Memory management method and device, system on chip, electronic equipment and medium

By obtaining and converting multiple discontinuous physical memory areas into continuous virtual addresses in the memory management system, the long memory allocation time and failure caused by memory fragmentation are solved, and more efficient memory allocation is achieved.

CN120066759AActive Publication Date: 2025-05-30BEIJING X RING TECHNOLOGY CO LTD

Patent Information

Application Number
CN202311629390.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-05-30
Estimated Expiration
2043-11-30

AI Technical Summary

Technical Problem

After the existing secure memory management method runs for a period of time, it leads to a large amount of memory fragments in the memory, resulting in a long memory allocation time when other requests to allocate continuous physical memory when subsequently requesting to allocate continuous physical memory, and it is easy to cause memory allocation failure.

Method used

By receiving a memory application request, multiple non-continuous physical memory areas with a specific size are obtained from the memory according to the memory size, and continuous virtual address conversion processing is performed on these non-continuous physical memory areas to obtain continuous virtual addresses and are provided to the requesting end as a response to the memory application request.

Benefits of technology

In the case of severe memory fragmentation in memory, the allocation time is reduced to the subsequent allocation time of other requesting terminals to avoid allocation failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120066759A_ABST
    Figure CN120066759A_ABST
Patent Text Reader

Abstract

The invention relates to a memory management method and device, a system on chip, electronic equipment and a medium, and the method comprises the steps: receiving a memory application request; the memory application request comprises a request identifier and a memory size; obtaining a plurality of discontinuous physical memory areas with specific sizes from a memory according to the memory size; performing continuous virtual address conversion processing on the physical addresses of the plurality of discontinuous physical memory areas to obtain continuous virtual addresses; the continuous virtual addresses serve as responses of the memory application request and are provided for the request end corresponding to the request identifier, and the memory distributes a plurality of physical memory areas with discontinuous physical addresses and continuous virtual addresses for the secure memory request initiated by the request end, so that the memory can be used for storing the secure memory request under the condition that the memory fragmentation in the memory is serious. The allocation duration for allocating the memories to other subsequent request ends is shortened, and the problem of allocation failure when the memories are allocated to other subsequent request ends is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data processing, and particularly to a memory management method, apparatus, system-on-chip, electronic device, and medium. Background Art

[0002] The current secure memory management method mainly is that when the memory management system receives an access request from a requesting end, it performs authentication processing on the access request; after the authentication passes, it queries the continuous physical memory allocated for the requesting end in the memory according to the physical address in the access request, and obtains the content at this physical address in the continuous physical memory.

[0003] In the above solution, the memory allocates continuous physical memory for the requesting end; after the memory management system runs for a period of time, there will be a large number of memory fragments in the memory, resulting in less or no continuous unallocated physical memory in the memory. When subsequent other requesting ends request to allocate continuous physical memory, the memory allocation time is long, and it is easy to cause the problem of memory allocation failure. Summary of the Invention

[0004] The present disclosure provides a memory management method, apparatus, system-on-chip, electronic device, and medium.

[0005] According to a first aspect of an embodiment of the present disclosure, there is provided a memory management method, the method including: receiving a memory application request; the memory application request includes a request identifier and a memory size; according to the memory size, obtaining a plurality of non-continuous physical memory regions with a specific size from the memory; performing continuous virtual address conversion processing on the physical addresses of the plurality of non-continuous physical memory regions to obtain continuous virtual addresses; and providing the continuous virtual addresses as a response to the memory application request to the requesting end corresponding to the request identifier.

[0006] In an embodiment of the present disclosure, the method further includes: in the case of receiving a memory protection request carrying the request identifier, obtaining the continuous virtual address of the requesting end corresponding to the request identifier; determining a plurality of non-continuous physical memory regions allocated for the requesting end according to the continuous virtual address; and performing access permission configuration processing on the plurality of non-continuous physical memory regions to obtain access permission configurations of the plurality of physical memory regions.

[0007] In one embodiment of the present disclosure, the method further includes: obtaining a security access request; the security access request includes the request identifier, the target physical address, and the access type; querying the memory according to the target physical address to obtain a target secure memory in the memory that includes the target physical address; in a case where there is a target secure memory area including the target physical address in the physical memory area of the target secure memory, performing an authentication process on the access request according to the request identifier, the access type, and the target secure memory area; in response to successful authentication, performing an access process on the content at the target physical address in the target secure memory area.

[0008] In one embodiment of the present disclosure, the method includes: obtaining a target memory area in the target secure memory that includes the target physical address; obtaining security indication information corresponding to the target secure memory; tags corresponding to each physical memory area in the target secure memory are set in the security indication information; the tag indicates whether the physical memory area is secure; in a case where the tag corresponding to the target memory area indicates security, determining the target memory area as the target secure memory area.

[0009] In one embodiment of the present disclosure, the method further includes: obtaining a target memory area in the target secure memory that includes the target physical address; obtaining security indication information corresponding to the target secure memory; tags corresponding to each physical memory area in the target secure memory are set in the security indication information; the tag indicates whether the physical memory area is secure; in a case where the tag corresponding to the target memory area indicates non-security, determining that the target memory area is not the target secure memory area.

[0010] In one embodiment of the present disclosure, the method further includes: in a case where there is no physical memory area in the target secure memory, performing an authentication process on the access request according to the request identifier, the access type, and the target secure memory; in response to successful authentication, performing an access process on the content at the target physical address in the target secure memory.

[0011] In one embodiment of the present disclosure, the method further includes: determining that the security access fails when at least one of the following situations exists: the memory does not include the target secure memory; the target secure memory area does not exist in the physical memory area of the target secure memory; the authentication fails.

[0012] In one embodiment of the present disclosure, the authentication processing of the access request according to the request identifier, the access type, and the target secure memory area includes: obtaining the access permission configuration of the target secure memory area; querying the access permission configuration according to the request identifier and the access type to determine whether the access type is included in the allowed access types corresponding to the request identifier in the access permission configuration; and determining that the access request is authenticated successfully when the access type is included in the allowed access types corresponding to the request identifier.

