Integrated circuit and device access isolation method thereof, medium and electronic device

By generating and matching the integrated identification information and preset identification information in the Zhijia chip, the problem of application isolation of different functional security levels in the Zhijia chip is solved, and refined access control and hardware cost savings are achieved.

CN120354447APending Publication Date: 2025-07-22XG TECHNOLOGIES PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510416962.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

In Zhijia chip, since the main controller runs applications with different functional security levels, the access request carries the same identification information, resulting in the firewall unit being unable to isolate applications with different functional security levels.

Method used

By determining the fusion identification information corresponding to the target application, an access request carrying the fusion identification information is generated, and matching it with the preset identification information stored in the isolation unit corresponding to the plurality of slave devices, the target slave device that needs to be isolated is determined based on the matching relationship.

Benefits of technology

Access isolation between applications of different functional security levels and corresponding target slave devices is achieved, the accuracy and flexibility of access control is improved, consumption during the switching process is reduced, and hardware costs of the chip are saved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354447A_ABST
    Figure CN120354447A_ABST
Patent Text Reader

Abstract

The invention discloses an integrated circuit and an equipment access isolation method thereof, a medium and electronic equipment. The method comprises the following steps: determining fusion identification information corresponding to a target application operated by a main controller; generating an access request carrying the fusion identification information; determining preset identification information stored in a plurality of isolation units corresponding to the plurality of slave devices; matching the preset identification information with the fused identification information; and based on a matching relationship between the preset identification information and the fused identification information, determining a target slave device needing to be isolated from the access request in the plurality of slave devices. According to the scheme, different fusion identification information can be determined based on applications with different function security levels, and after the access requests carrying the fusion identification information are initiated to the multiple slave devices, the isolation unit corresponding to each slave device can match the received dynamically changing fusion identification information with the preset identification information, so that the fusion identification information is matched with the preset identification information. And different target slave devices are determined for access isolation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of integrated circuit technology, and in particular, to an integrated circuit, a method for isolating device access thereof, a medium, and an electronic device. Background Art

[0002] In the field of intelligent driving, the main controller in the intelligent driving chip can run applications with different functional safety levels. When the main controller runs an application with a certain functional safety level, the main controller can initiate an access request to a slave device in the intelligent driving chip. Since the access requests initiated when the main controller runs applications with different functional safety levels all carry the same identification information, the identification information carried by the access requests received by the firewall unit in the intelligent driving chip is always the same, resulting in the inability of the firewall unit to isolate applications with different functional safety levels. Summary of the Invention

[0003] To solve the above technical problems, the present disclosure provides an integrated circuit, a method for isolating device access thereof, a medium, and an electronic device to perform secure isolation on applications with different functional safety levels.

[0004] In one aspect, a method for isolating device access is provided, including:

[0005] Determining fusion identification information corresponding to a target application running on a main controller;

[0006] Generating an access request carrying the fusion identification information;

[0007] Determining preset identification information respectively stored in a plurality of isolation units corresponding to a plurality of slave devices;

[0008] Matching the preset identification information with the fusion identification information;

[0009] Based on the matching relationship between the preset identification information and the fusion identification information, determining target slave devices among the plurality of slave devices that need to be isolated from the access request.

[0010] In another aspect, an integrated circuit is provided, including: a main controller, a plurality of slave devices, and a plurality of isolation units corresponding to the plurality of slave devices;

[0011] The main controller is configured to determine fusion identification information corresponding to a target application running on the main controller;

[0012] The main controller is further configured to generate an access request carrying the fusion identification information;

[0013] Each of the multiple isolation units is configured to determine the preset identification information stored therein and match the preset identification information with the fusion identification information;

[0014] Each of the isolation units is further configured to determine, based on the matching relationship between the preset identification information and the fusion identification information, the target slave devices among the multiple slave devices that need to be isolated from the access request.

[0015] In another aspect, an embodiment provides a computer program product, which, when executed by an instruction processor in the computer program product, implements the device access isolation method provided in the first aspect of the present disclosure.

[0016] In yet another aspect, an embodiment provides an electronic device, which includes: a processor; a memory for storing executable instructions executable by the processor; the processor is configured to read the executable instructions from the memory and execute the instructions to implement the device access isolation method described in the first aspect above; or, the electronic device includes the integrated circuit described in the second aspect above.

[0017] In the device access isolation method provided in the embodiments of the present disclosure, when the main controller runs a target application, since the fusion identification information corresponding to the target application can be determined and an access request carrying the fusion identification information is generated, the fusion identification information can be matched with the preset identification information stored in multiple isolation units corresponding to multiple slave devices, and based on the matching relationship between the fusion identification information and the fusion identification information, the target slave devices among the multiple slave devices that need to be isolated from the access request are determined. That is, the technical solution of the present disclosure can determine different fusion identification information based on applications with different functional safety levels running, so after an access request carrying the fusion identification information is sent to multiple slave devices, the isolation unit corresponding to each slave device can match the received dynamically changing fusion identification information with the preset identification information to determine the target slave devices that need to be isolated from the access request. That is to say, it is possible to determine the target slave devices corresponding to applications with different functional safety levels from multiple slave devices, thereby ensuring that applications with different functional safety levels are access-isolated from the corresponding target slave devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1A is a schematic structural diagram of an integrated circuit provided in an exemplary embodiment of the present disclosure.

[0019] Figure 1B is a schematic structural diagram of an integrated circuit provided in another exemplary embodiment of the present disclosure.

[0020] Figure 2It is a schematic flowchart of a device access isolation method provided by an exemplary embodiment of the present disclosure.

[0021] Figure 3 It is a schematic flowchart of a device access isolation method provided by another exemplary embodiment of the present disclosure.

[0022] Figure 4 It is a schematic flowchart of a device access isolation method provided by another exemplary embodiment of the present disclosure.

[0023] Figure 5 It is a schematic flowchart of a device access isolation method provided by yet another exemplary embodiment of the present disclosure.

[0024] Figure 6 It is a schematic flowchart of a device access isolation method provided by still another exemplary embodiment of the present disclosure.

