System with increased protected storage area and erase protection
By introducing memory control circuitry into the microcontroller, the protected portion of the memory is expanded and protected, solving the problem of easy write protection revocation and achieving persistent and irreversible protection for important data.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MICROCHIP TECHNOLOGY INC
- Filing Date
- 2021-10-13
- Publication Date
- 2026-05-12
AI Technical Summary
Existing microcontrollers suffer from insufficient write protection capabilities, including easy undoing and irreversible write protection, and cannot effectively accommodate additional data that may be added later.
By introducing a memory control circuit (MCC), the protected portion of the memory is defined and expanded to ensure read-only access, and permanent protection is achieved through fuse settings to prevent the size of the protected portion from shrinking.
It enables permanent extension of the protected portion of the memory, preventing write and erase operations and ensuring the durability and irreversibility of important data such as calibration data and serial numbers.
Smart Images

Figure CN115668155B_ABST
Abstract
Description
[0001] priority
[0002] This application claims priority to U.S. Provisional Patent Application No. 63 / 091,333, filed on October 14, 2020, the contents of which are incorporated herein by reference in their entirety. Technical Field
[0003] This disclosure relates to computation, and more specifically, to systems with increased protected storage areas and erase protection. Background Technology
[0004] Existing microcontrollers can use flash memory in several ways. Flash memory can be used for application data, where software running on the microcontroller's processor can allocate and release portions of the memory for various real-time uses. Flash memory can be used to store boot code or other boot data. Furthermore, flash memory can be used to store other data in a more persistent manner. This can be referred to as a Memory Area Flash (SAF) block.
[0005] Users may wish to persist data in SAF blocks so that it becomes available to different software on the microcontroller over time. For example, serial numbers and calibration data allow users or software to reserve areas in flash memory for storage. Some microcontrollers offer write protection for these areas. However, the inventors of embodiments of this disclosure have found that write protection for such areas can be limited. The write protection itself may be easily revoked. Furthermore, irreversible write protection does not allow for the containment of additional data that may be added later, for which the user wishes to write-protect. Embodiments of this disclosure address one or more of these disadvantages of other solutions. Summary of the Invention
[0006] Embodiments of this disclosure may include an apparatus. The apparatus may include a processor. The apparatus may include memory communicatively coupled to the processor. The apparatus may include a memory control circuit (MCC). The MCC may be configured to: define a protected portion of memory, wherein the protected portion of memory is configured for read-only access by the processor; increase the size of the protected portion of memory; and prevent the size of the protected portion of memory from decreasing after the size of the protected portion of memory has increased.
[0007] Embodiments of this disclosure may include a method. The method may include defining a protected portion of memory communicatively coupled to a processor. The protected portion of memory may be configured for read-only access by the processor. The method may include increasing the size of the protected portion of memory. The method may include preventing a decrease in the size of the protected portion of memory after the size of the protected portion of memory has been increased. Attached Figure Description
[0008] Figure 1 This is an illustration of an exemplary system for increasing protected storage areas according to embodiments of the present disclosure.
[0009] Figure 2 This is an illustration of adding a protected storage area in a system according to an embodiment of the present disclosure.
[0010] Figure 3 This is an illustration of how a system according to an embodiment of the present disclosure increases, but does not decrease, the protected storage area in the system.
[0011] Figure 4 This is an exemplary method for protecting a storage area in a memory according to embodiments of the present disclosure. Detailed Implementation
[0012] Embodiments of this disclosure may include an apparatus. The apparatus may include a processor. The apparatus may include memory communicatively coupled to the processor. The apparatus may include a memory control circuit (MCC). The MCC may be implemented by analog circuitry, digital circuitry, instructions executed by the processor, or any suitable combination thereof. The processor executing the instructions of the MCC may be the same as or different from the processor communicatively coupled to the memory described above. The instructions for execution may be stored in non-transitory memory, and this memory may be the same as or different from the memory communicatively coupled to the processor described above. The MCC may be configured to define a protected portion of the memory. The protected portion of the memory may be configured for read-only access by the processor. The MCC may be configured to increase the size of the protected portion of the memory. This size may be increased by including more memory within the protected portion. The MCC may be configured to prevent the size of the protected portion of the memory from decreasing after the size of the protected portion of the memory has increased. The protected memory may be used for any suitable purpose, such as immutable bootloader code, configuration data, or calibration data. It can protect the protected memory from any suitable action, such as read operations, read operations on application memory or other specified memory locations, self-write, or total erase operations.
