Memory protection method and protection agent control device
By performing permission checking on the memory access request of the accelerator or IO device in the protection agent control device, the security and isolation problems when the hardware accelerator or IO device directly accesses the system memory with a physical address are solved, and effective protection of the system memory is achieved.
Patent Information
- Application Number
- CN202510008757.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2020-07-31
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art is difficult to effectively protect the security and isolation of system memory when hardware accelerators or IO devices directly access system memory with physical addresses, especially in equipment designed by third-party manufacturers.
A memory protection method is adopted to receive memory access requests from the accelerator or IO device through the protection agent control device, read the corresponding permission information, and perform permission checks to ensure that only accesses with legal permissions can access system memory.
Effectively prevent illegal memory access, ensure the security and isolation of system memory, and avoid potential security threats.
Smart Images

Figure CN120068174A_ABST
Abstract
Description
[0001] This application is a divisional application. The application number of the original application is 202080104550.1, the original application date is July 31, 2020, and the entire content of the original application is incorporated herein by reference. Technical Field
[0002] This application relates to the field of computer processing technologies, and particularly relates to a memory protection method and a protection proxy control device. Background Art
[0003] In recent years, the use of hardware accelerators has become increasingly widespread. By using some interface technologies, accelerators can be more closely integrated with the central processor unit (CPU) logically. For example, in a heterogeneous system architecture (HSA), by using the shared virtual memory (SVM) technology, the accelerator and the CPU can share the virtual address space and cache, thus bringing software programming consistency.
[0004] However, while these interface technologies bring performance improvement and power consumption reduction, they also bring serious security and isolation risks. Especially when the accelerator or input-output (IO) device is designed and produced by a third-party manufacturer, if the accelerator or IO device is allowed to directly access the system memory by physical address, it may bring many risks to the system memory. For example, if accessing a physical address space without read permission, it will threaten the confidentiality of the system memory; if accessing a physical address space without write permission, it will threaten the correctness of the system memory.
[0005] To this end, there is a TrustZone mechanism under the ARM architecture in the prior art. This mechanism divides the system resources of software and hardware into two parts: a secure world and a normal world, so as to prevent insecure accelerators / IO devices from accessing the system memory belonging to the operating system (OS). Under this mechanism, processes in the normal world can only access the system resources in the normal world, and processes in the secure world can access the system resources in the normal world and the system resources in the secure world. Since the system resources are only divided into two parts: the secure world and the normal world, the protection granularity of this mechanism for the system memory is very coarse, and this mechanism cannot provide effective protection between processes belonging to the same normal world either. Summary of the Invention
[0006] The present application provides a memory protection method and a protection proxy control device for checking memory access permissions when an accelerator or an I / O device directly accesses the system memory using a physical address, thereby effectively ensuring the security of the system memory.
[0007] In a first aspect, the present application provides a memory protection method, which can be executed by a protection proxy control device. The method includes: receiving a memory access request from an accelerator or an input / output (I / O) device, where the memory access request includes an identifier of a data stream of the accelerator or the I / O device and a first physical address requested to be accessed; according to the identifier of the data stream of the accelerator or the I / O device, reading permission information corresponding to a first physical page table where the first physical address is located, and the permission information corresponding to the first physical page table is used to indicate whether the data stream has read permission and / or write permission in the first physical page table; performing a permission check on the memory access request according to the permission information corresponding to the first physical page table, and if the permission check passes, allowing the memory access request to access the first physical address.
[0008] By adopting the above technical solution, when an accelerator or an I / O device requests to directly access the system memory using a physical address, the protection proxy control device can, according to the identifier of the data stream of the accelerator or the I / O device, obtain the permission information of the first physical page table where the data stream accesses the first physical address, and perform a permission check on the memory access request according to the permission information, and only allow the direct physical address access of the accelerator or the I / O device when the permission check passes, thereby ensuring the security of the system memory.
[0009] In a possible design of the first aspect, the step of reading, according to the identifier of the data stream of the accelerator or the I / O device, the permission information corresponding to the first physical page table where the first physical address is located may include: according to the identifier of the data stream of the accelerator or the I / O device, determining a physical page table protection table and a protection table cache corresponding to the data stream, where the physical page table protection table stores permission information corresponding to at least one physical page table, and the protection table cache is a cache of the physical page table protection table; judging whether there is permission information corresponding to the first physical page table in the protection table cache according to the identifier of the first physical page table, if so, reading the permission information corresponding to the first physical page table from the protection table cache; if not, reading the permission information corresponding to the first physical page table from the physical page table protection table and loading the permission information corresponding to the first physical page table into the protection table cache.
[0010] With the above technical solution, by setting a corresponding protection table cache for the physical page table protection table corresponding to a data stream to cache the permission information of the physical page table in the physical page table protection table, when the protection proxy control device needs to obtain the permission information of the data stream in a certain physical page table, it can first search in the corresponding protection table cache, and when it cannot be found, then search in the physical page table protection table. In this way, the search efficiency of the permission information can be effectively improved.
[0011] In a possible design of the first aspect, one entry of the protection table cache stores the permission information corresponding to one or more physical page tables, and the entry in the protection table cache where the permission information corresponding to each physical page table is located is indexed according to the hash value of the identifier of the physical page table. In this way, under the premise of ensuring the search efficiency, the storage space of the protection table cache can be fully utilized, and the resource utilization rate can be improved.
[0012] In a possible design of the first aspect, the step of reading the permission information corresponding to the first physical page table where the first physical address is located according to the identifier of the data stream of the accelerator or IO device may include: determining the physical page table protection table corresponding to the data stream according to the identifier of the data stream of the accelerator or IO device, and the physical page table protection table stores the permission information corresponding to at least one physical page table; reading the permission information corresponding to the first physical page table from the physical page table protection table according to the identifier of the first physical page table.
[0013] In a possible design of the first aspect, before reading the permission information corresponding to the first physical page table where the first physical address is located according to the identifier of the data stream of the accelerator or IO device, the method further includes: reading the protection flow table entry corresponding to the flow identifier of the data stream of the accelerator or IO device in the protection flow table, and the protection flow table entry includes first control information and second control information, where the first control information is used to indicate whether the global permission information of the physical page table protection table corresponding to the data stream is not readable and not writable, and the second control information is used to indicate the boundary range of the physical page table protection table; if it is determined according to the first control information and the second control information that the global permission information of the physical page table protection table is not not readable and not writable, and the first physical address is within the boundary range of the physical page table protection table, then read the permission information corresponding to the first physical page table where the first physical address is located.
[0014] With the above technical solution, by establishing the protection flow table entry corresponding to the data stream in the protection flow table, various control configuration information can be set for the data stream, thereby realizing the access control function.
[0015] In a possible design of the first aspect, the protected flow table entry further includes third control information for indicating the protection granularity of the physical page table protection table. Before reading the permission information corresponding to the first physical page table where the first physical address is located, the method further includes: determining the first physical page table where the first physical address is located according to the boundary range and protection granularity of the physical page table protection table.
[0016] In a possible design of the first aspect, the protected flow table entry further includes fourth control information for indicating whether to enable the function of checking memory access permissions for the data stream. After obtaining the protected flow table entry corresponding to the flow identifier of the data stream of the accelerator or IO device in the protected flow table, the method further includes: determining that the function of checking memory access permissions for the data stream is enabled according to the fourth control information.
[0017] In a possible design of the first aspect, the method further includes: receiving, from the translation proxy unit, the identifier of the data stream of the accelerator or IO device, the first physical address, and the permission information for the accelerator or IO device to access the first physical address. If the permission information corresponding to the first physical page table where the first physical address is located exists in the protection table cache corresponding to the data stream, and the permission information corresponding to the first physical page table in the protection table cache is inconsistent with the permission information for the accelerator or IO device to access the first physical address received from the translation proxy unit, then update the physical page table protection table corresponding to the data stream and the permission information corresponding to the first physical page table in the protection table cache according to the permission information for the accelerator or IO device to access the first physical address received from the translation proxy unit.
[0018] In a possible design of the first aspect, the method further includes: if the permission information corresponding to the first physical page table where the first physical address is located does not exist in the protection table cache corresponding to the data stream, then write the permission information for the accelerator or IO device to access the first physical address received from the translation proxy unit as the permission information corresponding to the first physical page table where the first physical address is located into the physical page table protection table corresponding to the data stream and / or the protection table cache respectively.
[0019] By adopting the above technical solution, before the accelerator or IO device initiates a direct physical address access using the physical address obtained from the translation proxy unit, the protection proxy control device can refresh the permission information of the corresponding physical page table in the protection table cache and the physical page table protection table according to the physical address and the corresponding permission information obtained from the translation proxy unit, so as to ensure that accurate permission information can be used to check the permission of the memory access request of the accelerator or IO device subsequently, and to guarantee the security of the system memory.
[0020] In a possible design of the first aspect, the method further includes: receiving page table invalidation information from a page table management module, where the page table invalidation information includes an identifier of a data stream of the accelerator or the IO device and identifiers of one or more physical page tables that are invalidated; updating the permission information corresponding to the one or more physical page tables that are invalidated in the protection table cache corresponding to the data stream and the physical page table protection table to be unreadable and unwritable.
