Task stack protection method and device, electronic equipment, chip and medium

By initializing the memory protection unit and setting the MPU area on the ARMv8 architecture processor platform, the insecurity problem of task stack protection is solved, and the security and reliability of the task stack during the switching process is achieved.

CN120371390APending Publication Date: 2025-07-25SHANGHAI LIXIANG AUTOMOBILE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410109266.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-25
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

On the processor platform of ARMv8 architecture, the existing MPU stack protection policy has problems such as unsafe and unreliable, and cannot effectively prevent the task stack from being illegally accessed.

Method used

By initializing the memory protection unit, setting the MPU and MPU background area, removing the current task and setting the stack protection area for the next task, ensuring that the task is not illegally accessed during the switching process.

Benefits of technology

Improves the security and reliability of the memory protection unit's task stack protection for the memory area, preventing the task stack from being interrupted or illegally accessed by other tasks during the switching process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120371390A_ABST
    Figure CN120371390A_ABST
Patent Text Reader

Abstract

The invention provides a task stack protection method and device, electronic equipment, a chip and a medium, and relates to the technical field of computer security. The task stack protection method comprises the following steps: in response to starting of an operating system, initializing a memory protection unit; based on the memory protection unit, the first task is removed from a stack protection memory area, the stack protection memory area is a stack top space of a task stack memory area of an operating system memory, and the first task is a process or a thread operated by an operating system in the stack protection memory area; setting attributes of a stack protection memory area of a second task, the second task being a task executed after the first task and being an active task; and moving the second task into the stack protection memory area. Through the technical scheme provided by the invention, the problem that the task stack protection of the memory area by the memory protection unit is unsafe and unreliable is solved, and the safety and reliability of the task stack protection of the memory area by the memory protection unit are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer security technologies, and particularly to a method, apparatus, electronic device, chip, and medium for protecting a task stack. Background Art

[0002] With the iterative upgrade of chip processors, the data operation and processing capabilities are getting stronger and stronger, and the security of data processing has also received much attention. For the persistent and reliable secure access to memory areas, especially in the field of vehicle control, it is studied as a very important topic. For RTOS task stack protection, the following goals need to be achieved:

[0003] 1. Prevent the stack of a task from overflowing during runtime.

[0004] 2. Prevent the stack space of the currently running task from being accessed by other tasks or interrupts.

[0005] 3. Prevent the stack space of the tasks that are not currently running from being accessed by other tasks or interrupts.

[0006] In related technologies, in order to achieve the above goals, there are mainly two types of RTOS task stack protection schemes based on the ARM architecture:

[0007] The first scheme is runtime stack overflow detection, which mainly determines whether a stack overflow has occurred by judging whether the stack top pointer has crossed the boundary of the sum of the stack bottom pointer and the stack depth during task switching, or by judging whether a specific magic word at the stack bottom has been modified. This method is efficient and fast, but it only performs detection at the moment of task switching and cannot capture all stack overflows.

[0008] The second scheme is MPU stack protection based on ARM v7. In a processor platform based on ARM v7, the RTOS task stack is generally protected through the following strategy:

[0009] 1. Use Region0 or multiple Regions to set the legal memory mapping space (Memory Map) of the system as the background region, and set the permission to READ.

[0010] 2. Use Region15 as the dedicated MPU Region for stack protection, and set the Region access permissions to READ, WRITE, READ WRITE, EXECUTE, and EXECUTE-NEVER. The start address and length of the Region identify the stack space range of the currently running task. Due to the overlap feature of the MPU, the permissions of Region15 override those of Region0.

[0011] 3. When a task switch occurs, first clear the content of the MPU Region15 register. This can ensure that before the task being switched out is switched in again, the stack space permission is read-only, and other tasks and interrupts cannot modify it.

[0012] 4. After clearing the MPU Region15 register, set the register to the stack start address and length of the newly switched-in task. Since MPU Region15 configures the stack space of the currently running task to be readable and writable, the currently running task can normally access its own stack space. And because MPU Region15 is changed after the previous task is switched out, the current task cannot illegally modify the stack space of the previous task.

[0013] Due to the hardware differences between the ARMv8 and ARMv7 architectures, the ARMv8 MPU does not support the overlap and subregion features between regions. If an address appears in two different regions simultaneously, it will cause a bus error, Bus Fault. This stack protection strategy cannot be migrated to the processor platform of the ARMv8 architecture, resulting in insecure and unreliable task stack protection of the memory protection unit for memory regions. Summary of the Invention

[0014] The present disclosure provides a task stack protection method, apparatus, electronic device, chip, and medium to solve the problem of insecure and unreliable task stack protection of the memory protection unit for memory regions. By setting the MPU and the MPU background region, it is ensured that illegal access to the memory does not occur. The original task is moved out of the stack protection region, and the stack protection region is set to the memory of the switched-in task, thereby completing the task switch and enhancing the security and reliability of the task stack protection of the memory protection unit for memory regions.

