Inter-core communication system and chip circuit
By introducing secure and non-secure cache areas into the inter-core communication system and using security correction circuits to ensure the security of the delivered messages, the risk of safely delivered messages in existing systems is solved, and effective protection of messages of different security are achieved.
Patent Information
- Application Number
- CN202510174288.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-06-06
AI Technical Summary
The existing inter-core communication system fails to fully consider the security level of messages and software applications, resulting in non-secure software applications that may gain excessive access rights, and thus access messages with higher security levels, causing the risk of data leakage.
An inter-core communication system is designed, in which each processor core is a producer core or a consumer core, and the cache processing unit contains a secure and non-secure cache area. The secure delivery message can only be read by the consumer core in a secure state, and the accuracy of the security identification bits of the transmitted message is ensured through a security correction circuit.
It effectively avoids the leakage and illegal access of securely delivered messages, reduces the risk of sensitive information leakage, ensures the overall security of the system, and realizes effective protection of delivered messages with different security.
Smart Images

Figure CN120104561A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of system-on-chip (SOC), and in particular to an inter-core communication system and a chip circuit. Background Art
[0002] In the inter-core communication system, messages are transmitted between processor cores, and the transmission security of messages between different processor cores becomes crucial. Software applications with different security levels run on each processor core. The existing inter-core communication system fails to fully consider the security level of messages and software applications, which may allow non-secure software applications to obtain excessive access rights and access messages with higher security levels. For example, sensitive information is mistakenly accessed and misprocessed in an insecure environment, causing data leakage risks and affecting the overall security of the system. Summary of the invention
[0003] One aspect of the present application provides an inter-core communication system, comprising a plurality of processor cores in a secure state or an unsecure state and a plurality of cache processing units corresponding one to the plurality of processor cores; wherein each processor core is a producer core or a consumer core, the producer core is configured to generate a delivery message and write the delivery message to its corresponding cache processing unit, the consumer core is configured to read the delivery message from its corresponding cache processing unit, the delivery message including a secure delivery message and an unsecure delivery message; and each cache processing unit comprises a receiving buffer, the receiving buffer is divided into a secure cache area and an unsecure cache area, the secure delivery message is routed from the cache processing unit corresponding to the producer core to the secure cache area in the cache processing unit corresponding to the consumer core, the unsecure delivery message is routed from the cache processing unit corresponding to the producer core to the unsecure cache area in the cache processing unit corresponding to the consumer core, and the secure delivery message in the secure cache area can only be read by the consumer core in a secure state.
[0004] In some embodiments, the delivery message includes a security identification bit for indicating that it is a secure delivery message or an unsecure delivery message; the producer core is also configured to generate a security status signal based on its hardware status, and write the security status signal together with the delivery message into its corresponding cache processing unit, the security status signal indicating that the producer core is in a secure state or an unsecure state when writing the delivery message to its corresponding cache processing unit; the cache processing unit includes a security correction circuit, and the security correction circuit is configured to correct the security identification bit in the delivery message based on the security status signal and the security identification bit in the delivery message.
[0005] In some embodiments, the security correction circuit is configured to, when the security status signal indicates that the producer core is in a non-secure state and the security identification bit in the delivery message indicates that the delivery message is a secure delivery message, invert the security identification bit so that the delivery message is changed to a non-secure delivery message.
[0006] In some embodiments, the security correction circuit includes a first inverter, a second inverter, a third inverter and an AND gate circuit, the input end of the first inverter serves as the first input end of the security correction circuit, the input end of the second inverter serves as the second input end of the security correction circuit, the output end of the first inverter and the output end of the second inverter are respectively connected to the two input ends of the AND gate circuit, the output end of the AND gate circuit is connected to the input end of the third inverter, and the output end of the third inverter serves as the output end of the security correction circuit; and the security status signal is input to the first input end of the security correction circuit, the security identification bit is input to the second input end of the security correction circuit, and the signal output from the output end of the security correction circuit serves as the corrected security identification bit.
[0007] In some embodiments, the cache processing unit also includes a configuration register, the value of which can only be set by a processor core in a secure state; and the processor core in a secure state divides the receiving buffer into the secure cache area and the non-secure cache area, and sets the address range of the secure cache area and the non-secure cache area by setting the value of the configuration register in the cache processing unit corresponding to the processor core.
[0008] In some embodiments, the cache processing unit also includes: one or more message filters, each message filter corresponds to a different cache address segment in the receiving cache; and the one or more message filters are each configured to: receive the delivery message routed from the cache processing unit corresponding to the producer core, filter the received delivery message based on their respective filtering rules, and write the filtered delivery message into the corresponding cache address segment.
[0009] In some embodiments, each message filter includes a parameter configuration register, and the processor core sets the filtering rules of the message filter and the range of the cache address segment corresponding to the message filter by setting the value of the parameter configuration register in the message filter in the cache processing unit corresponding to the processor core.
[0010] In some embodiments, the parameter configuration register includes a security flag register, the value of which can only be set by a processor core in a secure state; the processor core in a secure state sets the message filter to a secure message filter or a non-secure message filter by setting the value of the security flag register in the message filter, the secure message filter is configured to filter the secure delivery message, and the non-secure message filter is configured to filter the non-secure delivery message; and the range of the cache address segment corresponding to the secure message filter is within the address range of the secure cache area, and the range of the cache address segment corresponding to the non-secure message filter is within the address range of the non-secure cache area.
[0011] In some embodiments, the value of the parameter configuration register in the message filter of the secure message filter can only be set by a processor core in a secure state.
[0012] Another aspect of the present application provides a chip circuit, including an inter-core communication system according to an embodiment of the present application.
[0013] According to the inter-core communication system and chip circuit of the present application, the cache processing unit serves as the endpoint for the transmission and routing of the message, and corresponds to each processor core in a distributed manner, so as to avoid multiple processor cores sharing a shared memory for inter-core communication, improve the read and write efficiency of the message, and thus improve the inter-core communication efficiency of the message. On this basis, the secure message with higher security is routed to the secure cache area in the cache processing unit corresponding to the consumer core, and the secure cache area is only allowed to be accessed by the consumer core in a secure state, so that the processor core in an unsecure state cannot read the secure message. Therefore, the operation in the unsecure state is strictly separated from the data flow, so as to avoid the activities in the unsecure area from interfering with or destroying the security core function of the system. The inter-core communication system of the present application avoids the leakage and illegal access of the secure message, greatly reduces the risk of sensitive information leakage, and effectively prevents data leakage caused by unauthorized operations. In addition, since the secure cache area only serves the consumer core in a secure state, resource competition is reduced. The inter-core communication system of the present application can effectively protect the message transmission of different security and meet the growing system security requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 A schematic diagram showing an inter-core communication system according to an embodiment of the present application;
[0015] Figure 2 A further schematic diagram showing an inter-core communication system according to an embodiment of the present application;
[0016] Figure 3 A schematic diagram showing the configuration of a message cache module according to an embodiment of the present application;
[0017] Figure 4 A schematic diagram showing the structure of a safety correction circuit according to an embodiment of the present application is shown;
[0018] Figure 5 A schematic diagram showing the configuration of a cache processing unit according to an embodiment of the present application;
[0019] Figure 6 A schematic diagram showing an example of the correspondence between a message filter and a cache address segment in a receiving buffer according to an embodiment of the present application. DETAILED DESCRIPTION
[0020] In existing SOCs, shared memory technology is usually used to achieve communication between multiple processor cores distributed in multiple subsystems. Shared memory is a memory area that can be directly accessed by multiple processor cores (such as CPU). In a multi-core system, processes or threads running on different processor cores often need to exchange data frequently. Multiple processor cores share the same system bus to access shared memory and transfer data through shared memory. When communicating between cores through shared memory, data entering and exiting shared memory also needs to go through complex processes such as memory controller scheduling and row and column address decoding, which increases read and write delays, cumbersome operation procedures, and large delays, resulting in low efficiency. In addition, in the existing inter-core communication mechanism, there is a lack of security division for transmitted messages, making it difficult to distinguish transmitted messages of different security during the communication process, which leads to the risk of sensitive data leakage.