[0021] In a possible design of the first aspect, the method further includes: receiving page table invalidation information from a page table management module, where the page table invalidation information includes an identifier of a data stream of the accelerator or the IO device and indication information for globally invalidating physical page tables related to the data stream; setting the global permission information of the physical page table protection table corresponding to the identifier of the data stream in the protection flow table entry stored in the protection flow table to be unreadable and unwritable.
[0022] By adopting the above technical solution, when the physical page tables related to the data stream of the accelerator or the IO device are invalidated, the protection proxy control device can perform corresponding processing, so that the permission information of the invalidated physical page tables can be updated to be unreadable and unwritable in a timely manner, thereby avoiding subsequent access to this part of the invalidated physical page tables and ensuring the security of the system memory.
[0023] In a second aspect, the present application provides a protection proxy control device, where a protection flow table and physical page table protection tables corresponding to at least one data stream are provided in the protection proxy control device, and the protection proxy control device realizes access control over the access of a third-party accelerator or IO to the system memory through the protection flow table and the physical page table protection tables corresponding to at least one data stream.
[0024] Among them, the protection flow table includes protection flow table entries corresponding to the at least one data stream, and control configuration information of each data stream is stored in the protection flow table entry corresponding to each data stream; permission information corresponding to at least one physical page table is stored in the physical page table protection table corresponding to each data stream, and the permission information corresponding to each physical page table is used to indicate whether the data stream has read permission and / or write permission in the physical page table.
[0025] In a possible design of the second aspect, the protection proxy control device further includes a protection table cache for each physical page table protection table, and the protection table cache is used to cache the permission information corresponding to the physical page tables in the physical page table protection table.
[0026] In a possible design of the second aspect, the control configuration information includes one or more of the following information: first control information, second control information, third control information, fourth control information, and fifth control information, where the first control information is used to indicate whether the global permission information of the physical page table protection table corresponding to the data stream is unreadable and unwritable, the second control information is used to indicate the boundary range of the physical page table protection table corresponding to the data stream, the third control information is used to indicate the protection granularity of the physical page table protection table corresponding to the data stream, the fourth control information is used to indicate whether to enable the function of checking memory access permissions for the data stream, and the fifth control information is used to indicate whether to control that the accelerator or IO device to which the data stream belongs can only initiate virtual address access.
[0027] In a third aspect, an embodiment of the present application provides a protection proxy control device, which has the functions implemented in the above first aspect or any possible design of the first aspect. The functions of the device can be implemented by hardware or by hardware executing corresponding software, and the hardware or software includes one or more modules or units corresponding to the above functions.
[0028] In a possible design, the structure of the device includes a processing module and a transceiver module. The processing module is configured to support the device to execute the corresponding functions in the above first aspect or any design of the first aspect. The transceiver module is used to support the communication between the device and other communication devices (such as accelerators or IO devices). The device may further include a storage module, which is coupled to the processing module and stores necessary program instructions and data of the device. As an example, the processing module may be a processor, the communication module may be a transceiver, and the storage module may be a memory. The memory may be integrated with the processor or may be separately provided from the processor, and the present application does not limit this.
[0029] In another possible design, the structure of the device includes a processor and may further include a memory. The processor is coupled to the memory and can be used to execute computer program instructions stored in the memory, so that the device executes the methods in the above first aspect or any possible design of the first aspect. Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface. The communication interface may be a transceiver or an input / output interface, or when the specific implementation form of the device is a chip, the communication interface may be the input / output interface of the chip. Optionally, the transceiver may be a transceiver circuit, and the input / output interface may be an input / output circuit.
[0030] Fourth aspect, an embodiment of the present application provides a chip system, which includes a processor, the processor is coupled to a memory, and the memory is used to store programs or instructions. When the programs or instructions are executed by the processor, the chip system implements the method in the above first aspect or any possible design of the first aspect.
[0031] Optionally, the chip system further includes an interface circuit, and the interface circuit is used to interact code instructions to the processor.
[0032] Optionally, the processor in the chip system can be one or more, and the processor can be implemented by hardware or by software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor that implements by reading software code stored in the memory.
[0033] Optionally, the memory in the chip system can also be one or more. The memory can be integrated with the processor or can be separately arranged from the processor, and the present application does not limit this. Exemplarily, the memory can be a non-transitory processor, such as a read-only memory ROM, which can be integrated with the processor on the same chip or can be separately arranged on different chips. The present application does not specifically limit the type of the memory and the setting manner of the memory and the processor.
[0034] Fifth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program or instruction is stored. When the computer program or instruction is executed, the computer executes the method in the above first aspect or any possible design of the first aspect.
[0035] Sixth aspect, an embodiment of the present application provides a computer program product. When a computer reads and executes the computer program product, the computer executes the method in the above first aspect or any possible design of the first aspect.
[0036] Seventh aspect, an embodiment of the present application provides a computer system, which includes the protection proxy control device described in the present application, and a CPU, at least one third-party accelerator or IO device coupled to the protection proxy control device. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figures 1a to 1d It is a schematic diagram of the system architecture applicable to the embodiment of the present application;
[0038] Figure 2 It is a schematic diagram of the structure of a protection proxy control device provided by the embodiment of the present application;
[0039] Figure 3aSchematic diagram of a flow table protection provided by an embodiment of the present application;
[0040] Figure 3b Schematic diagram of a secondary protection flow table provided by an embodiment of the present application;
[0041] Figure 3c Schematic diagram of a process-level protection flow table provided by an embodiment of the present application;
[0042] Figure 4 Schematic diagram of a physical page table protection flow provided by an embodiment of the present application;
[0043] Figure 5 Schematic diagram of a protection table cache provided by an embodiment of the present application;
[0044] Figure 6 Schematic diagram of a memory protection method provided by an embodiment of the present application;
[0045] Figure 7 Schematic diagram of the system software directly controlling the PAC device in an embodiment of the present application;
[0046] Figures 8a to 8d Schematic diagram of the overall process involved in the memory protection method in an embodiment of the present application;
[0047] Figure 9 Another structural schematic diagram of a protection proxy control device provided by an embodiment of the present application. Detailed implementation manners
[0048] In order to make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.
[0049] It should be noted that the specific operation methods in the method embodiments of the present application can also be applied to the device embodiments or system embodiments. "Multiple" means two or more. In view of this, in the embodiments of the present application, "multiple" can also be understood as "at least two". "At least one" can be understood as one or more, for example, understood as one, two, or more. For example, including at least one means including one, two, or more, and does not limit which ones are included. For example, including at least one of A, B, and C, then what can be included are A, B, C, A and B, A and C, B and C, or A, B, and C. Similarly, the understanding of descriptions such as "at least one kind" is similar. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / ", unless otherwise specified, generally represents an "or" relationship between the front and back associated objects.
[0050] Unless otherwise stated, the ordinal numbers such as "first" and "second" mentioned in the embodiments of this application are used to distinguish multiple objects, and are not used to limit the order, timing, priority or importance of multiple objects. Moreover, the descriptions of "first" and "second" do not necessarily limit that the objects are different.
[0051] The memory protection method provided by the embodiments of this application can be executed by a protection agent control (PAC) device, and is used to implement access permission checks for access requests from third-party accelerators or IO devices to directly access the system memory using physical addresses.
[0052] Specifically, the PAC device can be used as a standard address access protection module and integrated into an existing input-output memory management unit (IOMMU) / system memory management unit (SMMU) system, or it can also be used only as an agent module and integrated between the accelerator and the system memory or between the IO device and the system memory. By setting up the PAC device, all access requests from accelerators / IO devices to directly access the system memory using physical addresses can be checked by the PAC module to determine whether they have the corresponding access permissions, thereby ensuring the security of the system memory.
[0053] For example, the technical solution provided by this application can be applied to a system on chip (SoC) system integrated with a third-party accelerator. As Figure 1a shown, the SoC system includes a system memory, a CPU, an accelerator (accel) from an untrusted third party, and the PAC device. Among them, the PAC device is integrated between the system memory and the third-party accelerator, and has the effect of protecting the system memory. The SoC system also includes modules such as a memory management unit (MMU), a translation lookaside buffer (TLB), and an address translation service (ATS) that are respectively matched with the CPU and the third-party accelerator.
[0054] The technical solution provided by this application can also be applied to a computing network system extended through a PCI Express bus. As Figure 1bAs shown in the figure, the CPU is connected to external IO devices through the PCI Express bus to form a computing network system. Among them, the PAC device is integrated in the host, the IO device of the PCI Express bus implements the ATS function of the PCI Express protocol, and the IO device locally implements the address translation cache (ATC) function. The IO device can obtain in advance from the host the physical address required for direct memory access through the ATS mechanism, and then cache it in the local ATC module. In this way, when the IO device needs direct memory access, it can directly initiate a physical address access to the host memory, no longer requiring the IOMMU / SMMU to query the page table, and only needing to pass the permission check of the PAC to safely access the system memory.
[0055] The technical solution provided by this application can also be applied to a computing network system that is not extended by the PCI Express bus. As Figure 1c shown in the figure, the CPU is connected to external IO devices through a non-PCI Express bus to form a computing network system. The host integrates the PAC device of this application, and the bus supports an ATS mechanism similar to that of the PCI Express bus, which can enable the IO device to obtain in advance the physical address of the system memory space when direct memory access is required, and then cache it in the local ATC module. In this way, when the IO device needs direct memory access, it can directly initiate a physical address access to the host memory. At this time, it no longer requires the IOMMU / SMMU to query the page table, and only needs to pass the permission check of the PAC to safely access the system memory.
