A Memory Isolation Method, Device, and Medium for an Embedded System
By using domain protection units and domain state controllers to generate and manage memory access policies in embedded systems, the problems of large overhead of memory isolation performance and coarse protection granularity in the prior art are solved, and efficient memory isolation and protection are achieved.
Patent Information
- Application Number
- CN202510130712.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-06
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-02-06
AI Technical Summary
The memory isolation technology of existing embedded systems has a large overhead in application scenarios with high performance requirements, and the protection granularity is relatively coarse, making it difficult to meet the needs of complex systems for fine memory management.
The domain protection unit generates an initial domain policy according to the configuration of the target system, receives memory access requests, and determines the source domain and target domain through the domain state controller, generates access instructions and judges access permissions through the domain protection unit, and allows or denies access.
Effectively block unauthorized memory access, protect system security and data confidentiality, ensure that data in each domain can only be accessed and modified by domains with corresponding permissions, and ensure the integrity and accuracy of the data.
Smart Images

Figure CN119576814B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer science and technology, and particularly to a memory isolation method, device, and medium for an embedded system. Background Art
[0002] An embedded system is a computer system based on a microprocessor, usually embedded in other devices or products for controlling, monitoring, or performing specific tasks, with characteristics such as lightweight and strong specialization. In the current booming Internet of Things (IoT), embedded systems are widely used in many fields such as personal health care, home automation, intelligent transportation, and large-scale industry. However, due to the lightweight nature of embedded systems themselves, they are extremely vulnerable to serious security threats such as code injection, buffer overflow, and memory leakage. Therefore, in order to improve the security of embedded systems, it is particularly important to perform memory isolation on embedded systems.
[0003] For the existing memory isolation technology of embedded systems, the mapping from virtual memory to physical memory is usually controlled by a page table to manage the access permissions of different tasks to memory, such as a Memory Protection Unit (MPU). This method incurs a large overhead during domain switching due to the need for privileged-level intervention, which becomes a serious bottleneck in application scenarios with high performance requirements. Moreover, the protection granularity is relatively coarse, making it difficult to meet the needs of complex systems for fine-grained memory management. Summary of the Invention
[0004] To solve the above problems, this application proposes a memory isolation method for an embedded system, including:
[0005] Generating a corresponding initial domain policy for each memory area through a domain protection unit according to the configuration of the target system;
[0006] Receiving a memory access request, determining the source domain and target domain of the requested access through a domain status controller, obtaining the execution task in the memory access request, and adjusting the operating mode of the target system according to the execution task;
[0007] Generating an access instruction based on the memory access request and sending the access instruction to the domain protection unit;
[0008] Judging whether the source domain has the access permission to the target domain through the domain protection unit according to the initial domain policy corresponding to the target domain;
[0009] If so, allow the access and execute the execution task corresponding to the access instruction.
[0010] On the other hand, this application also proposes a memory isolation device for an embedded system, including:
[0011] At least one processor; and,
[0012] A memory communicatively connected to the at least one processor; wherein,
[0013] The memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute a memory isolation method for an embedded system as described in the above example.
[0014] On the other hand, the present application also proposes a non-volatile computer storage medium storing computer-executable instructions, and the computer-executable instructions are configured as: a memory isolation method for an embedded system as described in the above example.
[0015] The memory isolation method for an embedded system proposed by the present application can bring the following beneficial effects:
[0016] By the domain protection unit checking the access instructions according to the corresponding domain policy, unauthorized memory access operations can be directly blocked effectively in hardware, thereby effectively avoiding the tampering and stealing of critical system data by malicious programs or error programs, and protecting the security of the system and the confidentiality of data.
[0017] By isolating the memory, it is ensured that the data within each domain can only be accessed and modified by the domain with the corresponding permissions, preventing other irrelevant or untrusted domains from interfering with and damaging the data, and ensuring the integrity and accuracy of the data. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0019] Figure 1 is a schematic flowchart of a memory isolation method for an embedded system in an embodiment of the present application;
[0020] Figure 2 is a schematic flowchart of a memory isolation process in an embodiment of the present application;
[0021] Figure 3 is a schematic diagram of a memory isolation device for an embedded system in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] To make the objectives, technical solutions and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments of this application and the corresponding drawings. Obviously, the described embodiments are only a part rather than all of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.