[0021] The present application provides an inter-core communication system based on a distributed architecture, which can improve the security of communication while providing inter-core communication efficiency.
[0022] Figure 1 A schematic diagram of an inter-core communication system according to an embodiment of the present application is shown. The inter-core communication system is used for communication between multiple processor cores, such as message passing between multiple processor cores. The communication between multiple processor cores can be communication between multiple processor cores in the same processor, or it can be communication between processor cores in different processors. The communication between multiple processor cores can be communication between multiple processor cores in the same subsystem in the inter-core communication system, or it can be communication between multiple processor cores in different subsystems in the inter-core communication system. The inter-core communication system according to the present application can be applied to a SOC, and multiple processor cores can be located on the same SOC. In the present application, the transmission of messages between multiple processor cores is transmission via a hardware link.
[0023] like Figure 1As shown, the inter-core communication system includes multiple processor cores in a secure state or a non-secure state and multiple cache processing units corresponding one-to-one to the multiple processor cores.
[0024] Each processor core is a producer core or a consumer core. The producer core is configured to generate a delivery message and write the delivery message to its corresponding cache processing unit, and the consumer core is configured to read the delivery message from its corresponding cache processing unit.
[0025] The producer core is responsible for generating the processor core of data or resources, and the consumer core is the processor core responsible for using or processing these data or resources. In the inter-core communication system according to the present application, the producer core generates and sends the transfer message, and the consumer core receives and uses the transfer message. It is easy to understand that the producer core and the consumer core are both processor cores in the inter-core communication system, which is only a role division in the inter-core communication process. A processor core in the inter-core communication system is used as a producer core when generating and sending transfer messages, and as a consumer core when receiving and using transfer messages. The recipient of the transfer message can be one or more consumer cores, that is, a transfer message generated by the producer core can be transmitted to one or more consumer cores.
[0026] The cache processing unit is connected to its corresponding processor core via a hardware link, such as a bus. The processor core and its corresponding cache processing unit are located in the same subsystem in the inter-core communication system, and the cache processing unit is arranged near its corresponding processor core. The producer core and the consumer core can be located in the same subsystem or different subsystems in the inter-core communication system. The cache processing unit, as a transmission endpoint (End) for transmitting messages, is a logic circuit that can filter, cache, and other processing of transmitted messages.
[0027] exist Figure 1 In the inter-core communication system shown, each processor core can run a software application thereon to perform a predetermined operation and implement a predetermined function. The processor core as a producer core generates a transfer message, for example, the transfer message is generated by a software application run by the producer core. The producer core transmits the generated transfer message to its corresponding cache processing unit through a bus connected thereto, and then the transfer message is routed from the cache processing unit corresponding to the producer core to the cache processing unit corresponding to the processor core as a consumer core via a message routing unit, and the consumer core reads the transfer message from its corresponding cache processing unit through the bus connected thereto, thereby realizing the transfer message from the producer core to the consumer core, and realizing inter-core communication.
[0028] The processor core in the inter-core communication system can be in a secure state or in an unsecure state. Whether the processor core is in a secure state or an unsecure state is determined by whether the software application running on it has security requirements. The processor core being in a secure state means that the software application it is running has security requirements, and the processor core being in an unsecure state means that the software application it is running does not have security requirements. In other words, when the software application running on the processor core has security requirements, that is, when the security level of the software application running on the processor core is higher than a predetermined level, the processor is in a secure state, that is, running in a secure mode; when the software application running on the processor core does not have security requirements, that is, when the security level of the software application running on the processor core is lower than a predetermined level, the processor is in an unsecure state, that is, running in an unsecure mode. When the running application software involves sensitive information or information related to system security, it can be considered that the application software has security requirements; when the running application software only involves general public data, but not sensitive information or information related to system security, it can be considered that the application software does not have security requirements.
[0029] The transmission messages include secure transmission messages and insecure transmission messages. Secure transmission messages refer to transmission messages related to system security. Once these messages are leaked, tampered with or damaged, they may affect the safe operation of the system. Secure transmission messages are transmission messages whose security is higher than the predetermined level; insecure transmission messages refer to transmission messages that are not related to system security. Insecure transmission messages are transmission messages whose security is lower than the predetermined level. Even if insecure messages are illegally obtained, they will not cause serious security risks to the system.
[0030] Each cache processing unit includes a receiving cache, which is divided into a secure cache area and a non-secure cache area. Secure delivery messages are routed from the cache processing unit corresponding to the producer core to the secure cache area in the cache processing unit corresponding to the consumer core, and non-secure delivery messages are routed from the cache processing unit corresponding to the producer core to the non-secure cache area in the cache processing unit corresponding to the consumer core. The secure delivery messages in the secure cache area can only be read by the consumer core in a secure state.
[0031] Exemplarily, each cache processing unit may include a sending buffer (not shown) and a receiving buffer, for example, including a sending buffer and a receiving buffer, which are respectively used to cache the transfer messages to be sent and received by the processor core corresponding to the cache processing unit. Specifically, the sending buffer can be configured to cache the transfer messages sent by the processor core corresponding to the cache processing unit where it is located, and the receiving buffer can be configured to cache the transfer messages to be received by the processor core corresponding to the cache processing unit where it is located. Exemplarily, the sending buffer and the receiving buffer can be FIFO (First Input First Output) buffers.
[0032] See also Figure 1 , the receiving buffer is shown by the shaded part. The delivery message generated by the producer is transmitted to the corresponding cache processing unit via the bus connected thereto, and is cached in the sending buffer in the cache processing unit. The sending buffer then transmits the delivery message to the routing unit via the hardware link, and the routing unit routes it to the cache processing unit corresponding to the consumer core via the hardware link, and caches it in the receiving buffer in the cache processing unit corresponding to the consumer core. The consumer core accesses the receiving buffer via the bus connected thereto, and reads the delivery message cached therein from the receiving buffer. The routing unit can be understood as a logic circuit for realizing functions such as forwarding and routing of delivery messages.