[0056] The technical solution provided by this application can also be applied to a hybrid high-performance computing system architecture. As Figure 1d shown in the figure, in this computing system, the CPU is connected to multiple external IO devices through the PCI Express bus. In addition, the CPU is also connected to an external accelerator through a non-PCI Express bus. These IO devices / accelerators all support the ATS or an ATS-like mechanism and can obtain in advance the physical address of the system memory space required for direct memory access. The PAC device of this application is implemented between these IO devices / external accelerators and the system memory. In addition, a third-party accelerator (such as a third-party accelerator IP) is integrated inside the CPU, and the PAC device of this application is also implemented between it and the system memory. By setting the PAC device of this application between the IO device / accelerator and the system memory, secure protection for the IO device / accelerator to access the system memory can be achieved.
[0057] Please refer to Figure 2, which is a schematic structural diagram of a protection agent control (PAC) device provided by an embodiment of the present application. The PAC device includes a protection stream table (PST) and a physical page protection table (PPPT) corresponding to at least one data stream. Optionally, to improve the table lookup performance, the PAC device may further include a protection table cache (PTC) for each physical page protection table.
[0058] The protection stream table, physical page protection table, and protection table cache implemented in the PAC device will be described in detail below.
[0059] I. Protection Stream Table
[0060] The protection stream table includes at least one protection stream table entry (PSTE) corresponding to a data stream, and the control configuration information corresponding to the data stream is stored in the protection stream table entry corresponding to each data stream.
[0061] For a data stream, the control configuration information may include one or more of the first control information, second control information, third control information, fourth control information, and fifth control information. Among them, the first control information is used to indicate whether the global permission information of the physical page protection table corresponding to the data stream is not readable and not writable, the second control information is used to indicate the boundary range of the physical page protection table corresponding to the data stream, the third control information is used to indicate the protection granularity of the protection stream table corresponding to the data stream, the fourth control information is used to indicate whether to enable the function of checking memory access permissions for the data stream, and the fifth control information is used to indicate whether to control that the accelerator or IO device to which the data stream belongs can only initiate virtual address access.
[0062] It should be noted that in the embodiment of the present application, the protection stream table can provide a software programming interface externally. Through this software programming interface, the system software can set the control configuration information for different data streams respectively. Since the control configuration information corresponding to different data streams is set separately and is independent of each other, the information content included in the control configuration information corresponding to different data streams can be the same or different, and the present application does not limit this.
[0063] In the embodiments of the present application, the protection flow table is indexed based on the identifier of the data stream. In this way, for a data stream, the protection flow table entry corresponding to the data stream can be located according to the identifier of the data stream, and then the control configuration information corresponding to the data stream can be obtained from the corresponding protection flow table entry. As described above, the second control information in the control configuration information is used to indicate the boundary range of the physical page table protection table corresponding to the data stream, and the boundary range of the physical page table protection table can also be understood as the range of physical addresses of all physical page tables involved in the physical page table protection table. For example, the second control information may include information such as the base address and size of the physical page table protection table.
[0064] The identifier of the data stream is used to distinguish data streams of different accelerators or I / O devices, and the identifier of the data stream can be mapped one-to-one with the device identifier of the accelerator or I / O device. The identifier of the data stream can also be referred to as a stream identity number (stream ID), and the device identifier can also be referred to as a device identity number (device ID). For example, the identifier of the data stream can be the stream identifier (Stream ID) in the SMMU under the ARM architecture, and the device identifier can be the requester identifier (Requester ID) in the PCI Express bus. The Requester ID and the Stream ID are mapped one-to-one, so that the PCI Express bus can also be implemented under the ARM architecture.
[0065] Please refer to Figure 3a , which is a schematic diagram of a protection flow table provided by the embodiments of the present application. The protection flow table includes multiple protection flow table entries such as PSTE0, PSTE1, PSTE2, PSTE3,.... The protection flow table is indexed by the identifier (stream ID) of the data stream, that is, a data stream corresponds to a protection flow table entry, and different protection flow table entries can be indexed according to the identifiers of different data streams. For example, data stream 0 can correspond to Figure 3a PSTE0 shown in Figure 3a , and PSTE0 can be indexed according to the identifier of data stream 0; data stream 1 can correspond to Figure 3a PSTE1 shown in Figure 3a , and PSTE1 can be indexed according to the identifier of data stream 1; data stream 2 can correspond to
[0066] Taking the protection flow table entry PSTE0 as an example, the fields of the following control configuration information may be included in the protection flow table entry:
[0067] 1) The EN field is used to indicate whether to enable the Protected Agent Control (PAC) mechanism, that is, whether to check the permission for this data stream to directly access the system memory using the physical address. This EN is the fourth control information in the above text, indicating whether to enable the function of checking memory access permissions for this data stream.
[0068] For example, this EN field can be represented by a single bit. When the value of this EN field is 1, it can indicate that the PAC mechanism is enabled, and memory access permission checks need to be performed on all memory access requests from this data stream. When the value of this EN field is 0, it can indicate that the PAC mechanism is not enabled, and memory access permission checks are not performed on memory access requests from this data stream.
[0069] 2) The Zero field is used to indicate whether the physical page table protection table corresponding to this data stream is in the initialization period. If it is in the initialization period, the permission information of all physical page tables in the physical page table protection table corresponding to this data stream is non-readable and non-writable. This Zero field is the first control information in the above text, used to indicate whether the global permission information of the physical page table protection table corresponding to this data stream is non-readable and non-writable.
[0070] 3) The OU field is used to indicate whether to control that the accelerator or IO device to which this data stream belongs can only initiate virtual address access and cannot initiate physical address access. This OU field is the fifth control information in the above text, used to indicate whether to control that the accelerator or IO device to which this data stream belongs can only initiate virtual address access.
[0071] For example, this OU field can be represented by a single bit. When the value of this bit is 1, it can indicate that only virtual address access is allowed for the accelerator or IO device to which this data stream belongs, and physical address access is not allowed; when the value of this bit is 0, it can indicate that the accelerator or IO device to which this data stream belongs is allowed to initiate physical address access. Thus, if the PAC device receives a memory access request from a certain accelerator or IO device, requesting to directly access a certain address space in the system memory using the physical address, then the PAC device can query the corresponding protection flow table entry in the protection flow table according to the identifier of the data stream of this accelerator or IO device. At this time, if the value of the OU field in this protection flow table entry is 1, the PAC device can determine that it is necessary to control that the accelerator or IO device to which this data stream belongs can only initiate virtual address access, and then reject this memory access request.
[0072] 4) The PGS field is used to indicate the inspection granularity when performing memory access permission checks on this data stream. In the embodiments of the present application, the PAC device can perform memory access permission checks in units of physical page tables. Therefore, the inspection granularity refers to the size of each physical page table, that is, the protection granularity of the physical page table protection table. This PGS field is the third control information mentioned above and is used to indicate the protection granularity of the physical page table protection table corresponding to this data stream.
[0073] 5) (PAC base address_H field, PAC base address_L field), which is used to indicate the base address of the physical page table protection table corresponding to this data stream. Among them, the PAC base address_H field (i.e., the PAC base address_H field) represents the high N bits of the base address of this physical page table protection table, and the PAC base address_L field (i.e., the PAC base address_L field) represents the low N bits of the base address of this physical page table protection table. The value of N can be 32, for example, that is, the PAC base address_H field and the PAC base address_L field are respectively used to indicate the high 32 bits and the low 32 bits of the base address of the physical page table protection table.
[0074] 6) The PAT boundary field is used to indicate the size of the physical page table protection table corresponding to this data stream.
[0075] The (PAC base address_H field, PAC base address_L field) and the PAT boundary field are the second control information mentioned above. Through these fields, the boundary range of the physical page table protection table corresponding to this data stream can be uniquely determined, that is, the range of physical addresses involved in the physical page tables in the physical page table protection table, so as to facilitate subsequent querying of the physical page table protection table according to the physical address or the identifier of the physical page table to determine the memory access permission of the data stream.
[0076] It should be noted that the above several fields are several examples of the control configuration information in the protection flow table entry. The protection flow table entry may also contain other control configuration information, which is not limited in the present application. Further, since the protection flow table can provide a software programming interface externally, through this software programming interface, the system software can expand more other control configuration information in the protection flow table entry, thereby enhancing the security and scalability of access control.
[0077] In a possible implementation manner, the protection flow table in the embodiments of the present application may also be a secondary protection flow table, and the secondary protection flow table can also be understood as a protection flow table with a secondary index. As Figure 3bAs shown in the figure, it is a schematic diagram of a two - level protected flow table provided by an embodiment of the present application. Specifically, the two - level protected flow table means that the protected flow table is divided into two levels. Each entry (Desc) in the upper - level protected flow table stores the description information of the sub - protected flow table. The description information of different sub - protected flow tables points to different lower - level protected flow tables. Each entry (PSTE) in the lower - level protected flow table stores the control configuration information of the corresponding data stream.
[0078] Both levels of protected flow tables can be indexed by the identifier of the data stream. In the upper - level protected flow table, according to the identifier of the data stream, different entries can be indexed in the upper - level protected flow table. However, it should be noted that the identifier of a data stream can correspond to an entry in the upper - level protected flow table, but an entry in the upper - level protected flow table can correspond to one or more identifiers of data streams, or to an interval of a data - stream identifier. That is to say, in the upper - level protected flow table, the relationship between the identifier of the data stream and the entry can be one - to - one or many - to - one. According to the identifier of a data stream, a unique entry can be indexed in the upper - level data - stream table, but different identifiers of data streams may index to the same entry in the upper - level data - stream table.
