Chip hardware resource configuration method, chip and vehicle
By generating a hardware resource configuration interface and updating configuration content, the problem of low efficiency in configuring vehicle cockpit chip hardware resources was solved, and efficient and accurate permission and firewall status management was achieved.
Patent Information
- Application Number
- CN202510153105.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-11
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-02-11
AI Technical Summary
The hardware resource configuration of vehicle cockpit chips is inefficient and prone to errors, which may cause problems for the vehicle.
By generating a hardware resource configuration interface, the operation permissions and firewall status of hardware domains and hardware resources are determined, and the configuration content is updated based on configuration instructions. The target configuration information is generated and stored on the hardware platform, avoiding manual configuration.
It improves the efficiency and accuracy of hardware resource configuration and reduces the possibility of configuration errors.
Smart Images

Figure CN120085935B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of chip design and manufacturing, and in particular to a method for configuring hardware resources of a chip, a chip, and a vehicle. Background Technology
[0002] The cockpit chip in a vehicle is different from a simple chip. The resources associated with this cockpit chip are too complex. Moreover, since a single chip may contain a large number (possibly hundreds) of hardware resources, and each hardware resource corresponds to multiple hardware domains, when using hardware resources, users need to manually configure the operation permissions of hardware resources by referring to relevant manuals. This is inefficient and prone to errors, which may cause problems for the vehicle. Summary of the Invention
[0003] The purpose of this application is to provide a method for configuring hardware resources of a chip, a chip, and a vehicle. This method can efficiently and accurately determine the operation permissions of the chip's hardware domains for various related hardware resources.
[0004] To achieve this objective, embodiments of this application provide a method for configuring hardware resources of a chip, including:
[0005] The hardware resources associated with the hardware domain of the chip are identified, and a corresponding hardware resource configuration interface is generated based on the hardware resources. The hardware domain is a set of hardware components, each containing at least one processor core. The hardware resource configuration interface includes at least a first dimension information, a second dimension information, and a configuration content section. The first dimension information indicates each hardware resource. The second dimension information includes hardware domain information associated with the hardware resource and firewall information for the hardware resource. The configuration content section indicates the operation permissions of each hardware domain for each hardware resource, and the firewall status corresponding to each hardware resource. The operation permissions include at least one of the following: support permissions, user permissions, privileged permissions, non-security permissions, security permissions, write permissions, and read permissions.
[0006] Upon receiving configuration instructions for the hardware resource configuration interface, based on the configuration instructions, the operation permissions of each hardware domain for each hardware resource, as well as the corresponding firewall status of each hardware resource, are redefined and the configuration content is updated.
[0007] Based on the operation permissions and the firewall status, generate the corresponding target configuration information;
[0008] The application project information of the chip corresponding to the target configuration information is determined. The target configuration information and the application project information are associated to generate a corresponding target file, and the target file is stored on the hardware platform corresponding to the application project information.
[0009] Optionally, generating a corresponding hardware resource configuration interface based on the hardware resources includes:
[0010] Based on the identification information of the hardware resources, the first dimension information is determined;
[0011] The second dimension information is determined based on the hardware domain information and firewall information associated with the hardware resources.
[0012] Based on the first dimension information, the second dimension information, and the default configuration strategy, the hardware resource configuration interface is generated; or...
[0013] The hardware resource configuration interface is generated based on the first dimension information, the second dimension information, and the original configuration information.
[0014] Optionally, multiple permission groups are set for the hardware resources, each permission group including at least one permission item. The step of re-determining the operation permissions of each hardware domain for each hardware resource, and the corresponding firewall status of each hardware resource, based on the configuration instructions, includes:
[0015] Based on the configuration instructions, the permission groups for each hardware resource in each hardware domain are determined, wherein the permission types of each permission item in the same permission group are the same or similar.
[0016] Display the instruction information for each permission item in the determined permission group, and determine the operation permission based on the permission group.
[0017] Optionally, the configuration content portion includes a permission selection form for each of the hardware resources, and correspondingly, the configuration instructions include instructions generated in response to operations on the permission selection form.
[0018] Optionally, the permission configuration includes configuration information representing the hardware domain to which the hardware resource belongs, wherein the priority of the hardware domain's operation permission for the hardware resource within the domain is higher than the priority of other hardware domains' operation permission for the same hardware resource.
[0019] Optionally, the configuration instructions include firewall configuration sub-instructions. The step of re-determining the operation permissions of each hardware domain for each hardware resource, and the corresponding firewall status of each hardware resource, based on the configuration instructions, includes:
[0020] Based on the firewall configuration sub-instruction, the enabling status of the firewall corresponding to each hardware resource is set;
[0021] Accordingly, the method further includes: when the firewall corresponding to the hardware resource is enabled, blocking unauthorized manipulation of the hardware resource by other hardware domains that are not to which the resource belongs through the firewall.
[0022] Optionally, the application project information is used to indicate the application project of the chip, the application project having a corresponding hardware platform. The steps of determining the application project information of the chip corresponding to the target configuration information, associating the target configuration information and the application project information to generate a corresponding target file, and storing the target file on the hardware platform corresponding to the application project information include:
[0023] Based on the application project information, determine the hardware development board for the chip;
[0024] The target file is burned onto the hardware development board.
[0025] Alternatively, the method may further include:
[0026] When using the hardware platform, retrieve the target file stored therein;
[0027] Based on the target file, determine the permission configuration of each hardware domain for each hardware resource, as well as the corresponding firewall status of each hardware resource.