[0025] Figure 7 It is a structural diagram of an electronic device provided by an exemplary embodiment of the present disclosure. Detailed implementation manners

[0026] To explain the present disclosure, exemplary embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all embodiments. It should be understood that the present disclosure is not limited by the exemplary embodiments.

[0027] It should be noted that: Unless otherwise specifically stated, the relative arrangements of components and steps, numerical expressions, and values set forth in these embodiments do not limit the scope of the present disclosure.

[0028] Application overview

[0029] In the field of intelligent driving technology, there are applications with different functional safety levels on an intelligent driving chip, and applications with different functional safety levels can run on the same main controller of the intelligent driving chip. When the main controller runs an application, an access request carrying the identifier of the main controller can be generated and the corresponding slave device can be accessed through the access request. For the sake of functional safety, access isolation for applications with different functional safety levels needs to be performed for different slave devices.

[0030] In the traditional method, multiple isolation regions are obtained by partitioning the memory area on the main controller side through a Memory Protection Unit (MPU) to achieve isolation of the address space; however, since the number of isolation regions is limited while the number of slave devices to be isolated is large, the number of isolation regions and the number of slave devices cannot be aligned, resulting in inability to perform fine isolation on the slave devices; moreover, since the access requests received on the slave device side all carry the same identifier, it is impossible to isolate applications with different functional safety levels.

[0031] Based on the above technical problems, in the device access isolation method provided by the embodiments of the present disclosure, when the master controller runs a target application, since the fusion identification information corresponding to the target application can be determined and an access request carrying the fusion identification information is generated, the fusion identification information can be matched with the preset identification information stored in a plurality of isolation units corresponding to a plurality of slave devices, and based on the matching relationship between the fusion identification information and the fusion identification information, the target slave device that needs to be isolated from the access request among the plurality of slave devices is determined. That is, the technical solution of the present disclosure can determine different fusion identification information based on applications with different functional safety levels running, so after an access request carrying the fusion identification information is sent to a plurality of slave devices, the isolation unit corresponding to each slave device can match the received dynamically changing fusion identification information with the preset identification information to determine the target slave device that needs to be isolated from the access request. That is to say, for applications with different functional safety levels, the target slave device corresponding to the application with the corresponding functional safety level can be determined from a plurality of slave devices, so that access isolation between applications with different functional safety levels and the corresponding target slave devices can be achieved, and thus refined access control over applications with different functional safety levels can be performed.

[0032] Exemplary system

[0033] Figure 1A is a schematic structural diagram of an integrated circuit provided by an exemplary embodiment of the present disclosure.

[0034] Exemplarily, as Figure 1A shown, the above integrated circuit 100 may include: a master controller 101, a plurality of slave devices 102, and a plurality of isolation units 103 corresponding to the plurality of slave devices.

[0035] The master controller 101 is configured to determine the fusion identification information corresponding to the target application running on the master controller.

[0036] The master controller 101 is further configured to generate an access request carrying the fusion identification information.

[0037] Exemplarily, as Figure 1A shown, each of the plurality of isolation units 103 is configured to determine the preset identification information stored therein and match the preset identification information with the fusion identification information; wherein, the plurality of isolation units 103 include an isolation unit 1, an isolation unit 2, and an isolation unit 3.

[0038] Exemplarily, as Figure 1AAs shown, each isolation unit is further configured to determine, based on the matching relationship between the preset identification information and the fusion identification information, the target slave devices among the multiple slave devices 102 that need to be isolated from the access request; wherein, the multiple slave devices 102 include the slave device 1 corresponding to the isolation unit 1, the slave device 2 corresponding to the isolation unit 2, and the slave device 3 corresponding to the isolation unit 3.

[0039] In the embodiments of the present disclosure, the above-mentioned integrated circuit 100 may be a System on Chip (SOC). For example, the integrated circuit is an intelligent driving chip.

[0040] In some examples, the above Figure 1A is only an exemplary illustration. The integrated circuit 100 may further include other main controllers, slave devices, and isolation units corresponding to other slave devices, which are not limited in the embodiments of the present disclosure. Each of the above isolation units may be a hardware firewall or other hardware structures with isolation functions.

[0041] In some embodiments, as Figure 1A shown, the main controller 101 may specifically determine multiple identification information corresponding to the target application based on the operating parameters corresponding to the target application; fuse the multiple identification information corresponding to the target application with the identification information of the main controller to obtain the fusion identification information.

[0042] Exemplarily, the main controller 101 determines multiple identification information corresponding to the target application based on the operating parameters corresponding to the target application, including: determining the address space identifier based on the target address space corresponding to the target application; determining the virtual machine identifier based on the operating system corresponding to the target application; determining the permission identifier based on the access permission corresponding to the target application; determining the security identifier based on the access security type corresponding to the target application; wherein, the multiple identification information includes: address space identifier, virtual machine identifier, permission identifier, and security identifier.

[0043] In some embodiments, as Figure 1A shown, the multiple isolation units 103 may be configured to, in response to the mismatch between the target preset identification information and the fusion identification information corresponding to the target application, determine the target slave devices based on the slave devices corresponding to the target preset identification information.

[0044] In some embodiments, after determining the target slave devices, the target isolation unit corresponding to the target slave device isolates the access request of the target application for the target slave device; other isolation units among the multiple isolation units except the target isolation unit allow the access request to be transmitted to their respective corresponding slave devices.

[0045] For example, as Figure 1AAs shown, it is assumed that isolation unit 1 stores preset identification information 1, isolation unit 2 stores preset identification information 2, and isolation unit 3 stores preset identification information 3. After the main controller 101 generates an access request carrying the fused identification information for the target application, if both the preset identification information 1 and the preset identification information 3 match the fused identification information, and the preset identification information 2 does not match the fused identification information, then the slave device 2 corresponding to the preset identification information 2 is determined as the target slave device. Thus, the isolation unit 2 isolates the access request of the target application for the slave device 2, that is, it prohibits the transmission of the access request to the slave device 2, while the isolation units 1 and 3 allow the access request to be transmitted to their respective corresponding slave devices 1 and 3.

