Extracting area identifier for address based on instruction
By determining the current area identifier based on the instruction extraction address in the memory security circuit of the data processing system, dynamically defining the permissions of the memory access request, the problem of insufficient definition of the source permissions of the access request in the prior art is solved, and the integrity of the memory and the integrity of the control process are realized.
Patent Information
- Application Number
- CN202380073702.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-02
- Filing Date
- 2023-09-27
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art is difficult to effectively define permissions based on the source of memory access requests in data processing systems, resulting in the integrity of the control process and the integrity of other parts of the memory.
The current area identifier is determined based on a predetermined slice of the instruction extract address in the memory security circuit, and then the authorization information of the request issued in response to the instruction associated with the identifier is identified based on the identifier, and whether the request is prohibited.
It realizes dynamic definition of permissions based on the source of memory access requests, ensures the integrity of memory and the integrity of control processes, and avoids the integrity of memory data caused by the integrity of control processes.
Smart Images

Figure CN120077368A_ABST
Abstract
Description
[0001] This technology relates to the field of data processing.
[0002] In a data processing system, instructions can be executed that involve accessing data or instructions in a memory. For example, some instructions can include requests to read or write to a location in the memory, while other instructions can include requests to execute instructions stored at a location in the memory. It can be useful to be able to define permissions for these accesses.
[0003] In view of a first example of the present technology, there is provided an apparatus including:
[0004] an instruction extraction circuit that extracts an instruction associated with an instruction extraction address in response to the instruction extraction address;
[0005] a processing circuit that, in response to the instruction, when the instruction includes a request specifying a target memory address and the request specifying the target memory address is permitted, performs an operation depending on the target memory address; and
[0006] a memory security circuit that, when the instruction includes the request specifying the target memory address:
[0007] determines a current region identifier based on a predetermined slice of the instruction extraction address;
[0008] identifies permission information for a request issued in response to an instruction associated with the current region identifier based on the current region identifier;
[0009] determines whether to prohibit the request based on the permission information; and
[0010] issues a response indicating that the request is prohibited to the processing circuit in response to determining that the request is prohibited.
[0011] In view of another example, there is provided a method including:
[0012] extracting an instruction associated with an instruction extraction address in response to the instruction extraction address; and
[0013] when the instruction includes a request specifying a target memory address:
[0014] performing an operation depending on the target memory address in response to the instruction when the request specifying the target memory address is permitted; and
[0015] determining a current region identifier based on a predetermined slice of the instruction extraction address;
[0016] identifying permission information for a request issued in response to an instruction associated with the current region identifier based on the current region identifier;
[0017] Determine whether to prohibit the request based on the permission information; and
[0018] Issue a response indicating that the request is prohibited in response to determining that the request is prohibited.
[0019] In view of another example, provide a computer program that, when executed on a computer, causes the computer to provide:
[0020] Instruction extraction program logic that extracts an instruction associated with the instruction extraction address in response to the instruction extraction address;
[0021] Handler program logic that, in response to the instruction, executes a request indicating the target memory location when the instruction includes a request specifying a target memory address and the request specifying the target memory address is permitted; and
[0022] Memory security program logic that, when the instruction includes the request specifying the target memory address:
[0023] Determine a current region identifier based on a predetermined slice of the instruction extraction address;
[0024] Based on the current region identifier, identify permission information for a request issued in response to an instruction associated with the current region identifier;
[0025] Determine whether to prohibit the request based on the permission information; and
[0026] In response to determining that the request is prohibited, issue a response indicating that the request is prohibited to the handler program logic.
[0027] In view of another example, provide a computer-readable storage medium for storing the above computer program. The computer-readable storage medium can be a transient storage medium or a non-transient storage medium.
[0028] Further aspects, features, and advantages of the present technology will become apparent from the following example description read in conjunction with the accompanying drawings, in which:
[0029] Figure 1 Schematically illustrate a data processing device;
[0030] Figure 2A And Figure 2B Illustrate an example of permissions defined for a specific address space;
[0031] Figure 3A And Figure 3B Show an example of how instructions in different code regions can be executed;
[0032] Figures 4 to 6Illustrate various examples for determining a spatial region identifier (SRegionID) based on an instruction fetch address;
[0033] Figure 7 Illustrate examples of how read, write, and execute permissions can be defined in a permission table;
[0034] Figure 8 Illustrate examples of circuits that can be used to identify and access one or more permission tables;
[0035] Figure 9 A flowchart illustrating an example of a method that can be performed in response to a issued memory access request;
[0036] Figure 10 A flowchart illustrating an example of how a data processing apparatus can respond to the execution of some branch instructions; and
[0037] Figure 11 Illustrate an emulator implementation that can be used.
[0038] Before discussing example implementations with reference to the accompanying drawings, the following description of example implementations and associated advantages is provided.
[0039] According to an example configuration, a device is provided that includes an instruction fetch circuit that fetches an instruction associated with an instruction fetch address in response to the instruction fetch address. For example, the instruction fetch circuit can fetch an instruction from a memory location indicated by the instruction fetch address (e.g., it can be a virtual address or a physical address). In a particular example, the instruction fetch address can be a program counter (PC) address associated with the instruction.
[0040] The device further includes a processing circuit that, in response to the instruction, when the instruction includes a request specifying a target memory address and the request specifying the target memory address is permitted, performs an operation depending on the target memory address. For example, a load or store instruction specifying a target memory request can include a request to read or write to a target memory location associated with the target memory address, while a branch instruction specifying a target memory address (which can be a function call or a function return instruction in some examples) can include a request to perform a branch to an instruction stored at the target memory location. However, it should be understood that other types of instructions (instructions other than load, store, and branch instructions) can also include such requests.
[0041] Mechanisms that provide protection for data and instructions stored in memory from read and write accesses issued by code regions within a program that are not permitted to access such data / instructions, and that prevent execution branches to certain code regions, can be useful. One way to do this can be to define permissions that depend on the target memory address - such permissions can be defined in a table such as a page table. However, such permissions do not consider the source of the request - the permissions do not define which programs or which parts of a program are permitted to access / branch to which locations in memory. Thus, unless the permissions in the page table are updated, all instructions have the same access permissions to a given memory page. Updating these permissions can incur significant latency as accesses to memory are required, and thus such updates can only be performed between programs, in which case, within any one program (or application), all code within that application generally has equal privilege to read / write / execute data / instruction from any given memory location.