[0028] This application also provides a chip, including:
[0029] A generation module is configured to determine the hardware resources associated with the hardware domain of the chip and generate a corresponding hardware resource configuration interface based on the hardware resources. The hardware domain is a set of hardware components, each containing at least one processor core. The hardware resource configuration interface includes at least first-dimensional information, second-dimensional information, and configuration content. The first-dimensional information indicates each hardware resource. The second-dimensional information includes hardware domain information associated with the hardware resource and firewall information for the hardware resource. The configuration content indicates the operation permissions of each hardware domain for each hardware resource, and the firewall status corresponding to each hardware resource. The operation permissions include at least one of the following: support permissions, user permissions, privileged permissions, non-security permissions, security permissions, write permissions, and read permissions.
[0030] The configuration module is configured to, upon receiving a configuration instruction for the hardware resource configuration interface, redetermine the operation permissions of each hardware domain for each hardware resource, as well as the corresponding firewall status of each hardware resource, and update the configuration content portion based on the configuration instruction; and generate corresponding target configuration information based on the operation permissions and the firewall status.
[0031] The storage module is configured to determine the application project information of the chip corresponding to the target configuration information, associate the target configuration information and the application project information to generate a corresponding target file, and store the target file on the hardware platform corresponding to the application project information.
[0032] This application also provides a vehicle equipped with the chip described above, which is capable of configuring hardware resources associated with the chip's hardware domain.
[0033] The hardware resource configuration method of the chip in this application embodiment avoids the need for users to manually configure hardware resource operation permissions by referring to relevant manuals, thereby improving the efficiency and accuracy of configuring and using hardware resources. Attached Figure Description
[0034] Figure 1 This is a flowchart illustrating a method for configuring the hardware resources of a chip according to an embodiment of this application.
[0035] Figure 2 Examples of embodiments of this application Figure 1 A flowchart of one embodiment of step S100;
[0036] Figure 3 Examples of embodiments of this application Figure 1 A flowchart of one embodiment of step S200;
[0037] Figure 4 Examples of embodiments of this application Figure 1 A flowchart of one embodiment of step S400;
[0038] Figure 5 This is a schematic diagram of the hardware resource configuration interface in an embodiment of this application;
[0039] Figure 6 This is a schematic diagram of the permission selection form corresponding to the owner of the hardware resources in this application embodiment;
[0040] Figure 7 This is a schematic diagram of the permission selection form corresponding to the information security domain Secure in this embodiment of the application.
[0041] Figure 8This is a structural block diagram of the chip according to an embodiment of this application.
[0042] Explanation of reference numerals in the attached figures
[0043] 10 - First-dimensional information; 20 - Second-dimensional information; 30 - Configuration content section. Detailed Implementation
[0044] Various embodiments and features of this application are described herein with reference to the accompanying drawings.
[0045] It should be understood that various modifications can be made to the embodiments described herein. Therefore, the above description should not be considered as limiting, but merely as an example of embodiments. Other modifications within the scope and spirit of this application will be apparent to those skilled in the art.
[0046] The accompanying drawings, which are included in and form part of this specification, illustrate embodiments of the present application and, together with the general description of the present application given above and the detailed description of the embodiments given below, serve to explain the principles of the present application.
[0047] These and other features of this application will become apparent from the following description of preferred forms of embodiments given as non-limiting examples, with reference to the accompanying drawings.
[0048] It should also be understood that although this application has been described with reference to some specific examples, those skilled in the art can certainly implement many other equivalent forms of this application.
[0049] The above and other aspects, features and advantages of this application will become more apparent when taken in conjunction with the accompanying drawings and in view of the following detailed description.
[0050] Specific embodiments of this application are described thereafter with reference to the accompanying drawings; however, it should be understood that the claimed embodiments are merely examples of this application, which can be implemented in various ways. Well-known and / or repeated functions and structures are not described in detail to avoid unnecessary or redundant details that could obscure the application. Therefore, the specific structural and functional details claimed herein are not intended to be limiting, but merely serve as the basis and representative basis for the claims to teach those skilled in the art to use this application in a variety of substantially any suitable detailed structures.
[0051] This specification may use the phrases “in one embodiment,” “in another embodiment,” “in yet another embodiment,” or “in other embodiments,” all of which may refer to one or more of the same or different embodiments according to this application.
[0052] This application discloses a method for configuring hardware resources of a chip, applicable to a chip, such as a system-on-chip (SoC) for automotive applications. The chip contains various types of hardware resources, such as memory, PCIe, and DCI. Multiple hardware domains are configured within the chip, such as AP1, AP2, safety, and secure. Each hardware domain contains a specific set of hardware resources and can independently support the operation of an operating system. A hardware domain can have high read and write permissions on the hardware resources within its domain, but it can also have certain permissions on the hardware resources of other hardware domains.
[0053] The method will be explained in detail below with reference to the accompanying drawings. Figure 1 This is a flowchart of a method for configuring the hardware resources of a chip according to an embodiment of this application, as shown below. Figure 1 and Figure 5 As shown, the method includes the following steps:
[0054] S100: Determine the hardware resources associated with the hardware domain of the chip, and generate a corresponding hardware resource configuration interface based on the hardware resources. The hardware domain is a set of hardware components, each containing at least one processor core. The hardware resource configuration interface includes at least a first dimension information 10, a second dimension information 20, and a configuration content portion 30. The first dimension information 10 indicates each hardware resource. The second dimension information 20 includes hardware domain information associated with the hardware resource and firewall information for the hardware resource. The configuration content portion 30 indicates the operation permissions of each hardware domain for each hardware resource, and the firewall status corresponding to each hardware resource. The operation permissions include at least one of the following: support permissions, user permissions, privileged permissions, non-security permissions, security permissions, write permissions, and read permissions.
[0055] For example, a chip may include multiple hardware domains, each of which is a set of hardware and contains at least one processor core. A chip may also contain a large number of hardware resources.