[0033] The receiving buffer divides the address range of its memory space into two parts, one part is used as a secure buffer area, and the other part is used as a non-secure buffer area. Secure delivery messages are routed to the secure buffer area, and non-secure delivery messages are routed to the non-secure buffer area. Therefore, a specific address range is set in the receiving buffer for caching secure delivery messages. In the example of the accompanying drawings, the secure buffer area is located in the high-order address segment in the receiving buffer, and the non-secure buffer area is located in the low-order address segment in the receiving buffer, that is, in the example of the accompanying drawings, the address of the receiving buffer is from large to small from top to bottom.
[0034] The secure cache area in the receiving buffer can only be accessed by a processor core in a secure state, so that the secure delivery message routed to the secure cache area in the receiving buffer of the cache processing unit corresponding to the consumer core can only be read by the consumer core in a secure state.
[0035] According to the inter-core communication system of the present application, the cache processing unit serves as the endpoint for the transmission and routing of the message, and corresponds to each processor core in a distributed manner, so as to avoid multiple processor cores sharing a shared memory for inter-core communication, improve the read and write efficiency of the message, and thus improve the inter-core communication efficiency of the message. On this basis, the secure message with higher security is routed to the secure cache area in the cache processing unit corresponding to the consumer core, and the secure cache area is only allowed to be accessed by the consumer core in a secure state, so that the processor core in an unsecure state cannot read the secure message. Therefore, the operation in the unsecure state is strictly separated from the data flow, so as to avoid the activities in the unsecure area from interfering with or destroying the security core function of the system. The inter-core communication system of the present application avoids the leakage and illegal access of the secure message, greatly reduces the risk of sensitive information leakage, and effectively prevents data leakage caused by unauthorized operations. In addition, since the secure cache area only serves the consumer core in a secure state, resource competition is reduced. The inter-core communication system of the present application can effectively protect the message transmission of different security and meet the growing system security requirements.
[0036] Figure 2 A further schematic diagram of an inter-core communication system according to an embodiment of the present application is shown. The inter-core communication system may include multiple subsystems, such as subsystems AE. Each subsystem includes one or more processor cores, and the number of processor cores in each subsystem is not specifically limited. Each subsystem includes at least one message cache module corresponding to the subsystem, such as Figure 2 The message cache modules AE shown in correspond to the subsystems AE one by one. Each subsystem is integrated with a message cache module as a transmission node (Node) for transmitting messages. The message cache module is integrated in its corresponding subsystem as a part of its corresponding subsystem. The message cache module can be understood as a logic circuit for implementing functions such as decoding, caching, and forwarding of transmitted messages. Exemplarily, each subsystem includes a message cache module. It is easy to understand that the number of subsystems in the inter-core communication system of the present application may be only one. Subsystems AE are the various subsystems in the SOC, which are divided according to the implemented functions, that is, the circuits and components in the chip are classified into one or more subsystems according to their functions and roles, and each subsystem has independent functional logic. For example, the various subsystems can be a security subsystem, a protection subsystem, a media subsystem, a peripheral control subsystem, etc. in the SOC.
[0037] The processor core in each subsystem is connected to the message cache module corresponding to the subsystem where it is located via a bus. Each message cache module corresponds to all processor cores in the subsystem where the message cache module is located, and all processor cores in each subsystem are connected to the corresponding message cache module (that is, the message cache module integrated in the subsystem where the processor core is located) via a bus. Each subsystem has a separate bus, so the bus connected to the producer core and the bus connected to the consumer core can be the same bus or different buses. When the producer core and the consumer core are located in the same subsystem, the two are connected to the same bus, and when the producer core and the consumer core are located in the same subsystem, the two are connected to different buses. In each subsystem, the bus only needs to connect the processor core in the subsystem, and it is not necessary to connect all processor cores in all subsystems in the inter-core communication system with the same bus, thereby reducing the pressure of bus transmission data in each subsystem, avoiding bus congestion to a certain extent, and reducing the physical distance of the data link used to transmit and transfer messages, thereby reducing the waiting time for the processor to send data.
[0038] In some examples, the subsystem may include a processor circuit block and a peripheral circuit block. The peripheral circuit block includes a circuit component for implementing the function of the subsystem, and the peripheral circuit blocks of each subsystem may be different. The processor circuit block integrates a series of key components and circuits closely related to the processor. One or more processors are integrated in the processor circuit block. Each processor may be a single-core processor or a multi-core processor, that is, each processor includes one or more processor cores. In the present application, the message cache module is integrated in the processor circuit block. In the processor circuit block, all processor cores in the processor circuit block are connected to the message cache module via a bus, and the message can be transmitted between the message cache module and the processor core via the bus. The transmission of the message in the SOC is transmitted via a hardware link. The message cache module is integrated into the processor circuit block of each subsystem, and the transmission link of the message from the processor core to the message cache module and from the message cache module to the processor core is shorter, and the processor core in the subsystem can access the message cache module faster. In the present application, the bus is, for example, an AHB (Advanced High Performance Bus) bus.
[0039] Figure 3 A schematic diagram showing the configuration of a message cache module according to an embodiment of the present application is shown. Figure 3 As shown, each message cache module may include one or more cache processing units. Figure 3Also shown are multiple processor cores connected to the message cache module via a bus, which are located in the same subsystem as the message cache module and correspond to the message cache module. As described above, one or more cache processing units correspond one-to-one to one or more processing cores in the subsystem where the message cache module is located. For example, when subsystem A includes 2 processor cores, message cache module A includes at least 2 cache processing units, and the 2 cache processing units correspond one-to-one to the 2 processor cores in subsystem A. It is easy to understand that if the message cache module A includes more than 2 cache processing units, some of the cache processing units may be in an unenabled state. The cache processing unit is a sub-logic circuit in the message cache module, which can be understood as an endpoint (End) in a transmission node (Node). Multiple cache processing units in each message cache module can transmit and transfer messages to each other.
[0040] Each message cache module may also include an internal routing unit for routing transfer messages within the subsystem. Exemplarily, a message cache module includes an internal routing unit. The internal routing unit is configured to route transfer messages and route the transfer messages to corresponding destinations. The internal routing unit corresponds to all cache processing units in the cache processing module in which it is located. The internal routing unit is connected to all cache processing units in the cache processing module in which it is located. The above "connection" refers to connection through a hardware link. Transfer messages can be communicated between the cache processing unit and its corresponding internal routing unit through a hardware link.
[0041] The inter-core communication system may also include one or more message routing modules. The message routing module may be a module located outside each subsystem AE in the SOC system, and may be understood as a logic circuit for implementing functions such as forwarding and routing of transmitted messages.
[0042] One or more message routing modules are each connected to a message cache module in at least one of its corresponding subsystems, and more specifically, can be connected to an internal routing unit in a message cache module in at least one of its corresponding subsystems. Each message routing module corresponds to at least one subsystem in the inter-core communication system, and therefore each message routing module corresponds to at least one message cache module in the inter-core communication system, and each message routing module is connected to at least one message cache module corresponding to it. It is easy to understand that each subsystem and each message cache module has a corresponding message routing module, and only corresponds to one message routing module. When the inter-core communication system includes multiple message routing modules, the message routing modules are interconnected, and the transmitted messages can be transmitted between multiple message routing modules.