[0079] In the lower - level protected flow table, according to the identifier of the data stream, different entries can be indexed in the lower - level protected flow table, and the identifier of the data stream corresponds one - to - one with the entry in the lower - level protected flow table. According to the identifier of a data stream, a unique entry can be indexed in the lower - level protected flow table, and the control configuration information corresponding to the data stream is stored in this entry.
[0080] In the embodiment of the present application, by setting the data - stream table in the form of a two - level protected flow table, when the number of data streams is large, the query efficiency of the data - stream table can be improved, so that the protected - flow - table entry corresponding to the data stream can be found more efficiently, and the corresponding control configuration information can be obtained.
[0081] In another possible implementation manner, the protected flow table in the embodiment of the present application can also be a process - level protected flow table. Specifically, the protected flow table mentioned above in the present application can be understood as a device - level protected flow table, which means that the data streams of different accelerators / IO devices correspond to different protected - flow - table entries in the protected flow table. In this way, the control configuration information can be set separately for the data streams of different accelerators / IO devices, and the data streams of different accelerators / IO devices can correspond to different physical - page - table protection tables, so that access control can be performed separately for the data streams of different accelerators / IO devices.
[0082] The process-level protection flow table refers to further differentiating the sub-data flows of different processes in the data flow of an accelerator / IO device. Correspondingly, a process-level sub-protection flow table is created for the data flow under the device-level protection flow table. The sub-protection flow table includes at least one sub-protection flow table entry corresponding to a sub-data flow. The sub-data flows of different processes correspond to different sub-protection flow table entries in the sub-protection flow table. In this way, control configuration information can be set separately for the sub-data flows of different processes in the data flow, and the sub-data flows of different processes can correspond to different physical page table protection tables, so that access control can be performed separately for the sub-data flows of different processes in a data flow, effectively improving the granularity of access control.
[0083] Figure 3c FIG. is a schematic diagram of a process-level protection flow table provided by an embodiment of the present application, as Figure 3c shown, in the device-level protection flow table, it includes at least one protection flow table entry corresponding to a data flow. The data flow of an accelerator or IO device corresponds to a protection flow table entry. Different protection flow table entries are indexed based on the identifier of the data flow, and the identifier of the data flow is mapped one-to-one with the device identifier of the accelerator or IO device.
[0084] It should be noted that among the at least one data flow involved in the protection flow table, it may include a data flow that requires separate access control for the sub-data flows of different processes in the data flow (i.e., the data flow for which access control is performed at the process level), or it may include a data flow that does not require separate access control for the sub-data flows of different processes in the data flow (i.e., the data flow for which access control is performed at the data flow level). In view of this, in the protection flow table entry corresponding to each data flow in the device-level protection flow table, it may further include an indication information for indicating whether the data flow is a data flow that requires separate access control for the sub-data flows of different processes therein, and the indication information can be represented by a single bit.
[0085] For a data flow, if separate access control needs to be performed for the sub-data flows of different processes in the data flow, the description information of the sub-protection flow table of the data flow can be stored in the protection flow table entry corresponding to the data flow, and the description information of the sub-protection flow table points to the sub-protection flow table of the data flow.
[0086] Further, in the sub - protection flow table of the data stream, there are at least sub - protection flow table entries corresponding to one or more sub - data streams. One sub - data stream corresponds to one sub - protection flow table entry. Different sub - protection flow table entries are indexed based on the identifier of the sub - data stream. The identifier of the sub - data stream is used to distinguish sub - data streams of different processes in the data stream of an accelerator or an I / O device, and the identifier of the sub - data stream can be mapped one - to - one with the identifier of the process. For a sub - data stream, the control configuration information corresponding to the sub - data stream is stored in the sub - protection flow table entry corresponding to the sub - data stream. The specific information content included in the control configuration information corresponding to the sub - data stream can refer to the description of the control configuration information corresponding to the data stream in the above text and will not be repeated here.
[0087] For a data stream, if it is not necessary to perform access control on the sub - data streams of different processes in the data stream separately, the control configuration information corresponding to the data stream can be stored in the protection flow table entry corresponding to the data stream; or, the description information of the sub - protection flow table of the data stream can be stored in the protection flow table entry corresponding to the data stream. The description information of the sub - protection flow table points to the sub - protection flow table of the data stream, but there is only one sub - protection flow table entry in the sub - protection flow table of the data stream, and the control configuration information applicable to all sub - data streams of all processes of the data stream is stored therein.
[0088] II. Physical Page Table Protection Table
[0089] The physical page table protection table corresponding to each data stream is used to store the permission information corresponding to at least one physical page table. Specifically, for a data stream, the physical page table protection table corresponding to it includes at least physical page table protection table entries corresponding to one or more physical page tables. The permission information of the data stream in the physical page table is stored in each physical page table protection table entry corresponding to the physical page table. The permission information is used to indicate whether the data stream has read permission and / or write permission in the physical page table. For example, the permission information can be represented by 2 bit positions. The value of 1 bit position (R) is used to indicate whether there is read permission, and the value of the other bit position (W) is used to indicate whether there is write permission. It can be understood that the read permission refers to whether the data stream has the permission to perform a read operation in the physical page table, and the write permission refers to whether the data stream has the permission to perform a write operation in the physical page table.
[0090] The physical page table protection table can be indexed based on the physical address aligned according to the size of the protection granularity, such as the identifier of the physical page table, the physical page number (PPN) of the physical page table, etc. Thus, if an accelerator or an I / O device wants to directly access a memory space using a physical address, the PAC device can, according to the identifier of the data stream of the accelerator or the I / O device, locate the protection flow table entry corresponding to the data stream in the protection flow table, and determine, according to the indication of the control configuration information of the data stream stored in the protection flow table entry, the physical page number of the physical page table where the physical address of the memory space requested to be accessed by the accelerator or the I / O device is located. Then, according to the physical page number of the physical page table, it locates the physical page table protection table entry corresponding to the physical page table in the physical page table protection table, and further obtains the permission information of the data stream in the physical page table from the physical page table protection table entry, and determines whether the data stream has read permission and whether it has write permission in the physical page table.
[0091] Please refer to Figure 4 , which is a schematic diagram of a physical page table protection flow table provided by an embodiment of the present application. The physical page table protection table is a flattened table based on the physical address space, and stores information for indicating the access permissions of data streams in each physical page table, that is, the permission information mentioned above. As an example, the access permissions include read permission and write permission. Correspondingly, each physical page table in the physical page table protection table can have 2-bit permission information. Among them, 1-bit permission information in the 2-bit permission information can be called permission information R, which is used to indicate whether the data stream has read permission in the data page table. For example, when the value of the permission information R is 1, it can indicate having read permission (that is, can read), and when the value of the permission information R is 0, it can indicate not having read permission (that is, cannot read). The other 1-bit permission information can be called permission information W, which is used to indicate whether the data stream has write permission in the data page table. For example, when the value of the permission information R is 1, it can indicate having write permission (that is, can write), and when the value of the permission information W is 0, it can indicate not having write permission (that is, cannot write).
[0092] Thus, after obtaining the physical address to be accessed by the accelerator or the I / O device, the physical page number of the physical page table where the physical address is located can be determined according to the physical address and the protection granularity of the physical page table protection table. Then, the physical page table protection table is queried according to the physical page number to locate the physical page table protection table entry corresponding to the physical page table, and further, according to the permission information of the physical page table stored in the physical page table entry, it is determined whether the data stream of the accelerator or the I / O device has access permission in the physical page table.
[0093] III. Protection Table Cache
[0094] Each physical page table protection table may have a corresponding protection table cache for caching the permission information corresponding to the physical page tables in the physical page table protection table. The protection table cache may also be referred to as a protection table cache, or it may also be referred to as the cache of the physical page table protection table or the cache of the physical page table protection table. The present application does not limit this.
[0095] As the cache of the physical page table protection table, the protection table cache usually stores the recently accessed or frequently accessed permission information. Therefore, the hit rate of the protection table cache may be relatively high. When it is necessary to find the permission information corresponding to a data stream in a certain physical page table in the physical page table protection table, it can be first found in the protection table cache of the physical page table protection table. If it cannot be found in the protection table cache, then go to the physical page table protection table to find it, thereby effectively improving the search efficiency of the permission information.
[0096] It can be understood that in the embodiments of the present application, a certain cache replacement algorithm can be used to load the permission information in the physical page table protection table into the protection table cache, and delete the permission information with relatively low utilization rate or relatively long access time cached in the protection table cache according to the performance requirements. Therefore, which physical page tables' permission information is cached in the cache of the physical page table protection table is dynamically changing.
[0097] Specifically, for a physical page table protection table, the protection table cache of the physical page table protection table may also include multiple entries, and different entries may also be indexed based on the physical address, such as the physical address number or the identifier of the physical page table (such as the physical page table number PPN), etc. In a possible implementation manner, an entry in the protection table cache may store only the permission information corresponding to one physical page table. At this time, there are only 2 bits of useful information in one entry.