[0042] Another approach can be to additionally include a "permission overlap" or "permission key" mechanism that can dynamically revoke certain permissions based on the programmatic revocation or modification of certain permissions according to CPU registers. For example, if permissions are defined in a page table (for example), there can be several "overlap index" bits in a page table entry. Each page of memory is thus annotated with a "key", and there is a programmable "overlap interpretation" register that can subtract permissions. For example, the overlap interpretation register can indicate changes such as "remove write access from page with index 2" or "switch index 3 from writable to executable".
[0043] However, even this approach only provides a temporal view of permissions: none of the methods defined above consider the source of the access request (e.g., including the instruction that made the request), as the permissions are defined solely from "what was last written to the configuration register?" rather than "what code is currently being executed?". Thus, since the permissions are derived from the current values of the registers and the content currently stored in the page table entries, impaired control flow integrity (for example) can lead to impaired integrity of other parts of memory (e.g., due to a branch to a location where the expected path of the program flow to an unexpected location should have involved an update to the overlap interpretation register or the page table entry, but the overlap interpretation register or the page table entry was not updated).
[0044] To address this problem, the present technique provides a mechanism for permissions that are defined as code-space (e.g., depending on the source of the memory access request) rather than just code-time (e.g., depending on when the request was issued).
[0045] Specifically, the apparatus of the present technology includes a memory security circuit to determine a current region identifier (also referred to as "RegionID") based on a predetermined slice of the instruction fetch address when the instruction includes a request specifying a target memory address. Thus, the RegionID depends on the source of the request (e.g., the instruction) rather than solely on the target of the request (e.g., the target memory address - although it should be understood that the permissions of a particular RegionID may also depend on the target of the memory access). The memory security circuit is configured to identify permission information for a request issued in response to an instruction associated with the current region identifier based on the current region identifier, and determine whether to prohibit the request based on the permission information. The memory security circuit is further configured to issue a response indicating that the request is prohibited to the processing circuit in response to determining that the request is prohibited.
[0046] The RegionID is determined based on the instruction fetch address of an instruction that requests access to / branches to the memory location identified by the target memory address (and optionally also depends on other factors). Thus, since the permission information is looked up based on the RegionID, the memory security circuit determines whether to prohibit a request based on the source of the request. This allows the memory security circuit to enforce fine-grained permissions that depend on a particular location within the program / application represented by the issued request, and maintain the integrity of the code region even in the presence of compromised control flow integrity. Additionally, determining the RegionID based on a slice of the instruction fetch address provides a simple and low-cost mechanism for determining the RegionID, which can avoid the need, for example, to implement an expensive / high-latency table lookup based on the instruction fetch address. It should be noted that if the permission information indicates that the request is allowed, the access request may still be ultimately denied, for example, if it fails any other checks performed by the apparatus.
[0047] The present technology also provides a mechanism for defining different permissions for different instructions, which may be, for example, different parts of a single program or application (e.g., because the permissions depend on the source of the request rather than solely based on the target of the request, or based on values in configuration registers that need to be updated to update the permission groups). Thus, the present technology can be useful, for example, in application programs and in the operating system (OS) kernel for hardening the core security components of software. In the OS kernel, this mechanism can be used, for example, to harden the kernel memory management code and structures against accidental or malicious tampering by other kernel components. It can also be used to sandbox kernel drivers without the performance penalty of delegating these components to discrete programs. The same benefits can be applied within application programs: for example, by protecting the memory allocator library code / structures and / or the dynamic linker code / structures against tampering by the rest of the application program. It can also provide benefits to application programs including sandboxed environments or just-in-time (JIT) environments for handling untrusted input.
[0048] In some examples, the memory security circuit is configured to determine whether to prohibit the request based on the page table access permission information derived from a page table entry associated with the target memory address. In these examples, the memory security circuit is configured to issue the response indicating that the request is prohibited in response to determining that the request is prohibited based on at least one of the permission information and the page table permission information.
[0049] While defining permissions based on the source of the request is advantageous for the reasons set forth above, the present technique can be particularly effective if, in addition to providing the page table access permissions defined in the page table, these permissions that depend on the target memory address specified by the request are also provided. In such examples, if the permissions defined with respect to the RegionID differ from the permissions defined by the page table entry based on the target memory address, the memory security circuit is configured to consider the more restrictive permissions as correct (e.g., by issuing the response that the request is prohibited if one of the one or two sets of permissions indicates that the request is prohibited).
[0050] In some examples, the memory security circuit is configured to determine a source region identifier corresponding to the memory region storing the instruction based on a predetermined slice of the instruction fetch address, and determine the current region identifier depending on the source region identifier.
[0051] As explained above, the current region identifier depends on the instruction fetch address. In this example, this dependency is represented by the source region identifier (also referred to as the spatial region identifier (SRegionID)), which corresponds to the memory region storing the instruction (and thus corresponds to the address space region including the instruction fetch address).
[0052] In some examples, the processing circuit determines the current source region identifier in response to a return space identifier instruction identifying a destination register and stores the current source region identifier in the destination register.
[0053] This provides, for example, a mechanism by which a shared program library can identify which code regions call (branch to) it. It should be noted that the return space identifier instruction can be a dedicated instruction, or it can be a modification of an existing instruction - for example, the current source region identifier can be stored in a system register field, and the return space identifier instruction can be an instruction that reads the field of the system register.
[0054] In some examples, the apparatus includes a register to store a current time identifier, where the memory security circuit is configured to determine the current region identifier depending on the source region identifier and the current time identifier, and the current time identifier is looked up independently of the instruction fetch address. In these examples, the processing circuit sets the current time identifier to a predetermined value in response to detecting an instruction having a given source region identifier different from the source region identifier associated with a previous instruction.
[0055] In addition to the spatial component (e.g., the source region identifier), the current region identifier in this example also has a time component (e.g., based on the current time region identifier TRegionID), and this identifier is forced to a predetermined value (e.g., this may be zero) in response to a change in the source region identifier. This approach provides additional security against compromised control flow integrity because branching to a different code region forces the time region identifier to a predetermined value that can (e.g.) be associated with a set of predetermined permissions.
