the processor switches from the privileged mode to the user mode, the memory space that the processor can access also changes. The change in the memory space accessed by the processor is called a memory boundary switch.

[0174] Optionally, the trusted base can be implemented in software. The entire trusted base (i.e., the entire software implementing the trusted base) is used as the trusted base of the vehicle-mounted device. The MPU configuration information or the configuration information of the MMU is stored in the memory of the trusted base. Memory isolation is mainly achieved through the MPU configuration information and the MMU configuration information. Therefore, it can also be said that the trusted base of the vehicle-mounted device mainly includes the MPU configuration information or the MMU configuration information. Compared with the existing trusted protection base of the vehicle-mounted device composed of the kernel and trusted applications, the trusted base is reduced, and the security of the system is improved.

[0175] Figure 3 In the partition architecture shown, there are protection boundaries (or called memory protection boundaries) between the kernel and trusted applications, between the kernel and untrusted applications, between trusted applications and trusted applications, between trusted applications and untrusted applications, between different tasks of the same trusted application, and between different tasks of the same untrusted application. The protection boundary is the memory boundary mentioned above. When the memory that a task wants to access exceeds the memory boundary allocated by the trusted base for this task, a memory exception will occur. In the embodiments of the present application, after a memory exception occurs, the trusted base implements a memory boundary switch.

[0176] In the embodiments of the present application, the main protection mechanism of the vehicle-mounted device is implemented by the MPU configuration information or the MMU configuration information. The trusted base can be protected by means such as instruction elimination, post verification, and permission protection.

[0177] Instruction elimination means that through compiler technology, the original system instructions in the kernel (or OS) and tasks that access the MPU register or the MMU register are eliminated, and the code segment and data segment are protected by W⊕X. ⊕ represents the exclusive OR operation. W⊕X protection is data execution prevention (DEP). Only the trusted base has the system instructions to access and operate the MPU or MMU.

[0178] Privilege protection means configuring the memory switching configuration information and the interrupt vector table included in the trusted base as read-only, and configuring the code segment of the trusted base as non-writable for execution. Among them, the memory switching configuration information is used to switch the memory access boundary from the memory of the kernel to the memory of the task, or to switch the memory access boundary from the memory of the task to the memory of the kernel.

[0179] Post-verification: On the one hand, in order to prevent routing information protocol (RIP) attacks, the trusted base will verify whether the memory switching configuration information is legal. This verification process is the first post-verification. If it is found that the memory switching configuration information is illegal, resilience protection will be triggered, such as restarting the system, shutting down the system, terminating the service, etc. For interrupt requests, to avoid interrupts occurring after configuring the MPU or MMU, the first post-verification may be bypassed. In the embodiments of the present application, a second post-verification can also be performed. The second post-verification is to verify the interrupt request and check whether the return address of the interrupt handling function is legal.

[0180] Figure 4 It is a schematic diagram of the functional modules of the trusted base, such as Figure 4 shown. The trusted base includes a call point, an API gateway, and an initialization module. The call point is the service entry between the trusted base and the kernel, and between the trusted base and the task. When the program counter (PC) runs to the call point, the interface provided by the trusted base will be called. The interface includes: system bootloader interface, system call interface, interrupt handler interface, and task schedule interface. The initialization module is used to handle system initialization events and initialize the privilege control of I / O during the system startup process, including I / O privilege scanning and instruction elimination. The API gateway has the following functions: switching of the memory access boundary, post-verification, and exception handling. The API gateway is used to handle system calls, interrupt service functions, and task scheduling events. When the task or the kernel needs to switch the memory access boundary to access resources or services, the API gateway will switch the memory access boundary by configuring the MPU or the MMU. The API gateway configures the MPU or the MMU according to the configuration information stored in the memory of the trusted base and verifies the legality of the configuration information (i.e., post-verification). When the verification passes, the next instruction of the task or the kernel is returned.

[0181] Figure 5The flowchart of the method for kernel and task isolation provided in the first embodiment of this application. The method of this embodiment is executed by a computer system on which an OS and an application are running. A kernel is running on the OS, an application includes one or more tasks, and a trusted base is also running on the OS. As Figure 5 shown, the method provided in this embodiment includes the following steps:

[0182] S131. The kernel searches for a first task from the task queue.

[0183] AUTOSAR OS is a system with static task allocation, and tasks can be configured to start regularly or irregularly through a scheduling table. When the current task (i.e., the currently scheduled task) switches from the running state to the ready state, the scheduler (Scheduler or OSScheduler) runs. The scheduler is used for task scheduling. The scheduler saves the current task, saves the context information of the task, and finds the first task to be run from the task queue according to the scheduling policy.

[0184] The scheduler can schedule the tasks in the task queue according to the priorities between tasks. The first task may or may not be the current task. When the current task is the task with the highest priority in the task queue, the first task is the current task. When the current task is not the task with the highest priority in the task queue, the first task is not the current task but a task with a priority higher than the current task. It can be understood that this is only an example, and the tasks in the task queue can also be scheduled in other ways.

[0185] S132. The trusted base searches for the first memory switching configuration information corresponding to the first task from the memory, and configures the memory protection device according to the first memory switching configuration information.

[0186] In this embodiment, the memory protection device is a hardware component for protecting the memory of the computer system, and can be an MPU or an MMU. The first memory switching configuration information is used to switch the memory access boundary from the memory of the kernel to the memory of the first task.

[0187] Among them, the first memory switching configuration information includes the memory address information and memory operation permissions of the kernel, the memory address information and memory operation permissions of the first task. The configured memory operation permission of the kernel is no permission, and the configured permission of the first task is readable. The first memory switching configuration information may also include the memory address information and memory operation permissions of the trusted base.

[0188] In this embodiment, the memory operation permissions of the kernel, tasks, and trusted base are all composed of the permissions of the data segment (or called data segment memory), code segment (or called code segment memory), and read-only (RO) segment (or called read-only segment memory). The data segment memory is the memory occupied by the data segment, the code segment memory is the memory occupied by the code segment, and the read-only segment memory is the memory occupied by the read-only segment.

[0189] After configuration, the first task has no permission to operate on the memory of the kernel, that is, the first task has no permission for the data segment, code segment, and read-only segment of the kernel. Therefore, after configuration, the first task cannot access the memory of the kernel.

[0190] After configuration, the kernel can access the memory of the first task. Correspondingly, after configuration, the access permission of the kernel to the memory of the first task is readable. Among them, the operation permissions of the kernel to the memory of the first task specifically include: the permission of the kernel to the data segment of the first task is readable, writable, and non-executable; the permission of the kernel to the code segment of the first task is readable, executable, and non-writable; the permission of the kernel to the read-only segment of the first task is readable, non-writable, and non-executable.

[0191] Before and after configuration, the access permissions of the tasks and the kernel to the memory of the trusted base have not changed. The operation permissions of the kernel or the first task to the memory of the trusted base include, for example: the kernel or the first task has no permission for the data segment of the trusted base; the kernel or the first task has the permission to execute, non-readable, and non-writable for the code segment of the trusted base; the kernel or the first task has the permission to read, non-writable, and non-executable for the read-only segment of the trusted base.

[0192] The permissions of the above data segment, code segment, and readable segment are all composed of three permissions: read, write, and execute. When describing the permissions of the data segment, code segment, and readable segment, the three permissions of read, write, and execute can be described separately, or the permissions of the data segment, code segment, and readable segment can be described in a negative way. For example, when the permission of the data segment of the first task is readable, writable, and non-executable, if it is described in a negative way, then the permission of the data segment of the first task is non-executable; when the permission of the code segment of the first task is readable, executable, and non-writable, if it is described in a negative way, then the permission of the code segment of the first task is non-writable; when the permission of the read-only segment of the first task is readable, non-writable, and non-executable, if it is described in a negative way, then the permission of the read-only segment of the first task is non-writable and non-executable.

[0193] The trusted base reads the first memory switching configuration information from the memory (specifically, the memory of the trusted base), reads the first memory switching configuration information into the general register, and then reads the first memory switching configuration information in the general register into the register of the memory protection device. The protection domain of the memory protection device is configured according to the first memory switching configuration information in the register of the memory protection device. After the protection domain of the memory protection device is configured, the first task can only access the memory addresses within the protection domain. When the accessed memory address exceeds the protection domain, a memory access exception will occur, thus realizing memory isolation.

[0194] In the embodiment of the present application, before the trusted base configures the memory protection device, the memory access boundary is located in the kernel memory. At this time, if the first task needs to be called, since the kernel and the first task do not have access rights to each other, the memory of the first task cannot be accessed. Therefore, the memory access boundary needs to be switched first. After the memory protection device is configured, the first task has no permission to access the data segment, code segment, and read-only segment of the kernel. The kernel has the permission to read the memory of the first task. Therefore, after the configuration is completed, the first task cannot access the kernel memory, but the kernel can access the memory of the first task, thus completing the switching of the memory access boundary from the kernel memory to the memory of the first task.

