Management method and system for expanding BAR space, PCIe device and storage medium
By enabling the expansion of BAR space and mapping it to the cache space, combining the mapping of the host memory space and the verification mechanism of the secure isolation area, the problem of low security of device drivers in the prior art is solved, and higher security and stability are achieved.
Patent Information
- Application Number
- CN202411940390.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, the extended BAR space is directly mapped to the embedded storage device, resulting in low security of the device driver and is prone to abnormal tampering.
By enabling the expansion of BAR space, map it to the cache space, and map it from the host memory space to the cache space, set up a secure isolation area, verify the data through firmware and then write it to the flash memory space.
Improve the security of the device driver, avoid users' direct operation of the flash memory space, and reduce the risk of device driver being abnormally tampered with.
Smart Images

Figure CN120045473A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of storage applications, and in particular to a management method, system, PCIe device, and storage medium for expanding the BAR space. Background Art
[0002] The expansion BAR space (Expansion Base Address Register), as a specific BAR configuration space in the PCIe protocol, is usually used to store PXE drivers and / or other specific drivers. To run the PXE function in the BIOS stage, the driver of the network card needs to be loaded. The BIOS loads the driver into memory through the expansion BAR space for execution. When other PCIe devices also need drivers to be executed in the BIOS stage, they are stored in the space mapped by the expansion BAR space in the same way and are loaded and executed after being verified by the BIOS.
[0003] Currently, the expansion BAR space is directly mapped to an embedded storage device. For example, a section of the storage device is directly mapped through passthrough. When users read and write the expansion BAR space, they directly operate the read and write of the storage device, resulting in too many operation permissions exposed to external users, which may cause the device driver of the storage device to be abnormally tampered with, resulting in low security of the device driver. Summary of the Invention
[0004] Embodiments of this application provide a management method, system, PCIe device, and storage medium for expanding the BAR space. By enabling the expansion BAR space, mapping the expansion BAR space to the cache space, and then mapping the host memory space to the cache space, and setting a security isolation area in the cache space, this application can improve the security of the device driver.
[0005] Embodiments of this application provide the following technical solutions:
[0006] In a first aspect, embodiments of this application provide a management method for expanding the BAR space, which is applied to a PCIe device. The PCIe device is connected to a host, the host includes a host memory space, the PCIe device includes an expansion BAR space, a cache space, and a flash memory space, and the cache space includes a security isolation area. The method includes:
[0007] After the operating system of the host is started, obtain an enable command to enable the expansion BAR space;
[0008] Map the expansion BAR space to the cache space and map the host memory space to the cache space;
[0009] After the host data is written into the cache space, the host data is stored in the secure isolation area of the cache space, and the firmware is used to verify the host data in the secure isolation area. If the verification passes, the host data in the secure isolation area is written into the flash space.
[0010] In some embodiments, the extended BAR space corresponds to an enable bit, and the state of the enable bit is an enabled state or a non-enabled state;
[0011] Obtaining an enable command to enable the extended BAR space includes:
[0012] Obtaining an enable command;
[0013] According to the enable command, set the state of the enable bit of the base address register corresponding to the extended BAR space to the enabled state to enable the extended BAR space.
[0014] In some embodiments,
[0015] Mapping the extended BAR space to the cache space includes:
[0016] Mapping the address of the extended BAR space to the address of the cache space;
[0017] Mapping the cache space to the host memory space includes:
[0018] Mapping the address of the host memory space to the address of the cache space.
[0019] In some embodiments, the method further includes:
[0020] Obtaining a firmware upgrade instruction and a firmware upgrade package;
[0021] According to the firmware upgrade instruction, send the firmware upgrade package to the extended BAR space to store the firmware upgrade package in the cache space;
[0022] Verifying the firmware upgrade package;
[0023] If the verification is successful, write the firmware upgrade package into the flash space to upgrade the current firmware of the PCIe device according to the firmware upgrade package.
[0024] In some embodiments,
[0025] The extended BAR space includes a first partition for storing configuration information;
[0026] The method further includes:
[0027] Receiving an information storage instruction and configuration information sent by the host, and storing the configuration information in the cache space;
[0028] Verify the information storage instruction and the configuration information, and determine whether the verification is successful;
[0029] If the verification is successful, write the configuration information in the cache space to the flash space.
[0030] In some embodiments,
[0031] Verify the information storage instruction and the configuration information, and determine whether the verification is successful, including:
[0032] Encrypt and package the information storage instruction and the configuration information through an encryption packaging tool to obtain a compressed package;
[0033] Decrypt the compressed package through a predetermined decryption algorithm;
[0034] If the decryption is successful, determine that the verification is successful;
[0035] If the decryption fails, determine that the verification fails.
[0036] In some embodiments,
[0037] The extended BAR space includes an extended base address register, and the extended base address register is used to specify the memory and I / O address ranges required by the PCIe device.
[0038] In some embodiments,
[0039] The secure isolation area is a specific area in the cache space, and the secure isolation area is used to store the host data written by the host.
[0040] In a second aspect, an embodiment of the present application provides a PCIe device, including:
[0041] A processor and a memory, the processor is used to execute the executable program code in the memory, and when the executable program code is executed, the processor executes the instructions of the management method of the extended BAR space as described in any item of the first aspect.
[0042] In a third aspect, an embodiment of the present application provides a management system for an extended BAR space, including:
[0043] The PCIe device as described in the second aspect;
[0044] A host, connected to the PCIe device.
[0045] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program, and when the computer program is executed, the management method of the extended BAR space as described in any item of the first aspect is implemented.
[0046] The beneficial effects of the embodiments of this application are as follows: Different from the prior art, a method for managing an extended BAR space provided by the embodiments of this application is applied to a PCIe device. The PCIe device is connected to a host, and the host includes a host memory space. The PCIe device includes an extended BAR space, a cache space, and a flash memory space. The cache space includes a secure isolation area. The method includes: after the operating system of the host is started, obtaining an enable command to enable the extended BAR space; mapping the extended BAR space to the cache space and mapping the host memory space to the cache space; after the host data is written to the cache space, storing the host data in the secure isolation area of the cache space, and verifying the host data in the secure isolation area through firmware. If the verification passes, the host data in the secure isolation area is written to the flash memory space.