[0056] In some examples, the apparatus includes a configuration register to store slice identification information indicative of the predetermined slice of the instruction fetch address.
[0057] The use of bits of the instruction fetch address for the predetermined slice may be hardwired (e.g., not software configurable) in some examples. However, in this example, the predetermined slice is identified by the slice identification information stored in the configuration register. This configuration register may be made software accessible, allowing the slice identification information to be configured by software.
[0058] The manner of representing the slice identification information is not particularly limited. For example, it may be represented as an indication of the first and last bit positions (i.e., the most significant and least significant bit positions) of the instruction fetch address to be used for the predetermined slice (e.g., if bits 44:38 of the instruction fetch address are to be used, the slice identification information may identify bit positions 44 and 38). Alternatively, the configuration register may store an indication of either the first or last bit position of the slice and the number of bits in the slice (e.g., in the example of using bits 44:38, either bit position 44 or bit position 38 may be identified, and the number of bits in the slice may be indicated as 7).
[0059] In some examples, the memory security circuit determines the source region identifier to be a default source region identifier in response to determining that another slice of the instruction fetch address has a value different from a predetermined value.
[0060] It can be used to identify another slice of the instruction fetch address and use this slice to provide additional information related to the source region identifier. For example, if this other slice holds a specific value (or a value other than some predetermined values), it can be determined that the default source region identifier will be used. This provides additional flexibility in associating which regions of memory with which source region identifiers. For example, this method can be used to require region identification to occur only for specific larger regions of the address space, such that (for example) an application can operate using the "surrounding" address space that it carves out several regions from (e.g., with a default source region identifier of zero). This allows a set of small address space regions to be selected for sandboxing within a program / application, while most of the address space is used for any less trusted components within the application. Using the other slice as a mask to provide this surrounding address space incurs only a small hardware cost, as it is a simple mask that can be applied at the front end of the microarchitecture, meaning that the source region identifier can be informed to the rest of the device (e.g., the CPU pipeline) in advance.
[0061] In the above example, the manner in which the source region identifier is determined using a predetermined slice of the instruction is not particularly limited. However, in a specific example, the predetermined slice can be directly used as the source region identifier. This provides a method that requires less complex circuitry than alternative methods such as using the predetermined slice to indirectly determine the identifier (e.g., by applying some function to the predetermined slice, or using the predetermined slice to look up a storage structure to determine the source region identifier). However, the disadvantage of directly using the predetermined slice as the source region identifier can be lower flexibility in associating which regions or memories are assigned to which source region identifiers.
[0062] In some examples, the instruction fetch address includes a virtual address, the instruction fetch circuit is configured to fetch the instruction depending on a given portion of the instruction fetch address, the given portion of the instruction fetch address indicating the location where the instruction is stored in memory, wherein the given portion of the instruction fetch address and the predetermined slice of the instruction fetch address overlap by at least one bit.
[0063] In some architectures, a program can use a virtual address to reference a location in memory, and the virtual address can be translated into a physical address that identifies the location in memory. This can allow, for example, the definition of multiple different virtual address spaces each having its own mapping to the physical address space. For example, different programs can have different virtual address spaces.
[0064] This can lead to a situation where multiple different virtual addresses map to the same physical address. For example, if multiple different programs with different virtual address spaces wish to access a given instruction in a shared code library, each may reference the instruction using a different virtual address. This is known as aliasing. However, aliasing can affect the performance of the device - for example, entries in the translation lookaside buffer or instruction cache memory may be indexed and / or tagged by virtual address, meaning that each aliased virtual address will map to a different entry. This can result in multiple copies of the same instruction / translation being stored in separate entries of the cache memory / TLB, occupying space that could otherwise be used to store other instructions.
[0065] One way to address the problem, for example, is by not allowing aliasing - for example, by requiring a given portion of the instruction fetch address to be the same for every virtual address that maps to a particular physical address. However, it can be useful to retain some information in the given portion indicating which program / section of the source code the particular example of the aliased virtual address originated from. To address this, the inventors of the present technique propose allowing one or more bits of the given portion (used to identify the corresponding physical address) to overlap with one or more bits of a predetermined slice (used to determine the source region identifier). For example, while the other bits in the given portion remain the same, these bits can be different for aliased virtual addresses. This allows a structure (such as a cache memory) to look up based on the given portion excluding the overlapping bits, such that only one copy of the instruction from a given physical address is stored in the cache memory, while still retaining information to distinguish aliased addresses.
[0066] In some examples, the memory security circuit is configured to determine whether to prohibit the request based on the privilege information identifying at least one of the following:
[0067] ● Read access privilege;
[0068] ● Write access privilege;
[0069] ● Privilege to execute a branch; and
[0070] ● Privilege to execute a branch without causing a stored return address.
[0071] Thus, the access privilege information can indicate any combination of read, write, and execute instructions, and can further indicate when a branch needs to be executed as a function call (saving the return address).
[0072] In some examples, the memory security circuit is configured to determine a destination region identifier based on the target memory address. In these examples, the memory security circuit includes a table access circuit to look up a permission table in the memory based on the current region identifier and the destination region identifier, where the permission table defines the permission information. Further, in these examples, the table access circuit is configured to support at least one encoding of the permission table, where different permission information is defined for different combinations of the current region identifier and different destination region identifiers.
[0073] In this example, the permission table can be viewed as a two-dimensional table, where the table is looked up based on both the current region identifier (determined depending on the instruction fetch address) and the destination region identifier (determined depending on the target memory address). This allows the permission information to be defined for multiple different combinations of the current region identifier and the target region identifier, such that it can be determined whether the current execution part of the code is allowed to access / branch to a specific memory location indicated by the requested target memory address. This allows access to a specific memory region to be granted to a specific code region or denies access to a specific code region to a specific memory region.
[0074] In some examples, the memory security circuit includes a table access circuit to access a permission table in the memory that defines the permission information, and the device includes a table identification register to store address information indicating the location of the permission table in the memory.
[0075] For example, the address information can be the base address of the table in the memory. The table access circuit uses the address information to locate the table in the memory.