[0195] Among them, before the memory boundary is switched, the kernel has no permission to access the data segment, code segment, and read-only segment of the first task. The kernel has the permission to read, write, and not execute the data segment of the kernel; the kernel has the permission to read, execute, and not write the code segment of the kernel; the kernel has the permission to read, not write, and not execute the read-only segment of the kernel; the kernel has no permission to access the data segment of the trusted base, the kernel has the permission to execute, not read, and not write the code segment of the trusted base, and the kernel has the permission to read, not write, and not execute the read-only segment of the trusted base. Therefore, before the memory boundary is switched, the kernel cannot access the memory of the first task, and the working mode of the processor is the privileged mode. After the memory boundary is switched from the kernel memory to the memory of the first task, the first task cannot access the kernel memory, and the working mode of the processor is the user mode.

[0196] The memory address information of the kernel and the trusted base of the first task can be the starting address and the address length of the memory, or the starting address and the ending address. The operation permissions of the memory can be not readable, not writable, and not executable, etc. When the memory protection device is an MPU, the memory addresses of the kernel and the trusted base of the first task are physical addresses. When the memory protection device is an MMU, the memory addresses of the kernel and the trusted base of the first task are physical addresses, virtual addresses, or a mapping table of virtual addresses and physical addresses.

[0197] In the embodiments of the present application, there are two types of memory switching configuration information. One type of memory switching configuration information is used to switch the memory access boundary from the memory of the kernel to the memory of the task, and the other type of memory switching configuration information is used to switch the memory access boundary from the memory of the task to the memory of the kernel. Both types of memory switching configuration information are stored in the memory of the trusted base. Specifically, this memory switching configuration information is stored in the read-only segment of the trusted base, and the operation permission of the read-only segment of the trusted base is configured to be read-only, that is, the read-only segment of the trusted protection unit cannot be written or executed.

[0198] In the embodiments of the present application, only the trusted base can read this memory switching configuration information and execute this memory switching configuration information to complete the MPU configuration or the MMU configuration, thereby completing the memory boundary switching, while the kernel cannot execute this memory switching configuration information and cannot configure the MPU or the MMU. In the prior art, the configuration of the MPU or the MMU is completed by the kernel.

[0199] Optionally, the first memory switching configuration information can be stored in the memory of the trusted base in the form of a table. Exemplarily, this first memory switching configuration information is stored in the memory boundary access table, and the memory boundary access table can be statically generated or pre-configured. The memory boundary access table includes multiple task-to-kernel switching tables and multiple kernel-to-task switching tables. Among them, the task-to-kernel switching table is used to switch the memory access boundary from the memory of the kernel to the memory of the task and to switch the memory access boundary from the memory of the task to the memory of the kernel.

[0200] Figure 6 It is a schematic diagram of the memory boundary access table provided by the present application. As Figure 6 shown, the address range of the memory on the MCU is: 0X00000000 - 0XFFFFFFFF, and the layout of this memory address range is as Figure 6 shown. The address range of this memory is divided into the memory of the kernel, the memory of the trusted base, the memory of task 1 to task n, the memory of privileged I / O, and the memory of ordinary I / O. Among them, the memory of the kernel, the memory of the trusted base, and the memory of the task all include: data segment memory, code segment memory, and read-only segment memory, and the memory of the task (including the read-only segment, code segment, and data segment) is arranged in a continuous address space.

[0201] It can be understood that the address spaces of the memory of the kernel, the memory of the trusted base, the memory of the task, the memory of privileged I / O, and the memory of ordinary I / O can be continuous or discontinuous, Figure 6 This is just a schematic diagram and does not constitute a limitation on the memory division.

[0202] As Figure 6As shown, each task can correspond to three task-to-kernel switching tables. The first task-to-kernel switching table includes the starting address, ending address, and permissions of the code segment memory of the kernel, task, and trusted base respectively. The second task-to-kernel switching table includes the starting address, ending address, and permissions of the data segment memory of the kernel, task, and trusted base respectively. The third task-to-kernel switching table includes the starting address, ending address, and permissions of the read-only segment memory of the kernel, task, and trusted base respectively. Of course, the content in the three task-to-kernel switching tables can also be stored in one table, and this embodiment does not limit this.

[0203] Figure 6 In it, the 0th row in the task-to-kernel table represents the starting address (Kernel_stext), ending address (Kernel_etext), and permissions of the code segment of the kernel. The 1st row represents the starting address (Task_stext), ending address (Task_etext), and permissions of the code segment of the task. The 2nd row represents the starting address (PEKM_stext), ending address (PEKM_etext), and permissions of the code segment of the trusted base. Similarly, Figure 6 in it (Kernel / Task / PEKM_sdata) represents the starting address of the data segment of the kernel / task / trusted base, (Kernel / Task / PEKM_edata) represents the ending address of the data segment of the kernel / task / trusted base, (Kernel / Task / PEKM_sro) represents the starting address of the read-only segment of the kernel / task / trusted base, and (Kernel / Task / PEKM_ero) represents the ending address of the read-only segment of the kernel / task / trusted base.

[0204] Similarly, each task also corresponds to three kernel-to-task switching tables. The first kernel-to-task switching table includes the starting address, ending address, and permissions of the code segment memory of the task, kernel, and trusted base respectively. The second kernel-to-task switching table includes the starting address, ending address, and permissions of the data segment memory of the task, kernel, and trusted base respectively. The third kernel-to-task switching table includes the starting address, ending address, and permissions of the read-only segment memory of the task, kernel, and trusted base respectively.

[0205] S133. The kernel calls the first task.

[0206] After the memory access boundary switches from the memory of the kernel to the memory of the first task, the first task cannot access the memory of the kernel, and the memory of the first task can be accessed by the kernel. The kernel calls the first task. At this time, the working mode of the processor is the user mode. In the user mode, the first task can only access its own memory and cannot access the memory of the kernel.

[0207] It should be noted that the method of this embodiment is applicable to the following two scenarios: ordinary applications are located in the non-privileged layer, and the kernel and trusted applications are located in the privileged layer; all applications are located in the privileged layer, that is, ordinary applications are also located in the privileged layer. Among them, compared with the former scenario, the latter scenario can improve the system performance, that is, improve the response speed of applications. When all applications are in the privileged layer, no privilege switching is required when an ordinary application makes a system call, reducing the overhead of privilege switching, thereby improving the response speed of the application.

[0208] In addition, the trusted base in this embodiment is mainly composed of MPU configuration information or MMU configuration information. Compared with the prior art where the trusted base is composed of the kernel and trusted applications together, the trusted base is reduced, improving the security of the system.

[0209] In this embodiment, the trusted base is independent of the kernel and tasks. When performing task scheduling, the trusted base searches for the first memory switching configuration information of the first task from the memory, and configures the memory protection device according to the first memory switching configuration information. The first memory switching configuration information includes the memory address information and operation permissions of the kernel, as well as the memory address information and operation permissions of the first task; the memory operation permission of the configured kernel is no permission, and the permission of the configured first task is readable. After the memory protection unit is configured, since the memory operation permissions of the kernel are all no permissions, that is, the first task cannot access the memory of the kernel, thus ensuring the security of the task and the kernel.

[0210] Figure 7 This is the flowchart of the method for kernel and task isolation provided in the second embodiment of this application. On the basis of the first embodiment, before the trusted base configures the memory protection device, the interrupt is closed, and the interrupt is opened after the memory protection device is configured, so as to avoid tampering with the first memory switching configuration information in the register due to interrupt operations. Further, before opening the interrupt, a post-verification can be performed, that is, verifying whether the first memory switching configuration information is legal. When the first memory switching configuration information is legal, the interrupt is opened. Through the post-verification, flow control attacks such as Jump-oriented Programming (JOP) or Return-Oriented Programming (ROP) can be prevented.

[0211] S201. The kernel searches for the first task from the task queue.

[0212] S202. The trusted base closes the interrupt.

[0213] Before configuring the memory protection device, turning off the interrupt can prevent the interrupt from modifying the first memory switching configuration information stored in the general register. If the interrupt is not turned off, the interrupt may modify the first memory switching configuration information stored in the general register. If the first memory switching configuration information stored in the general register is modified, subsequent errors may occur in the memory protection device.

[0214] S203. The trusted base searches for the first memory switching configuration information of the first task from the memory and configures the memory protection device according to the first memory switching configuration information.

[0215] The first memory switching configuration information includes the memory protection device configuration information of the kernel, the first task, and the trusted base. The memory protection device configuration information of the kernel includes the memory address information of the kernel and the memory operation permission of the kernel. The memory protection device configuration information of the first task includes the memory address information of the first task and the memory operation permission of the first task. The memory protection device configuration information of the trusted base includes the memory address information of the trusted base and the memory operation permission of the trusted base.

[0216] The trusted base first loads the memory protection device configuration information of the kernel, the first task, and the trusted base from the memory into the general register respectively. Exemplarily, the memory protection device configuration information of the kernel, the first task, and the trusted base are loaded into the general registers r0, r1, and r2 respectively. r0 = table[kenel], r1 = table[task1 ID], r2 = table[PEKM]. "=" represents the assignment operation. table[kenel] represents the memory protection device configuration information of the kernel stored in the memory. table[task1 ID] represents the memory protection device configuration information of the first task stored in the memory. [PEKM] represents the memory protection device configuration information of the trusted base stored in the memory.

