Method and device for processing abnormal information of memory protection unit, equipment and medium

By configuring the matching relationship between the memory area and access permissions in the memory protection unit and verifying the exception information, the problem of possible errors in the transmission of exception information is solved, and the security and stability of memory data are guaranteed.

CN120030566APending Publication Date: 2025-05-23CHERY AUTOMOBILE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510002765.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-02
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In the memory protection unit, errors may occur during the transmission of exception information, resulting in the inability to accurately handle real exceptions, affecting the security and stability of the system.

Method used

By configuring the matching relationship between the memory area and the access permissions in the memory protection unit, the memory area to which the access address belongs and its target access permissions are determined. For memory access requests that do not meet access permissions, exception information is generated and checked before storage and sending to the security management unit to ensure the accuracy of exception information.

Benefits of technology

Effectively prevent illegal or unauthorized memory access, avoid accidental or malicious tampering of data, and ensure that the security management unit can accurately handle exception information, thereby ensuring the security and stability of data in memory.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030566A_ABST
    Figure CN120030566A_ABST
Patent Text Reader

Abstract

The invention provides a processing method and device for abnormal information of a memory protection unit, equipment and a medium, and belongs to the technical field of computers. In response to a memory access request, determining a target access permission corresponding to a memory area to which an access address belongs based on the access address in the memory access request and a matching relationship in a memory protection unit; under the condition that the memory access request does not conform to the target access permission, abnormal information is generated, the abnormal information is stored in the memory protection unit, and the abnormal information is sent to a security management unit; verifying the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit to obtain a verification result; and under the condition that the verification result indicates that the abnormal information in the safety management unit is correct, processing the abnormal information through the safety management unit. According to the method, the security and stability of the data in the memory can be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method, device, equipment and medium for processing abnormal information of a memory protection unit. Background Art

[0002] The Memory Protection Unit (MPU) is a hardware unit that improves system reliability and robustness. It provides memory protection and access control functions, implements memory isolation and protection of the operating system, and prevents illegal access to system memory due to software errors or malicious attacks.

[0003] After the operating system is started, each external device will pass through the memory protection unit when accessing the memory area. Once illegal access is detected, the memory protection unit will generate exception information and hand it over to the security management unit, which will handle the exception information.

[0004] However, errors may occur during the transmission of exception information, resulting in the inability to handle real exceptions, affecting the security and stability of the system. Summary of the invention

[0005] The embodiment of the present application provides a method, device, equipment and medium for processing abnormal information of a memory protection unit, which can ensure the security and stability of data in the memory. The technical solution is as follows:

[0006] On the one hand, a method for processing abnormal information of a memory protection unit is provided, the method comprising:

[0007] In response to a memory access request, determining a target access permission corresponding to a memory region to which the access address belongs based on an access address in the memory access request and a matching relationship in a memory protection unit, wherein the matching relationship is a corresponding relationship between a memory region and an access permission;

[0008] In a case where the memory access request does not comply with the target access permission, generating exception information, storing the exception information in the memory protection unit, and sending the exception information to the security management unit;

[0009] Based on the abnormal information stored in the memory protection unit, verify the abnormal information received by the security management unit to obtain a verification result, wherein the verification result is used to indicate whether the abnormal information in the security management unit is accurate;

[0010] When the verification result indicates that the abnormal information in the security management unit is correct, the abnormal information is processed by the security management unit.

[0011] On the other hand, a device for processing abnormal information of a memory protection unit is provided, the device comprising:

[0012] A first determination module, configured to determine, in response to a memory access request, a target access permission corresponding to a memory region to which the access address belongs based on an access address in the memory access request and a matching relationship in a memory protection unit, wherein the matching relationship is a corresponding relationship between a memory region and an access permission;

[0013] A generating module, configured to generate exception information when the memory access request does not comply with the target access permission, store the exception information in the memory protection unit, and send the exception information to a security management unit;

[0014] A verification module, configured to verify the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit, and obtain a verification result, wherein the verification result is used to indicate whether the abnormal information in the security management unit is accurate;

[0015] The first processing module is used to process the abnormal information through the security management unit when the verification result indicates that the abnormal information in the security management unit is correct.

[0016] In some embodiments, the verification module is used to perform at least one of the following:

[0017] Based on the abnormal information stored in the memory protection unit, a cyclic redundancy check is performed on the abnormal information received by the security management unit to obtain a corresponding check result;

[0018] Based on the abnormal information stored in the memory protection unit, performing a parity check on the abnormal information received by the security management unit to obtain a corresponding check result;

[0019] Based on the abnormal information stored in the memory protection unit, a longitudinal redundancy check is performed on the abnormal information received by the security management unit to obtain a corresponding check result;

[0020] A hash algorithm is used to verify the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit to obtain a corresponding verification result.

[0021] In some embodiments, the verification module is used to:

[0022] Sending the abnormal information stored in the memory protection unit and the abnormal information received by the security management unit to the CRC module;

[0023] Calculate the CRC value of the abnormal information stored in the memory protection unit through the CRC module to obtain a first check code;

[0024] Calculate the CRC value of the abnormal information received by the security management unit through the CRC module to obtain a second check code;

[0025] The first verification code and the second verification code are compared to obtain the verification result.

[0026] In some embodiments, the apparatus further comprises:

[0027] The second determining module is configured to perform at least one of the following:

[0028] Based on the target access rights corresponding to the access address, determining a verification device for the abnormal information, wherein the accuracy of the verification device is positively correlated with the target access rights;

[0029] Based on the number of abnormal information appearing at the current moment, a verification device for the abnormal information is determined, and a response time of the verification device for each abnormal information is inversely proportional to the number of abnormal information.