[0013] In conjunction with any of the above embodiments, the MCC can also be configured to permanently prevent the size of the protected portion of the memory from shrinking.
[0014] In conjunction with any of the above embodiments, the MCC can also be configured to permanently increase the size of the protected portion of the memory.
[0015] In conjunction with any of the above embodiments, the MCC can also be configured to write a value to a fuse specifying the address range of the protected portion of the memory in order to increase the size of the protected portion of the memory, the value being used to change the default value.
[0016] In conjunction with any of the above embodiments, the MCC can also be configured to write values to a fuse within an address range of a protected portion of a specified memory, based on settings that specify the type of read-only behavior.
[0017] In conjunction with any of the above embodiments, this setting may also indicate that overall erasure is not allowed.
[0018] In conjunction with any of the above embodiments, the MCC can also be configured to prevent changes to the setting based on this setting.
[0019] In conjunction with any of the above embodiments, the MCC can also be configured to prevent writes to the protected portion of the memory based on this setting.
[0020] In conjunction with any of the above embodiments, the specification of protecting a given memory location from total erasure may take precedence over the specification of protecting a given memory from self-write. Therefore, if a given memory is protected from total erasure, it can be protected from self-write by default, and no specification allowing self-write needs to be considered.
[0021] Figure 1 This is an illustration of an exemplary system 100 for increasing a protected storage area according to embodiments of the present disclosure. System 100 may include or be embodied as a processor, microcontroller, control circuitry, or any other suitable device. Furthermore, system 100 may include memory. The memory may include a protected storage area. The system may be configured to provide erase protection for the protected storage area. Additionally, in one embodiment, the device may be configured to increase a portion of the memory dedicated to the protected storage area. In one embodiment, although the device may be configured to increase a portion of the memory dedicated to the protected storage area, the device and memory may be configured to prevent the portion of memory dedicated to the protected storage area from shrinking. Therefore, the size of the protected storage area may be increased but not decreased.
[0022] For example, system 100 may include processor 104 and memory 108. Processor 104 and memory 108 may be implemented in any suitable manner. For example, processor 104 may include a processor of a microcontroller. Memory 108 may include flash memory. Processor 104 may be configured to read data elements from memory 108. Furthermore, processor 104 may be configured to write data elements to memory 108. However, the ability to write to specific portions of memory 108 may be controlled by suitable elements of system 100. For example, system 100 may include memory control circuitry (MCC) 102.
[0023] MCC 102 may be implemented by analog circuitry, digital circuitry, instructions executed by a processor (such as processor 104), or any suitable combination thereof. MCC 102 may be configured to control the allocation of memory (such as memory 108) for storage. MCC 102 may be communicatively coupled to processor 104 or included within the processor. Furthermore, MCC 102 may be communicatively coupled to any suitable number and type of registers 106. Although shown as a register, register 106 may be implemented in any suitable memory, fuse, or other suitable storage mechanism. MCC 102 may be configured to read register 106 or set register 106. Processor 104 may also be configured to read or set register 106. Register 106 may be implemented within any suitable portion of system 100, such as memory 108.
[0024] Memory 108 is shown as logically divided into different blocks 124. While an embodiment of dividing memory 108 into blocks is shown, memory 108 can be divided into any suitable number and type of blocks. In one embodiment, memory 108 may be divided into different blocks 124 such that MCC 102 can be configured to define portions of block 124 that will be reserved for protected storage. However, portions of memory 108 may be reserved for protected storage in any suitable manner. Furthermore, portions of memory 108 (such as block 122) may represent those portions of memory 108 that are not configured to be reserved by MCC 102 for protected storage in the same way as portions of block 124 may be reserved. Block 122 and the portions of block 124 that are not reserved for protected storage can be used for any suitable purpose of system 100.