[0043] For example, Figure 2As shown, message routing modules X and Y are connected to each other, message routing module X is connected to message cache modules A, B, and C, and message routing module Y is connected to message cache modules D and E. The above "connection" refers to connection through hardware links. Messages can be transmitted between a message cache module and its corresponding message routing module, and between multiple message routing modules through hardware links.
[0044] It should be understood that the inter-core communication system may include only one message routing module, in which case the message cache modules in all subsystems are connected to the message routing module. The message routing module is configured to route and transfer messages between the cache processing units, so that the cache processing units in different subsystems of the inter-core communication system can transmit and transfer messages to each other.
[0045] exist Figure 2 In the example shown, the delivery message is generated by the producer core, and the producer core writes the delivery message to the message cache module in the subsystem where the producer core is located via the bus, and the message cache module receives the delivery message via its bus interface. The message cache module processes the received delivery message via the address decoding logic to identify the producer core from which it comes, so as to write the delivery message into the sending buffer in the cache processing unit corresponding to the producer core. The sending buffer in the cache processing unit corresponding to the producer core transmits the delivery message to the receiving buffer in the cache processing unit corresponding to the consumer core via the internal routing unit, and the consumer core reads the delivery message from the receiving buffer in the cache processing unit corresponding to the consumer core, thereby realizing the delivery message from the producer core to the consumer core and realizing inter-core communication. It is easy to understand that if the producer core and the consumer core are not located in the same subsystem, after the delivery message is transmitted to the internal routing unit in the message cache module corresponding to the producer core, the internal routing unit routes it to the message routing module connected thereto, and routes it to the internal routing unit in the message cache module corresponding to the consumer core through the message routing module, and then routes it to the cache processing unit corresponding to the consumer core by the internal routing unit in the message cache module corresponding to the consumer core.
[0046] exist Figure 2 In the example, each subsystem includes a message cache module as a transmission node for transmitting messages, and the message cache module includes a cache processing unit corresponding to the processor core one by one as a transmission endpoint for transmitting messages. The transmission nodes and transmission endpoints are distributedly integrated in each subsystem, which can improve the read and write efficiency of message transmission, thereby improving the inter-core communication efficiency of message transmission. In addition, the number of processor cores connected to the same bus is small, which reduces the pressure on the bus to transmit data and avoids bus congestion to a certain extent. In this way, the processor core has a small delay when communicating between cores, thereby reducing the load on the processors in each subsystem, and the inter-core communication system adopts a distributed architecture with good scalability.
[0047] In some embodiments, the delivery message may include a security identification bit for indicating that it is a secure delivery message or an unsecure delivery message; the producer core may also be configured to generate a security status signal based on its hardware status, and write the security status signal together with the delivery message to its corresponding cache processing unit, the security status signal indicating that the producer core is in a secure state or an unsecure state when writing the delivery message to its corresponding cache processing unit; the cache processing unit may include a security correction circuit, and the security correction circuit may be configured to correct the security identification bit in the delivery message based on the security status signal and the security identification bit in the delivery message.
[0048] Exemplarily, a delivery message may include a message header and a payload. The message header usually carries key meta-information, such as the source, destination, type, etc. of the delivery message. When a delivery message is sent or received, the message header is sent or received first, so that the receiving end can know in advance how to process subsequent data. The payload is the content body in the delivery message. The security flag is used to indicate the security of the delivery message. The security flag can be a bit in the message header, which can be "1" or "0". For example, when the security flag is "1", it indicates that the delivery message is an unsecured delivery message, and when the security flag is "0", it indicates that the delivery message is a secure delivery message.
[0049] The message header of the delivery message is generated by the software application run by the producer core as part of the delivery message, so the security identification bit of the delivery message is set by the software application run by the producer core. Generally, when the software application run by the producer core has security requirements, the generated delivery message can be a secure delivery message or an insecure delivery message; when the software application run by the producer core does not have security requirements, the generated delivery message is an insecure delivery message. However, some software applications that do not have security requirements may maliciously generate delivery messages as secure delivery messages in order to obtain more permissions. For example, a software application that does not have security requirements tamper with the security identification bit of the generated delivery message to "0". This may affect the performance and communication security of the system.
[0050] In some examples, the message header of the delivery message may also include: a producer core identification bit for identifying the producer core from which it comes, and a consumer core identification bit for identifying the consumer core to which it is to be sent. The producer core identification bit and the consumer core identification bit are used to determine the routing path and destination of the delivery message in the routing process of inter-core communication. The message header of the delivery message may also include the length information of the delivery message, the width information, the identification bit indicating whether it is a loopback test message, and the reserved fields that can be defined by the software application.
[0051] The producer core generates a security status signal based on its hardware status. The generation of the security status signal is performed roughly simultaneously with the generation of the transfer message. For example, in some of the above examples, the transfer message generated by the producer core is written to the corresponding cache processing unit via the bus connected to the producer core. At this time, in order to use the bus to write the transfer message, the producer core needs to initiate a bus request to the bus. A bus request is an application signal sent by a processor (such as a processor core) to the system bus in order to obtain bus control in order to transfer data, access memory or other devices. In this case, the bus request carries the security status signal corresponding to the transfer message.
[0052] The security state signal indicates whether the producer core is in a secure state or an unsecure state when writing the transfer message to its corresponding cache processing unit. Since the same transfer message must be generated by the same software application, that is, the software application run by the producer core does not change when generating and writing the same transfer message, and whether the software application has security requirements does not change, therefore, when the same transfer message is written to its corresponding cache processing unit, the security state of the producer core does not change, and therefore the security state signal does not change. That is, it can be understood that one transfer message corresponds to one security state signal.
[0053] The security state signal can be expressed as "1" or "0", indicating that the producer core is in an unsafe state and a safe state at this time, respectively. As can be seen from the above, when the software application running on the processor core has security requirements, that is, when the security level of the software application running on the processor core is higher than the predetermined level, the processor is in a safe state, that is, running in a safe mode; when the software application running on the processor core does not have security requirements, that is, when the security level of the software application running on the processor core is lower than the predetermined level, the processor is in an unsafe state, that is, running in an unsafe mode. When the processor core runs in a safe mode, the hardware of the processor core will enable a series of additional security mechanisms; when the processor runs in an unsafe mode, the hardware of the processor core can optimize resource allocation, reduce unnecessary security protection overhead, and thus improve operating efficiency. That is, the hardware state of the processor core is different when it is in a safe state and in an unsafe state. The processor core can accurately determine whether the current processor core is in a safe state or an unsafe state based on its hardware state. Since the hardware state is difficult to be tampered with, the security state signal generated according to the hardware state has high reliability.
[0054] Further, the security state signal is set by a hardware circuit of the processor core (or the processor in which the processor core is located), that is, the hardware circuit sets the security state signal to "1" or "0". Based on the reliability of the hardware circuit, the security state signal is difficult to be tampered with.