[0047] By enabling the extended BAR space, mapping the extended BAR space to the cache space, then mapping the host memory space to the cache space, and at the same time setting a secure isolation area in the cache space, which is managed by firmware, the interaction data between the host and the cache space is verified by the firmware. After the verification passes, data interaction is performed with the flash memory space, enabling the host to indirectly perform data interaction with the flash memory space, thereby avoiding the user directly operating the flash memory space, reducing the problem of abnormal tampering of the device driver, and improving the security of the device driver. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] One or more embodiments are exemplarily illustrated by the pictures in the corresponding drawings. These exemplary illustrations do not limit the embodiments. Elements with the same reference numerals in the drawings are represented as similar elements. Unless otherwise stated, the drawings in the figures do not constitute a proportional limitation.
[0049] Figure 1 It is a schematic diagram of the loading process of an extended BAR space provided by the embodiments of this application;
[0050] Figure 2 It is a schematic diagram of the structure of a management system for an extended BAR space provided by the embodiments of this application;
[0051] Figure 3 It is a schematic diagram of the flow of a method for managing an extended BAR space provided by the embodiments of this application;
[0052] Figure 4 is Figure 3 a detailed flowchart of step S301 in;
[0053] Figure 5 It is a schematic diagram of the overall process of mapping an extended BAR space provided by the embodiments of this application;
[0054] Figure 6 It is a schematic flowchart of a firmware upgrade provided by an embodiment of the present application;
[0055] Figure 7 It is an interaction timing diagram of a firmware upgrade provided by an embodiment of the present application;
[0056] Figure 8 It is a schematic diagram of expanding the BAR space provided by an embodiment of the present application;
[0057] Figure 9 It is a schematic flowchart of writing configuration information into the flash memory space provided by an embodiment of the present application;
[0058] Figure 10 is Figure 9 a refined flowchart of step S903 in
[0059] Figure 11 It is an interaction timing diagram of configuring firmware provided by an embodiment of the present application;
[0060] Figure 12 It is a schematic structural diagram of a PCIe device provided by an embodiment of the present application.
[0061] Explanation of the reference numerals in the drawings:
[0062] Detailed implementation manners
[0063] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0064] It should be noted that if there is no conflict, the various features in the embodiments of the present application can be combined with each other, and all are within the protection scope of the present application. In addition, although the functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order from the module division in the device or the flowchart. Furthermore, the terms "first", "second", "third", etc. used in the present application do not limit the data and execution order, but only distinguish the same items or similar items with basically the same functions and effects.
[0065] Before the present application is described in detail, the nouns and terms involved in the embodiments of the present application are described. The nouns and terms involved in the embodiments of the present application are applicable to the following explanations:
[0066] (1) Expansion Base Address Register, which refers to a specific BAR configuration space in the PCIe protocol and is usually used to store PXE drivers and / or other specific drivers. The expansion BAR space typically contains the firmware of the device or other necessary code during startup, such as the Preboot Execution Environment (PXE) startup code of a Network Interface Card (NIC), or the BIOS extension of a RAID controller. These codes are called by the main system BIOS or UEFI during system startup to initialize the device and prepare it for the loading of the operating system.
[0067] (2) Base Address Register, which is used to specify the base address of the expansion BAR space and is used to store device firmware or driver code. The firmware or driver code is usually executed during device initialization or startup. When the system's BIOS performs the Power-On Self-Test (POST) process, it detects the Expansion ROM BAR of the PCI device and maps its memory address to the system's address space to allow the BIOS to execute the code in the ROM.
[0068] Please refer to Figure 1 , Figure 1 which is a schematic diagram of the loading process of an expansion BAR space provided by an embodiment of the present application.
[0069] As Figure 1 shown, the loading process of the expansion BAR space includes the following steps S101 - S109:
[0070] Step S101: The host is powered on.
[0071] Specifically, the host is connected to the power supply and the system starts to initialize.
[0072] Step S102: The BIOS starts.
[0073] Specifically, the Basic Input Output System (BIOS) is loaded. The Basic Input Output System is used for hardware initialization, Power-On Self-Test (POST), and running basic code.
[0074] Among them, hardware initialization includes initializing each hardware component in the system, including devices such as the CPU, memory, hard disk, graphics card, keyboard, and mouse, and allocating necessary resources (such as memory addresses, I / O ports, etc.) to prepare for the subsequent loading of the operating system.
[0075] Among them, self-checking includes a series of tests on hardware components during the startup process of the host to ensure that all key hardware works properly. For example, memory testing, device detection, and error reporting are carried out. Among them, memory testing includes checking whether the random access memory (RAM) is normal to ensure that data can be correctly read and written. Among them, device detection includes identifying and detecting connected hardware devices such as hard disks, optical drives, graphics cards, etc., and ensuring that they can operate normally. Among them, error reporting includes that if an error is found during self-checking, the BIOS will prompt the user through beeping sounds or display error messages, and abort the startup process to enable the user to troubleshoot the problem.
[0076] Among them, running the basic code, that is, the firmware code, includes loading the bootloader and entering the operating system.
[0077] Step S103: PCIe device enumeration.
[0078] It can be understood that PCIe device enumeration refers to the process in which the operating system identifies and configures all connected PCIe devices (PCI Express, PCIe) during the startup of the host or the loading of the operating system. Specifically, PCIe device enumeration includes: the operating system scans all PCIe slots through the PCIe bus to discover the connected PCIe devices. After that, necessary resources such as memory addresses and I / O ports are allocated to each PCIe device. After that, the operating system checks whether there are driver programs suitable for each identified device. If the driver programs are available, the operating system will load these driver programs so that the PCIe devices can work properly.
[0079] Step S104: Driver verification.
[0080] Specifically, verify the driver for the extended BAR space. If the verification is successful, proceed to step S103.
[0081] Step S105: Driver loading.
[0082] Specifically, if the PCIe device has an extended BAR space, the system will load the firmware or driver program in the extended read-only storage space so that the PCIe device can work properly. After the driver for the extended BAR space is loaded, proceed to step S104.
[0083] Step S106: System startup.
[0084] Specifically, the operating system starts to load and prepares to take over the management and operation of the host.
[0085] Step S107: Device driver loading.
[0086] Specifically, the operating system loads the driver of the PCIe device, enabling the PCIe device to operate through the operating system.
[0087] Step S108: Map the extended BAR space.
[0088] Specifically, map the address space of the extended BAR space of the PCIe device to the system memory address so as to be able to access the extended BAR space. It can be understood that the extended BAR space, as a memory area, is used to specify the memory and I / O address ranges required by the PCIe device. For example: The extended BAR space includes the Expansion ROM BAR space, and the Expansion ROM BAR space corresponds to a register, namely the Base Address Register (BAR), which is a register used to store the device resource address. That is, the Expansion ROM base address register is used to specify the memory mapping address of the Expansion ROM.
[0089] Step S109: Read and write the extended BAR space.
