Chip for realizing secure access between circuits and access request processing method

By introducing firewall circuits or protection circuits into the chip, storing access permission configuration information and performing legality verification, the access security problem of internal circuits of the chip is solved, and access security and driving safety are improved.

CN120335424APending Publication Date: 2025-07-18SHANGHAI ANTING HORIZON INTELLIGENT TRANSP TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510401808.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

How to improve the access security between internal circuits of the chip and prevent adverse effects caused by illegal access, especially driving safety issues that may be caused by smart driving chips.

Method used

Introduce firewall circuits or protection circuits to store access permission configuration information, judge the legality of the access request through the legality verification mechanism, and allow access when the verification is passed, otherwise illegal access will be blocked.

Benefits of technology

Improve the security of circuit access, prevent the adverse effects of illegal access, and ensure the normal operation and driving safety of the chip.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120335424A_ABST
    Figure CN120335424A_ABST
Patent Text Reader

Abstract

The invention discloses a chip for realizing secure access between circuits and an access request processing method. The chip for realizing secure access between circuits comprises a storage circuit which is used for storing access permission configuration information corresponding to at least one slave control circuit; the master control circuit is used for generating an access request for a target slave control circuit in the at least one slave control circuit; the protection circuit is used for determining access permission configuration information corresponding to the target slave control circuit from the access permission configuration information stored in the storage circuit; based on the access permission configuration information corresponding to the target slave control circuit, performing legality verification on the access request to obtain a verification result; and processing the access request based on the verification result. According to the embodiment of the invention, by introducing a legality verification mechanism, legal access of the master control circuit to each slave control circuit can be allowed, illegal access of the master control circuit to each slave control circuit can be forbidden, and thus the access security can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to functional safety technology, and in particular to a chip for realizing secure access between circuits and an access request processing method. Background Art

[0002] Currently, chips are increasingly widely used. For example, in the field of intelligent driving, intelligent driving chips are increasingly widely used.

[0003] Inside a chip, some circuits may need to access other circuits. How to improve the access security in the above access scenarios is a technical problem worthy of attention for those skilled in the art. Summary of the Invention

[0004] To solve the above technical problems, the present disclosure provides a chip for realizing secure access between circuits and an access request processing method.

[0005] According to one aspect of the embodiments of the present disclosure, a chip for realizing secure access between circuits is provided, including:

[0006] A storage circuit, configured to store access permission configuration information respectively corresponding to at least one slave circuit;

[0007] A master control circuit, configured to generate an access request for a target slave circuit among at least one of the slave circuits;

[0008] A protection circuit, configured to determine the access permission configuration information corresponding to the target slave circuit from the access permission configuration information stored in the storage circuit; perform a legality check on the access request based on the access permission configuration information corresponding to the target slave circuit to obtain a check result; and process the access request based on the check result.

[0009] According to another aspect of the embodiments of the present disclosure, an access request processing method is provided, including:

[0010] Obtain an access request generated by a master control circuit for a target slave circuit among at least one slave circuit;

[0011] Determine the access permission configuration information corresponding to the target slave circuit from the access permission configuration information respectively corresponding to the stored at least one slave circuit;

[0012] Perform a legality check on the access request based on the access permission configuration information corresponding to the target slave circuit to obtain a check result;

[0013] Process the access request based on the check result.

[0014] According to another aspect of the embodiments of the present disclosure, there is provided a computer-readable storage medium storing a computer program for executing the above access request processing method.

[0015] According to another aspect of the embodiments of the present disclosure, there is provided an electronic device, including:

[0016] a processor;

[0017] a memory for storing executable instructions of the processor;

[0018] The processor is configured to read the executable instructions from the memory and execute the instructions to implement the above access request processing method.

[0019] According to another aspect of the embodiments of the present disclosure, there is provided a computer program product, when the instructions in the computer program product are executed by a processor, the above access request processing method is executed.

[0020] Based on the chip, access request processing method, storage medium, electronic device and program product for realizing secure access between circuits provided in the above embodiments of the present disclosure, if the master circuit needs to access the target slave circuit, the master circuit can initiate an access request for the target slave circuit to the protection circuit. The protection circuit can receive the access request from the master circuit and determine the access permission configuration information corresponding to the target slave circuit from the various access permission configuration information stored in the storage circuit. Since the access permission configuration information corresponding to the target slave circuit can be used to assist in judging the access permission of other circuits to the target slave circuit, referring to the access permission configuration information corresponding to the target slave circuit, the protection circuit can perform access permission-related judgment on the access request to implement the legality verification of the access request, thereby obtaining a verification result. The protection circuit can process the access request by a processing method adapted to the verification result. For example, if the verification result indicates that the legality verification of the access request passes, indicating that the access request is a legal request, the protection circuit can forward the access request to the target slave circuit so that the target slave circuit can respond to the access request, thereby realizing the legal access of the master circuit to the target slave circuit. For another example, if the verification result indicates that the legality verification of the access request fails, indicating that the access request is an illegal request, the protection circuit can not forward the access request to the target slave circuit to avoid the target slave circuit responding to the access request, thereby avoiding the illegal access of the master circuit to the target slave circuit. In this way, by introducing a legality verification mechanism, the legal access of the master circuit to each slave circuit can be allowed and the illegal access of the master circuit to each slave circuit can be prohibited, thereby improving the access security to avoid the adverse effects brought by illegal access. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 is a system architecture diagram applicable to some exemplary embodiments of the present disclosure.

[0022] Figure 2 is one of the schematic structural diagrams of a chip for implementing secure access between circuits provided by some exemplary embodiments of the present disclosure.

[0023] Figure 3 is a schematic diagram of the principle for determining the target permission status of a master control circuit under a target access type in some exemplary embodiments of the present disclosure.

[0024] Figure 4 is another schematic structural diagram of a chip for implementing secure access between circuits provided by some exemplary embodiments of the present disclosure.

[0025] Figure 5 is yet another schematic structural diagram of a chip for implementing secure access between circuits provided by some exemplary embodiments of the present disclosure.

[0026] Figure 6 is a schematic diagram for protecting input and output information of a circuit in some exemplary embodiments of the present disclosure.

[0027] Figure 7 is a schematic diagram of the working process of a circuit protection circuit in some exemplary embodiments of the present disclosure.

[0028] Figure 8-1 is a schematic diagram for protecting input and output information of a storage circuit in some exemplary embodiments of the present disclosure.

[0029] Figure 8-2 is a schematic diagram of remapping information in some exemplary embodiments of the present disclosure.

[0030] Figure 9 is one of the schematic flowcharts of an access request processing method provided by some exemplary embodiments of the present disclosure.

[0031] Figure 10 is another schematic flowchart of an access request processing method provided by some exemplary embodiments of the present disclosure.

[0032] Figure 11 is yet another schematic flowchart of an access request processing method provided by some exemplary embodiments of the present disclosure.

[0033] Figure 12 is still another schematic flowchart of an access request processing method provided by some exemplary embodiments of the present disclosure.

[0034] Figure 13It is the fifth schematic flowchart of the access request processing method provided by some exemplary embodiments of the present disclosure.

[0035] Figure 14 It is the schematic structural diagram of an electronic device provided by some exemplary embodiments of the present disclosure. Detailed implementation manners

[0036] To explain the present disclosure, exemplary embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. It should be understood that the present disclosure is not limited by the exemplary embodiments.

