Data access method, SoC and equipment

By dividing multiple storage areas in the SoC and setting access conditions, the problem of how to protect the system firmware in flash memory from being attacked by malicious programs is solved, and effective security management of the system firmware is achieved to ensure the normal startup of the operating system.

CN120068061APending Publication Date: 2025-05-30HUAWEI TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202311623719.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-28
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

How to protect the system firmware stored in flash memory from being attacked by malicious programs and ensure that the operating system can start normally.

Method used

By dividing multiple storage areas in the SoC and setting different access conditions for each storage area, restricting visitors and access timing, ensuring that only authorized processing cores can access the area of ​​the storage system firmware at a specific time.

Benefits of technology

Effectively prevent malicious program attacks, ensure the security of the system firmware stored in flash memory, and avoid the risk that the operating system cannot start normally.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068061A_ABST
    Figure CN120068061A_ABST
Patent Text Reader

Abstract

The invention provides a data access method, SoC and equipment, the method is applied to the SoC, the SoC comprises a flash memory controller and a plurality of processing cores, a flash memory controlled by the flash memory controller comprises a plurality of storage areas, the method comprises the following steps: the flash memory controller receives an access request from a target processing core and obtains access information corresponding to the access request, the access information comprises at least one of indication information of the target processing core and the access opportunity, determining a target storage area where an access address corresponding to the access request is located in the flash memory, obtaining a target access condition corresponding to the target storage area, and executing the access request under the condition that the access information meets the target access condition. By adopting the method and the device, the system firmware stored in the flash memory can be effectively protected from being attacked by malicious programs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of flash storage technology, and particularly to a method for data access, a SoC, and a device. Background Art

[0002] System firmware is usually stored in flash memory. System firmware is the program that is first executed after the device is powered on and is loaded and run prior to the Operating System (OS). If the system firmware is attacked by a malicious program, problems such as the inability of the operating system to start properly may occur. Since the system firmware plays a crucial role in the device, how to protect the system firmware stored in the flash memory from being attacked by malicious programs has become an urgent problem to be solved currently. Summary of the Invention

[0003] This disclosure provides a method for data access, a SoC, and a device, which can protect the firmware stored in the flash memory from being attacked by malicious programs. The corresponding technical solutions are as follows:

[0004] In a first aspect, a method for data access is provided. The method is applied to a SoC. The SoC includes a flash memory controller and multiple processing cores. The flash memory controlled by the flash memory controller includes multiple storage areas. The method includes:

[0005] The flash memory controller receives an access request from a target processing core, obtains access information corresponding to the access request, where the access information includes at least one of indication information of the target processing core and an access timing. The flash memory controller determines a target storage area in the flash memory where the access address corresponding to the access request is located, obtains a target access condition corresponding to the target storage area, and executes the access request when the access information meets the target access condition.

[0006] In the technical solution provided by this disclosure, the flash memory is divided into multiple storage areas, and different storage areas may correspond to different access conditions. By restricting at least one of the accessor and the access timing through the access conditions, differential security management of different storage areas is realized. For the storage area storing the system firmware, the processing cores that can access this storage area can be restricted by restricting the access conditions, so that malicious programs cannot access this storage area, thereby protecting the firmware stored in the flash memory from being attacked by malicious programs.

[0007] In a possible implementation, the SoC further includes an address permission register, which is used to store the address ranges of each storage area in multiple storage domains. Correspondingly, the processing for the flash memory controller to determine the target storage area in the flash memory where the access address corresponding to the access request is located can be as follows:

[0008] The flash memory controller reads the address range of each storage area in the address permission register. Based on the address range of each storage area, it determines the target storage area in the flash memory where the access address corresponding to the access request is located.

[0009] In a possible implementation, the address permission register is further used to store the access conditions corresponding to each storage area in multiple storage domains. Correspondingly, the process of the flash memory controller obtaining the target access condition corresponding to the target storage area can be as follows:

[0010] The flash memory controller reads the target access condition corresponding to the target storage area in the address permission register.

[0011] In a possible implementation, the SoC further includes a multi-port arbiter, and the multi-port arbiter is respectively connected to the flash memory controller and multiple processing cores;

[0012] Before the flash memory controller receives an access request from the target processing core, the method further includes:

[0013] The multi-port arbiter receives the access request sent by the target processing core, determines the indication information of the target processing core according to the port that receives the access request. Then, the multi-port arbiter sends the access request and the indication information of the target processing core to the flash memory controller.