[0090] Specifically, read and write the Expansion ROM Base Address Register space to perform necessary configuration and initialization operations to ensure the normal operation of the device. Among them, the Expansion ROM BAR space corresponds to the Expansion ROM BAR register, and the Expansion ROM BAR register specifies a memory address, which is the base address of the Expansion ROM space and is used to store the device firmware or driver code, and this firmware or driver code is usually executed during device initialization or startup.
[0091] It should be noted that in traditional application scenarios, the Expansion ROM (extended read-only storage space) is usually used to load the driver for PXE installation after the BIOS starts, and the extended BAR space is usually disabled by default after the normal host system starts, resulting in the inavailability of the extended BAR space after the operating system starts.
[0092] Moreover, conventional extended BAR spaces directly map the embedded storage device, such as NOR flash. Through passthrough, a section of the flash space of this storage device is directly mapped. It can be understood that passthrough means mapping the flash space to the host to form a shared memory space, so that the host can read and write this flash space, and the firmware can also obtain the data changes of this flash space in real time.
[0093] Since the passthrough method allows users to directly operate the read and write of the storage device during the process of reading and writing the extended BAR space, it exposes too many operation permissions to external users, which may cause the device driver of the storage device to be abnormally tampered with, resulting in low security of the device driver.
[0094] In view of this, the embodiment of the present application provides a management method for an extended read-only storage space. By enabling the extended read-only storage space, mapping the extended read-only storage space to the cache space, and then mapping the host memory space to the cache space, the security of the device driver can be improved.
[0095] The technical solution of the present application will be specifically described below with reference to the accompanying drawings of the specification:
[0096] The management method for the extended read-only storage space in the embodiment of the present application is applied to a PCIe device. The PCIe device is connected to a host, and the PCIe device includes: flash memory devices such as USB flash drives, SD cards, microSD cards, CF cards, and solid state drives (SSDs).
[0097] It can be understood that a flash memory device is a storage device using semiconductor flash memory (NAND Flash) as the medium, and its main components include a flash memory medium, a flash memory controller, a dynamic random access memory (DRAM), etc. Among them, an important function of the flash memory controller is to perform storage operations as the driver of the flash memory chip, and its main operations include erasing, writing, and reading.
[0098] Please refer to Figure 2 , Figure 2 which is a schematic structural diagram of a management system for an extended BAR space provided by an embodiment of the present application.
[0099] As Figure 2 shown, the management system 300 for the extended BAR space includes: a host 100 and a PCIe device 200. Among them, the host 100 is connected to the PCIe device 200, and the PCIe device 200 is communicatively connected to the host 100 in a wired or wireless manner for data interaction.
[0100] Among them, the host 100 includes: a host memory space 110 for storing data or instructions of the host 100.
[0101] It can be understood that the host memory space 110 refers to the memory area in the computer system of the host 100 for storing data and instructions. The host memory space 110 is a key component for the computer to run programs, process data, and execute tasks.
[0102] In an embodiment of the present application, the host memory space 110 includes: Random Access Memory (RAM) and Read-Only Memory (ROM).
[0103] Among them, the random access memory includes Dynamic Random Access Memory (DRAM) and Static Random Access Memory (SRAM).
[0104] Among them, the read-only memory includes Programmable Read-Only Memory (PROM), Erasable Programmable Read-Only Memory (EPROM), and Electrically Erasable Programmable Read-Only Memory (EEPROM).
[0105] Among them, the PCIe device 200 includes: an extended BAR space 210, a cache space 220, and a flash space 230.
[0106] Among them, the extended BAR space 210 refers to the extended base address registers (Base Address Registers, BARs) used to configure and map device memory and I / O space. That is, the extended BAR space 210 includes extended base address registers (extended BAR registers). The extended base address register allows the PCIe device to provide more resource address space to the host system, so that the device can access more memory or I / O resources. The PCIe device can request additional address space through the extended BAR register in its configuration space.
[0107] In some embodiments, the PCIe device 200 includes multiple BAR spaces. For example: a read-only storage space, that is, an Expansion ROM space. This read-only storage space includes an extended read-only storage space (Expansion ROM BAR). This extended read-only storage space is used to store firmware or drivers. Specifically, it is used to store boot code, device drivers, or other necessary software to support the functions of the PCIe device 200.
[0108] Among them, the cache space 220, that is, the Cache space, is a fast storage area in the PCIe device 200 for storing data and instructions. The cache space 220 is used to improve the data access speed of the PCIe device 200 and shorten the time delay for accessing the extended BAR space 210 or the flash space 230.
[0109] Among them, the flash space 230, that is, flash memory, is composed of a flash medium, which is connected to a controller (not shown in the figure). Among them, the flash medium serves as the storage medium of the PCIe device 200, and is also called flash, NAND Flash, Flash memory, or Flash particle. It belongs to a type of storage device and is a non-volatile memory that can store data permanently even without current supply. Its storage characteristics are equivalent to those of a hard disk, making the flash medium the basis for the storage medium of various portable digital devices.
[0110] In some embodiments, the controller includes a processor, a memory, a flash controller, and an interface.
[0111] Among them, the processor is respectively connected to the memory, the flash controller, and the interface. Among them, the processor can be connected to the memory, the flash controller, and the interface through a bus or other means. The processor is used to run non-volatile software programs, instructions, and modules stored in the memory, so as to implement any method embodiment of the present application. On this basis, through firmware development, it is also used to be responsible for the core processing of the Flash translation layer (FTL).
[0112] Among them, the memory is mainly used to cache the read / write instructions sent by the host, and to cache the read data or write data obtained from the flash medium according to the read / write instructions sent by the host.
[0113] Among them, the flash controller is connected to the flash medium, the processor, and the memory, and is used to access the backend flash medium and manage various parameters and data I / O of the flash medium.
[0114] Among them, the interface connects the host, the processor, and the memory, and is used to receive the data sent by the host, or to receive the data sent by the processor, so as to realize the data transmission between the host and the processor. The interface can be a SATA-2 interface, a SATA-3 interface, a SAS interface, an MSATA interface, a PCI-E interface, an NGFF interface, a CFast interface, an SFF-8639 interface, and an M.2 NVME / SATA protocol.
[0115] Please refer to Figure 3 , Figure 3It is a flowchart of a method for managing an extended BAR space provided by an embodiment of the present application.
[0116] Among them, the method for managing the extended BAR space is applied to a PCIe device. Specifically, the execution entity of the method for managing the extended BAR space is one or at least two processors of the PCIe device.