[0046] In some embodiments, as Figure 1A shown, multiple isolation units 103 can also verify the fused identification information to obtain verification result information; and based on the verification result information, match the preset identification information with the fused identification information.

[0047] Exemplarily, multiple isolation units respond to the verification result information indicating that the fused identification information passes the verification, and match the preset identification information with the fused identification information.

[0048] Through the above solution, since the verification of the fused identification information is added, it is ensured that the fused identification information will not generate errors during the transmission process, enhancing the reliability of the fused identification information. Thus, it is possible to match the more reliable fused identification information with the preset identification information to determine the accurate target slave device, thereby improving the accuracy of access isolation for applications with different functional safety levels.

[0049] In some other examples, as Figure 1B shown, the integrated circuit 100 may further include: a system bus 104, and the main controller 101 and multiple isolation units 102 are connected through the system bus 104. In this way, the access request carrying the fused identification information generated by the main controller 101 can be transmitted to each isolation unit through the system bus 104.

[0050] The embodiments of the present disclosure provide a method for device access isolation of integrated circuits. When the main controller runs a target application, since the fusion identification information corresponding to the target application can be determined based on the running parameters of the target application and an access request carrying the fusion identification information is generated, the fusion identification information can be matched with the preset identification information stored in multiple isolation units corresponding to multiple slave devices, and based on the matching relationship between the fusion identification information and the fusion identification information, the target slave device that needs to be isolated from the access request among the multiple slave devices is determined. That is, the technical solution of the present disclosure can determine different fusion identification information based on applications with different functional safety levels. Therefore, after an access request carrying the fusion identification information is sent to multiple slave devices, the isolation unit corresponding to each slave device can receive the dynamically changing fusion identification information and match it with the preset identification information to determine the target slave device that needs to be isolated from the access request. That is to say, for applications with different functional safety levels, the target slave device corresponding to the application with the corresponding functional safety level can be determined from multiple slave devices, so that access isolation between applications with different functional safety levels and the corresponding target slave devices can be realized, and thus refined access control for applications with different functional safety levels can be achieved.

[0051] Moreover, since the solution of the present disclosure only needs to switch the corresponding bit information in the fusion identification information to achieve the switching of different operating systems, different access permissions, etc. when the intelligent driving chip switches to run applications with different functional safety levels, this not only reduces the consumption during the switching process but also greatly improves the running speed and flexibility. In addition, when the same slave device can be accessed by applications with different functional safety levels, the dynamically changing fusion identification information enables the same slave device to be reused between different functional safety levels, thus saving the hardware cost of the chip.

[0052] Exemplary method

[0053] Figure 2 is a schematic flowchart of the device access isolation method provided by an exemplary embodiment of the present disclosure. This embodiment can be applied to the integrated circuit as shown above Figure 1A or Figure 1B shown, or applied to an electronic device including the integrated circuit shown above Figure 1A or Figure 1B shown. As Figure 2 shown, the method may include the following steps:

[0054] Step 201, determine the fusion identification information corresponding to the target application running on the main controller.

[0055] In some embodiments, the above-mentioned main controller may be a processor in a System on Chip (SOC). For example, the main controller is a central processing unit on an intelligent driving chip. The main controller may also be other types of processors, and the embodiments of the present disclosure do not limit this.

[0056] In some embodiments, the above-mentioned fusion identification information is information used to isolate applications with different functional safety levels. Since different applications correspond to different functional safety levels, different applications correspond to different fusion identification information. Thus, when the main controller switches to run different applications, different fusion identification information can be obtained.

[0057] Exemplarily, different applications can be classified into functional safety levels according to the Automotive Safety Integrity Level (ASIL) defined by the International Organization for Standardization and the risks related to hazards, and are divided into four levels: ASIL-A, ASIL-B, ASIL-C, and ASIL-D, as well as Quality Management (QM). Among them, the functional safety level specified by ASIL-D is the highest, and the functional safety levels specified by ASIL-C, ASIL-B, and ASIL-B, as well as QM, decrease gradually in turn. For example, the functional safety level corresponding to the autonomous driving perception system is ASIL-D, and the functional safety level corresponding to the in-vehicle music player is ASIL-A.

[0058] In some examples, the above-mentioned fusion preset information may be a string with a preset length, and the string may include at least one of the following: letters, numbers, or symbols, etc. The length of the string may be fixed or unfixed, and the embodiments of the present disclosure do not limit this, and it can be specifically determined according to the actual usage situation.

[0059] Exemplarily, the above-mentioned target application may be a navigation application or an autonomous driving application, etc., and the embodiments of the present disclosure do not limit this.

[0060] Step 202, generate an access request carrying the fusion identification information.

[0061] In some embodiments, an access request can be generated by executing specific instructions, and the access request is transmitted through the system bus.

[0062] Step 203, determine the preset identification information stored in each of the multiple isolation units corresponding to the multiple slave devices.

[0063] In some embodiments, each isolation unit may store one or more pieces of preset identification information. For any one slave device, if the slave device only allows one application to access it, the isolation unit corresponding to the slave device stores one piece of preset identification information. Or, if the slave device allows multiple applications to access it, the isolation unit corresponding to the slave device stores multiple pieces of preset identification information.

[0064] In some embodiments, the preset identification information stored in each isolation unit may be the same or different. If the applications allowed to be accessed by each slave device are different, the isolation units corresponding to each slave device store different preset identification information. Or, if the applications allowed to be accessed by each slave device are the same application, the isolation units corresponding to each slave device may store the same preset identification information. Specifically, it can be determined according to the actual usage situation, and the embodiments of the present disclosure do not limit this.

[0065] In some examples, the above isolation unit may be a hardware circuit unit with isolation function.

[0066] In some examples, the above preset identification information may be a string of a preset length, and the string may include at least one of the following: letters, numbers, or symbols, etc. The length of the string may be fixed or not fixed, and the embodiments of the present disclosure do not limit this. Specifically, it can be determined according to the actual usage situation.