[0217] The trusted base reads the configuration information of the kernel, the first task, and the memory protection device stored in the general-purpose registers r0, r1, and r2 into the registers of the memory protection device. The registers of the memory protection device are dedicated registers. Then, the trusted base configures the protection domain of the memory protection device according to the configuration information of the kernel, the first task, and the memory protection device stored in the registers of the memory protection device. Among them, the configuration of the protection domain of the memory protection device can be expressed in the following way: region[0]=r0, region[1]=r1, region[2]=r2, where region[0], region[1], and region[2] respectively represent the protection domains of the memory protection device, that is, the access permissions of the memory spaces of the kernel, the first task, and the trusted base are set according to the configuration information in the general-purpose registers r0, r1, and r2. By configuring the memory protection device, the memory boundary switching is completed.

[0218] S204. The trusted base compares whether the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory.

[0219] It can be understood that the first memory switching configuration information stored in the memory is read-only and cannot be tampered with, while the first memory switching configuration information stored in the general-purpose register may be tampered with due to interrupts, JOP, or ROP. Therefore, in this embodiment, before enabling the interrupt, it is first determined whether the first memory switching configuration information stored in the memory is the same as the first memory switching configuration information stored in the general-purpose register. If they are the same, it means that the first memory switching configuration information in the general-purpose register has not been tampered with, and then the interrupt is enabled. If they are different, it means that the first memory switching configuration information in the general-purpose register has been tampered with, and the trusted base shuts down the OS or terminates the first task, thereby preventing control flow attacks such as ROP or JOP or interrupts from modifying the first memory switching configuration information.

[0220] After the trusted base completes the configuration of the memory protection device, step S203 is executed. Step S203 is an optional step. Exemplarily, the trusted base reads the first memory switching configuration information from the memory into the general-purpose registers r3, r4, and r5. r3 is used to store the configuration information of the memory protection device of the kernel, r4 is used to store the configuration information of the memory protection device of the first task, and r5 is used to store the configuration information of the memory protection device of the trusted base.

[0221] Among them, the memory protection device configuration information of the kernel, the first task, and the trusted base stored in the general-purpose registers r0, r1, and r2 may be modified by interrupts, ROP, JOP, etc. However, the values in the general-purpose registers r3, r4, and r5 are the values just read from the memory and have not been modified. Therefore, the trusted base compares the values of r0 and r3, compares the values of r1 and r4, and compares the values of r2 and r5. If the values in the three groups of general-purpose registers are the same, it indicates that the first memory switching configuration information has not been modified.

[0222] Exemplarily, the above comparison process can be represented in the following way: cmp(table[kenel], r0), cmp(table[task1], r1), cmp(table[PEKM], r2). The cmp represents the comparison operation, table[kenel / task1 / PEKM] represents the memory protection device configuration information of the kernel, the first task, and the trusted base stored in the memory, and r0, r1, and r2 represent the memory protection device configuration information of the kernel, the first task, and the trusted base stored in the general-purpose registers.

[0223] When the first memory switching configuration information stored in the general-purpose register is the same as the first memory switching configuration information stored in the memory, it indicates that the first memory switching configuration information is legal, that is, the first memory switching configuration information on the general-purpose register has not been tampered with. At this time, step S205 is executed. When the first memory switching configuration information stored in the general-purpose register is different from the first memory switching configuration information stored in the memory, it indicates that the first memory switching configuration information is not legal and the first memory switching configuration information on the general-purpose register has been tampered with. At this time, step S207 is executed.

[0224] S205: The trusted base enables interrupts.

[0225] S206: The kernel invokes the first task.

[0226] S207: The kernel shuts down the OS and / or terminates the first task.

[0227] When the first memory switching configuration information is not legal, step S207 is executed.

[0228] In this embodiment, before the trusted base searches for the first memory switching configuration information of the first task in the memory, it closes the interrupt. After configuring the memory protection device according to the first memory switching configuration information, it opens the interrupt, thereby preventing the interrupt from modifying the first memory switching configuration information stored in the general register. Optionally, before opening the interrupt, the trusted protection compares whether the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory. If the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory, then the interrupt is opened. If the first memory switching configuration information stored in the memory and the register is the same, it means that the first memory switching configuration information in the register has not been tampered with by attacks such as ROP or JOP. After the memory switching configuration information in the register is modified, it may cause the data in the memory of the task and the kernel to be leaked, thus unable to ensure the security of the task and the kernel. In this embodiment, if the first memory switching configuration information stored in the memory and the register is different, then the OS is shut down and / or the first task is terminated, thereby ensuring the security of the task and the memory.

[0229] It can be understood that the interrupt operation can be closed before the configuration of the memory protection device, and the subsequent verification can be decoupled and implemented. That is, in a possible embodiment, the trusted base can close the interrupt operation before configuring the memory protection device, and open the interrupt after the configuration is completed. Before opening the interrupt, it does not compare whether the first memory switching configuration information stored in the memory is the same as the first memory switching configuration information stored in the register. In another possible embodiment, the trusted base can not close the interrupt operation before configuring the memory protection device, and compare whether the first memory switching configuration information stored in the memory is the same as the first memory switching configuration information stored in the register before calling the service.

[0230] Figure 8 The flowchart of the method for kernel and task isolation provided in Embodiment 3 of this application. The method of this embodiment is executed by a computer system, on which an OS and an application are running, a kernel is running on the OS, the application includes one or more tasks, and a trusted base is also running on the OS. This embodiment takes the memory boundary switching during the system call process by the trusted base as an example for illustration. It can be understood that the method of this embodiment can be executed independently of the method of Embodiment 1, or can be executed before or after Embodiment 1. This embodiment does not limit this. As Figure 8 shown, the method provided in this embodiment includes the following steps:

[0231] S301. When the second task needs to call the system service API, the trusted base saves the task ID of the second task.

[0232] The task number of the second task is used to uniquely represent a task. When the second task needs to call system services, the second task sends the service ID as the system service number of the system service request to the trusted base.

[0233] The second task is different from the first task. The second task is a task that needs to perform system calls, and the first task is a task that performs ordinary function calls. To perform a system call, the second task needs to switch the working state of the processor from the user mode to the kernel mode before it can perform the system call. During the process of performing an ordinary function call, the first task remains in the user mode all the time.

[0234] S302. The trusted base searches for the second memory switching configuration information of the second task and configures the memory protection device according to the second memory switching configuration information.

[0235] The memory protection device is a hardware component used to protect the memory of a computer system, and it can be an MMU or an MPU. Since the second task needs to perform a system call and needs to switch the working state of the processor from the user mode to the kernel mode, whether the processor can access the kernel memory in the kernel mode. In the current state, the memory access boundary is located in the memory of the second task. Therefore, in this embodiment, it is necessary to switch the memory access boundary from the memory of the second task to the kernel memory.

[0236] Among them, the second memory switching configuration information is used to switch the memory access boundary from the memory of the second task to the kernel memory. The second memory switching configuration information includes the memory address information of the kernel and the memory operation permissions of the kernel, as well as the memory address information of the second task and the memory operation permissions of the second task. Among them, after configuration, the kernel has no permission to operate on the memory of the second task, and after configuration, the second task has the permission to read the kernel memory.

[0237] Among them, after configuration, the kernel has no permission to operate on the memory of the second task, that is, the kernel has no permission to access the data segment, code segment, and read-only segment of the second task, and the kernel cannot access the memory of the second task.

[0238] Among them, after configuration, the second task has the permission to read the kernel memory, that is, after configuration, the second task can access the kernel memory. Among them, the operation permissions of the second task on the kernel memory can include: the second task has the permissions to read, write, and not execute on the data segment of the kernel; the second task has the permissions to read, execute, and not write on the code segment of the kernel; the second task has the permissions to read, not write, and not execute on the read-only segment of the kernel.

[0239] Optionally, the operating permissions of the kernel and the second task for the memory of the trusted base remain unchanged before and after configuration. The operating permissions of the kernel or the second task for the memory of the trusted base include, for example: the kernel or the second task has no permission for the data segment of the trusted base, the kernel or the second task has the permissions of executable, non-readable, and non-writable for the code segment of the trusted base, and the kernel or the second task has the permissions of readable, non-writable, and non-executable for the read-only segment of the trusted base. Among them, the second memory switching configuration information is stored in the read-only segment of the trusted base.

[0240] As can be seen from the above, both the second memory switching configuration information and the first memory switching configuration information include: the memory address information and memory access permissions of the kernel, the memory address information and memory access permissions of the task, and the memory address information and memory access permissions of the trusted base. However, the specific values of the memory address information and memory access permissions in the two configuration information are different. The second memory switching configuration information can be stored in the memory of the trusted base in the form of a table, for example, stored in Figure 6 the memory boundary access table shown, specifically stored in the task-to-kernel table. The specific implementation manner of the second memory switching configuration information can refer to the description of the first memory switching configuration information in Embodiment 1, which will not be elaborated here.