[0015] The first aspect embodiment of the present disclosure proposes a task stack protection method, which includes:

[0016] Responding to the startup of the operating system, initializing the memory protection unit;

[0017] Based on the memory protection unit, moving the first task out of the stack protection memory region, where the stack protection memory region is the top space of the task stack memory region of the operating system memory, and the first task is a process or thread running by the operating system in the stack protection memory region;

[0018] Setting the attributes of the stack protection memory region of the second task, where the second task is a task executed after the first task and is an active task;

[0019] Moving the second task into the stack protection memory region.

[0020] In one embodiment of the present disclosure, in response to the startup of the operating system, initializing the memory protection unit includes:

[0021] In response to the startup of the operating system,

[0022] Initializing the memory area of the operating system memory and the memory protection unit, and enabling the memory protection unit.

[0023] In one embodiment of the present disclosure, before initializing the memory protection unit in response to the startup of the operating system, it further includes:

[0024] In response to the startup of the operating system, verifying the memory protection unit;

[0025] If the verification passes, disabling the memory protection unit and the background area of the memory protection unit.

[0026] In one embodiment of the present disclosure, initializing the memory area of the operating system memory and the memory protection unit includes:

[0027] Setting the attributes of the operating system memory;

[0028] Setting the attributes of each protection area of the memory protection unit, and the protection areas include the stack protection memory area.

[0029] In one embodiment of the present disclosure, setting the attributes of each protection area of the memory protection unit includes:

[0030] Setting the area number register, area base address register, and area limit address register of the protection area of the memory protection unit.

[0031] In one embodiment of the present disclosure, based on the memory protection unit, moving the first task out of the stack protection memory area includes: moving the first task out of the stack protection memory area and saving the context of the first task;

[0032] Clearing the attribute registers for saving the stack protection memory area, and the attribute registers include the area number register, area base address register, and area limit address register.

[0033] In one embodiment of the present disclosure, setting the attributes of the stack protection memory area of the second task includes:

[0034] Writing the start address of the stack space of the second task into the area base address register;

[0035] Writing the end address of the stack space of the second task into the area limit address register.

[0036] In a second aspect embodiment of the present disclosure, a task stack protection device is proposed, and the device includes:

[0037] An initialization module, used for initializing a memory protection unit in response to startup of an operating system;

[0038] A removal module, used for removing the first task from the stack protection memory area based on the memory protection unit, where the stack protection memory area is the top stack space of the memory area;

[0039] A setting module, used to set the attributes of the stack protection memory area of the second task, where the second task is a task executed after the first task and is an active task;

[0040] The move-in module is used to move the second task into the stack protection memory area.

[0041] The third aspect embodiment of the present disclosure proposes an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any one of the methods in the first aspect embodiment of the present disclosure.

[0042] A fourth aspect embodiment of the present disclosure provides a vehicle, comprising the task stack protection device in the second aspect embodiment of the present disclosure.

[0043] In summary, according to the task stack protection method proposed in the present disclosure, in response to the startup of the operating system, the memory protection unit is initialized so that all accesses to illegal memory locations will be intercepted by the MPU; based on the memory protection unit, the first task is moved out of the stack protection memory area, the stack protection memory area is the stack top space of the task stack memory area of the operating system memory, the first task is the process or thread running in the stack protection memory area of the operating system, and it is ensured that the stack address space of the running task will not be interrupted or illegally accessed by other tasks; the attributes of the stack protection memory area of the second task are set, the second task is a task executed after the first task, and is an active task, and the advance setting is completed for the second task to safely enter the stack protection memory area; the second task is moved into the stack protection memory area, and the safe switching of tasks in the stack protection memory area is realized. The security and reliability of the memory protection unit's protection of the task stack of the memory area are improved.

[0044] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] The drawings herein are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the description are used to explain the principles of the present disclosure, and do not constitute improper limitations on the present disclosure.

[0046] Figure 1Flowchart of a task stack protection method according to an embodiment of the present disclosure;

[0047] Figure 2 Flowchart of initializing a memory protection unit in response to the startup of an operating system according to an embodiment of the present disclosure;

[0048] Figure 3 Flowchart of initializing the memory area of the operating system memory and the memory protection unit according to an embodiment of the present disclosure;

[0049] Figure 4 Flowchart of setting the attributes of each protection area of the memory protection unit according to an embodiment of the present disclosure;

[0050] Figure 5 Flowchart of removing a first task from the stack protection memory area based on the memory protection unit according to an embodiment of the present disclosure;

[0051] Figure 6 Flowchart of setting the attributes of the stack protection memory area of a second task according to an embodiment of the present disclosure;

[0052] Figure 7 Flowchart of the MPU initializing the memory protection area according to an embodiment of the present disclosure;

[0053] Figure 8 Flowchart of the RTOS task switching to set the MPU register according to an embodiment of the present disclosure;

[0054] Figure 9 Schematic diagram of the operating system memory according to an embodiment of the present disclosure;

[0055] Figure 10 Schematic diagram of the structure of a task stack protection device according to an embodiment of the present disclosure;

[0056] Figure 11 Block diagram of an electronic device for implementing the task stack protection method of the present disclosure shown according to an exemplary embodiment;

[0057] Figure 12 Schematic diagram of the structure of a chip according to an embodiment of the present disclosure. Detailed implementation manners

[0058] The embodiments of the present disclosure are described in detail below. The examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to explain the present disclosure, but should not be construed as limiting the present disclosure.