[0056] Hardware resources associated with a hardware domain include hardware within that hardware domain, as well as hardware from other hardware domains. The hardware resources associated with a hardware domain can be determined based on the identity information of all hardware resources in the chip and / or the resource information of the hardware contained in each hardware domain. A corresponding hardware resource configuration interface is then generated based on these hardware resources.
[0057] In one embodiment, the hardware resource configuration interface may be the hardware resource configuration interface associated with the application project of the chip. Different application projects may have different hardware resource configuration interfaces.
[0058] The hardware resource configuration interface is used to configure the operation permissions of hardware resources associated with hardware domains. Specifically, it can configure the operation permissions of each hardware domain of the chip for that hardware resource. These operation permissions include at least one of the following: support permissions, user permissions, privileged permissions, non-secure permissions, secure permissions, write permissions, and read permissions. Support permissions (Y) can be operation permissions that support all hardware domains; user permissions (U) can refer to different levels of access and control capabilities granted to different users or processes when accessing and using various hardware resources within the chip; privileged permissions (P) are equivalent to Privilege permissions; non-secure permissions (N) indicate that no operation permissions are assigned, and combined protection N represents Non-Secure permissions; secure permissions (S) are Secure permissions for the chip's hardware resources; write permissions (W) are Write permissions for writing data to hardware resources; and read permissions (R) are Read permissions for reading data from hardware resources.
[0059] In one embodiment, such as Figure 5 As shown, the hardware resource configuration interface includes at least first-dimensional information 10, second-dimensional information 20, and configuration content 30. First-dimensional information 10 indicates each hardware resource. For example, first-dimensional information 10 can be part of the row information in the hardware resource configuration interface, indicating all hardware resources associated with hardware domains in the chip, with each row indicating one hardware resource. Second-dimensional information 20 can be part of the column information in the hardware resource configuration interface, including hardware domain information associated with the hardware resources, such as the names of all hardware domains in the chip. Furthermore, second-dimensional information 20 also includes firewall information for the hardware resources, indicating the firewalls associated with each hardware resource.
[0060] Regarding the configuration content section 30 in the hardware resource configuration interface, on the one hand, it indicates the operation permissions of each hardware domain for each hardware resource. This includes the different operation permissions of each hardware domain for each hardware resource. For example, the first hardware domain has support permissions and user permissions for the first hardware resource, while the second hardware domain may have privileged permissions and security permissions for the same first hardware resource. On the other hand, the configuration content section 30 also indicates the firewall status corresponding to each hardware resource. That is, it indicates the enabled status of the firewall corresponding to each hardware resource. For example, the firewall corresponding to the first hardware resource is indicated as enabled, while the firewall corresponding to the second hardware resource is indicated as disabled.
[0061] In one embodiment, the content in the hardware resource configuration interface can be adjusted according to the needs of specific application scenarios, such as adjusting the order, position, presentation, and color of the content. No limitations are imposed here.
[0062] S200, upon receiving the configuration instructions for the hardware resource configuration interface, based on the configuration instructions, re-determine the operation permissions of each hardware domain for each hardware resource, as well as the firewall status corresponding to each hardware resource, and update the configuration content section 30.
[0063] For example, the hardware resource configuration interface can be manipulated to generate corresponding configuration instructions to operate on hardware resource access permissions and corresponding firewalls.
[0064] Configuration commands can be triggered in various ways. On one hand, users can generate corresponding configuration commands by operating the hardware resource configuration interface as needed. This includes users operating the hardware resource configuration interface through relevant input devices, such as clicking, selecting, and inputting, thereby generating the corresponding configuration commands.
[0065] On the other hand, configuration instructions can also be generated based on system preset strategies. For example, in the first application scenario of the chip, a first configuration instruction is generated to configure the hardware resource configuration interface, and in the second application scenario of the chip, a second configuration instruction is generated to configure the hardware resource configuration interface.
[0066] On the other hand, the configuration command can also be received via a network. For example, the operator can send a configuration command to the chip via the network to control the hardware resource configuration interface.
[0067] The hardware resource configuration interface displays the original content, such as the default content or the content after the last configuration. Based on configuration commands, the operation permissions of each hardware domain for each hardware resource can be redefined. For example, for a first hardware resource, multiple hardware domains can be configured to perform operation permissions for that first hardware resource; similarly, multiple hardware domains can be configured to perform operation permissions for a second hardware resource.
[0068] Configuration commands can also be used to redetermine the firewall status of each hardware resource. Specifically, the firewall status for each hardware resource can be adjusted. For example, the firewall status for the first hardware resource can be changed from enabled to disabled, and the firewall status for the second hardware resource can be changed from disabled to enabled.
[0069] After configuring the hardware resource configuration interface according to the configuration commands, the configuration content section 30 of the hardware resource configuration interface is updated and displayed. This allows users to more intuitively view the information displayed on the current hardware resource configuration interface.
[0070] S300: Based on the operation permissions and the firewall status, generate the corresponding target configuration information.
[0071] For example, data related to operation permissions and firewall status can be combined and packaged to generate corresponding target configuration information. This target configuration information can represent all content in the hardware resource configuration interface, including first-dimensional information 10, second-dimensional information 20, and configuration content section 30. The generated target configuration information is easy to operate and process.
[0072] S400, determine the application project information of the chip corresponding to the target configuration information, associate the target configuration information and the application project information to generate a corresponding target file, and store the target file on the hardware platform corresponding to the application project information.
[0073] For example, the operating permissions and firewall status of hardware resources are associated with specific application projects of the chip, and different application projects may have different operating permissions and firewall statuses. The application project information of the chip corresponding to the target configuration information can be determined based on user needs and / or the chip's usage scenario. Application project information characterizes the identity and usage requirements of the chip's application project, including the application project's name, purpose, and usage time limit.