[0067] In some embodiments, the above preset identification information is the identification information that the isolation unit allows the access request to be transmitted to the corresponding slave device. First, determine the applications with different functional safety levels allowed to be accessed by each slave device, and then generate corresponding fusion identification information based on the operating parameters of the applications with different functional safety levels, and pre-store the fusion identification information in the storage unit of the isolation unit corresponding to each slave device, which is the preset identification information. In this way, the preset identification information can be read from the storage unit of each isolation unit.

[0068] Step 204, match the preset identification information with the fusion identification information.

[0069] In some embodiments, a suitable matching algorithm may be determined first, and then the preset identification information is matched with the fusion identification information based on the selected matching algorithm.

[0070] In some examples, both the preset identification information and the fusion identification information are strings. When matching the preset identification information with the fusion identification information, the lengths of the two strings of the preset identification information and the fusion identification information may be matched first. Based on the length matching result, each bit of the two strings is further compared. If the lengths of the two strings of the preset identification information and the fusion identification information are the same, each bit of the two strings is further compared to obtain the matching relationship between the preset identification information and the fusion identification information. Or, if the lengths of the two strings of the preset identification information and the fusion identification information are different, it is not necessary to further compare each bit of the two strings.

[0071] When the lengths of the two strings of preset identification information and fused identification information are the same, if the two elements of each corresponding bit in the two strings are the same, it indicates that the preset identification information matches the fused identification information. Conversely, if the two elements of any corresponding bit in the two strings are different, it indicates that the preset identification information does not match the fused identification information.

[0072] Since each isolation unit stores preset identification information, it is necessary to match the fused identification information with the preset identification information stored in each isolation unit one by one.

[0073] Step 205: Based on the matching relationship between the preset identification information and the fused identification information, determine the target slave devices among the multiple slave devices that need to be isolated from the access request.

[0074] In some examples, the matching relationship between the preset identification information and the fused identification information includes two types: (1) the preset identification information matches the fused identification information; (2) the preset identification information does not match the fused identification information.

[0075] In some examples, the above-mentioned multiple slave devices can be various devices and sensors connected to the master controller, used to collect various data or used to execute the instructions of the master controller to implement certain functions. For example, the multiple slave devices can include at least one of the following: microphone, camera, lidar, speaker, etc.

[0076] In some embodiments, if the preset identification information stored in at least one isolation unit does not match the fused identification information, it indicates that there are target slave devices that do not allow the access request to access, and it is necessary to isolate the access request from the target slave devices. Therefore, the target slave devices that need to be isolated from the access request among the multiple slave devices can be determined, so that the isolation unit corresponding to the target slave device isolates the access request to prohibit the access request from being transmitted to the target slave device. Conversely, if the preset identification information stored in each isolation unit matches the fused identification information, it indicates that there are no target slave devices that do not allow the access request to access, and there is no need to isolate the access request from each slave device. Therefore, each isolation unit does not need to perform an isolation operation on the access request, and thus each isolation unit can allow the access request to be transmitted to each slave device.

[0077] Exemplarily, as Figure 1A shown, the integrated circuit includes isolation unit 1, isolation unit 2, and isolation unit 3, slave device 1 corresponding to isolation unit 1, slave device 2 corresponding to isolation unit 2, and slave device 3 corresponding to isolation unit 3; wherein, isolation unit 1 stores preset identification information 1, isolation unit 2 stores preset identification information 2, and isolation unit 3 stores preset identification information 3.

[0078] In a possible example, after the master controller generates an access request carrying the fusion identification information, and after the fusion identification information is respectively matched with the preset identification information 1, the preset identification information 2, and the preset identification information 3, since the preset identification information 2 does not match the fusion identification information, the slave device 2 can be determined as the target slave device, so that the isolation unit 2 isolates the access request from the slave device 2, that is, the access request cannot be transmitted to the slave device 2.

[0079] In another possible example, after the master controller generates an access request carrying the fusion identification information, and after the fusion identification information is respectively matched with the preset identification information 1, the preset identification information 2, and the preset identification information 3, since the fusion identification information matches all of the preset identification information 1, the preset identification information 2, and the preset identification information 3, there is no target slave device that does not allow the access request to access, so that each isolation unit allows the access request to be transmitted to each corresponding slave device.

[0080] The device access isolation method provided by the embodiments of the present disclosure, when the master controller runs the target application, since the fusion identification information corresponding to the target application can be determined and an access request carrying the fusion identification information is generated, the fusion identification information can be matched with the preset identification information stored in a plurality of isolation units corresponding to a plurality of slave devices, and based on the matching relationship between the fusion identification information and the fusion identification information, the target slave device that needs to be isolated from the access request among the plurality of slave devices is determined. That is, the technical solution of the present disclosure can determine different fusion identification information based on the applications with different functional safety levels running, so after an access request carrying the fusion identification information is sent to a plurality of slave devices, the isolation unit corresponding to each slave device can match the received dynamically changing fusion identification information with the preset identification information to determine the target slave device that needs to be isolated from the access request. That is to say, for applications with different functional safety levels, the target slave device corresponding to the application with the corresponding functional safety level can be determined from a plurality of slave devices, so that access isolation between applications with different functional safety levels and the corresponding target slave devices can be realized, and thus refined access control for applications with different functional safety levels can be achieved.

[0081] As Figure 3 shown, on the basis of the above Figure 2 shown embodiment, step 201 may include the following steps:

[0082] Step 2011, determine a plurality of identification information corresponding to the target application based on the operating parameters corresponding to the target application.

[0083] In some examples, the above operating parameters may include at least one operating parameter, and each operating parameter corresponds to different identification information. Therefore, based on the at least one operating parameter, a plurality of identification information corresponding to the at least one operating parameter can be obtained.

[0084] Exemplarily, the above operating parameters may include: the target address space corresponding to the target application, the operating system corresponding to the target application, the access permission corresponding to the target application, and the access security type corresponding to the target application. The above plurality of identification information may include: an address space identifier, a virtual machine identifier, a permission identifier, and a security identifier.

[0085] In some embodiments, applications with different functional safety levels correspond to different operating parameters. Therefore, for applications with different functional safety levels, different multiple identification information can be determined.