[0098] In another possible implementation manner, considering that the permission information corresponding to one physical page table is only 2 bits, and the number of bits occupied by each entry in the protection table cache is fixed and usually greater than 2 bits, for example, it may be 8 bits. Storing the permission information of each physical page table separately in one entry will cause waste of storage resources. In view of this, in order to efficiently utilize the storage space in the protection table cache, such as Figure 5As shown, the permission information (page permissions) corresponding to one or more physical page tables can be stored in the same entry of the protection table cache. At this time, different entries can be indexed by the hash value of the identifier of the physical page table. That is, the tag of each entry in the protection table cache is the hash value of the identifier of the physical page table. As an example, the hash value can be the divisor obtained by dividing the physical page table number by the maximum number of physical page table permission information that can be stored in an entry of the protection table cache, indicating that the permission information of multiple physical page tables with consecutive physical page table numbers can be stored in the same entry of the protection table cache. It should be noted that this application does not specifically limit the hash algorithm used when calculating the hash value according to the identifier of the physical page table.
[0099] It should be noted that the above physical page table protection table and protection table cache are the protection flow tables at the device level with the protection flow table, and the physical page table protection table and protection table cache corresponding to the data stream are described by taking the case of access control for the data streams of different accelerators or IO devices respectively. It can be understood that in the embodiments of this application, different data streams can correspond to different protection flow table entries in the protection flow table, and different data streams can correspond to different physical page table protection tables and protection table caches. This means that access permissions can be set separately for different data streams and access control can be performed separately.
[0100] In a possible implementation manner, different data streams can also correspond to the same protection flow table entry in the protection flow table, and different data streams can correspond to the same physical page table protection table and protection table cache. This means that the access permissions of the data streams of all accelerators / IO devices are the same, and unified permission control can be performed on all data streams. It should be noted that in this case, it is no longer necessary to index the protection flow table entry according to the identifier of the data stream, because there is only one protection flow table entry in the protection flow table, and the control configuration information corresponding to the data streams of all accelerators or IO devices is the same, and the memory access permissions can be checked by looking up the same physical page table protection table and protection table cache.
[0101] It should also be understood that in the case of a process-level protection flow table, on the basis of distinguishing the data streams of different accelerators or IO devices, and access control is also performed separately for the sub-data streams of different processes in the same data stream, the physical page table protection table and protection table cache corresponding to the sub-data streams can be implemented by a method similar to the description above, and this application will not elaborate.
[0102] Based on the above system architecture and PAC device, please refer to Figure 6 , which is a schematic flowchart of a memory protection method provided by an embodiment of this application. The method includes:
[0103] Step S601: The PAC device receives a memory access request from an accelerator or an IO device. The memory access request includes an identifier of the data stream of the accelerator or the IO device, and a first physical address requested by the accelerator or the IO device to be accessed.
[0104] Step S602: The PAC device reads the permission information corresponding to the first physical page table where the first physical address is located according to the identifier of the data stream of the accelerator or the IO device. The permission information corresponding to the first physical page table is used to indicate whether the data stream has read permission and / or write permission in the first physical page table.
[0105] Optionally, before reading the permission information corresponding to the first physical page table where the first physical address is located, the PAC device can determine the identifier of the first physical page table where the first physical address is located according to the first physical address, the boundary range of the physical page table protection table corresponding to the configured data stream, and the protection granularity of the physical page table protection table. For example, it can be the physical page table number of the first physical page table.
[0106] In the embodiments of the present application, the PAC device can read the permission information of the first physical page table where the first physical address is located through the following two possible implementation manners:
[0107] In a possible implementation manner, the PAC device can determine the physical page table protection table corresponding to the data stream of the accelerator or the IO device according to the identifier of the data stream of the accelerator or the IO device, and then read the permission information of the first physical page table from the physical page table protection table entry corresponding to the identifier of the first physical page table in the physical page table protection table.
[0108] In another possible implementation manner, the PAC device can determine the physical page table protection table corresponding to the data stream of the accelerator or the IO device and the protection table cache of the physical page table protection table according to the identifier of the data stream of the accelerator or the IO device. Then, according to the identifier of the first physical page table, look up the permission information of the first physical page table in the protection table cache. If the permission information of the first physical page table is found in the protection table cache, read the permission information of the first physical page table from the protection table cache. Otherwise, if the permission information of the first physical page table cannot be found in the protection table cache, read the permission information of the first physical page table from the physical page table protection table according to the identifier of the first physical page table, and load the permission information of the first physical page table into the protection table cache.
[0109] Step S603: The PAC device performs a permission check on the memory access request according to the permission information corresponding to the first physical page table. If the permission check passes, the memory access request is allowed to access the first physical address. Otherwise, the memory access request is refused to access the first physical address.
[0110] Specifically, the PAC device's permission check on the memory access request according to the permission information corresponding to the first physical page table may include: If the memory access request requests to perform a read operation at the first physical address, and the permission information corresponding to the first physical page table indicates that the data stream of the accelerator or IO device has read permission in the first physical page table, that is, it can be read, then the permission check passes. Correspondingly, when the PAC device allows the memory access request to access the first physical address at this time, it means allowing the data stream of the accelerator or IO device to read the information stored in the first physical address, that is, allowing a read operation to be performed at the first physical address.
[0111] If the memory access request requests to perform a read operation at the first physical address, but the permission information corresponding to the first physical page table indicates that the data stream of the accelerator or IO device does not have read permission in the first physical page table, that is, it cannot be read, then the permission check fails, and the PAC device should reject the memory access request to access the first physical address.
[0112] If the memory access request requests to perform a write operation at the first physical address, and the permission information corresponding to the first physical page table indicates that the data stream of the accelerator or IO device has write permission in the first physical page table, that is, it can be written, then the permission check passes. Correspondingly, when the PAC device allows the memory access request to access the first physical address at this time, it means allowing the data stream of the accelerator or IO device to write new information in the first physical address, that is, allowing a write operation to be performed at the first physical address.
[0113] If the memory access request requests to perform a write operation at the first physical address, but the permission information corresponding to the first physical page table indicates that the data stream of the accelerator or IO device does not have write permission in the first physical page table, that is, it cannot be written, then the permission check fails, and the PAC device should reject the memory access request to access the first physical address.
[0114] If the memory access request requests to perform a read operation and a write operation at the first physical address, and the permission information corresponding to the first physical page table indicates that the data stream of the accelerator or IO device has both read permission and write permission in the first physical page table, that is, it can be read and written, then the permission check passes. Correspondingly, when the PAC device allows the memory access request to access the first physical address at this time, it means allowing the data stream of the accelerator or IO device to read the information stored in the first physical address, and at the same time allowing the data stream of the accelerator or IO device to write new information in the first physical address, that is, allowing a read operation and a write operation to be performed at the first physical address.
[0115] If the memory access request requests a read operation and a write operation to be performed at a first physical address, but the permission information corresponding to the first physical page table indicates that the data stream of the accelerator or I / O device does not have read permission (i.e., is not readable) in the first physical page table, or the permission information corresponding to the first physical page table indicates that the data stream of the accelerator or I / O device does not have write permission (i.e., is not writable) in the first physical page table, then the permission check fails, and the PAC device shall reject the memory access request to access the first physical address.
[0116] Optionally, before the PAC device reads the permission information of the first physical page table where the first physical address is located in step S602, it may also read the protection flow table entry corresponding to the flow identifier of the data stream of the accelerator or I / O device in the protection flow table. As described above, the protection flow table entry stores the control configuration information of the data stream of the accelerator or I / O device, including the first control information for indicating whether the global permission information of the physical page table protection table corresponding to the data stream is not readable or writable, the second control information for indicating the boundary range of the physical page table protection table, the third control information for indicating the protection granularity of the physical page table protection table, the fourth control information for indicating whether to enable the function of checking the memory access permission for the data stream, etc.
[0117] In this way, after the PAC device reads the protection flow table entry corresponding to the flow identifier of the data stream of the accelerator or I / O device in the protection flow table, it can first determine, according to the indication of the fourth control information, whether the function of checking the memory access permission for the data stream has been enabled. If it has been enabled, it means that the memory access permission needs to be checked for the data stream, and the PAC device can continue the subsequent process of checking the memory access permission. If it has not been enabled, it means that the memory access permission is not checked for the data stream, and at this time, the PAC device can directly forward this access.
[0118] After the PAC device determines that the function of checking the memory access permission for the data stream has been enabled, it can determine, according to the indication of the fifth control information, whether to control the data stream to only initiate virtual address access and not initiate physical address access. If the fifth control information indicates that the data stream can only initiate virtual address access and not initiate physical address access, then the PAC device can directly reject this access. If the fifth control information indicates that the data stream can initiate physical address access, then the PAC device can continue the subsequent process of checking the memory access.
[0119] Subsequently, the PAC device can determine, according to the indication of the first control information, whether the global permission information of the physical page table protection table corresponding to the data stream is not readable or writable, and determine, according to the boundary range of the physical page table protection table indicated by the second control information corresponding to the data stream, whether the first physical address is within the boundary range of the physical page table protection table.
[0120] If the global permission information of the physical page table protection table corresponding to the data stream indicated by the first control information is not readable and writable, it means that all physical page tables involved in the physical page table protection table cannot be accessed, that is, the permission information of all physical page tables is not readable and writable. This situation may be because the memory access request arrives before the initialization of the physical page table protection table. At this time, the PAC device can directly reject this access. Similarly, if the first physical address is outside the boundary range of the physical page table protection table indicated by the second control information, it means that the data stream of the accelerator or IO device attempts to access an address space outside its permission range or invisible or unknown to it. At this time, the PAC device can also directly reject this access.
