A memory protection component and method that support multiple general-purpose embedded devices
By designing a memory protection component that supports multiple embedded devices, the instability of embedded devices caused by memory problems is solved, and the universality and development efficiency of programs are improved.
Patent Information
- Application Number
- CN202210634854.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-06
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-06-06
AI Technical Summary
Embedded devices are often unstable during operation due to problems such as illegal memory access, cross-borders, and cross-permissions. The existing technology cannot effectively solve it, which increases the difficulty and cost of development.
Design a memory protection component that supports common to multiple embedded devices, including a memory protection component abstraction layer module and a processor with memory protection unit. By identifying and matching different processors, general memory protection permissions, thread stack detection and global protection modules are configured.
It solves the problem of processor dependence on a single memory protection unit, improves program universality and reuse efficiency, and reduces the difficulty of developing and porting embedded products.
Smart Images

Figure CN115033931B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of memory protection in embedded operating systems, and particularly relates to a memory protection component and method that support multiple embedded devices in a general manner. Background Art
[0002] With the rapid development of embedded systems in the field of communication technology, the applications of embedded devices are becoming more and more complex. Problems such as illegal memory access, memory out-of-bounds, and memory permission crossover seriously affect the stability of embedded product development and greatly increase the development difficulty. In chip design and integrated development software, although a large number of memory debugging interfaces and software tools are provided, the problem of instability during the operation of embedded products caused by the lack of memory protection cannot be effectively solved, resulting in abnormal operation of the products accidentally or extremely accidentally. Usually, such problems require senior engineers to track and analyze for a long time.
[0003] In order to detect in a timely manner during the early stage of development the occurrence of program problems caused by memory, during the process of embedded software development, engineers will choose processors with memory protection units, construct various memory protection components according to these different processors, and then rewrite the application programs.
[0004] In order to reduce the need in the program design of embedded products to change different memory protection methods and rewrite application programs multiple times for the same application when facing multiple types of processors, the present invention solves the problem of dependence on processors with a single memory protection unit, making the program more general, reducing the transplantation difficulty, increasing the efficiency of program reuse, and reducing the development work of embedded products. Summary of the Invention
[0005] In view of this, there is provided a memory protection component and method that support multiple embedded devices in a general manner.
[0006] The memory protection component and method provided by the present invention are applied to an embedded operating system. The memory protection component includes a memory protection component abstraction layer module and a processor with a memory protection unit;
[0007] The processor with a memory protection unit includes multiple types of processors with a memory protection unit;
[0008] The memory protection component abstraction layer module receives a first parameter for identifying a processor with a memory protection unit and performs identification and matching with the processor.
[0009] Further, the multiple types of processors with a memory protection unit include ARM type processors, RISC-V type processors, MIPS type processors, and CSKY type processors.
[0010] Furthermore, the memory protection component abstraction layer module further includes a general memory protection identification module, a general memory protection permission module, a general memory protection thread stack detection module, and a general memory protection global protection module;
[0011] The memory protection component abstraction layer module receives a first parameter for identifying a processor with a memory protection unit. The general memory protection identification module identifies and matches the processor with the memory protection unit according to the first parameter, and allocates the general memory protection permission module, the general memory protection thread stack detection module, and the general memory protection global protection module according to the identified processor.
[0012] Furthermore, the first parameter includes a processor interface description with a memory protection unit, a processor memory protection configuration table, and processor memory configuration information;
[0013] The processor interface description is used to identify various types of processors with a memory protection unit;
[0014] The processor memory protection configuration table is used to configure the starting address of the application program thread stack and the size of the thread stack
[0015] The processor memory configuration information is used to represent 8 or 16 memory regions.
[0016] Furthermore, the memory protection component abstraction layer module configures 8 or 16 memory regions for various types of processors with a memory protection unit according to the first parameter.
[0017] Furthermore, applied to an embedded operating system, the memory protection component includes a memory protection component abstraction layer module and a processor with a memory protection unit. The method includes:
[0018] The memory protection component abstraction layer module receives a first parameter for identifying a processor with a memory protection unit, and identifies and matches with the processor;
[0019] The processor with a memory protection unit includes various types of processors with a memory protection unit;
[0020] The memory protection component abstraction layer module includes a general memory protection identification module, a general memory protection permission module, a general memory protection thread stack detection module, and a general memory protection global protection module;
[0021] The memory protection component abstraction layer module receives a first parameter for identifying a processor with a memory protection unit. The general memory protection identification module identifies and matches the processor with the memory protection unit according to the first parameter, and allocates a general memory protection permission module, a general memory protection thread stack detection module, and a general memory protection global protection module according to the processor.