[0086] In some embodiments, step 2011 above may specifically include the following steps: determining an address space identifier based on the target address space corresponding to the target application; determining a virtual machine identifier based on the operating system corresponding to the target application; determining a permission identifier based on the access permission corresponding to the target application; determining a security identifier based on the access security type corresponding to the target application; wherein the multiple identification information includes: an address space identifier, a virtual machine identifier, a permission identifier, and a security identifier.

[0087] In some examples, different address spaces can be pre-configured for each application respectively based on business requirements and the functional safety levels of different applications; when the main controller runs the target application, the target address space corresponding to the target application can be determined, and the target application can be run in the target address space.

[0088] In some embodiments, the above address space identifier is an identifier used to uniquely identify the address space. Therefore, different address spaces correspond to different address space identifiers, and thus different address spaces can be distinguished by the address space identifier.

[0089] In some examples, after different address spaces are configured for each application respectively, a unique address space identifier can be generated for each address space, that is, the address space and the address space identifier are in one-to-one correspondence; when the main controller runs the target application, the address space identifier corresponding to the target address space can be determined based on the target address space corresponding to the target application.

[0090] Exemplarily, the above address space identifier may be randomly generated, or obtained based on the starting address of the target address space; the address space identifier may be represented in binary form or other possible forms, and the embodiments of the present disclosure do not limit this. For example, the address space identifier is the binary string corresponding to the starting address of the target address space.

[0091] Since applications with different functional safety levels correspond to different address spaces, when switching to run different applications, the address space is switched, thereby isolating applications with different functional safety levels.

[0092] In some examples, in the field of automotive technology, for the scenario of a hybrid operating system, multiple virtual machines can be pre-created. Each virtual machine is independent, and different operating systems are run on different virtual machines. Thus, a one-to-one binding relationship between the operating system and the virtual machine is achieved, and isolation between different operating systems is thus realized. The operating system can include a kernel (Linux Operating System, Linux) operating system, a Microsoft Windows operating system, a Quick UNIX (QNX) operating system, or other types of operating systems. The embodiments of the present disclosure do not limit this, and it is specifically determined according to actual usage.

[0093] In some examples, to ensure isolation between applications with different functional safety levels, different virtual machines can be pre-allocated for applications with different functional safety levels. Since different operating systems are run on different virtual machines, applications with different functional safety levels can run under different operating systems, and thus isolation between applications with different functional safety levels is achieved. When the main controller runs the target application, the operating system corresponding to it can be determined based on the functional safety level of the target application.

[0094] In some examples, the above-mentioned virtual machine identifier (Virtual Machine ID, VMID) is an identifier used to uniquely identify a virtual machine. Therefore, different virtual machine identifiers correspond to different virtual machines, and different virtual machines can thus be distinguished by the virtual machine identifier. Since a virtual machine corresponds one-to-one to the operating system it runs, it can also be considered that the virtual machine identifier can be used to distinguish different operating systems. Thus, based on the operating system corresponding to the target application, the virtual machine corresponding to the operating system can be determined, and the virtual machine identifier of the virtual machine can be obtained.

[0095] Exemplarily, in the case of multiple virtual machines, since the virtual machine identifier is an identifier used to uniquely identify a virtual machine, different virtual machine identifiers can be pre-set for each virtual machine; the virtual machine identifier can be randomly generated or user-defined. The virtual machine identifier can be represented in hexadecimal form or other possible forms. The embodiments of the present disclosure do not limit this. For example, the virtual machine identifier is a string composed of numbers and letters.

[0096] In some embodiments, in a chip system, multiple access permissions may be included, such as the exception level (EL) in a certain chip architecture, and each access permission is different. To ensure isolation between applications with different functional safety levels, different access permissions may be configured for applications with different functional safety levels in advance based on the functional safety level, so the access permissions of applications with different functional safety levels to data are different. When running a target application, the access permission corresponding to the target application may be determined based on the functional safety level of the target application. For different applications, the corresponding access permissions may be different or the same, and the embodiments of the present disclosure do not limit this, which is specifically determined according to the actual usage situation.

[0097] In some examples, the above permission identifier may be used to uniquely identify the access permission; for multiple access permissions, different permission identifiers are configured for each access permission; for applications with different functional safety levels, since they correspond to different access permissions, the determined permission identifiers are also different.

[0098] In some examples, the above permission identifier may be a string. For example, the string is composed of letters and numbers.

[0099] Exemplarily, it is assumed that the access permissions may include a first access permission, a second access permission, a third access permission, and a fourth access permission; among them, the first access permission is represented by EL0, the second access permission is represented by EL1, the third access permission is represented by EL2, and the fourth access permission is represented by EL3. When running a target application, based on the functional safety level of the target application, the access permission corresponding to the target application is determined to be the first access permission, so the permission identifier EL0 of the first access permission can be obtained.

[0100] In some embodiments, the above access security types include a secure type (s) and a non-secure type (ns). Different access security types may be configured for applications with different functional safety levels in advance based on the functional safety level; when running a target application, the access security type corresponding to the target application may be determined based on the functional safety level of the target application. For different applications, the corresponding access security types may be different or the same, and the embodiments of the present disclosure do not limit this, which is specifically determined according to the actual usage situation.

[0101] For example, the functional safety level of the first application is ASIL D, and the access security type corresponding to the first application is the secure type; the functional safety level of the second application is ASIL B, and the access security type corresponding to the second application is the secure type.

[0102] For another example, the functional safety level of the first application is ASIL D, and the access security type corresponding to the first application is a secure type; the functional safety level of the third application is ASIL C, and the access security type corresponding to the second application is a non-secure type.

[0103] In some examples, the above security identifier can be used to uniquely identify the access security type; for different access security types, different security identifiers can be pre-configured for each access security type; for different applications, if different applications correspond to different access security types, different security identifiers can be determined, or, if different applications correspond to the same access security type, the same security identifier can be determined.

[0104] In some examples, the above security identifier can be a string. For example, the string consists only of numbers.

[0105] Exemplarily, the security identifier can be represented by 0 or 1. When the access security type is a secure type, the security identifier is 0, and when the access security type is a non-secure type, the security identifier is 1; or, when the access security type is a secure type, the security identifier is 1, and when the access security type is a non-secure type, the security identifier is 0.