[0241] After the memory protection device is configured, the permissions of the data segment, code segment, and read-only segment of the second task are all no permissions, so the memory of the second task cannot be accessed by the kernel or other tasks. Whether the memory of the kernel can be accessed by the second task, so that system calls can be made.

[0242] S303. The kernel calls the second task.

[0243] After the memory protection device is configured according to the second memory switching configuration information, the memory access boundary is successfully switched, that is, the memory access boundary is switched from the memory of the second task to the memory of the kernel.

[0244] S304. The kernel calls the system service.

[0245] After the memory protection device is configured according to the second memory switching configuration information, the memory access boundary is successfully switched, that is, the memory access boundary is switched from the memory of the second task to the memory of the kernel. At this time, the kernel can call the second task and the system service. Exemplarily, the kernel finds the system service according to the service ID.

[0246] S305. After the system service is completed, the trusted base retrieves the task number of the second task and switches the memory access boundary from the memory of the kernel to the memory of the second task.

[0247] System calls require two memory boundary switches, that is, switching the memory boundary from the memory of the second task to the memory of the kernel. After the system service is completed, it is also necessary to switch the memory boundary from the memory of the kernel to the memory of the second task.

[0248] After the system service is completed, the kernel calls the call point of the trusted base and retrieves the saved task number.

[0249] Exemplarily, the trusted base can switch the memory access boundary from the memory of the kernel to the memory of the second task in the following way: the trusted base searches for the third memory switching configuration information of the second task in the memory and configures the memory protection device according to the third memory switching configuration information.

[0250] The third memory switching configuration information is used to switch the memory access boundary from the memory of the kernel to the memory of the second task. Among them, the third memory switching configuration information includes: the memory address information of the kernel and the memory operation permissions of the kernel, as well as the memory address information of the second task and the memory operation permissions of the second task. After configuration, the second task has no permission to operate on the memory of the kernel, and after configuration, the kernel has the permission to read the memory of the second task.

[0251] After configuration, the second task has no permission to operate on the memory of the kernel, that is, the second task has no permission to access the data segment, code segment, and read-only segment of the kernel. Therefore, after the configuration is completed, the second task cannot access the memory of the kernel.

[0252] After configuration, the kernel has the permission to read the memory of the second task, that is, after configuration, the kernel can access the memory of the second task. Among them, the permission of the kernel to read the memory of the second task can include, for example: the kernel has the permission to read, write, and not execute the data segment of the second task, the kernel has the permission to read, execute, and not write the code segment of the second task, and the kernel has the permission to read, not write, and not execute the read-only segment of the second task.

[0253] Before and after configuration, the access permissions of the second task and the kernel to the memory of the trusted base have not changed. The operation permissions of the kernel or the second task to the memory of the trusted base include, for example: the kernel or the second task has no permission to access the data segment of the trusted base, the kernel or the second task has the permission to execute, not read, and not write the code segment of the trusted base, and the kernel or the second task has the permission to read, not write, and not execute the read-only segment of the trusted base.

[0254] Optionally, the third memory switching configuration information may further include the memory address information and memory operation permissions of the trusted base. The permission of the data segment of the trusted base included in the third memory switching configuration information is no permission, the permission of the code segment of the trusted base is executable, not readable, and not writable, and the permission of the read-only segment of the trusted base is readable, not writable, and not executable.

[0255] The function of the third memory switching configuration information is the same as that of the first memory switching configuration information in the first embodiment, which is used to switch the memory access boundary from the memory of the kernel to the memory of the task. For the specific description of the third memory switching configuration information, reference can be made to the description of the first memory switching configuration information in the first embodiment, which will not be elaborated here.

[0256] S306. The kernel invokes the second task to obtain the result returned by the system service.

[0257] In this embodiment, when the second task needs to invoke the system service, two memory boundary switches are required. Before the system call, the memory access boundary is located in the memory of the second task. Therefore, it is necessary to first switch the memory access boundary from the memory of the second task to the memory of the kernel according to the second memory switching configuration information. After the memory access boundary is switched to the memory of the kernel, the system call can be made. After the system call is completed, the memory access boundary needs to be switched from the memory of the kernel to the memory of the second task. At this time, the memory access boundary is switched according to the third memory switching configuration information, and the memory access boundary is switched back to the memory of the second task. The method realizes the system call through two memory boundary switches during the system call process, which can ensure the memory isolation between the second task and the kernel.

[0258] Figure 9 This is a flowchart of the method for kernel and task isolation provided in the fourth embodiment of the present application. On the basis of the third embodiment, before the trusted base configures the memory protection device, the interrupt needs to be turned off. Before the interrupt is turned on after the configuration is completed, further, the legality of the second memory switching configuration information and the third memory switching configuration information can be verified before the interrupt is turned on. When the second memory switching configuration information or the third memory switching configuration information is legal, the interrupt is turned on. This can prevent the modification of the memory switching configuration information by the interrupt, JOP or ROP.

[0259] S401. When the second task needs to invoke the system service API, the trusted base turns off the interrupt and saves the task number of the second task.

[0260] S402. The trusted base searches for the second memory switching configuration information of the second task from the memory and configures the memory protection device according to the second memory switching configuration information.

[0261] The second memory switching configuration information includes the memory protection device configuration information of the kernel, the second task, and the trusted base. The trusted base first loads the memory protection device configuration information of the kernel, the second task, and the trusted base from the memory into the general-purpose registers respectively. Exemplarily, the trusted base loads the memory protection device configuration information of the kernel, the second task, and the trusted base into the general-purpose registers r0, r1, and r2 respectively, r0 = table[kenel], r1 = table[task2 ID], r2 = table[PEKM], where "=" represents the assignment operation, table[kenel] represents the memory protection device configuration information of the kernel stored in the memory, table[task2 ID] represents the memory protection device configuration information of the second task stored in the memory, and [PEKM] represents the memory protection device configuration information of the trusted base stored in the memory.

[0262] The trusted base reads the memory protection device configuration information of the kernel, the second task, and the trusted base stored in the general-purpose registers r0, r1, and r2 into the registers of the memory protection device. The registers of the memory protection device are dedicated registers. Then, the trusted base configures the protection domain of the memory protection device according to the memory protection device configuration information of the kernel, the second task, and the trusted base stored in the registers of the memory protection device. Among them, the configuration of the protection domain of the memory protection device can be expressed in the following way: region[0] = r0, region[1] = r1, region[2] = r2, where region[0], region[1], and region[2] respectively represent the protection domains of the memory protection device, that is, the access permissions of the memory spaces of the kernel, the first task, and the trusted base are set according to the configuration information in the general-purpose registers r0, r1, and r2. By configuring the memory protection device, the memory boundary switching is completed.

[0263] S403. The trusted base compares whether the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory.

[0264] It can be understood that the second memory switching configuration information stored in the memory is read-only and cannot be tampered with, while the second memory switching configuration information stored in the general-purpose register may be tampered with due to interrupts, JOP, or ROP. Therefore, in this embodiment, before enabling the interrupt, it is first determined whether the second memory switching configuration information stored in the memory is the same as the second memory switching configuration information stored in the general-purpose register. If they are the same, it means that the second memory switching configuration information in the general-purpose register has not been tampered with, and then the interrupt is enabled. If they are different, it means that the second memory switching configuration information in the general-purpose register has been tampered with, and the trusted base shuts down the OS or terminates the first task, thereby preventing control flow attacks such as ROP or JOP or interrupts from modifying the second memory switching configuration information.

[0265] When the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory, that is, when the second memory switching configuration information is legal, step S404 is executed. When the second memory switching configuration information stored in the register is different from the second memory switching configuration information stored in the memory, that is, when the second memory switching configuration is illegal, step S410 is executed. Among them, the implementation manner of determining whether the second memory switching configuration information is legal is the same as that of determining whether the first memory switching configuration information is legal in Embodiment 1, and the function is also the same, so it will not be elaborated here.

[0266] S404. The trusted base enables the interrupt.

[0267] S405. The kernel invokes the second task and system services.

[0268] S406. After the system service is completed, the trusted base retrieves the task number of the second task, disables the interrupt, searches for the third memory switching configuration information of the second task in the memory, and configures the memory protection device according to the third memory switching configuration information.

[0269] S407. The trusted base compares whether the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory.

[0270] When the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory, that is, when the third memory switching configuration information is legal, step S408 is executed. When the third memory switching configuration information stored in the register is different from the third memory switching configuration information stored in the memory, that is, when the third memory switching configuration is illegal, step S410 is executed. Among them, the implementation manner of determining whether the third memory switching configuration information is legal is the same as that of determining whether the first memory switching configuration information is legal in Embodiment 1, and the function is also the same, so it will not be elaborated here.

[0271] S408. The trusted base enables the interrupt.

[0272] S409. The kernel invokes the second task to obtain the result returned by the system service.

[0273] S410. The kernel shuts down the OS and / or terminates the second task.