[0117] As Figure 3 shown, the method for managing the extended BAR space includes the following steps S301 - step S306:
[0118] Step S301: After the host operating system starts, obtain an enable command to enable the extended BAR space.
[0119] Specifically, the extended BAR space (Expansion ROM) is re-enabled through the enable command, so that the extended BAR space can still be in an available state after the host operating system starts. Among them, the base address register (BAR) of the extended BAR space corresponds to an enable bit, and the state of the enable bit is an enabled state or a non-enabled state. By enabling the base address register, the extended BAR space can be enabled.
[0120] Please refer to Figure 4 , Figure 4 is Figure 3 a refined flowchart of step S301 in
[0121] As Figure 4 shown, the refined process of step S301 includes the following steps S3011 - step S3012:
[0122] Step S3011: Obtain an enable command.
[0123] Specifically, the enable command is used to enable the extended BAR space, and the enable command includes the setpci command. It can be understood that the setpci command is generated and executed by the setpci tool. Among them, the setpci tool is a command-line tool for directly accessing and modifying the configuration space of a PCI (Peripheral Component Interconnect) device. Through the setpci command, PCI device information can be viewed and PCI device registers can be modified.
[0124] Step S3012: According to the enable command, set the state of the enable bit of the base address register corresponding to the extended BAR space to the enabled state to enable the extended BAR space.
[0125] Specifically, the base address register of the extended BAR space corresponds to an enable bit, and the state of the enable bit is an enabled state or a non-enabled state. Through an enable command, the state of the enable bit of the base address register is set to the enabled state. For example, the enable bit is a binary bit, and a value of 1 for the binary bit represents that the state of the enable bit is the enabled state, and a value of 0 for the binary bit represents that the state of the enable bit is the non-enabled state. By the enable command, the value of the enable bit is set to 1, thereby enabling the base address register, and further enabling the extended BAR space corresponding to the base address register.
[0126] In the embodiment of the present application, by enabling the base address register and further enabling the extended BAR space corresponding to the base address register, the present application can further use the extended BAR space after the host operating system is started. The extended BAR space is a multi-functional shared space, which can take into account the original firmware storage function of the extended read-only storage space, realize a flexible interaction path for extended firmware update and configuration update, and is jointly managed by the driver and the firmware, which is beneficial to improving the availability and flexibility of the extended BAR space.
[0127] Step S302: Map the extended BAR space to the cache space, and map the host memory space to the cache space.
[0128] Specifically, mapping the extended BAR space to the cache space includes:
[0129] Mapping the address of the extended BAR space to the address of the cache space, which specifically includes the following steps (1)-(2):
[0130] (1) Determine the address range of the extended BAR space and determine the address range of the cache space.
[0131] Among them, the extended BAR space includes a BAR space, and the BAR space is a storage area of a PCIe device. If the host needs to read and write to the BAR space, the BAR space needs to be mapped to the host memory space of the host, and the start address of the BAR space is the base address.
[0132] In the embodiment of the present application, the extended BAR space includes a Programmable Read-Only Memory (PROM), an Erasable Programmable Read-Only Memory (EPROM), and an Electrically Erasable Programmable Read-Only Memory (EEPROM).
[0133] Among them, the cache space includes a cache space, where the cache space includes a Static Random Access Memory (SRAM), the address of the cache space includes an SRAM address, and the address range of the cache space includes a start address and an end address.
[0134] (2) Establish a mapping relationship between the address of the extended BAR space and the address of the cache space to map the address of the extended BAR space to the address of the cache space.
[0135] Specifically, mapping the host memory space to the cache space includes:
[0136] Mapping the address of the host memory space to the address of the cache space specifically includes the following steps (1)-(2):
[0137] (1) Determine the address range of the host memory space and determine the address range of the cache space.
[0138] Among them, the host memory space includes the address range that can be addressed in the memory, that is, the set of memory addresses that the Central Processing Unit (CPU) can directly access. The host first applies for a section of the host memory space for mapping with the hardware space of the PCIe device, so that the host can realize the reading and writing of the hardware storage space by writing to the local storage space.
[0139] In the embodiment of the present application, the host memory space includes a host memory, and the host memory includes: Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), etc.
[0140] (2) Establish a mapping relationship between the address of the host memory space and the address of the cache space to map the address of the host memory space to the address of the cache space.
[0141] In the embodiments of the present application, the data in the cache space is used to be written into the flash space of the PCIe device, or the data in the flash space of the PCIe device is used to be read into the cache space. After mapping the address of the extended BAR space to the address of the cache space and mapping the address of the host memory space to the address of the cache space, the host can directly read and write the data in the cache space, but cannot directly read and write the data in the flash space, enabling the host to interact with the cache space, while the cache space interacts with the flash space, so that the host indirectly interacts with the flash space, thereby avoiding the user from directly operating the flash space, reducing the problem of abnormal tampering of the device driver, and improving the security of the device driver.
[0142] Step S303: After the host data is written into the cache space, store the host data in the secure isolation area of the cache space, and verify the host data in the secure isolation area through the firmware.
[0143] It can be understood that since data interaction can be carried out between the cache space and the flash space, in order to improve the security of the data in the flash space, data verification is required.
[0144] Specifically, the cache space includes a secure isolation area, which is a specific area in the cache space and is used to store the host data written by the host. It can be understood that the cache space also includes a normal data area, which is used to store other data, such as user data read from the flash space.
[0145] By setting up the secure isolation area, the host data can be better verified to better flush the host data sent by the host to the flash space and improve the data security of the flash space.
[0146] Step S304: Determine whether the verification is passed;
[0147] Specifically, verify the host data in the cache space. If the verification is passed, proceed to step S305: Write the host data in the secure isolation area into the flash space.
[0148] If the verification fails, proceed to step S306: Do not write into the flash space.
[0149] Specifically, the firmware performs a security verification on the data in the cache space, so that the host data must pass the verification according to the encryption requirements before it can be written into the flash space. It can be understood that there are various ways to perform a security verification on the host data, and the main purpose is to ensure the integrity, authenticity, confidentiality, and availability of the host data. For example:
[0150] Perform security verification on the host data through hash verification. Specifically: Use a hash algorithm (such as SHA-256, SHA-1, SHA-512, MD5, etc.) to generate the hash value of the host data, calculate the host data in the cache space, that is, the data to be written into the flash space, to obtain the corresponding hash value, and compare it with the hash value provided by the host to verify whether the host data has been tampered with. If the hash values are the same, it is determined that the verification passes, and then the host data in the secure isolation area is written into the flash space.