[0076] In some examples, the device is arranged to operate at one of a plurality of privilege levels, and the device includes a plurality of registers, each configured to store address information indicating the location of a corresponding permission table in the memory. In these examples, the device further includes a register selection circuit to select one of the plurality of registers as the permission table identification register based on the current privilege level.
[0077] In this example, a separate permission table can be defined for each privilege level. For example, there can be one register for the kernel and one register for user space. This allows, for example, more restrictive permissions to be defined when the device operates at a lower privilege level.
[0078] In some examples, the memory security circuit includes a table access circuit to access a permission table in memory that defines the permission information, the apparatus includes a register to store a current set of permissions indicating the permission information defined in the permission table for the current region identifier, and the table access circuit responds to determining that the current region identifier has changed to a new region identifier by looking up the permission table based on the new region identifier for an identifier and an updated set of permissions to be stored in the register.
[0079] Thus, the permission information associated with the current region identifier can be loaded into the register in this example such that it can be accessed with reduced latency. Then, each time the current region identifier changes, the permission information in the register can be replaced with an updated set of permissions associated with the new region identifier.
[0080] The format of the register is not particularly limited, but the register can, for example, include a field for each of a plurality of target region identifiers, with each field storing corresponding permission information (e.g., one bit indicating one permission - such as a read bit, a write bit, and an execute bit).
[0081] In some examples, the memory security circuit includes a table access circuit to access a permission table in memory that defines the permission information, and the apparatus includes a cache memory to store a subset of the permissions defined in the permission table. In these examples, the apparatus is configured to operate in one of a plurality of contexts each associated with a context identifier, and the cache memory includes a plurality of entries each associated with a corresponding context identifier.
[0082] Thus, in this example, some of the permission information can be cached such that further access to the permission information can be performed with reduced latency, thus improving performance. Additionally, associating each entry with a context identifier (e.g., this can be a combination of a virtual machine identifier (VMID) and an address space identifier (ASID)) avoids the need to clear the cache memory during a context switch, thus improving performance because the cached data can still be used for access in the future.
[0083] In some examples, the apparatus includes a plurality of registers, the plurality of registers including a register for each of a plurality of current region identifiers to store a set of permissions indicating the permission information for the current region identifier.
[0084] These registers can be provided to replace the permission table in memory, or in addition to the permission table in memory. Although adding additional registers can increase the circuit area occupied by the apparatus, they can be advantageous since such registers can be accessed with reduced latency (thus allowing improvement in the performance of the apparatus).
[0085] Due to the above example, the format of the register is not particularly limited, but each register in the register may, for example, include a field for each target region identifier among a plurality of target region identifiers, and each field stores corresponding access permission information.
[0086] The techniques discussed above may be implemented in a hardware device having circuit hardware that implements the instruction extraction circuit, the processing circuit, and the memory security circuit described above. However, in another example, the same techniques may be implemented in a computer program (e.g., an architecture simulator or model) that may provide an instruction execution environment for controlling a host data processing device to provide for the execution of instructions from object code. In some specific examples, these instructions may include any one of a return space identifier instruction, a time identifier update instruction, a branch and change time identifier instruction, and a branch and hold time identifier instruction.
[0087] The computer program may include instruction extraction program logic to extract instructions from object code, and processing program logic to control a host data processing device to perform data processing in response to the instruction. Thus, the instruction extraction program logic emulates the functionality of the instruction extraction circuit of the hardware device discussed above, and the processing program logic emulates the processing circuit.
[0088] Furthermore, in some examples, some or all of the registers described above may be emulated - specifically, the program may include register maintenance program logic that maintains a data structure (in the memory of the host device or in the architectural registers) that represents (emulates) the architectural registers of the instruction set architecture simulated by the program. The emulated registers may include any one of the multiple registers described in some of the above examples.
[0089] Thus, this simulator computer program may present an instruction execution environment similar to the environment that would be provided by an actual hardware device capable of directly executing the target instruction set for the object code executed on the simulator computer program, even if there may be no actual hardware on the host computer executing the simulator program that provides these features. This can be useful for executing code written for an architecture on a host platform that does not actually support that architecture. Furthermore, the simulator can be useful during the development of software for a new version of an instruction set architecture while software development is being performed in parallel with the development of hardware devices that support the new architecture. This may allow the software to be developed and tested on the simulator so that software development can begin before hardware devices that support the new architecture are available.
[0090] Specific embodiments will now be described with reference to the accompanying drawings.
[0091] Figure 1Schematically illustrated is a data processing apparatus 100 within which an example of the present technology may be implemented. As shown, the data processing apparatus 100 includes an instruction fetch circuit 105 to fetch instructions from a memory (optionally via one or more cache memories). The fetch circuit 105 fetches instructions from memory locations identified by instruction fetch addresses (e.g., these addresses may be memory addresses that define the locations where the instructions are stored in the memory) or from one or more intervening cache memories (not shown). In Figure 1 the example, the instruction fetch address of the next instruction to be fetched by the instruction fetch circuit 105 is held in a program counter (PC) register 110, which is one of a set of registers 115 provided in this example. The PC register 110 identifies the next instruction to be fetched and thus is incremented each time an instruction is fetched (such that it points to the next instruction in program order). The register file 115 also includes other registers, which in this example include a time region identifier register 130 that stores a time region identifier (TRegionID). This will be disclosed in more detail below.
[0092] The instruction fetch circuit 105 provides the instructions to an instruction decode circuit 120, which decodes the instructions and issues control signals to a processing circuit 125 to control the processing circuit 125 to execute the decoded instructions. The processing circuit 125 executes the decoded instructions with reference to data stored in the registers 115 (e.g., the processing circuit may read the operands of a data processing operation from a register and store the result of the data processing operation into a register).
[0093] The processing circuit 125 also issues memory access requests in response to some instructions to access data or instructions stored in the memory. For example, the processing circuit 125 may issue a memory access request to a memory controller (not shown) to load data from the memory into a register or store data from a register into the memory. The processing circuit 125 may also update the value stored in the PC register 110 in response to control flow instructions (such as branch instructions) to change the instruction flow to be fetched by the instruction fetch circuit 105.