[0030] In some embodiments, the apparatus further comprises:

[0031] The second processing module is configured to perform any of the following:

[0032] In a case where the verification result indicates that the exception information in the security management unit is erroneous, modifying the exception information received by the security management unit based on the exception information stored in the memory protection unit;

[0033] In a case where the verification result indicates that the exception information in the security management unit is erroneous, resending the exception information to the security management unit based on the exception information stored in the memory protection unit;

[0034] In a case where the verification result indicates that the exception information in the security management unit is erroneous, the exception information is regenerated based on the memory access request, and the exception information is resent to the security management unit.

[0035] In some embodiments, the apparatus further comprises:

[0036] The third processing module is used to generate error information when the verification result indicates that the abnormal information in the security management unit is wrong, and the error information is used to indicate the location where the error occurs in the abnormal information; process the error information to obtain the error factor that causes the error information; and report the error factor.

[0037] In some embodiments, the apparatus further comprises:

[0038] The fourth processing module is used to obtain the account level of the user account to which the memory access request belongs if the target access permission corresponding to the access address does not exist in the target access permission of the access address; if the account level meets the conditions, add the permission allowing the target operation to the target access permission; if the account level does not meet the conditions, send the memory access request to the management account of the memory protection unit.

[0039] On the other hand, an electronic device is provided, comprising a processor and a memory, wherein the memory is used to store at least one computer program, and the at least one computer program is loaded by the processor and executes the above-mentioned method for processing exception information of the memory protection unit.

[0040] On the other hand, a computer-readable storage medium is provided, in which at least one computer program is stored. The at least one computer program is loaded and executed by a processor to implement a method for processing exception information of a memory protection unit as in an embodiment of the present application.

[0041] On the other hand, a computer program product is provided, including a computer program, which is stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the computer device executes the method for processing exception information of a memory protection unit provided in the above-mentioned various aspects or various optional implementations of various aspects.

[0042] An embodiment of the present application provides a method for processing exception information of a memory protection unit, by configuring a matching relationship between a memory area and access rights in the memory protection unit so that when a memory access request is subsequently received, the configured matching relationship can be followed for access, thereby preventing illegal or unauthorized memory access, thereby preventing data in the memory from being accidentally or maliciously tampered with; and, for the exception information generated when the memory access request does not comply with the access rights, it can be stored in the memory protection unit while being sent to the security management unit for processing, and the exception information received by the security management unit can be verified before processing to detect whether an error occurs in the transmission of the exception information, so that the exception information can be subsequently processed on the basis of ensuring that it is accurate, thereby ensuring that the security management unit accurately handles the exception information, and further ensuring the security and stability of the data in the memory. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0044] Figure 1 It is a schematic diagram of an implementation environment of a method for processing abnormal information of a memory protection unit provided in an embodiment of the present application;

[0045] Figure 2 It is a flowchart of a method for processing abnormal information of a memory protection unit provided in an embodiment of the present application;

[0046] Figure 3 It is a framework diagram for processing abnormal information provided according to an embodiment of the present application;

[0047] Figure 4 It is a block diagram of a device for processing abnormal information of a memory protection unit provided according to an embodiment of the present application;

[0048] Figure 5 is a structural block diagram of a terminal provided according to an embodiment of the present application;

[0049] Figure 6 It is a structural diagram of a server provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0050] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.

[0051] In this application, the terms "first", "second", etc. are used to distinguish identical or similar items with basically the same effects and functions. It should be understood that there is no logical or temporal dependency between "first", "second", and "nth", nor is there any limitation on quantity and execution order.

[0052] In the present application, the term "at least one" means one or more, and the term "plurality" means two or more.

[0053] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions. For example, the instructions and vectors involved in this application are obtained with full authorization.

[0054] The method for processing abnormal information of the memory protection unit provided in the embodiment of the present application can be executed by an electronic device. In some embodiments, the electronic device is a terminal or a server. The following first takes the electronic device as an example to introduce the implementation environment of the method for processing abnormal information of the memory protection unit provided in the embodiment of the present application. Figure 1 Schematic diagram of an implementation environment of a method for processing abnormal information of a memory protection unit provided in an embodiment of the present application. Figure 1 The implementation environment includes a terminal 101 and a server 102. The terminal 101 and the server 102 can be directly or indirectly connected via wired or wireless communication, which is not limited in this application.

[0055] In some embodiments, terminal 101 is a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, an intelligent voice interaction device, a smart home appliance, a vehicle-mounted terminal, etc., but is not limited thereto. A memory protection unit is installed on terminal 101, and the embodiments of the present application do not limit the specifications of the memory protection unit. Schematically, terminal 101 is a terminal used by a user. Accordingly, when receiving a memory access request from an external device (such as a server 102 or other terminal 101) or its own operating system, terminal 101 can determine whether the memory access request complies with the authority through the memory access unit. Only when it complies with the authority is access to the memory of terminal 101 allowed, which plays a role in protecting the stability and security of the data in the memory.

[0056] Those skilled in the art will appreciate that the number of the above terminals may be more or less. For example, the above terminal may be only one, or the above terminals may be dozens or hundreds, or more. The embodiment of the present application does not limit the number of terminals and device types.

[0057] In some embodiments, server 102 is an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), big data and artificial intelligence platforms. A memory protection unit may also be installed in server 102 to protect stored data through the memory protection unit. In some embodiments, server 102 undertakes the main computing work and terminal 101 undertakes the secondary computing work; or, server 102 undertakes the secondary computing work and terminal 101 undertakes the main computing work; or, a distributed computing architecture is used between server 102 and terminal 101 for collaborative computing.