[0074] The target configuration information corresponds to the identified application project information. That is, the chip's hardware resource operation permissions and firewall status are adapted to the application project indicated in the application project information. For example, the first target configuration information is adapted to the first application project information, and the second target configuration information is adapted to the second application project information. After associating the target configuration information and application project information, a corresponding target file is generated. The target file records the association relationship between the target configuration information and the application project information. The target file is stored on the hardware platform corresponding to the application project information. The hardware platform can be hardware used to support the application project, such as a hardware development board for developing the application project, or hardware devices for implementing the application project. This hardware platform can install the chip, thereby accessing the hardware domains and associated hardware resources within the chip.
[0075] When users utilize this hardware platform to support application projects, they can access the target files stored within it. After parsing these files, they can obtain the chip's application project information and its corresponding target configuration information, which can be displayed through the hardware resource configuration interface. Users no longer need to reconfigure the chip's hardware resources; they can quickly determine the hardware domain's operational permissions for each hardware resource and the firewall status corresponding to each hardware resource, thus improving configuration efficiency.
[0076] The hardware resource configuration method of the chip in this application embodiment avoids the need for users to manually configure hardware resource operation permissions by referring to relevant manuals, thereby improving the efficiency and accuracy of configuring and using hardware resources.
[0077] In one embodiment of this application, the step of generating a corresponding hardware resource configuration interface based on the hardware resources is as follows: Figure 2 As shown, it includes the following steps:
[0078] S110, based on the identification information of the hardware resources, determine the first dimension information 10.
[0079] For example, the identification information of hardware resources can be the serial number or name of the hardware resources. In the hardware resource configuration interface, this identification information can be expressed in various forms such as numbers and characters, making it convenient for users to view and perform related operations. The first dimension information 10 can be a part of the row information in the hardware resource configuration interface. Based on the identification information of all hardware resources in the hardware resource configuration interface, the first dimension information 10 is determined. The first dimension information 10 indicates all hardware resources in the chip that are related to the hardware domain.
[0080] S120, based on the hardware domain information and firewall information associated with the hardware resources, determine the second dimension information 20.
[0081] For example, the second dimension information 20 can be a portion of the column information in the hardware resource configuration interface, including information about various hardware domains and firewalls. Hardware domain information includes the hardware domain name and hardware resource indication information, such as the names of hardware domains like the first application domain AP1, the second application domain AP2, the functional safety domain (safety), the information security domain (Secure), and the multiprocessor domain (mP). Hardware resource indication information includes the ID number, hardware category, and hardware resource name. Firewall information can include the firewall name, etc. Based on the hardware domain information and firewall information, the second dimension information 20 can be determined. Of course, both the first dimension information 10 and the second dimension information 20 can be adjusted according to the user's needs regarding the layout and changes in the hardware resource configuration interface, thus more flexibly adapting to user needs.
[0082] S130, the hardware resource configuration interface is generated based on the first dimension information 10, the second dimension information 20, and the default configuration strategy; or, the hardware resource configuration interface is generated based on the first dimension information 10, the second dimension information 20, and the original configuration information.
[0083] For example, the default configuration policy is the default configuration for hardware resources related to hardware domains in the chip. This default configuration policy can be used to configure hardware resources before receiving other configuration instructions. For instance, the default configuration of operation permissions for hardware resources and the corresponding firewall states for each hardware resource are implemented before the chip leaves the factory. In one embodiment, the default configuration policy indicates the configuration content section 30 of the default hardware resource configuration interface.
[0084] The original configuration information can be the configuration information generated after the last configuration of the hardware resources, or the configuration information generated after the initial configuration of the hardware resources. For example, the original configuration information is generated after the user performed a configuration operation on the hardware resource configuration interface last time. In one embodiment, the original configuration policy indicates the configuration content section 30 of the previous hardware resource configuration interface.
[0085] In this embodiment, a hardware resource configuration interface can be generated based on the first dimension information 10, the second dimension information 20, and the default configuration strategy. Alternatively, it can also be generated based on the first dimension information 10, the second dimension information 20, and the original configuration information. This satisfies different user needs for the hardware resource configuration interface.
[0086] In one embodiment of this application, multiple permission groups are set for the hardware resources, and each permission group includes at least one permission item. On one hand, permission items with the same or similar permission types can be set to the same group. On the other hand, permission items with opposing or mutually exclusive permission types can be set to the same group. Alternatively, multiple permission groups can be formed based on user-defined settings for each hardware resource.
[0087] Based on the configuration instructions, the operation permissions of each hardware domain for each hardware resource, and the corresponding firewall status of each hardware resource are redefined, such as... Figure 3 As shown, it includes the following steps:
[0088] S210, based on the configuration instructions, determine the permission group for each hardware resource in each hardware domain, wherein the permission types of each permission item in the same permission group are the same or similar.
[0089] S220, display the indication information of each permission item in the determined permission group, and determine the operation permission based on the permission group.
[0090] For example, setting up permission groups facilitates the categorization and configuration of numerous operation permissions for hardware resources, further improving configuration efficiency. When configuring operation permissions for each hardware resource in a hardware domain, at least one permission must be configured for each permission group to prevent misconfiguration of operation permissions. A permission group includes at least one permission item, and the permission types of all permission items within the same permission group are the same or similar.
[0091] The hardware resource configuration interface can display the name or identifier of each permission item in each permission group. For example, the drop-down menu corresponding to the permission group can display the instruction information (such as name or identifier) of each permission item. Users can select the name or identifier of each permission item to determine the operation permissions for that hardware resource.
[0092] For example, such as Figure 7 As shown, the operation permissions for hardware resources include:
[0093] • Y: Supports all permissions
[0094] ·U: User Permissions
[0095] •P:Privilege permissions
[0096] • N: Selecting N alone means no operation permissions are assigned; selecting N in combination with other protections means Non-Secure permissions.