[0022] Furthermore, the memory protection component abstraction layer module identifies the processor with the memory protection unit according to the first parameter, and identifies and matches with the processor. When thread switching occurs in the processor, the memory protection configuration table is switched through the general memory protection thread stack detection module.
[0023] Furthermore, the general memory protection thread stack detection module includes the following steps:
[0024] The memory protection thread stack detection module configures the user to register a memory access exception callback service according to the memory protection configuration table, which is used to execute the callback service when detecting a thread stack overflow;
[0025] When the memory protection thread stack detection module performs thread switching in the thread program, it obtains the memory protection configuration table in the thread control block, including the starting address of the thread stack and the size of the thread stack;
[0026] The memory protection thread stack detection module sets the 32-byte distance area from the top of the thread stack to be read-only according to the processor with the memory protection unit identified by the first parameter;
[0027] The memory protection thread stack detection module detects the 32-byte stack area.
[0028] Furthermore, the general memory protection global protection module includes the following steps:
[0029] The general memory protection global protection module identifies the processor with the memory protection unit according to the first parameter, and sets the starting address and area size of the global memory protection area as the global memory protection area configuration table;
[0030] The general memory protection global protection module reads the global memory protection configuration table;
[0031] The general memory protection global protection module inserts the configuration information of the global memory protection configuration table into the global memory protection area configuration table;
[0032] The general memory protection global protection module protects the thread memory data according to the global memory protection area configuration table.
[0033] Furthermore, the global memory protection area configuration table includes the starting address of the thread stack and the size of the thread stack.
[0034] A memory protection component and method applicable to multiple general embedded devices provided by the present invention are applied in an embedded operating system. The memory protection component includes a memory protection component abstraction layer module and a processor with a memory protection unit. The processor with a memory protection unit includes multiple types of processors with memory protection units. The memory protection component abstraction layer module receives a first parameter for identifying the processor with a memory protection unit and performs identification and matching with the processor. The present invention solves the problem of dependence on a single processor with a memory protection unit, making the program more general, reducing the transplantation difficulty, increasing the efficiency of program reuse, and reducing the development work of embedded products.
[0035] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following specifically enumerates preferred embodiments and, in conjunction with the accompanying drawings, makes the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] To more clearly illustrate the technical solutions of the present invention, the following briefly introduces the drawings required to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0037] Figure 1 A block diagram of a memory protection component provided by the present invention.
[0038] Figure 2 Another block diagram of a memory protection component provided by the present invention.
[0039] Figure 3 A flowchart of a method for a memory protection component provided by the present invention.
[0040] Figure 4 A flowchart of a sub-step for the memory protection component abstraction layer module to receive the first parameter in the method for a memory protection component provided by the present invention.
[0041] Figure 5 A flowchart of the running steps of the memory protection component abstraction layer module in the method for a memory protection component provided by the present invention.
[0042] Figure 6 A flowchart of the steps of the general memory protection thread stack detection module in the memory protection component abstraction layer module in the method for a memory protection component provided by the present invention.
[0043] Among them, 10 - Memory Protection Component Abstraction Layer Module; 11 - General Memory Protection Identification Module; 12 - General Memory Protection Permission Module; 13 - General Memory Protection Thread Stack Detection Module; 14 - General Memory Protection Global Protection Module; 20 - Processor with Memory Protection Unit; 21 - ARM-Type Processor; 22 - RISC-V-Type Processor; 23 - MIPS-Type Processor; 24 - CSKY-Type Processor. Detailed implementation
[0044] The technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. The components of the present invention described in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of the present invention provided in the accompanying drawings below is not intended to limit the scope of the present invention claimed, but only represents the selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0045] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0046] With the rapid development of embedded systems in the field of communication technology, the applications of embedded devices are becoming more and more complex. Problems such as illegal memory access, memory out-of-bounds, and memory permission crossing often seriously affect the stability and development difficulty of embedded product development. In chip design and integrated development software, although a large number of memory debugging tools and interfaces are provided, they cannot effectively handle the unstable factors in embedded products caused by the lack of memory protection. These unstable factors often manifest as occasional occurrences of product problems and require senior engineers to track and analyze for a long time.
[0047] In order to detect the occurrence of program problems caused by memory in a timely manner at an early stage of development, during the process of embedded software development, engineers will choose processors with memory protection units, construct various memory protection components according to these different processors, and then rewrite the application program.
