Resource management method and device, electronic equipment and readable storage medium

By dividing the memory space into multiple logically isolated supervision domains and configuring access permissions, the problem of insufficient memory isolation and permission control in the traditional RISC-V architecture is solved, and fine-grained resource management is realized, improving security and resource utilization.

CN120371738APending Publication Date: 2025-07-25BEIJING INSTITUTE OF OPEN SOURCE CHIP
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510859525.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-25
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

Traditional RISC-V architectures are difficult to achieve fine-grained memory isolation and permission control in a cloud computing multi-tenant environment, resulting in the risk of data leakage and resource competition.

Method used

The memory space is divided into multiple logically isolated supervisory domains, each domain has unique access permissions, and fine-grained access control and permission management are realized through the supervised domain identifier and address written to the control status register.

Benefits of technology

Improve the accuracy of resource management, prevent data leakage and mutual interference between tenants, support flexible division of multi-tenants or multi-security levels, and improve resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120371738A_ABST
    Figure CN120371738A_ABST
Patent Text Reader

Abstract

Embodiments of the invention provide a resource management method and apparatus, an electronic device and a readable storage medium. The method comprises the steps of dividing a memory space into at least one logically isolated region; each region belongs to a unique supervision domain; under the condition that an access request of a first tenant is received, a first supervision domain corresponding to the first tenant is determined, and the access permission of the first tenant for memory resources corresponding to the first supervision domain is configured; writing a supervision domain identifier of the first supervision domain and a first address into a control state register, so that the processor executes a program corresponding to the first tenant in the first supervision domain according to the access permission; wherein the first address is used for indicating a storage address of the access permission. According to the embodiment of the invention, the control granularity of access management is refined, and the resource management precision is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technologies, and in particular, to a resource management method, apparatus, electronic device, and readable storage medium. Background Art

[0002] With the rapid development of Internet and cloud computing technologies, traditional RISC-V architectures face various threats in cloud computing multi-tenant environments, and these threats mainly come from system software attackers and unauthorized software attackers. Traditional memory management methods are difficult to achieve fine-grained memory isolation and permission control, which makes there a risk of mutual interference between the data and workloads of different tenants, and may lead to key data leakage and resource contention. Summary of the Invention

[0003] Embodiments of the present invention provide a resource management method, apparatus, electronic device, and readable storage medium, which can solve the problem in related technologies that it is difficult to achieve fine-grained memory isolation and permission control, resulting in data leakage and resource contention.

[0004] On the one hand, embodiments of the present invention disclose a resource management method applied to a processor, and the method includes: Dividing a memory space into at least one logically isolated area; each area belongs to a unique supervision domain; When receiving an access request from a first tenant, determining a first supervision domain corresponding to the first tenant, and configuring an access right of the first tenant to memory resources corresponding to the first supervision domain; Writing a supervision domain identifier of the first supervision domain and a first address into a control status register for the processor to execute a program corresponding to the first tenant within the first supervision domain according to the access right; Wherein, the first address is used to indicate a storage address of the access right.

[0005] Optionally, the configuring the access right of the first tenant to memory resources corresponding to the first supervision domain includes: Determining entries corresponding to each page of the first supervision domain in a memory protection table, determining the entries as leaf nodes, and determining a page directory entry corresponding to the entry as an intermediate node; Determining a first base address corresponding to the intermediate node according to an address space corresponding to the intermediate node, and determining the first base address as the first address; Determining a second base address corresponding to the leaf node according to an address space corresponding to the leaf node, and determining the second base address as a second address; Write the second address to the intermediate node, and configure the access rights of the first tenant to each page corresponding to the first supervision domain in the leaf node.

[0006] Optionally, the method further includes: When receiving an access request from the first tenant, determine the supervision domain identifier corresponding to the first tenant; Query the memory protection table according to the supervision domain identifier to determine the access rights of the first tenant to the target address carried in the access request; Perform access control on the access request according to the access rights.

[0007] Optionally, the querying the memory protection table according to the supervision domain identifier to determine the access rights of the first tenant to the target address carried in the access request includes: Divide the memory resources into a first address segment, a second address segment, and a third address segment, and divide the cache into a first cache, a second cache, and a third cache; wherein, the first cache is used to store the intermediate node corresponding to the first address segment, the second cache is used to store the intermediate node corresponding to the second address segment, and the third cache is used to store the leaf node corresponding to the third address segment; Access the third cache according to the target address carried in the access request; When the access request hits the third cache, determine the target node address according to the first address in the control status register and the target address carried in the access request; Read the access rights from the corresponding leaf node according to the target node address; When the access request hits the third cache, read the access rights from the leaf node corresponding to the target address; When the access request does not hit the third cache, access the first cache and the second cache respectively according to the target address; When the first cache hits or the second cache hits, write the base address stored in the intermediate node corresponding to the target address to the miss status register, so that the processor reads the access rights from the memory according to the base address stored in the miss status register; When both the first cache and the second cache do not hit, write the first address in the control status register to the miss status register, so that the processor reads the access rights from the memory according to the first address stored in the miss status register.