[0059] First, relevant terms in the present disclosure are briefly introduced:

[0060] Memory Protection Unit (MPU): In this disclosure, it refers to a hardware unit in a computer chip, and its main task is to provide memory protection and access control functions. Through the MPU, the memory area can be divided into several protection areas, and data read / write permissions and code execution permissions can be set according to the area type. Usually, the MPU realizes its function as a part of the Central Processing Unit (CPU).

[0061] ARM v8-R: ARM v8-R is a chip architecture designed by ARM for the automotive industry and is mainly used for automotive controller components with high security requirements, high performance, and real-time capabilities.

[0062] MPU Region (Memory Protection Region): The MPU can divide the memory mapping (MemoryMap) area of the system into several regions (Region, equivalent to region), and independent access permissions and memory attributes can be set for each region. Each MPU in ARMv8-R supports up to 24 Regions at most.

[0063] MPU Background: The MPU background area. When the MPU is enabled, usually when accessing an address that does not belong to any defined region, a data abort exception will occur. However, as long as the background area function is enabled, accessing an address that does not belong to any defined region will be regarded as accessing the default Memory Map.

[0064] Real-time operating system (RTOS): It refers to an operating system that can accept and process external events or data quickly enough when they occur, and its processing tasks can control the production process or respond quickly to the processing system within the specified time, schedule all available resources to complete real-time tasks, and control all real-time tasks to run in coordination. High reliability is its main feature.

[0065] Stack overflow: It refers to the phenomenon that a specific task uses up all the stack space allocated to it and invades the storage area that is not allocated to it for storing its own information.

[0066] Task stack protection: During the operation of multi-programs, once the stack of a task is illegally accessed and modified by other tasks or interrupts during operation, it may cause a fatal error for the task. The stack protection mechanism is a strategy to protect the task stack from being illegally accessed by other tasks and interrupts during operation.

[0067] The method proposed in this disclosure is applied to the task stack protection task, and its application has rich scenarios. Task stack protection is widely used in many fields and applications. For example, by placing a buffer at the end of the MPU region, buffer overflow can be prevented, and at the same time, the task stack can be placed in an area that cannot be accessed by any unprivileged code, thereby providing an ability to prevent malicious access to incorrect memory. In an embedded system, such as IAR Embedded Workbench, a heuristic mode is used to determine whether a function requires stack protection.

[0068] In addition, the operating system prohibits untrusted system applications from writing to their own task stacks, allows tasks or second-class interrupt handlers to read and write to private task stacks, but prohibits other tasks / interrupts within untrusted system applications from writing to private task stacks. This mechanism is applied in many operating systems. For example, the application launcher in the Android system uses a task stack to manage the interactive component Activity of the application. In the embodiments of this disclosure, the application scenarios are not restricted.

[0069] The task stack protection method provided by this disclosure will be introduced in detail below with reference to the accompanying drawings.

[0070] Figure 1 It is a flowchart of a task stack protection method according to an embodiment of this disclosure. As Figure 1 shown in the embodiment, the task stack protection method includes:

[0071] Step 101, in response to the startup of the operating system, initialize the memory protection unit.

[0072] In this embodiment, preferably, the operating system in this disclosure is RTOS. The memory protection unit refers to a hardware unit in a computer chip that provides memory protection and access control functions. During the startup of the RTOS real-time operating system, the memory protection unit is initialized, and the attributes and access permissions of the MPU control register, MPU region register, etc. are configured.

[0073] Step 102, based on the memory protection unit, move the first task out of the stack protection memory area. The stack protection memory area is the top space of the task stack memory area of the operating system memory, and the first task is a process or thread running by the operating system in the stack protection memory area.

[0074] In this embodiment, the first task is the currently running process or thread in the operating system. The operating system memory, also known as system memory or main memory, is a key component of a computer. It is used to temporarily store the operation data in the Central Processing Unit (CPU) and the data exchanged with external memories such as hard disks. When the system performs a process switch, it is necessary to move the currently running first task out of the operating system memory. The system memory is essentially a Random Access Memory (RAM). The stack protection memory area is the area corresponding to the top space of the task stack memory area in the operating system memory. The top space is the storage space where the top element in the data structure of the memory stack is located. When a new element is pushed onto the stack, this new element will be placed above the top element, making it the new top element. Based on the memory protection unit, the first task is moved out of the stack protection memory area to complete the safe cut-out of the task.

[0075] Step 103, set the attributes of the stack protection memory area of the second task. The second task is the task to be executed after the first task and is an active task.