[0094] The data processing apparatus in this example further includes a memory security circuit 135, which will be described in more detail below.
[0095] In many modern hardware and software architectures, the read and write permissions for loading or storing data into / from a particular region of memory and the execution permission for fetching instructions from a particular region of memory are controlled by permissions described in a page table (e.g., a multi-level page table) programmed by the operating system and stored in memory. For example, a memory controller or a memory management unit (which controls access to memory in response to memory access requests including requests to load / store data and fetch instructions) may include a page table traversal circuit to access the page table and identify the permissions for a particular access request. Specifically, the page table is looked up based on the target memory address of the access request (e.g., the address of the data or instruction to be accessed) to identify the relevant permissions. Thus, such access permissions are defined based on the target of the access request rather than on the instruction represented by the issued access request.
[0096] In a general data processing device, within any one program (or application), all code within that application has equal privilege to read / write / execute any memory in its address space. For example, different instructions within a given program generally have the same permissions. As explained above, some architectures additionally include a "permission overlap" or "permission key" mechanism that can dynamically revoke certain permissions based on the programming of CPU registers that allow the revocation or modification of certain permissions. For example, page table entries can use these overlap bits / keys, and the programming of the CPU registers can indicate (e.g.) that a given permission should be revoked for any page associated with a certain key value (e.g., "revoke read access for permission key 2"). This allows the modification of access permissions defined in the page table, but only provides a temporal view of the permissions. The inventors of the present technology have recognized that, for example, if there is a compromise in control flow integrity (e.g., if control flow branches are allowed to an unexpected code region), this can lead to potential problems.
[0097] Figures 2 to 3 assist in illustrating how this problem can occur. Specifically, Figure 2A and Figure 2B illustrate examples of permissions that may be desired to be defined for a particular address space 200. As shown, different portions of code ("code 1", "code 2", and "code 3") and different data ("data A" and "data B") may be stored in different regions of the address space. Each of these different regions may have different read / write access permissions, which may additionally depend on what code is being executed at any particular point in time. For example, as Figure 2A shown, instructions fetched from code region 1 (code 1) may have read (R) and write (W) access to the data in data region A (data A) (e.g., the permission to load data from it and store data to it), but no access to the data stored in data region B (data B). At the same time, code region 3 (code 3) may have read-only (RO) access to data region A and read and write access to data region B.
[0098] Similarly, as Figure 2B shown, each code region may have different execution access permissions (e.g., defining whether instructions from a given code section are allowed to branch to instructions in a different code section). For example, in this example, instructions from code region 1 are allowed to branch to instructions in code regions 2 and 4 (code 4), while instructions from code region 3 are allowed to branch to instructions in code region 2 but not to instructions in code region 4.
[0099] It may be expected that the privilege overlap mechanism defined above may be used when executing these privileges, e.g., by changing the content of the overlap interpretation register when switching from one code region. However, as will be explained with reference to Figure 3A and Figure 3B below, this mechanism is less effective in cases where control flow integrity is compromised.
[0100] Figure 3A and Figure 3B show examples of how instructions from different code regions can be executed. Figure 3A shows an example of the expected instruction flow. As shown, before switching from code region 3 to code region 1, an instruction is executed to update the configuration register such that the access permissions defined by the page table in combination with the overlap bits are updated. After this update, an instruction from code region 1 (instruction C) is executed, causing the processing circuit to issue an access request to read data in region B. However, the permissions in the configuration register and the page table in combination with the overlap bits indicate that read access to data region B is prohibited, and thus the access request is rejected.
[0101] However, Figure 3B illustrates how compromised control flow integrity can lead to compromised data integrity. For example, Figure 3B shows what may happen if an instruction from code region 3 unexpectedly branches to an instruction in code region 1. In this case, with the configuration register not updated, instruction A is branched to instruction C. This means that when instruction C is executed, the permissions defined by the configuration register in combination with the page table are still the same as those for code region 3. Instructions from code region 3 are allowed read and write access to data region A, and thus read access to data region B is allowed. Therefore, due to compromised control flow integrity, the integrity or confidentiality of the data stored in data region B may be compromised. In other words, the integrity / confidentiality of the data stored in data region B depends on the maintenance of control flow integrity.
[0102] This technique provides a mechanism to solve this problem. Specifically, this technique defines a source region identifier (also referred to as a spatial region identifier, SRegionID) for the instruction fetch address of an instruction that depends on accessing a specific memory location (whether it is a read, write, or execute access). This allows the access permission information to depend on the source of the access request, rather than only depending on the destination of the access request and / or the timing definition of the access request.
[0103] For example, Figure 4 illustrates how a spatial region identifier (SRegionID) can be determined based on the instruction fetch address (which can be obtained from the PC register). The spatial region identifier can be determined by the memory security circuit 135 in response to a memory access request issued by the processing circuit.
[0104] In Figure 4 a 64-bit instruction fetch address is shown, although it should be understood that this is only an example - the instruction fetch address can have an implementation-dependent size, although the example shown in Figure 4 may be more applicable to architectures that employ a larger address width, such as 64 bits or greater. The spatial region identifier is determined based on a selected portion of the instruction fetch address, where some state (e.g., registers) 400 in the memory security circuit 135 indicates which bits of the instruction fetch address will be used. For example, the state 400 in the memory security circuit can indicate the first and last bit positions of the portion to be used, or the first / last bit positions and size of the portion. In an alternative example, the portion of the instruction fetch address to be used can be hardwired rather than programmable in a configuration register.
[0105] Figure 4 An example of the general format of a 64-bit PC is shown in "A". The figure also shows three examples (B, C, D) of the portion of the instruction fetch address that is used to derive or be the spatial region identifier. In all four examples, the instruction fetch address includes several regular / tag bits and useful VA (virtual address) bits that define the location where the instruction is stored in memory. Examples B, C, and D each include a portion (SRegionID) used to derive the spatial region identifier. It should be noted that although the examples show using a virtual instruction fetch address to determine the spatial region identifier, a physical address can alternatively be used.
[0106] The first example (A) shows an example of a general instruction fetch address. The regular / tag bits occupy bit positions 63:49 of the instruction fetch address, and the remaining bits 48:0 are all useful VA bits.