[0121] If the global permission information of the physical page table protection table corresponding to the data stream indicated by the first control information is not not readable and writable, and the first physical address is within the boundary range of the physical page table protection table indicated by the second control information, the PAC device can read the permission information of the first physical page table where the first physical address is located.
[0122] Optionally, before reading the permission information of the first physical page table where the first physical address is located, the PAC device can determine the identifier of the first physical page table where the first physical address is located according to the first physical address, the boundary range of the physical page table protection table corresponding to the data stream indicated by the second control information, and the protection granularity of the physical page table protection table corresponding to the data stream indicated by the third control information. For example, obtain the physical page table number of the first physical page table, and then execute step S602 to read the permission information of the data stream in the first physical page table from the physical page table protection table or from the protection table cache of the physical page table protection table.
[0123] Optionally, before executing step S601, the PAC device can also execute the protection table refresh process. Specifically, the PAC device can receive the identifier of the data stream of the accelerator or IO device, the first physical address requested by the data stream to access, and the permission information of the accelerator or IO device to access the first physical address from the translation proxy unit.
[0124] In the embodiment of the present application, the translation proxy unit is a functional unit for translating a virtual address into a corresponding physical address. The translation proxy unit can receive an address translation request from an accelerator or an I / O device. The address translation request includes an identifier of a data stream of the accelerator or the I / O device, and a first virtual address requested by the accelerator or the I / O device for translation. After receiving the address translation request, the translation proxy unit can translate the first virtual address into a corresponding first physical address, and then send the first physical address in the address translation result to the accelerator or the I / O device. In addition, the translation proxy unit can also synchronously send the address translation result to the PAC device. The address translation result includes the first physical address, and at the same time, relevant information such as the identifier of the data stream of the accelerator or the I / O device and the permission information of the first physical page table where the accelerator or the I / O address accesses the first physical address is sent.
[0125] After receiving the identifier of the data stream of the accelerator or the I / O device and the request from the accelerator or the I / O device to access the first physical address from the translation proxy unit, the PAC device can determine, according to the identifier of the data stream of the accelerator or the I / O device, a protection flow table entry corresponding to the identifier of the data stream from the protection flow table, and read the control configuration information of the data stream from the corresponding protection flow table entry. Furthermore, the PAC device determines, according to the control configuration information of the data stream, a physical page table protection table corresponding to the data stream of the accelerator or the I / O device, and an identifier of the first physical page table where the first physical address is located.
[0126] Furthermore, the PAC device can determine whether the permission information of the first physical page table stored in the physical page table protection table corresponding to the data stream of the accelerator or the I / O device is consistent with the permission information of the accelerator or the I / O device accessing the first physical address received from the translation proxy unit, that is, determine whether the accurate access permission of the data stream in the first physical page table is stored in the physical page table protection table corresponding to the data stream of the accelerator or the I / O device.
[0127] Specifically, if the permission information corresponding to the first physical page table is stored in the protection table cache of the physical page table protection table corresponding to the data stream, and the permission information corresponding to the first physical page table stored in the protection table cache is inconsistent with the permission information of the accelerator or the I / O device accessing the first physical address received by the PAC device from the translation proxy unit, the PAC device can update the permission information corresponding to the first physical page table stored in the physical page table protection table and the protection table cache according to the permission information of the accelerator or the I / O device accessing the first physical address received from the translation proxy unit.
[0128] That is to say, the PAC device can consider the permission information for the accelerator or IO device to access the first physical address received from the translation proxy unit as the accurate access permission for the accelerator or IO device at the first physical page table. If the permission information stored in the physical page table protection table and the protection table cache corresponding to the data stream is inconsistent with this access permission, then the accurate permission information received from the translation proxy unit is used to refresh the permission information of the first physical page table stored in the physical page table protection table and the protection table cache, so as to ensure that when the PAC device uses the permission information stored in the physical page table protection table or the protection table cache to check the memory access permission, the accurate permission information is used.
[0129] If the permission information corresponding to the first physical page table is stored in the protection table cache of the physical page table protection table corresponding to the data stream, and the permission information corresponding to the first physical page table stored in the protection table cache is consistent with the permission information for the accelerator or IO device to access the first physical address received by the PAC device from the translation proxy unit, then the PAC device does not need to do anything.
[0130] If the permission information corresponding to the first physical page table is not stored in the protection table cache of the physical page table protection table corresponding to the data stream, then the PAC device can use the permission information for the accelerator or IO device to access the first physical address received from the translation proxy unit as the permission information corresponding to the first physical page table, and write it into the physical page table protection table corresponding to the data stream and / or the protection table cache of the physical page table protection table respectively.
[0131] Specifically, the PAC device can create a new physical page table protection table entry in the physical page table protection table corresponding to the data stream, establish a mapping relationship between the physical page table protection table entry and the identifier of the first physical page table, and then store the permission information for the accelerator or IO device to access the first physical address into this physical page table protection table entry. The method for the PAC device to write the permission information for the accelerator or IO device to access the first physical address into the protection table cache is similar and will not be elaborated here.
[0132] Optionally, during the operation of the accelerator or IO device, the relevant physical page table may be updated. For example, a new physical page table may be established, or the mapping between virtual addresses and physical addresses may change. At this time, the system software may choose to invalidate part of the physical page table, or choose to invalidate all physical page tables related to a certain process in the accelerator or IO device, or even choose to invalidate all physical page tables related to the accelerator or IO device. In either case, the page table management module in the system software knows exactly which physical page tables will be invalidated and sends the information of the invalidated physical page tables to the PAC device so that the PAC device can make corresponding processing, including refreshing the control configuration information corresponding to the data stream of the accelerator or IO device stored in the protection flow table, and the permission information of the invalidated physical page tables stored in the physical page table protection table.
[0133] Specifically, in a possible implementation manner, the PAC device may receive page table invalidation information from the page table management module. The page table invalidation information includes the identifier of the data stream of the accelerator or IO device and the identifier of one or more physical page tables to be invalidated. Furthermore, the PAC device may update the permission information corresponding to the one or more invalidated physical page tables in the physical page table protection table corresponding to the data stream and the corresponding protection table cache to unreadable and unwritable.
[0134] In another possible implementation manner, the PAC device may receive page table invalidation information from the page table management module. The page table invalidation information includes the identifier of the data stream of the accelerator or IO device and the indication information for globally invalidating the physical page tables related to the data stream. Furthermore, the PAC device may set the global permission information of the physical page table protection table corresponding to the data stream in the protection flow table to unreadable and unwritable. If the number of physical page tables related to the data stream is small, the PAC device may also choose to traverse the physical page table protection table and / or the physical page tables in the protection table cache corresponding to the data stream, and set the permission information of each physical page table to unreadable and unwritable one by one. This application does not limit this. This implementation manner can be referred to as global invalidation based on the stream ID (stream identifier).
[0135] In yet another possible implementation, the PAC device may receive page table invalidation information from the page table management module. The page table invalidation information includes the identifier of the data stream of the accelerator or IO device, the identifier of the sub-data stream of a certain process in the accelerator or IO device, and the indication information for globally invalidating the physical page table related to the sub-data stream. In this scenario, if the protection flow table is a process-level protection flow table and each process in the accelerator or IO device has a corresponding physical page table protection table for its sub-data stream, then the PAC device may set the global permission information of the physical page table protection table corresponding to the sub-data stream in the sub-protection flow table of the data stream to unreadable and unwritable. Alternatively, if the number of physical page tables related to the sub-data stream is small, the PAC device may also choose to traverse the physical page table protection table corresponding to the sub-data stream and / or the physical page tables in the protection table cache, and set the permission information of each physical page table to unreadable and unwritable one by one. This implementation may be referred to as global invalidation based on sub-stream ID.
[0136] It should be noted that in the embodiments of the present application, the physical page table protection table and the protection table cache in the PAC device can be automatically maintained and refreshed in a hardware manner. However, it should be noted that this method requires the accelerator or IO device to support the address translation service (ATS) mechanism or other similar mechanisms, such as the distributed translation interface (DTI) mechanism under the ARM architecture. The ATS mechanism means that the accelerator or IO device carries information such as the identifier of its own data stream and the identifier of the sub-data stream (if necessary), the starting address and the size of the virtual address space, and applies to the system translation agent (TA) for the physical address space corresponding to the virtual address space, so as to obtain the corresponding address space and related address space attributes and other information before the accelerator or IO device accesses the system memory.
[0137] Alternatively, the physical page table protection table and the protection table cache in the PAC device can also be maintained and refreshed by the system software in a software manner. Specifically, please refer to Figure 7As shown in the figure, the system software (such as the operation system (OS)) can directly control the PAC device. Before the driver of the corresponding accelerator or IO device starts its business work, the system software allocates relevant resources for it, creates corresponding protection flow table entries in the protection flow table, and sets up the control configuration information. In addition, the system software also creates a physical page table protection table for the corresponding accelerator or IO device in the PAC device, and configures the access permissions of relevant physical addresses in the corresponding physical page table protection table.
[0138] The following uses Figures 8a to 8d the flowchart in to elaborate in detail on the overall process involved in the memory protection method provided by the embodiments of this application.