[0151] Alternatively, perform security verification through public key encryption. Specifically: Use a public key algorithm (such as RSA, ECDSA, etc.) to encrypt the host data or its hash value to generate a digital signature. The PCIe device can use the public key of the host to verify the signature to ensure the source and integrity of the host data to determine whether the verification passes. If the verification passes, the host data in the secure isolation area is written into the flash space.
[0152] Step S305: Write the host data in the secure isolation area into the flash space.
[0153] Specifically, if the host data in the secure isolation area passes the security verification, it is confirmed that the host data meets the writing requirements. At this time, the host data in the secure isolation area is written into the flash space.
[0154] Step S306: Do not write into the flash space.
[0155] Specifically, if the host data in the secure isolation area fails the security verification, the host data in the secure isolation area is not written into the flash space.
[0156] In the embodiment of the present application, by verifying the host data in the secure isolation area of the cache space, it is possible to avoid damage to the original data in the flash space caused by the data directly written into the flash space, thereby improving the security of the data.
[0157] Please refer to Figure 5 , Figure 5 which is the overall flowchart of the mapping of an extended BAR space provided by the embodiment of the present application.
[0158] As Figure 5 shown, the overall process of the mapping of the extended BAR space includes the following steps S501 - step S506:
[0159] Step S501: Power on the PCIe device.
[0160] Specifically, the power supply of the PCIe device is turned on, and the host accesses the configuration space of the PCIe device through the PCIe bus to read the configuration information of the PCIe device. The PCIe device initializes according to the information obtained from the configuration space, sets the working mode, functions, and resource allocation (such as memory mapping, IRQ allocation, etc.) of the PCIe device. The operating system of the host loads the corresponding device driver to support the functions and services of the PCIe device.
[0161] Step S502: Load the data in the flash space into the cache space.
[0162] Specifically, the firmware starts up and loads the flash data in the flash space into the cache space, for example: the SRAM space.
[0163] Step S503: PCIe initialization.
[0164] Specifically, the PCIe initialization includes the following steps (1)-(3):
[0165] (1) Initialize information. Specifically, initialize according to the information in the configuration space, including setting the DMA channel, buffer, control register, etc.
[0166] (2) Load the driver. Specifically, the operating system loads the corresponding PCIe device driver during the startup process to support the functions and services of the PCIe device.
[0167] (3) Function test. Specifically, the PCIe device may execute a self-test program to ensure that all functions are normal.
[0168] Step S504: PCIe BAR initialization.
[0169] Specifically, the PCIe BAR initialization includes the following steps (1)-(3):
[0170] (1) Configure the PCIe BAR. Specifically, when reading the PCIe BAR, the host or the operating system requests the required address range from the device, usually set to 0 so that the device can return the address space it needs. During the process of reading the BAR, the operating system needs to identify the type (memory or I / O) and address width (32-bit or 64-bit) of each PCIe BAR.
[0171] (2) Allocate resources. Specifically, the operating system allocates appropriate memory or I / O address space for each PCIe BAR to ensure that there is no conflict with the address space of other devices.
[0172] (3) Function initialization. Specifically, the PCIe device performs memory and I / O operations through the allocated address space.
[0173] Step S505: Enable the extended BAR space.
[0174] Specifically, obtain an enable command, and according to the enable command, set the status of the enable bit of the base address register corresponding to the extended BAR space to the enabled state to enable the extended BAR space.
[0175] Step S506: Transparently transmit the address of the cache space to the host.
[0176] Specifically, map the address of the host memory space to the address of the cache space to transparently transmit the address of the cache space to the host. For example: Transparently transmit the SRAM address to the host.
[0177] In the embodiment of the present application, by modifying the space actually mapped to the host operation in the Expansion ROM space to the SRAM address, and then the firmware writes the data of the SRAM to the flash or reads the data from the flash to the SRAM, the secure isolation of the user's direct operation of the flash is achieved, so that the user can be prevented from directly operating the flash memory space, reducing the problem that the device driver is abnormally tampered with and improving the security of the device driver.
[0178] Further, after enabling the extended BAR space, firmware upgrade can be performed by using the extended BAR space.
[0179] Specifically, please refer to Figure 6 , Figure 6 which is a schematic flow diagram of upgrading firmware provided by the embodiment of the present application.
[0180] As Figure 6 shown, the process of upgrading the firmware includes the following steps S601 - step S606:
[0181] Step S601: Obtain a firmware upgrade instruction and a firmware upgrade package.
[0182] Specifically, the firmware upgrade instruction is sent from the host to the PCIe device for upgrading the current firmware of the PCIe device. The firmware upgrade package is used for the firmware to perform an upgrade operation to upgrade the current firmware of the PCIe device. For example:
[0183] The customized upgrade tool running in the host can trigger the firmware upgrade by writing specific instructions or bits (bit) to the extended BAR space of the PCIe device. The instructions include starting the upgrade, checking the firmware version, writing new firmware data, etc. Among them, the firmware of the PCIe device will monitor the data changes in its BAR space in real time. For example: It is implemented through a certain form of interrupt, polling or other mechanisms, so that the firmware of the PCIe device can detect the firmware upgrade instruction sent by the host.
[0184] Step S602: According to the firmware upgrade instruction, send the firmware upgrade package to the extended BAR space to store the firmware upgrade package in the cache space.
[0185] Specifically, once the firmware detects a data change, based on the received data content, the firmware will execute corresponding instructions, including: starting data transmission to update the firmware. That is, after receiving the firmware upgrade instruction, the PCIe device further receives the firmware upgrade package sent by the host and sends the firmware upgrade package to the extended BAR space. After that, the PCIe device sends the firmware upgrade package in the extended BAR space to the cache space to store the firmware upgrade package in the cache space.
[0186] Step S603: Verify the firmware upgrade package.
[0187] Specifically, after storing the firmware upgrade package in the cache space, such as the SRAM space, the firmware can read the firmware upgrade package through the SRAM space and verify the firmware upgrade package.
[0188] Step S604: Determine whether the verification is successful.
[0189] Specifically, according to the header information of the firmware upgrade package and decrypting the firmware upgrade package through a decryption algorithm to confirm whether it passes the verification. The header information includes information such as firmware version number, firmware size, encryption type, hash value, manufacturer information, compatibility information, and check field. Among them, the firmware version number is used to distinguish different versions of the firmware to ensure that higher existing versions are not overwritten. The firmware size is used to indicate the size of the entire firmware package for correct memory allocation during reception and loading. The encryption type is used to indicate the algorithm (such as AES, RSA, etc.) used to encrypt the firmware content for using the corresponding algorithm during decryption. The hash value refers to the hash value (such as SHA-256) of the firmware content for verifying the integrity of the firmware after decryption. The manufacturer information contains relevant information about the source of the firmware to ensure that the firmware is from a trusted manufacturer. The compatibility information is used to indicate the device types and versions applicable to the firmware to prevent the installation of inapplicable firmware. The check field includes a checksum and / or CRC check value for detecting the integrity of the header itself.