[0058] Figure 2 is a flowchart of a method for processing abnormal information of a memory protection unit provided in accordance with an embodiment of the present application, see Figure 2 In the embodiment of the present application, the method for processing abnormal information of the memory protection unit includes the following steps:

[0059] 201. In response to a memory access request, the electronic device determines a target access permission corresponding to a memory region to which the access address belongs based on an access address in the memory access request and a matching relationship in a memory protection unit, where the matching relationship is a corresponding relationship between the memory region and the access permission.

[0060] In an embodiment of the present application, before receiving a memory access request, the electronic device may configure a matching relationship between a memory region and an access right in a memory protection unit, and store the matching relationship in a register in the memory protection unit. That is, a user may write the matching relationship between a memory region and an access right in a register in the memory protection unit through an operating system on the electronic device.

[0061] Among them, the electronic device can divide the memory space into multiple memory areas through the memory protection unit, and configure attribute information for each memory area, such as access rights, cache, and write cache. There may be overlapping areas between different memory areas, or there may not be overlapping areas, etc., which is not limited by the embodiments of the present application. The access rights corresponding to different memory areas may be the same or different, which is not limited by the embodiments of the present application.

[0062] After the operating system on the electronic device is started, the electronic device can send an enable signal to the memory management unit to indicate that the memory management unit is in working state. Whenever a memory access request is received, the electronic device matches the access address in the memory access request with the memory area and access rights configured in the memory protection unit. That is, the electronic device determines the memory area to which the access address belongs, and then determines the corresponding target access rights.

[0063] Among them, the memory access request may include instructions corresponding to various operations such as read operations (reading data in the memory), write operations (writing data in the memory) or other processing operations (for example, modification operations, editing operations, and saving operations), so that the corresponding operations can be performed in the memory later if the permissions are met.

[0064] 202. When the memory access request does not comply with the target access permission, the electronic device generates exception information, stores the exception information in the memory protection unit, and sends the exception information to the security management unit.

[0065] In an embodiment of the present application, the electronic device detects whether a memory access request complies with the target access rights. That is, the electronic device detects whether there is indication information in the target access rights that allows the operation in the memory access request to be performed at the access address. If there is no indication information in the target access rights that allows the operation in the memory access request to be performed at the access address, or the indication information in the target access rights does not allow the operation in the memory access request to be performed at the access address, the electronic device can determine that the memory access request does not comply with the target access rights. In other words, if it is not specified or explicitly not allowed in the target access rights, the electronic device can be deemed to be not compliant with the target access rights. In this case, the electronic device generates exception information.

[0066] Among them, the exception information may include the access address in the memory access request, the data in the memory access request (such as data to be written to the memory), the operation type in the memory access request (such as write, read, modify, etc.), the time of receiving the memory access request, the source of the memory access request (such as the user account to which it belongs), and other information. The embodiments of the present application do not limit this.

[0067] After generating the exception information, in addition to sending the exception information to the security management unit for processing, the electronic device can also store the exception information in the register of the memory protection unit so that the exception information received by the security management unit can be subsequently verified through the stored exception information to prevent the security management unit from processing errors caused by errors in the exception information during transmission.

[0068] In some embodiments, for situations not specified in the target access rights, the electronic device can determine whether it complies with the target access rights based on the source of the memory access request (such as the user account to which it belongs). Accordingly, if the permission corresponding to the target operation in the memory access request does not exist in the target access rights corresponding to the access address, the electronic device obtains the account level of the user account to which the memory access request belongs. When the account level meets the conditions, the electronic device adds the permission to allow the target operation to the target access rights. In this case, the electronic device determines that the memory access request complies with the target access rights and can access the memory. The above conditions may be that the account level is higher than the preset level, or the account level is within a preset range, etc., and the embodiments of the present application do not limit this.

[0069] That is, if the account level of the user account is high enough, during the process of accessing the memory, if an unspecified situation occurs, the memory can be accessed based on the current operation of the user account. That is, if the memory protection unit does not configure permissions for a certain type of operation for the access address, when the user account initiates a memory access request, it can be confirmed that the user expects the access address to allow the operation in the memory access request. In this case, the electronic device adds permissions to allow the operation in the memory access request to the target access permission corresponding to the access address, which not only meets the user's intention, but also does not require the user to manually set permissions, which can improve operational efficiency.

[0070] When the account level does not meet the conditions, the electronic device sends a memory access request to the management account of the memory protection unit to instruct the management account to review whether the memory access request meets the permissions, and can prompt the management account to supplement the insufficient permissions configured in the memory protection unit.

[0071] 203. The electronic device verifies the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit to obtain a verification result, where the verification result is used to indicate whether the abnormal information in the security management unit is accurate.

[0072] In an embodiment of the present application, the electronic device can use the abnormal information stored in the memory protection unit as a reference to verify the abnormal information received by the security management unit to obtain a verification result of the abnormal information. The embodiment of the present application does not limit the verification method. The following is an exemplary introduction to a variety of verification methods, but is by no means limited to this.

[0073] In a first manner, the electronic device performs a cyclic redundancy check (CRC) on the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit to obtain a corresponding check result.

[0074] In a second manner, the electronic device performs a parity check on the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit to obtain a corresponding check result.

[0075] In a third manner, the electronic device performs a longitudinal redundancy check on the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit to obtain a corresponding check result.

[0076] In a fourth manner, the electronic device uses a hash algorithm to verify the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit to obtain a corresponding verification result.

[0077] The following takes the first method as an example to introduce the process of verifying the abnormal information received by the security management unit. Among them, the electronic device can send the abnormal information stored in the memory protection unit and the abnormal information received by the security management unit to the CRC module. Then, the electronic device calculates the CRC value of the abnormal information stored in the memory protection unit through the CRC module to obtain a first check code. The electronic device calculates the CRC value of the abnormal information received by the security management unit through the CRC module to obtain a second check code. Then, the electronic device compares the first check code and the second check code to obtain a check result.