[0076] In this embodiment, the second task is the process or thread to be switched in the operating system and is executed after the first task. After being automatically triggered by the system, it becomes an active task and waits to be safely switched into the stack protection memory area. After the first task is cut out of the stack protection memory area and before the second task is switched into the stack protection memory area, the attributes of the stack protection memory area are set and modified to the attribute information of the second task in the memory, so as to facilitate the safe switch of the second task to the stack protection memory area and prevent the stack space of the currently running task from being accessed by other tasks or interrupts.

[0077] Step 104, move the second task into the stack protection memory area.

[0078] In this embodiment, after clearing the stack protection memory area and modifying its attributes to the settings of the second task, the second task is moved into the stack protection memory area. For example, the second task is an image display program, and the starting address of the memory it occupies is 0x024FF, and the ending address is 0xED45C. Before the second task is switched into the stack protection memory area, set the MPU PRSELR register to the region number determined by the MPU. For example, select the region with number 0 through mpu_select_region(mpu,0). Set the region base address of the MPU_PRBAR register to 0x024FF and the access permission to executable. Set the region limit address of the MPU_PRBLR register to 0xED45C and enable the region to activate the region. Then, the second task is moved into the stack protection memory area, ensuring the safety of the task when it is pushed onto the stack.

[0079] In one implementation manner of this embodiment,

[0080] Figure 2 is a flowchart of setting MPU registers for RTOS task switching in an embodiment of the present disclosure. In this embodiment, as Figure 2 shown, the scheduler of the RTOS operating system obtains the next task TCB to be executed. Save the context of the previous task. Clear the contents of the registers corresponding to the stack protection Region. Set the base address register and limit address register of the stack protection Region to the start address and end address of the stack space of the next task. Thus, the task switching is completed.

[0081] In summary, according to the task stack protection method proposed by the present disclosure, in response to the startup of the operating system, the memory protection unit is initialized so that access to illegal memory locations will be intercepted by the MPU; based on the memory protection unit, the first task is moved out of the stack protection memory area, and the stack protection memory area is the top space of the task stack memory area of the operating system memory, ensuring that the stack address space of the running task will not be interrupted and illegally accessed by other tasks; set the attributes of the stack protection memory area of the second task, where the second task is the task executed after the first task and is an active task, which completes the pre-setting for the second task to safely enter the stack protection memory area; move the second task into the stack protection memory area, realizing the safe switching of tasks in the stack protection memory area. The security and reliability of the memory protection unit for task stack protection in the memory area are improved.

[0082] Figure 3 is a flowchart of initializing the memory protection unit in response to the startup of the operating system in an embodiment of the present disclosure. Figure 3 is a further description of Figure 1 step 101 of Figure 3 Based on the embodiment shown in

[0083] Step 301, in response to the startup of the operating system, check the memory protection unit.

[0084] In this embodiment, during the startup of the RTOS real-time operating system, the memory protection unit is checked to check whether the configurations of each memory region Region in the memory protection unit are legal.

[0085] In one implementation manner of this embodiment, by checking whether each memory region Region in the memory protection unit is aligned with 64 bytes, that is, whether the length is an integer multiple of 64 bytes, to confirm whether the configuration is legal.

[0086] Step 302, if the check passes, disable the memory protection unit and the background region of the memory protection unit.

[0087] In this embodiment, if the memory protection unit passes the verification, the MPU and the MPU Background are disabled, so as to ensure that access to illegal memory locations will be intercepted by the MPU.

[0088] Step 303: Initialize the memory of the operating system and the memory area of the memory protection unit, and enable the memory protection unit.

[0089] In this embodiment, during the startup of the RTOS operating system, the memory area Region of the operating system memory RAM and the memory protection unit MPU is initialized. For example, system startup resources are loaded into the RAM, and the serial number, base address, limit address, access permission, and memory attribute of each Region in the MPU are set. The memory protection unit is enabled. For example, the MPU is declared by armv8m_mpu_t*mpu=(armv8m_mpu_t*)0xE000ED90, the region with serial number 0 is selected by mpu_select_region(mpu, 0), and the base address of region0 is set to 0x30000000 by using mpu_set_region_base(mpu, 0x30000000UL, REGION_NON_SHAREABLE, REGION_RO_PRIV_ONLY, REGION_XN), the access permission is read-only, and the memory attribute is non-executable. The limit address of region0 is set to 0x30001FFF by using mpu_set_region_limit(mpu, 0x30001FFFUL, 0, REGION_EN), and region0 is enabled.

[0090] In one implementation manner of this embodiment,

[0091] Figure 4 is a schematic diagram of the memory of an operating system according to an embodiment of the present disclosure. In this embodiment, as Figure 4 shown, in the RTOS operating system, it is necessary to plan the memory mapping area during the development stage, configure the common segment attributes using the MPU Region, and reserve a fixed Region to configure the stack space of the running tasks as the stack protection memory area. The common area includes the Block Started by Symbol (BSS) area, the data area, and the text area, and the stack protection area includes the stack area composed of many task stacks such as Task 1 stack and Task 2 stack. The operating system memory is planned to establish a mapping with the regions of the MPU, providing a preparation for initializing the memory of the operating system and the memory area of the MPU during the startup of the RTOS.