[0025] exist Figure 1 In some embodiments, portions of memory 108 reserved for protected storage may include portions 110, 112, and 114. Each of portions 110, 112, and 114 may represent a portion of blocks 124A, 124B, and 124C reserved for protected storage, respectively. Furthermore, in Figure 1In one embodiment, portions of memory 108 not reserved for protected storage may include portions 116, 118, 120, and 122. Each of portions 116, 118, and 120 may represent a portion of blocks 124A, 124B, and 124C that is not reserved for protected storage. In one embodiment, the size of one or more portions 110, 112, and 114 may be expanded to include additional memory addresses, thus increasing the size of the memory reserved for protected storage. In another embodiment, the size of block 114 may be prevented from decreasing, even if it is expandable. In yet another embodiment, the size of one or more portions 110, 112, and 114 may be expanded, and the size of one or more portions 116, 118, and 120 may be reduced, respectively. Therefore, expanding the memory reserved for protected storage within a memory block may come at the cost of not being able to reserve corresponding memory for protected storage within the same memory block. Figure 1 The protected storage in the memory can be represented by storage area 126, which includes portions 110, 112, and 114. Figure 1 The unprotected storage in the memory can be represented by storage area 128, which includes portions 116, 118, 120, and 122.
[0026] The portions of memory 108 reserved for protected storage as storage area 128 can be reserved for any suitable purpose. For example, memory 108 may include any information that can be placed in read-only memory (ROM). Memory 108 may include, for example, immutable bootloader code, configuration data, or calibration data. MCC can be configured to expand storage area 126 to accommodate additional data required for such purposes.
[0027] Parts of memory 108 can be reserved for protected storage in storage area 126 in any suitable manner. For example, parts of memory 108 can be marked as read-only to be included in the protected storage in storage area 126. Furthermore, parts of memory 108 can be marked as read-only in any suitable manner. For example, parts of memory 108 can be marked as read-only by preventing the following operations: a total erase operation, a self-write operation, or a read operation on a given other part of the memory. MCC 102 can set parts of memory 108 in various read-only modes. Furthermore, the implementation of such settings can be performed by MCC 102. These modes can be set by writing values to register 106. Furthermore, instances of such settings may appear in register 106 for associated instances of block 124.
[0028] In one embodiment, portions of memory 108 can be preserved for protected storage in storage region 126 by allowing memory addresses to be marked as unavailable for a total erase operation. Such a total erase operation can be performed by an external programmer. The ability to designate a portion of memory 108 as unavailable for a total erase is given as LOCK. When LOCK is logic high or "1", the corresponding portion of memory 108 is unavailable for a total erase. When LOCK is logic low or "0", the corresponding portion of memory 108 is available for a total erase. LOCK can be expressed using negation, such as... Therefore, when When the value is logic low or "0", the corresponding portion of memory 108 may not be available for complete erasure. When the value is logic high or "1", the corresponding portion of memory 108 can be erased entirely. Alternatively, the reverse can also be achieved, where when... When the value is logic low or "0", the corresponding portion of memory 108 can be completely erased, and when When the value is logic high or "1", the corresponding portion of memory 108 cannot be used for overall erasure. LOCK or The value can be stored in register 106. Furthermore, for each block 124 of memory 108, there may be a value for LOCK or... The register instance is used to specify whether a given block 124 is available or not for overall erasure. LOCK or Values can be stored, for example, as fuses. By using fuses, the default memory location can be specified as erasable entirely, but when changed to non-erasable, the change can be permanent and irreversible. When an overall erase occurs, a LOCK or... The fuse is set to "1". This allows setting the stored lock or... A portion of the value's memory is protected from being completely erased.