[0078] When the first check code and the second check code are the same, the electronic device determines a first check result, and the first check result is used to indicate that the abnormal information in the security management unit is correct. When the first check code and the second check code are different, the electronic device determines a second check result, and the second check result is used to indicate that the abnormal information in the security management unit is wrong. Alternatively, when the similarity between the first check code and the second check code reaches a similarity threshold, the electronic device determines the first check result; when the similarity between the first check code and the second check code does not reach the similarity threshold, the electronic device determines the second check result. The similarity between the first check code and the second check code can reflect the similarity between the abnormal information stored in the memory protection unit and the abnormal information received by the security management unit.

[0079] The solution provided in the embodiment of the present application verifies the exception information received by the security management unit through a cyclic redundancy check to detect whether an error occurs in the transmission process of the exception information, so that subsequent processing can be performed on the basis of ensuring that the exception information is accurate, thereby ensuring the security management unit's accurate processing of the exception information, and further ensuring the security and stability of the data in the memory.

[0080] For example, Figure 3 is a framework diagram for processing abnormal information according to an embodiment of the present application. Figure 3, the operating system configures specific access rights for each memory area. When the memory protection unit is enabled, whenever a memory access request is received, the memory protection unit can query the matching relationship between the memory area and the access right to determine whether the memory access request meets the target access right corresponding to the access address. If it does not meet the requirements, the memory protection unit generates exception information, which will be stored in its own register and sent to the security management unit. Before processing the exception information, a control signal can be sent to the CRC module, and the control signal can instruct the CRC module to initialize (i.e., clear the previous calculation result). After receiving the ready signal of the CRC module, the memory protection unit sends the stored exception information to the CRC module through the bus, and the security management unit will also send the received exception information to the CRC module so that the CRC module can perform verification and return the verification result to the security management unit. For example, if the first verification code and the second verification code are the same, the CRC module outputs 1 as the first verification result; if the first verification code and the second verification code are different, the CRC module outputs 0 as the second verification result.

[0081] The above four methods can be freely combined to obtain a new verification method. For example, the electronic device uses any three of the above verification methods for verification. Accordingly, for any verification method, the electronic device can use the verification method to calculate the similarity between the abnormal information stored in the memory protection unit and the abnormal information received by the security management unit. Then, the electronic device can perform a weighted summation of the similarities corresponding to the three verification methods to obtain the target similarity (i.e., the final similarity) of the abnormal information. Then, the electronic device determines the corresponding verification result based on the target similarity. For example, when the target similarity exceeds the similarity threshold, the electronic device determines that the verification result is the first verification result; when the target similarity does not exceed the similarity threshold, the electronic device determines that the verification result is the second verification result. The embodiment of the present application provides a solution, which can verify the abnormal information received by the security management unit in a variety of verification methods, and the verification result depends on a variety of verification methods. Compared with the solution of verifying in only one way, the verification result is more accurate, thereby ensuring the accurate processing of the abnormal information by the security management unit, and then ensuring the security and stability of the data in the memory.

[0082] Among them, the weight of the similarity corresponding to each verification method can be positively correlated with the performance of the verification method. That is, the better the performance of the verification method, the higher the weight of the similarity corresponding to the verification method; the worse the performance of the verification method, the lower the weight of the similarity corresponding to the verification method. The performance of the verification method may include the accuracy of the verification method, the response time (i.e., the verification efficiency), etc., and the embodiments of the present application are not limited to this.

[0083] The above verification method can be customized by the user or determined according to a certain rule, and the present application embodiment does not limit this. The following exemplarily introduces a variety of determination methods, but is by no means limited to this.

[0084] The first determination method is that the electronic device determines the verification method of the abnormal information based on the target access rights corresponding to the access address. The accuracy of the verification method is positively correlated with the target access rights. That is, the higher the target access rights, the higher the accuracy of the verification method is selected. Since more private data is usually stored at access addresses with higher permissions, for access addresses with higher permissions, a higher accuracy verification method is selected to verify the abnormal information, which is conducive to improving the accuracy of the verification results, thereby ensuring the security management unit's accurate processing of the abnormal information, and then ensuring the security and stability of the data in the memory.

[0085] The second determination method is that the electronic device determines the verification method of the abnormal information based on the number of abnormal information that appears at the current moment. The response time of the verification method for each abnormal information is inversely proportional to the number of abnormal information. That is, the more abnormal information there is, the shorter the response time is. In this method, when more abnormal information appears at the same time, a verification method with a shorter response time is selected for verification, which can ensure the verification efficiency, thereby ensuring that the security management unit processes the abnormal information faster, which is conducive to meeting the user's memory access needs.

[0086] The above two determination methods can be freely combined to obtain a new determination method, which is not limited in the embodiments of the present application. For example, when the target access rights corresponding to the access address reach a preset level and the number of abnormal information appearing at the current moment reaches a preset number, the electronic device selects a verification method whose accuracy exceeds the accuracy threshold and whose response time is less than the preset duration to verify the abnormal information.

[0087] 204. When the verification result indicates that the abnormal information in the security management unit is correct, the electronic device processes the abnormal information through the security management unit.

[0088] In an embodiment of the present application, when the verification result shows that the abnormal information in the security management unit is correct, the electronic device controls the security management unit to process the abnormal information to solve the abnormal problem.

[0089] In some embodiments, when the verification result indicates that the abnormal information in the security management unit is wrong, the electronic device can also modify the abnormal information. Correspondingly, when the verification result indicates that the abnormal information in the security management unit is wrong, the electronic device modifies the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit. This method is aimed at erroneous abnormal information, and can be modified according to the abnormal information stored in the memory protection unit to ensure that the abnormal information to be processed by the security management unit is consistent with the abnormal information in the memory protection unit, thereby ensuring that the subsequent processing can be carried out on the basis of ensuring that the abnormal information is accurate, thereby ensuring the accurate processing of the abnormal information by the security management unit, and then ensuring the security and stability of the data in the memory.