[0097] • S:Secure permissions
[0098] •W:Write permission
[0099] • R:Read permission
[0100] Each of the above-mentioned operation permissions is a permission item, while U / P can be a permission group, N / S can be a permission group, and W / R can be a permission group. When configuring accessible operation permissions, at least one operation permission must be configured for each permission group; otherwise, the configuration will be invalid.
[0101] In the hardware resource configuration interface, the permission settings in section 30 can be set to Y or N by default unless there are specific requirements. Furthermore, operation permission configurations also support combinations, as shown in Table 1 below:
[0102]
[0103]
[0104]
[0105] Table 1
[0106] In one embodiment of this application, the configuration content portion 30 includes a permission selection form for each of the hardware resources, and correspondingly, the configuration instructions include instructions generated in response to operations on the permission selection form.
[0107] For example, such as Figure 6 and Figure 7 As shown, the configuration content section 30 of the hardware resource configuration interface includes a permission selection form for each hardware resource. This permission selection form allows users to select operation permissions and firewall status. For example, users can select operation permissions for the corresponding hardware resource from the permission selection form, such as by clicking or entering information, to select one or more operation permissions and firewall status, thereby generating corresponding configuration instructions. Based on these configuration instructions, the chip can determine the configuration of operation permissions for each hardware resource in each hardware domain, as well as the corresponding firewall status of each hardware resource, and update the configuration content section 30 to display the latest content.
[0108] In one embodiment of this application, the permission configuration includes configuration information representing the hardware domain to which the hardware resource belongs, wherein the hardware domain has higher operation permissions for hardware resources within the domain than other hardware domains have higher operation permissions for the same hardware resource.
[0109] For example, the second dimension information 20 includes hardware resource ownership information (such as owner), and the corresponding configuration content portion 30 has the name of the hardware domain to which the hardware resource belongs. A hardware resource belongs to a hardware domain; that is, all hardware resources within a hardware domain belong to that hardware domain. However, other hardware domains can also use hardware resources within the same hardware domain. For example, a first hardware domain includes a first hardware resource, which is a resource within that first hardware domain, and a second hardware domain can also use that first hardware resource. In this embodiment, the priority of a hardware domain's operation permissions on hardware resources within its domain is higher than the priority of other hardware domains' operation permissions on that hardware resource. For example, the priority of a first hardware domain's operation permissions on its first hardware resource within its domain is higher than the priority of a second hardware domain's operation permissions on the first hardware resource. For instance, when a first hardware domain uses its first hardware resource within its domain for read / write operations, a second hardware domain cannot call upon that first hardware resource for read / write operations.
[0110] In one embodiment of this application, the configuration instruction includes a firewall configuration sub-instruction. The step of re-determining the operation permissions of each hardware domain for each hardware resource, and the corresponding firewall status of each hardware resource, based on the configuration instruction, includes:
[0111] Based on the firewall configuration sub-instruction, the enabling status of the firewall corresponding to each hardware resource is set;
[0112] Accordingly, the method further includes: when the firewall corresponding to the hardware resource is enabled, blocking unauthorized manipulation of the hardware resource by other hardware domains that are not to which the resource belongs through the firewall.
[0113] For example, each hardware resource corresponds to a firewall, which can be configured to be enabled or disabled according to firewall configuration sub-instructions. These firewall configuration sub-instructions can also be generated in various ways, such as through user operation or system presets. For instance, a user can select permissions from the firewall permission selection form displayed in the hardware resource configuration interface, thereby generating corresponding firewall configuration sub-instructions to set the enabling / disabling status of the firewall corresponding to the hardware resource.
[0114] In one embodiment of this application, the firewall corresponding to the hardware resource is implemented based on the hardware resource's access control list (ACL) and stateful inspection technology. When the firewall of the hardware resource is set to the enabled state, the firewall can filter access requests to the hardware resource according to the rules in the ACL. For illegal manipulation requests from outside the hardware domain, the firewall intercepts them by blocking the data transmission channel, sending alarm signals, etc., and records illegal access logs. At the same time, it works in conjunction with the hardware domain's permission management module to ensure that operations within the scope of legal permissions are not affected.
[0115] In one embodiment of this application, the application project information is used to indicate the application project of the chip. The application project has a corresponding hardware platform. The process involves determining the application project information of the chip corresponding to the target configuration information, associating the target configuration information and the application project information to generate a corresponding target file, and storing the target file on the hardware platform corresponding to the application project information. Figure 4 As shown, it includes:
[0116] S410, Based on the application project information, determine the hardware development board for the chip.
[0117] For example, a hardware development board is the hardware that supports the operation of a chip, such as the hardware required during the development, testing, or use of the chip. Application project information indicates the application project of the chip, and the application project has a corresponding hardware platform; therefore, the corresponding hardware development board for the chip can be determined based on the application project information.
[0118] S420, burn the target file onto the hardware development board.
[0119] For example, burning the target file onto a hardware development board can solidify the target file onto the board, such as by solidifying it onto the board's storage medium. This makes it easy to save the target file and prevents it from being easily modified. When needed, the target file can be quickly retrieved from the hardware development board.
[0120] Preferably, the method further includes the following steps:
[0121] When using the hardware platform, retrieve the target file stored therein;
[0122] Based on the target file, determine the permission configuration of each hardware domain for each hardware resource, as well as the corresponding firewall status of each hardware resource.
[0123] For example, when the hardware platform starts up, the relevant systems on the hardware platform can automatically retrieve the target file from the storage medium of the hardware development board according to a preset file directory structure and filename rules. The retrieved target file is then verified for integrity and legality, such as through CRC checksum and digital signature verification. After successful verification, the chip's parsing module parses the configuration information in the target file, sets the operation permissions for hardware resources and firewall status for each hardware domain according to the parsing results, and monitors the validity of permissions and firewall status in real time during operation. If any anomalies are detected, adjustments and repairs are made promptly.