[0037] It should be noted that: unless otherwise specifically stated, the relative arrangements of components and steps, numerical expressions and values set forth in these embodiments do not limit the scope of the present disclosure.

[0038] Application Overview

[0039] Inside the chip, some circuits may need to access other circuits; among them, the circuit to be accessed can be called the slave circuit, and the circuit that accesses the slave circuit can be called the master circuit. Optionally, the master circuit can be represented as Master, and the slave circuit can be represented as Slaver.

[0040] In the process of implementing the present disclosure, the inventors found that the access security in the above access scenario is crucial for the normal operation of the chip. How to improve the access security in the above access scenario is a technical problem worthy of attention for those skilled in the art.

[0041] Exemplary System

[0042] To improve the access security in the above access scenario, as Figure 1 shown, a firewall circuit 10 can be introduced in the embodiments of the present disclosure; among them, the firewall circuit 10 can be a circuit for functionally protecting the slave circuit 20. The firewall circuit 10 can be represented as Firewall. The firewall circuit 10 can be electrically connected to the master circuit 30 and the slave circuit 20 respectively.

[0043] If the master circuit 30 needs to access the slave circuit 20, the master circuit 30 can send an access request for the slave circuit 20 to the firewall circuit 10. The firewall circuit 10 can receive the access request from the master circuit 30, perform a legality check on the access request, and obtain a check result. The firewall circuit 10 can also process the access request based on the check result.

[0044] For example, if the verification result indicates that the legitimacy verification of the access request has passed, it means that the access request is a legitimate request, and the firewall circuit 10 can forward the access request to the slave control circuit 20, so that the slave control circuit 20 can respond to the access request, thereby enabling the master control circuit 30 to legally access the slave control circuit 20.

[0045] For another example, if the verification result indicates that the legitimacy verification of the access request fails, it means that the access request is an illegal request, and the firewall circuit 10 can refrain from forwarding the access request to the slave control circuit 20 to prevent the slave control circuit 20 from responding to the access request, thereby avoiding the master control circuit 30 from illegally accessing the slave control circuit 20.

[0046] Generally speaking, when software and the like running on the chip jointly belonging to the master control circuit 30 and the slave control circuit 20 are maliciously attacked, illegal access of the master control circuit 30 to the slave control circuit 20 may occur, affecting access security and causing unexpected behaviors in the chip jointly belonging to the master control circuit 30 and the slave control circuit 20. For example, if the chip jointly belonging to the master control circuit 30 and the slave control circuit 20 is an intelligent driving chip, and there is an obstacle in front of the vehicle equipped with the intelligent driving chip, if the vehicle does not decelerate or stop, it is very likely that the vehicle will collide with the obstacle. In normal circumstances, the intelligent driving chip and / or the software running on it need to control the vehicle to decelerate or stop. However, due to the above-mentioned malicious attack, the master control circuit 30 may illegally access the slave control circuit 20, resulting in information for prompting the vehicle to accelerate being written into the slave control circuit 20, causing the intelligent driving chip to control the vehicle to accelerate, which is obviously an unexpected behavior and will affect driving safety.

[0047] In view of this, in the embodiments of the present disclosure, by introducing a legitimacy verification mechanism, legal access of the master control circuit 30 to the slave control circuit 20 can be allowed, and illegal access of the master control circuit 30 to the slave control circuit 20 can be prohibited, thereby enhancing access security to avoid the adverse effects brought by illegal access, such as avoiding illegal access from affecting driving safety.

[0048] Exemplary Chip

[0049] Embodiments of the present disclosure provide a chip for realizing secure access between circuits. The chip for realizing secure access between circuits can be, for example, an intelligent driving chip, an intelligent cockpit chip, etc. For the sake of simplicity, the chip for realizing secure access between circuits can be abbreviated as the target chip in the following text.

[0050] As Figure 2 shown, the target chip may include:

[0051] A storage circuit 40, which is used to store access permission configuration information corresponding to at least one slave control circuit 20 respectively;

[0052] The main control circuit 30 is configured to generate an access request for a target slave control circuit among at least one slave control circuit 20;

[0053] The protection circuit 45 is configured to determine, from the access permission configuration information stored in the storage circuit 40, the access permission configuration information corresponding to the target slave control circuit; perform a legality check on the access request based on the access permission configuration information corresponding to the target slave control circuit to obtain a check result; and process the access request based on the check result.

[0054] Optionally, the main control circuit 30 can be any circuit in the target chip that can actively initiate an access request. For example, the main control circuit 30 can be a Central Processing Unit (CPU), a Microcontroller Unit (MCU), a Graphics Processing Unit (GPU), etc. The access request can be, for example, a read request, a write request, etc.

[0055] Optionally, the slave control circuit 20 can be a circuit in the target chip that passively receives an access request and is a circuit with a configuration space and / or a storage space; wherein, the configuration space can be a space for storing configuration information; the storage space can be a space for storing data. For example, the slave control circuit 20 can be a Static Random Access Memory (SRAM), a register, a peripheral interface, etc.

[0056] It should be noted that the number of slave control circuits 20 can be at least one. If the main control circuit 30 needs to access any one of the at least one slave control circuit 20, then this slave control circuit 20 can be used as the target slave control circuit, and the main control circuit 30 can generate an access request for the target slave control circuit. The access request can carry the main control identifier of the main control circuit 30 (such as the target main control identifier in the following text) and the requested access address of the access request. The target main control identifier can be, for example, the ID of the main control circuit 30, and the ID of the main control circuit 30 can also be expressed as Master ID. If the access request is a read request, the requested access address of the access request can be a read address. If the access request is a write request, the requested access address of the access request can be a write address.

[0057] Optionally, a Figure 1 firewall circuit 10 can be introduced to perform functional safety protection on the slave control circuit 20. The firewall circuit 10 can include: a storage circuit 40 and a protection circuit 45.

[0058] Optionally, the storage circuit 40 may be a circuit with storage function in the target chip. The storage circuit 40 may be, for example, various types of memories. The storage circuit 40 may store at least one piece of access permission configuration information corresponding to each slave control circuit 20 respectively; wherein, the access permission configuration information corresponding to any one slave control circuit 20 may be configuration information for assisting in determining the access permission of other circuits to the slave control circuit 20. Here, the storage circuit 40 may include multiple storage regions (Regions); wherein, each of the multiple Regions may store at least part of the access permission configuration information corresponding to one slave control circuit 20. In this way, the storage of all the access permission configuration information corresponding to one slave control circuit 20 may only require one Region, or may require more than one Region.

[0059] Optionally, the protection circuit 45 may be a circuit in the target chip for performing functional safety protection on the slave control circuit 20 to prevent the slave control circuit 20 from being illegally accessed. The protection circuit 45 may be electrically connected to the master control circuit 30, the storage circuit 40, and at least one slave control circuit 20 respectively, so that the protection circuit 45 can communicate with the master control circuit 30, the storage circuit 40, and at least one slave control circuit 20 respectively.