[0023] The technical solutions provided by each embodiment of this application will be described in detail below with reference to the drawings.
[0024] As Figure 1 shown, an embodiment of this application provides a memory isolation method for an embedded system, including:
[0025] S101: Through a domain protection unit, generate corresponding initial domain policies for each memory area according to the configuration of the target system.
[0026] Specifically, analyze the target system, including the hardware architecture of the system, the type of processor, the memory layout, and the functional requirements of the system, etc. According to the memory layout of the target system, divide the physical memory into several memory areas, and each memory area corresponds to a different function or module. For example, divide the memory into a kernel area, a user application area, a device driver area, a data storage area, etc. Through the domain protection unit, define corresponding address mappings for each memory area, clarify the start address and end address of each memory area, and the boundaries between them, and generate an address space configuration policy based on the address space mapping.
[0027] Furthermore, according to the functional requirements corresponding to the memory area, set the allocation ownership, trusted objects, and protection levels corresponding to the memory area, and generate corresponding memory access protection policies based on the allocation ownership, trusted objects, and protection levels, so as to determine the access permissions and security levels of the memory segments. Among them, the permission indicates the permission for the code stored in this memory area segment, -x indicates the execution permission, and -rw indicates the read and write permission; the trust relationship indicates which domains this domain can be accessed by. As Figure 2 shown, the R1 domain can only be accessed by itself, the R2 domain can be accessed by R2 and R3, and R3 can be accessed by R1 and R3. Each domain can be accessed by itself, and trusted domains can be added in addition.
[0028] For example, for the kernel area, read, write, and execution permissions in privileged mode may be allowed, but any access in non-privileged mode is prohibited; for the user application area, read and write operations by user programs in non-privileged mode are allowed, but execution permissions are prohibited (to prevent code injection). As Figure 2As shown, the ownership of code segment Region1 is the memory region Region1, and it has no ownership of memory regions Region2 or Region3.
[0029] For example, in an Internet of Things device, different functional modules may correspond to different domains. Suppose there are a data acquisition module (Region1), a data processing module (Region2), and a communication module (Region3) in the device. The data collected by the data acquisition module is stored in a specific memory segment, whose ownership belongs to Region1, and it only trusts Region1 and Region2 to access it, with the protection level set to normal. When the data processing module (Region2) needs to process the collected data, since it is in the trust list, it can access this memory segment; while if the communication module (Region3) attempts to access this memory segment, because it is not in the trust list, the access will be blocked, ensuring the security and isolation of the data.
[0030] It should be noted that the domain protection unit (Region Protection Unit, domain status register) is responsible for configuring address space allocation and protecting memory access. The domain protection unit formulates detailed domain policies for each memory region, including important information such as domain ownership, trust relationships, and protection levels. Through these policies, the domain protection unit can precisely control the access permissions of different domains to each memory segment, achieving efficient memory isolation and protection.
[0031] It should be noted that the role of the domain policy is to configure the address space and protect memory access. It assigns ownership, trust, and protection levels to each memory segment, thereby determining the access permissions and security levels of the memory segment. As Figure 2 shown, if the access comes from an untrusted domain, such as Region2's access to some code segments in Region1, the access will be blocked and an exception will be thrown. In Figure 2 , the control states register (Control States Register, CSR) is used for domain status management and implementation of domain protection policies. Domain status management includes the following RSR (domain status controller) and PRSR (pre-domain status controller), which limit the switching of the processor between privileged and non-privileged states. Domain protection includes information and policies such as controlling the ownership, trust, and protection levels of memory regions. The real-time domain represents the domain in which the current processor is located; the address range represents the address number corresponding to this domain, corresponding to the memory segment encoding in the memory.
[0032] It should be noted that after generating the corresponding initial domain policies for each memory region, at the software level, the driver completes the initialization settings for the hardware and is ready to accept calls from the application program. The application program can perform operations such as creating domains and allocating memory through the API interface, where the API interface refers to a software - encapsulated function library.