[0092] In this embodiment, in response to the startup of the operating system, the memory protection unit is initialized, providing a secure operating environment for task stack protection.

[0093] Figure 5 It is a flowchart for initializing the memory area of the operating system memory and the memory protection unit in an embodiment of the present disclosure. Figure 5 It is a further explanation of step 303 in Figure 3 , based on the embodiment shown in Figure 5 , including the following steps:

[0094] Step 501, set the attributes of the operating system memory.

[0095] In this embodiment, the attributes of the operating system memory include information such as the read / write permissions of the memory and whether code is stored. If the memory protection unit is initialized, since there is a memory mapping relationship between the operating system memory and the memory protection unit, the operating system memory is initialized simultaneously, and the attributes of the operating system memory are set to complete the initialization of the memory area in the RAM.

[0096] Step 502, set the attributes of each protection area of the memory protection unit, and the protection area includes the stack protection memory area.

[0097] In this embodiment, the attributes of each protection area Region of the memory protection unit are set, and the attributes take effect by modifying the corresponding registers of the attribute information. For example, the Region number is determined by setting the MPU PRSELR register, the base address and access permissions of the Region are determined by setting the MPU PRBAR register, and the limit address and memory attributes of the Region are determined by setting the MPU PRBLR register. Each memory area in the protection area Region is stored in a stack structure, and the stack protection memory area is the memory area at the top of the stack of the protection area Region.

[0098] In an implementation manner of this embodiment,

[0099] Figure 6 It is a flowchart for initializing the memory protection area of the MPU in an embodiment of the present disclosure. In this embodiment, as shown in Figure 6 , the RTOS system starts. Check whether the MPU configuration is legal. After confirming that the MPU is legal, disable the MPU, and then disable the MPU Background to intercept illegal access to the memory. Set the Region memory attributes, that is, set the memory attributes associated with the MPU Region in the RTOS system. Set the attributes of the MPU Region in the system, and complete the initialization of the MPU by setting different attribute registers of the MPU Region, and enable the MPU to make the settings of the MPU take effect.

[0100] In this embodiment, initializing the memory of the operating system and the memory area of the memory protection unit provides a prerequisite for task stack protection.

[0101] Figure 7 It is a flowchart for setting the attributes of each protection area of the memory protection unit according to an embodiment of the present disclosure. Figure 7 It is a specific description of Figure 5 Step 502 of, based on Figure 7 the embodiment shown, includes the following steps:

[0102] Step 701, set the area number register, area base address register, and area limit address register of the protection area of the memory protection unit.

[0103] In this embodiment, the area number register refers to the register in the memory protection unit that stores the number of the protection area Region, the area base address register refers to the register in the memory protection unit that stores the starting address of the protection area Region, and the area limit address register refers to the register in the memory protection unit that stores the termination address (boundary address) of the protection area Region. During the startup of the RTOS operating system, the area number register, area base address register, and area limit address register of each protection area Region of the memory protection unit are initialized to default values. Optionally, the default value is 0, so that all memory areas are set to be inaccessible. Then, during the program operation, the values of these registers are modified through software according to actual needs, so as to achieve access control of specific memory areas.

[0104] In this embodiment, the attributes of each protection area of the memory protection unit are set through corresponding registers, completing the initialization of the memory protection unit and providing key security protection hardware for task stack protection.

[0105] Figure 8 It is a flowchart for removing the first task from the stack protection memory area based on the memory protection unit according to an embodiment of the present disclosure. Figure 8 It is a specific description of Figure 1 Step 102 of, based on Figure 8 the embodiment shown, includes the following steps:

[0106] Step 801, remove the first task from the stack protection memory area and save the context of the first task.

[0107] In this embodiment, since the first task performs stack space protection in the stack protection memory area, when task switching occurs, it is necessary to first remove it from the stack protection memory area and save the context of the first task. Since the RTOS is a single-state OS, the context of the first task includes two parts: register context and system-level context.

[0108] The register context covers information such as the program counter, general-purpose registers, control registers, status word registers, and stack pointers. Among them, the program counter stores the address of the next instruction, the general-purpose registers are used to temporarily store calculation results, the control registers store the status information of the processor, such as whether interrupts are enabled, etc., the status word registers save the main status flags of the processor, and the stack pointer points to the stack space of the current task.

[0109] The system-level context includes the Process Control Block (PCB), main memory management information (page table & segment table), and the information of the kernel stack. The process control block is the core data structure of the process, which records all the information required by the operating system to manage the process; the main memory management information is important data for managing the system memory, and the page table and segment table are the keys to memory management; the kernel stack is mainly used to support system function calls and returns. The system-level context also includes the Thread Control Block.