[0274] In this embodiment, before the trusted base configures the memory protection device according to the memory switching configuration information (including the second memory switching configuration information and the third memory switching configuration information), the interrupt is turned off, and the interrupt is turned on after the configuration is completed, which can prevent the interrupt from modifying the memory switching configuration information in the register. Moreover, before turning on the interrupt, by comparing whether the memory switching configuration information stored in the memory is the same as that stored in the register, it is possible to prevent attacks such as ROP or JOP from modifying the memory switching configuration information in the register. Thereby, it is possible to prevent the memory access permission from being tampered with due to the modification of the memory switching configuration information in the register. The tampering of the memory access permission may cause the data in the memory of the task and the kernel to be leaked, thus unable to ensure the security of the task and the kernel during the system call process.

[0275] It can be understood that the operation of turning off the interrupt before the configuration of the memory protection device and the subsequent verification can be decoupled and implemented. That is, in one possible embodiment, the trusted base can turn off the interrupt operation before configuring the memory protection device, turn on the interrupt after the configuration is completed, and do not compare whether the memory switching configuration information stored in the memory is the same as that stored in the register before turning on the interrupt. In another possible embodiment, the trusted base may not turn off the interrupt operation before configuring the memory protection device, and compare whether the memory switching configuration information stored in the memory is the same as that stored in the register before calling the service.

[0276] Figure 10 The flowchart of the method for kernel and task isolation provided in the fifth embodiment of the present application can be executed on the basis of the second or fourth embodiment above. That is, after the trusted base turns on the interrupt, the interrupt is processed according to the method of this embodiment, that is, the second subsequent verification. As Figure 10 shown, the method provided in this embodiment includes the following steps:

[0277] S501. The trusted base initializes the interrupt vector table.

[0278] The interrupt vector table is stored in the read-only segment of the trusted base, so as to avoid illegal modification of the interrupt vector table. Different from the prior art, in the embodiment of the present application, the interrupt vector table includes a normal interrupt service function and an interrupt service function of the trusted base, and the interrupt service function of the trusted base is a newly added function. In the prior art, the interrupt vector table only includes a normal interrupt service function. In the embodiment of the present application, when an interrupt is triggered, the interrupt service function of the trusted base is preferentially called for legality verification, and after the verification passes, the normal interrupt service function is executed. It can also be considered that the priority of the interrupt service function of the trusted base is higher than that of the normal interrupt service function.

[0279] In the embodiments of the present application, the interrupt service function of the trusted base is set to perform secondary legality verification, which improves security. In most cases, attacks can be prevented by verifying the legality of the memory switching configuration information. However, if an attacker modifies the interrupt vector table and enters an interrupt after the trusted base configures the MPU or MMU, thus bypassing the subsequent verification. To address this situation, the trusted base verifies whether the interrupt is a legal interrupt through the interrupt service function of the trusted base.

[0280] S502. When an interrupt request (IRQ) is received, the trusted base queries the interrupt vector table.

[0281] After the interrupt is enabled, if the trusted base receives an IRQ, it queries the interrupt vector table.

[0282] S503. The trusted base enters the interrupt service function of the trusted base according to the interrupt vector table.

[0283] S504. The trusted base obtains the return address of the interrupt and determines whether the return address of the interrupt belongs to a preset address range.

[0284] During normal execution, each time an instruction is executed, the PC register is updated. When an interrupt occurs, after the current instruction is executed, it will jump to the corresponding interrupt handling function (i.e., the normal interrupt service function) in the interrupt vector table. Before entering the interrupt handling function, the scene will be saved, and the current value of the PC register will be assigned to the return address of the current interrupt.

[0285] An illegal interrupt refers to an attacker attempting to enter the code segment of the trusted base through code segment jumps and maliciously issue an interrupt to try to bypass the subsequent verification.

[0286] In this embodiment, the memory of the trusted base includes data segment memory, code segment memory, and read-only segment memory. The preset address range can be the address range of the code segment memory of the trusted base. Since the trusted base has disabled the interrupt before configuring the memory protection device, only malicious code will generate an interrupt within the address range of the code segment memory of the trusted base.

[0287] Therefore, in this embodiment, through the second subsequent verification, it is determined whether the return address of the interrupt belongs to the preset address range. If the return address of the interrupt belongs to the preset address range, the interrupt is determined to be an illegal interrupt. If the return address of the interrupt does not belong to the preset address range, the interrupt is determined to be a legal interrupt. When the interrupt is a legal interrupt, step S505 is executed. When the interrupt is an illegal interrupt, step S506 is executed.

[0288] S505. The trusted base calls the normal interrupt service function.

[0289] S506. The kernel takes resilience protection.

[0290] This resilience protection can be a shutdown operation, shutting down the operating system, etc.

[0291] It can be understood that in this embodiment, the normal interrupt service function and the interrupt service function of the trusted base can also adopt other names. For example, the normal interrupt service function can be called the first interrupt service function, and the interrupt service function of the trusted base can be called the second interrupt service function.

[0292] In this embodiment, when an interrupt request is received, the interrupt vector table is queried. The interrupt vector table includes the normal interrupt service function and the interrupt service function of the trusted base. According to the interrupt vector table, the interrupt service function of the trusted base is entered, the return address of the interrupt is obtained, and it is determined whether the return address of the interrupt belongs to a preset address range. When the return address of the interrupt belongs to the preset address range, it is determined that the interrupt is an illegal interrupt, and resilience protection is taken; when the return address of the interrupt does not belong to the preset address range, it is determined that the interrupt is a legal interrupt, and the normal interrupt service function is called. By verifying whether the interrupt is a legal interrupt, the security of system calls or task calls is improved.

[0293] Figure 11 It is a flowchart of the method for kernel and task isolation provided in Embodiment VI of the present application. As Figure 11 shown, the method provided in this embodiment includes the following steps:

[0294] S601. During the computer startup process, the trusted base performs I / O privilege scanning on the code segments of the kernel and tasks.

[0295] In the existing system, different privilege modes determine different I / O access permissions. I / O access includes memory mapping I / O (MMIO) and registers. To ensure privilege isolation of I / O access, that is, in ordinary tasks, specific I / O registers cannot be accessed, or specific I / O address spaces cannot be accessed. In the embodiments of the present application, even if ordinary tasks are placed after the privilege layer, the I / O access permissions still need to be restricted. Therefore, during the system initialization process, I / O privilege scanning is performed on the code segments of the kernel and tasks. Among them, the code segment of the kernel includes various register operation instructions and various I / O operation instructions, and the code segment of the task includes various I / O operation instructions.

[0296] I / O privilege scanning means scanning the various operations of non-privileged tasks, partially privileged tasks, and privileged tasks to obtain the specific operations in non-privileged tasks, partially privileged tasks, and privileged tasks.

[0297] S602. The trusted base replaces the specific operations in non-privileged tasks, partially privileged tasks, and privileged tasks with exception instructions according to the scanning results.

[0298] Among them, the specific operations of non-privileged tasks include: IRQ register operation instructions, I / O status register query instructions, serial port register operations, timer register operations, system register operations, and MPU register operations. The specific operations of some privileged tasks include: system register operations and MPU register operations. The specific operation of privileged tasks includes: MPU register operations.

[0299] In this embodiment, for the access to specific registers, the specific operations in non-privileged tasks, some privileged tasks, and privileged tasks are replaced with exception instructions, and the exception instruction can be Trap (system exception). The task corresponding to the replaced exception instruction will not access the specific register. Subsequently, when a task attempts to illegally access the specific register, an exception will be triggered.

[0300] S603. Start the operating system.

[0301] It should be noted that in other embodiments of the present application, the specific operations in non-privileged tasks, some privileged tasks, and privileged tasks can also be instruction-eliminated, and the tasks after instruction-elimination will not access the specific register.

[0302] In the seventh embodiment of the present application, taking the AUTOSAR airbag system as an example, in the airbag system, a collision event is detected by a collision sensor. After data processing, the airbag actuator is notified, and it is usually required to complete the stress response within 10 ms. Figure 12 It is a schematic diagram of the hardware and software architecture of the vehicle-mounted device applicable to this embodiment, as Figure 12 shown. The vehicle-mounted device adopts a layered architecture, including: a hardware layer, a trusted base, a Run-Time Environment (RTE) layer, and a software component (SWC) layer.

[0303] Among them, the hardware layer includes: a central processing unit (CPU), an MPU, sensors, and actuators. The sensors are used to detect collision events, and the actuators are used to control operations such as the opening and closing of the airbag.

[0304] The trusted base includes call points, an API gateway, and an initialization module.

[0305] The RTE layer includes a communication module, a task entity module, and a life cycle module.

[0306] The SWC layer includes a collision sensor detection SWC, an airbag actuator SWC, and an application program SWC.

[0307] Figure 13 It is a schematic diagram of the process for the airbag system to feedback collision detection, as Figure 13 shown. This collision detection process includes:

[0308] S701. The collision detection application detects a collision and initiates a notification to the airbag application.

[0309] The collision detection application determines whether a collision has occurred by analyzing the input of the collision sensor. When it is confirmed that a collision has occurred, the airbag needs to be opened. However, since collision detection and airbag opening belong to different task entities, it is necessary to notify the airbag application through inter-task communication.

[0310] S702. The communication module of the RTE layer calls the system service.