[0139] I. Initialization
[0140] Please refer to Figure 8a . First, the system management software discovers the accelerator / IO device, and the system software enables the ATS mechanism. The system software creates corresponding protection flow table entries for this accelerator / IO device according to the flow identifier or device identifier of the accelerator / IO device (such as stream ID or requesterID), and initializes the protection flow table entries. Then the system software starts the accelerator to work.
[0141] When initializing, the system software does not need to traverse the entire physical page table protection table and set the permission bit of each physical page table to 00b (indicating no read permission and write permission) one by one. Instead, when initializing the protection flow table entry corresponding to this accelerator / IO device, the Zero bit in it can be set to 1, indicating that the accelerator / IO device corresponding to the flow identifier has no read permission and write permission, that is, the global permission of the corresponding physical page table protection table is not readable and not writable.
[0142] The system software can also set other control configuration information such as the base address and boundary size in memory of the physical page table protection table corresponding to this accelerator / IO device during initialization.
[0143] II. Protection Table Refresh
[0144] Please refer to Figure 8b, when there is a lack of ATC locally in the accelerator / IO device, the accelerator / IO device can request address translation from the IOMMU / SMMU through the ATS mechanism. After the address translation is completed, the IOMMU / SMMU can return the corresponding address translation result to the accelerator / IO device. In addition, the IOMMU / SMMU can also synchronously send the address translation result and related information to the PAC device in this application. Among them, the address translation result includes the physical address of the address space requested by the accelerator / IO device to access, and the related information may include the stream identifier of the accelerator / IO device and the permission information of the corresponding physical page table.
[0145] Subsequently, the PAC device can determine whether the protection table cache corresponding to the stream identifier of the accelerator / IO device locally has the correct access permission. If the permission information of the corresponding physical page table exists in the protection table cache and the permission information in the protection table cache is consistent with the permission information provided by the IOMMU / SMMU, the PAC device does nothing; if the permission information of the corresponding physical page table exists in the protection table cache, but the permission information in the protection table cache is inconsistent with the permission information provided by the IOMMU / SMMU, at this time, the PAC device refreshes the permission information of the corresponding physical page table in the protection table cache and writes the permission information back to the corresponding Physical Page Protection Table (PPPT); if the permission information of the corresponding physical page table does not exist in the protection table cache, at this time, the PAC device creates an entry cache of the corresponding physical page table in the protection table cache and writes the permission information of this physical page table to the corresponding physical page table protection table.
[0146] III. Memory Access
[0147] Please refer to Figure 8c, after the accelerator / IO device obtains the physical address and initiates a memory access, all memory access requests will pass through the PAC device in this application for access permission checking. If it is found at this time that the check switch bit in the protection table flow table entry corresponding to the access stream of this access is not turned on (that is, the EN field indicates not to check the access), then directly route this access forward. Otherwise, if the access request of the accelerator / IO device to access the system memory using the physical address arrives before the initialization of the physical page table protection table (that is, the ZERO field indicates that the global permission information is not readable and not writable, or the ZERO field is considered invalid), or the value after alignment of the physical address granularity of this access is greater than the boundary range of the physical page table protection table, then directly block this access and report an event to the system software. Otherwise, it is judged whether there is permission information corresponding to the physical page table in the protection table cache in the PAC device at this time. If not, the permission information corresponding to the physical page table is loaded from the physical page table protection table into the protection table cache, and then the permission check is performed; otherwise, the permission information corresponding to the physical page table in the protection table cache is directly read for the permission check. If the permission check passes, this access can be routed forward; otherwise, this access is blocked and an event is reported to the software.
[0148] IV. Invalidation of the protection table
[0149] Please refer to Figure 8d , during the process of the process, the corresponding physical page table may be updated. If a new physical page table needs to be established or the mapping between the previous virtual address and the physical address changes, then the PAC device of this application also needs to make corresponding processing. At this time, the system software can choose to invalidate part of the page table mapping or invalidate all the page tables belonging to this process. In either case, the page table management module of the system needs to know which page tables of the specific physical page table need to be invalidated. At this time, this information will be synchronized to the PAC device, and then the PAC device can mark the cache entries corresponding to the invalid page tables in the protection table cache as the dirty state, refresh the permission information of the relevant invalid page tables in the physical page table protection table, and refresh the corresponding protection table entries or sub-protection table entries in the protection flow table.
[0150] The invalidation can also be global invalidation based on sub-StreamID or global invalidation based on StreamID. Among them, global invalidation based on sub-StreamID means that the invalidation operation will affect all relevant physical page tables under this SubstreamID, and global invalidation based on StreamID means that the invalidation operation will affect all relevant physical page tables under this streamID.
[0151] The embodiment of this application also provides a protection proxy control device. Please refer toFigure 9 , which is a schematic structural diagram of a protection proxy control device provided by an embodiment of the present application. The protection proxy control device 900 includes: a communication module 910 and a processing module 920. The protection proxy control device can be used to implement any of the above method embodiments.
[0152] Exemplarily, when the protection proxy control device executes Figure 6 the method embodiment shown in, the communication module 910 is used to receive a memory access request from an accelerator or an input / output IO device. The memory access request includes an identifier of a data stream of the accelerator or the IO device and a first physical address requested to be accessed; the processing module 920 is used to read permission information corresponding to a first physical page table where the first physical address is located according to the identifier of the data stream of the accelerator or the IO device. The permission information corresponding to the first physical page table is used to indicate whether the data stream has read permission and / or write permission in the first physical page table; and, perform a permission check on the memory access request according to the permission information corresponding to the first physical page table. If the permission check passes, the memory access request is allowed to access the first physical address.
[0153] The processing module 920 involved in the protection proxy control device can be implemented by a processor or processor-related circuit components, and the communication module 910 can be implemented by a transceiver or transceiver-related circuit components. The operations and / or functions of each module in the protection proxy control device are respectively for implementing Figure 6 , Figure 7 , Figure 8a , Figure 8b , Figure 8c or Figure 8d the corresponding processes of the methods shown in, and for the sake of brevity, they will not be elaborated here.
[0154] An embodiment of the present application further provides a chip system, including: a processor, the processor is coupled to a memory, and the memory is used to store programs or instructions. When the programs or instructions are executed by the processor, the chip system implements the methods in any of the above method embodiments.
[0155] Optionally, the processor in the chip system can be one or more. The processor can be implemented by hardware or by software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor, which is implemented by reading software code stored in the memory.
[0156] Optionally, the memory in the chip system may also be one or more. The memory may be integrated with the processor or may be separately provided from the processor, and the present application does not limit this. Exemplarily, the memory may be a non-transitory processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or may be separately provided on different chips. The present application does not specifically limit the type of the memory and the setting manner of the memory and the processor.
[0157] Exemplarily, the chip system may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processing unit (CPU), a network processor (NP), a digital signal processing circuit (DSP), a micro controller unit (MCU), a programmable logic device (PLD), or other integrated chips.
[0158] It should be understood that the steps in the above method embodiments can be completed by the logic circuit in the processor or the instructions in the form of software. The method steps disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware processor, or executed and completed by the combination of the hardware and software modules in the processor.
[0159] The embodiments of the present application further provide a computer-readable storage medium, in which computer-readable instructions are stored. When the computer reads and executes the computer-readable instructions, the computer is caused to execute the methods in the above method embodiments.
[0160] The embodiments of the present application further provide a computer program product. When the computer reads and executes the computer program product, the computer is caused to execute the methods in the above method embodiments.
[0161] The embodiments of the present application provide a computer system, which includes the protection proxy control device described in the present application, and a CPU, at least one third-party accelerator or IO device coupled to the protection proxy control device.
[0162] It should be understood that the processor mentioned in the embodiments of the present application may be a CPU, or may also be other general-purpose processors, DSPs, ASICs, FPGAs, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0163] It should also be understood that the memory mentioned in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DRRAM).
[0164] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) is integrated in the processor.
[0165] It should be noted that the memory described herein is intended to include but not be limited to these and any other suitable types of memory.
[0166] It should be understood that the various digital numbers involved in the various embodiments of the present application are only for the convenience of description and differentiation. The magnitude of the sequence numbers of the above processes does not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0167] In various embodiments of the present application, without special instructions and logical conflicts, the terms and / or descriptions between different embodiments are consistent and can be cross-referenced. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0168] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0169] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0170] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0171] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0172] In addition, the functional units in various embodiments of the present application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0173] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories, random access memories, magnetic disks, or optical discs.
[0174] As described above, the above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. A memory protection method, characterized in that, the method includes: receiving a memory access request from a first device, where the memory access request includes an identifier of a data stream of the first device and a first physical address for which access is requested; reading, according to the identifier of the data stream of the first device, permission information corresponding to a first physical page table where the first physical address is located, and the permission information corresponding to the first physical page table is used to indicate whether the data stream has read permission and / or write permission in the first physical page table; performing a permission check on the memory access request according to the permission information corresponding to the first physical page table, and if the permission check passes, allowing the memory access request to access the first physical address.