[0060] In an embodiment of the present disclosure, if the master control circuit 30 needs to access a target slave control circuit, the master control circuit 30 may initiate an access request for the target slave control circuit to the protection circuit 45. The protection circuit 45 may receive the access request from the master control circuit 30, and determine the access permission configuration information corresponding to the target slave control circuit from the various access permission configuration information stored in the storage circuit 40. Since the access permission configuration information corresponding to the target slave control circuit can be used to assist in judging the access permission of other circuits to the target slave control circuit, referring to the access permission configuration information corresponding to the target slave control circuit, the protection circuit 45 may perform access permission-related judgment on the access request to implement the legality verification of the access request, thereby obtaining a verification result. The protection circuit 45 may process the access request by adopting a processing method adapted to the verification result. For example, if the verification result indicates that the legality verification of the access request passes, indicating that the access request is a legal request, the protection circuit 45 may forward the access request to the target slave control circuit so that the target slave control circuit responds to the access request, thereby realizing the legal access of the master control circuit 10 to the target slave control circuit. For another example, if the verification result indicates that the legality verification of the access request fails, indicating that the access request is an illegal request, the protection circuit 45 may not forward the access request to the target slave control circuit to avoid the target slave control circuit responding to the access request, thereby avoiding the illegal access of the master control circuit 30 to the target slave control circuit. In this way, by introducing a legality verification mechanism, the legal access of the master control circuit 30 to each slave control circuit 20 can be allowed, and the illegal access of the master control circuit 30 to each slave control circuit 20 can be prohibited, thereby improving the access security to avoid the adverse effects brought by illegal access, such as avoiding the illegal access affecting the driving safety.

[0061] In some alternative examples, among the various access permission configuration information stored in the storage circuit 40, each access permission configuration information may include: an address range and permission information;

[0062] Before the protection circuit 45 is used to determine the access permission configuration information corresponding to the target slave control circuit from the various access permission configuration information stored in the storage circuit 40, the protection circuit 45 is further used to determine the requested access address of the access request and determine the distribution information of the requested access address relative to each address range;

[0063] The protection circuit 45 is used to determine the access permission configuration information corresponding to the target slave control circuit from the various access permission configuration information stored in the storage circuit 40; based on the access permission configuration information corresponding to the target slave control circuit, performing legality verification on the access request may include:

[0064] The protection circuit 45 is configured to determine, based on the distribution information, the access permission configuration information corresponding to the target slave circuit from the access permission configuration information stored in the storage circuit 40, and perform a legality check on the access request based on the permission information in the access permission configuration information corresponding to the target slave circuit.

[0065] Optionally, the distribution information of the requested access address relative to any address range can be used to indicate whether the requested access address is within that address range.

[0066] As introduced above, the storage circuit 40 may include multiple Regions. Each Region of the multiple Regions may store at least partial access permission configuration information corresponding to one slave circuit 20.

[0067] If each Region of the multiple Regions stores all the access permission configuration information corresponding to one slave circuit 20, then for any Region of the multiple Regions, the address range included in the access permission configuration information stored in that Region may be the address range of the target space (which includes the configuration space and / or the storage space) of the corresponding slave circuit 20, and the permission information included in the access permission configuration information stored in that Region may be information used to assist in determining the access permission of other circuits to the target space.

[0068] If each Region of the multiple Regions stores partial access permission configuration information corresponding to one slave circuit 20, then for any Region of the multiple Regions, the address range included in the access permission configuration information stored in that Region may be a proper subset of the address range of the target space (which includes the configuration space and / or the storage space) of the corresponding slave circuit 20, and the permission information included in the access permission configuration information stored in that Region may be information used to assist in determining the access permission of other circuits to the subspace corresponding to the proper subset in the target space.

[0069] Optionally, the access request may carry a requested access address, and the protection circuit 45 may extract the requested access address from the access request. The protection circuit 45 may also compare the requested access address with the address ranges in the access permission configuration information stored in each Region to determine the distribution information of the requested access address relative to each address range. The protection circuit 45 may also determine the access permission configuration information corresponding to the target slave circuit from the access permission configuration information stored in the storage circuit 40 based on the distribution information. For example, if a certain distribution information indicates that the requested access address is within the corresponding address range, the protection circuit 45 may determine the access permission configuration information where the distribution information is located as the access permission configuration information corresponding to the target slave circuit. The protection circuit 45 may also perform a legality check on the access request based on the permission information in the access permission configuration information corresponding to the target slave circuit to obtain a check result. For example, if the permission information indicates that the master circuit 30 has the permission to access the target space of the target slave circuit, the check result may indicate that the legality check of the access request passes. For another example, if the permission information indicates that the master circuit 30 does not have the permission to access the target space of the target slave circuit, the check result may indicate that the legality check of the access request fails.

[0070] In the embodiments of the present disclosure, by comparing the requested access address of the access request with the address ranges in each access permission configuration information respectively, the access permission configuration information corresponding to the target slave circuit can be efficiently and reliably located, so that the permission information in the access permission configuration information corresponding to the target slave circuit can be used for the legality check of the access request. In this way, the permission information adapted to the access request can be used for the legality check of the access request, which is beneficial to improving the accuracy and reliability of the check result.

[0071] In some alternative examples, the protection circuit 45 for performing a legality check on the access request based on the access permission configuration information corresponding to the target slave circuit may include:

[0072] The protection circuit 45 is used to determine the target access type of the access request, determine the target permission status of the master circuit 30 in the target access type based on the access permission configuration information corresponding to the target slave circuit, and perform a legality check on the access request based on the target permission status.

[0073] Optionally, there may be two cases for the target access type of the access request, namely the read type and the write type. The protection circuit 45 may determine the target permission status of the master circuit 30 in the target access type based on the access permission configuration information corresponding to the target slave circuit; wherein, the target permission status may indicate whether the master circuit 30 has the permission to perform an access of the target access type to the target slave circuit.

[0074] In some alternative embodiments of the present disclosure, the access permission configuration information corresponding to the target slave control circuit may include: the target number of master identifiers, the read-write permission status mapped by each of the target number of master identifiers; and one of the target number of master identifiers is used as a predetermined master identifier.

[0075] The protection circuit 45 is configured to determine the target permission status of the master control circuit 30 under the target access type based on the access permission configuration information corresponding to the target slave control circuit, and may include:

[0076] The protection circuit 45 is configured to, in response to the target master identifier of the master control circuit 30 being any one of the target number of master identifiers, determine the target permission status of the master control circuit 30 under the target access type based on the read-write permission status mapped by the target master identifier in the access permission configuration information corresponding to the target slave control circuit;

[0077] Or,

[0078] The protection circuit 45 is configured to, in response to the target master identifier of the master control circuit 30 being different from any one of the target number of master identifiers, determine the target permission status of the master control circuit 30 under the target access type based on the read-write permission status mapped by the predetermined master identifier in the access permission configuration information corresponding to the target slave control circuit.

[0079] Optionally, the target number of master identifiers may be a number less than a preset maximum value; wherein, the preset maximum value may be a pre-set maximum number of master control circuits 30 in the target chip. For example, if the preset maximum number is 128, the target number of master identifiers may be 32.

[0080] Optionally, the master identifier may be a Master ID. The read-write permission status mapped by any one master identifier may indicate whether the master control circuit 30 having this master identifier has read permission and whether it has write permission. Which one of the target number of master identifiers is used as the predetermined master identifier may be pre-set.

[0081] The protection circuit 45 may receive an access request from the master control circuit 30, and the access request may carry the target master identifier. The protection circuit 45 may compare the target master identifier with the target number of master identifiers in the access permission configuration information corresponding to the target slave control circuit respectively.