[0055] Furthermore, the security status signal can be a control signal in the bus protocol of the bus connected to the producer core, such as the Hnonsec control signal in the AHB bus protocol, which is used to indicate the security attribute of the current bus transmission. This signal has only one bit, and distinguishes whether the transmission is non-secure or secure through the two states of "1" or "0".
[0056] For example, if the processor core is executing an ordinary user software application that does not have security requirements, and the ordinary user software application accesses general data and does not involve system sensitive information, when the processor core initiates a bus request, its hardware state indicates that the processor core is in a non-secure state, and the corresponding hardware circuit will set the Hnonsec signal to "1". When the processor core executes a secure software application with security requirements, such as executing system kernel code, performing key operations such as security authentication and accessing protected system resources, when the processor core initiates a bus request, its hardware state indicates that the processor core is in a secure state, and the Hnonsec signal will be set to "0". It is easy to understand that a transfer message may be written to the cache processing unit through a single write operation via the bus, or it may be split into multiple data blocks and written to the cache processing unit through multiple write operations via the bus. Each time a transfer message is written to the cache processing unit via the bus, the processor core must initiate a bus request, that is, a transfer message can correspond to one or more bus requests, but because the same transfer message is generated by a processor core in the same hardware state, the value of the Hnonsec signal of all bus requests corresponding to the same transfer message is the same.
[0057] The producer core writes the security status signal together with the transfer message into the cache processing unit corresponding to the producer core. Figure 3 The thick solid line in the figure shows the transmission path of the security status signal and the transfer message through the arrow. For example, the transfer message and the security status signal corresponding to the transfer message are transmitted to the cache processing unit via the bus for processing by the cache processing unit. Exemplarily, when the producer core wants to write the transfer message to its corresponding cache processing unit, it initiates a bus request to the bus connected to it, and the bus request carries the Hnonsec signal, which is set by the producer core based on its hardware state. Then, the Hnonsec signal is written to the cache processing unit corresponding to the producer core via the bus together with the corresponding transfer message.
[0058] The security correction circuit is a subcircuit in the cache processing unit, and is a part of the cache processing unit. It receives the security status signal and the corresponding security identification bit in the transfer message as input, and corrects the security identification bit in the transfer message through logical calculation. It is easy to understand that the security identification bit in the transfer message may change after being corrected by the security correction subcircuit, for example, from "0" to "1", that is, whether the transfer message is a secure transfer message or an unsecure transfer message may change, for example, from a secure transfer message to an unsecure transfer message.
[0059] The corrected security identification bit is applied to the transfer message, and the transfer message is transmitted after its security identification bit is corrected. More specifically, before the transfer message is cached in the sending buffer of the cache processing unit, its security identification bit has been corrected by the security correction subcircuit, and the transfer message cached into the sending buffer is the transfer message with the security identification bit corrected, and then the cache processing unit transmits the transfer message with the security identification bit corrected. During the transmission process of the transfer message from the sending buffer in the cache processing unit corresponding to the producer core to the receiving buffer in the cache processing unit corresponding to the consumer core, the security identification bit of the transfer message will not change.
[0060] According to this embodiment, whether the transfer message is a secure transfer message or an unsecure transfer message is determined not only by the software application that generates the transfer message, but also by the hardware state of the producer core. The transfer message actually transmitted to the consumer core is a transfer message whose security identification bit has been corrected, which can more reliably determine whether the transfer message actually transmitted to the consumer core is a secure transfer message or an unsecure transfer message, and more reliably classify and process the transfer messages, thereby effectively protecting the transfer messages of different security. In addition, the control signal bit in the bus can be used to indicate whether the producer core is in a secure state or an unsecure state, without the need to set up additional hardware components, and is easy to implement.
[0061] In some embodiments, the security correction circuit is configured to invert the security identification bit so that the delivery message is changed to a non-secure delivery message when the security status signal indicates that the producer core is in a non-secure state and the security identification bit in the delivery message indicates that the delivery message is a secure delivery message.
[0062] Generally, a producer core in an unsafe state, that is, a producer core on which a software application running does not have a safety requirement, can only generate an unsafe transfer message. However, since the transfer message is generated by the software running on the producer core, when an error occurs in the running of the software application, or when a software application that does not have a safety requirement maliciously tampers with the safety identification bit of the transfer message, the producer core in an unsafe state may mistakenly generate a safe transfer message, which may affect the performance and communication security of the system. In this case, the security correction circuit reverses the safety identification bit of the transfer message, for example, reverses "0" to "1", so that the transfer message is changed to an unsafe transfer message. Therefore, when the producer core is in an unsafe state, even if the transfer message generated by the software application running on it and written to the cache processing unit is a safe transfer message, the transfer message will be modified by the security correction circuit to an unsafe transfer message, and the transfer message actually transmitted to the consumer core is therefore also an unsafe transfer message. In other words, when the producer core in an unsafe state writes a safe transfer message to its corresponding cache processing unit, the cache processing unit modifies the written safe transfer message to an unsafe transfer message for subsequent transmission.
[0063] According to this embodiment, when the producer core is in a non-secure state, even if the software application mistakenly generates a transfer message as a secure transfer message, the cache processing circuit can correct the security of the transfer message by inverting the security identification bit, so that the transfer message from the producer core in the non-secure state can only be transmitted as a non-secure transfer message, thereby avoiding the communication security being affected by software errors. In addition, the security correction circuit only needs to invert the security identification bit to change the security of the transfer message, and will not modify the payload or other content of the transfer message, and will not reduce the reliability of the transmission.
[0064] In some embodiments, the security correction circuit includes a first inverter, a second inverter, a third inverter and an AND gate circuit, the input end of the first inverter serves as the first input end of the security correction circuit, the input end of the second inverter serves as the second input end of the security correction circuit, the output end of the first inverter and the output end of the second inverter are respectively connected to the two input ends of the AND gate circuit, the output end of the AND gate circuit is connected to the input end of the third inverter, and the output end of the third inverter serves as the output end of the security correction circuit. The security state signal is input to the first input end of the security correction circuit, the security identification bit is input to the second input end of the security correction circuit, and the signal output from the output end of the security correction circuit serves as the corrected security identification bit.
[0065] Figure 4 FIG. 2 shows a schematic diagram of the structure of a safety correction circuit according to an embodiment of the present application. Figure 4As shown, the safety correction circuit 300 of the embodiment of the present application has a first input terminal IN1 and a second input terminal IN2 as input terminals, and an output terminal OUT as an output terminal. The safety correction circuit 300 includes a first inverter 310, a second inverter 320, a third inverter 340 and an AND gate circuit 330. The input terminal of the first inverter 310 serves as the first input terminal IN1 of the safety correction circuit 300, the input terminal of the second inverter 320 serves as the second input terminal IN2 of the safety correction circuit 300, the output terminal of the first inverter 310 and the output terminal of the second inverter 320 are respectively connected to the two input terminals of the AND gate circuit 330, that is, the output of the first inverter 310 and the second inverter 320 serve as the input of the AND gate circuit 330, and the output terminal of the AND gate circuit 330 is connected to the input terminal of the third inverter 340, that is, the output of the AND gate circuit 330 serves as the input of the third inverter 340, and the output terminal of the third inverter 340 serves as the output terminal OUT of the safety correction circuit 300.