[0048] In order to reduce the need to change different memory protection methods and rewrite the application program multiple times for the same application when facing multiple types of processors in the program design of embedded products, the present invention solves the problem of dependence on processors with a single memory protection unit, making the program more general, reducing the transplantation difficulty, increasing the efficiency of program reuse, and reducing the development work of embedded products.
[0049] Based on the above research, a memory protection component and method that support multiple general-purpose embedded devices. Please refer to Figure 1 , Figure 1 which is a block diagram of a memory protection component provided by the present invention. The memory protection component includes a memory protection component abstraction layer module 10 and a processor 20 with a memory protection unit.
[0050] Furthermore, the processor 20 with a memory protection unit includes multiple types of processors with a memory protection unit.
[0051] The memory protection component abstraction layer module 10 receives a first parameter for identifying the processor 20 with a memory protection unit, and performs identification and matching with the processor 20.
[0052] Furthermore, when multiple types of processors with a memory protection unit are replaced, the memory protection component abstraction layer module 10 needs to find, according to the first parameter of the processor to be replaced, the parameters of multiple types of processors for matching the target memory protection unit to be replaced in the memory protection component abstraction layer module 10, compare the parameters for matching the target processor to be replaced with the second parameter. If the parameters for matching the processor to be replaced are consistent with the second parameter, then the processor is matched with the target processor to be replaced. It can be understood that the second parameter is also a specific parameter of the target processor to be replaced. Furthermore, in this way, the application layer solves the dependence on a single processor and improves the generality of program applications.
[0053] Furthermore, please refer to Figure 2 , the memory protection component abstraction layer module further includes a general memory protection identification module 11, a general memory protection permission module 12, a general memory protection thread stack detection module 13, and a general memory protection global protection module 14.
[0054] Among them, multiple types of processors with a memory protection unit include an ARM type processor 21, a RISC-V type processor 22, a MIPS type processor 23, and a CSKY type processor 24.
[0055] The memory protection component abstraction layer module 10 receives a first parameter for identifying a processor with a memory protection unit. The general memory protection identification module 11 identifies and matches the processor 20 with a memory protection unit according to the first parameter, and allocates the general memory protection permission module 12, the general memory protection thread stack detection module 13, and the general memory protection global protection module 14 according to the processor.
[0056] Furthermore, the first parameter includes a processor interface description with a memory protection unit, a processor memory protection configuration table, and processor memory configuration information;
[0057] The processor interface description is used to identify various types of processors with a memory protection unit;
[0058] The processor memory protection configuration table is used to configure the starting address of the application program thread stack and the size of the thread stack;
[0059] The processor memory configuration information is used to represent 8 or 16 memory regions.
[0060] Please refer to Figure 3 , which is a schematic flowchart of a method for a memory protection component provided by the present invention. The following will Figure 3 elaborate in detail on the specific process shown.
[0061] Step S10: The memory protection component abstraction layer module 10 receives the first parameter for identifying the processor 20 with a memory protection unit.
[0062] Step S20: The memory protection component abstraction layer module 10 determines the target processor type from various types of processors with a memory protection unit according to the first parameter.
[0063] Among them, the memory protection component abstraction layer module 10 includes a general memory protection identification module 11, a general memory protection permission module 12, a general memory protection thread stack detection module 13, and a general memory protection global protection module 14.
[0064] Step S30: The general memory protection component abstraction layer module 10 identifies and matches with the target processor with a memory protection unit.
[0065] Among them, the various types of processors with a memory protection unit include ARM type processors 21, RISC-V type processors 22, MIPS type processors 23, and CSKY type processors 24. However, the various types of processors include but are not limited to the processors mentioned in the present invention.
[0066] Please refer to Figure 4 , which is a schematic flowchart of the sub-steps of the memory protection component abstraction layer module receiving the first parameter in a method for a memory protection component provided by the present invention.
[0067] Before the memory protection component abstraction layer module 10 determines the corresponding target processor from various types of processors with a memory protection unit according to the first parameter, the method further includes the following steps:
[0068] Step S11: The memory protection component abstraction layer module 10 obtains the first parameter passed in from the application layer.
[0069] Step S12: The general memory protection recognition module 11 recognizes and matches the processor type according to the processor interface description with a memory protection unit.
[0070] Among them, the processor interface description is used to recognize multiple types of processors with memory protection units.
[0071] Step S13: The general memory protection recognition module 11 configures the program thread stack according to the processor memory protection configuration table.