[0014] In the technical solution provided by the present disclosure, the multi-port arbiter allocates indication information to the target processing core that sends the access request according to the connection port with the target processing core, and the indication information is used to indicate the target processing core that sends the access request. The allocation method of the indication information is simple and direct, and the efficiency is higher.

[0015] In a possible implementation, the multiple storage areas include a first storage area, and the first access condition corresponding to the first storage area includes: the processing core indicated by the indication information in the access information is the security subsystem.

[0016] In the technical solution provided by the present disclosure, the first storage area can be the one with the highest security level among the multiple storage areas, and this storage area is only accessible to the security subsystem. In this way, the security subsystem firmware can be stored in the first storage area.

[0017] In a possible implementation, the multiple storage areas include a second storage area, and the second access condition corresponding to the second storage area includes: the access timing in the access information is before entering the operating system OS.

[0018] In the technical solution provided by the present disclosure, the access condition of the second storage area is that access is only allowed before entering the OS, while malicious programs can only attack the system firmware during the operation of the OS. In this way, the data stored in the second storage area is also relatively secure and can be protected from being attacked by malicious programs. The BIOS can be stored in the second storage area.

[0019] In a possible implementation, the multiple storage areas include a third storage area, and the third access condition corresponding to the third storage area. The third access condition includes: the processing core indicated by the indication information in the access information is any one of the secure subsystem, the management subsystem, and the application processor in the secure state.

[0020] In the technical solution provided by the present disclosure, the access condition of the third storage area is that only processing cores with a high security level are allowed to access, such as the secure subsystem, the management subsystem, and the application processor in the secure state. While malicious programs can only attack the system firmware through the application processor in the non-secure state. In this way, the data stored in the third storage area is also relatively secure and can be protected from being attacked by malicious programs. The management subsystem firmware can be stored in the third storage area.

[0021] In a possible implementation, the multiple storage areas include a fourth storage area, and the fourth access condition corresponding to the fourth storage area. The fourth access condition includes: the processing core indicated by the indication information in the access information is any one of the multiple processing cores.

[0022] In the technical solution provided by the present disclosure, the security level of the third storage area can be relatively low and can be used to store the configuration data of the system firmware. These configuration data can be information that will not affect the system operation even if attacked.

[0023] In a possible implementation, the access request further carries operation type indication information. Before the flash memory controller obtains the access information corresponding to the access request, the method further includes:

[0024] The flash memory controller determines that the operation type indicated by the operation type indication information is a read operation or a write operation.

[0025] In the technical solution provided by the present disclosure, only the access requests corresponding to the read operation and the write operation can be restricted.

[0026] In a possible implementation, the method further includes:

[0027] In the case where it is determined that the operation type indicated by the operation type indication information is not a read operation or a write operation, the flash memory controller executes the access request.

[0028] In the technical solution provided by the present disclosure, for access requests corresponding to operations other than read operations and write operations, access condition judgment may not be performed, and the access request can be directly executed. For example, operations such as querying the flash memory model, setting the flash memory operation mode, and flash memory quality inspection do not read or write the system firmware in the flash memory, that is, they do not affect the security of the system firmware.

[0029] In a second aspect, a SoC is provided. The SoC includes a flash memory controller and multiple processing cores. The flash memory controlled by the flash memory controller includes multiple storage areas. The flash memory controller is configured to:

[0030] Receive an access request from a target processing core;

[0031] Obtain access information corresponding to the access request, where the access information includes at least one of indication information of the target processing core and access timing;

[0032] Determine a target storage area in the flash memory where the access address corresponding to the access request is located;

[0033] Obtain a target access condition corresponding to the target storage area;

[0034] Execute the access request when the access information meets the target access condition.

[0035] In a possible implementation, the SoC further includes an address permission register, and the address permission register is used to store the address range of each storage area in the multiple storage domains;

[0036] The flash memory controller is configured to read the address range of each storage area in the address permission register, and determine the target storage area in the flash memory where the access address corresponding to the access request is located according to the address range of each storage area.

[0037] In a possible implementation, the address permission register is further used to store the access condition corresponding to each storage area in the multiple storage domains;

[0038] The flash memory controller is configured to read the target access condition corresponding to the target storage area in the address permission register.