[0311] The RTE provides a communication interface for software modules. Moreover, it is also used to create task entities, including application software modules, and it also controls the activation or termination of tasks. Usually, the RTE uses the shared memory method for inter-task communication. Therefore, it is necessary to use the system services GetResource() or ReleaseResource() to ensure data consistency, and it is also necessary to call the system services SetEvent(), WaitEvent(), ActivateTask(), etc. to notify tasks to receive data, that is, there are multiple system calls for communication. Taking the ActivateTask() to schedule the airbag execution task as an example, the RTE calls the system service call point.

[0312] S703. The communication module of the RTE calls the call point of the trusted base and executes the ActivateTask() system service to activate the airbag task.

[0313] S704. Before the trusted base executes this system service in the kernel, it uses the system call point to call the API gateway, configures the MPU, switches the memory access boundary from the task's memory to the kernel's memory, and completes the subsequent verification.

[0314] S705. Before the scheduler schedules the airbag task, the API gateway module configures the MPU and switches the memory access boundary from the kernel's memory to the airbag task's memory.

[0315] S706. The communication module of the RTE checks whether a corresponding collision event has occurred. When the collision event occurs, it quickly calls the actuator to pop up the airbag.

[0316] The communication module of the RTE needs to call the corresponding system service to query the corresponding event GetEvent(), and check whether there is a corresponding collision event through GetEvent().

[0317] Figure 14 FIG. is a schematic structural diagram of a computer system provided in the eighth embodiment of the present application. As Figure 14 shown, the computer system 800 includes: a kernel 81 and a trusted base 82. Among them, both the kernel 81 and the trusted base 82 run on the OS of the computer system 800. One or more applications also run on the computer system, and each application calls one or more tasks.

[0318] The kernel 81 is used to find the first task from the task preparation queue;

[0319] The trusted base 82 is used to find the first memory switching configuration information of the first task from the memory, and configure the memory protection device according to the first memory switching configuration information. The memory protection device is a hardware component used to protect the memory of the computer system; the first memory switching configuration information includes the memory address information and memory operation permissions of the kernel, as well as the memory address information and memory operation permissions of the first task. After configuration, the operation permission of the first task for the memory of the kernel is no permission; after configuration, the operation permission of the kernel for the memory of the first task is readable;

[0320] The kernel 81 also calls the first task.

[0321] Optionally, the trusted base 81 is further used to: close the interrupt before finding the first memory switching configuration information of the first task from the memory, and open the interrupt after configuring the memory protection device according to the first memory switching configuration information.

[0322] Optionally, the trusted base 81 is further used to: compare whether the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory; if the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory, it is determined that the first memory switching configuration information is legal. The kernel 82 is further used to: call the first task when the first memory switching configuration information is legal.

[0323] Optionally, the trusted base 81 is further used to: if the first memory switching configuration information stored in the register is different from the first memory switching configuration information stored in the memory, it is determined that the first memory switching configuration information is illegal;

[0324] The kernel is further configured to: when the first memory switching configuration information is illegal, shut down the OS and / or terminate the first task.

[0325] Optionally, the OS and all applications on the computer system are in the privileged layer.

[0326] Optionally, after the trusted base 81 enables the interrupt, the trusted base is further configured to: when receiving an interrupt request, query the interrupt vector table, where the interrupt vector table includes a normal interrupt service function and an interrupt service function of the trusted base; enter the interrupt service function of the trusted base according to the interrupt vector table; obtain the return address of the interrupt, and determine whether the return address of the interrupt belongs to a preset address range; when the return address of the interrupt belongs to the preset address range, determine that the current interrupt is an illegal interrupt and take resilience protection; when the return address of the interrupt does not belong to the preset address range, determine that the current interrupt is a legal interrupt and call the normal interrupt service function.

[0327] Optionally, the trusted base 81 is further configured to: initialize the interrupt vector table by the trusted base, and the interrupt vector table is stored in the read-only segment of the trusted base.

[0328] Optionally, the trusted base 81 is further configured to: during the startup process of the computer system, perform input / output I / O privilege scanning on the code segment of the kernel and the code segment of the task; according to the scanning result, replace specific operations of non-privileged tasks, partial-privileged tasks, and privileged tasks with exception instructions; start the OS.

[0329] Optionally, the specific operations of the non-privileged tasks include: IRQ register operation instructions, I / O status register query instructions, serial port register operations, timer register operations, system register operations, and memory protection device register operations; the specific operations of the partial-privileged tasks include: system register operations and memory protection device register operations; the specific operations of the privileged tasks include memory protection device register operations.

[0330] The computer system of this embodiment can be used to execute the method described in any one of the above Method Embodiment 1, Method Embodiment 2, Method Embodiment 5, or Method Embodiment 6. The specific implementation manners and technical effects are similar and will not be elaborated here.

[0331] Figure 15 The structural schematic diagram of the computer system provided in Embodiment 9 of the present application is as Figure 15 shown. The computer system 900 includes: a kernel 91 and a trusted base 92. Among them, both the kernel 91 and the trusted base 92 run on the OS of the computer system 800. One or more applications also run on the computer system, and each application calls one or more tasks.

[0332] The trusted base 91 is used to save the task number of the second task when the second task needs to call the system service application programming interface (API).

[0333] The trusted base 91 is further used to find the second memory switching configuration information of the second task from the memory, and configure the memory protection device according to the second memory switching configuration information. The memory protection device is a hardware component used to protect the memory of the computer system. The second memory switching configuration information includes the memory address information and memory operation permissions of the kernel, as well as the memory address information and memory operation permissions of the second task. After configuration, the kernel has no permission to operate on the memory of the second task, and after configuration, the second task has read permission to the memory of the kernel.

[0334] The kernel 92 is used to call the second task and the system service.

[0335] The trusted base 91 is further used to retrieve the task number of the second task after the system service is completed, and switch the memory access boundary from the memory of the kernel to the memory of the second task.

[0336] The kernel 92 is further used to call the second task to obtain the return result of the system service.

[0337] Optionally, the trusted base 91 is further used to: turn off the interrupt before finding the second memory switching configuration information corresponding to the second task from the memory; turn on the interrupt after the configuration of the memory protection device according to the second memory switching configuration information is completed.

[0338] Optionally, the trusted base 91 is further used to: compare whether the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory; if the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory, it is determined that the second memory switching configuration information is legal. The kernel is further used to: call the second task when the second memory switching configuration information is legal.

[0339] Optionally, the trusted base 91 is further used to: if the second memory switching configuration information stored in the register is different from the second memory switching configuration information stored in the memory, it is determined that the second memory switching configuration information is illegal. The kernel 92 is further used to: turn off the OS and / or terminate the second task when the second memory switching configuration information is illegal.

[0340] Optionally, the trusted base 91 switches the memory access boundary from the memory of the kernel to the memory of the second task, including: finding third memory switching configuration information of the second task from the memory, and configuring the memory protection device according to the third memory switching configuration information. The third memory switching configuration information includes: the memory address information of the kernel and the memory operation permission of the kernel, as well as the memory address information of the second task and the memory operation permission of the second task. After configuration, the second task has no permission to operate on the memory of the kernel, and after configuration, the kernel has the permission to read the memory of the second task.

[0341] Optionally, the trusted base 91 is further configured to: close the interrupt before finding the third memory switching configuration information of the second task from the memory, and open the interrupt after completing the configuration of the memory protection device according to the third memory switching configuration information.

[0342] Optionally, the trusted base 91 is further configured to: compare whether the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory; if the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory, determine that the third memory switching configuration information is legal; the kernel 92 is further configured to: when the third memory switching configuration information is legal, call the second task to obtain the return result of the system service.

[0343] Optionally, the trusted base 91 is further configured to: if the third memory switching configuration information stored in the register is different from the third memory switching configuration information stored in the memory, determine that the third memory switching configuration information is illegal; the kernel 92 is further configured to: when the third memory switching configuration information is illegal, close the OS and / or terminate the second task.

[0344] Optionally, the OS and all applications on the computer system are in the privileged layer.

[0345] Optionally, after opening the interrupt, the trusted base 91 is further configured to:

[0346] When receiving an interrupt request, query the interrupt vector table, where the interrupt vector table includes a normal interrupt service function and an interrupt service function of the trusted base;

[0347] Enter the interrupt service function of the trusted base according to the interrupt vector table;

[0348] Obtain the return address of the interrupt, and determine whether the return address of the interrupt belongs to a preset address range;

[0349] When the return address of the interrupt belongs to the preset address range, determine that the interrupt is an illegal interrupt and take resilience protection;

[0350] When the return address of the interrupt does not belong to the preset address range, determine that the interrupt is a legal interrupt and call the normal interrupt service function.

[0351] Optionally, the trusted base 91 is further configured to: initialize the interrupt vector table, and the interrupt vector table is stored in the read-only segment of the trusted base.

[0352] Optionally, the trusted base 91 is further configured to: during the startup process of the computer system, perform I / O privilege scanning on the OS code segment and the code segments of tasks, and according to the scanning results, replace specific operations of non-privileged tasks, partially privileged tasks, and privileged tasks with exception instructions; start the OS.