[0110] Step 802, clear the attribute registers that save the stack protection memory area. The attribute registers include the area number register, area base address register, and area limit address register.

[0111] In this embodiment, the attribute register refers to the register that stores the attributes of the stack protection memory area, including the area number register, area base address register, and area limit address register. When performing task switching on the stack protection memory area, first cut out the first task, and then it is necessary to clear the attribute information about the first task in the attribute registers of the stack protection memory area. That is, clear the attribute registers that save the stack protection memory area.

[0112] In this embodiment, based on the memory protection unit, the first task is moved out of the stack protection memory area, ensuring that the stack address space of the running task will not be interrupted and illegally accessed by other tasks.

[0113] Figure 9 It is a flowchart for setting the attributes of the stack protection memory area of the second task in an embodiment of the present disclosure. Figure 9 It is for Figure 1 Steps 103 and Figure 7 For a specific description, based on Figure 9 The embodiment shown, includes the following steps:

[0114] Step 901, write the starting address of the stack space of the second task into the area base address register.

[0115] In this embodiment, the starting address of the stack space of the second task is written into the region base address register. That is, the starting address of the memory occupied by the second task is used as the starting address of the stack protection memory region.

[0116] Step 902, write the ending address of the stack space of the second task into the region limit address register.

[0117] In this embodiment, the ending address of the stack space of the second task is written into the region limit address register. That is, the ending address of the memory occupied by the second task is used as the boundary address of the stack protection memory region.

[0118] In this embodiment, by aligning the starting address and the ending address of the second task in the memory with the region base address and the region limit address of the stack protection memory region, it is ensured that the stack protection memory region can completely store the second task for stack space protection.

[0119] A task stack protection method provided by an embodiment of the present disclosure initializes a memory protection unit in response to the startup of an operating system, so that access to illegal memory locations will be intercepted by the MPU; based on the memory protection unit, the first task is moved out of the stack protection memory region, and the stack protection memory region is the top space of the task stack memory region of the operating system memory, and the first task is a process or thread running by the operating system in the stack protection memory region, ensuring that the stack address space of the running task will not be interrupted and illegally accessed by other tasks; set the attributes of the stack protection memory region of the second task, and the second task is a task executed after the first task and is an active task, which completes the pre-setting for the second task to safely enter the stack protection memory region; move the second task into the stack protection memory region, realizing the safe switching of tasks in the stack protection memory region. It improves the security and reliability of the memory protection unit for task stack protection of memory regions.

[0120] Corresponding to the methods provided in the above several embodiments, the present disclosure also provides a task stack protection device. Since the device provided by the embodiment of the present disclosure corresponds to the methods provided in the above several embodiments, the implementation manners of the methods are also applicable to the device provided in this embodiment and will not be described in detail in this embodiment.

[0121] Figure 10 It is a schematic structural diagram of a task stack protection device 1000 according to an embodiment of the present disclosure. As Figure 10 shown, the task stack protection device includes:

[0122] An initialization module 1010, configured to initialize a memory protection unit in response to the startup of an operating system;

[0123] A removal module 1020, configured to remove a first task from a stack protection memory area based on a memory protection unit, where the stack protection memory area is the top space of a task stack memory area of an operating system memory, and the first task is a process or a thread that the operating system runs in the stack protection memory area;

[0124] A setting module 1030, configured to set attributes of a stack protection memory area of a second task, where the second task is a task that is executed after the first task and is an active task;

[0125] A moving-in module 1040, configured to move the second task into the stack protection memory area.

[0126] In some embodiments, an initialization module 1010 is configured to:

[0127] In response to the startup of the operating system,

[0128] Initialize the memory areas of the operating system memory and the memory protection unit, and enable the memory protection unit.

[0129] In some embodiments, before initializing the memory protection unit in response to the startup of the operating system, the initialization module 1010 is further configured to:

[0130] In response to the startup of the operating system, verify the memory protection unit;

[0131] If the verification passes, disable the memory protection unit and the background area of the memory protection unit.

[0132] In some embodiments, the initialization module 1010 initializes the memory areas of the operating system memory and the memory protection unit in the following manner:

[0133] Set the attributes of the operating system memory;

[0134] Set the attributes of each protection area of the memory protection unit, where the protection areas include the stack protection memory area.

[0135] In some embodiments, the initialization module 1010 sets the attributes of each protection area of the memory protection unit in the following manner:

[0136] Set the area number register, the area base address register, and the area limit address register of the protection area of the memory protection unit.

[0137] In some embodiments, the removal module 1020 is configured to:

[0138] Remove the first task from the stack protection memory area and save the context of the first task;

[0139] Clear the attribute registers of the stack protection memory area for preservation. The attribute registers include an area number register, an area base address register, and an area limit address register.

[0140] In some embodiments, the setting module 1030 is configured to:

[0141] Write the starting address of the stack space of the second task into the area base address register;

[0142] Write the ending address of the stack space of the second task into the area limit address register.