[0124] This application also provides a chip, such as... Figure 8 As shown, it includes:
[0125] A generation module is configured to determine the hardware resources associated with the hardware domain of the chip and generate a corresponding hardware resource configuration interface based on the hardware resources. The hardware domain is a set of hardware components, each containing at least one processor core. The hardware resource configuration interface includes at least a first dimension information 10, a second dimension information 20, and a configuration content portion 30. The first dimension information 10 indicates each of the hardware resources. The second dimension information 20 includes hardware domain information associated with the hardware resource and firewall information for the hardware resource. The configuration content portion 30 indicates the operation permissions of each hardware domain for each hardware resource, and the firewall status corresponding to each hardware resource. The operation permissions include at least one of the following: support permissions, user permissions, privileged permissions, non-security permissions, security permissions, write permissions, and read permissions.
[0126] For example, a chip may include multiple hardware domains, each of which is a set of hardware and contains at least one processor core. A chip may also contain a large number of hardware resources.
[0127] The hardware resources associated with a hardware domain include hardware within that hardware domain, as well as hardware from other hardware domains. The generation module can determine the hardware resources associated with the chip's hardware domains based on the identity information of all hardware resources in the chip and / or the resource information of the hardware contained in each hardware domain. A corresponding hardware resource configuration interface is then generated based on these hardware resources.
[0128] In one embodiment, the hardware resource configuration interface may be the hardware resource configuration interface associated with the application project of the chip. Different application projects may have different hardware resource configuration interfaces.
[0129] The hardware resource configuration interface is used to configure the operation permissions of hardware resources associated with hardware domains. Specifically, it can configure the operation permissions of each hardware domain of the chip for that hardware resource. These operation permissions include at least one of the following: support permissions, user permissions, privileged permissions, non-secure permissions, secure permissions, write permissions, and read permissions. Support permissions (Y) can be operation permissions that support all hardware domains; user permissions (U) can refer to different levels of access and control capabilities granted to different users or processes when accessing and using various hardware resources within the chip; privileged permissions (P) are equivalent to Privilege permissions; non-secure permissions (N) indicate that no operation permissions are assigned, and combined protection N represents Non-Secure permissions; secure permissions (S) are Secure permissions for the chip's hardware resources; write permissions (W) are Write permissions for writing data to hardware resources; and read permissions (R) are Read permissions for reading data from hardware resources.
[0130] In one embodiment, the hardware resource configuration interface includes at least first-dimensional information 10, second-dimensional information 20, and configuration content 30. The first-dimensional information 10 indicates various hardware resources. For example, the first-dimensional information 10 may be a portion of the row information in the hardware resource configuration interface, indicating all hardware resources associated with hardware domains in the chip, with each row indicating one hardware resource. The second-dimensional information 20 may be a portion of the column information in the hardware resource configuration interface, including hardware domain information associated with the hardware resources, such as the names of all hardware domains in the chip. Furthermore, the second-dimensional information 20 also includes firewall information for the hardware resources, indicating the firewalls associated with each hardware resource.
[0131] Regarding the configuration content section 30 in the hardware resource configuration interface, on the one hand, it indicates the operation permissions of each hardware domain for each hardware resource. This includes the different operation permissions of each hardware domain for each hardware resource. For example, the first hardware domain has support permissions and user permissions for the first hardware resource, while the second hardware domain may have privileged permissions and security permissions for the same first hardware resource. On the other hand, the configuration content section 30 also indicates the firewall status corresponding to each hardware resource. That is, it indicates the enabled status of the firewall corresponding to each hardware resource. For example, the firewall corresponding to the first hardware resource is indicated as enabled, while the firewall corresponding to the second hardware resource is indicated as disabled.
[0132] In one embodiment, the content in the hardware resource configuration interface can be adjusted by the generation module according to the needs of specific application scenarios, such as adjusting the order, position, presentation, and color of the content. No limitations are imposed here.
[0133] The configuration module is configured to, upon receiving a configuration instruction for the hardware resource configuration interface, redetermine the operation permissions of each hardware domain for each hardware resource, as well as the corresponding firewall status of each hardware resource, and update the configuration content portion 30 based on the configuration instruction; and generate corresponding target configuration information based on the operation permissions and the firewall status.
[0134] For example, the hardware resource configuration interface can be operated to generate corresponding configuration instructions, so that the configuration module can operate on the hardware resource operation permissions and the corresponding firewall.
[0135] Configuration commands can be triggered in various ways. On one hand, users can generate corresponding configuration commands by operating the hardware resource configuration interface as needed. This includes users operating the hardware resource configuration interface through relevant input devices, such as clicking, selecting, and inputting, thereby generating the corresponding configuration commands.
[0136] On the other hand, configuration instructions can also be generated based on system preset strategies. For example, in the first application scenario of the chip, a first configuration instruction is generated to configure the hardware resource configuration interface, and in the second application scenario of the chip, a second configuration instruction is generated to configure the hardware resource configuration interface.
[0137] On the other hand, the configuration command can also be received via a network. For example, the operator can send a configuration command to the chip via the network to control the hardware resource configuration interface.
[0138] The hardware resource configuration interface displays the original content, such as the default content or the content after the last configuration. Based on configuration commands, the configuration module can redefine the operation permissions of each hardware domain for each hardware resource. For example, for a first hardware resource, multiple hardware domains can be configured to grant operation permissions for that first hardware resource; similarly, for a second hardware resource, multiple hardware domains can be configured to grant operation permissions for that second hardware resource.