[0106] Step 2012, fuse multiple identification information corresponding to the target application with the identification information of the main controller to obtain fused identification information.

[0107] In some embodiments, the identification information of the above main controller is an identifier used to uniquely identify the main controller. The identification information of the same main controller is the same, and different main controllers correspond to different identification information. The identification information of the above main controller can be the serial number of the main controller, and the serial number of the main controller can be the serial number written by the chip manufacturer when the chip leaves the factory, or a custom serial number written by the user through a security protocol.

[0108] In some examples, the identification information of the main controller is obtained by accessing a specific register in the main controller.

[0109] In some embodiments, multiple identification information and the identification information of the main controller can be fused according to a preset fusion strategy to obtain fused identification information.

[0110] Exemplarily, multiple identification information and the identification information of the main controller are directly concatenated to form a new string, and this string is the fused identification information.

[0111] The device access isolation method provided by the embodiments of the present disclosure can determine multiple corresponding identification information based on various operating parameters corresponding to the target application. Therefore, when fusing the multiple identification information with the identification information of the master controller to obtain the fused identification information, when switching to run applications with different functional safety levels, only by switching the corresponding bit information in the fused identification information can the switching of different operating systems, different access permissions, etc. be realized. In this way, not only the consumption during the switching process is reduced, but also the operating speed and flexibility are greatly improved.

[0112] In addition, when the same slave device can be accessed by applications with different functional safety levels, the dynamically changing fused identification information enables the same slave device to be reused between different functional safety levels, thereby saving the hardware cost of the chip.

[0113] Such as Figure 4 shown, based on the above Figure 2 shown embodiment, step 205 may include the following steps:

[0114] Step 2051, in response to the matching relationship that the target preset identification information does not match the fused identification information, determine the target slave device based on the slave device corresponding to the target preset identification information.

[0115] In some embodiments, the target preset identification information and the fused identification information are strings. Therefore, the corresponding bits in the target preset identification information and the fused identification information can be compared one by one. When the characters of a certain bit in the target preset identification information are different from the characters of the corresponding bit in the fused identification information, it can be determined that the target preset identification information does not match the fused identification information. The target preset identification information can be the preset identification information stored in any one isolation unit.

[0116] In some embodiments, when the target preset identification information does not match the fused identification information, the slave device corresponding to the target preset identification information can be determined, and the slave device corresponding to the target preset identification information is determined as the target slave device.

[0117] In some examples, the number of target preset identification information can be one or more. When the number of target preset identification information is one, the target slave device is only the slave device corresponding to the only one target preset identification information; or, when the number of target preset identification information is multiple, if multiple target preset identification information all correspond to the same slave device, the target slave device is this one slave device, or, if multiple target preset identification information respectively correspond to at least two slave devices, the target slave device is these at least two slave devices.

[0118] Exemplarily, it is assumed that the integrated circuit includes isolation unit 1, isolation unit 2, and isolation unit 3, slave device 1 corresponding to isolation unit 1, slave device 2 corresponding to isolation unit 2, and slave device 3 corresponding to isolation unit 3; among them, isolation unit 1 stores preset identification information 1, isolation unit 2 stores preset identification information 2, and isolation unit 3 stores preset identification information 3. When the preset identification information 2 does not match the fusion identification information, since the preset identification information 2 corresponds to slave device 2, slave device 2 can be determined as the target slave device.

[0119] In some embodiments, after the target slave device is determined, the isolation unit corresponding to the target slave device isolates the access request from the target slave device, that is, prohibits the access request from being transmitted to the target slave device, so that the target slave device cannot be accessed through the access request; other slave devices except the target slave device among the multiple slave devices can be accessed through the access request.

[0120] In other embodiments, in response to the matching relationship that the preset identification information stored in all isolation units matches the fusion identification information, it indicates that none of the multiple slave devices need to be isolated from the access request. At this time, each slave device among the multiple slave devices can be accessed separately through the access request.

[0121] The device access isolation method provided by the embodiments of the present disclosure can determine the target slave device based on the slave device corresponding to the target preset identification information when the target preset identification information does not match the fusion identification information. Therefore, the access request cannot access the target slave device, so that different applications with different functional safety levels correspond to different fusion identification information, realizing access isolation for applications with different functional safety levels.

[0122] As Figure 5 shown, based on the above Figure 2 shown embodiments, step 204 may include the following steps:

[0123] Step 2041, verify the fusion identification information to obtain verification result information.

[0124] In some examples, the verification method may include any one of the following: parity check, cyclic redundancy check, or arithmetic accumulation check, etc. Of course, other possible verification methods may also be used to verify the fusion identification information. The embodiments of the present disclosure do not limit the verification method of the fusion identification information, and can be specifically determined according to the actual usage situation.

[0125] Exemplarily, taking odd parity in parity check as an example for exemplary illustration. Assume that the fusion identification information is 1011. When performing parity check on the fusion identification information in the odd parity mode, first count the number of "1"s in the fusion identification information: 3. Since the odd parity mode is adopted and the number of "1"s in the fusion identification information is odd (3), a parity bit is required to keep the total number of "1"s in the entire data odd. Therefore, the parity bit is set to 0 to keep the number of "1"s odd, and the parity bit and 1011 are combined to obtain the odd parity code "10110". When the odd parity code is received at the receiving end, if the odd parity code is "10110", then the total number of "1"s in this odd parity code is calculated to be 3. Since the total number of "1"s is odd, it indicates that the check passes. Or, if the odd parity code is "10111", then the total number of "1"s in this odd parity code is calculated to be 4. Since the total number of "1"s is even, it indicates that the check fails.

[0126] In some examples, the above check result information may include two cases: (1) The check result information indicates that the fusion identification information passes the check; (2) The check result information indicates that the fusion identification information fails the check.

[0127] In some examples, the above check result information can be represented by an identifier, and different identifiers correspond to different check result information. For example, the identifier "1" can be used to represent that the check result information is that the fusion identification information passes the check, and the identifier "0" can be used to represent that the check result information is that the fusion identification information fails the check.