[0082] If the target master identifier is the same as any one of the target number of master identifiers, it indicates that the read / write permission status mapped by the target master identifier exists in the access permission configuration information corresponding to the target slave circuit. Then, the protection circuit 45 can directly determine the target permission status of the master circuit 30 in the target access type based on the read / write permission status mapped by the target master identifier in the access permission configuration information corresponding to the target slave circuit. For example, if the read / write permission status mapped by the target master identifier indicates that the master circuit 30 with the target master identifier has read permission and write permission, the target permission status can indicate that the master circuit 30 has the permission to access the target slave circuit in the target access type. If the read / write permission status mapped by the target master identifier indicates that the master circuit 30 with the target master identifier does not have read permission and write permission, the target permission status can indicate that the master circuit 30 does not have the permission to access the target slave circuit in the target access type. If the read / write permission status mapped by the target master identifier indicates that the master circuit 30 with the target master identifier only has read permission, in the case where the target access type is the read type, the target permission status can indicate that the master circuit 30 has the permission to access the target slave circuit in the target access type, while in the case where the target access type is only the write type, the target permission status can indicate that the master circuit 30 does not have the permission to access the target slave circuit in the target access type.

[0083] If the target master identifier is not the same as any one of the target number of master identifiers, it indicates that the read / write permission status mapped by the target master identifier does not exist in the access permission configuration information corresponding to the target slave circuit. Then, the protection circuit 45 can determine the target permission status of the master circuit 30 in the target access type based on the read / write permission status mapped by a predetermined master identifier in the access permission configuration information corresponding to the target slave circuit. The specific determination method can refer to the relevant introduction in the above text about the method of determining the target permission status based on the read / write permission status mapped by the target master identifier in the access permission configuration information corresponding to the target slave circuit, and will not be elaborated here.

[0084] In an example, the target number of master identifiers in the access permission configuration information corresponding to the target slave circuit can be 32 master identifiers, which are sequentially represented as Figure 3 id_0, id_1, id_2,..., id_31 in Figure 3 And, in the access permission configuration information corresponding to the target slave circuit, the read / write permission status mapped by the master identifier id_0 is Figure 3 the read / write permission status 0 in Figure 3The read / write permission status 2 in..., the read / write permission status mapped by the master control identifier id_31 is expressed as Figure 3 The read / write permission status 31 in. Additionally, Figure 3 The master control identifier id_31 in is used as the predetermined master control identifier.

[0085] If the target master control identifier carried in the access request initiated by the master control circuit 30 is any one of id_0, id_1, id_2,..., id_31, for example, id_2, since the read / write permission status mapped by id_2 is the read / write permission status 2, the protection circuit 45 can determine the target permission status of the master control circuit 30 in the target access type based on the read / write permission status 2.

[0086] If the target master control identifier carried in the access request initiated by the master control circuit 30 is not any one of id_0, id_1, id_2,..., id_31, for example, id_50, since the predetermined master control identifier is id_31, and the read / write permission status mapped by id_31 is the read / write permission status 31, the protection circuit 45 can determine the target permission status of the master control circuit 30 in the target access type based on the read / write permission status 31.

[0087] In this embodiment, the access permission configuration information corresponding to the target slave control circuit does not need to include the read / write permission status mapped by each of all the master control circuits 30, but only needs to include the read / write permission status mapped by some of the master control circuits 30. If there is no corresponding read / write permission status in the access permission configuration information for an access request initiated for a certain master control circuit 30, the read / write permission status mapped by the predetermined master control identifier can be directly reused. In this way, it is beneficial to reduce the amount of information of the access permission configuration information corresponding to the target slave control circuit, thereby saving the space required to store the access permission configuration information corresponding to the target slave control circuit.

[0088] Of course, the method for the protection circuit 45 to determine the target permission status of the master control circuit 30 in the target access type is not limited to this. For example, if the preset maximum number is represented as M, the access permission configuration information corresponding to the target slave control circuit may include: M master control identifiers and the read / write permission status mapped by each of the M master control identifiers. In this case, the protection circuit 45 can directly determine the target permission status of the master control circuit 30 in the target access type based on the read / write permission status mapped by the target master control identifier in the access permission configuration information corresponding to the target slave control circuit.

[0089] After determining the target permission status, the main control circuit 10 may perform a legality check on the access request based on the target permission status to obtain a check result. For example, if the target permission status indicates that the main control circuit 30 has the permission to access the target slave circuit in the target access type, the check result may indicate that the legality check of the access request passes. For another example, if the target permission status indicates that the main control circuit 30 does not have the permission to access the target slave circuit in the target access type, the check result may indicate that the legality check of the access request fails.

[0090] In the embodiments of the present disclosure, for different access types, the protection circuit 45 may perform a legality check on the access request according to the corresponding permission status. That is, for the access of various access types, the embodiments of the present disclosure can improve the access security, can better ensure the security of the target chip, and avoid unexpected behaviors of the entire target chip due to malicious attacks (for example, refer to the introduction in the above "Exemplary System" section).

[0091] In some alternative examples, the protection circuit 45 for performing a legality check on the access request based on the access permission configuration information corresponding to the target slave circuit may include:

[0092] The protection circuit 45 is configured to determine the target security type of the access request, determine the configured security type based on the access permission configuration information corresponding to the target slave circuit, and perform a legality check on the access request based on the target security type and the configured security type.

[0093] Optionally, the access request may carry the target security type, and the protection circuit 40 may extract the target security type from the access request. The target security type may have two cases, namely the first type representing security and the second type representing non-security.

[0094] Optionally, the access permission configuration information corresponding to the target slave circuit may include: the configured security type, and the protection circuit 45 may extract the configured security type from the access permission configuration information corresponding to the target slave circuit. Similar to the target security type, the configured security type may also have two cases, namely the first type representing security and the second type representing non-security.

[0095] If the configured security type is the first type, then when the target security type is the first type, the check result may indicate that the legality check of the access request passes, and when the target security type is the second type, the check result may indicate that the legality check of the access request fails.

[0096] If the configured security type is the second type, regardless of whether the target security type is the first type or the second type, the check result may indicate that the legality check of the access request passes.

[0097] In this way, by combining the target security type of the access request and the configured security type in the access permission configuration information corresponding to the target slave circuit, the legality verification of the access request can be carried out efficiently and reliably.

[0098] It should be noted that the above introduces the method for verifying the legality of the access request. For example, the legality of the access request can be verified based on the target permission status. For another example, the legality of the access request can be verified based on the target security type and the configured security type. In specific implementation, these two methods can also be used in combination. For example, if the target permission status indicates that the master circuit 30 has the permission to access the target slave circuit in the target access type, and both the target security type and the configured security type are the first type, the verification result can indicate that the legality verification of the access request passes. If the target permission status indicates that the master circuit 30 does not have the permission to access the target slave circuit in the target access type, and / or the target security type is the second type and the configured security type is the first type, the verification result can indicate that the legality verification of the access request fails.

[0099] In some alternative examples, the number of protection circuits 45 can be multiple, and different protection circuits 45 can correspond to different master circuits 30. For example, the number of protection circuits 45 can be R, and an input bus can be provided between each protection circuit 45 and the corresponding master circuit 30 for transmitting the access request; where R can be an integer greater than or equal to 2.

[0100] The protection circuit 45 is used to verify the legality of the access request and obtain a verification result, which may include:

[0101] Each protection circuit 45 is used to verify the legality of the access request from the corresponding master circuit 30 and obtain the corresponding verification result;

[0102] The target chip may further include:

[0103] A notification circuit 50, and the notification circuit 50 is used to notify the verification results corresponding to the respective protection circuits 45 to the storage circuit 40;

[0104] The storage circuit 40 is used to record the abnormal information corresponding to the access request from the corresponding master circuit 30 in response to the verification result corresponding to any one of the protection circuits 45 indicating that the legality verification fails.