[0039] In a possible implementation, the SoC further includes a multi-port arbiter, and the multi-port arbiter is respectively connected to the flash memory controller and the multiple processing cores;

[0040] The multi-port arbiter is configured to receive an access request sent by the target processing core; determine indication information of the target processing core according to the port that receives the access request; and send the access request and the indication information of the target processing core to the flash memory controller.

[0041] In a possible implementation, the multiple storage areas include a first storage area, and a first access condition corresponding to the first storage area, where the first access condition includes: the processing core indicated by the indication information in the access information is a security subsystem.

[0042] In a possible implementation, the multiple storage areas include a second storage area, and a second access condition corresponding to the second storage area, where the second access condition includes: the access timing in the access information is before entering the operating system OS.

[0043] In a possible implementation, the multiple storage areas include a third storage area, and a third access condition corresponding to the third storage area, where the third access condition includes: the processing core indicated by the indication information in the access information is any one of a security subsystem, a management subsystem, and an application processor in a secure state.

[0044] In a possible implementation, the multiple storage areas include a fourth storage area, and a fourth access condition corresponding to the fourth storage area, where the fourth access condition includes: the processing core indicated by the indication information in the access information is any one of the multiple processing cores.

[0045] In a possible implementation, operation type indication information is further carried in the access request. Before the flash memory controller obtains access information corresponding to the access request, it is further configured to:

[0046] Determine that the operation type indicated by the operation type indication information is a read operation or a write operation.

[0047] In a possible implementation, the flash memory controller is further configured to:

[0048] Execute the access request when it is determined that the operation type indicated by the operation type indication information is not a read operation or a write operation.

[0049] In a third aspect, an electronic device is provided, where the electronic device includes the SoC and the flash memory as described in the second aspect above. Description of the Drawings

[0050] Figure 1 is a schematic structural diagram of an SoC provided by an embodiment of the present disclosure;

[0051] Figure 2It is a schematic flowchart of a data access method provided by an embodiment of the present disclosure;

[0052] Figure 3 It is a schematic structural diagram of a SoC provided by an embodiment of the present disclosure;

[0053] Figure 4 It is a schematic structural diagram of a SoC provided by an embodiment of the present disclosure;

[0054] Figure 5 It is a schematic structural diagram of a chip system provided by an embodiment of the present disclosure. Detailed implementation manners

[0055] To make the objectives, technical solutions and advantages of the present disclosure clearer, the following will further describe the embodiments of the present disclosure in detail with reference to the accompanying drawings.

[0056] An embodiment of the present disclosure provides a data access method, which can be applied to a System on Chip (SoC). The SoC can be a chip in electronic devices such as base stations, routers, servers, desktop computers, laptop computers, etc. Refer to Figure 1 A schematic structural diagram of a SoC is shown. The SoC includes multiple processing cores, such as a Security module, a Management module, and an Application CPU. Among them, the Security module is used to handle system security-related affairs, the Management module is used to manage the system state, and the Application CPU is used to run an Operating System (OS) and application programs. The Application CPU is also called a service core. When running, the Application CPU can be in a secure state and a non-secure state.

[0057] In the SoC, there is also a Flash Controller, which is connected to a flash memory. System firmware, such as Security module firmware (smfirmware), Management module firmware (mm firmware), and Basic Input Output System (BIOS), is stored in the flash memory. Among them, the Security module firmware is run by the Security module to provide system security functions, the Management module firmware is run by the Management module to provide system management functions, and the BIOS is run by the Application CPU to initialize the system and start the OS.

[0058] In addition, in the SoC, a memory controller (DDR Controller) and a hard disk controller (SATA Controller) may also be included. Among them, the DDR Controller is connected to the DDR, and the SATA Controller is connected to a Serial Advanced Technology Attachment hard disk (which can also be simply referred to as a SATA hard disk). The DDR is used to provide system memory, and the SATA hard disk is used to store the operating system, etc.

[0059] Since system firmware with different system permissions is stored in the flash memory, during the OS running stage, if the OS is attacked or has security vulnerabilities, malicious programs may access the flash memory and tamper with the system firmware stored in the flash memory, resulting in the OS being unable to run properly or having serious security vulnerabilities.

[0060] Embodiments of the present disclosure provide a data access method implemented by the SoC. In this method, the flash memory is divided into multiple storage areas, and different storage areas may correspond to different access conditions. By restricting at least one of the visitor and the access timing through the access conditions, differential security management of different storage areas is achieved. The following describes this method with reference to the accompanying drawings. See Figure 2 , the method may include the following steps:

[0061] Step 201, the flash memory controller receives an access request from a target processing core.