[0066] As described above, the security status signal and the corresponding transfer message are written into the cache processing unit together. In this case, the security status signal is input to the first input terminal IN1 of the security correction circuit 300, and the security identification bit in the transfer message is input to the second input terminal IN2 of the security correction circuit 300. The security correction circuit 300 performs a logical operation on the input signal and outputs the operation result to the output terminal OUT. The signal outputted from the output terminal OUT of the security correction circuit 300 is used as the corrected security identification bit.
[0067] When the security status signal is "1" indicating that the producer core is in a non-secure state, the security status signal is "0" indicating that the producer core is in a secure state, and the security flag is "1" indicating that the transmission message is a non-secure transmission message, and the security flag is "0" indicating that the transmission message is a secure transmission message, the security correction circuit 300 may have the following input and output conditions:
[0068] Case 1: the input of the first input terminal IN1 is "0", the input of the second input terminal IN2 is "0", and the output of the output terminal OUT is "0"; this case indicates that the producer core is in a safe state, and the transfer message generated by the software application running in the producer core is a safe transfer message. After correction by the security correction circuit 300, the transfer message actually transmitted to the consumer core is still a safe transfer message.
[0069] Case 2: The input of the first input terminal IN1 is "0", and the input of the second input terminal IN2 is "1", then the output of the output terminal OUT is "1"; this case indicates that the producer core is in a secure state, and the transfer message generated by the software application running in the producer core is a non-secure transfer message. After correction by the security correction circuit 300, the transfer message actually transmitted to the consumer core is still a non-secure transfer message. From this case, it can be seen that producers in a secure state are allowed to generate non-secure transfer messages and transmit them. This is because, although the software application running in a secure state has security requirements, the transfer messages generated by the software application with security requirements are not all secure transfer messages, and it can also generate non-secure transfer messages. In this case, there is no need to change the security of the transfer message, and it can continue to be transmitted as a non-secure transfer message.
[0070] Case three: the input of the first input terminal IN1 is "1", the input of the second input terminal IN2 is "1", and the output of the output terminal OUT is "1"; this case indicates that the producer core is in a non-secure state, and the transfer message generated by the software application running in the producer core is a non-secure transfer message. After correction by the security correction circuit 300, the transfer message actually transmitted to the consumer core is still a non-secure transfer message.
[0071] Case 4: the input of the first input terminal IN1 is "1", the input of the second input terminal IN2 is "0", and the output of the output terminal OUT is "1". This case indicates that the producer core is in a non-secure state, and the transfer message generated by the software application running in the producer core is a secure transfer message. After being corrected by the security correction circuit 300, the transfer message actually transmitted to the consumer core is changed to a non-secure transfer message.
[0072] As can be seen from the above, after the security identification bit is corrected, the security of the transfer message may change or remain unchanged. Specifically, if the transfer message generated by the software program run by the producer core is a non-secure transfer message, then after the security identification bit is corrected by the security correction circuit 300, the transfer message is still a non-secure transfer message for subsequent transmission; if the transfer message generated by the software program run by the producer core is a secure transfer message, then the security correction circuit 300 determines whether to change the transfer message to a non-secure transfer message for subsequent transmission according to the hardware status of the producer core.
[0073] According to this embodiment, whether the transfer message actually transmitted to the consumer core is a secure transfer message or an unsecure transfer message is jointly determined by the hardware state of the producer core and the software program run by the producer core. The security correction circuit can properly correct the security identification bit of the transfer message under different circumstances, and more reliably determine whether the transfer message actually transmitted to the consumer core is a secure transfer message or an unsecure transfer message. The inter-core communication system can more reliably classify and process the transfer messages, thereby effectively protecting the transfer messages of different security levels.
[0074] In some embodiments, the cache processing unit also includes a configuration register, the value of which can only be set by a processor core in a secure state; and the processor core in a secure state divides the receiving buffer into a secure cache area and a non-secure cache area by setting the value of the configuration register in the cache processing unit corresponding to the processor core, and sets the address range of the secure cache area and the non-secure cache area.
[0075] Figure 5 A schematic diagram showing the configuration of a cache processing unit according to an embodiment of the present application is shown. Figure 5 As shown, the cache processing unit includes a configuration register, which is used to define a predetermined address in a receiving buffer (hereinafter referred to as the receiving buffer corresponding to the configuration register) in the cache processing unit where the configuration register is located. For example, by writing the predetermined address into the configuration register as the value of the configuration register.
[0076] The value of the configuration register can only be set by a processor core in a secure state, which means that only a processor core in a secure state can access the security flag register and set and modify the value of the configuration register. Since the processor core in a secure state is running a software application with security requirements, it can be understood that the value of the configuration register can only be set by a software application with security requirements. More specifically, only when the processor core connected to the cache processing unit where the configuration register is located is in a secure state, the processor core in a secure state can access the configuration register in the cache processing unit corresponding to the processor core (i.e., connected via a bus), for example, the value of the configuration register can be set by a software application with security requirements running by the processor core in a secure state.
[0077] In the receiving buffer, the memory area corresponding to the address range below the predetermined address (i.e., the address range in the receiving buffer that is smaller than the predetermined address) may be a non-secure buffer area, and the memory area corresponding to the address range above the predetermined address (i.e., the address range in the receiving buffer that is larger than the predetermined address) may be a secure buffer area. The specific setting is not limited to this. In another example, the memory area corresponding to the address range below the predetermined address may be a secure buffer area, and the memory area corresponding to the address range above the predetermined address may be a non-secure buffer area. In other words, the predetermined address is the boundary address between the secure buffer area and the non-secure buffer area in the receiving buffer.
[0078] Specifically, the processor core in the secure state can divide the memory area in the receiving buffer into two parts, namely, a secure cache area and a non-secure cache area, by setting the value of the configuration register in the cache processing unit corresponding to the processor core, such as writing a predetermined address into the configuration register or modifying the value in the configuration register. Accordingly, since the predetermined address plays a role in dividing the address range of the memory area in the receiving buffer and the overall address range of the receiving buffer is known, the address ranges of the secure cache area and the non-secure cache area can be determined.
[0079] In some examples, the configuration register has a default value, which is the maximum address of the receiving buffer corresponding to the configuration register. That is, by default, the entire address range of the receiving buffer is used as a non-secure cache area.
[0080] In some examples, the predetermined address is determined by a software application with security requirements. The software application with security requirements can determine the size of the secure cache area and the non-secure cache area based on the situation of the software application running in the inter-core communication system, and more specifically based on the expected capacity of secure and non-secure message delivery, thereby determining the predetermined address to be written to the configuration register.
[0081] It should be understood that when a processor core is in a non-secure state, the configuration register in its corresponding cache processing unit cannot be accessed, and the value of the configuration register cannot be set or modified.
[0082] According to this embodiment, the configuration register can only be configured by the processor core in the secure state. This restriction ensures that the key address partitioning parameters will not be arbitrarily tampered with by software applications that do not have security requirements, maintaining the stability and reliability of the system security mechanism. Even if software that does not have security requirements attempts to change the value of the configuration register, it will not succeed because it does not have configuration permissions.