[0029] In another embodiment, portions of memory 108 can be reserved for protected storage in storage region 126 by allowing memory addresses to be marked as unavailable for self-write operations. Such self-write operations may include software running from memory blocks that are reserved for protected storage, thus prohibiting writes to the same memory blocks, or memory blocks reserved for any such editing within system 100. The ability to designate a portion of memory 108 as unavailable for self-write operations is given as WRTSAF. When WRTSAF is logic high or "1", the corresponding portion of memory 108 is unavailable for self-write operations. When WRTSAF is logic low or "0", the corresponding portion of memory 108 is available for self-write operations. WRTSAF can be expressed as a negation, such as... .when When the value is logic low or "0", the corresponding portion of memory 108 can be used for self-write operations. When When the value is logic high or "1", the corresponding portion of memory 108 can be used for self-write operations. Alternatively, the reverse can also be achieved, where when... When the value is logic low or "0", the corresponding portion of memory 108 cannot be used for self-write operations, and when When the value is logic high or "1", the corresponding portion of memory 108 can be used for self-write operations. WRTSAF or The value can be stored in register 106. Furthermore, for each block 124 of memory 108, there may be a value for WRTSAF or... The register instance is used to specify whether a given block 124 is available or not for self-write operations. WRTSAF or Values can be stored, for example, as fuses. By using fuses, the default memory location can be specified as self-writable, but when changed to non-self-writable, the change can be permanent and irreversible.
[0030] In various embodiments, portions of memory 108 can be reserved for protected storage in storage area 126 by allowing memory addresses to be marked as, for example, not readable from certain other flash memory locations. For instance, some memory addresses can be marked as not readable from code executable in the application area. This can be used, for example, to allow a bootloader and other specific code to read the stored key, but not to allow other applications to read the key.
[0031] In one embodiment, for a given memory location, LOCK may take precedence over WRTSAF. For example, when register 106 specifies that LOCK indicates that total erasure is unavailable, self-write may also be unavailable by default, regardless of the WRTSAF specification. When LOCK indicates that total erasure is available, the availability of self-write may be specified by WRTSAF. Furthermore, any other suitable specification, and combinations of such specifications with LOCK and WRTSAF, may be used as additional methods to implement read-only behavior for protected regions of memory 108.
[0032] As described above, for a given memory location, address, or block, LOCK and WRTSAF can be specified in register 106. For example, instances of LOCK and WRTSAF for each block 124 can be provided in register 106. Furthermore, in one embodiment, register 106 may include a SAFSIZE register or specification for each block 124, specifying which portions of the corresponding block 124 will be reserved for protected storage in storage region 126. SAFSIZE can specify the address range that will be in the protected portion of the memory. The specific manner of storage protection in the corresponding block 124 can be provided by WRTSAF and LOCK. The SAFSIZE specification can be implemented in any suitable manner, such as by three bits. These three bits can define the address or other specification of the portions of a given block 124 to be protected. Thus, for each of the N different memory blocks 124, a corresponding SAFSIZE[0...2] can exist. N WRTSAF N and LOCK N Register or specified.
[0033] exist Figure 1 In the illustrated embodiment, the ability to enable or disable total erase and self-write can be specified. and The negative representation of LOCK is used to express this. This can result in implementations where "1" or "0" can be programmed as bits in registers 106 and block 124, but optionally "0" can be permanently assigned to this bit. For example, a bit specified by a given LOCK can be implemented as a fuse with a default value of "1", but when "0" is written to this bit, it is permanent. In other implementations, where fuses are implemented but these bits default to a value of "0", but when "1" is written to this bit, it is permanent, the positive representation of LOCK and WRTSAF can be used to express enabling or disabling the ability to perform a total erase and self-write.
[0034] As mentioned above, WRTSAF N and LOCK N The register or specification defines how a corresponding portion of block 124N is protected. In one embodiment, WRTSAF N and LOCK N The register or specification can also define how to protect WRTSAF. N and LOCK N Register or the specified register itself.
[0035] For example, block 124A may include components from... and The specified portion 110 is neither self-write protected nor fully erase protected. Portion 110 is self-writeable and fully eraseable. The size of portion 110 within block 124A can be specified by SAFSIZE. This portion of block 124A not specified as part of portion 110 by SAFSIZE can be shown as portion 116. Furthermore, the register values of LOCK, WRTSAF, and SAFSIZE in block 124A are also self-writeable and fully eraseable. Therefore, within portion 110, register 106A, including these specified values, is shown. Register 106A may have the same protection as the memory (block 124A) specified by register 106A. For the reader's understanding of this relationship, register 106A is shown as being within portion 110, but register 106A may be implemented within portion 110 or elsewhere.