[0062] Among them, the target processing core is any processing core in the SoC, such as any one of the security subsystem, the management subsystem, and the application processor.

[0063] Step 202, the flash memory controller determines whether the operation type indication information carried in the access request is in the command control whitelist.

[0064] In implementation, for operations other than read operations or write operations, the system firmware will not be modified or read. Then, the operation type indication information of these operations can be added to the command control whitelist. Exemplarily, for operations such as querying the flash memory model, setting the flash memory operation mode, and flash memory quality inspection, the operation type indication information corresponding to these operations can be added to the command control whitelist.

[0065] After receiving the access request, the flash memory controller can read the operation type indication information in the access request and determine whether the operation type indication information is in the above command control whitelist.

[0066] Step 203: If the operation type indication information carried in the access request is in the command control whitelist, the flash controller executes the access request.

[0067] In implementation, if the flash controller determines that the operation type indication information carried in the access request is in the command control whitelist, it executes the operation indicated by the operation type indication information in the access request.

[0068] Step 204: If the operation type indication information carried in the access request is not in the command control whitelist, it is determined whether the access address corresponding to the access request is within any one of multiple storage areas.

[0069] In implementation, to protect data such as system firmware stored in the flash with different security levels, multiple storage areas can be divided in the flash, and different storage areas correspond to different security levels. The data such as system firmware stored in the flash that needs to be protected is stored in these multiple storage areas according to the required security level. Exemplarily, the flash can be divided into four storage areas, and each storage area can be a continuous storage area or composed of multiple non - continuous sub - storage spaces.

[0070] When the operation type indication information carried in the access request is not in the command control whitelist, the flash controller can obtain the address range of each storage area in the above - mentioned multiple storage areas. Then, it is determined whether the access address corresponding to the access request is within the address range of any storage area.

[0071] The following describes how the flash controller obtains the address range of each storage area in the multiple storage areas.

[0072] See Figure 3 , in the embodiments of the present disclosure, an address permission register can be configured in the SoC, and in this address permission register, the address range of each storage space is stored. For each storage area, if the storage area is a continuous storage area, the address range of the storage area refers to the start address of the storage area and the size of the storage area. If the storage area is composed of multiple non - continuous sub - storage areas, the address range of the storage area refers to the start address of each sub - storage area in the storage area and the size of the sub - storage area.

[0073] In addition, the start address in the address range can be a relative address in the flash, and the relative address in the flash can also be called the offset address in the flash. After obtaining the access address carried in the access request, the access address can be first converted into a relative address in the flash, and then according to the address range of each storage area, it is determined whether the access address is within any storage area.

[0074] Step 205: If the access address corresponding to the access request is not within any of the multiple storage areas, the flash controller executes the access request.

[0075] In implementation, if the flash controller determines that the access address corresponding to the access request is not within any of the multiple storage areas, it executes the operation indicated by the operation type indication information in the access request.

[0076] Step 206: If the access address corresponding to the access request is within the target storage area among the multiple storage areas, the flash controller obtains the access conditions corresponding to the target storage area.

[0077] In implementation, the access conditions corresponding to each storage area are also stored in the above address permission register. The access conditions are used to restrict at least one of the visitor and the access timing. The access conditions are described below through an example.

[0078] Exemplarily, as shown in Table 1 below, the flash memory includes four storage areas, denoted as the security area, the boot area, the critical area, and the general area respectively. The access condition corresponding to the security area is that only the security subsystem can access. The access condition corresponding to the boot area is that it can only be accessed before entering the OS. The access condition corresponding to the critical area is that only the security subsystem, the management subsystem, and the application processor in the secure state can access. The access condition corresponding to the general area is that all processing cores in the SoC can access. Here, all processing cores include the security subsystem, the management subsystem, the application processor in the secure state, and the application processor in the non-secure state.

[0079] Table 1

[0080]

[0081] When it is determined that the access address corresponding to the access request is within the target storage area, the flash controller reads the access conditions corresponding to the target storage area from the address permission register.

[0082] Step 207: The flash controller determines whether the access information of the access request meets the access conditions corresponding to the target storage area.

[0083] In implementation, the flash controller can obtain the access information of the access request. The access information includes the indication information of the target processing core and the access timing. The indication information of the target processing core and the access timing are described below respectively.