[0083] In some embodiments, the cache processing unit also includes: one or more message filters, each message filter corresponds to a different cache address segment in the receiving cache; the one or more message filters are each configured to: receive a delivery message routed from the cache processing unit corresponding to the producer core, filter the received delivery message based on their respective filtering rules, and write the filtered delivery message into the corresponding cache address segment.
[0084] Figure 6 A schematic diagram showing an example of a correspondence between a message filter and a cache address segment in a receiving cache according to an embodiment of the present application. Figure 5 and Figure 6 , each message filter corresponds to a different cache address segment in the receiving cache in the cache processing unit where the message filter is located. Each message filter is configured with a predetermined filtering rule. The message filter receives the transfer message from the internal routing unit and filters the received transfer message. Filtering the transfer message means selecting (retaining) the transfer message that meets the predetermined filtering rule in the received message. The message filter then writes the filtered transfer message (that is, the transfer message that meets the predetermined rule of the message filter) into the cache address segment corresponding to the message filter, that is, the filtered transfer message is cached in the corresponding cache address segment. The message filter can be implemented by a logic circuit. The processor core can set which message filter or messages are specifically enabled in the cache processing unit by configuring the corresponding cache processing unit. Each enabled message filter has its corresponding cache address segment, and the address ranges of the cache address segments corresponding to each enabled message filter do not overlap.
[0085] The filtering rule may be to filter one or more fields of the message header of the transmitted message, such as filtering the producer core identification bit field, length field or reserved field within a certain range. The filtering rule may also be to filter the payload of the transmitted message, such as filtering the payload that meets the predetermined conditions. It is easy to understand that the filtering rule of a message filter can apply one or more filtering conditions at the same time.
[0086] In some examples, such as Figure 5 As shown, the receiving buffer is also provided with a default address segment, and the delivery message that is not selected by any one of the one or more message filters in the cache processing unit will be written into the default address segment. For example, the cache processing unit also includes a default filter, and the default filter corresponds to the default address segment. The delivery message that is not selected by any one of the one or more message filters in the cache processing unit can enter the default filter and be written into the default address segment. The default address segment is located within the address range of the non-secure cache area.
[0087] According to this embodiment, a specific delivery message can be distinguished from other delivery messages, so as to facilitate management and use by consumers.
[0088] In some embodiments, each message filter includes a parameter configuration register, and the processor core sets the filtering rules of the message filter and the range of the cache address segment corresponding to the message filter by setting the value of the parameter configuration register in the message filter in the cache processing unit corresponding to the processor core.
[0089] See again Figure 5 Each message filter includes a parameter configuration register, and the message filter is configured by configuring the value of the parameter configuration register. Specifically, each message filter may include multiple parameter configuration registers, and each function of the message filter may be configured by setting the value of each parameter configuration register. More specifically, setting the value of each parameter configuration register will change the circuit structure and logic of the actual operation of the message filter, thereby realizing different functions.
[0090] In practical applications, the filtering rules of each message filter and the range of each cache address segment (e.g., the start and end addresses of each cache address segment) can be set according to actual needs. For example, if the capacity of a certain type of transmission message is expected to be large, the cache address segment to be written can be set to a larger address segment range. In other words, the circuit structure and logic of the actual operation of the message filter can be configured according to actual needs by setting the value of the parameter configuration register.
[0091] It is easy to understand that n-1 enabled message filters correspond to n-1 cache address segments in the receiving buffer. There may be another default address segment in the receiving buffer for writing the delivery messages that are not selected by the n-1 enabled message filters. Therefore, in this case, the receiving buffer includes n cache address segments, and each cache address segment is continuous and non-overlapping. Correspondingly, the delivery messages are divided into n types. One cache address segment corresponds to one type of delivery message. For example, after being enabled, the message filter receives the value of the parameter configuration register and is then configured according to the value of the parameter configuration register. In the present application, a message filter that has been configured with the parameter configuration register can be understood as an enabled message filter.
[0092] like Figure 6As shown, 7 message filters are integrated in a cache processing unit, of which 3 message filters (message filter 1, message filter 2 and message filter 3) are actually enabled. The filtering rules of message filter 1, message filter 2 and message filter 3 are respectively to select secure delivery messages from a predetermined producer core, select secure delivery messages with a predetermined length and select non-secure delivery messages from a predetermined producer core. The delivery messages selected by these three message filters will be written to cache address segment 1, cache address segment 2 and cache address segment 3 in the receiving buffer respectively. The delivery messages that are not selected by any enabled message filter will be uniformly written to cache address segment 4 which is the default address segment.
[0093] According to this embodiment, the message filter can be set according to actual needs, so that the filtering of the transmitted messages is flexibly applicable to different application scenarios.
[0094] In some embodiments, the parameter configuration register includes a security flag register, the value of which can only be set by a processor core in a secure state; the processor core in a secure state sets the message filter to a secure message filter or a non-secure message filter by setting the value of the security flag register in the message filter, the secure message filter is configured to filter secure delivery messages, and the non-secure message filter is configured to filter non-secure delivery messages; and the range of the cache address segment corresponding to the secure message filter is within the address range of the secure cache area, and the range of the cache address segment corresponding to the non-secure message filter is within the address range of the non-secure cache area.
[0095] As described above, each message filter may include multiple parameter configuration registers, and the security flag register is one of the multiple parameter configuration registers. The value of the security flag register can only be set by a processor core in a secure state, which means that only a processor core in a secure state can access the security flag register and set and modify the value of the security flag register. Since the processor core in a secure state is running a software application with security requirements, it can be understood that the value of the security flag register can only be set by a software application with security requirements. More specifically, only when the processor core connected to the cache processing unit where the security flag register is located is in a secure state, the processor core in a secure state can access the security flag register in the cache processing unit corresponding to the processor core (i.e., connected via a bus), for example, the value of the security flag register is set by a software application with security requirements running by the processor core in a secure state.
[0096] The security flag register is used to define whether the message filter in which it is located is a secure message filter or an unsecure message filter. More specifically, a processor core in a secure state can set the message filter in which it is located to a secure message filter or an unsecure message filter by setting the value of the security flag register. The secure message filter is used to filter the security identification bit in the transmitted message to select the secure transmitted message; the unsecure message filter is used to filter the security identification bit in the transmitted message to select the unsecure transmitted message. It is easy to understand that a cache processing unit can include one or more secure message filters and one or more unsecure message filters.
[0097] As described above, each enabled message filter has its corresponding cache address segment, and accordingly, each secure message filter and each non-secure message filter has a corresponding cache address segment. The range of the cache address segment corresponding to the secure message filter is within the address range of the secure cache area, and the range of the cache address segment corresponding to the non-secure message filter is within the address range of the non-secure cache area, so that secure delivery messages are routed to the secure cache area, and non-secure delivery messages are routed to the non-secure cache area.