[0013] In one embodiment of the present disclosure, the authentication processing of the access request according to the request identifier, the access type, and the target secure memory area further includes: obtaining the access permission configuration of the target secure memory area; querying the access permission configuration according to the request identifier and the access type to determine whether the access type is included in the allowed access types corresponding to the request identifier in the access permission configuration; and determining that the access request is not authenticated successfully when the access type is not included in the allowed access types corresponding to the request identifier.

[0014] In one embodiment of the present disclosure, the access permission configuration processing for multiple non - contiguous physical memory areas to obtain the access permission configurations of the multiple physical memory areas includes: for each physical memory area among the multiple non - contiguous physical memory areas, and for each requester, obtaining the label corresponding to the physical memory area, the access permission corresponding to the requester, and the request identifier of the requester; determining the access permission of the physical memory area for the requester according to the access permission corresponding to the requester, the request identifier of the requester, and the label corresponding to the physical memory area; and generating the access permission configuration corresponding to the physical memory area according to the access permissions of the physical memory area for each requester.

[0015] In one embodiment of the present disclosure, the obtaining of the secure access request includes: obtaining an access request, where the access request includes an access label, the request identifier, the target physical address, and the access type; and determining that the access request is the secure access request when the access label indicates secure access.

[0016] According to a second aspect of the embodiments of the present disclosure, there is also provided a memory management device, which includes: a receiving module, configured to receive a memory application request; the memory application request includes a request identifier and a memory size; a first obtaining module, configured to obtain, according to the memory size, a plurality of discontinuous physical memory regions with a specific size from a memory; a conversion processing module, configured to perform a continuous virtual address conversion process on the physical addresses of the plurality of discontinuous physical memory regions to obtain continuous virtual addresses; and a providing module, configured to provide the continuous virtual addresses as a response to the memory application request to a request end corresponding to the request identifier.

[0017] According to a third aspect of the embodiments of the present disclosure, there is also provided a system on a chip, which includes: a processor; the processor is connected to drivers of a plurality of request ends; a memory management unit SMMU hardware is provided in the drivers, configured to convert the physical addresses of a plurality of discontinuous physical memory regions into continuous virtual addresses; a memory connected to the processor through a bus and a security gate; the memory includes a memory provided with a plurality of physical memory regions; wherein, the processor is configured to implement the steps of the memory management method as described above.

[0018] According to a fourth aspect of the embodiments of the present disclosure, there is also provided an electronic device, which includes: a processor; a memory for storing executable instructions of the processor; wherein, the processor is configured to: implement the steps of the memory management method as described above.

[0019] According to a fifth aspect of the embodiments of the present disclosure, there is also provided a non-transitory computer-readable storage medium, when instructions in the storage medium are executed by a processor, enabling the processor to execute the memory management method as described above.

[0020] The technical solutions provided by the embodiments of the present disclosure at least bring the following beneficial effects:

[0021] By receiving a memory application request; the memory application request includes a request identifier and a memory size; obtaining, according to the memory size, a plurality of discontinuous physical memory regions with a specific size from a memory; performing a continuous virtual address conversion process on the physical addresses of the plurality of discontinuous physical memory regions to obtain continuous virtual addresses; and providing the continuous virtual addresses as a response to the memory application request to a request end corresponding to the request identifier, wherein, for a secure memory request initiated by a request end, the memory allocates a plurality of physical memory regions with discontinuous physical addresses and continuous virtual addresses, so as to reduce the allocation duration when allocating memory for subsequent other request ends in the case of serious memory fragmentation in the memory, and avoid the problem of allocation failure when allocating memory for subsequent other request ends.

[0022] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure, and do not constitute an undue limitation on the present disclosure.

[0024] Figure 1 A flowchart of a memory management method according to an embodiment of the present disclosure;

[0025] Figure 2 A flowchart of a memory management method according to another embodiment of the present disclosure;

[0026] Figure 3 A flowchart of a memory management method according to another embodiment of the present disclosure;

[0027] Figure 4 A block diagram schematic of memory management;

[0028] Figure 5 A schematic structural diagram of a memory management device according to an embodiment of the present disclosure;

[0029] Figure 6 A block diagram of a structure of an electronic device shown according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0030] In order to enable those of ordinary skill in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings.

[0031] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above accompanying drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such data used may be interchanged under appropriate circumstances so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0032] The current secure memory management method is mainly that when the memory management system receives an access request from the requesting end, it performs authentication processing on the access request; after the authentication passes, it queries the continuous physical memory allocated to the requesting end in the memory according to the physical address in the access request, and obtains the content at this physical address in the continuous physical memory.

[0033] In the above solution, the memory allocates continuous physical memory for the requesting end; after the memory management system runs for a period of time, there will be a large number of memory fragments in the memory, resulting in less or no continuous physical memory unallocated in the memory. When subsequent other requesting ends request to allocate continuous physical memory, the memory allocation time is long and it is easy to cause the problem of memory allocation failure.

[0034] Figure 1 FIG. is a flowchart of a memory management method according to an embodiment of the present disclosure. It should be noted that the memory management method of this embodiment can be applied to a memory management device, which can be configured in an electronic device or a system on a chip, so that the electronic device or the system on a chip can perform memory management functions.

[0035] Among them, the electronic device can be any device with computing capabilities, such as a personal computer (PC), a mobile terminal, a server, a controller in a vehicle, etc. The mobile terminal can be, for example, a vehicle-mounted device, a mobile phone, a tablet computer, a personal digital assistant, a wearable device, etc., which are hardware devices with various operating systems, touch screens, and / or display screens.

[0036] Among them, a system on a chip (SoC) refers to the technology of integrating a complete system on a single chip and grouping all or part of the necessary electronic circuits. This "system" usually includes a central processing unit (CPU), a memory, and peripheral circuits, etc. Among them, the system on a chip is mainly applied to SOC chips.

[0037] In addition, the memory management device can also be software in the electronic device, etc. Among them, the software is, for example, a memory management system, etc. Among them, in the following embodiments, the execution entity is taken as an example of the memory management system for description.

[0038] As Figure 1 shown, the method includes the following steps:

[0039] Step 101, receiving a memory application request; the memory application request includes a request identifier and a memory size.