[0139] Based on configuration commands, the configuration module can also redetermine the firewall status corresponding to each hardware resource. Specifically, the firewall status for each hardware resource can be adjusted. For example, the firewall status for the first hardware resource can be changed from enabled to disabled, and the firewall status for the second hardware resource can be changed from disabled to enabled.
[0140] Based on the configuration instructions, the configuration module configures the hardware resource configuration interface accordingly, then updates and displays the configuration content section 30 of the hardware resource configuration interface. This allows users to more intuitively view the information displayed on the current hardware resource configuration interface.
[0141] Furthermore, the configuration module can combine and package relevant data on operation permissions and firewall status to generate corresponding target configuration information. This target configuration information can represent all content in the hardware resource configuration interface, including first-dimensional information 10, second-dimensional information 20, and configuration content section 30. The generated target configuration information is easy to operate and process.
[0142] The storage module is configured to determine the application project information of the chip corresponding to the target configuration information, associate the target configuration information and the application project information to generate a corresponding target file, and store the target file on the hardware platform corresponding to the application project information.
[0143] For example, the operating permissions and firewall status of hardware resources are associated with specific application projects of the chip, and different application projects may have different operating permissions and firewall statuses. The application project information of the chip corresponding to the target configuration information can be determined based on user needs and / or the chip's usage scenario. Application project information characterizes the identity and usage requirements of the chip's application project, including the application project's name, purpose, and usage time limit.
[0144] The target configuration information corresponds to the determined application project information. That is, the chip's hardware resource operation permissions and firewall status are adapted to the application project indicated in the application project information. For example, the first target configuration information is adapted to the first application project information, and the second target configuration information is adapted to the second application project information. The storage module associates the target configuration information and application project information to generate a corresponding target file, which records the association between the target configuration information and the application project information. The storage module stores the target file on the hardware platform corresponding to the application project information. The hardware platform can be hardware used to support the application project, such as a hardware development board for developing the application project, or hardware devices for implementing the application project. This hardware platform can install the chip, thereby accessing the hardware domains and associated hardware resources within the chip.
[0145] When users utilize this hardware platform to support application projects, they can access the target files stored within it. After parsing these files, they can obtain the chip's application project information and its corresponding target configuration information, which can be displayed through the hardware resource configuration interface. Users no longer need to reconfigure the chip's hardware resources; they can quickly determine the hardware domain's operational permissions for each hardware resource and the firewall status corresponding to each hardware resource, thus improving configuration efficiency.
[0146] In one embodiment of this application, the generation module is further configured as follows:
[0147] Based on the identification information of the hardware resources, the first dimension information 10 is determined;
[0148] Based on the hardware domain information and firewall information associated with the hardware resources, the second dimension information 20 is determined;
[0149] Based on the first dimension information 10, the second dimension information 20, and the default configuration strategy, the hardware resource configuration interface is generated; or...
[0150] The hardware resource configuration interface is generated based on the first dimension information 10, the second dimension information 20, and the original configuration information.
[0151] In one embodiment of this application, multiple permission groups are set for the hardware resources, and each permission group includes at least one permission item. The configuration module is further configured as follows:
[0152] Based on the configuration instructions, the permission groups for each hardware resource in each hardware domain are determined, wherein the permission types of each permission item in the same permission group are the same or similar.
[0153] Display the instruction information for each permission item in the determined permission group, and determine the operation permission based on the permission group.
[0154] In one embodiment of this application, the configuration content portion 30 includes a permission selection form for each of the hardware resources, and correspondingly, the configuration instructions include instructions generated in response to operations on the permission selection form.
[0155] In one embodiment of this application, the permission configuration includes configuration information representing the hardware domain to which the hardware resource belongs, wherein the priority of the hardware domain's operation permission for the hardware resource within the domain is higher than the priority of other hardware domains' operation permission for the same hardware resource.
[0156] In one embodiment of this application, the configuration instruction includes a firewall configuration sub-instruction, and the configuration module is further configured as follows:
[0157] Based on the firewall configuration sub-instruction, the enabling status of the firewall corresponding to each hardware resource is set;
[0158] Accordingly, when the firewall corresponding to the hardware resource is enabled, the firewall blocks unauthorized manipulation of the hardware resource by other hardware domains that do not belong to it.
[0159] In one embodiment of this application, the application item information is used to indicate the application item of the chip, the application item has a corresponding hardware platform, and the storage module is further configured as follows:
[0160] Based on the application project information, determine the hardware development board for the chip;
[0161] The target file is burned onto the hardware development board.
[0162] In one embodiment of this application, the chip further includes a calling module, which is configured as follows:
[0163] When using the hardware platform, retrieve the target file stored therein;
[0164] Based on the target file, determine the permission configuration of each hardware domain for each hardware resource, as well as the corresponding firewall status of each hardware resource.
[0165] This application also provides a vehicle equipped with the chip described above, which is capable of configuring hardware resources associated with the chip's hardware domain.
[0166] This application also provides an electronic device, as shown in the figure, including a processor and a memory, wherein the memory stores an executable program, and the memory executes the executable program to perform the steps of the method described above.
[0167] This application also provides a storage medium carrying one or more computer programs, which, when executed by a processor, implement the steps of the method described above.
[0168] It should be understood that in the embodiments of this application, the processor may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0169] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).
[0170] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) is integrated into the processor.
[0171] It should be noted that the memories described herein are intended to include, but are not limited to, these and any other suitable types of memories.
[0172] It should also be understood that the first, second, third, fourth and various numerical designations used herein are merely for descriptive convenience and are not intended to limit the scope of this application.
[0173] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.
[0174] In implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software. The steps of the method disclosed in the embodiments of this application can be directly implemented by a hardware processor, or by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are omitted here.