[0353] Optionally, the specific operations of the non-privileged tasks include: IRQ register operation instructions, I / O status register query instructions, serial port register operations, timer register operations, system register operations, and memory protection device register operations; the specific operations of the partially privileged tasks include: system register operations and memory protection device register operations; the specific operations of the privileged tasks include memory protection device register operations.

[0354] The computer system of this embodiment can be used to execute the methods described in any one of Embodiments 3 to 6 of the above method embodiment. The specific implementation manners and technical effects are similar and will not be elaborated here.

[0355] Figure 16 For the structural schematic diagram of the computer system provided in Embodiment 10 of this application, as Figure 16 shown, the computer system 200 includes a processor 21, a memory 22, and a memory protection device 23. The memory 22 includes an internal memory. The processor 21 runs an operating system OS and applications. The kernel runs on the OS. The applications include one or more tasks. The trusted base also runs on the OS. The memory 22 is used to store instructions, and the processor 21 is used to execute the instructions stored in the memory 22 so that the processor 21 executes the methods described in any one of Embodiments 1 to 7 of the above method embodiment. The specific implementation manners and technical effects are similar and will not be elaborated here.

[0356] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be in electrical, mechanical or other forms.

[0357] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0358] In addition, each functional unit in various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.

[0359] The above integrated units implemented in the form of software functional units can be stored in a computer-readable storage medium. The above software functional units stored in a storage medium include several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute some steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

Claims

1. A method for kernel and task isolation, characterized in that, The method is applied to an autonomous driving system, on which an operating system OS and applications are running. A kernel is running on the OS. The applications include one or more tasks. A trusted base is also running on the OS. The OS and all applications on the autonomous driving system are in the privileged layer. The method includes: The kernel searches for a first task from a task preparation queue. The trusted base searches for first memory switching configuration information of the first task from memory, and configures a memory protection device according to the first memory switching configuration information. The memory protection device is a hardware component for protecting the memory of the autonomous driving system. The first memory switching configuration information includes the memory address information and memory operation permissions of the kernel, and the memory address information and memory operation permissions of the first task. After configuration, the first task has no permission to operate on the memory of the kernel. After configuration, the kernel has read permission to operate on the memory of the first task. The kernel calls the first task.

2. The method according to claim 1, wherein Before the trusted base searches for the first memory switching configuration information of the first task from memory, it further includes: The trusted base closes the interrupt. After the trusted base configures the memory protection device according to the first memory switching configuration information, it further includes: The trusted base opens the interrupt.

3. The method according to claim 1, characterized in that, Before the kernel calls the first task, it further includes: The trusted base compares whether the first memory switching configuration information stored in a register is the same as the first memory switching configuration information stored in the memory. If the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory, it is determined that the first memory switching configuration information is legal. When the first memory switching configuration information is legal, the kernel calls the first task.

4. The method according to claim 3, characterized in that, It further includes: If the first memory switching configuration information stored in the register is not the same as the first memory switching configuration information stored in the memory, the trusted base determines that the first memory switching configuration information is illegal. When the first memory switching configuration information is illegal, the kernel closes the OS and / or terminates the first task.

5. The method according to claim 2, wherein After the trusted base opens the interrupt, the method further includes: When an interrupt request is received, the trusted base queries an interrupt vector table, which includes a normal interrupt service function and an interrupt service function of the trusted base. The trusted base enters the interrupt service function of the trusted base according to the interrupt vector table. The trusted base obtains the return address of the interrupt and determines whether the return address of the interrupt belongs to a preset address range. When the return address of the interrupt belongs to the preset address range, the trusted base determines that the current interrupt is an illegal interrupt and takes resilience protection. When the return address of the interrupt does not belong to the preset address range, the trusted base determines that the current interrupt is a legal interrupt and calls the normal interrupt service function.

6. The method according to claim 5, wherein It further includes: The trusted base initializes the interrupt vector table, which is stored in the read-only segment of the trusted base.

7. The method according to any one of claims 1-6, characterized in that, It further includes: During the startup process of the autonomous driving system, the trusted base performs input / output (I / O) privilege scanning on the code segments of the kernel and the tasks. Based on the scanning results, the trusted base replaces specific operations in non-privileged tasks, partially privileged tasks, and privileged tasks with exception instructions. The trusted base starts the OS.

8. The method according to claim 7, wherein The specific operations of the non-privileged tasks include: IRQ register operation instructions, I / O status register query instructions, serial port register operations, timer register operations, system register operations, and memory protection device register operations. The specific operations of the partially privileged tasks include: system register operations and memory protection device register operations. The specific operation of the privileged task includes memory protection device register operation.

9. A method for kernel and task isolation, characterized in that, The method is applied to an autonomous driving system on which an operating system (OS) and applications are running. The OS runs a kernel, and the applications include one or more tasks. A trusted base also runs on the OS, and all applications on the OS and the autonomous driving system are in the privileged layer. The method includes: When a second task needs to call the system service application programming interface (API), the trusted base saves the task number of the second task. The trusted base searches for the second memory switching configuration information of the second task in the memory and configures the memory protection device according to the second memory switching configuration information. The memory protection device is a hardware component used to protect the memory of the autonomous driving system. The second memory switching configuration information includes the memory address information and memory operation permissions of the kernel, as well as the memory address information and memory operation permissions of the second task. After configuration, the kernel has no permission to operate on the memory of the second task, and the second task has read permission to operate on the memory of the kernel. The kernel calls the second task. The kernel calls the system service. After the system service is completed, the trusted base retrieves the task number of the second task and switches the memory access boundary from the memory of the kernel to the memory of the second task. The kernel calls the second task to obtain the return result of the system service.

10. The method according to claim 9, characterized in that, Before the trusted base searches for the second memory switching configuration information corresponding to the second task in the memory, it further includes: The trusted base disables interrupts. After the trusted base configures the memory protection device according to the second memory switching configuration information, it further includes: The trusted base enables interrupts.

11. The method according to claim 9, characterized in that Before the kernel calls the second task, it further includes: The trusted base compares whether the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory. If the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory, the trusted base determines that the second memory switching configuration information is legal. When the second memory switching configuration information is legal, the kernel invokes the second task.

12. The method according to claim 11, characterized in that, It further includes: If the second memory switching configuration information stored in the register is different from the second memory switching configuration information stored in the memory, the trusted base determines that the second memory switching configuration information is illegal; When the second memory switching configuration information is illegal, the kernel shuts down the OS and / or terminates the second task.

13. The method according to any one of claims 9-12, characterized in that, The switching of the memory access boundary from the memory of the kernel to the memory of the second task includes: The trusted base searches for the third memory switching configuration information of the second task in the memory, configures the memory protection device according to the third memory switching configuration information, and the third memory switching configuration information includes: the memory address information of the kernel and the memory operation permission of the kernel, as well as the memory address information of the second task and the memory operation permission of the second task. After configuration, the second task has no permission to operate on the memory of the kernel, and after configuration, the kernel has the permission to read the memory of the second task.

14. The method according to claim 13, wherein Before the trusted base searches for the third memory switching configuration information of the second task in the memory, it further includes: The trusted base closes the interrupt; After the trusted base configures the memory protection device according to the third memory switching configuration information, it further includes: The trusted base opens the interrupt.

15. The method according to claim 13, wherein Before the kernel invokes the second task to obtain the return result of the system service, it further includes: The trusted base compares whether the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory; If the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory, the trusted base determines that the third memory switching configuration information is legal; When the third memory switching configuration information is legal, the kernel invokes the second task to obtain the return result of the system service.

16. The method according to claim 15, wherein It further includes: If the third memory switching configuration information stored in the register is different from the third memory switching configuration information stored in the memory, the trusted base determines that the third memory switching configuration information is illegal; When the third memory switching configuration information is illegal, the kernel shuts down the OS and / or terminates the second task.

17. The method according to claim 10 or 14, characterized in that, After opening the interrupt, the method further includes: When receiving an interrupt request, the trusted base queries the interrupt vector table, and the interrupt vector table includes a normal interrupt service function and an interrupt service function of the trusted base; The trusted base enters the interrupt service function of the trusted base according to the interrupt vector table; The trusted base obtains the return address of the interrupt and determines whether the return address of the interrupt belongs to a preset address range; When the return address of the interrupt belongs to the preset address range, the trusted base determines that the interrupt is an illegal interrupt and takes resilience protection; When the return address of the interrupt does not belong to the preset address range, the trusted base determines that the interrupt is a legal interrupt and calls the normal interrupt service function.

18. The method according to claim 17, wherein It further includes: The trusted base initializes the interrupt vector table, and the interrupt vector table is stored in the read-only segment of the trusted base.

19. The method according to any one of claims 9-12, 14-16, 18, characterized in that, It further includes: During the startup process of the autonomous driving system, the trusted base performs I / O privilege scanning on the OS code segment and the code segments of tasks; Based on the scanning results, the trusted base replaces specific operations of non-privileged tasks, partial-privileged tasks, and privileged tasks with exception instructions; The trusted base starts the OS.