[0033] S102: Receive a memory access request, determine the source domain and target domain of the requested access through the domain status controller, obtain the execution task in the memory access request, and adjust the operating mode of the target system according to the execution task.
[0034] Specifically, upon receiving a memory access request, the domain status controller determines the source domain of the program that issues the access request based on the relevant information carried in the request, or by querying specific registers, data structures, etc., and determines the target domain of the requested access by parsing the memory address in the request. Obtain the execution task in the memory access request, and adjust the operating mode of the target system according to the execution task.
[0035] Among them, the operating mode of the target system includes a privileged mode and a non - privileged mode. The access permissions of the processor to system resources are different in different modes. In the privileged mode, the processor can access hardware resources without restriction and execute special instructions, which is used for the operation of key components such as the operating system kernel; the non - privileged mode strictly restricts resource access for the operation of ordinary user programs.
[0036] It should be noted that during the operation of the computer system, various programs, processes, or hardware devices continuously generate memory access requirements, such as reading data for calculation or writing operation results, etc., because various programs or processes send memory access requests to the target system.
[0037] It should be noted that the Region State Register (RSR) is used to represent the active domain in which the processor is currently located in the non - privileged mode. It plays a key identification role during the memory access process, restricting the processor to perform operations only within the specified domain, thereby implementing domain - based memory access control.
[0038] S103: Generate an access instruction based on the memory access request and send the access instruction to the domain protection unit.
[0039] Specifically, the memory access request is analyzed to obtain request information, including basic information such as the target memory address to be accessed, access type (read, write, or execute), and the associated execution task. According to the parsed request information, corresponding access instructions are generated. For example, if the execution task is to load the executable code of an application, then the access type is likely to be "read", and the target memory address should be the area where the application code is stored.
[0040] Further, the generated access instructions are sent to the domain protection unit.
[0041] S104: Through the domain protection unit, according to the initial domain policy corresponding to the target domain, determine whether the source domain has the access right to the target domain.
[0042] Specifically, the domain protection unit checks the access instruction according to the initial domain policy to determine whether the source domain of the request has the access right to the target domain, that is, whether it has the right to perform the requested operation on the specified memory address of the target domain.
[0043] If so, access is allowed, and the execution task corresponding to the access instruction is executed. If not, access is denied, an exception report is generated, based on the exception report, the exception situation corresponding to the access request is determined, and the corresponding exception handling is triggered. When the exception situation is out-of-bounds access or unauthorized domain access, the process corresponding to the access request is aborted, and an error report is generated based on the request information corresponding to the access request. When the exception situation is insufficient permissions, the error code corresponding to insufficient permissions is returned.
[0044] For example, if the target memory area belongs to the operating system kernel domain and only specific domains in privileged mode have the right to access, the domain protection unit will check whether the source domain of the request is in privileged mode and has the corresponding permissions. If the access instruction conforms to the domain policy, the domain protection unit will allow the instruction to continue execution, thereby realizing access to the target memory area; if not, access will be denied, and the corresponding exception handling operation will be executed.
[0045] S105: If so, access is allowed, and the execution task corresponding to the access instruction is executed.
[0046] Specifically, if the source domain corresponding to the access instruction has the access right to the target domain, the access task corresponding to the access instruction number is executed.
[0047] In addition, during the execution of the task, when a task switching event is triggered, the target domain to be switched corresponding to the target task for switching is obtained, and it is determined whether the switching target domain is the same as the target domain. If not, domain switching is performed through the previous domain status register.
[0048] Further, obtain the domain identification field in the previous region state register, set the domain identification field to the switching target domain identification corresponding to the switching target domain, determine the task execution type of the target task, adjust the operating mode of the target system according to the execution type, and execute the target task based on the switching target domain.
[0049] When the operating mode of the target system is the privileged mode and the target task is the execution of a user program, convert the operating mode of the target system to the non-privileged mode, and back up the domain state register through the previous region state register. When the operating mode of the target system is the non-privileged mode and the target task is the execution of a system call, convert the operating mode of the target system to the privileged mode, and restore the domain state register through the previous region state register.