[0190] Specifically, decrypting the firmware upgrade package through a decryption algorithm to confirm whether it passes the verification includes the following steps (1)-(2):
[0191] (1) Decrypt the firmware upgrade package through a preset key or a key sent by the host based on a decryption algorithm matching the encryption type specified in the header to obtain the decrypted data.
[0192] (2) Perform security verification on the decrypted data. If the security verification passes, it is determined that the firmware upgrade package verification is successful; if the security verification fails, it is determined that the firmware upgrade package verification fails.
[0193] Specifically, the security verification includes: integrity verification, version verification, firmware size verification, and security verification, etc.
[0194] Among them, integrity verification refers to calculating the hash value of the decrypted firmware content and comparing it with the hash value in the packet header to confirm that the firmware data has not been tampered with during transmission.
[0195] Among them, version verification refers to checking the firmware version number to ensure that the upgraded version is appropriate and will not introduce firmware that is incompatible with the existing system.
[0196] Among them, firmware size verification refers to confirming that the size of the decrypted firmware is the same as the firmware size declared in the packet header.
[0197] Among them, security verification refers to confirming that the source and content of the firmware package comply with security rules to ensure that the upgraded firmware has not been maliciously tampered with.
[0198] If the firmware upgrade package verification is successful, proceed to step S605.
[0199] If the firmware upgrade package verification fails, proceed to step S606.
[0200] Step S605: Write the firmware upgrade package into the flash memory space to upgrade the current firmware of the PCIe device according to the firmware upgrade package.
[0201] Specifically, write the firmware upgrade package into the flash memory space. After upgrading the current firmware of the PCIe device using the firmware upgrade package, restart the PCIe device to apply the new firmware.
[0202] Step S606: Upgrade failed.
[0203] Specifically, if the firmware upgrade package is not verified successfully, it is determined that the upgrade fails.
[0204] In the embodiments of the present application, by performing security verification on the firmware upgrade package, the security of upgrading the PCIe device can be ensured, and the operation stability of the PCIe device can be improved.
[0205] Please refer to Figure 7 , Figure 7 which is an interaction timing diagram for upgrading firmware provided by the embodiments of the present application.
[0206] As Figure 7 shown, the interaction timing for upgrading firmware includes the following steps S701 - step S707:
[0207] Step S701: The host sends a firmware upgrade instruction to the PCIe device.
[0208] Specifically, the host responds to the user's operation, generates a firmware upgrade instruction, and sends the firmware upgrade instruction to the PCIe device. The firmware upgrade instruction is used to upgrade the current firmware of the PCIe device.
[0209] Step S702: The PCIe device receives the firmware upgrade instruction.
[0210] Step S703: The host sends a firmware upgrade package to the PCIe device.
[0211] Step S704: The PCIe device verifies the firmware upgrade package.
[0212] Step S705: The PCIe device burns the firmware.
[0213] Specifically, after the PCIe device successfully verifies the firmware upgrade package, the PCIe device writes the new firmware into the flash memory space so that the firmware can be loaded when starting up next time. It can be understood that after the firmware update is completed, the PCIe device needs to be restarted or re-initialized to load the new firmware and apply the new functions.
[0214] Step S706: The PCIe device sends a burn success instruction to the host.
[0215] Specifically, after the firmware is burned successfully, the PCIe device sends a burn success instruction to the host. The burn success instruction includes information such as a status code, the version number of the new firmware, the unique identification information of the PCIe device (such as device ID, model), and a hash value.
[0216] Step S707: The host determines that the firmware upgrade is completed.
[0217] Specifically, after receiving the burn success instruction sent by the PCIe device, the host determines that the firmware upgrade of the PCIe device is completed.
[0218] In the embodiment of the present application, by re-enabling the extended BAR space after the host starts up and using the extended BAR space for firmware upgrade, the extended BAR space can be extended and used, improving the availability of the extended BAR space.
[0219] Furthermore, in order to utilize the extended BAR space, the present application also partitions the extended BAR space. For example: performing a functional partition on the extended BAR space.
[0220] Specifically, the extended BAR space is partitioned. For example: divided into a first partition and a second partition. Please refer to Figure 8 ,Figure 8 This is a schematic diagram of an extended BAR space provided by an embodiment of the present application.
[0221] As Figure 8 shown, the extended BAR space 210 includes a first partition 211 and a second partition 212. Among them, the first partition 211 and the second partition 212 are respectively used for different operations. For example, the first partition 211 is used to store configuration information, and the second partition 212 is used to store other data. Among them, the configuration information includes firmware version, product information, etc. The configuration information in this cache space can be written into the flash space. Among them, the configuration information can include programming information, such as: product information, such as manufacturer information, serial number, etc. This programming information is used to be written into the flash space for persistent storage.
[0222] In the embodiment of the present application, by setting the first partition of the extended BAR space to store configuration information for persistent storage of firmware configuration and special information such as firmware version, product information, etc., the host can display information saved to the hardware to the user or issue configuration commands to the firmware to implement the interaction between the host and the hardware device.
[0223] In the embodiment of the present application, the extended BAR space can be understood as a shared memory area. The upgrade tool of the host and the firmware perform command processing and / or data interaction according to a unified planned area. For example, the extended BAR space can also include a third partition. Among them, the first partition is used for command interaction, the second partition is used for firmware data transmission, and the third partition is used to store firmware information to utilize the extended BAR space to implement different functions.
[0224] Please refer to Figure 9 , Figure 9 This is a schematic diagram of a process for writing configuration information to the flash space provided by an embodiment of the present application.
[0225] As Figure 9 shown, the process of writing configuration information to the flash space includes the following steps S901 - step S905:
[0226] Step S901: Receive the information storage instruction and configuration information issued by the host, and store the configuration information in the cache space.
[0227] Specifically, the information storage instruction issued by the host is used to store the configuration information in the PCIe device. The PCIe device receives the information storage instruction and configuration information issued by the host through the extended BAR space. For example, the configuration information is stored through the first partition, and through the mapping relationship between the extended BAR space and the cache space, the configuration information is stored in the cache space.
[0228] Step S902: Verify the information storage instruction and the configuration information.