[0105] Optionally, the notification circuit 50 can be a circuit in the target chip for notifying the verification result obtained by the protection circuit 45 to the storage circuit 40. The notification circuit 50 can be electrically connected to the R protection circuits 45 and the storage circuit 40 respectively.

[0106] In one example, as Figure 4 shown, the number of protection circuits 45 and main control circuits 30 can both be five. The five protection circuits 45 and the five main control circuits 30 can correspond one by one. Among them, for each protection circuit 45, an input bus and an output bus can be provided. The input bus can be used for communication between the protection circuit 45 and the main control circuit 30, and the output bus can be used for communication between the protection circuit 45 and the slave control circuit 20. The storage circuit 40 can include: a memory and a storage controller. The memory has a storage function, and the storage controller can execute control and processing logic related to storage. The five protection circuits 45 can respectively perform legality verification on access requests from the corresponding main control circuits 30 to obtain verification results. The notification circuit 50 can notify each verification result to the storage circuit 40. For example, the notification circuit 50 can be a multiplexer. The multiplexer can include: five input terminals and one output terminal. Each of the five input terminals can be electrically connected to a protection circuit 45 respectively, and one output terminal can be electrically connected to the storage circuit 40. For any protection circuit 45, if the corresponding verification result indicates that the legality verification of the access request passes, the signal it transmits to the corresponding input terminal can be a low-level signal; if the corresponding verification result indicates that the legality verification of the access request fails, the signal it transmits to the corresponding input terminal can be a high-level signal. If the five signals received by the five input terminals are all low-level signals, the multiplexer can output a low-level signal to the storage circuit 40. In response to receiving the low-level signal, the storage controller in the storage circuit 40 can determine that none of the protection circuits 45 have detected an illegal request. If at least one of the five signals received by the five input terminals is a high-level signal, the multiplexer can output a high-level signal to the storage circuit 40, and the multiplexer can also output the identifier of the input terminal from which the high-level signal comes to the storage circuit 40. The storage controller in the storage circuit 40 can determine that the protection circuit 45 corresponding to the input terminal with this identifier has detected an illegal request. The storage controller in the storage circuit 40 can record the abnormal information corresponding to the access request that belongs to the illegal request in the memory of the storage circuit 40. The abnormal information can include the main control identifier of the main control circuit 30 from which the access request comes, the requested access address of the access request, etc.

[0107] In embodiments of the present disclosure, the number of protection circuits 45 can be multiple. Different protection circuits 45 can correspond to different main control circuits 30. Then, for access requests from different main control circuits 30, different protection circuits 45 can perform legality verification and subsequent processing of the access requests. Different protection circuits 45 can work in parallel, which is beneficial to improving the access efficiency. In addition, through the setting of the notification circuit 50, the verification results corresponding to each protection circuit 45 can be notified to the storage circuit 40, so that the storage circuit 40 stores the abnormal information corresponding to illegal requests. Subsequently, the abnormal information can be called in a software manner for the user side to view the abnormal information.

[0108] In some alternative examples, the storage circuit 40 may include:

[0109] A first set of registers for storing each access permission configuration information;

[0110] A second set of registers for storing abnormal information;

[0111] Wherein, the target slave circuit is any register in the first set of registers or any register in the second set of registers.

[0112] Optionally, the memory in the storage circuit 40 may include a large number of registers, which can be divided into two groups. One group is used to store access permission configuration information and can be called the first set of registers, and the other group is used to store abnormal information and can be called the second set of registers. The main control circuit 30 can initiate an access request to the protection circuit 45 for the target slave circuit. If the target slave circuit is any register in the first set of registers, when it is determined through legality verification that the access request is a legal access request, the main control circuit 30 can access the access permission configuration information in the register. If the target slave circuit is any register in the second set of registers, when it is determined through legality verification that the access request is a legal access request, the main control circuit 30 can access the abnormal information in the register.

[0113] In embodiments of the present disclosure, the registers in the storage circuit 40 can themselves be used as the target slave circuit. In this way, the protection circuit 45 can perform functional safety protection on the registers in the storage circuit 40 to ensure the security of the access permission configuration information and the abnormal information. For example, it can prevent the access permission configuration information from being illegally tampered with and prevent the abnormal information from being illegally obtained, etc.

[0114] In some embodiments, the target slave circuit may not be a register in the storage circuit 40, but other circuits independent of the storage circuit 40. The present disclosure does not limit this.

[0115] In some optional examples, the protection circuit 45 is used to process the access request based on the verification result, and may include:

[0116] The protection circuit 45 is used to forward the access request to the target slave circuit in response to the verification result indicating that the legality verification has passed, so that the target slave circuit performs the request response operation corresponding to the access request;

[0117] Or,

[0118] The protection circuit 45 is used to intercept the access request and output an exception prompt corresponding to the access request in response to the verification result indicating that the legality verification has failed;

[0119] Or,

[0120] The protection circuit 45 is used to determine the communication protocol used by the protection circuit 45 in response to the verification result indicating that the legality verification has failed, and forward the access request with the default access address as the destination address in response to the communication protocol used by the protection circuit 45 being the preset communication protocol;

[0121] Or,

[0122] The protection circuit 45 is used to determine the communication protocol used by the protection circuit 45 in response to the verification result indicating that the legality verification has failed, and intercept the access request and return an exception prompt corresponding to the access request to the main control circuit 30 in response to the communication protocol used by the protection circuit 45 being different from the preset communication protocol.

[0123] Optionally, the communication protocol used by the protection circuit 45 may include but is not limited to the Advanced eXtensible Interface (AXI) protocol, the Advanced Peripheral Bus (APB) protocol, the Advanced High performance Bus (AHB) protocol, etc. The preset communication protocol may be the AXI protocol.

[0124] Optionally, the default access address may be a pre-set address of the space that can be contaminated. The default access address may be pre-stored in the storage circuit 40. Here, the "space that can be contaminated" can be understood as a space where no matter what data is stored, it will not have an adverse impact on the normal operation of the target chip.

[0125] The main control circuit 30 may initiate an access request to the target slave circuit to the protection circuit 45, and the protection circuit 45 may perform a legality verification on the received access request.

[0126] If the verification result indicates that the legality verification of the access request passes, it means that the access request is a legal request. The protection circuit 45 can forward the access request to the target slave circuit so that the target slave circuit can execute the request response operation corresponding to the access request.

[0127] For example, if the access request is a read request, the target slave circuit can, in response to the read request, read data from the requested access address and return a read feedback including the read data (which can be referred to as read data) to the protection circuit 45. The protection circuit 45 can forward the received read feedback to the master control circuit 30.

[0128] For another example, if the access request is a write request, the target slave circuit can, in response to the write request, write the write data indicated by the write request to the requested access address and return a write feedback indicating write success or write failure to the protection circuit 45. The protection circuit 45 can forward the received write feedback to the master control circuit 30.

[0129] If the verification result indicates that the legality verification of the access request fails, it means that the access request is an illegal request. Then, there can be the following three situations:

[0130] (1) The protection circuit 45 can intercept the access request to prevent the access request from being forwarded to the target slave circuit, thereby achieving functional safety protection for the target slave circuit. Moreover, the protection circuit 45 can output an exception prompt to the software running on the target chip to indicate that an illegal request has been detected. Subsequently, the software running on the target chip can call the exception information stored in the second set of registers.