[0090] In other embodiments, when the verification result indicates that the exception information in the security management unit is wrong, the electronic device can also resend the exception information. When the verification result indicates that the exception information in the security management unit is wrong, the electronic device resends the exception information to the security management unit based on the exception information stored in the memory protection unit. This method is aimed at erroneous exception information, and can resend the exception information from the memory protection unit to the security management unit, which is not only conducive to improving the accuracy of the exception information, but also ensuring that the subsequent processing can be carried out on the basis of ensuring that the exception information is accurate, thereby ensuring the accurate processing of the exception information by the security management unit, and then ensuring the security and stability of the data in the memory; and compared with the modification of the exception information, this method does not need to detect the location of the error in the exception information, which is conducive to improving the efficiency of obtaining accurate exception information, thereby improving the efficiency of exception processing and memory access.

[0091] In other embodiments, when the verification result shows that the abnormal information in the security management unit is wrong, the electronic device can also regenerate the abnormal information. When the verification result indicates that the abnormal information in the security management unit is wrong, the electronic device regenerates the abnormal information based on the memory access request and resends the abnormal information to the security management unit. Since the abnormal information stored in the memory protection unit may also be erroneous during the storage process, when the verification result shows that the abnormal information stored in the memory protection unit is different from the abnormal information received by the security management unit, in order to avoid the abnormal information stored in the memory protection unit The error is caused, this method regenerates the abnormal information, which is conducive to improving the accuracy of the abnormal information and ensuring that the subsequent processing can be carried out on the basis of ensuring that the abnormal information is accurate, thereby ensuring the accurate processing of the abnormal information by the security management unit, and then ensuring the security and stability of the data in the memory.

[0092] For the above-mentioned resent or regenerated exception information, when the security management unit receives the exception information again, the electronic device can also verify the newly received exception information to ensure the accuracy of the exception information to be processed.

[0093] In some embodiments, when the verification result indicates that the abnormal information in the security management unit is wrong, the electronic device also generates an error message, and the error message is used to indicate the location where the error occurs in the abnormal information. Then, the electronic device processes the error information to obtain the error factor that causes the error information. Then, the electronic device reports the error factor. The solution provided in the embodiment of the present application can also analyze the factors that cause the error and report it for the abnormal information that has an error, so that the user can promptly process the factors that cause the error.

[0094] An embodiment of the present application provides a method for processing exception information of a memory protection unit, by configuring a matching relationship between a memory area and access rights in the memory protection unit so that when a memory access request is subsequently received, the configured matching relationship can be followed for access, thereby preventing illegal or unauthorized memory access, thereby preventing data in the memory from being accidentally or maliciously tampered with; and, for the exception information generated when the memory access request does not comply with the access rights, it can be stored in the memory protection unit while being sent to the security management unit for processing, and the exception information received by the security management unit can be verified before processing to detect whether an error occurs in the transmission of the exception information, so that the exception information can be subsequently processed on the basis of ensuring that it is accurate, thereby ensuring that the security management unit accurately handles the exception information, and further ensuring the security and stability of the data in the memory.

[0095] Figure 4 1 is a block diagram of a memory protection unit exception information processing device provided according to an embodiment of the present application. The memory protection unit exception information processing device is used to execute the steps of the above-mentioned memory protection unit exception information processing method. Figure 4 , the memory protection unit exception information processing device includes:

[0096] A first determination module 401 is used to determine, in response to a memory access request, a target access right corresponding to a memory region to which the access address belongs based on an access address in the memory access request and a matching relationship in a memory protection unit, wherein the matching relationship is a corresponding relationship between a memory region and an access right;

[0097] A generating module 402, for generating exception information when a memory access request does not comply with a target access right, storing the exception information in a memory protection unit, and sending the exception information to a security management unit;

[0098] A verification module 403, used to verify the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit, and obtain a verification result, where the verification result is used to indicate whether the abnormal information in the security management unit is accurate;

[0099] The first processing module 404 is configured to process the abnormal information through the security management unit when the verification result indicates that the abnormal information in the security management unit is correct.

[0100] In some embodiments, the verification module 403 is configured to perform at least one of the following:

[0101] Based on the abnormal information stored in the memory protection unit, a cyclic redundancy check is performed on the abnormal information received by the security management unit to obtain a corresponding check result;

[0102] Based on the abnormal information stored in the memory protection unit, a parity check is performed on the abnormal information received by the security management unit to obtain a corresponding check result;

[0103] Based on the abnormal information stored in the memory protection unit, a longitudinal redundancy check is performed on the abnormal information received by the security management unit to obtain a corresponding check result;

[0104] A hash algorithm is used to verify the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit to obtain a corresponding verification result.

[0105] In some embodiments, the verification module 403 is used to:

[0106] Sending the abnormal information stored in the memory protection unit and the abnormal information received by the security management unit to the CRC module;

[0107] Calculate the CRC value of the abnormal information stored in the memory protection unit through the CRC module to obtain a first check code;

[0108] Calculate the CRC value of the abnormal information received by the security management unit through the CRC module to obtain a second check code;

[0109] The first check code is compared with the second check code to obtain a check result.

[0110] In some embodiments, the apparatus further comprises:

[0111] The second determining module is configured to perform at least one of the following:

[0112] Based on the target access rights corresponding to the access address, a verification device for abnormal information is determined, wherein the accuracy of the verification device is positively correlated with the target access rights;

[0113] Based on the number of abnormal information appearing at the current moment, a verification device for the abnormal information is determined, and the response time of the verification device for each abnormal information is inversely proportional to the number of abnormal information.