[0229] It can be understood that when storing configuration information, verification is usually required to ensure data integrity and accuracy. The firmware verifies the information storage instruction and the configuration information, for example: verifying the instruction format of the information storage instruction, verifying the integrity of the information storage instruction, or verifying the data format of the configuration information, performing security verification on the configuration information, etc.
[0230] Step S903: Determine whether the verification is successful.
[0231] Specifically, determine whether the information storage instruction and the configuration information pass the verification.
[0232] If the verification is successful, proceed to Step S904.
[0233] If the verification fails, proceed to Step S905.
[0234] Please refer to Figure 10 , Figure 10 Yes Figure 9 is the detailed process schematic diagram of Step S903 in
[0235] As Figure 10 shown, this Step S903 includes the following Steps S9031 - Step S9035:
[0236] Step S9031: Encrypt and package the information storage instruction and the configuration information through an encryption packaging tool to obtain a compressed package.
[0237] Specifically, use a dedicated encryption packaging tool to encrypt and package the information storage instruction and the configuration information to obtain a compressed package. For example: encrypt and package the information storage instruction and the configuration information through the AES algorithm, RSA algorithm, DSA algorithm, or the Elliptic Curve Public Key Cryptography Algorithm (SM2) to obtain a compressed package.
[0238] Step S9032: Decrypt the compressed package through a predetermined decryption algorithm.
[0239] Specifically, according to the decryption algorithm corresponding to the encryption algorithm used for encryption, for example: the AES algorithm, RSA algorithm, DSA algorithm, or the Elliptic Curve Public Key Cryptography Algorithm (SM2).
[0240] Decrypt the compressed package, which specifically includes the following steps:
[0241] (1) Unzip the compressed package through an unzipping tool.
[0242] (2) Calculate the checksum of the compressed package (such as SHA-256) and compare it with the checksum stored in the compressed package to ensure that the data has not been tampered with or damaged.
[0243] (3) Extract the encrypted data part from the compressed package.
[0244] (4) Use a predetermined decryption algorithm and key to decrypt the encrypted content to generate the original data. If symmetric encryption (such as AES) is used, directly use the same key for decryption. If asymmetric encryption (such as RSA) is used, use the corresponding private key for decryption.
[0245] Step S9033: Determine whether the decryption is successful.
[0246] Specifically, determine whether the original data can be decompressed through the predetermined decryption algorithm. If so, determine that the decryption is successful, and at this time, enter step S9034; if not, determine that the decryption fails, and at this time, enter step S9035.
[0247] Step S9034: Determine that the verification is successful.
[0248] Specifically, if the decryption is successful, determine that the verification is successful.
[0249] Step S9035: Determine that the verification fails.
[0250] Specifically, if the decryption fails, determine that the verification fails.
[0251] Step S904: Write the configuration information in the cache space to the flash space.
[0252] Specifically, after the information storage instruction and the configuration information verification are successful, according to the mapping relationship between the cache space and the flash space, write the configuration information in the cache space to the flash space.
[0253] Furthermore, after the PCIe is powered on, the firmware can copy the configuration information in the flash space to the extended BAR space. Specifically, according to the mapping relationship between the flash space and the cache space, copy the configuration information in the flash space to the cache space, and then further according to the mapping relationship between the cache space and the extended BAR space, copy the configuration information in the cache space to the extended BAR space.
[0254] Step S905: Do not write to the flash space.
[0255] Specifically, if the information storage instruction and the configuration information verification fail, do not write the configuration information to the flash space.
[0256] Please refer to Figure 11 , Figure 11It is an interaction timing diagram for configuring firmware provided by an embodiment of the present application.
[0257] As Figure 11 shown, the interaction timing of the configuration firmware includes the following steps S1101 - step S1106:
[0258] Step S1101: The host sends an information storage instruction and configuration information to the PCIe device.
[0259] Step S1102: The PCIe device stores the configuration information in the cache space.
[0260] Step S1103: The PCIe device verifies the configuration information.
[0261] Step S1104: The PCIe device configures the firmware according to the configuration information.
[0262] Specifically, the PCIe device sets the hardware registers according to the configuration information sent by the host to configure the firmware. Among them, the configuration information includes device identification information. For example: Vendor ID, which refers to the unique identifier used to identify the device manufacturer. The configuration information also includes Device ID, which refers to the unique identifier used to identify a specific device.
[0263] It can be understood that the configuration information may also include related information such as register configuration, allocation of memory and I / O addresses, interrupt management, firmware configuration, power management, etc.
[0264] Through the configuration information sent by the host, the PCIe device can perform corresponding settings on the hardware registers to ensure the normal operation of the PCIe device and effective interaction with the host.
[0265] Step S1105: The PCIe device sends an information storage instruction success instruction to the host.
[0266] Step S1106: The host determines that the information storage instruction is completed.
[0267] Specifically, if the host receives the instruction success instruction fed back by the PCIe device, it determines that the information storage instruction is completed.
[0268] In an embodiment of the present application, by providing a method for managing an extended BAR space, which is applied to a PCIe device. The PCIe device is connected to a host, and the host includes a host memory space. The PCIe device includes an extended BAR space, a cache space, and a flash memory space. The method includes: after the operating system of the host is started, obtaining an enable command to enable the extended BAR space; mapping the extended BAR space to the cache space, and mapping the host memory space to the cache space, so that the host directly reads and writes data in the cache space, where the data in the cache space is used to be written into the flash memory space, or the data in the flash memory space is used to be read into the cache space.
[0269] By enabling the extended BAR space, mapping the extended BAR space to the cache space, and then mapping the host memory space to the cache space, the host interacts with the cache space, and the cache space interacts with the flash memory space, so that the host indirectly interacts with the flash memory space, thus avoiding the user directly operating the flash memory space, reducing the problem of abnormal tampering of the device driver, and improving the security of the device driver.
[0270] In an embodiment of the present application, for the network card without a specific user-firmware interaction path, by expanding the ExpansionROM space into a user-firmware interaction space, the expansion of network card functions is realized, such as updating the firmware and issuing configurations. The present application can improve the availability and flexibility of the extended BAR space.
[0271] Please refer to Figure 12 , Figure 12 which is a schematic structural diagram of a PCIe device provided by an embodiment of the present application.
[0272] As Figure 12 shown, the PCIe device 200 includes one or more processors 201 and a memory 202. Among them, Figure 12 one processor 201 is taken as an example.
[0273] The processor 201 and the memory 202 can be connected through a bus or other means, Figure 12 and taking the connection through a bus as an example.