[0084] Regarding the indication information of the target processing core:

[0085] The indication information of the target processing core is used to indicate the target processing core for sending the access. Exemplarily, the first indication information is used to indicate that the target processing core is the security subsystem, the second indication information is used to indicate that the target processing core is the management subsystem, the third indication information is used to indicate that the target processing core is the application processor in the secure state, and the fourth indication information is used to indicate the application processor in the non-secure state. Since malicious programs run on the application processor in the non-secure state, for the application processor, the application processor in the secure state and the application processor in the non-secure state can be regarded as two different visitors and identified with two different indication information.

[0086] There are various methods to obtain the indication information of the target processor. Two methods are exemplarily listed below for illustration.

[0087] Method 1:

[0088] Carry the indication information of the target processing core in the access request. Correspondingly, after receiving the access request, the flash memory controller can obtain the indication information of the target processing core carried in the access request.

[0089] Method 2:

[0090] See Figure 4, in the embodiments of the present disclosure, the SoC may further include a multi-port arbiter, and the multi-port arbiter is respectively connected to the flash memory controller and multiple processing cores. When the target processing core sends an access request to the flash memory controller, the multi-port arbiter first receives the access request and determines the indication information of the target processing core according to the port from which the access request is received. Specifically, if the access request is received through the first port, the indication information of the target processing core is determined as the first indication information, such as port0, and the first indication information is used to indicate that the target processing core sending the access request is the security subsystem. If the access request is received through the second port, the indication information of the target processing core is determined as the second indication information, such as port1, and the second indication information is used to indicate that the target processing core sending the access request is the management subsystem. If the access request is received through the third port and the first status identifier sent by the application processor is received, and the first status identifier is used to indicate that the operating state of the application processor is the secure state, the indication information of the target processing core is determined as the third indication information, such as port2, and the third indication information is used to indicate that the target processing core sending the access request is the application processor in the secure state. If the access request is received through the third port and the status identifier received is the second status identifier, and the second status identifier is used to indicate that the operating state of the application processor is the non-secure state, the indication information of the target processing core is determined as the fourth indication information, such as port3, and the fourth indication information is used to indicate that the target processing core sending the access request is the application processor in the non-secure state.

[0091] After determining the indication information of the target processing core, the multi-port arbiter sends the access request and the indication information of the target processing core to the flash memory controller. Correspondingly, the flash memory controller can receive the access request and the indication information of the target processing core.

[0092] Regarding the access timing:

[0093] When the flash memory controller receives the access request, it determines whether it is before entering the OS or after entering the OS. Here, before entering the OS and after entering the OS are two access timings. After entering the OS is also during the operation of the OS.

[0094] Taking the storage areas and corresponding access conditions shown in Table 1 above as an example, the access information of the access request is judged to see if it meets the access conditions corresponding to the target storage area.

[0095] If the target storage area is a secure area and the corresponding access condition is that only the security subsystem can access it, the flash memory controller determines whether the indication information of the target processing core is the indication information for indicating the security subsystem. If the indication information of the target processing core is the first indication information for indicating the security subsystem, it is determined that the access information of the access request meets the access condition corresponding to the target storage area. If the indication information of the target processing core is not the indication information for indicating the security subsystem, it is determined that the access information of the access request does not meet the access condition corresponding to the target storage area.

[0096] If the target storage area is a boot area and the corresponding access condition is that it can only be accessed before entering the OS, the flash memory controller determines whether the access timing is before entering the OS. If the access timing is before entering the OS, it is determined that the access information of the access request meets the access condition corresponding to the target storage area. If the access timing is not before entering the OS, it is determined that the access information of the access request does not meet the access condition corresponding to the target storage area.

[0097] If the target storage area is a critical area and the corresponding access condition is that only the security subsystem, the management subsystem, and the application processor in a secure state can access it, the flash memory controller determines whether the indication information of the target processing core is any one of the first indication information for indicating the security subsystem, the second indication information for indicating the management subsystem, and the third indication information for indicating the application processor in a secure state. If the indication information of the target processing core is any one of the first indication information for indicating the security subsystem, the second indication information for indicating the management subsystem, and the third indication information for indicating the application processor in a secure state, it is determined that the access information of the access request meets the access condition corresponding to the target storage area. If the indication information of the target processing core is not any one of the first indication information for indicating the security subsystem, the second indication information for indicating the management subsystem, and the third indication information for indicating the application processor in a secure state, it is determined that the access information of the access request does not meet the access condition corresponding to the target storage area.