[0114] In some embodiments, the apparatus further comprises:

[0115] The second processing module is configured to perform any of the following:

[0116] In the case where the verification result indicates that the exception information in the security management unit is wrong, modifying the exception information received by the security management unit based on the exception information stored in the memory protection unit;

[0117] If the verification result indicates that the exception information in the security management unit is wrong, resending the exception information to the security management unit based on the exception information stored in the memory protection unit;

[0118] In the case where the verification result indicates that the exception information in the security management unit is wrong, the exception information is regenerated based on the memory access request and the exception information is resent to the security management unit.

[0119] In some embodiments, the apparatus further comprises:

[0120] The third processing module is used to generate error information when the verification result indicates that the abnormal information in the security management unit is wrong, and the error information is used to indicate the location where the error occurs in the abnormal information; process the error information to obtain the error factor that causes the error information; and report the error factor.

[0121] In some embodiments, the apparatus further comprises:

[0122] The fourth processing module is used to obtain the account level of the user account to which the memory access request belongs if the target access permission corresponding to the access address does not exist in the target access permission, and add the permission to allow the target operation in the target access permission if the account level meets the conditions; if the account level does not meet the conditions, send the memory access request to the management account of the memory protection unit.

[0123] An embodiment of the present application provides a device for processing exception information of a memory protection unit, which configures a matching relationship between a memory area and access rights in the memory protection unit so that when a memory access request is subsequently received, the configured matching relationship can be followed for access, thereby preventing illegal or unauthorized memory access, thereby preventing data in the memory from being accidentally or maliciously tampered with; and, for the exception information generated when the memory access request does not comply with the access rights, it can be stored in the memory protection unit while being sent to the security management unit for processing, and the exception information received by the security management unit can be verified before processing to detect whether an error occurs in the transmission of the exception information, so that the exception information can be subsequently processed on the basis of ensuring that it is accurate, thereby ensuring that the security management unit accurately handles the exception information, and further ensuring the security and stability of the data in the memory.

[0124] In the embodiments of the present application, the electronic device can be configured as a terminal or a server. When the electronic device is configured as a terminal, the terminal can be used as the execution subject to implement the technical solution provided in the embodiments of the present application. When the electronic device is configured as a server, the server can be used as the execution subject to implement the technical solution provided in the embodiments of the present application. The technical solution provided in the present application can also be implemented through interaction between the terminal and the server. The embodiments of the present application are not limited to this.

[0125] Figure 5 This is a block diagram of a terminal 500 provided according to an embodiment of the present application. The terminal 500 may be a portable mobile terminal, such as a smart phone, a tablet computer, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 player (Moving Picture Experts Group Audio Layer IV), a laptop computer or a desktop computer. The terminal 500 may also be referred to as a user device, a portable terminal, a laptop terminal, a desktop terminal or other names.

[0126] Typically, the terminal 500 includes a processor 501 and a memory 502 .

[0127] The processor 501 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 501 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 501 may also include a main processor and a coprocessor. The main processor is a processor for processing data in an awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in a standby state. In some embodiments, the processor 501 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 501 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.

[0128] The memory 502 may include one or more computer-readable storage media, which may be non-transitory. The memory 502 may also include a high-speed random access memory and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In some embodiments, the non-transitory computer-readable storage medium in the memory 502 is used to store at least one computer program. The at least one computer program is used to be executed by the processor TH01 to implement the method for processing the abnormal information of the memory protection unit provided in the method embodiment of the present application.

[0129] In some embodiments, the terminal 500 may further optionally include: a peripheral device interface 503 and at least one peripheral device. The processor 501, the memory 502 and the peripheral device interface 503 may be connected via a bus or a signal line. Each peripheral device may be connected to the peripheral device interface 503 via a bus, a signal line or a circuit board. Specifically, the peripheral device includes: at least one of a radio frequency circuit 504, a display screen 505, a camera assembly 506, an audio circuit 507 and a power supply 508.

[0130] The peripheral device interface 503 may be used to connect at least one peripheral device related to I / O (Input / Output) to the processor 501 and the memory 502. In some embodiments, the processor 501, the memory 502, and the peripheral device interface 503 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 501, the memory 502, and the peripheral device interface 503 may be implemented on a separate chip or circuit board, which is not limited in this embodiment.

[0131] The radio frequency circuit 504 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The radio frequency circuit 504 communicates with the communication network and other communication devices through electromagnetic signals. The radio frequency circuit 504 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals into electrical signals. In some embodiments, the radio frequency circuit 504 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, and the like. The radio frequency circuit 504 can communicate with other terminals through at least one wireless communication protocol. The wireless communication protocol includes, but is not limited to: the World Wide Web, a metropolitan area network, an intranet, various generations of mobile communication networks (2G, 3G, 4G and 5G), a wireless local area network and / or a WiFi (Wireless Fidelity) network. In some embodiments, the radio frequency circuit 504 may also include circuits related to NFC (Near Field Communication), which is not limited in this application.

[0132] The display screen 505 is used to display a UI (User Interface). The UI may include graphics, text, icons, videos, and any combination thereof. When the display screen 505 is a touch display screen, the display screen 505 also has the ability to collect touch signals on the surface or above the surface of the display screen 505. The touch signal can be input to the processor 501 as a control signal for processing. At this time, the display screen 505 can also be used to provide virtual buttons and / or virtual keyboards, also known as soft buttons and / or soft keyboards. In some embodiments, the display screen 505 can be one, set on the front panel of the terminal 500; in other embodiments, the display screen 505 can be at least two, respectively set on different surfaces of the terminal 500 or in a folding design; in other embodiments, the display screen 505 can be a flexible display screen, set on a curved surface or a folding surface of the terminal 500. Even, the display screen 505 can also be set to a non-rectangular irregular shape, that is, a special-shaped screen. The display screen 505 can be made of materials such as LCD (Liquid Crystal Display), OLED (Organic Light-Emitting Diode), etc.