[0274] The processor 201 is used to provide computing and control capabilities to control the PCIe device 200 to perform corresponding tasks. For example, it controls the PCIe device 200 to execute the method for managing the extended BAR space in any one of the above method embodiments. Applied to the PCIe device, the PCIe device is connected to the host, the host includes a host memory space, and the PCIe device includes an extended BAR space, a cache space, and a flash memory space. The method includes: after starting the operating system of the host, obtaining an enabling command to enable the extended BAR space; mapping the extended BAR space to the cache space and mapping the host memory space to the cache space, so that the host can directly read and write the data in the cache space, where the data in the cache space is used to be written into the flash memory space, or the data in the flash memory space is used to be read into the cache space.
[0275] By enabling the extended BAR space, mapping the extended BAR space to the cache space, and then mapping the host memory space to the cache space, the host can interact with the cache space, and the cache space can interact with the flash memory space, so that the host can indirectly interact with the flash memory space, thus avoiding the user from directly operating the flash memory space, reducing the problem of abnormal tampering of the device driver, and improving the security of the device driver.
[0276] The processor 201 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), a hardware chip, or any combination thereof; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The above PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0277] The memory 202 serves as a non-transitory computer-readable storage medium and can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as the program instructions / modules corresponding to the method for managing the extended BAR space in the embodiments of the present application. By running the non-transitory software programs, instructions, and modules stored in the memory 202, the processor 201 can implement the method for managing the extended BAR space in any of the following method embodiments. Specifically, the memory 202 may include volatile memory (VM), such as random access memory (RAM); the memory 202 may also include non-volatile memory (NVM), such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD), or other non-transitory solid-state storage devices; the memory 202 may further include a combination of the above types of memories.
[0278] The memory 202 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage devices. In some embodiments, the memory 202 optionally includes memories remotely located relative to the processor 201, and these remote memories can be connected to the processor 201 through a network. Examples of the above networks include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.
[0279] One or more modules are stored in the memory 202 and, when executed by one or more processors 201, implement the method for managing the extended BAR space in any of the above method embodiments. For example, execute the Figure 3 respective steps shown above.
[0280] In the embodiments of the present application, the PCIe device 200 may also have components such as a wired or wireless network interface, a keyboard, and an input / output interface for input / output. The PCIe device 200 may further include other components for implementing the functions of the device, which will not be elaborated here.
[0281] The embodiments of the present application also provide a non-volatile computer-readable storage medium, such as a memory including program code, and the above program code can be executed by a processor to complete the method for managing the extended BAR space in the above embodiments. For example, the non-volatile computer-readable storage medium can be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CDROM), magnetic tape, floppy disk, and optical data storage device, etc.
[0282] The embodiments of the present application also provide a computer program product, which includes one or more pieces of program code, and the program code is stored in a non-volatile computer-readable storage medium. The processor of the PCIe device reads the program code from the non-volatile computer-readable storage medium, and the processor executes the program code to complete the method steps of the method for managing the extended BAR space provided in the above embodiments.
[0283] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above embodiments can be completed by hardware, or can be completed by hardware related to program code. The program can be stored in a non-volatile computer-readable storage medium, and the non-volatile computer-readable storage medium mentioned above can be a read-only memory, a magnetic disk, or an optical disc, etc.
[0284] Through the description of the above embodiments, those of ordinary skill in the art can clearly understand that each embodiment can be implemented by means of software plus a general hardware platform, and of course, it can also be implemented by hardware. Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by a computer program instructing related hardware. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the non-volatile computer-readable storage medium can be a magnetic disk, an optical disc, a read-only memory (ROM), or a random access memory (RAM), etc.
[0285] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than limiting them; under the idea of the present application, the technical features in the above embodiments or different embodiments can also be combined, and the steps can be implemented in any order, and there are many other changes in different aspects of the present application as described above. For the sake of brevity, they are not provided in detail; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for managing an extended BAR space, characterized in that: Applied to a PCIe device, the PCIe device is connected to a host, the host includes a host memory space, the PCIe device includes an extended BAR space, a cache space, and a flash memory space, the cache space includes a secure isolation area, and the method includes: After the operating system of the host is started, obtaining an enable command to enable the extended BAR space; Mapping the extended BAR space to the cache space, and mapping the host memory space to the cache space; After the host data is written into the cache space, the host data is stored in the secure isolation area of the cache space, and the host data in the secure isolation area is verified by firmware. If the verification passes, the host data in the secure isolation area is written into the flash memory space.
2. The method according to claim 1, characterized in that The extended BAR space corresponds to an enable bit, and the state of the enable bit is an enabled state or a disabled state; The obtaining of the enabling command to enable the extended BAR space includes: Get the enable command; According to the enable command, the state of the enable bit of the base address register corresponding to the extended BAR space is set to an enable state to enable the extended BAR space.
3. The method according to claim 1, characterized in that The method further comprises: Get firmware upgrade instructions and firmware upgrade packages; According to the firmware upgrade instruction, the firmware upgrade package is sent to the extended BAR space to store the firmware upgrade package in the cache space; Verifying the firmware upgrade package; If the verification is successful, the firmware upgrade package is written into the flash memory space to upgrade the current firmware of the PCIe device according to the firmware upgrade package.
4. The method according to claim 1, characterized in that: The extended BAR space includes a first partition, and the first partition is used to store configuration information; The method further comprises: receiving an information storage instruction and configuration information sent by a host, and storing the configuration information in the cache space; Verifying the information storage instruction and the configuration information, and determining whether the verification is successful; If the verification is successful, the configuration information in the cache space is written into the flash memory space.
5. The method according to claim 4, characterized in that The verifying the information storage instruction and the configuration information, and determining whether the verification is successful, includes: Encrypt and package the information storage instructions and configuration information using an encryption and packaging tool to obtain a compressed package; Decrypting the compressed package using a predetermined decryption algorithm; If the decryption is successful, the verification is determined to be successful; If the decryption fails, then the verification is determined to have failed.
6. The method according to any one of claims 1 to 5, characterized in that: The extended BAR space includes an extended base address register, and the extended base address register is used to specify the memory and I / O address range required by the PCIe device.
7. The method according to any one of claims 1 to 5, characterized in that: The secure isolation area is a specific area in the cache space, and the secure isolation area is used to store host data written by the host.
8. A PCIe device, characterized in that: include: A processor and a memory, wherein the processor is used to execute an executable program code in the memory, and when the executable program code is executed, the processor executes instructions of the method for managing the extended BAR space as described in any one of claims 1 to 7.
9. A management system for expanding a BAR space, comprising: The PCIe device as claimed in claim 8; A host is connected to the PCIe device.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed, the method for managing the extended BAR space according to any one of claims 1 to 7 is implemented.