[0131] (2) The protection circuit 45 can determine the communication protocol it uses. If the communication protocol used by the protection circuit 45 is a preset communication protocol, such as the AXI protocol, the protection circuit 45 can forward the access request with the default access address as the destination address. Accordingly, the access request belonging to the illegal request will be forwarded to the pre-set space that can be contaminated instead of being forwarded to the space corresponding to the requested access address. In this way, it is beneficial to prevent the space in the target slave circuit from being contaminated, thereby achieving functional safety protection for the target slave circuit and ensuring the normal operation of the target chip.

[0132] (3) The protection circuit 45 can determine the communication protocol it uses. If the communication protocol used by the protection circuit 45 is different from the preset communication protocol, for example, it is the APB protocol or the AHB protocol, the protection circuit 45 can intercept the access request to prevent the access request from being forwarded to the target slave circuit, thereby achieving the functional safety protection of the target slave circuit. Moreover, the protection circuit 45 can output an exception prompt to the software running on the target chip to indicate that an illegal request has been detected, and the software running on the target chip can subsequently call the exception information stored in the second set of registers.

[0133] In the embodiments of the present disclosure, if the protection circuit 45 determines that the access request is a legal request, the protection circuit 45 can normally forward the access request so that the target slave circuit performs the request response operation corresponding to the access request, thereby completing the normal access of the master circuit 30 to the target slave circuit. If the protection circuit 45 determines that the access request is an illegal request, the protection circuit 45 can handle the access request by means of interception, forwarding with the default access address as the destination address, etc., so as to better achieve the functional safety protection of the target slave circuit. Additionally, if the protection circuit 45 determines that the access request is an illegal request, the protection circuit 45 can also notify the software running on the target chip of the detected illegal request situation efficiently and reliably through the output of an exception prompt. Correspondingly, the software running on the target chip can further determine whether the access request is indeed an illegal request. If the software running on the target chip determines that the access request is not an illegal request, the software running on the target chip can check the correctness of the access permission configuration information corresponding to the target slave circuit. If the software running on the target chip determines that the access request is indeed an illegal request, the software running on the target chip can subsequently try to avoid the access of the master circuit 30 that initiated the access request to the target space of the target slave circuit.

[0134] In some alternative examples, the storage circuit 40 is in the hardware lock state, and in the hardware lock state, each access permission configuration information stored in the storage circuit 40 is prohibited from being modified.

[0135] As introduced above, the storage circuit 40 may include: a first set of registers, and the first set of registers is used to store each access permission configuration information. It should be noted that each register in the first set of registers can be a register with a hardware lock function. During the initialization process of the target chip, the software running on the target chip can enable the hardware lock functions of these registers, so that these registers are all in the hardware lock state. In this way, during the operation of the target chip, each access permission configuration information stored in the storage circuit 40 is prohibited from being modified, that is, each access permission configuration information stored in the storage circuit 40 cannot be illegally rewritten, which is beneficial to improving the security of each access permission configuration information stored in the storage circuit 40.

[0136] In some alternative examples, the master control circuit 30 may be represented as Master, the slave control circuit 20 may be represented as Slaver, and the firewall circuit 10 may be represented as Firewall. Generally speaking, Master belongs to the upstream circuit and Slaver belongs to the downstream circuit.

[0137] As Figure 5 shown, the upstream Master may initiate an access request to the Firewall. The Firewall may determine whether to allow the upstream Master to access the downstream Slave (equivalent to performing a legality check on the access request above) based on the requested access address, Master ID (equivalent to the target master identifier above), and security / non-security information (equivalent to the target security type above) carried in the access request. If the legality check of the access request passes, the Firewall may forward the access request to the downstream Slave and transmit the response information (e.g., read feedback or write feedback) fed back by the downstream Slave to the upstream Master. If the legality check of the access request fails, the Firewall may intercept the access request, directly feedback the transmission response to the upstream Master to avoid bus hang-up, and the Firewall may also output an exception prompt and record the exception information including the requested access address and Master ID.

[0138] Optionally, the protection circuit 45 included in the Firewall may be a Memory Protect Unit (MPU). The storage circuit 40 included in the Firewall may include multiple registers, and each register may have an area for information storage. Correspondingly, the storage circuit 40 may have multiple Regions, and the multiple Regions may be used to store access permission configuration information, exception information, etc. Here, the number of Regions is, for example but not limited to, 64, and the 64 Regions may be independent of each other (i.e., different Regions can be configured separately, and the information in different Regions may not affect each other). The MPU is an internal protection unit of the Firewall. The MPU performs a legality check on the access request by combining the requested access address, Master ID, security / non-security information carried in the access request, and the access permission configuration information stored in the corresponding Region, and the unit may also output an exception prompt. The number of MPUs may be one or multiple. Additionally, the Firewall may support a hardware lock mechanism for Slave access permissions to ensure that the access permission configuration information stored in the Region is not illegally rewritten, improving the security of the access permission configuration information.

[0139] Optionally, as Figure 6 shown, the MPU may include the following five groups of interfaces:

[0140] (a1) AXI / APB / AHB bus interface, used to receive access requests from the Master. The access requests may carry read / write addresses (equivalent to the request access address in the above text), security / non-security information (equivalent to the target security type in the above text), etc.;

[0141] (a2) Region address interface, used to receive the Region address from the Register (equivalent to the address range included in the access permission configuration information in the above text), so as to determine which Region the access request will fall into, and use the read / write and security / non-security access permissions of this Region for judgment (equivalent to determining the distribution information of the request access address relative to each address range in the above text, based on the distribution information, determining the access permission configuration information corresponding to the target slave circuit, and based on the permission information in the access permission configuration information corresponding to the target slave circuit, performing legality verification on the access request);

[0142] (a3) Master ID read / write access permission interface, used to receive the read / write permission status from the Register, so as to determine whether to allow the Master to read / write the downstream Slave corresponding to a certain Region (equivalent to the application of the read / write permission status in the above text);

[0143] (a4) Security / non-security access permission interface, used to receive the security / non-security configuration information from the Register. If the Region is configured with non-security access permission (equivalent to the case where the configured security type is the second type in the above text), then both secure and non-secure transmissions can access the Slave corresponding to this Region. If the Region is configured with security access permission (equivalent to the case where the configured security type is the first type in the above text), then only secure transmissions are allowed to access (that is, only when the target security type is the first type, the legality verification of the access request may pass);

[0144] (a5) Interrupt interface, used to output an exception prompt when the legality verification of the access request fails.

[0145] In some alternative examples, such as Figure 7As shown, the MPU can make a judgment based on the requested access address of the access request and the address range corresponding to each Region. If the requested access address is not within the address range corresponding to any Region, the MPU does not perform subsequent processing on the access request. If the requested access address is within the address range corresponding to a Region, a legality check is performed on the access request based on the permission information corresponding to the Region. If the legality check fails, for example, the Master does not have access permission to the Slave, and / or the Region only allows secure access, but the access request carries a non-secure signal (corresponding to the case where the target security type is the second type and the configured security type is the first type in the above text), the MPU intercepts the access request and outputs an exception prompt. If the legality check passes, the MPU forwards the access request to the downstream Slave.