[0107] In a second example (B), the same bits 63:49 are used as regular / tag bits, but bits 44:38 are used to derive a spatial region identifier. In this example, additional constants that may provide additional information are defined in bit positions 48:45. For example, a memory security circuit may be arranged to determine that a default spatial region identifier should be used when the constants have certain values. This leaves bits 37:0 to define useful VA bits.
[0108] In a third example (C), again the same bits 63:49 are used as regular / tag bits, but bits 48:45 are used to derive a spatial region identifier. This leaves bits 44:0 to define useful VA bits.
[0109] In a fourth example (D), bit positions 63:55 are used to derive a spatial region identifier, where the number of regular / tag bits is reduced to occupy bit positions 54:49. This leaves bits 48:0 to define useful VA bits.
[0110] In all examples B through D, the selection of bits of the instruction fetch address is used to determine the spatial region identifier such that the spatial region identifier depends on the source of the memory access request (e.g., depends on the instruction fetch address of the instruction that caused the memory access request to be issued), rather than depending on the destination of the memory access request (e.g., the target address of the data or instruction to be accessed). The manner in which the selected bits are used to determine the spatial region identifier is not particularly limited. In some examples, the selected bits may be directly used as the spatial region identifier, while in other examples, the selected bits may be mapped to the spatial region identifier by the memory security circuit in some other way.
[0111] In some examples, the SRegionID portion and the useful VA bits may overlap by a few bits (e.g., a few bits are used to determine the SregionID and to determine the location where the instruction is stored in memory). As explained above, in cases where software is forced to maintain all other VA bit constants between alias virtual addresses, this can provide a mechanism for differentiating between alias virtual addresses. Additionally, the useful VA bits may include all of the SRegionID bits in some examples.
[0112] In some examples, the architecture may support multiple techniques for determining the SRegionID based on the instruction fetch address. For example, two or more of the methods shown in Figure 4 may be supported. For example, the PC bit register 400 may be configurable such that the bits to be processed as SRegionID slices are programmable.
[0113] Additionally, in addition to supporting the determination of the SRegionID using slices of the instruction fetch address, the architecture may support additional mechanisms. This can provide additional flexibility to chip designers using the architecture. For example, Figure 5Shows another method for determining a spatial region identifier. Specifically, as Figure 5 shown, the memory security circuit 135 includes a register set 500 that maps different regions of an address space (e.g., virtual or physical) to region identifiers. In the Figure 5 specific example shown, a pair of registers is provided for each of the plurality of spatial region identifiers, the pair of registers including a base address register 505 that identifies the base address of the corresponding region in memory and a size register 510 that identifies the size of the corresponding region in memory. In this example, the memory security circuit is arranged to compare all or part of the instruction fetch address with the base address and size indicated by the registers to determine within which of the regions the instruction fetch address falls. The spatial region identifier then corresponds to the identification of that region.
[0114] It should be noted that the size of each region can be indicated as, for example, the number of bits in the memory of the corresponding region, the number of pages in the memory region, the number of bits of the base address that are masked off as part of the region identification or as the end address of the region in memory.
[0115] Figure 6 Shows another additional mechanism that can be supported in the architecture. In this example, the memory security circuit 135 includes a table access circuit (also referred to as an SRegionID table access circuit, a spatial region identifier table access circuit, or a source region identifier table access circuit) 600. The SRegionID table access circuit looks up a table in memory 605 based on the instruction fetch address of the instruction that caused the memory access request to be issued in response to a memory access request. The table 610 defines the mapping of spatial region identifiers to instruction fetch addresses.
[0116] When a table in memory is used to define the mapping of instruction fetch addresses to spatial region identifiers, as in the Figure 6 example shown, the memory security circuit may also include one or more cache memories to cache data from the table in memory.
[0117] Thus, the spatial region identifier depends on the source of the memory access and can therefore also be referred to as a source region identifier. A set of memory access permissions (e.g., read / write permissions) can then be defined that depend on the spatial region identifier (and optionally can also depend on the target address of the memory access). Such permissions can be defined in addition to those defined in the page table.
[0118] Additionally, while much of the discussion above focuses on permissions defined for memory access (e.g., loading and storing data or instructions to / from memory), it should be understood that execution permissions can also be defined depending on the spatial region identifier - for example, the spatial region identifier of a branch instruction can be used to determine whether the branch is allowed.
[0119] The access permission may further depend on a time region identifier (TRegionID) that can be stored in Figure 1 the time identifier register 130 shown. This register may be software-accessible, in which case the time region identifier may be updated by an instruction executed by the processing circuit. In a particular example, a region identifier (RegionID) is defined as a concatenation of a spatial region identifier (SRegionID) and a time region identifier (TRegionID).
[0120] Figure 7 An example is shown of how read, write, and execute permissions can be defined based on the region identifier. In this particular example, the access permission for a given memory access request or branch request is defined for each combination of several combinations of the current region identifier (e.g., the concatenation of the spatial region identifier of the requesting instruction and the current time region identifier) and the target region identifier (e.g., the concatenation of the spatial region identifier of the target address and the current time identifier). Thus, Figure 7 the table shown in can be regarded as a two-dimensional (2D) table because it is looked up by both the current region identifier and the target region identifier.
[0121] In the table, "RW" indicates that read and write access is allowed, "RO" indicates that read access is allowed but write access is not allowed, "X" indicates that a branch is allowed, and "XL" indicates a function call (a branch that saves the return address to, e.g., a link register) rather than other types of branches. A dash "-" indicates that access is not allowed.
[0122] This table (which may be referred to as a permission table, for example) may be stored in memory. For example, the table may be a single table, or it may be a multi-level table. In some examples, the branch and function call permissions ("X" and "XL") may be defined in a separate table or bit map, where the permission table only defines read and write permissions.