[0133] The camera assembly 506 is used to capture images or videos. In some embodiments, the camera assembly 506 includes a front camera and a rear camera. Typically, the front camera is disposed on the front panel of the terminal, and the rear camera is disposed on the back of the terminal. In some embodiments, there are at least two rear cameras, which are any one of a main camera, a depth of field camera, a wide-angle camera, and a telephoto camera, so as to realize the fusion of the main camera and the depth of field camera to realize the background blur function, the fusion of the main camera and the wide-angle camera to realize the panoramic shooting and the VR (Virtual Reality) shooting function or other fusion shooting functions. In some embodiments, the camera assembly 506 may also include a flash. The flash may be a monochrome temperature flash or a dual-color temperature flash. A dual-color temperature flash refers to a combination of a warm light flash and a cold light flash, which can be used for light compensation at different color temperatures.

[0134] The audio circuit 507 may include a microphone and a speaker. The microphone is used to collect sound waves from the user and the environment, and convert the sound waves into electrical signals and input them into the processor 501 for processing, or input them into the radio frequency circuit 504 to achieve voice communication. For the purpose of stereo acquisition or noise reduction, there may be multiple microphones, which are respectively arranged at different parts of the terminal 500. The microphone may also be an array microphone or an omnidirectional acquisition microphone. The speaker is used to convert the electrical signal from the processor 501 or the radio frequency circuit 504 into sound waves. The speaker may be a traditional film speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can not only convert the electrical signal into sound waves audible to humans, but also convert the electrical signal into sound waves inaudible to humans for purposes such as ranging. In some embodiments, the audio circuit 507 may also include a headphone jack.

[0135] The power supply 508 is used to power various components in the terminal 500. The power supply 508 can be an alternating current, a direct current, a disposable battery, or a rechargeable battery. When the power supply 508 includes a rechargeable battery, the rechargeable battery can be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery charged through a wired line, and a wireless rechargeable battery is a battery charged through a wireless coil. The rechargeable battery can also be used to support fast charging technology.

[0136] In some embodiments, the terminal 500 further includes one or more sensors 509 , including but not limited to: an acceleration sensor 510 , a gyroscope sensor 511 , a pressure sensor 512 , an optical sensor 513 , and a proximity sensor 514 .

[0137] The acceleration sensor 510 can detect the magnitude of acceleration on the three coordinate axes of the coordinate system established by the terminal 500. For example, the acceleration sensor 510 can be used to detect the components of gravity acceleration on the three coordinate axes. The processor 501 can control the display screen 505 to display the user interface in a horizontal view or a vertical view according to the gravity acceleration signal collected by the acceleration sensor 510. The acceleration sensor 510 can also be used to collect game or user motion data.

[0138] The gyro sensor 511 can detect the body direction and rotation angle of the terminal 500, and the gyro sensor 511 can cooperate with the acceleration sensor 510 to collect the user's 3D actions on the terminal 500. The processor 501 can implement the following functions based on the data collected by the gyro sensor 511: motion sensing (such as changing the UI according to the user's tilt operation), image stabilization during shooting, game control, and inertial navigation.

[0139] The pressure sensor 512 can be set on the side frame of the terminal 500 and / or the lower layer of the display screen 505. When the pressure sensor 512 is set on the side frame of the terminal 500, it can detect the user's holding signal of the terminal 500, and the processor 501 performs left and right hand recognition or shortcut operation according to the holding signal collected by the pressure sensor 512. When the pressure sensor 512 is set on the lower layer of the display screen 505, the processor 501 controls the operability controls on the UI interface according to the user's pressure operation on the display screen 505. The operability controls include at least one of a button control, a scroll bar control, an icon control, and a menu control.

[0140] The optical sensor 513 is used to collect the ambient light intensity. In one embodiment, the processor 501 can control the display brightness of the display screen 505 according to the ambient light intensity collected by the optical sensor 513. Specifically, when the ambient light intensity is high, the display brightness of the display screen 505 is increased; when the ambient light intensity is low, the display brightness of the display screen 505 is reduced. In another embodiment, the processor 501 can also dynamically adjust the shooting parameters of the camera component 506 according to the ambient light intensity collected by the optical sensor 513.

[0141] The proximity sensor 514, also called a distance sensor, is usually arranged on the front panel of the terminal 500. The proximity sensor 514 is used to collect the distance between the user and the front of the terminal 500. In one embodiment, when the proximity sensor 514 detects that the distance between the user and the front of the terminal 500 is gradually decreasing, the processor 501 controls the display screen 505 to switch from the screen-on state to the screen-off state; when the proximity sensor 514 detects that the distance between the user and the front of the terminal 500 is gradually increasing, the processor 501 controls the display screen 505 to switch from the screen-off state to the screen-on state.

[0142] Those skilled in the art will understand that Figure 5 The structure shown in the figure does not constitute a limitation on the terminal 500, and the terminal 500 may include more or less components than those shown in the figure, or combine some components, or adopt a different component arrangement.

[0143] Figure 6It is a structural diagram of a server provided according to an embodiment of the present application. The server 600 may have relatively large differences due to different configurations or performances, and may include one or more processors (Central Processing Units, CPU) 601 and one or more memories 602, wherein the memory 602 stores at least one computer program, and the at least one computer program is loaded and executed by the processor 601 to implement the method for processing abnormal information of the memory protection unit provided in the above-mentioned various method embodiments. Of course, the server may also have components such as a wired or wireless network interface, a keyboard, and an input and output interface for input and output. The server may also include other components for implementing device functions, which will not be described in detail here.