[0146] In some alternative examples, as Figure 8-1 shown, the Register can provide the following types of information:

[0147] (c1) Region address (equivalent to the address range included in the access permission configuration information in the above text);

[0148] (c2) Read / write permission status;

[0149] (c3) Secure / non-secure configuration information (equivalent to the configured security type in the above text);

[0150] (c4) Default access address;

[0151] (c5) Remapping information (which can be referred to Figure 8-2 , used to indicate the IDs mapped by all master identifiers respectively, and this ID is specifically the remapping ID, where the IDs on the left are master identifiers and the IDs on the right are remapping IDs);

[0152] (6) Exception information.

[0153] Here, the MPU can obtain the master identifier from the access request from the Master. If, based on Figure 8-2 , the remapping ID mapped by this master identifier is determined, then a legality check can be performed on the access request based on the read / write permission status mapped by this remapping ID. For example, if the master identifier carried by the access request is id_1, based on Figure 8-2 , it is determined that the remapping ID mapped to id_1 is id_1, then a legality check can be performed on the access request based on the read / write permission status 1 mapped to id_1 in Figure 3 . If the master identifier carried by the access request is id_255, based on Figure 8-2, if it is determined that the remapped ID mapped to id_255 is id_31, then based on Figure 3 the read / write permission status 31 mapped by id_31 in

[0154] Optionally, Register can support a hardware lock mechanism. After the Region configuration is completed, the information stored in the Region can be in a locked state, and the information stored in the Region is not allowed to be rewritten. If the software running on the target chip determines that there is a problem with the Region configuration, the software running on the target chip can control the Firewall to reset, and at this time, the information stored in the Region can be unlocked and modified.

[0155] In some embodiments, Register can support a software lock mechanism. In this case, the information stored in the Region can also be in a locked state. When the correct password is entered, the information stored in the Region can be unlocked and modified.

[0156] In summary, in the embodiments of the present disclosure, by configuring the access permissions of each Slave, functional safety protection can be provided for each Slave and even the entire target chip. If the access request initiated by the Master is a legitimate request, the Master can access the downstream Slave. If the access request initiated by the Master is an illegal request, the Master cannot access the downstream Slave, and the Firewall can output an exception prompt and record the exception information. In addition, the embodiments of the present disclosure can provide three types of Firewalls, namely, the Firewall supporting the AXI protocol, the Firewall supporting the APB protocol, and the Firewall supporting the AHB protocol, to ensure the generality of the target chip.

[0157] Exemplary Method

[0158] Figure 9 is a schematic flowchart of a method for processing an access request provided by some exemplary embodiments of the present disclosure. Figure 9 The method shown may include:

[0159] Step 910, obtaining an access request generated by the master control circuit for a target slave circuit in at least one slave circuit;

[0160] Step 920, determining the access permission configuration information corresponding to the target slave circuit from the access permission configuration information respectively corresponding to at least one slave circuit stored;

[0161] Step 930, performing a legality check on the access request based on the access permission configuration information corresponding to the target slave circuit to obtain a check result;

[0162] Step 940. Process the access request based on the verification result.

[0163] In some alternative examples, among the access permission configuration information respectively corresponding to at least one slave control circuit, each piece of access permission configuration information includes: an address range and permission information;

[0164] As Figure 10 shown, before step 920, the method provided by the embodiments of the present disclosure may further include:

[0165] Step 1010. Determine the requested access address of the access request and determine the distribution information of the requested access address relative to each address range;

[0166] Step 920 may include:

[0167] Step 1020. Based on the distribution information, determine the access permission configuration information corresponding to the target slave control circuit from the stored pieces of access permission configuration information;

[0168] Step 930 may include:

[0169] Step 1030. Perform a legality verification on the access request based on the permission information in the access permission configuration information corresponding to the target slave control circuit.

[0170] In some alternative examples, as Figure 11 shown, step 930 may include:

[0171] Step 1110. Determine the target access type of the access request;

[0172] Step 1120. Based on the access permission configuration information corresponding to the target slave control circuit, determine the target permission status of the master control circuit in the target access type;

[0173] Step 1130. Perform a legality verification on the access request based on the target permission status.

[0174] In some alternative examples, the access permission configuration information corresponding to the target slave control circuit includes: a target number of master control identifiers, the read / write permission status mapped by each of the target number of master control identifiers; one of the target number of master control identifiers is used as a predetermined master control identifier;

[0175] Step 920 may include:

[0176] In response to the target master control identifier of the master control circuit being any one of the target number of master control identifiers, based on the read / write permission status mapped by the target master control identifier in the access permission configuration information corresponding to the target slave control circuit, determine the target permission status of the master control circuit in the target access type;

[0177] Or

[0178] In response to the target master identification of the master control circuit being different from any of the master identifications among the target number of master identifications, based on the read / write permission status mapped by the predetermined master identification in the access permission configuration information corresponding to the target slave control circuit, determine the target permission status of the master control circuit under the target access type.

[0179] In some alternative examples, as Figure 12 shown, step 930 may include:

[0180] Step 1210, determine the target security type of the access request;

[0181] Step 1220, based on the access permission configuration information corresponding to the target slave control circuit, determine the configured security type;

[0182] Step 1230, based on the target security type and the configured security type, perform a legality check on the access request.

[0183] In some alternative examples, as Figure 13 shown, step 930 may include:

[0184] Step 1310, perform a legality check on the access requests from different master control circuits respectively to obtain corresponding check results;

[0185] The method provided by the embodiments of the present disclosure further includes:

[0186] Step 1320, in response to any of the check results indicating that the legality check fails, record the exception information corresponding to the access request from the corresponding master control circuit.

[0187] In some alternative examples, step 940 may include:

[0188] In response to the check result indicating that the legality check passes, forward the access request to the target slave control circuit so that the target slave control circuit performs the request response operation corresponding to the access request;

[0189] Or

[0190] In response to the check result indicating that the legality check fails, intercept the access request and output an exception prompt;

[0191] Or

[0192] In response to the check result indicating that the legality check fails, determine the communication protocol used by the protection circuit. In response to the communication protocol used by the protection circuit being the preset communication protocol, forward the access request with the default access address as the destination address;

[0193] Alternatively,

[0194] In response to the verification result indicating that the legality verification fails, determine the communication protocol used by the protection circuit. In response to the communication protocol used by the protection circuit being different from the preset communication protocol, intercept the access request and output an exception prompt.

[0195] In some alternative examples, each access permission configuration information is stored in a first set of registers included in the storage circuit, and the exception information is stored in a second set of registers included in the storage circuit. The target slave circuit is any register in the first set of registers or any register in the second set of registers.

[0196] In some alternative examples, each access permission configuration information is stored in the storage circuit, and the storage circuit is in a hardware lock state. In the hardware lock state, each access permission configuration information stored in the storage circuit is prohibited from being modified.

[0197] In the method of the present disclosure, various alternative embodiments, alternative implementations, and alternative examples disclosed in the above-exemplary chip can be flexibly selected and combined as needed to achieve corresponding functions and effects, and the present disclosure does not list them one by one.

[0198] For the beneficial technical effects corresponding to the exemplary embodiments of the present method, reference can be made to the corresponding beneficial technical effects in the above-exemplary circuit part, and details are not repeated here.

[0199] Exemplary Electronic Device

[0200] Figure 14 The block diagram of an electronic device according to an embodiment of the present disclosure is illustrated. The electronic device 1400 includes one or more processors 1410 and a memory 1420.

[0201] The processor 1410 can be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and can control other components in the electronic device 1400 to perform desired functions.