[0123] Figure 8 An example is shown of how one or more permission tables can be identified and accessed (e.g., Figure 7An example of a circuit of the table shown in []. In this example, the memory security circuit 135 includes a privilege table access circuit 800 to access the privilege table 805 in the memory 605. The base address in the privilege table is defined in a set of registers 810. In this particular example, it is assumed that the data processing device can operate at any one of three privilege levels, and a table is defined for each privilege level. Therefore, registers 815 are provided to store the base address of each table in the memory, and the privilege table access circuit accesses the privilege table based on the base address stored in the corresponding register. The memory security circuit in this example also includes one or more privilege table cache memories 820 arranged to cache a subset of the contents of the privilege table. The entries in the privilege table cache memory can be tagged by a virtual machine identifier (VMID) and an address space identifier (ASID), such that the cache memory does not need to be cleared every time there is a context switch. Alternatively, the cache memory can be tagged by some alternative context identifier.
[0124] In Figure 8 the example shown, only some of the circuits that may exist in the memory security circuit 135 are shown. It should be understood that the memory security circuit in this example may also include circuits such as the SRegionID table access circuit 600, the SRegionID register 500, or the PC bit register shown in other figures. Further, although this example assumes that the data processing device can operate at multiple different privilege levels, this is not necessary.
[0125] Figure 9 A flowchart illustrating an example of a method that can be performed by a data processing device in response to a memory access request issued. It should be noted that a similar method can also be performed in response to the execution of a branch instruction.
[0126] As shown in the figure, the method includes step 900 of reading the current time region identifier from the TRegionID register and step 905 of determining the current spatial region identifier (SRegionID) of the instruction fetch address for an instruction that, based thereon, incurs the issuance of a memory access request. The method further includes step 910 of determining a target spatial region identifier (i.e., the spatial region identifier corresponding to the target of the access request) based on the target address of the memory access request. Having determined the current time region identifier and the current spatial identifier, the method includes step 915 of determining the current region identifier (RegionID) based on the current spatial region identifier and the time region identifier (e.g., as explained above, the RegionID can be a concatenation of the SRegionID and the TRegionID). Furthermore, the method includes step 920 of determining a target region identifier (RegionID) based on the target spatial region identifier and the current time region identifier. Having determined the current region identifier and the target region identifier, the method includes step 925 of looking up a permission table based on these two identifiers – for example, this can be a lookup in a table such as Figure 7 shown in the figure.
[0127] Figure 10 For another flowchart, an example is shown in this case of how a data processing apparatus can respond to the execution of a branch instruction. Specifically, in some examples, the data processing apparatus can be arranged to set the time region identifier to zero (or some other default value) when the execution of a branch instruction causes a change in the spatial region identifier (SRegionID) (e.g., when the branch instruction is associated with one spatial region identifier and the target of the branch instruction is associated with a different spatial region identifier). This helps to maintain control flow integrity.
[0128] Specifically, Figure 10 the method shown in the figure includes step 1000 of determining whether to execute a branch instruction. When it is determined that the branch instruction has been executed, the method includes step 1005 of determining whether the execution of the branch instruction has caused a change in the spatial region identifier. When it is determined that this is the case, the time region identifier is set 1010 to zero.
[0129] Figure 11Illustrates an available simulator implementation. Although earlier implementations of the invention were implemented as devices and methods for operating specific processing hardware that supports the technology of interest, it is also possible to provide an instruction execution environment according to the implementations described herein, which is implemented by using a computer program. Such computer programs are often referred to as simulators because they provide software-based implementations of hardware architectures. Types of simulator computer programs include emulators, virtual machines, models, and binary translators (including dynamic binary translators). Generally, a simulator implementation can run on a host processor 1330 that optionally runs a host operating system 1320 and supports a simulator program 1310. In some configurations, there can be multiple layers of simulation between the hardware and the provided instruction execution environment and / or between different instruction execution environments provided on the same host processor. Historically, powerful processors have been required to provide simulator implementations that execute at a reasonable speed, but this approach can be justified in certain cases, such as when it is necessary to execute code native to another processor due to compatibility or reuse reasons. For example, a simulator implementation can provide an instruction execution environment with additional functionality not supported by the host processor hardware, or provide an instruction execution environment generally associated with a different hardware architecture. A review of simulation is given in "Some Efficient Architecture Simulation Techniques", Robert Bedichek, Winter 1990 USENIX Conference, pages 53 to 63.
[0130] In cases where implementations have been previously described with reference to a specific hardware architecture or feature, in a simulation implementation, equivalent functionality can be provided by a suitable software architecture or feature. For example, a specific circuit can be implemented as computer program logic in a simulation implementation. In Figure 11 the example shown, an instruction fetch program logic 1340 is provided, which provides the same functionality as the instruction fetch circuit of the previous example. Additionally, a processing program logic 1350 is provided, which provides the same functionality as the processing circuit described above, and a memory security program logic 1360 is provided, which provides the functionality of the memory security circuit in the above example. Similarly, memory hardware (such as registers or caches) can be implemented as software data structures in a simulation implementation. In a configuration where one or more of the hardware elements mentioned in the previously described implementations exist on the host hardware (e.g., host processor 1330), some simulation implementations can utilize the host hardware as appropriate.
[0131] The simulator program 1310 can be stored on a computer-readable storage medium (which can be a non-transitory medium) and provides a program interface (instruction execution environment) to the object code 1300 (which can include an application program, an operating system, and a hypervisor), and the program interface is the same as the interface of the hardware architecture modeled by the simulator program 1310. Therefore, the program instructions of the object code 1300, including the instructions, branch instructions, function call instructions, and function return instructions that need to issue memory access requests as described above, can be executed using the simulator program 1310 within the instruction execution environment, so that the host computer 1330 that actually does not have the hardware features of the device 100 discussed above can simulate these features.
[0132] In this application, the term "configured to..." is used to mean that an element of a device has a configuration capable of performing the defined operation. In this context, "configuration" means the configuration or manner of interconnection of hardware or software. For example, the device may have dedicated hardware that provides the defined operation, or a processor or other processing device may be programmed to perform the function. "Configured to" does not mean that the device element needs to be changed in any way to provide the defined operation.
[0133] Further, the phrase "comprising at least one of..." in this application is used to mean any one of the following options or any combination of the following options. For example, "at least one of the following: A; B; and C" is intended to mean A or B or C or any combination of A, B, and C (e.g., A and B or A and C or B and C).
[0134] Although the illustrative embodiments of the present invention have been described in detail herein with reference to the accompanying drawings, it should be understood that the present invention is not limited to the precise embodiments, and various changes and modifications can be made by those skilled in the art without departing from the scope of the present invention as defined by the appended claims.