[0040] In an embodiment of the present disclosure, the requesting end corresponding to the request identifier may be an application program module or hardware that uses the memory in the memory, etc. Among them, the application program module that uses the memory in the memory, for example, video-related applications, picture-related applications, etc. The hardware that uses the memory in the memory, for example, a Neural-network Processing Unit (NPU), a Graphics Processing Unit (GPU), a Video Processing Unit (VPU), etc. Among them, the request identifier, for example, a device unique identification code (Master ID, MID), etc., can uniquely identify the requesting end.

[0041] Step 102: Obtain multiple non-contiguous physical memory regions with a specific size from the memory according to the memory size.

[0042] In an embodiment of the present disclosure, the memory may include multiple memory blocks, and multiple physical memory regions with smaller granularity may be set in some of the memory blocks. Among them, the sizes of the multiple memory blocks may be the same or different. The sizes of the multiple physical memory regions may be the same.

[0043] In an embodiment of the present disclosure, in one example, in a scenario where there are many idle memory blocks in the memory, before step 102, the memory management system may also perform the following process: According to the memory size, determine whether there is a memory block in the memory whose size is greater than the size of the memory applied by the requesting end, that is, the memory size; if it exists, obtain the memory block from the memory; perform continuous virtual address conversion processing on the continuous physical addresses in the memory block to obtain continuous virtual addresses. If such a memory block does not exist in the memory, then perform step 102. If multiple non-contiguous physical memory regions with a specific size are not obtained when performing step 102, trigger the memory compaction and recycling mechanism and try to allocate again; if sufficient memory is still not obtained, determine that the allocation fails.

[0044] Among them, in a scenario where there are many idle memory blocks in the memory, giving priority to allocating memory in units of these memory blocks can quickly select the memory blocks to be allocated, perform address conversion processing, and provide them to the requesting end, thereby improving the memory allocation speed.

[0045] In another example, when there are fewer free memory blocks in the memory and the overall free memory is sufficient, that is, in a scenario where there are more physical memory regions in the free state, step 102 is first executed. When multiple non - contiguous physical memory regions of a specific size cannot be obtained from the memory, it is determined whether there is a certain memory block in the memory whose size is greater than the size of the memory requested by the requester, that is, this memory size, according to the memory size. If it exists, obtain this memory block from the memory; perform continuous virtual address conversion processing on the continuous physical addresses in this memory block to obtain continuous virtual addresses. If such a memory block cannot be obtained when this step is executed, trigger the memory compaction and recycling mechanism and try to allocate again; if sufficient memory still cannot be obtained, determine that the allocation fails.

[0046] Among them, in a scenario where there are fewer free memory blocks in the memory and the overall free memory is sufficient, it is preferred to perform memory allocation processing in units of physical memory regions, which can quickly select multiple physical memory regions to be allocated, perform address conversion processing, and provide them to the requester, thereby improving the memory allocation speed.

[0047] It should be noted that the memory can be, for example, Double Data Rate Synchronous Dynamic Random Access Memory (DDR), etc., and can be set according to actual needs, and no specific limitation is made here.

[0048] Step 103: Perform continuous virtual address conversion processing on the physical addresses of multiple non - contiguous physical memory regions to obtain continuous virtual addresses.

[0049] In the embodiments of the present disclosure, each requester corresponds to a System Memory Management Unit (SMMU) hardware for managing the memory allocated to this requester. For the requester corresponding to the request identifier, the memory management system can call the SMMU hardware corresponding to this requester to instruct the SMMU hardware to perform address conversion processing.

[0050] Among them, the mapping processing between virtual addresses and physical addresses by the SMMU hardware, and the setting of physical memory regions in the memory, facilitate the memory management system to allocate multiple physical memory regions that are discontinuous in physical addresses but continuous in virtual addresses to the requester, thereby being able to effectively utilize the memory in the memory, improving the memory utilization rate, and increasing the success rate of memory allocation.

[0051] Step 104: Provide the continuous virtual addresses as a response to the memory application request to the requester corresponding to the request identifier.

[0052] Among them, consecutive virtual addresses are provided to the request side corresponding to the request identifier, that is, multiple non-consecutive physical memory regions corresponding to the consecutive virtual addresses are allocated to the request side.

[0053] In the embodiments of the present disclosure, it should be noted that after the memory management system executes steps 101 to 104, the memory allocated to the request side is not secure memory. In order to implement protection processing for the memory allocated to the request side, the memory management system can also execute the following process: when receiving a memory protection request carrying a request identifier, obtain the consecutive virtual addresses of the request side corresponding to the request identifier; determine multiple non-consecutive physical memory regions allocated to the request side according to the consecutive virtual addresses; perform access permission configuration processing on the multiple non-consecutive physical memory regions to obtain access permission configurations of the multiple physical memory regions.

[0054] Among them, the process by which the memory management system determines the access permission configurations of multiple physical memory regions can be, for example, for each physical memory region among the multiple non-consecutive physical memory regions, for each request side, obtain the label corresponding to the physical memory region, the access permission corresponding to the request side, and the request identifier of the request side; determine the access permission of the physical memory region to the request side according to the access permission corresponding to the request side, the request identifier of the request side, and the label corresponding to the physical memory region; generate the access permission configuration corresponding to the physical memory region according to the access permissions of the physical memory region to each request side. Among them, the label corresponding to the physical memory region indicates whether the physical memory region is a secure memory region.

[0055] Among them, the access permission corresponding to the request side, for example, the request side has the permission to read the video in the memory, but does not have the permission to write the video into the memory. Another example is that the request side has the permission to read the password in the physical memory region and the permission to write the password into the physical memory region. Among them, the access permission corresponding to the request side can be provided by the request side, or pre-stored at a specified location in the memory, and read by the memory management system from the specified location.

[0056] In the memory management method according to the embodiments of the present disclosure, a memory application request is received; the memory application request includes a request identifier and a memory size; according to the memory size, a plurality of non - contiguous physical memory regions with a specific size are obtained from the memory; the physical addresses of the plurality of non - contiguous physical memory regions are subjected to continuous virtual address conversion processing to obtain continuous virtual addresses; the continuous virtual addresses are provided as a response to the memory application request to the request side corresponding to the request identifier, wherein the memory allocates a plurality of physical memory regions with discontinuous physical addresses and continuous virtual addresses for the secure memory requests initiated by the request side, thereby reducing the allocation duration when allocating memory for subsequent other request sides in the case of serious memory fragmentation in the memory and avoiding the problem of allocation failure when allocating memory for subsequent other request sides.