20. The method according to claim 19, characterized in that, The specific operations of the non-privileged tasks include: IRQ register operation instructions, I / O status register query instructions, serial port register operations, timer register operations, system register operations, and memory protection device register operations; The specific operations of the partial-privileged tasks include: system register operations and memory protection device register operations; The specific operation of the privileged task includes memory protection device register operation.

21. An autonomous driving system, characterized in that, An operating system OS and applications run on the autonomous driving system. A kernel runs on the OS. The applications include one or more tasks. A trusted base also runs on the OS. All applications on the OS and the autonomous driving system are in the privileged layer; The kernel is used to find the first task from the task preparation queue; The trusted base is used to find the first memory switching configuration information of the first task from the memory, and configure the memory protection device according to the first memory switching configuration information. The memory protection device is a hardware component used to protect the memory of the autonomous driving system; The first memory switching configuration information includes the memory address information and memory operation permissions of the kernel, as well as the memory address information and memory operation permissions of the first task. After configuration, the first task has no permission to operate on the memory of the kernel; after configuration, the kernel has read permission to the memory of the first task; The kernel also calls the first task.

22. The system according to claim 21, wherein The trusted base is further used for: Closing the interrupt before finding the first memory switching configuration information of the first task from the memory; Opening the interrupt after completing the configuration of the memory protection device according to the first memory switching configuration information.

23. The system according to claim 21, wherein The trusted base is further used for: Comparing whether the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory; If the first memory switching configuration information stored in the register is the same as the first memory switching configuration information stored in the memory, it is determined that the first memory switching configuration information is legal; The kernel is further used for: calling the first task when the first memory switching configuration information is legal.

24. The system according to claim 23, wherein The trusted base is further used for: If the first memory switching configuration information stored in the register is not the same as the first memory switching configuration information stored in the memory, it is determined that the first memory switching configuration information is illegal; The kernel is further configured to: when the first memory switching configuration information is illegal, shut down the OS and / or terminate the first task.

25. The system according to claim 22, wherein After the trusted base enables the interrupt, the trusted base is further configured to: When receiving an interrupt request, query an interrupt vector table, where the interrupt vector table includes normal interrupt service functions and interrupt service functions of the trusted base; Enter the interrupt service function of the trusted base according to the interrupt vector table; Obtain the return address of the interrupt, and determine whether the return address of the interrupt belongs to a preset address range; When the return address of the interrupt belongs to the preset address range, determine that the current interrupt is an illegal interrupt and take resilience protection; When the return address of the interrupt does not belong to the preset address range, determine that the current interrupt is a legal interrupt and call the normal interrupt service function.

26. The system according to claim 25, wherein The trusted base is further configured to: The trusted base initializes the interrupt vector table, and the interrupt vector table is stored in the read-only segment of the trusted base.

27. The system according to any one of claims 21-26, characterized in that, The trusted base is further configured to: During the startup process of the autonomous driving system, perform input / output (I / O) privilege scanning on the code segment of the kernel and the code segments of tasks; According to the scanning results, replace specific operations of non-privileged tasks, partially privileged tasks, and privileged tasks with exception instructions; Start the OS.

28. The system according to claim 27, wherein The specific operations of the non-privileged tasks include: IRQ register operation instructions, I / O status register query instructions, serial port register operations, timer register operations, system register operations, and memory protection device register operations; The specific operations of the partially privileged tasks include: system register operations and memory protection device register operations; The specific operation of the privileged tasks includes memory protection device register operations.

29. An autonomous driving system, characterized in that, An operating system (OS) and applications run on the autonomous driving system, a kernel runs on the OS, the applications include one or more tasks, and a trusted base also runs on the OS; all applications on the OS and the autonomous driving system are in the privileged layer; The trusted base is configured to save the task number of a second task when the second task needs to call a system service application programming interface (API); The trusted base is further configured to find second memory switching configuration information of the second task from memory, and configure a memory protection device according to the second memory switching configuration information, where the memory protection device is a hardware component for protecting the memory of the autonomous driving system; The second memory switching configuration information includes the memory address information and memory operation permissions of the kernel, and the memory address information and memory operation permissions of the second task. After configuration, the operation permission of the kernel for the memory of the second task is no permission, and the operation permission of the second task for the memory of the kernel is readable; The kernel is configured to call the second task and the system service; The trusted base is further configured to, after the system service is completed, take out the task number of the second task and switch the memory access boundary from the memory of the kernel to the memory of the second task. The kernel is further configured to call the second task to obtain the return result of the system service.

30. The system according to claim 29, wherein The trusted base is further configured to: Before looking up the second memory switching configuration information corresponding to the second task in the memory, turn off the interrupt; After completing the configuration of the memory protection device according to the second memory switching configuration information, turn on the interrupt.

31. The system according to claim 29, wherein The trusted base is further configured to: Compare whether the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory; If the second memory switching configuration information stored in the register is the same as the second memory switching configuration information stored in the memory, determine that the second memory switching configuration information is legal; The kernel is further configured to: when the second memory switching configuration information is legal, call the second task.

32. The system according to claim 31, characterized in that, The trusted base is further configured to: If the second memory switching configuration information stored in the register is different from the second memory switching configuration information stored in the memory, determine that the second memory switching configuration information is illegal; The kernel is further configured to: when the second memory switching configuration information is illegal, turn off the OS and / or terminate the second task.

33. The system according to any one of claims 29-32, characterized in that, The trusted base switches the memory access boundary from the memory of the kernel to the memory of the second task, including: Looking up the third memory switching configuration information of the second task in the memory, and configuring the memory protection device according to the third memory switching configuration information. The third memory switching configuration information includes: the memory address information of the kernel and the memory operation permission of the kernel, as well as the memory address information of the second task and the memory operation permission of the second task. After configuration, the second task has no permission to operate on the memory of the kernel, and after configuration, the kernel has the permission to read the memory of the second task.

34. The system according to claim 33, wherein The trusted base is further configured to: Before looking up the third memory switching configuration information of the second task in the memory, turn off the interrupt; After completing the configuration of the memory protection device according to the third memory switching configuration information, turn on the interrupt.

35. The system according to claim 33, characterized in that, The trusted base is further configured to: Compare whether the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory; If the third memory switching configuration information stored in the register is the same as the third memory switching configuration information stored in the memory, determine that the third memory switching configuration information is legal; The kernel is further configured to: when the third memory switching configuration information is legal, call the second task to obtain the return result of the system service.

36. The system according to claim 35, wherein The trusted base is further configured to: If the third memory switching configuration information stored in the register is different from the third memory switching configuration information stored in the memory, determine that the third memory switching configuration information is illegal; The kernel is further configured to: when the third memory switching configuration information is illegal, turn off the OS and / or terminate the second task.

37. The system according to claim 34, characterized in that, After turning on the interrupt, the trusted base is further configured to: When an interrupt request is received, query the interrupt vector table, where the interrupt vector table includes normal interrupt service functions and interrupt service functions of the trusted base; Enter the interrupt service function of the trusted base according to the interrupt vector table; Obtain the return address of the interrupt, and determine whether the return address of the interrupt belongs to a preset address range; When the return address of the interrupt belongs to the preset address range, determine that the interrupt is an illegal interrupt and take resilience protection; When the return address of the interrupt does not belong to the preset address range, determine that the interrupt is a legal interrupt and call the normal interrupt service function.

38. The system according to claim 37, wherein The trusted base is further configured to: Initialize the interrupt vector table, and the interrupt vector table is stored in the read-only segment of the trusted base.

39. The system according to any one of claims 29 - 32, 34 - 38, characterized in that, The trusted base is further configured to: During the startup process of the autonomous driving system, perform I / O privilege scanning on the OS code segment and the code segments of tasks; According to the scanning results, replace specific operations in non-privileged tasks, partially privileged tasks, and privileged tasks with exception instructions; Start the OS.

40. The system according to claim 39, wherein, The specific operations of the non-privileged tasks include: IRQ register operation instructions, I / O status register query instructions, serial port register operations, timer register operations, system register operations, and memory protection device register operations; The specific operations of the partially privileged tasks include: system register operations and memory protection device register operations; The specific operation of the privileged task includes memory protection device register operation.

41. An autonomous driving system, characterized in that, Comprising: A processor, a memory, and a memory protection device, where the memory includes an internal memory, the processor runs an operating system OS and applications, a kernel runs on the OS, the applications include one or more tasks, a trusted base also runs on the OS, the memory is used to store instructions, and the processor is used to execute the instructions stored in the memory, so that the processor executes the method according to any one of claims 1-8.

42. An autonomous driving system, characterized in that, Comprising: A processor, a memory, and a memory protection device, where the memory includes an internal memory, the processor runs an operating system OS and applications, a kernel runs on the OS, the applications include one or more tasks, a trusted base also runs on the OS, the memory is used to store instructions, and the processor is used to execute the instructions stored in the memory, so that the processor executes the method according to any one of claims 9-20.

Citation Information

Patent Citations

  • Dynamic configuration and peripheral access in a processor

    CN107408068A

Cited By

  • Method and apparatus for isolating kernel from task

    WO2022001514A1