[0143] In summary, through the task stack protection device, in response to the startup of the operating system, the memory protection unit is initialized; based on the memory protection unit, the first task is moved out of the stack protection memory area. The stack protection memory area is the top space of the task stack memory area of the operating system memory, and the first task is a process or thread that the operating system runs in the stack protection memory area; the attributes of the stack protection memory area of the second task are set. The second task is a task that is executed after the first task and is an active task; the second task is moved into the stack protection memory area. This device solves the problem that the memory protection unit has insecurity and unreliability in the task stack protection of the memory area, and improves the security and reliability of the memory protection unit for the task stack protection of the memory area.

[0144] In the above embodiments provided by the present disclosure, the methods and devices provided by the embodiments of the present disclosure are introduced. To implement the various functions in the methods provided by the above embodiments of the present disclosure, an electronic device may include a hardware structure, software modules, and implement the above various functions in the form of a hardware structure, software modules, or a combination of a hardware structure and software modules. A certain function among the above various functions may be executed in the form of a hardware structure, software module, or a combination of a hardware structure and software module.

[0145] Figure 11 It is a block diagram of an electronic device 1100 for implementing the above task stack protection method shown according to an exemplary embodiment.

[0146] For example, the electronic device 1100 may be a mobile phone, a computer, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0147] Refer to Figure 11 , the electronic device 1100 may include one or more of the following components: a processing component 1102, a memory 1104, a power component 1106, a multimedia component 1108, an audio component 1110, an input / output (I / O) interface 1112, a sensor component 1114, and a communication component 1116.

[0148] The processing component 1102 generally controls the overall operation of the electronic device 1100, such as operations associated with display, telephone calls, data communications, camera operations, and recording operations. The processing component 1102 may include one or more processors 1120 to execute instructions to complete all or part of the steps of the above methods. In addition, the processing component 1102 may include one or more modules to facilitate the interaction between the processing component 1102 and other components. For example, the processing component 1102 may include a multimedia module to facilitate the interaction between the multimedia component 1108 and the processing component 1102.

[0149] The memory 1104 is configured to store various types of data to support the operation of the electronic device 600. Examples of such data include instructions for any application or method operating on the electronic device 1100, contact data, phone book data, messages, pictures, videos, etc. The memory 1104 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk.

[0150] The power component 1106 provides power to various components of the electronic device 1100. The power component 1106 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the electronic device 1100.

[0151] The multimedia component 1108 includes a screen that provides an output interface between the electronic device 1100 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can not only sense the boundaries of touch or swipe actions, but also detect the duration and pressure associated with the touch or swipe operations. In some embodiments, the multimedia component 1108 includes a front camera and / or a rear camera. When the electronic device 1100 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each of the front camera and the rear camera may be a fixed optical lens system or have focal length and optical zoom capabilities.

[0152] The audio component 1110 is configured to output and / or input audio signals. For example, the audio component 1110 includes a microphone (MI11), which is configured to receive external audio signals when the electronic device 1100 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 1104 or transmitted via the communication component 1116. In some embodiments, the audio component 1110 further includes a speaker for outputting audio signals.

[0153] The I / O interface 1112 provides an interface between the processing component 1102 and a peripheral interface module, and the peripheral interface module can be a keyboard, a click wheel, buttons, etc. These buttons can include, but are not limited to: a home button, a volume button, a power button, and a lock button.

[0154] The sensor component 1114 includes one or more sensors for providing status assessments of various aspects of the electronic device 1100. For example, the sensor component 1114 can detect the on / off state of the electronic device 1100, the relative positioning of components, such as the display and keypad of the electronic device 1100. The sensor component 1114 can also detect a change in the position of the electronic device 1100 or a component of the electronic device 1100, the presence or absence of user contact with the electronic device 1100, the orientation or acceleration / deceleration of the electronic device 1100, and the temperature change of the electronic device 1100. The sensor component 1114 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor component 1114 can also include a light sensor, such as a 11MOS or 1111D image sensor, for use in imaging applications. In some embodiments, the sensor component 1114 can further include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0155] The communication component 1116 is configured to facilitate communication between the electronic device 1100 and other devices in a wired or wireless manner. The electronic device 1100 can access a wireless network based on communication standards, such as WiFi, 2G or 3G, 4G LTE, 5G NR (New Radio), or a combination thereof. In an exemplary embodiment, the communication component 1116 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 1116 further includes a near field communication (NF11) module to facilitate short-range communication. For example, the NF11 module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0156] In an exemplary embodiment, the electronic device 1100 may be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components for performing the above-described method.

[0157] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 1104 including instructions, and the above instructions can be executed by a processor 1120 of the electronic device 1100 to complete the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), 11D-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0158] An embodiment of the present disclosure also proposes a non-transitory computer-readable storage medium storing computer instructions, where the computer instructions are used to cause a computer to execute the task stack protection method described in the above embodiments of the present disclosure.

[0159] An embodiment of the present disclosure also proposes a computer program product, including a computer program, and the computer program executes the task stack protection method described in the above embodiments of the present disclosure when being executed by a processor.