[0057] Figure 2 FIG. is a flowchart of a memory management method according to another embodiment of the present disclosure. It should be noted that the memory management method of this embodiment can be applied to a memory management device, which can be configured in an electronic device or a system - on - a - chip (SoC) so that the electronic device or the SoC can perform memory management functions.

[0058] Among them, the electronic device can be any device with computing capabilities, such as a personal computer (PC), a mobile terminal, a server, a controller in a vehicle, etc. The mobile terminal can be, for example, a vehicle - mounted device, a mobile phone, a tablet computer, a personal digital assistant, a wearable device, etc., which are hardware devices with various operating systems, touch screens, and / or display screens.

[0059] Among them, a system - on - a - chip (SoC) refers to the technology of integrating a complete system on a single chip and grouping all or part of the necessary electronic circuits. This "system" usually includes a central processing unit (CPU), a memory, and peripheral circuits, etc. Among them, the system - on - a - chip is mainly applied to SoC chips.

[0060] In addition, the memory management device can also be software in an electronic device, etc. Among them, the software is, for example, a memory management system, etc. In the following embodiments, the execution entity is taken as an example of a memory management system for description.

[0061] As Figure 2 shown, on the basis of the embodiment shown in Figure 1 the method includes the following steps:

[0062] Step 201, obtain a secure access request; the secure access request includes a request identifier, a target physical address, and an access type.

[0063] In an embodiment of the present disclosure, the process of the memory management system executing step 201 may be, for example, to obtain an access request, where the access request includes an access label, a request identifier, a target physical address, and an access type; when the access label indicates a secure access, determine that the access request is a secure access request.

[0064] In addition, when the access label indicates a non-secure access, the memory management system may directly access the content at the target physical address in the memory to return the access processing result to the requester.

[0065] Among them, the target physical address in the secure access request is obtained by mapping the target virtual address in the original access request initiated by the requester. Correspondingly, the process for the memory management system to obtain the secure access request may be, for example: (1) The requester initiates an original access request; the original access request includes a target virtual address, a request identifier, an access type, and an access label. (2) The requester transmits the original access request to the memory management unit (System Memory Management Unit, SMMU) hardware corresponding to the requester in the memory management system. (3) The SMMU hardware obtains the target virtual address in the original access request; combines a preset address mapping table to perform a mapping process on the target virtual address to obtain the target physical address corresponding to the target virtual address. (4) The SMMU hardware replaces the target virtual address in the original access request with the corresponding target physical address to obtain an access request. (5) The SMMU hardware sends the access request to the secure gate in the memory management system through the bus, instructing the secure gate to process the access request according to Figure 2 the embodiment shown.

[0066] In an embodiment of the present disclosure, the access type may include at least one of the following: read type, write type, etc. Among them, the read type refers to reading the content at the target physical address in the memory; the write type refers to performing a content write process at the target physical address in the memory.

[0067] Step 202, query the memory according to the target physical address to obtain the target secure memory in the memory that includes the target physical address.

[0068] In an embodiment of the present disclosure, the memory may include multiple memory blocks, and multiple physical memory regions may be set in some memory blocks. Among them, the sizes of the multiple memory blocks may be the same or different. The sizes of the multiple physical memory regions may be the same.

[0069] Among them, the process of the memory management system executing step 202 may be, for example, to query the memory according to the target physical address to obtain the memory in the memory that includes the target physical address; determine this memory as the target secure memory.

[0070] Step 203, when there is a target secure memory area including the target physical address in the physical memory area of the target secure memory, perform an authentication process on the access request according to the request identifier, access type, and target secure memory area.

[0071] In the embodiment of the present disclosure, the process of the memory management system executing Step 203 may be, for example, obtaining the access permission configuration of the target secure memory area; querying the access permission configuration according to the request identifier and access type, and determining whether the access type is included in the allowed access types corresponding to the request identifier in the access permission configuration; when the access type is included in the allowed access types corresponding to the request identifier, determining that the access request authentication passes; when the access type is not included in the allowed access types corresponding to the request identifier, determining that the access request authentication fails.

[0072] Step 204, in response to the authentication passing, perform an access process on the content at the target physical address in the target secure memory area.

[0073] In the embodiment of the present disclosure, the process of the memory management system executing Step 204 may be, for example, in response to the authentication passing, combining the access type in the secure access request, and performing an access process on the content at the target physical address in the target secure memory area.

[0074] For example, if the access type is the read type, the memory management system reads the content at the target physical address in the target secure memory area; and returns the content at the target physical address as a secure access response to the request side. Also for example, if the access type is the write type, the secure access request may further include candidate content to be written to the target physical address; the memory management system may write the candidate content to the target physical address in the target secure memory area, and return the write result as a secure access response to the request side. Among them, the write result may be, for example, write success or write failure, etc.

[0075] In the memory management method according to the embodiments of the present disclosure, a secure access request is obtained; the secure access request includes a request identifier, a target physical address, and an access type; the memory is queried according to the target physical address to obtain a target secure memory including the target physical address in the memory; in the case where there is a target secure memory area including the target physical address in the physical memory area of the target secure memory, the access request is authenticated according to the request identifier, the access type, and the target secure memory area; in response to successful authentication, access processing is performed on the content at the target physical address in the target secure memory area; wherein, for the secure memory request initiated by the request side, the memory allocates multiple physical memory areas with discontinuous physical addresses and continuous virtual addresses, so that when receiving the secure access request, the target secure memory area including the target physical address can be obtained in units of physical memory areas, and then access processing is performed on the content at the target physical address in the target secure memory area, thereby being able to quickly find the content at the target physical address and improve the access speed.

[0076] Figure 3 It is a flowchart of the memory management method according to another embodiment of the present disclosure. It should be noted that the memory management method of this embodiment can be applied to a memory management device, and this device can be configured in an electronic device or a system on a chip, so that the electronic device or the system on a chip can perform the memory management function.

[0077] Among them, the electronic device can be any device with computing power, such as a personal computer (PC for short), a mobile terminal, a server, a controller in a vehicle, etc. The mobile terminal can be a hardware device with various operating systems, touch screens, and / or display screens, such as an in-vehicle device, a mobile phone, a tablet computer, a personal digital assistant, a wearable device, etc.