[0202] The memory 1420 can include one or more computer program products, and the computer program products can include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory can include, for example, random access memory (RAM) and / or cache memory, etc. Non-volatile memory can include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions can be stored on the computer-readable storage media, and the processor 1410 can run one or more computer program instructions to implement the methods of the various embodiments of the present disclosure described above and / or other desired functions.

[0203] In one example, the electronic device 1400 may further include: an input device 1430 and an output device 1440, and these components are interconnected through a bus system and / or other forms of connection mechanisms (not shown).

[0204] The input device 1430 may further include, for example, a keyboard, a mouse, and so on.

[0205] The output device 1440 can output various information to the outside, which may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, and so on.

[0206] Of course, for simplicity, Figure 14 only some of the components related to the present disclosure in the electronic device 1400 are shown, and components such as a bus, an input / output interface, and so on are omitted. In addition, according to specific application scenarios, the electronic device 1400 may further include any other appropriate components.

[0207] Exemplary Computer Program Product and Computer Readable Storage Medium

[0208] In addition to the above methods and devices, an embodiment of the present disclosure may also be a computer program product, which includes computer program instructions that, when run by a processor, cause the processor to execute the steps in the methods according to various embodiments of the present disclosure described in the above "Exemplary Method" section of this specification.

[0209] The computer program product can be written in any combination of one or more programming languages for programming code to perform the operations of the embodiments of the present disclosure. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0210] Furthermore, an embodiment of the present disclosure may also be a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are run by a processor, the processor is caused to execute the steps in the methods according to various embodiments of the present disclosure described in the above "Exemplary Method" section of this specification.

[0211] The computer-readable storage medium may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may include, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0212] The basic principles of the present disclosure have been described in conjunction with specific embodiments. However, the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations. It cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. The specific details disclosed above are only for the purpose of illustration and easy understanding, rather than limitations. The above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.

[0213] Those skilled in the art can make various changes and modifications to the present disclosure without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present disclosure and their equivalent technologies, the present disclosure also intends to include these changes and modifications.

Claims

1. A chip for realizing secure access between circuits, comprising: A storage circuit for storing access permission configuration information corresponding to at least one slave circuit respectively; A master control circuit for generating an access request to a target slave circuit among at least one of the slave circuits; A protection circuit for determining the access permission configuration information corresponding to the target slave circuit from the access permission configuration information stored in the storage circuit; Performing a legality check on the access request based on the access permission configuration information corresponding to the target slave circuit to obtain a check result; And processing the access request based on the check result.

2. The chip according to claim 1, wherein, Among the access permission configuration information stored in the storage circuit, each access permission configuration information includes: an address range and permission information; Before the protection circuit is used to determine the access permission configuration information corresponding to the target slave circuit from the access permission configuration information stored in the storage circuit, the protection circuit is further used to determine the requested access address of the access request and determine the distribution information of the requested access address relative to each of the address ranges; The protection circuit is used to determine the access permission configuration information corresponding to the target slave circuit from the access permission configuration information stored in the storage circuit; performing a legality check on the access request based on the access permission configuration information corresponding to the target slave circuit includes: The protection circuit is used to determine the access permission configuration information corresponding to the target slave circuit from the access permission configuration information stored in the storage circuit based on the distribution information; performing a legality check on the access request based on the permission information in the access permission configuration information corresponding to the target slave circuit.

3. The chip according to claim 1, wherein The protection circuit is used to perform a legality check on the access request based on the access permission configuration information corresponding to the target slave circuit, including: The protection circuit is used to determine the target access type of the access request, determine the target permission state of the master control circuit in the target access type based on the access permission configuration information corresponding to the target slave circuit, and perform a legality check on the access request based on the target permission state.

4. The chip according to claim 3, wherein, The access permission configuration information corresponding to the target slave circuit includes: a target number of master control identifiers, read / write permission states respectively mapped by the target number of master control identifiers; one of the target number of master control identifiers is used as a predetermined master control identifier; The protection circuit is used to determine the target permission state of the master control circuit in the target access type based on the access permission configuration information corresponding to the target slave circuit, including: The protection circuit is configured to, in response to the target master identifier of the master control circuit being any one of the target number of master identifiers, determine the target permission status of the master control circuit under the target access type based on the read / write permission status mapped by the target master identifier in the access permission configuration information corresponding to the target slave control circuit; Or, The protection circuit is configured to, in response to the target master identifier of the master control circuit being different from any one of the target number of master identifiers, determine the target permission status of the master control circuit under the target access type based on the read / write permission status mapped by the predetermined master identifier in the access permission configuration information corresponding to the target slave control circuit.

5. The chip according to claim 1, wherein, The protection circuit is configured to perform a legality check on the access request based on the access permission configuration information corresponding to the target slave control circuit, including: The protection circuit is configured to determine the target security type of the access request, determine the configured security type based on the access permission configuration information corresponding to the target slave control circuit, and perform a legality check on the access request based on the target security type and the configured security type.

6. The chip according to claim 1, wherein, The number of the protection circuits is multiple, and different protection circuits correspond to different master control circuits; The protection circuit is configured to perform a legality check on the access request to obtain a check result, including: Each protection circuit is configured to perform a legality check on the access request from the corresponding master control circuit to obtain the corresponding check result; The chip further includes: A notification circuit, which is configured to notify the check results respectively corresponding to each protection circuit to the storage circuit; The storage circuit is configured to, in response to the check result corresponding to any one of the protection circuits indicating that the legality check fails, record the exception information corresponding to the access request from the corresponding master control circuit.

7. The chip according to claim 6, wherein, The storage circuit includes: A first set of registers, which are configured to store each access permission configuration information; A second set of registers, which are configured to store the exception information; Wherein, the target slave control circuit is any register in the first set of registers or any register in the second set of registers.

8. The chip according to claim 1, wherein The protection circuit is configured to process the access request based on the check result, including: The protection circuit is configured to, in response to the check result indicating that the legality check passes, forward the access request to the target slave control circuit so that the target slave control circuit performs the request response operation corresponding to the access request; Or, The protection circuit is configured to, in response to the check result indicating that the legality check fails, intercept the access request and output an exception prompt; Or, The protection circuit is configured to, in response to the check result indicating that the legality check fails, determine the communication protocol used by the protection circuit, and in response to the communication protocol used by the protection circuit being a preset communication protocol, forward the access request with the default access address as the destination address; Or, The protection circuit is configured to determine the communication protocol used by the protection circuit in response to the verification result indicating that the legality verification fails, intercept the access request and output an exception prompt in response to the communication protocol used by the protection circuit being different from a preset communication protocol.

9. The chip according to any one of claims 1-8, wherein, The storage circuit is placed in a hardware lock state, and in the hardware lock state, each of the access permission configuration information stored in the storage circuit is prohibited from being modified.

10. An access request processing method, comprising: Obtaining an access request generated by a master control circuit for a target slave control circuit in at least one slave control circuit; Determining the access permission configuration information corresponding to the target slave control circuit from the access permission configuration information respectively corresponding to at least one of the stored slave control circuits; Performing a legality verification on the access request based on the access permission configuration information corresponding to the target slave control circuit to obtain a verification result; Processing the access request based on the verification result.

11. A computer-readable storage medium storing a computer program for executing the access request processing method according to claim 10 above.

12. An electronic device, the electronic device comprising: A processor; A memory for storing executable instructions of the processor; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the access request processing method according to claim 10 above.