[0036] Block 124B may include components from... The portion 112, specified by WRTSAF, is protected against self-write but not against total erase. Portion 112 is not self-write but is erasable. The size of portion 112 within block 124B can be specified by SAFSIZE. This portion of block 124B not specified by SAFSIZE as part of portion 112 can be shown as portion 118. Furthermore, the register values of LOCK, WRTSAF, and SAFSIZE in block 124B are erasable but not self-writeable. Therefore, within portion 112, register 106B, including these specified values, is shown. Register 106B may have the same protection as the memory (block 124B) specified by register 106B. For the reader's understanding of this relationship, register 106B is shown as being within portion 112, but register 106B may be implemented within portion 112 or elsewhere.
[0037] Block 124C may include a portion 114, specified by LOCK, that is protected against self-write but not against total erase. Given the specification of LOCK, the specification of WRTSAF can be ignored. Portion 114 cannot be self-written or completely erased. The size of portion 114 within block 124C may be specified by SAFSIZE. This portion of block 124C not specified by SAFSIZE as part of portion 114 may be shown as portion 120. Furthermore, the register values of LOCK, WRTSAF, and SAFSIZE in block 124C may also be neither completely erased nor self-written. Therefore, within portion 114, register 106C, including these specifications, is shown. Register 106C may have the same protection as the memory (block 124C) specified by register 106C. For the reader's understanding of this relationship, register 106C is shown as being within portion 114, but register 106C may be implemented within portion 114 or elsewhere.
[0038] However, in one embodiment, when LOCK is enabled, the memory locations or registers used for SAFSIZE and LOCK can be implemented as bit-only programs, without the ability to undo writes or write different values. Once a bit is written, its value cannot be changed. As mentioned above, various implementations can therefore consider whether the default value is "0" or "1", and based on that default value, selectively write another value to permanently assign that value. If the default value is "1", then the specification of LOCK in the register can actually be... That is, because enabling LOCK is irreversible, and the default value in the system is set to "1", enabling or disabling LOCK can be done by setting specific... This is accomplished using the register value. When the default value is "1", LOCK is disabled. When LOCK is enabled, It is irreversibly changed to "0".
[0039] The specification of SAFSIZE is similarly responsible for the default values of bits in the system. When LOCK is enabled, SAFSIZE can be configured to be written to, but once a bit of SAFSIZE is written, it cannot be undone. Therefore, SAFSIZE can be configured to increase the corresponding protected area of the memory (such as the corresponding portions in portions 110, 112, and 114) as bits are written. However, when LOCK is enabled and SAFSIZE writes cannot be undone, the corresponding protected area of the memory can be increased but not decreased. Similarly, since LOCK itself cannot be disabled once enabled, the bits of SAFSIZE cannot be changed once written. Furthermore, as described above, once a portion of memory 108 is designated as a protected area of memory (such as the corresponding areas in portions 110, 1112, and 114), the content can be protected from total erasure or self-write according to the settings of LOCK and WRTSAF.
[0040] Users of System 100 can utilize this capability in any suitable manner. For example, after System 100 has been manufactured and deployed for use, parts of System 100 can be calibrated or recalibrated. Preventing such calibration data from being overwritten can be useful. Even if new calibration data is later determined, existing calibration data can be prevented from being erased to provide forensic analysis of the operation of System 100. In another embodiment, as System 100 is created and deployed through the supply chain, distributors, incorporated into larger systems, etc., different serial numbers can be added to identify System 100 in different contexts. Even as more identification information is added to System 100, existing serial numbers can be prevented from being erased. In yet another embodiment, as System 100 performs various tasks, these tasks can be recorded in the blockchain. When a task is performed, it can be verified or authenticated and added as a new leaf to the existing record in the blockchain. Erasure of the entire blockchain, both new and old, can be prevented. In yet another embodiment, System 100 may require additional cryptographic keys or certificates. New keys or certificates can be added to system 100 in read-only mode without overwriting existing keys or certificates. In another embodiment, bits specifying the boot region of memory 108 may be included in...