[0078] Among them, a system on a chip (SoC) refers to a technology of integrating a complete system on a single chip and grouping all or part of the necessary electronic circuits. This "system" usually includes a central processing unit (CPU), a memory, and peripheral circuits, etc. Among them, the system on a chip is mainly applied to an SOC chip.

[0079] In addition, the memory management device can also be software in an electronic device, etc. Among them, the software is, for example, a memory management system, etc. Among the following embodiments, the memory management system is taken as an example of the execution entity for description.

[0080] As Figure 3 shown, on the basis of the embodiment shown in Figure 1 the method includes the following steps:

[0081] Step 301, obtain a secure access request; the secure access request includes a request identifier, a target physical address, and an access type.

[0082] Step 302, query the memory according to the target physical address to obtain a target secure memory in the memory that includes the target physical address.

[0083] Step 303, obtain a target memory area in the target secure memory that includes the target physical address.

[0084] In the embodiments of the present disclosure, the target secure memory may or may not include a physical memory area. It should be noted that, in the case where there is a physical memory area in the target secure memory, it means that perhaps all the physical addresses in the target secure memory are not allocated to the same requester. For example, all the physical addresses in the target secure memory are allocated to multiple requesters. In this case, the physical memory areas in the target secure memory may all be secure memory areas. Another example is that some of the physical addresses in the target secure memory are allocated to one or more requesters, and some physical addresses are not configured. In this case, among the physical memory areas in the target secure memory, perhaps some physical memory areas are secure memory areas and some physical memory areas are not secure memory areas. Therefore, the memory management system needs to make a further judgment. It can first obtain a target memory area that includes the target physical address, and then further determine whether the target memory area is a secure area.

[0085] Step 304, obtain secure indication information corresponding to the target secure memory; the secure indication information is set with labels corresponding to each physical memory area in the target secure memory; the label indicates whether the physical memory area is secure.

[0086] In the embodiments of the present disclosure, the manifestation form of the secure indication information may be, for example, a table, multiple key-value pairs, an array, etc. Taking the table as an example, multiple labels may be sequentially set in the table; the multiple labels correspond one-to-one to multiple physical memory areas in the target secure memory. Taking multiple key-value pairs as an example, the multiple key-value pairs correspond one-to-one to multiple physical memory areas in the target secure memory. The key in the key-value pair may be the start position, end position, etc. of the corresponding physical memory area. Taking the array as an example, multiple labels may be sequentially set in the array; the multiple labels correspond one-to-one to multiple physical memory areas in the target secure memory.

[0087] Among them, the label indicates whether the corresponding physical memory area is secure; when the label corresponding to the target memory area indicates secure, determine that the target memory area is a secure area; when the label corresponding to the target memory area indicates non-secure, determine that the target memory area is a non-secure area.

[0088] Among them, the number of bits of each tag can be, for example, one bit. Correspondingly, the value of the tag can be 0 or 1. When the value of the tag is 0, it indicates that the corresponding physical memory area is not secure, that is, the corresponding physical memory area is not allocated to any requesting party; when the value of the tag is 1, it indicates that the corresponding physical memory area is secure, that is, the corresponding physical memory area has been allocated to a certain requesting party.

[0089] Among them, it should be noted that for the convenience of management, the sizes of multiple physical memory areas in the memory of the memory can be the same, such as all being 2^n MB, etc.

[0090] Step 305, when the tag corresponding to the target memory area indicates security, determine the target memory area as the target secure memory area.

[0091] Among them, when it is determined that the target memory area is the target secure memory area, it means that there is a target secure memory area in the physical memory area representing the target secure memory.

[0092] Step 306, when the tag corresponding to the target memory area indicates non-security, determine that the target memory area is not the target secure memory area.

[0093] Among them, when it is determined that the target memory area is not the target secure memory area, it means that there is no target secure memory area in the physical memory area representing the target secure memory.

[0094] Step 307, when there is a target secure memory area including the target physical address in the physical memory area of the target secure memory, perform authentication processing on the access request according to the request identifier, access type, and target secure memory area.

[0095] Step 308, in response to successful authentication, perform access processing on the content at the target physical address in the target secure memory area.

[0096] Step 309, when there is no physical memory area in the target secure memory, perform authentication processing on the access request according to the request identifier, access type, and target secure memory.

[0097] In the embodiments of the present disclosure, the target secure memory may include a physical memory area or may not include a physical memory area. Among them, it should be noted that when there is no physical memory area in the target secure memory, it means that all physical addresses in the target secure memory are secure physical addresses allocated to the same requesting party, and it is not necessary to determine whether the target physical address in the target secure memory is a secure physical address. Therefore, the authentication processing of the access request can be directly performed according to the request identifier, access type, and target secure memory.

[0098] Step 310, in response to successful authentication, perform access processing on the content at the target physical address in the target secure memory.

[0099] In the embodiments of the present disclosure, the memory management system may further perform the following process: determine a secure access failure when at least one of the following situations exists: the target secure memory is not included in the memory; the target secure memory area does not exist in the physical memory area of the target secure memory; the authentication fails.

[0100] It should be noted that among the secure memories set in the memory, there may be multiple first secure memories for storing content, and one second secure memory for storing abnormal content. Among them, when the target secure memory including the target physical address does not exist in the memory, the memory management system may access the specified physical address in the second secure memory to obtain the secure access failure content; and provide the secure access failure content to the requesting end to indicate a secure access failure to the requesting end.

[0101] For example, the memory may include m secure memories, which are gate0 to gate m - 1 respectively. Among them, gate0 may be the second secure memory; gate1 to gate m - 1 may be the first secure memories.

[0102] It should be noted that for the detailed description of steps 301 to 302, reference may be made to Figure 2 Steps 201 to 202 in the illustrated embodiments, and details will not be described herein again.