[0050] Among them, during the register data replication process, some verification operations will be performed to check whether the domain identification in the previous region state register is valid and whether it is consistent with the domain information configured in the system to ensure the integrity and correctness of the data. If an abnormality is found, an error handling mechanism will be triggered to suspend the domain switching process and perform troubleshooting.
[0051] It should be noted that the previous region state register (PRSR) is mainly used for communication and state backup between privilege levels. When the processor switches from the privileged mode to the non-privileged mode, the previous region state register will back up the value of the domain state register; conversely, when switching back from the non-privileged mode to the privileged mode, the domain state register will restore the corresponding value from the previous region state register to ensure the stable and correct switching of the domain state.
[0052] It should be noted that with the domain switching, the domain state register needs to reconfigure the memory access permissions according to the new domain state. The domain state register will look up the domain policies related to the new domain, and these policies have been pre-set during system initialization or domain creation. The domain policies contain the access permission information of each memory segment for different domains, such as read, write, and execute permissions, etc. According to the new domain policies, the domain state register will adjust the accessibility settings of the memory area. For the memory segments that the new domain has the right to access, the processor will enable the corresponding access paths. For the memory segments that the new domain has no right to access, the processor will disable their access paths to ensure data security and isolation.
[0053] It should be noted that in this specification, in terms of domain-forced memory isolation, the domain status register closely managed by the processor operates in coordination with the domain protection unit. The domain status register, as the core domain identifier in non-privileged mode, accurately reflects the current active domain status, while the previous domain status register plays a crucial role in the privilege level conversion process, ensuring the stable transfer and seamless connection of the domain status. The domain protection unit carefully configures domain policies containing key elements such as ownership, trust, and protection levels for each region of the system memory. This unique design architecture enables efficient and precise memory access management in a multi-domain environment, successfully eliminating the high overhead generated during traditional domain switching, and effectively ensuring the smoothness and stability of system operation. In terms of the domain isolation function, the system can strongly support the isolation operation of multiple non-privileged domains. During system execution, the processor intelligently applies corresponding protection and occupancy mechanisms based on the ownership information of the code. The domain status register accurately activates memory segments according to this mechanism, quickly constructs a legal address space, and realizes efficient and reliable domain switching. For example, during domain switching, by quickly updating the domain identifier, the accessible memory area of the domain can be reconfigured immediately, greatly reducing the switching overhead compared with traditional methods, and significantly improving the system's response speed and operation efficiency.
[0054] By having the domain protection unit check the access instructions according to the corresponding domain policy, unauthorized memory access operations can be directly blocked effectively in hardware, thus effectively avoiding the tampering and stealing of critical system data by malicious or incorrect programs, and protecting the security of the system and the confidentiality of data.
[0055] By isolating the memory, it is ensured that the data within each domain can only be accessed and modified by the domain with the corresponding permissions, preventing other irrelevant or untrusted domains from interfering with and damaging the data, and ensuring the integrity and accuracy of the data.
[0056] As Figure 3 shown, the embodiment of the present application also proposes a memory isolation device for an embedded system, including:
[0057] At least one processor; and,
[0058] A memory communicatively connected to the at least one processor; wherein,
[0059] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a memory isolation method for an embedded system as described in any one of the above embodiments.
[0060] An embodiment of the present application also provides a non-volatile computer storage medium storing computer-executable instructions, and the computer-executable instructions are configured as: a memory isolation method for an embedded system as described in any of the above embodiments.
[0061] The embodiments in the present application are all described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the device and medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiments.
[0062] The device and medium provided by the embodiment of the present application correspond one by one to the method. Therefore, the device and medium also have beneficial technical effects similar to those of the corresponding method. Since the beneficial technical effects of the method have been described in detail above, the beneficial technical effects of the device and medium will not be elaborated here.
[0063] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0064] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0065] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device realizes the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0066] These computer program instructions may also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or steps for implementing the functions specified in multiple blocks.
[0067] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0068] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.