[0098] If the target storage area is a normal area and the corresponding access condition is that all processing cores in the SoC can access it, the flash memory controller determines that the access information of the access request meets the access condition corresponding to the target storage area.

[0099] Step 208: If it is determined that the access information of the access request meets the access condition corresponding to the target storage area, the flash memory controller executes the access request.

[0100] In implementation, if the flash memory controller determines that the access information of the access request meets the access condition corresponding to the target storage area, it executes the operation indicated by the operation type indication information in the access request.

[0101] Step 209: If it is determined that the access information of the access request does not meet the access conditions corresponding to the target storage area, the flash memory controller does not execute the access request.

[0102] In a possible implementation, the security subsystem firmware can be stored in the above-mentioned security area, the BIOS can be stored in the startup area (when the BIOS supports reboot update), the management subsystem firmware can be stored in the critical area, and the configuration data of the system firmware can be stored in the normal area. These configuration data can be information that will not affect the system operation even if attacked.

[0103] In another possible implementation, when the BIOS does not support reboot update, the BIOS can be stored in the critical area, and the update and upgrade of the BIOS are implemented by the security subsystem, the management subsystem, or the application processor in a secure state.

[0104] In a possible implementation, for the above-mentioned command control whitelist, a command control list can also be used. The command control list can include read operation indication information and write operation indication information. Correspondingly, step 202 above can be replaced with: The flash memory controller determines whether the operation type indication information carried in the access request is in the command control list.

[0105] The above step 203 can be replaced with: If the operation type indication information carried in the access request is not in the command control list, the flash memory controller executes the access request.

[0106] The above step 204 can be replaced with: If the operation type indication information carried in the access request is in the command control list, it is determined whether the access address corresponding to the access request is in any of the multiple storage areas.

[0107] Next, in combination with the storage areas and corresponding access conditions shown in Table 1 above, the execution of the data access method provided by the embodiments of the present disclosure will be described in the scenarios where a malicious program attempts to tamper with the system firmware stored in the flash memory and in the scenario of normal system firmware upgrade.

[0108] Scenario 1: A malicious program attempts to tamper with the system firmware stored in the flash memory. In this scenario, the data access method provided by the embodiments of the present disclosure can have the following processing flow.

[0109] Step 301: The flash memory controller receives an access request from an application processor in a non-secure state.

[0110] In implementation, malicious programs may hijack the OS to send access requests to the flash memory. The access requests carry write operation indication information and an access address, where the access address is the storage address of the system firmware in the flash memory. The system firmware may be the security subsystem firmware, the management subsystem firmware, the BIOS, etc.

[0111] In this case, the application processor in the non-secure state sends the above access request to the flash memory controller.

[0112] Step 302: The flash memory controller determines whether the write operation indication information carried in the access request is in the command control white list.

[0113] Step 303: The flash memory controller determines that the write operation indication information is not in the command control white list, and determines whether the access address corresponding to the access request is within any of the multiple storage areas.

[0114] Step 304: The flash memory controller determines that the write operation indication information is within the secure area, and obtains the access conditions corresponding to the secure area.

[0115] Step 305: The flash memory controller determines that the access information of the access request does not meet the access conditions corresponding to the secure area, and does not execute the access request.

[0116] In implementation, the access condition corresponding to the secure area is that only the security subsystem can access. The flash memory controller determines that the indication information of the processing core sending the access request is the indication information of the application processor in the non-secure state. Furthermore, it can be determined that the access information of the access request does not meet the access conditions corresponding to the secure area, and the access request is not executed. In this way, the tampering attack of malicious programs on the system firmware can be effectively prevented.

[0117] Scenario 2: Normal system firmware upgrade. In this scenario, the data access method provided by the embodiments of the present disclosure may have the following processing flow.

[0118] Step 401: The flash memory controller receives an access request from the security subsystem.

[0119] In implementation, when the OS needs to update the system firmware, it can call the security subsystem firmware upgrade interface to send the upgrade data to the security subsystem. The security subsystem uses the public key to verify the integrity of the upgrade data. If the verification passes, it sends an access request to the flash memory controller. The access request carries an access address, where the access address is the storage address of the system firmware in the flash memory. The system firmware may be the security subsystem firmware, the management subsystem firmware, the BIOS, etc.

[0120] Step 402: The flash memory controller determines whether the write operation indication information carried in the access request is in the command control white list.