[0072] Among them, the processor memory protection configuration table is used to configure the starting address of the application program thread stack and the size of the thread stack;
[0073] Step S14: The general memory protection recognition module 11 configures the memory area according to the processor memory protection configuration information.
[0074] Among them, the processor memory configuration information is used to represent 8 or 16 memory areas.
[0075] Please refer to Figure 5 , which is a schematic diagram of the running step process of the memory protection component abstraction layer module in a method for a memory protection component provided by the present invention. After the general memory protection component abstraction layer module 10 receives the first parameter and passes it to the general memory protection recognition module 11 to recognize and match multiple types of processors with memory protection units, the method further includes the following steps:
[0076] Step S31: The general memory protection component abstraction layer module 10 allocates the general memory protection permission module 12.
[0077] The general memory protection permission module 12 configures the partition table of the current thread according to the processor memory protection configuration information and inserts the memory area configuration into the current thread partition table.
[0078] Step S32: The general memory protection component abstraction layer module 10 allocates the general memory protection thread stack detection module 13.
[0079] The general memory protection thread stack detection module 13 configures the memory access exception callback service that the user needs to register according to the memory protection configuration table to execute the callback service when detecting a thread stack overflow.
[0080] The general memory protection thread stack detection module 13 obtains the memory protection configuration table in the thread control block when the thread program performs thread switching, including the starting address of the thread stack and the size of the thread stack.
[0081] The general memory protection thread stack detection module 13 sets the 32-byte distance area from the top of the thread stack to read-only permission according to the processor with a memory protection unit identified by the first parameter.
[0082] The top of the thread stack is divided into an increasing memory address stack and a decreasing stack according to multiple types of processors with memory protection units. If it is an increasing stack, the 32-byte distance area from the top of the thread stack is the area obtained by subtracting 32 bytes from the top of the stack. If it is a decreasing stack, the 32-byte distance area from the top of the thread stack is the area obtained by adding 32 bytes to the top of the stack.
[0083] The general memory protection thread stack detection module 13 detects the 32-byte stack area.
[0084] Step S33: The general memory protection component abstraction layer module allocates the function table of the general memory protection global protection module.
[0085] Further, please refer to Figure 6 , which is a schematic flow chart of the steps of the general memory protection thread stack detection module of the memory protection component abstraction layer module in a method for a memory protection component provided by the present invention. After identification and matching, the general memory protection component abstraction layer module 10 allocates the general memory protection thread stack detection module 13. The method for program operation further includes the following steps:
[0086] Step S321: Perform memory protection configuration table switching through the general memory protection thread stack detection module 13.
[0087] Step S322: According to the configuration in the memory protection configuration table, the user needs to register a memory access exception callback service, and the registered exception callback service responds and executes when a thread stack overflow occurs.
[0088] Step S323: Obtain the memory protection configuration table in the thread control block, including the starting address of the thread stack and the size of the thread stack.
[0089] Step S324: The general memory protection thread stack detection module 13 sets the 32-byte distance area from the top of the thread stack to read-only permission according to the processor with a memory protection unit identified by the first parameter
[0090] Step S325: Determine whether the new thread performs a write operation on the protected 32-byte stack area. If a write operation is performed, execute step S3251. If no write operation is performed on the 32-byte stack area, execute step S326.
[0091] Step S3251: Trigger the memory access exception service, and respond and execute the memory access exception callback service that the user needs to register.
[0092] Step S326: The general memory protection component abstraction layer module allocates the function table of the general memory protection global protection module.
[0093] In summary, the present invention provides a memory protection component and method applicable to multiple general embedded devices and used in an embedded operating system. The memory protection component includes a memory protection component abstraction layer module and a processor with a memory protection unit. The processor with a memory protection unit includes multiple types of processors with memory protection units. The memory protection component abstraction layer module receives a first parameter for identifying the processor with a memory protection unit and performs identification and matching with the processor. The present invention solves the problem of dependence on a processor with a single memory protection unit, making the program more general, reducing the transplantation difficulty, increasing the efficiency of program reuse, and reducing the development work of embedded products.
[0094] In the embodiments provided by the present invention, it should be understood that the disclosed components and methods can also be implemented in other ways. The above-described component and method embodiments are merely illustrative. For example, the flowcharts and block diagrams in the drawings show the possible architectures, functions, and operations of the components, methods, and computer program products according to the embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0095] In addition, in each embodiment of the present invention, the functional modules may be integrated together to form an independent part, or each module may exist alone, or two or more modules may be integrated to form an independent part.
[0096] When the above functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device to execute all or part of the steps of the methods described in the various embodiments of the present invention.