[0069] Computer-readable media includes permanent and non-permanent, removable and non-removable media and can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0070] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.
[0071] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A memory isolation method for an embedded system, characterized in that: include: Collect geographic information and actual traffic information of the target city through information collection equipment; Generate a corresponding initial domain policy for each memory area according to the configuration of the target system through the domain protection unit; Receive a memory access request, determine a source domain and a target domain of the access request through a domain state controller, obtain an execution task in the memory access request, and adjust an operation mode of the target system according to the execution task; generating an access instruction based on the memory access request, and sending the access instruction to the domain protection unit; By means of the domain protection unit, judging whether the source domain has access rights to the target domain according to the initial domain policy corresponding to the target domain; If yes, access is allowed and the execution task corresponding to the access instruction is executed; After executing the current task corresponding to the access instruction, the method further includes: When a task switching event is triggered, a switching target domain corresponding to the target task to be switched is obtained, and it is determined whether the switching target domain is consistent with the target domain; If not, a domain switch is performed through the previous domain status register; The performing of domain switching through the previous domain status register specifically includes: Obtaining a domain identification field in a previous domain status register, and setting the domain identification field to a switching target domain identification corresponding to a switching target domain; Determine a task execution type of the target task, and adjust an operation mode of the target system according to the execution type; Based on the switching target domain, executing the target task; The operation mode includes a privileged mode and a non-privileged mode; the task execution type includes user program execution and system call execution; The adjusting the operation mode of the target system according to the target task specifically includes: When the operation mode of the target system is a privileged mode and the target task is executed by a user program, converting the operation mode of the target system to a non-privileged mode, and backing up the domain status register through the pre-domain status register; When the operation mode of the target system is a non-privileged mode and the target task is executed by a system call, the operation mode of the target system is converted to a privileged mode, and the domain status register is restored through the previous domain status register.
2. The memory isolation method of an embedded system according to claim 1, characterized in that: Before obtaining the domain identification field in the pre-domain status register and setting the domain identification field to the switching target domain identification corresponding to the switching target domain, the method further includes: Obtaining a switching target domain identifier corresponding to the switching target domain through the domain status register; The domain identifier value corresponding to the switching target domain identifier is extracted by base conversion, and it is determined whether the domain identifier value is within a valid domain identifier range.
3. The memory isolation method of an embedded system according to claim 1, characterized in that: The initialization and strategy include address space configuration strategy and memory access protection strategy; The domain protection unit generates a corresponding initial domain policy for each memory area according to the configuration of the target system, specifically including: Divide the physical memory into several memory areas according to the memory layout of the target system; By means of a domain protection unit, corresponding address space mappings are defined for the plurality of memory regions, and corresponding address space configuration policies are generated based on the address space mappings; According to the functional requirements corresponding to the memory area, the allocation ownership, trust object and protection level corresponding to the memory area are set, and the corresponding memory access protection policy is generated based on the allocation ownership, the trust object and the protection level.
4. The memory isolation method of an embedded system according to claim 1, characterized in that: After determining whether the source domain has access rights to the target domain, the method further includes: If not, access is denied and an exception report is generated; Based on the exception report, an exception situation corresponding to the access request is determined, and corresponding exception processing is triggered.
5. The memory isolation method of an embedded system according to claim 4, characterized in that: The abnormal situations include out-of-bounds access, insufficient permissions, and unauthorized domain access; When the abnormal situation is the cross-border access or the unauthorized domain access, terminating the process corresponding to the access request, and generating an error report based on the request information corresponding to the access request; When the abnormal situation is insufficient authority, an error code corresponding to the insufficient authority is returned.
6. A memory isolation device for an embedded system, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a memory isolation method for an embedded system as described in any one of claims 1 to 5.
7. A non-volatile computer storage medium storing computer executable instructions, characterized in that: The computer executable instructions are configured as: a memory isolation method for an embedded system as described in any one of claims 1 to 5.
Citation Information
Patent Citations
System on chip, interrupt isolation method and computer equipment
CN114329439A
Memory configuration method, memory access method and device for memory protection
CN117951046A