[0160] Figure 12 FIG. is a schematic structural diagram of a chip 1200 for implementing the above task stack protection method according to an exemplary embodiment.

[0161] Refer to Figure 12 , the chip 1200 includes at least one communication interface 1201 and a processor 1202; the communication interface 1201 is used to receive signals input to the chip 1200 or signals output from the chip 1200, and the processor 1202 communicates with the communication interface 1201 and implements the task stack protection method described in the above embodiments through logic circuits or by executing code instructions.

[0162] An embodiment of the present disclosure also proposes a vehicle, where the vehicle includes a task stack protection device as Figure 10 shown.

[0163] It should be noted that the terms "first", "second", etc. in the description of the present disclosure, the claims and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0164] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "schematic embodiments", "examples", "specific examples" or "some examples", etc. means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present disclosure. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.

[0165] Any process or method description in a flowchart or described in other ways herein can be understood to represent a module, segment or portion of code including one or more executable instructions for implementing a specific logical function or process, and the scope of the preferred embodiments of the present disclosure includes additional implementations, where the functions can be executed in a manner that is not shown or discussed, including in a substantially simultaneous manner or in a reverse order according to the functions involved, which should be understood by those skilled in the technical field to which the embodiments of the present disclosure belong.

[0166] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definable sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processing module, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or used in conjunction with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. More specific examples (non-exhaustive list) of computer-readable media include the following: electrical connection parts with one or more wirings (control methods), portable computer disk cartridges (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber devices, and portable compact disc read-only memory (CDROM). Additionally, a computer-readable medium can even be paper or other suitable media on which a program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or other appropriate processing as necessary, and then stored in a computer memory.

[0167] It should be understood that various parts of the embodiments of the present disclosure can be implemented using hardware, software, firmware, or combinations thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits with logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits with suitable combinational logic gate circuits, programmable gate arrays (PGA), field-programmable gate arrays (FPGA), etc.

[0168] Those of ordinary skill in the art of this technology can understand that all or part of the steps carried by the methods of the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.

[0169] In addition, each functional unit in various embodiments of the present disclosure may be integrated into one processing module, or each unit may exist physically alone, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium. The above-mentioned storage medium may be a read-only memory, a magnetic disk or an optical disc, etc.

[0170] Although the embodiments of the present disclosure have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present disclosure. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present disclosure.

Claims

1. A method for protecting a task stack, characterized in that, The method includes: Initializing a memory protection unit in response to the startup of an operating system; Based on the memory protection unit, moving a first task out of a stack protection memory area, where the stack protection memory area is the top space of the task stack memory area of the operating system memory, and the first task is a process or thread that the operating system runs in the stack protection memory area; Setting the attributes of the stack protection memory area of a second task, where the second task is a task that is executed after the first task and is an active task; Moving the second task into the stack protection memory area.

2. The method according to claim 1, wherein The initializing a memory protection unit in response to the startup of an operating system includes: Initializing the memory area of the operating system memory and the memory protection unit in response to the startup of the operating system, and enabling the memory protection unit.

3. The method according to claim 1, characterized in that, Before the initializing a memory protection unit in response to the startup of an operating system, it further includes: Verifying the memory protection unit in response to the startup of the operating system; If the verification passes, disabling the memory protection unit and the background area of the memory protection unit.

4. The method according to claim 2, characterized in that, The initializing the memory area of the operating system memory and the memory protection unit includes: Setting the attributes of the operating system memory; Setting the attributes of each protection area of the memory protection unit, where the protection areas include the stack protection memory area.

5. The method according to claim 4, characterized in that, The setting the attributes of each protection area of the memory protection unit includes: Setting the area number register, area base address register, and area limit address register of the protection area of the memory protection unit.

6. The method according to claim 1, wherein The moving a first task out of a stack protection memory area based on the memory protection unit includes: Moving the first task out of the stack protection memory area and saving the context of the first task; Clearing the attribute registers that save the stack protection memory area, where the attribute registers include the area number register, area base address register, and area limit address register.

7. The method according to claim 6, wherein The setting the attributes of the stack protection memory area of a second task includes: Writing the start address of the stack space of the second task into the area base address register; Writing the end address of the stack space of the second task into the area limit address register.

8. A task stack protection device, characterized in that, The device includes: An initialization module for initializing a memory protection unit in response to the startup of an operating system; A removal module for moving a first task out of a stack protection memory area based on the memory protection unit, where the stack protection memory area is the top space of the task stack memory area of the operating system memory; A setting module for setting the attributes of the stack protection memory area of a second task, where the second task is a task that is executed after the first task and is an active task; A moving-in module for moving the second task into the stack protection memory area.

9. An electronic device, characterized in that, It includes: At least one processor; And A memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method according to any one of claims 1-6.

10. A vehicle, characterized in that, Comprising the task stack protection device according to claim 6.

Citation Information

Cited By

  • Stack protection method and device for embedded real-time operating system and storage medium

    CN121902129A