[0128] Exemplarily, when performing a check on the fusion identification information, if the fusion identification information passes the check, the check result information "1" can be obtained. Or, if the fusion identification information fails the check, the check result information "0" can be obtained.

[0129] Step 2042, based on the check result information, match the preset identification information with the fusion identification information.

[0130] In some embodiments, the above step 2042 may specifically include: in response to the check result information indicating that the fusion identification information passes the check, match the preset identification information with the fusion identification information.

[0131] When the check result information indicates that the fusion identification information passes the check, it indicates that the fusion identification information has not erred during transmission, that is, the fusion identification information is correct. Therefore, the preset identification information can be matched with the fusion identification information. On the contrary, when the check result information indicates that the fusion identification information fails the check, it indicates that the fusion identification information has erred during transmission, that is, the fusion identification information is incorrect. Therefore, no operation needs to be performed.

[0132] Exemplarily, when the verification result information is "1", it indicates that the fusion identification information passes the verification. At this time, the preset identification information and the fusion identification information can be matched. Or, when the verification result information is "0", it indicates that the fusion identification information fails the verification. At this time, no operation needs to be performed.

[0133] The matching of the preset identification information and the fusion identification information can refer to the detailed description in the above embodiments, and the embodiments of the present disclosure will not be elaborated herein.

[0134] The device access isolation method provided by the embodiments of the present disclosure obtains verification result information by verifying the fusion identification information, and matches the preset identification information and the fusion identification information based on the verification result information, and in response to the verification result information indicating that the fusion identification information passes the verification, matches the preset identification information and the fusion identification information. Since the verification of the fusion identification information is added, it is ensured that the fusion identification information will not generate errors during the transmission process, enhancing the reliability of the fusion identification information, so that it is possible to match the more reliable fusion identification information with the preset identification information to determine the accurate target slave device, thereby improving the accuracy of access isolation for different functional safety applications.

[0135] As Figure 6 shown, based on the above Figure 2 shown embodiment, step 204 may include the following steps:

[0136] Step 204a, determine the length of the preset identification information and the length of the fusion identification information.

[0137] In some examples, since the preset identification information and the fusion identification information are strings, the length of the preset identification information and the length of the fusion identification information can be respectively obtained based on the string length function. Or, the lengths of the preset identification information and the fusion identification information can be determined by traversing the two strings of the preset identification information and the fusion identification information and respectively counting the characters in the two strings. Other methods can also be used to obtain the length of the preset identification information and the length of the fusion identification information, and the embodiments of the present disclosure do not limit this.

[0138] Step 204b, match the length of the preset identification information and the length of the fusion identification information to obtain a first matching result.

[0139] In some embodiments, after determining the lengths of the preset identification information and the fused identification information, the lengths of the preset identification information and the fused identification information are compared; if the lengths of the preset identification information and the fused identification information are equal, the lengths of the preset identification information and the fused identification information match, that is, the first matching result is that the lengths of the preset identification information and the fused identification information match, or, if the lengths of the preset identification information and the fused identification information are not equal, the lengths of the preset identification information and the fused identification information do not match, that is, the first matching result is that the lengths of the preset identification information and the fused identification information do not match.

[0140] Step 204c, in response to the first matching result being that the lengths of the preset identification information and the fused identification information match, perform a bit-by-bit comparison of the preset identification information and the fused identification information to determine the second matching result.

[0141] In some embodiments, when the lengths of the preset identification information and the fused identification information match, compare the elements of all corresponding bits in the preset identification information and the fused identification information; if the elements of all corresponding bits in the preset identification information and the fused identification information are the same, the second matching result is that the preset identification information and the fused identification information match, or, if the elements of any one corresponding bit in the preset identification information and the fused identification information are different, the second matching result is that the preset identification information and the fused identification information do not match.

[0142] Step 204d, in response to the first matching result being that the lengths of the preset identification information and the fused identification information do not match, determine that the preset identification information and the fused identification information do not match.

[0143] When the lengths of the preset identification information and the fused identification information do not match, it can be determined that the preset identification information and the fused identification information do not match, and there is no need to compare the elements in the preset identification information and the fused identification information anymore.

[0144] The device access isolation method provided by the embodiments of the present disclosure can obtain the first matching result by matching the lengths of the determined preset identification information and the fused identification information. Therefore, on the one hand, when the first matching result is that the lengths of the preset identification information and the fused identification information do not match, it can be directly determined that the preset identification information and the fused identification information do not match, thereby quickly excluding the case of length mismatch, avoiding unnecessary element comparison, and improving the matching efficiency; on the other hand, when the first matching result is that the lengths of the preset identification information and the fused identification information match, by performing a bit-by-bit comparison of the preset identification information and the fused identification information, it can accurately determine whether the two identification information is consistent, ensuring the accuracy of the matching result.

[0145] Exemplary electronic device

[0146] Figure 7 This is a structural diagram of an electronic device provided by an embodiment of the present disclosure, including at least one processor 111 and a memory 112.

[0147] The processor 111 may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device 11 to perform desired functions.

[0148] The memory 112 may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 111 may run one or more computer program instructions to implement the device access isolation method and / or other desired functions of the various embodiments of the present disclosure described above.

[0149] In one example, the electronic device 11 may further include: an input device 113 and an output device 114, and these components are interconnected through a bus system and / or other forms of connection mechanisms (not shown).

[0150] The input device 113 may include various types of sensors, including but not limited to: a ranging sensor for detecting the distance between a target object and the vehicle; an image sensor for collecting information about the vehicle's surrounding environment. In some examples, the input device may further include a pressure sensor for detecting seat pressure to determine whether there is a passenger and the position of the passenger; a temperature sensor for monitoring the temperature inside the cockpit; a humidity sensor for monitoring the humidity inside the cockpit to assist in adjusting the vehicle interior environment; an air quality sensor for monitoring the air quality inside the vehicle, such as carbon dioxide, volatile organic compounds (VOCs), etc.; a light sensor for detecting the light intensity inside and outside the vehicle; an acceleration sensor for detecting changes in the vehicle's acceleration; a distance sensor for detecting the distance between the vehicle and other objects; a touch screen sensor for interaction with the vehicle infotainment system; a biometric sensor such as fingerprint recognition, facial recognition, etc.; a heart rate monitor for monitoring the driver's heart rate; a sound sensor for voice recognition and interaction to achieve voice control functions; a seat sensor for monitoring the usage of the seat, such as whether the seat is occupied and the body type of the passenger; a wireless communication sensor such as Bluetooth, Wi-Fi, etc. for connecting to smart devices to achieve data transmission and remote control. In addition to the examples given above, the input device may further include more or fewer sensors, which will not be elaborated here.