[0103] In the memory management method according to the embodiments of the present disclosure, a secure access request is obtained; the secure access request includes a request identifier, a target physical address, and an access type; the memory is queried according to the target physical address to obtain a target secure memory including the target physical address in the memory; a target memory area including the target physical address in the target secure memory is obtained; secure indication information corresponding to the target secure memory is obtained; tags corresponding to each physical memory area in the target secure memory are set in the secure indication information; the tag indicates whether the physical memory area is secure; when the tag corresponding to the target memory area indicates security, it is determined that the target memory area is the target secure memory area; when the tag corresponding to the target memory area indicates non-security, it is determined that the target memory area is not the target secure memory area; when there is a target secure memory area including the target physical address in the physical memory area of the target secure memory, the access request is authenticated according to the request identifier, the access type, and the target secure memory area; in response to successful authentication, access processing is performed on the content at the target physical address in the target secure memory area; when there is no physical memory area in the target secure memory, the access request is authenticated according to the request identifier, the access type, and the target secure memory; in response to successful authentication, access processing is performed on the content at the target physical address in the target secure memory; wherein, for a secure memory request initiated by a request end, the memory allocates multiple physical memory areas with discontinuous physical addresses and continuous virtual addresses, so that when a secure access request is received, the target secure memory area including the target physical address can be obtained in units of physical memory areas, and then access processing is performed on the content at the target physical address in the target secure memory area, thereby being able to quickly find the content at the target physical address and improve the access speed.

[0104] Figure 4 is a block diagram schematic diagram of memory management. In Figure 4 there are a DPU driver (request end), a VPU driver (request end), and an XXX driver (request end). Among them, each request end is provided with a corresponding SMMU. The DPU driver is provided with a DPU SMMU; the VPU driver is provided with a VPU SMMU; the XXX driver is provided with an XXX SMMU.

[0105] Among them, the request end communicates with the secure gate through a BUS (bus) and sends an access request carrying an NS (access label), an MID (request identifier), and a Write / Read (access type) to the secure gate.

[0106] Among them, a plurality of secure memories are set in the DDR (memory), for example, gate0 to gate m-1. Among them, physical memory areas are set in gate1 to gate m-2; no physical memory areas are set in gate0 and gate m-1. That is to say, gate0 to gate m-1 support the subgate mechanism. Taking gate1 as an example, in Figure 4 Among them, the multiple rectangular areas in gate1 represent multiple physical memory areas; the physical memory area marked with 1 is a secure area; the physical memory area marked with 0 is a non-secure area.

[0107] Among them, for the convenience of access, the start address and end address of each gate in the memory can be multiples of 2^n KB respectively. Among them, the size of each physical memory area in gate1 is 2^n) MB. Correspondingly, for the kth physical memory area in gate1, the physical address range of this physical memory area can be the start address of gate1 + (2^n) MB to the start address of gate1 + (k + 1) * (2^n) MB.

[0108] Figure 5 It is a schematic structural diagram of a memory management device according to an embodiment of the present disclosure.

[0109] As Figure 5 shown, the memory management device may include: a receiving module 501, a first obtaining module 502, a conversion processing module 503, and a providing module 504.

[0110] Among them, the receiving module 501 is used to receive a memory application request; the memory application request includes a request identifier and a memory size; the first obtaining module 502 is used to obtain a plurality of non-continuous physical memory areas with a specific size from the memory according to the memory size; the conversion processing module 503 is used to perform continuous virtual address conversion processing on the physical addresses of the plurality of non-continuous physical memory areas to obtain continuous virtual addresses; the providing module 504 is used to provide the continuous virtual addresses as a response to the memory application request to the request end corresponding to the request identifier.

[0111] In an embodiment of the present disclosure, the device further includes: a second obtaining module, a first determining module, and a permission configuration module; the second obtaining module is used to obtain the continuous virtual address of the request end corresponding to the request identifier when receiving a memory protection request carrying the request identifier; the first determining module is used to determine a plurality of non-continuous physical memory areas allocated to the request end according to the continuous virtual address; the permission configuration module is used to perform access permission configuration processing on the plurality of non-continuous physical memory areas to obtain access permission configurations of the plurality of physical memory areas.

[0112] In one embodiment of the present disclosure, the device further includes: a third acquisition module, a fourth acquisition module, an authentication processing module, and an access processing module; the third acquisition module is configured to acquire a secure access request; the secure access request includes the request identifier, the target physical address, and the access type; the fourth acquisition module is configured to query a memory according to the target physical address to acquire a target secure memory including the target physical address in the memory; the authentication processing module is configured to, in the case that there is a target secure memory area including the target physical address in the physical memory area of the target secure memory, perform authentication processing on the access request according to the request identifier, the access type, and the target secure memory area; the access processing module is configured to, in response to successful authentication, perform access processing on the content at the target physical address in the target secure memory area.

[0113] In one embodiment of the present disclosure, the device further includes: a fifth acquisition module, a sixth acquisition module, and a second determination module; the fifth acquisition module is configured to acquire a target memory area including the target physical address in the target secure memory; the sixth acquisition module is configured to acquire security indication information corresponding to the target secure memory; tags corresponding to each physical memory area in the target secure memory are set in the security indication information; the tag indicates whether the physical memory area is secure; the second determination module is configured to, in the case that the tag corresponding to the target memory area indicates security, determine the target memory area as the target secure memory area.

[0114] In one embodiment of the present disclosure, the device further includes: a seventh acquisition module, an eighth acquisition module, and a third determination module; the seventh acquisition module is configured to acquire a target memory area including the target physical address in the target secure memory; the eighth acquisition module is configured to acquire security indication information corresponding to the target secure memory; tags corresponding to each physical memory area in the target secure memory are set in the security indication information; the tag indicates whether the physical memory area is secure; the third determination module is configured to, in the case that the tag corresponding to the target memory area indicates non-security, determine that the target memory area is not the target secure memory area.

[0115] In one embodiment of the present disclosure, the authentication processing module is further configured to, in the case that there is no physical memory area in the target secure memory, perform authentication processing on the access request according to the request identifier, the access type, and the target secure memory; the access processing module is further configured to, in response to successful authentication, perform access processing on the content at the target physical address in the target secure memory.

[0116] In one embodiment of the present disclosure, the apparatus further includes: a fourth determination module, configured to determine that a secure access fails when at least one of the following conditions exists: the target secure memory is not included in the memory; the target secure memory area does not exist in the physical memory area of the target secure memory; the authentication fails.