[0041] In each of these embodiments, protected areas of the memory (such as portions 110, 112, 114) may be added so that such additional information can be stored in a read-only manner. Data to be added can be written to unprotected areas of the memory (such as portions 116, 118, 120), and then MCC 102 can be configured to redesignate a portion of the corresponding block 124 as a protected area of the memory.
[0042] For example, MCC 102 can be configured to determine that a new cryptographic key will be written to memory 108 in read-only mode. MCC 102 can write the new cryptographic key to portion 120 of block 124C. Then, MCC 102 can specify an additional value to be written to the SAFSIZE address of block 124C, causing the address where the new cryptographic key is now part of portion 114 instead of portion 120. This may not be reversible if LOCK is enabled for portion 114.
[0043] Furthermore, before designating unprotected areas of memory 108 (such as portions 116, 118, 120) as protected areas of memory 108 (such as portions 110, 112, 114), system 100 may use the unprotected areas of memory 108 in any other suitable manner. Contents can be read, written, and erased as needed. Therefore, system 100 can flexibly provide read-only data to users as needed.
[0044] Register 106 may include any other suitable data that is prevented from being overwritten when a lock is enabled. For example, register 106 may include a boot code address or a designation of memory allocated for such boot code. MCC 102 may write the address or size of the boot code into an unprotected area of memory 108 (such as section 120) and then enable a lock on the written data (via, for example, extension section 114). In another embodiment, register 106 may include a designation on whether an external recorder or programmer (such as a recorder or programmer for in-circuit serial programming (ICSP) is permitted. Once such a designation is disabled by, for example, writing a "0" to a register bit, a lock on the location of the written bit can be enabled via MCC 102, making the designation permanent. This can be used, for example, in a secure deployment system 100, to prevent an external programmer from further accessing its contents.
[0045] Figure 2 This is an illustration of a protected storage area in an added system 100 according to an embodiment of the present disclosure. Figure 2 The diagram shows memory block 202 with portions 204 and 206. Block 202 can implement... Figure 1 Any suitable item in block 124. Part 204 can be implemented. Figure 1 Any suitable item from parts 110, 112, and 114. Part 206 can be implemented. Figure 1 Any one of the appropriate options in parts 116, 118, and 120.
[0046] In (A), there may be no protected portion of block 202. Therefore, portion 204 may be empty or nonexistent. Portion 206 may occupy the entire block 202. The size of block 202 may be, for example, 896 words. The SAFSIZE specification for this arrangement may be, for example, {11111111}.
[0047] In (B), both protected and unprotected portions of block 202 may exist. Portion 204 may include 128 words. Portion 206 may include 768 words. The SAFSIZE specification for this arrangement could be, for example, {11111110}. Therefore, by changing the last bit of the SAFSIZE from "1" to "0", it is possible that 128 words have been reassigned from portion 206 to portion 204.
[0048] Part 204 can occupy either the first 128 words of block 202 or the last 128 words of block 202. Similarly, part 206 can occupy either the last 768 words of block 202 or the first 768 words of block 202.
[0049] In (C), both protected and unprotected portions of block 202 may exist. Portion 204 may include 512 words. Portion 206 may include 384 words. The SAFSIZE specification for this arrangement may be, for example, {11100000}. Therefore, by changing the three additional bits of the SAFSIZE from "1" to "0", it is possible that additional words have been reassigned from portion 206 to portion 204.
[0050] While the above illustrates a specific allocation between the protected memory in section 204 and the unprotected memory in section 206, any suitable allocation scheme can be used. The LOCK specification can be used to allow the protected memory to expand while preventing it from shrinking by designating each bit of SAFSIZE to correspond to a memory region in block 202, as shown. Figure 3 See below for more details.
[0051] Figure 3 This is an illustration of how a system 100 according to an embodiment of this disclosure can increase but prevent the reduction of protected storage areas in the system. (Using...) Figure 2 Using the same enumeration process and elements, two different scenarios are presented for changing the allocation of the protected and unprotected memory portions of block 202.