[0175] In the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0176] Those skilled in the art will recognize that the various illustrative logical blocks (ILBs) and steps described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0177] In the several embodiments provided in this application, it should be understood that the disclosed methods and chips can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.
[0178] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0179] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0180] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.
[0181] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method of configuring hardware resources of a chip, the method comprising: receiving a configuration file; and configuring the hardware resources of the chip based on the configuration file. The method comprises the following steps: determining hardware resources associated with hardware domains of a chip, and generating a corresponding hardware resource configuration interface based on the hardware resources, wherein the hardware domains are hardware sets and each of the hardware sets comprises at least one processor core, the hardware resource configuration interface comprises at least first dimension information, second dimension information and a configuration content part, the first dimension information indicates each of the hardware resources, the second dimension information comprises hardware domain information associated with the hardware resources and firewall information for the hardware resources, the configuration content part is used to indicate operation permissions of each of the hardware domains for each of the hardware resources and respective firewall states of the hardware resources, and the operation permissions comprise at least one of the following: support permission, user permission, privilege permission, non-secure permission, secure permission, write permission and read permission; in the case that a configuration instruction for the hardware resource configuration interface is obtained, the operation permissions of each of the hardware domains for each of the hardware resources and the respective firewall states of the hardware resources are re-determined based on the configuration instruction, and the configuration content part is updated; target configuration information is generated based on the operation permissions and the firewall states; application project information of the chip corresponding to the target configuration information is determined, the target configuration information and the application project information are associated to generate a corresponding target file, and the target file is stored in a hardware platform corresponding to the application project information.
2. The method of claim 1, wherein, The method of generating the hardware resource configuration interface based on the hardware resources comprises the following steps: the first dimension information is determined based on identification information of the hardware resources; the second dimension information is determined based on hardware domain information associated with the hardware resources and firewall information; the hardware resource configuration interface is generated based on the first dimension information, the second dimension information and a default configuration strategy; or the hardware resource configuration interface is generated based on the first dimension information, the second dimension information and original configuration information.
3. The method of claim 1, wherein, A plurality of permission groups are set for the hardware resources, each of the permission groups comprises at least one permission item, and the operation permissions of each of the hardware domains for each of the hardware resources and the respective firewall states of the hardware resources are re-determined based on the configuration instruction, which comprises the following steps: the permission groups of each of the hardware domains for each of the hardware resources are determined based on the configuration instruction, wherein the permission types of each of the permission items in the same permission group are the same or similar; indication information of each of the permission items in the determined permission groups is displayed, and the operation permissions are determined based on the permission groups.
4. The method of claim 1, wherein, The configuration content part comprises a permission selection form for each of the hardware resources, and correspondingly, the configuration instruction comprises an instruction generated for the operation of the permission selection form.
5. The method of claim 1, wherein, The permission configuration comprises configuration information representing a hardware domain to which the hardware resource belongs, and the priority of the operation permissions of the hardware domain for the hardware resources in the domain is higher than the priority of the operation permissions of other hardware domains for the hardware resources.
6. The method of claim 5, wherein, The configuration instruction includes a firewall configuration sub-instruction, and based on the configuration instruction, the operation permissions of each hardware domain for each hardware resource and the respective corresponding firewall states of the hardware resources are re-determined, including: Based on the firewall configuration sub-instruction, the open state of the firewall corresponding to each hardware resource is set; Correspondingly, the method further includes: in the case where the firewall corresponding to the hardware resource is in an open state, intercepting, by the firewall, illegal manipulation of the hardware resource by other hardware domains that do not belong to the hardware resource.
7. The method of claim 1, wherein, The application project information is used to indicate the application project of the chip, the application project has a corresponding hardware platform, the application project information corresponding to the target configuration information is determined, the target configuration information and the application project information are associated to generate a corresponding target file, and the target file is stored to the hardware platform corresponding to the application project information, including: Based on the application project information, a hardware development board of the chip is determined; The target file is burned on the hardware development board.
8. The method of claim 1, wherein, The method further includes: In the case of using the hardware platform, the target file stored therein is called; Based on the target file, the permission configuration of each hardware domain for each hardware resource and the respective corresponding firewall states of the hardware resources are determined.
9. A chip, characterized by It includes: A generation module configured to determine hardware resources associated with hardware domains of a chip and generate a corresponding hardware resource configuration interface based on the hardware resources, wherein the hardware domains are hardware sets and each of the hardware sets includes at least one processor core, the hardware resource configuration interface includes at least first dimension information, second dimension information, and a configuration content part, the first dimension information indicates each of the hardware resources, the second dimension information includes hardware domain information associated with the hardware resources and firewall information for the hardware resources, and the configuration content part is used to indicate operation permissions of each hardware domain for each hardware resource and respective corresponding firewall states of the hardware resources, the operation permissions including at least one of the following: support permissions, user permissions, privileged permissions, non-secure permissions, secure permissions, write permissions, and read permissions; A configuration module configured to, in the case of obtaining a configuration instruction for the hardware resource configuration interface, re-determine the operation permissions of each hardware domain for each hardware resource and the respective corresponding firewall states of the hardware resources based on the configuration instruction and update the configuration content part, and generate corresponding target configuration information based on the operation permissions and the firewall states; A storage module configured to determine application project information of the chip corresponding to the target configuration information, associate the target configuration information and the application project information to generate a corresponding target file, and store the target file to a hardware platform corresponding to the application project information.
10. A vehicle characterized by comprising: The chip is installed as claimed in claim 9, and the chip can configure hardware resources associated with hardware domains of the chip. The chip is installed as claimed in claim 9, and the chip can configure hardware resources associated with hardware domains of the chip.
Citation Information
Patent Citations
Resource operation control method, electronic equipment, chip and readable storage medium
CN114490010A
Resource management method and device, electronic equipment and readable storage medium
CN115878296A