[0121] Step 403: The flash memory controller determines that the write operation instruction information is not in the command control whitelist, and determines whether the access address corresponding to the access request is within any one of multiple storage areas.

[0122] Step 404: The flash memory controller determines that the write operation instruction information is within the secure area, and obtains the access conditions corresponding to the secure area.

[0123] Step 405: The flash memory controller determines that the access information of the access request meets the access conditions corresponding to the secure area, and then executes the access request.

[0124] In implementation, the access condition corresponding to the secure area is that only the secure subsystem can access. The flash memory controller determines that the instruction information of the processing core sending the access request is the instruction information of the secure subsystem. Furthermore, it can be determined that the access information of the access request meets the access conditions corresponding to the secure area, and then the access request is executed. In this way, the normal upgrade of the system firmware can be realized.

[0125] Figure 5 It is a schematic structural diagram of a chip system provided by the present disclosure. As Figure 5 shown, the chip 1800 includes a processor 1801 and an interface circuit 1802. Among them, the interface circuit 1802 is used to receive instructions and transmit them to the processor 1801. The chip 1800 can be the SoC in the above embodiments, and is used to execute the data access method provided by the embodiments of the present disclosure. The processor 1801 is coupled to a memory 1803, and the memory 1803 can include flash memory, memory, hard disk, etc.

[0126] In a possible implementation, there is at least one processor 1801 in the chip system. It should be understood that in the present disclosure, the processor 1801 can be a CPU or other general-purpose processors. The processor 1801 can also be one or more integrated circuits, such as, for example, a digital signal processor (DSP), ASIC, PLD, FPGA, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0127] In a possible implementation, the memory 1803 in the chip system can also be one or more. The memory 1803 can be integrated with the processor 1801 or can be separately arranged from the processor 1801, which is not limited in the present disclosure. Exemplarily, the memory 1803 can be integrated with the processor 1801 on the same chip, as Figure 5As shown, the memory 1803 and the processor 1801 may also be provided on different chips respectively. The present disclosure does not specifically limit the type of the memory 1803 and the setting manner of the memory 1803 and the processor 1801.

[0128] Among them, the memory 1803 may include a read-only memory and a random access memory, and provide instructions and data to the processor 1801. The memory 1803 may also include a non-volatile random access memory. The memory 1803 may also be a volatile memory, or may include both volatile and non-volatile memories.

[0129] Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).

[0130] Exemplarily, the chip may be an FPGA, may be an ASIC, may also be a SoC, may also be a CPU, may also be a network processor (NP), may also be a digital signal processing circuit (DSP), may also be a micro controller unit (MCU), may also be a PLD or other integrated chip.

[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present disclosure, rather than to limit them; although the present disclosure has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the present disclosure in various embodiments.

Claims

1. A method for data access, characterized in that, the method is applied to a system-on-chip (SoC), the SoC includes a flash memory controller and multiple processing cores, the flash memory controlled by the flash memory controller includes multiple storage areas, and the method includes: the flash memory controller receives an access request from a target processing core; the flash memory controller obtains access information corresponding to the access request, wherein the access information includes at least one of indication information of the target processing core and an access timing; the flash memory controller determines a target storage area in the flash memory where the access address corresponding to the access request is located; the flash memory controller obtains a target access condition corresponding to the target storage area; when the access information meets the target access condition, the flash memory controller executes the access request.

2. The method according to claim 1, characterized in that, the SoC further includes an address privilege register, the address privilege register is used to store the address range of each storage area in the multiple storage domains, and the flash memory controller determines the target storage area in the flash memory where the access address corresponding to the access request is located, including: the flash memory controller reads the address range of each storage area in the address privilege register; according to the address range of each storage area, determines the target storage area in the flash memory where the access address corresponding to the access request is located.

3. The method according to claim 2, characterized in that, the address privilege register is further used to store the access condition corresponding to each storage area in the multiple storage domains, and the flash memory controller obtains the target access condition corresponding to the target storage area, including: the flash memory controller reads the target access condition corresponding to the target storage area in the address privilege register.

4. The method according to any one of claims 1-3, characterized in that, the SoC further includes a multi-port arbiter, the multi-port arbiter is respectively connected to the flash memory controller and the multiple processing cores; before the flash memory controller receives an access request from a target processing core, it further includes: the multi-port arbiter receives the access request sent by the target processing core; the multi-port arbiter determines the indication information of the target processing core according to the port that receives the access request; the multi-port arbiter sends the access request and the indication information of the target processing core to the flash memory controller.