[0052] When LOCK is not enabled, the assignment bit of SAFSIZE (default "1") can be written to "0", and then subsequently rewritten to "1", etc. Therefore, by writing "0" to the second, third, and fourth rightmost bits of SAFSIZE, the state of block 202 during the transition from (B) to (C) is compared, and the size of portion 204 is adjusted from the first 128 words of block 202 to the first 512 words of block 202. Furthermore, when examining the state of block 202 during the transition from (C) to (B), rewriting "1" to the second, third, and fourth rightmost bits of SAFSIZE adjusts the size of portion 204 from the first 512 words of block 202 all the way back to the first 128 words of block 202.
[0053] However, when LOCK is enabled, the given position of SAFSIZE can be written to "0", but not subsequently rewritten to "1". The state of block 202 during the transition from (B) to (C) is indicated by writing "0" to the second, third, and fourth rightmost bits of SAFSIZE. The size of portion 204 is adjusted from the first 128 words of block 202 to the first 512 words of block 202. However, there is no ability to transition from (C) back to (B). The second, third, and fourth rightmost bits of SAFSIZE are prevented from being rewritten to "1". The size of portion 204 cannot be adjusted from the first 512 words of block 202 back to the first 128 words of block 202.
[0054] Figure 4 This is an exemplary method 400 for protecting a storage region in memory according to embodiments of the present disclosure. Method 400 can be performed by any suitable part of system 100. Specifically, method 400 can be performed by MCC 102. MCC 102 may represent processor 102, performing method 400 on memory 108. Method 400 may include... Figure 4 The steps may be more or fewer. The steps of method 400 may optionally be repeated, omitted, performed in parallel or recursively, or performed in any suitable order. Method 400 may begin with any suitable step, such as step 405. Method 400 may optionally be repeated entirely or partially.
[0055] In step 405, it can be determined whether a write operation has been received. If not, method 400 can proceed to step 410. If yes, method 400 can proceed to step 415.
[0056] In step 410, other processing may be performed, such as processing unrelated to the write operation or permission, or processing related to a write operation or permission not separately addressed in method 400. It can be determined whether method 400 should be repeated. If so, method 400 may return to step 405. Otherwise, method 400 may terminate.
[0057] In step 415, it can be determined whether the received write is directed to an address within the protected data block. If so, method 400 may proceed to step 420. Otherwise, method 400 may proceed to step 445.
[0058] In step 420, it can be determined whether the LOCK specification indicates that a total erase of that address is prevented. If so, method 400 may proceed to step 425. Otherwise, method 400 may proceed to step 430.
[0059] In step 425, writing may be rejected. Method 400 may proceed to step 410.
[0060] In step 430, it can be determined whether the WRTSAF specification indicates: prevent self-write to the address. If yes, method 400 may proceed to step 440. Otherwise, method 400 may proceed to step 435.
[0061] In step 435, it can be determined whether any other write permissions have been applied, and whether additional writes are permitted. If not, method 400 may proceed to step 425. Otherwise, method 400 may proceed to step 445.
[0062] In step 440, it can be determined whether the attempted write is a total erase or a self-write. If the attempted write is a self-write, this can be prevented by specifying WRTSAF, and method 400 can proceed to step 425. If the attempted write is a total erase, this can be allowed by specifying LOCK and not prevented by specifying WRTSAF, and method 400 can proceed to step 445.
[0063] In step 445, writing is permitted.
[0064] In step 450, it is determined whether the data written as a result of step 445 will become permanently read-only. If not, method 400 may proceed to step 410. Otherwise, method 400 may proceed to step 455.
[0065] In step 455, a lock can be enabled for the block that was just written. The designation of the protected portion of the block, such as SAFSIZE, can be edited to increment the protected area of the block, thereby including the data written as a result of step 445. Method 400 can then proceed to step 410.
[0066] While exemplary embodiments have been described above, this disclosure may have other variations and embodiments without departing from the spirit and scope of these embodiments.
Claims
1. An apparatus comprising: processor; The memory is communicatively coupled to the processor, and the memory includes multiple memory blocks, each containing a set of contiguous memory addresses; and a memory control circuit (MCC), the MCC being used to: The protected portion is defined as a subset of a first memory block among the plurality of memory blocks, wherein the protected portion as a subset of the first memory block is configured for read-only access by the processor and the protected portion of the first memory block is smaller than the entire first memory block; Increase the size of the protected portion, which is a subset of the first memory block; After the size of the protected portion, which is a subset of the first memory block, is increased, the size of the protected portion, which is a subset of the first memory block, is prevented from decreasing. In response to determining whether a total erase operation is allowed based on a first value stored in a first register, a self-write operation is determined based on a second value stored in a second register; as well as In response to determining that the overall erase operation is not allowed based on the first value stored in the first register, it is determined that the self-write operation is not allowed regardless of the second value stored in the second register.