2. The method according to claim 1, characterized in that, the step of reading, according to the identifier of the data stream of the first device, permission information corresponding to a first physical page table where the first physical address is located includes: determining, according to the identifier of the data stream of the first device, a physical page table protection table and a protection table cache corresponding to the data stream, where the physical page table protection table stores permission information corresponding to at least one physical page table, and the protection table cache is a cache of the physical page table protection table; judging whether the permission information corresponding to the first physical page table exists in the protection table cache according to the identifier of the first physical page table, and if it exists, reading the permission information corresponding to the first physical page table from the protection table cache; if it does not exist, reading the permission information corresponding to the first physical page table from the physical page table protection table and loading the permission information corresponding to the first physical page table into the protection table cache.
3. The method according to claim 2, characterized in that, one entry of the protection table cache stores permission information corresponding to one or more physical page tables, and the entry where the permission information corresponding to each physical page table is located in the protection table cache is indexed according to the hash value of the identifier of the physical page table.
4. The method according to claim 1, characterized in that, the step of reading, according to the identifier of the data stream of the first device, permission information corresponding to a first physical page table where the first physical address is located includes: determining, according to the identifier of the data stream of the first device, a physical page table protection table corresponding to the data stream, where the physical page table protection table stores permission information corresponding to at least one physical page table; reading, according to the identifier of the first physical page table, the permission information corresponding to the first physical page table from the physical page table protection table.
5. The method according to any one of claims 1 to 4, characterized in that, before the step of reading, according to the identifier of the data stream of the first device, permission information corresponding to a first physical page table where the first physical address is located, the method further includes: Read the protection flow table entry corresponding to the flow identifier of the data stream of the first device in the protection flow table. The protection flow table entry includes first control information and second control information. The first control information is used to indicate whether the global permission information of the physical page table protection table corresponding to the data stream is not readable and writable. The second control information is used to indicate the boundary range of the physical page table protection table. If it is determined according to the first control information and the second control information that the global permission information of the physical page table protection table is not not readable and writable, and the first physical address is within the boundary range of the physical page table protection table, then read the permission information corresponding to the first physical page table where the first physical address is located.
6. The method according to claim 5, wherein, the protection flow table entry further includes third control information, and the third control information is used to indicate the protection granularity of the physical page table protection table; before reading the permission information corresponding to the first physical page table where the first physical address is located, it further includes: determine the first physical page table where the first physical address is located according to the boundary range and protection granularity of the physical page table protection table.
7. The method according to claim 5 or 6, wherein, the protection flow table entry further includes fourth control information, and the fourth control information is used to indicate whether to enable the function of checking memory access permissions for the data stream; after obtaining the protection flow table entry corresponding to the flow identifier of the data stream of the first device in the protection flow table, the method further includes: determine that the function of checking memory access permissions for the data stream is enabled according to the fourth control information.
8. The method according to any one of claims 1 to 7, wherein, the method further includes: receive the identifier of the data stream of the first device, the first physical address, and the permission information for the first device to access the first physical address from the translation proxy unit; if the permission information corresponding to the first physical page table where the first physical address is located exists in the protection table cache corresponding to the data stream, and the permission information corresponding to the first physical page table in the protection table cache is inconsistent with the permission information for the first device to access the first physical address received from the translation proxy unit, then update the physical page table protection table corresponding to the data stream and the permission information corresponding to the first physical page table in the protection table cache according to the permission information for the first device to access the first physical address received from the translation proxy unit.
9. The method according to claim 8, wherein, the method further includes: if the permission information corresponding to the first physical page table where the first physical address is located does not exist in the protection table cache corresponding to the data stream, then use the permission information for the first device to access the first physical address received from the translation proxy unit as the permission information corresponding to the first physical page table where the first physical address is located, and write it into the physical page table protection table corresponding to the data stream and / or the protection table cache respectively.
10. The method according to any one of claims 1 to 9, Characterized in that, The method further includes: Receiving page table invalidation information from a page table management module, where the page table invalidation information includes an identifier of a data stream of the first device and identifiers of one or more physical page tables that are invalidated; Updating the permission information corresponding to the one or more physical page tables that are invalidated in the protection table cache corresponding to the data stream and the physical page table protection table to be unreadable and unwritable.
11. The method according to any one of claims 1 to 10, Characterized in that, The first device includes an accelerator or an input / output (IO) device.
12. A protection proxy control device, Characterized in that, The device includes a processor and a communication interface; wherein, The communication interface is configured to receive a memory access request from a first device, where the memory access request includes an identifier of a data stream of the first device and a first physical address requested to be accessed; The processor is configured to, according to the identifier of the data stream of the first device, read the permission information corresponding to the first physical page table where the first physical address is located, and the permission information corresponding to the first physical page table is used to indicate whether the data stream has read permission and / or write permission in the first physical page table; And perform a permission check on the memory access request according to the permission information corresponding to the first physical page table, and if the permission check passes, allow the memory access request to access the first physical address.
13. The device according to claim 12, Characterized in that, The processor is specifically configured to: According to the identifier of the data stream of the first device, determine the physical page table protection table and the protection table cache corresponding to the data stream, where the physical page table protection table stores permission information corresponding to at least one physical page table, and the protection table cache is a cache of the physical page table protection table; According to the identifier of the first physical page table, determine whether the permission information corresponding to the first physical page table exists in the protection table cache, and if it exists, read the permission information corresponding to the first physical page table from the protection table cache; If it does not exist, read the permission information corresponding to the first physical page table from the physical page table protection table and load the permission information corresponding to the first physical page table into the protection table cache.
14. The device according to claim 13, Characterized in that, One entry of the protection table cache stores permission information corresponding to one or more physical page tables, and the entry where the permission information corresponding to each physical page table is located in the protection table cache is indexed according to the hash value of the identifier of the physical page table.
15. The device according to claim 12, Characterized in that, The processor is specifically configured to: According to the identifier of the data stream of the first device, determine the physical page table protection table corresponding to the data stream, where the physical page table protection table stores permission information corresponding to at least one physical page table; According to the identifier of the first physical page table, read the permission information corresponding to the first physical page table from the physical page table protection table.
16. The device according to any one of claims 12 to 15, Characterized in that, The processor is further configured to: Read the protection flow table entry corresponding to the flow identifier of the data flow of the first device in the protection flow table. The protection flow table entry includes first control information and second control information. The first control information is used to indicate whether the global permission information of the physical page table protection table corresponding to the data flow is not readable and not writable. The second control information is used to indicate the boundary range of the physical page table protection table. If it is determined, based on the first control information and the second control information, that the global permission information of the physical page table protection table is not not readable and not writable, and the first physical address is within the boundary range of the physical page table protection table, then read the permission information corresponding to the first physical page table where the first physical address is located.
17. The apparatus according to claim 16, wherein, the protection flow table entry further includes third control information, and the third control information is used to indicate the protection granularity of the physical page table protection table; the processor is further configured to determine the first physical page table where the first physical address is located according to the boundary range and the protection granularity of the physical page table protection table.
18. The apparatus according to claim 16 or 17, wherein, the protection flow table entry further includes fourth control information, and the fourth control information is used to indicate whether to enable the function of checking the memory access permission for the data flow; the processor is further configured to determine that the function of checking the memory access permission for the data flow is enabled according to the fourth control information.
19. The apparatus according to any one of claims 12 to 18, wherein, the communication interface is further configured to: receive the identifier of the data flow of the first device, the first physical address, and the permission information for the first device to access the first physical address from the translation proxy unit; the processor is further configured to: if the permission information corresponding to the first physical page table where the first physical address is located exists in the protection table cache corresponding to the data flow, and the permission information corresponding to the first physical page table in the protection table cache is inconsistent with the permission information for the first device to access the first physical address received from the translation proxy unit, then update the physical page table protection table corresponding to the data flow and the permission information corresponding to the first physical page table in the protection table cache according to the permission information for the first device to access the first physical address received from the translation proxy unit.
20. The apparatus according to claim 19, wherein, the processor is further configured to: if the permission information corresponding to the first physical page table where the first physical address is located does not exist in the protection table cache corresponding to the data flow, then use the permission information for the first device to access the first physical address received from the translation proxy unit as the permission information corresponding to the first physical page table where the first physical address is located, and write it into the physical page table protection table corresponding to the data flow and / or the protection table cache respectively.
21. The apparatus according to any one of claims 12 to 20, wherein, the communication interface is further configured to: Receive page table invalidation information from the page table management module, where the page table invalidation information includes the identifier of the data stream of the first device and the identifier of one or more physical page tables that are invalidated. The processor is further configured to: Update the permission information corresponding to the one or more physical page tables that are invalidated in the protection table cache corresponding to the data stream and the physical page table protection table to be unreadable and unwritable.
22. The apparatus according to any one of claims 12 to 20, wherein, The communication interface is further configured to: Receive page table invalidation information from the page table management module, where the page table invalidation information includes the identifier of the data stream of the first device and the indication information for globally invalidating the physical page tables related to the data stream; The processor is further configured to: Set the global permission information of the physical page table protection table corresponding to the data stream stored in the protection flow table entry corresponding to the identifier of the data stream in the protection flow table to be unreadable and unwritable.
23. A computing device, wherein, The communication device includes: A memory for storing instructions; At least one processor for calling and running the instructions from the memory, so that the communication device implements the method according to any one of claims 1 to 11.
24. A computer-readable storage medium, wherein, The computer-readable storage medium stores a computer program, and when the computer program runs on a computer, the computer is caused to execute the method according to any one of claims 1 to 11.
25. A computer program product, wherein, The computer program product includes a computer program, and when the computer program runs on a computer, the computer is caused to execute the method according to any one of claims 1 to 11.