[0117] In one embodiment of the present disclosure, the authentication processing module is specifically configured to obtain the access permission configuration of the target secure memory area; query the access permission configuration according to the request identifier and the access type, and determine whether the access type is included in the allowed access types corresponding to the request identifier in the access permission configuration; when the access type is included in the allowed access types corresponding to the request identifier, determine that the access request authentication passes.

[0118] In one embodiment of the present disclosure, the authentication processing module is further specifically configured to obtain the access permission configuration of the target secure memory area; query the access permission configuration according to the request identifier and the access type, and determine whether the access type is included in the allowed access types corresponding to the request identifier in the access permission configuration; when the access type is not included in the allowed access types corresponding to the request identifier, determine that the access request authentication fails.

[0119] In one embodiment of the present disclosure, the permission configuration module is specifically configured to, for each physical memory area among a plurality of non - contiguous physical memory areas, and for each requestor, obtain the label corresponding to the physical memory area, the access permission corresponding to the requestor, and the request identifier of the requestor; determine the access permission of the physical memory area to the requestor according to the access permission corresponding to the requestor, the request identifier of the requestor, and the label corresponding to the physical memory area; generate the access permission configuration corresponding to the physical memory area according to the access permissions of the physical memory area to each requestor.

[0120] In one embodiment of the present disclosure, the third obtaining module is specifically configured to obtain an access request, where the access request includes an access label, the request identifier, the target physical address, and the access type; when the access label indicates a secure access, determine that the access request is the secure access request.

[0121] In the memory management device according to the embodiments of the present disclosure, a memory application request is received; the memory application request includes a request identifier and a memory size; according to the memory size, a plurality of non - contiguous physical memory regions with a specific size are obtained from the memory; the physical addresses of the plurality of non - contiguous physical memory regions are subjected to continuous virtual address conversion processing to obtain continuous virtual addresses; the continuous virtual addresses are provided as a response to the memory application request to the request side corresponding to the request identifier, wherein the memory allocates a plurality of physical memory regions with discontinuous physical addresses and continuous virtual addresses for the secure memory requests initiated by the request side, so as to reduce the allocation duration when allocating memory for subsequent other request sides in the case of serious memory fragmentation in the memory, and avoid the problem of allocation failure when allocating memory for subsequent other request sides.

[0122] According to the third aspect of the embodiments of the present disclosure, there is also provided a system - on - chip, including: a processor; the processor is connected to the drivers of a plurality of request sides; a memory management unit SMMU hardware is provided in the driver for converting the physical addresses of a plurality of non - contiguous physical memory regions into continuous virtual addresses; a memory connected to the processor through a bus and a security gate; the memory includes a memory provided with a plurality of physical memory regions; wherein, the processor is configured to implement the steps of the memory management method as described above.

[0123] According to the fourth aspect of the embodiments of the present disclosure, there is also provided an electronic device, including: a processor; a memory for storing processor - executable instructions, wherein the processor is configured to: implement the memory management method as described above.

[0124] To implement the above - mentioned embodiments, the present disclosure also proposes a non - transitory computer - readable storage medium.

[0125] Wherein, when the instructions in the storage medium are executed by the processor, the processor is enabled to execute the memory management method as described above.

[0126] To implement the above - mentioned embodiments, the present disclosure also provides a computer program product.

[0127] Wherein, when the computer program product is executed by the processor of the electronic device, the electronic device is enabled to execute the method as described above.

[0128] Figure 6 It is a structural block diagram of an electronic device shown according to an exemplary embodiment. Figure 6 The electronic device shown is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present disclosure.

[0129] Such as Figure 6As shown, the electronic device 1000 includes a processor 111, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 112 or a program loaded from a memory 116 into a random access memory (RAM) 113. In the RAM 113, various programs and data required for the operation of the electronic device 1000 are also stored. The processor 111, the ROM 112, and the RAM 113 are connected to each other via a bus 114. An input / output (I / O) interface 115 is also connected to the bus 114.

[0130] The following components are connected to the I / O interface 115: a memory 116 including a hard disk, etc.; and a communication part 117 including a network interface card such as a local area network (LAN) card, a modem, etc., and the communication part 117 performs communication processing via a network such as the Internet; a drive 118 is also connected to the I / O interface 115 as needed.

[0131] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 117. When the computer program is executed by the processor 111, the above functions defined in the method of the present disclosure are performed.

[0132] In an exemplary embodiment, a storage medium including instructions is also provided, such as a memory including instructions, and the above instructions can be executed by the processor 111 of the electronic device 1000 to complete the above method. Optionally, the storage medium can be a non-transitory computer-readable storage medium. For example, the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.

[0133] In the present disclosure, a computer-readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution system, apparatus, or device. And in the present disclosure, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination of the foregoing.

[0134] In addition, the word "exemplary" is used herein to mean serving as an example, instance, or illustration. Any aspect or design described herein as "exemplary" is not necessarily to be understood as being advantageous compared to other aspects or designs. Instead, the use of the word exemplary is intended to present concepts in a concrete manner. As used herein, the term "or" is intended to mean an inclusive "or" rather than an exclusive "or". That is, unless otherwise specified or clear from the context, "X applies A or B" is intended to mean any arrangement in a natural inclusive arrangement. That is, if X applies A; X applies B; or X applies both A and B, then "X applies A or B" is satisfied in any of the foregoing instances. Additionally, unless otherwise specified or clear from the context indicating a singular form, the articles "a" and "an" as used in this application and the appended claims are generally understood to mean "one or more".

[0135] Similarly, although the present disclosure has been shown and described with respect to one or more implementations, equivalent variations and modifications will occur to those skilled in the art upon reading and understanding this specification and the drawings. The present disclosure includes all such modifications and variations and is limited only by the scope of the claims. Specifically with respect to the various functions performed by the components described above (e.g., elements, resources, etc.), unless otherwise indicated, the terms used to describe such components are intended to correspond to any component (functionally equivalent) that performs the specific function of the described component, even if not structurally equivalent to the disclosed structure. Additionally, although a particular feature of the present disclosure may have been disclosed with respect to only one of several implementations, such a feature may, as may be desired and advantageous for any given or particular application, be combined with one or more other features of other implementations. Further, with respect to the use of "comprising," "having," "including," "containing," or variants thereof in the detailed description or claims, such terms are intended to be inclusive in a manner similar to the term "including."