2. The apparatus of claim 1, wherein the MCC permanently prevents the size of the protected portion, which is a subset of the first memory block, from decreasing.
3. The apparatus of claim 1, wherein the MCC permanently increases the size of the protected portion, which is a subset of the first memory block.
4. The apparatus of claim 1, wherein the MCC is configured to: in order to increase the size of the protected portion, which is a subset of the first memory block, write a value to a fuse specifying an address range of the protected portion, which is a subset of the first memory block, the value being used to change a default value.
5. The apparatus of claim 4, wherein the MCC writes the value to the fuse specifying the address range of the protected portion as a subset of the first memory block based on a setting for specifying the type of read-only behavior, the type of read-only behavior being a single type among a plurality of possible read-only behaviors.
6. The apparatus of claim 5, wherein the setting configures the protected portion, which is a subset of the first memory block, for read-only access by an instruction disallowing total erasure, the total erasure comprising a command to completely erase one or more memory regions.
7. The apparatus of claim 5, wherein the MCC prevents changes to the settings based on the settings.
8. The apparatus of claim 5, wherein the MCC prevents writing to the protected portion, which is a subset of the first memory block, based on the settings.
9. The apparatus of claim 1, wherein the protected portion, which is a subset of the first memory block, is configured for read-only access by the processor via an instruction disallowing self-write operations.
10. The apparatus of claim 1, wherein the protected portion, which is a subset of the first memory block, is configured to be protected by the processor via an instruction that read operations on a given memory address are not permitted.
11. A method comprising: The protected portion is defined as a subset of a memory block comprising a set of contiguous memory addresses and communicatively coupled to a processor, wherein the protected portion of the memory block is configured for read-only access by the processor and the protected portion of the memory block is smaller than the entire memory block, wherein the read-only access includes an overall erase setting and a self-write setting, the overall erase setting taking precedence over the self-write setting; Increase the size of the protected portion, which is a subset of the memory block; After the size of the protected portion, which is a subset of the memory block, is increased, the size of the protected portion, which is a subset of the memory block, is prevented from decreasing. In response to determining whether a total erase operation is allowed based on a first value stored in a first register, a self-write operation is determined based on a second value stored in a second register; as well as In response to determining that the overall erase operation is not allowed based on the first value stored in the first register, it is determined that the self-write operation is not allowed regardless of the second value stored in the second register.
12. The method of claim 11, comprising: Permanently prevent the size of the protected portion, which is a subset of the memory block, from being reduced.
13. The method of claim 11, comprising: The size of the protected portion, which is a subset of the memory block, is permanently increased.
14. The method of claim 11, comprising: In order to increase the size of the protected portion, which is a subset of the memory block, a value is written to a fuse that specifies the address range of the protected portion, which is a subset of the memory block, to change the default value.
15. The method of claim 14, comprising: Based on the settings used to specify the type of read-only behavior, the value is written to the fuse specifying the address range of the protected portion that is a subset of the memory block, wherein the type of read-only behavior is a single type among a plurality of possible read-only behaviors.
16. The method of claim 15, wherein the setting is configured to indicate that a total erase is not allowed, the total erase comprising a command to completely erase one or more memory regions.
17. The method of claim 15, comprising: Based on the aforementioned settings, changes to those settings are prevented.
18. The method of claim 15, comprising: Based on the aforementioned settings, writing to the protected portion, which is a subset of the memory block, is prevented.
19. The method of claim 11, wherein the protected portion, which is a subset of the memory block, is configured for read-only access by the processor via an indication that self-write operations are not permitted.
20. The method of claim 11, wherein the protected portion, which is a subset of the memory block, is configured to be protected by the processor via an indication that read operations on a given memory address are not permitted.