[0144] The embodiment of the present application also provides a computer-readable storage medium, in which at least one computer program is stored, and the at least one computer program is loaded and executed by a processor of an electronic device to implement the operation performed by the electronic device in the method for processing abnormal information of the memory protection unit of the above embodiment. For example, the computer-readable storage medium can be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), a magnetic tape, a floppy disk, an optical data storage device, etc.

[0145] In some embodiments, the computer program involved in the embodiments of the present application may be deployed and executed on one electronic device, or on multiple electronic devices located at one location, or on multiple electronic devices distributed at multiple locations and interconnected by a communication network. Multiple electronic devices distributed at multiple locations and interconnected by a communication network may constitute a blockchain system.

[0146] The embodiment of the present application also provides a computer program product, including a computer program, which is stored in a computer-readable storage medium. A processor of an electronic device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the electronic device can use the method for processing abnormal information of a memory protection unit described in any of the above embodiments.

[0147] A person skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware or by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.

[0148] The above description is only an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A method for processing abnormal information of a memory protection unit, characterized in that: The method comprises: In response to a memory access request, determining a target access permission corresponding to a memory region to which the access address belongs based on an access address in the memory access request and a matching relationship in a memory protection unit, wherein the matching relationship is a corresponding relationship between a memory region and an access permission; In a case where the memory access request does not comply with the target access permission, generating exception information, storing the exception information in the memory protection unit, and sending the exception information to the security management unit; Based on the abnormal information stored in the memory protection unit, verify the abnormal information received by the security management unit to obtain a verification result, wherein the verification result is used to indicate whether the abnormal information in the security management unit is accurate; When the verification result indicates that the abnormal information in the security management unit is correct, the abnormal information is processed by the security management unit.

2. The method according to claim 1, characterized in that The checking of the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit to obtain a checking result includes at least one of the following: Based on the abnormal information stored in the memory protection unit, a cyclic redundancy check is performed on the abnormal information received by the security management unit to obtain a corresponding check result; Based on the abnormal information stored in the memory protection unit, performing a parity check on the abnormal information received by the security management unit to obtain a corresponding check result; Based on the abnormal information stored in the memory protection unit, a longitudinal redundancy check is performed on the abnormal information received by the security management unit to obtain a corresponding check result; A hash algorithm is used to verify the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit to obtain a corresponding verification result.

3. The method according to claim 2, characterized in that The performing a cyclic redundancy check on the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit to obtain a corresponding check result includes: Sending the abnormal information stored in the memory protection unit and the abnormal information received by the security management unit to the CRC module; Calculate the CRC value of the abnormal information stored in the memory protection unit through the CRC module to obtain a first check code; Calculate the CRC value of the abnormal information received by the security management unit through the CRC module to obtain a second check code; The first verification code and the second verification code are compared to obtain the verification result.

4. The method according to claim 1, characterized in that: The method further comprises at least one of the following: Based on the target access rights corresponding to the access address, determining a verification method for the abnormal information, wherein the accuracy of the verification method is positively correlated with the target access rights; Based on the number of abnormal information appearing at the current moment, a verification method for the abnormal information is determined, wherein a response time of the verification method for each abnormal information is inversely proportional to the number of abnormal information.

5. The method according to claim 1, characterized in that The method further comprises any of the following: In a case where the verification result indicates that the exception information in the security management unit is erroneous, modifying the exception information received by the security management unit based on the exception information stored in the memory protection unit; In a case where the verification result indicates that the exception information in the security management unit is erroneous, resending the exception information to the security management unit based on the exception information stored in the memory protection unit; In a case where the verification result indicates that the exception information in the security management unit is erroneous, the exception information is regenerated based on the memory access request, and the exception information is resent to the security management unit.

6. The method according to claim 1, characterized in that The method further comprises: If the verification result indicates that the abnormal information in the security management unit is erroneous, generating error information, the error information being used to indicate a location where the error occurs in the abnormal information; Processing the error information to obtain an error factor causing the error information to appear; The error factor is reported.

7. The method according to claim 1, characterized in that The method further comprises: If the target access permission corresponding to the access address does not have the permission corresponding to the target operation in the memory access request, obtaining the account level of the user account to which the memory access request belongs; If the account level meets the conditions, adding a permission to allow the target operation in the target access permission; When the account level does not meet the condition, the memory access request is sent to the management account of the memory protection unit.

8. A device for processing abnormal information of a memory protection unit, characterized in that: The device comprises: A first determination module, configured to determine, in response to a memory access request, a target access permission corresponding to a memory region to which the access address belongs based on an access address in the memory access request and a matching relationship in a memory protection unit, wherein the matching relationship is a corresponding relationship between a memory region and an access permission; A generating module, configured to generate exception information when the memory access request does not comply with the target access permission, store the exception information in the memory protection unit, and send the exception information to a security management unit; A verification module, configured to verify the abnormal information received by the security management unit based on the abnormal information stored in the memory protection unit, and obtain a verification result, wherein the verification result is used to indicate whether the abnormal information in the security management unit is accurate; The first processing module is used to process the abnormal information through the security management unit when the verification result indicates that the abnormal information in the security management unit is correct.

9. An electronic device, characterized in that: The electronic device includes a processor and a memory, the memory is used to store at least one computer program, and the at least one computer program is loaded by the processor and executed by the method for processing exception information of the memory protection unit according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store at least one computer program, and the at least one computer program is used to execute the method for processing exception information of the memory protection unit according to any one of claims 1 to 7.

Citation Information

Cited By

  • Method and apparatus for processing exception information of memory protection unit, device, and medium

    WO2026144313A1