[0136] Other embodiments of the present disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include known or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the present disclosure are pointed out by the following claims.

[0137] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes may be made without departing from its scope. The scope of the present disclosure is limited only by the appended claims.

Claims

1. A memory management method, characterized in that, the method includes: Receiving a memory application request; the memory application request includes a request identifier and a memory size; According to the memory size, obtaining a plurality of discontinuous physical memory regions with a specific size from the memory; Performing continuous virtual address conversion processing on the physical addresses of the plurality of discontinuous physical memory regions to obtain continuous virtual addresses; Providing the continuous virtual addresses as a response to the memory application request to the request end corresponding to the request identifier.

2. The method according to claim 1, characterized in that, the method further includes: When receiving a memory protection request carrying the request identifier, obtaining the continuous virtual address of the request end corresponding to the request identifier; Determining a plurality of discontinuous physical memory regions allocated to the request end according to the continuous virtual address; Performing access permission configuration processing on the plurality of discontinuous physical memory regions to obtain access permission configurations of the plurality of physical memory regions.

3. The method according to claim 1 or 2, characterized in that, the method further includes: Obtaining a security access request; the security access request includes the request identifier, a target physical address, and an access type; Querying the memory according to the target physical address to obtain a target secure memory in the memory that includes the target physical address; When there is a target secure memory region including the target physical address in the physical memory region of the target secure memory, performing authentication processing on the access request according to the request identifier, the access type, and the target secure memory region; In response to successful authentication, performing access processing on the content at the target physical address in the target secure memory region.

4. The method according to claim 3, characterized in that, the method includes: Obtaining a target memory region in the target secure memory that includes the target physical address; Obtaining security indication information corresponding to the target secure memory; tags corresponding to each physical memory region in the target secure memory are set in the security indication information; the tag indicates whether the physical memory region is secure; When the tag corresponding to the target memory region indicates security, determining the target memory region as the target secure memory region.

5. The method according to claim 3, characterized in that, the method further includes: Obtaining a target memory region in the target secure memory that includes the target physical address; Obtaining security indication information corresponding to the target secure memory; tags corresponding to each physical memory region in the target secure memory are set in the security indication information; the tag indicates whether the physical memory region is secure; When the tag corresponding to the target memory region indicates non - security, determining that the target memory region is not the target secure memory region.

6. The method according to claim 3, characterized in that, the method further includes: In the case where there is no physical memory area in the target secure memory, authenticate the access request according to the request identifier, the access type, and the target secure memory; In response to successful authentication, perform an access process on the content at the target physical address in the target secure memory.

7. The method according to claim 3, wherein, the method further includes: when at least one of the following situations exists, determine that the secure access fails: the memory does not include the target secure memory; the target secure memory area does not exist in the physical memory area of the target secure memory; the authentication fails.

8. The method according to claim 3, wherein, the authenticating the access request according to the request identifier, the access type, and the target secure memory area includes: obtain the access permission configuration of the target secure memory area; query the access permission configuration according to the request identifier and the access type, and determine whether the access type is included in the allowed access types corresponding to the request identifier in the access permission configuration; when the access type is included in the allowed access types corresponding to the request identifier, determine that the access request is authenticated successfully.

9. The method according to claim 3, wherein, the authenticating the access request according to the request identifier, the access type, and the target secure memory area further includes: obtain the access permission configuration of the target secure memory area; query the access permission configuration according to the request identifier and the access type, and determine whether the access type is included in the allowed access types corresponding to the request identifier in the access permission configuration; when the access type is not included in the allowed access types corresponding to the request identifier, determine that the access request is not authenticated successfully.

10. The method according to claim 2, wherein, the performing an access permission configuration process on multiple non - contiguous physical memory areas to obtain access permission configurations of the multiple physical memory areas includes: for each physical memory area among the multiple non - contiguous physical memory areas, and for each requestor, obtain the label corresponding to the physical memory area, the access permission corresponding to the requestor, and the request identifier of the requestor; determine the access permission of the physical memory area for the requestor according to the access permission corresponding to the requestor, the request identifier of the requestor, and the label corresponding to the physical memory area; generate the access permission configuration corresponding to the physical memory area according to the access permissions of the physical memory area for each requestor.

11. The method according to claim 3, wherein, the obtaining a secure access request includes: obtain an access request, where the access request includes an access label, the request identifier, the target physical address, and the access type; when the access label indicates a secure access, determine that the access request is the secure access request.

12. A memory management device, wherein, the device includes: A receiving module, configured to receive a memory application request; the memory application request includes a request identifier and a memory size; A first obtaining module, configured to obtain, according to the memory size, a plurality of non - contiguous physical memory regions with a specific size from a memory; A conversion processing module, configured to perform a continuous virtual address conversion process on the physical addresses of the plurality of non - contiguous physical memory regions to obtain continuous virtual addresses; A providing module, configured to provide the continuous virtual addresses as a response to the memory application request to a request end corresponding to the request identifier.

13. A system - on - chip, characterized in that, it includes: a processor; The processor is connected to drivers of a plurality of request ends; a memory management unit SMMU hardware is provided in the drivers, configured to convert the physical addresses of a plurality of non - contiguous physical memory regions into continuous virtual addresses; A memory connected to the processor through a bus and a security gate; the memory includes a memory provided with a plurality of physical memory regions; Wherein, the processor is configured to implement the steps of the memory management method according to any one of claims 1 to 11.

14. An electronic device, characterized in that, it includes: a processor; a memory for storing executable instructions of the processor; Wherein, the processor is configured to: implement the steps of the memory management method according to any one of claims 1 to 11.

15. A non - transitory computer - readable storage medium, when instructions in the storage medium are executed by a processor, enabling the processor to execute the memory management method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Address conversion method and device of application shared memory

    CN103077120A

  • Storage space management method, data processing chip, equipment and storage medium

    CN114490433A

  • Memory access system and method and medium

    CN115827502A

  • Address mapping acquisition method and device, electronic equipment and readable storage medium

    CN116340200A

Cited By

  • Memory allocation method and system, medium and product

    CN121807578A

  • A memory allocation method, system, medium and product

    CN121807578B