[0097] It should be noted that in this document, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element. In addition, the terms "first", "second", etc. are only used for descriptive distinction and cannot be construed as indicating or implying relative importance.
[0098] The above are only optional embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A memory protection component that supports multiple embedded devices in a general way, Characterized in that: Applied to an embedded operating system, the memory protection component includes a memory protection component abstraction layer module and a processor with a memory protection unit; The processor with a memory protection unit includes multiple types of processors with a memory protection unit; The memory protection component abstraction layer module receives a first parameter for identifying a processor with a memory protection unit and identifies and matches it with the processor; The memory protection component abstraction layer module further includes a general memory protection identification module, a general memory protection permission module, a general memory protection thread stack detection module, and a general memory protection global protection module; The memory protection component abstraction layer module receives a first parameter for identifying a processor with a memory protection unit. The general memory protection identification module identifies and matches the processor with a memory protection unit according to the first parameter, and allocates the general memory protection permission module, the general memory protection thread stack detection module, and the general memory protection global protection module according to the processor with a memory protection unit; The first parameter includes a processor interface description with a memory protection unit, a processor memory protection configuration table, and processor memory configuration information; The processor interface description is used to identify multiple types of processors with a memory protection unit; The processor memory protection configuration table is used to configure the starting address of the application program thread stack and the size of the thread stack; The processor memory configuration information is used to represent 8 or 16 memory regions.
2. The memory protection component that supports multiple embedded devices in a general way according to claim 1, Characterized in that The multiple types of processors with a memory protection unit include ARM type processors, RISC-V type processors, MIPS type processors, and CSKY type processors.
3. The memory protection component that supports multiple embedded devices in a general way according to claim 1, Characterized in that The memory protection component abstraction layer module configures 8 or 16 memory regions for multiple types of processors with a memory protection unit according to the first parameter.
4. A memory protection method that supports multiple embedded devices in a general way, Characterized in that Applied to an embedded operating system, the device includes the memory protection component according to any one of claims 1-3. The memory protection component includes a memory protection component abstraction layer module and a processor with a memory protection unit. The method includes: The memory protection component abstraction layer module receives a first parameter for identifying a processor with a memory protection unit and identifies and matches it with the processor; The processor with a memory protection unit includes multiple types of processors with a memory protection unit; The memory protection component abstraction layer module includes a general memory protection identification module, a general memory protection permission module, a general memory protection thread stack detection module, and a general memory protection global protection module; The memory protection component abstraction layer module receives a first parameter for identifying a processor with a memory protection unit. The general memory protection identification module identifies and matches the processor with the memory protection unit according to the first parameter, and allocates a general memory protection permission module, a general memory protection thread stack detection module, and a general memory protection global protection module according to the processor with the memory protection unit.
5. A memory protection method applicable to multiple embedded devices according to claim 4, wherein, the memory protection component abstraction layer module identifies the processor with the memory protection unit according to the first parameter, and performs identification and matching with the processor. When thread switching occurs in the processor, the memory protection configuration table is switched through the general memory protection thread stack detection module.
6. A memory protection method applicable to multiple embedded devices according to claim 4, wherein, the general memory protection thread stack detection module includes the following steps: The memory protection thread stack detection module configures the memory access exception callback service that the user needs to register according to the memory protection configuration table, and is used to execute the callback service when detecting a thread stack overflow; When the thread program performs thread switching, the memory protection thread stack detection module obtains the memory protection configuration table in the thread control block, including the starting address of the thread stack and the size of the thread stack; The memory protection thread stack detection module sets the 32-byte distance area at the top of the thread stack as a read-only permission according to the processor with the memory protection unit identified by the first parameter; The memory protection thread stack detection module detects the 32-byte stack area.
7. A memory protection method applicable to multiple embedded devices according to claim 4, wherein, the general memory protection global protection module includes the following steps: The general memory protection global protection module identifies the processor with the memory protection unit according to the first parameter, and sets the starting address and area size of the global memory protection area as the global memory protection area configuration table; The general memory protection global protection module reads the global memory protection configuration table; The general memory protection global protection module inserts the configuration information of the global memory protection configuration table into the global memory protection area configuration table; The general memory protection global protection module protects the thread memory data according to the global memory protection area configuration table.
8. A memory protection method applicable to multiple embedded devices according to claim 7, wherein, the global memory protection area configuration table includes the starting address of the thread stack and the size of the thread stack.
Citation Information
Patent Citations
System and method
CN112749397A
Multi-process MPU protection method and device and electronic equipment
CN113569231A