5. The method according to any one of claims 1-4, characterized in that, the multiple storage areas include a first storage area, and a first access condition corresponding to the first storage area, the first access condition includes: the processing core indicated by the indication information in the access information is a security subsystem.

6. The method according to any one of claims 1-5, characterized in that, the multiple storage areas include a second storage area, and a second access condition corresponding to the second storage area, the second access condition includes: the access timing in the access information is before entering the operating system (OS).

7. The method according to any one of claims 1-6, characterized in that, The multiple storage areas include a third storage area, and a third access condition corresponding to the third storage area. The third access condition includes: the processing core indicated by the indication information in the access information is any one of a security subsystem, a management subsystem, and an application processor in a secure state.

8. The method according to any one of claims 1-7, wherein, the multiple storage areas include a fourth storage area, and a fourth access condition corresponding to the fourth storage area. The fourth access condition includes: the processing core indicated by the indication information in the access information is any one of the multiple processing cores.

9. The method according to any one of claims 1-8, wherein, operation type indication information is further carried in the access request. Before the flash memory controller acquires the access information corresponding to the access request, the method further includes: the flash memory controller determines that the operation type indicated by the operation type indication information is a read operation or a write operation.

10. The method according to claim 9, wherein, the method further includes: in the case where it is determined that the operation type indicated by the operation type indication information is not a read operation or a write operation, the flash memory controller executes the access request.

11. An SoC, wherein, the SoC includes a flash memory controller and multiple processing cores. The flash memory controlled by the flash memory controller includes multiple storage areas. The flash memory controller is configured to: receive an access request from a target processing core; acquire the access information corresponding to the access request, where the access information includes at least one of indication information of the target processing core and an access timing; determine a target storage area in the flash memory where the access address corresponding to the access request is located; acquire a target access condition corresponding to the target storage area; execute the access request when the access information meets the target access condition.

12. The SoC according to claim 11, wherein, the SoC further includes an address permission register for storing the address range of each storage area in the multiple storage domains; the flash memory controller is configured to read, in the address permission register, the address range of each storage area, and determine, according to the address range of each storage area, a target storage area in the flash memory where the access address corresponding to the access request is located.

13. The SoC according to claim 12, wherein, the address permission register is further configured to store the access condition corresponding to each storage area in the multiple storage domains; the flash memory controller is configured to read, in the address permission register, the target access condition corresponding to the target storage area.

14. The SoC according to any one of claims 11-13, wherein, the SoC further includes a multi-port arbiter, and the multi-port arbiter is respectively connected to the flash memory controller and the multiple processing cores; the multi-port arbiter is configured to receive an access request sent by the target processing core; and determine the indication information of the target processing core according to the port that receives the access request. Send the access request and indication information of the target processing core to the flash memory controller.

15. The SoC according to any one of claims 11-14, wherein, the multiple storage areas include a first storage area, and a first access condition corresponding to the first storage area, the first access condition including: the processing core indicated by the indication information in the access information is a security subsystem.

16. The SoC according to any one of claims 11-15, wherein, the multiple storage areas include a second storage area, and a second access condition corresponding to the second storage area, the second access condition including: the access timing in the access information is before entering the operating system OS.

17. The SoC according to any one of claims 11-16, wherein, the multiple storage areas include a third storage area, and a third access condition corresponding to the third storage area, the third access condition including: the processing core indicated by the indication information in the access information is any one of a security subsystem, a management subsystem, and an application processor in a secure state.

18. The SoC according to any one of claims 11-17, wherein, the multiple storage areas include a fourth storage area, and a fourth access condition corresponding to the fourth storage area, the fourth access condition including: the processing core indicated by the indication information in the access information is any one of the multiple processing cores.

19. The SoC according to any one of claims 11-18, wherein, operation type indication information is further carried in the access request, and before the flash memory controller obtains the access information corresponding to the access request, it is further configured to: determine whether the operation type indicated by the operation type indication information is a read operation or a write operation.

20. The SoC according to claim 19, wherein, the flash memory controller is further configured to: execute the access request when it is determined that the operation type indicated by the operation type indication information is not a read operation or a write operation.

21. An electronic device, wherein, the electronic device includes the SoC and the flash memory as described in claims 11-20 above.

Citation Information

Cited By

  • Data access method, SOC and device

    EP4797131A1

  • Data access method, soc and device

    WO2025112927A1