Claims
1. An apparatus, the apparatus comprising: an instruction fetch circuit that fetches an instruction associated with the instruction fetch address in response to the instruction fetch address; a processing circuit that, in response to the instruction, when the instruction includes a request specifying a target memory address and the request specifying the target memory address is permitted, performs an operation depending on the target memory address; and a memory security circuit that, when the instruction includes the request specifying the target memory address: determines a current region identifier based on a predetermined slice of the instruction fetch address; identifies permission information of a request issued in response to an instruction associated with the current region identifier based on the current region identifier; determines whether to prohibit the request based on the permission information; and issues a response indicating that the request is prohibited to the processing circuit in response to determining that the request is prohibited.
2. The apparatus according to claim 1, wherein the memory security circuit is configured to: determine whether to prohibit the request based on page table access permission information derived from a page table entry associated with the target memory address; and issue the response indicating that the request is prohibited in response to determining that the request is prohibited based on at least one of the permission information and the page table permission information.
3. The apparatus according to claim 1 or claim 2, wherein the memory security circuit is configured to determine a source region identifier corresponding to a memory region storing the instruction based on the predetermined slice of the instruction fetch address, and determine the current region identifier depending on the source region identifier.
4. The apparatus according to claim 3, wherein the processing circuit determines a current source region identifier in response to a return space identifier instruction identifying a destination register and stores the current source region identifier in the destination register.
5. The apparatus according to claim 3 or claim 4, the apparatus comprising a register for storing a current time identifier, wherein the memory security circuit is configured to determine the current region identifier depending on the source region identifier and the current time identifier, and the current time identifier is looked up independently of the instruction fetch address; and the processing circuit sets the current time identifier to a predetermined value in response to detecting an instruction having a given source region identifier different from a source region identifier associated with a previous instruction.
6. The apparatus according to any one of the preceding claims, the apparatus comprising a configuration register for storing slice identification information indicating the predetermined slice of the instruction fetch address.
7. The apparatus according to any one of the preceding claims, wherein the memory security circuit determines the source region identifier as a default source region identifier in response to determining that another slice of the instruction fetch address has a value different from a predetermined value.
8. The apparatus according to any one of the preceding claims, wherein: the instruction fetch address includes a virtual address; The instruction fetch circuit is configured to fetch the instruction depending on a given portion of the instruction fetch address, the given portion of the instruction fetch address indicating the location where the instruction is stored in the memory; and the given portion of the instruction fetch address and a predetermined slice of the instruction fetch address overlap by at least one bit.
9. The apparatus according to any one of the preceding claims, wherein the memory security circuit is configured to determine whether to prohibit the request based on the privilege information identifying at least one of the following: read access privilege; write access privilege; privilege to execute a branch; and privilege to execute a branch without causing a stored return address.
10. The apparatus according to any one of the preceding claims, wherein: the memory security circuit is configured to determine a destination region identifier based on the target memory address; the memory security circuit includes a table access circuit to look up a privilege table in the memory based on the current region identifier and the destination region identifier, the privilege table defining the privilege information; and the table access circuit is configured to support at least one encoding of the privilege table, wherein different privilege information is defined for different combinations of the current region identifier and different destination region identifiers.
11. The apparatus according to any one of the preceding claims, wherein: the memory security circuit includes a table access circuit to access a privilege table in the memory that defines the privilege information; and the apparatus includes a table identification register to store address information indicating the location of the privilege table in the memory.
12. The apparatus according to claim 11, wherein: the apparatus is arranged to operate at one of a plurality of privilege levels; and the apparatus includes: a plurality of registers, each of the plurality of registers being configured to store address information indicating the location of a corresponding privilege table in the memory; and a register selection circuit to select, based on the current privilege level, one of the plurality of registers as the privilege table identification register.
13. The apparatus according to any one of the preceding claims, wherein: the memory security circuit includes a table access circuit to access a privilege table in the memory that defines the privilege information; and the apparatus includes a register to store a current set of privileges that define the privilege information in the privilege table for the current region identifier; and the table access circuit, in response to determining that the current region identifier has changed to a new region identifier, looks up the privilege table based on the new region identifier to identify an updated set of privileges to be stored in the register.
14. The apparatus according to any one of the preceding claims, wherein: the memory security circuit includes a table access circuit to access a privilege table in the memory that defines the privilege information; the apparatus includes a cache memory to store a subset of the privileges defined in the privilege table; the apparatus is configured to operate in one of a plurality of contexts each associated with a context identifier; and the cache memory includes a plurality of entries each associated with a corresponding context identifier.
15. The apparatus according to any one of the preceding claims, the apparatus comprising a plurality of registers, the plurality of registers including a register for each of a plurality of current region identifiers to store a set of permissions indicating the permissions information of the current region identifier.
16. A method, the method comprising extracting an instruction associated with the instruction extraction address in response to the instruction extraction address ; and when the instruction includes a request specifying a target memory address: performing an operation depending on the target memory address in response to the instruction when the request specifying the target memory address is permitted; determining a current region identifier based on a predetermined slice of the instruction extraction address; identifying the permissions information of a request issued in response to an instruction associated with the current region identifier based on the current region identifier; determining whether to prohibit the request based on the permissions information; and issuing a response indicating that the request is prohibited in response to determining that the request is prohibited.
17. A computer program which, when executed on a computer, causes the computer to provide: instruction extraction program logic that extracts an instruction associated with the instruction extraction address in response to the instruction extraction address; processing program logic that performs an operation depending on the target memory address in response to the instruction when the instruction includes a request specifying a target memory address and the request specifying the target memory address is permitted; and memory security program logic that, when the instruction includes the request specifying the target memory address: determines a current region identifier based on a predetermined slice of the instruction extraction address; identifies the permissions information of a request issued in response to an instruction associated with the current region identifier based on the current region identifier; determines whether to prohibit the request based on the permissions information; and issues a response indicating that the request is prohibited to the processing program logic in response to determining that the request is prohibited.
18. A computer-readable storage medium for storing the computer program according to claim 17.
Citation Information
Cited By
Instruction prediction method and device, electronic equipment, storage medium and product
CN121635965A