[0098] As described above, the processor core sets the range of the cache address segment corresponding to the message filter by setting the value of the parameter configuration register in the message filter in the corresponding cache processing unit. In this embodiment, the processor core (specifically, the software application running on the processor core) can only set the corresponding cache address segment to the address range of the secure cache area by setting the value of the parameter configuration register of the secure message filter; if the processor core attempts to set the cache address segment corresponding to the secure message filter to the address range of the non-secure cache area, it will not be actually implemented, and an address segment configuration error will be returned to the processor. Correspondingly, the processor core (specifically, the software application running on the processor core) can only set the corresponding cache address segment to the address range of the non-secure cache area by setting the value of the parameter configuration register of the non-secure message filter; if the processor core attempts to set the cache address segment corresponding to the non-secure message filter to the address range of the secure cache area, it will not be actually implemented, and an address segment configuration error will be returned to the processor.
[0099] According to this embodiment, by setting a secure message filter and an unsecure message filter, secure delivery messages can only be routed to and cached in the secure cache area, and unsecure delivery messages can only be routed to and cached in the unsecure cache area. Thus, it is easy to distinguish secure delivery messages from unsecure delivery messages at the consumer core end.
[0100] In some embodiments, the value of a parameter configuration register in a message filter of a secure message filter can only be set by a processor core in a secure state.
[0101] As described above, a processor core in a secure state can set the value of the security flag register in the message filter in its corresponding cache processing unit, thereby setting the message filter to a secure message filter or a non-secure message filter. When the message filter is set to a secure message filter, the other parameter configuration registers in the message filter can only be set by the processor core in a secure state, that is, the values of the other parameter configuration registers in the message filter (that is, all parameter configuration registers in the message filter) can only be set and modified by the processor core in a secure state (more specifically, the software application with security requirements running thereon). In other words, when the message filter is set to a secure message filter, the other filtering rules and other settings of the secure message filter can only be set by the processor core in a secure state.
[0102] On the other hand, when the message filter is set as a non-safe message filter, other parameter configuration registers in the message filter can be set by the processor core in a safe state or a non-safe state, that is, the values of other parameter configuration registers in the message filter can be set and modified by the processor core in a safe state or a non-safe state, more specifically, by software applications with security requirements or software applications without security requirements running on the processor core. In other words, when the message filter is set as a non-safe message filter, other filtering rules and other settings of the safe message filter can be set by the processor core in a safe state or a non-safe state.
[0103] According to this embodiment, the setting of the security message filter can only be performed by the processor core in the secure state, which prevents software applications without security requirements from tampering with the setting of the security message filter, thereby ensuring the reliability of secure message transmission and filtering.
[0104] Another aspect of the present application provides a chip circuit, comprising the inter-core communication system in the above-described embodiment. Exemplarily, the chip circuit may be a SOC chip.
[0105] The technical features of the above-described embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0106] The above-mentioned embodiments only express several implementation methods of the present invention, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.
Claims
1. An inter-core communication system, comprising a plurality of processor cores in a secure state or a non-secure state and a plurality of cache processing units corresponding to the plurality of processor cores one by one; wherein Each processor core is a producer core or a consumer core, the producer core is configured to generate a delivery message and write the delivery message into its corresponding cache processing unit, the consumer core is configured to read the delivery message from its corresponding cache processing unit, the delivery message includes a secure delivery message and an unsecure delivery message; and Each cache processing unit includes a receiving cache, which is divided into a secure cache area and a non-secure cache area. The secure transfer message is routed from the cache processing unit corresponding to the producer core to the secure cache area in the cache processing unit corresponding to the consumer core, and the non-secure transfer message is routed from the cache processing unit corresponding to the producer core to the non-secure cache area in the cache processing unit corresponding to the consumer core. The secure transfer message in the secure cache area can only be read by the consumer core in a secure state.
2. The inter-core communication system according to claim 1, wherein: The transfer message includes a security identification bit for indicating whether it is a secure transfer message or an unsecure transfer message; The producer core is further configured to generate a security state signal based on its hardware state, and write the security state signal together with the delivery message to its corresponding cache processing unit, wherein the security state signal indicates that the producer core is in a secure state or a non-secure state when writing the delivery message to its corresponding cache processing unit; The cache processing unit includes a security correction circuit, and the security correction circuit is configured to correct the security flag bit in the transfer message based on the security status signal and the security flag bit in the transfer message.
3. The inter-core communication system according to claim 2, wherein: The security correction circuit is configured to, when the security status signal indicates that the producer core is in a non-secure state and the security identification bit in the transfer message indicates that the transfer message is a secure transfer message, invert the security identification bit so that the transfer message is changed into a non-secure transfer message.
4. The inter-core communication system according to claim 2, wherein: The safety correction circuit comprises a first inverter, a second inverter, a third inverter and an AND gate circuit, the input end of the first inverter serves as the first input end of the safety correction circuit, the input end of the second inverter serves as the second input end of the safety correction circuit, the output end of the first inverter and the output end of the second inverter are respectively connected to the two input ends of the AND gate circuit, the output end of the AND gate circuit is connected to the input end of the third inverter, and the output end of the third inverter serves as the output end of the safety correction circuit; and The safety state signal is input to the first input terminal of the safety correction circuit, the safety identification bit is input to the second input terminal of the safety correction circuit, and the signal outputted from the output terminal of the safety correction circuit serves as the corrected safety identification bit.
5. The inter-core communication system according to claim 1, wherein: The cache processing unit also includes a configuration register, the value of which can only be set by a processor core in a secure state; and The processor core in a secure state divides the receiving buffer into the secure cache area and the non-secure cache area by setting the value of the configuration register in the cache processing unit corresponding to the processor core, and sets the address range of the secure cache area and the non-secure cache area.
6. The inter-core communication system according to claim 5, wherein: The cache processing unit further includes: one or more message filters, each message filter corresponding to a different cache address segment in the receiving cache; The one or more message filters are each configured to: receive the delivery message routed from the cache processing unit corresponding to the producer core, filter the received delivery message based on their own filtering rules, and write the filtered delivery message into the corresponding cache address segment.
7. The inter-core communication system according to claim 6, wherein: Each message filter includes a parameter configuration register, and the processor core sets the filtering rules of the message filter and the range of the cache address segment corresponding to the message filter by setting the value of the parameter configuration register in the message filter in the cache processing unit corresponding to the processor core.
8. The inter-core communication system according to claim 7, wherein: The parameter configuration register includes a security flag register, the value of which can only be set by a processor core in a secure state; The processor core in a secure state sets the message filter as a secure message filter or a non-secure message filter by setting the value of the security flag register in the message filter, wherein the secure message filter is configured to filter the secure delivery message, and the non-secure message filter is configured to filter the non-secure delivery message; and The range of the cache address segment corresponding to the secure message filter is within the address range of the secure cache area, and the range of the cache address segment corresponding to the non-secure message filter is within the address range of the non-secure cache area.
9. The inter-core communication system according to claim 8, wherein: The value of the parameter configuration register in the message filter of the secure message filter can only be set by a processor core in a secure state.
10. A chip circuit comprising the inter-core communication system according to any one of claims 1 to 9.