[0151] The output device 114 may output various information or signals to other hardware or devices, which may include a display, an in-vehicle audio system, seats, windows, a steering wheel, etc., as well as a communication network and its connected remote output devices, etc. Among them, the display may include multiple different displays such as a driver's display, a front passenger's display, a rear display, etc., and the in-vehicle audio system may include multiple speakers arranged at different positions inside the vehicle cockpit. Different displays or speakers may work independently.

[0152] Of course, for simplicity, Figure 7 only some of the components of the electronic device 11 related to the present disclosure are shown in, and components such as a bus, an input / output interface, etc. are omitted. In addition, according to specific application scenarios, the electronic device 11 may further include any other appropriate components.

[0153] Of course, for simplicity, Figure 7 only some of the components of the electronic device 11 related to the present disclosure are shown in, and components such as a bus, an input / output interface, etc. are omitted. In addition, according to specific application scenarios, the electronic device 11 may further include any other appropriate components.

[0154] Exemplary Computer Program Product and Computer Readable Storage Medium

[0155] In addition to the above methods and devices, embodiments of the present disclosure may also provide a computer program product, including computer program instructions that, when run on a processor, cause the processor to execute the steps in the device access isolation method of various embodiments of the present disclosure described in the "Exemplary Method" section above.

[0156] The computer program product may be written in any combination of one or more programming languages for programming code to perform the operations of the embodiments of the present disclosure. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The programming code may be executed entirely on the user's computing device, partially on the user's device, executed as an independent software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0157] In addition, embodiments of the present disclosure may also be a computer-readable storage medium having computer program instructions stored thereon that, when run on a processor, cause the processor to execute the steps in the device access isolation method of various embodiments of the present disclosure described in the "Exemplary Method" section above.

[0158] The computer-readable storage medium may employ any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium, for example but not limited to, includes systems, devices, or components of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: electrical connections with one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.

[0159] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that they are essential for each embodiment of the present disclosure. In addition, the above-described specific details are only for the purposes of illustration and easy understanding, rather than limitations. The above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.

[0160] Those skilled in the art can make various changes and modifications to the present disclosure without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present disclosure and their equivalent technologies, the present disclosure also intends to include these changes and modifications.

Claims

1. An access isolation method for a device, comprising: Determining fusion identification information corresponding to a target application running on a master controller; Generating an access request carrying the fusion identification information; Determining preset identification information stored in respective isolation units corresponding to a plurality of slave devices; Matching the preset identification information with the fusion identification information; Based on a matching relationship between the preset identification information and the fusion identification information, determining target slave devices among the plurality of slave devices that need to be isolated from the access request.

2. The method according to claim 1, wherein, The determining fusion identification information corresponding to a target application running on a master controller includes: Based on operating parameters corresponding to the target application, determining a plurality of identification information corresponding to the target application; Fusing the plurality of identification information corresponding to the target application with identification information of the master controller to obtain the fusion identification information.

3. The method according to claim 2, wherein The based on operating parameters corresponding to the target application, determining a plurality of identification information corresponding to the target application includes: Based on a target address space corresponding to the target application, determining an address space identifier; Based on an operating system corresponding to the target application, determining a virtual machine identifier; Based on access permissions corresponding to the target application, determining a permission identifier; Based on an access security type corresponding to the target application, determining a security identifier; Wherein, the plurality of identification information includes: the address space identifier, the virtual machine identifier, the permission identifier, and the security identifier.

4. The method according to claim 1, wherein The based on a matching relationship between the preset identification information and the fusion identification information, determining target slave devices among the plurality of slave devices that need to be isolated from the access request includes: In response to the matching relationship being that a target preset identification information does not match the fusion identification information, determining the target slave devices based on slave devices corresponding to the target preset identification information.

5. The method according to claim 1, wherein, The matching the preset identification information with the fusion identification information includes: Verifying the fusion identification information to obtain verification result information; Based on the verification result information, matching the preset identification information with the fusion identification information.

6. The method according to claim 5, wherein The based on the verification result information, matching the preset identification information with the fusion identification information includes: In response to the verification result information indicating that the fusion identification information passes the verification, matching the preset identification information with the fusion identification information.

7. The method according to claim 1, wherein The matching the preset identification information with the fusion identification information includes: Determining the length of the preset identification information and the length of the fusion identification information; Matching the length of the preset identification information with the length of the fusion identification information to obtain a first matching result; In response to the first matching result being that the length of the preset identification information matches the length of the fusion identification information, comparing the preset identification information and the fusion identification information bit by bit to determine a second matching result; or, In response to the first matching result being that the length of the preset identification information does not match the length of the fusion identification information, determining that the preset identification information does not match the fusion identification information.

8. An integrated circuit, comprising: A master controller, a plurality of slave devices, and a plurality of isolation units corresponding to the plurality of slave devices; The master controller is configured to determine fusion identification information corresponding to a target application running on the master controller; The master controller is further configured to generate an access request carrying the fusion identification information; Each of the plurality of isolation units is configured to determine preset identification information stored therein and match the preset identification information with the fusion identification information; Each of the isolation units is further configured to determine a target slave device among the plurality of slave devices that needs to be isolated from the access request based on a matching relationship between the preset identification information and the fusion identification information.

9. A computer-readable storage medium storing a computer program for executing the device access isolation method according to any one of claims 1-7 above.

10. An electronic device, comprising: A processor; A memory for storing executable instructions of the processor; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the device access isolation method according to any one of claims 1-7 above; Alternatively, the electronic device includes the integrated circuit according to claim 8 above.