[0008] Optionally, when receiving an access request from a first tenant, determining a first supervision domain corresponding to the first tenant includes: When receiving an access request from a first tenant, querying an unallocated supervision domain from a supervision domain configuration table; the supervision domain configuration table is used to record the correspondence between supervision domains and tenants; Determining a supervision domain from the unallocated supervision domains as the first supervision domain corresponding to the first tenant; Updating the supervision domain configuration table according to the tenant identifier of the first tenant and the supervision domain identifier of the first supervision domain.

[0009] Optionally, configuring the access right of the first tenant to the memory resources corresponding to the first supervision domain includes: Determining exclusive resources and shared resources corresponding to the first supervision domain; Configuring a first access right of the first tenant to the exclusive resources according to resource isolation requirements; Configuring a second access right of the first tenant to the shared resources according to resource sharing requirements.

[0010] Optionally, the processor includes a multi-core processor, and each processor core corresponds to a control status register; writing the supervision domain identifier and a first address of the first supervision domain into the control status register includes: Determining a first processor core corresponding to the first supervision domain; Writing the supervision domain identifier of the first supervision domain and the first address into the control status register corresponding to the first processor core.

[0011] On the other hand, an embodiment of the present invention discloses a resource management device applied to a processor, and the device includes: An isolation module, configured to divide a memory space into at least one logically isolated area; each area belongs to a unique supervision domain; A configuration module, configured to determine a first supervision domain corresponding to the first tenant and configure the access right of the first tenant to the memory resources corresponding to the first supervision domain when receiving an access request from the first tenant; A writing module, configured to write the supervision domain identifier of the first supervision domain and a first address into a control status register for the processor to execute a program corresponding to the first tenant within the first supervision domain according to the access right; Wherein, the first address is used to indicate the storage address of the access right.

[0012] Optionally, the configuration module includes: The first determination sub-module is configured to determine the table entries corresponding to each page of the first supervision domain in the memory protection table, determine the table entries as leaf nodes, and determine the page directory entries corresponding to the table entries as intermediate nodes; The second determination sub-module is configured to determine a first base address corresponding to the intermediate node according to the address space corresponding to the intermediate node, and determine the first base address as the first address; The third determination sub-module is configured to determine a second base address corresponding to the leaf node according to the address space corresponding to the leaf node, and determine the second base address as the second address; The first configuration sub-module is configured to write the second address into the intermediate node, and configure the access permissions of the first tenant to each page corresponding to the first supervision domain in the leaf node.

[0013] Optionally, the apparatus further includes: The identifier determination module is configured to determine a supervision domain identifier corresponding to the first tenant when receiving an access request of the first tenant; The query module is configured to query the memory protection table according to the supervision domain identifier to determine the access permission of the first tenant to a target address carried in the access request; The access control module is configured to perform access control on the access request according to the access permission.

[0014] Optionally, the query module includes: The resource division sub-module is configured to divide the memory resources into a first address segment, a second address segment, and a third address segment, and divide the cache into a first cache, a second cache, and a third cache; wherein, the first cache is used to store intermediate nodes corresponding to the first address segment, the second cache is used to store intermediate nodes corresponding to the second address segment, and the third cache is used to store leaf nodes corresponding to the third address segment; The first query sub-module is configured to access the third cache according to the target address carried in the access request; The permission reading sub-module is configured to read the access permission from the leaf node corresponding to the target address when the access request hits the third cache; The second query sub-module is configured to access the first cache and the second cache respectively according to the target address when the access request does not hit the third cache; The first writing sub-module is configured to write the base address stored in the intermediate node corresponding to the target address into the miss status register when the first cache hits or the second cache hits, so that the processor reads the access permission from the memory according to the base address stored in the miss status register; A second writing sub-module, configured to write a first address in the control status register into a miss status register when both the first cache and the second cache miss, so that the processor reads the access right from a memory according to the first address stored in the miss status register.

[0015] Optionally, the configuration module includes: A supervision domain query sub-module, configured to query an unallocated supervision domain from a supervision domain configuration table when receiving an access request of a first tenant; the supervision domain configuration table is used to record a correspondence between a supervision domain and a tenant; A supervision domain allocation sub-module, configured to determine a supervision domain from the unallocated supervision domains as a first supervision domain corresponding to the first tenant; An update sub-module, configured to update the supervision domain configuration table according to a tenant identifier of the first tenant and a supervision domain identifier of the first supervision domain.

[0016] Optionally, the configuration module includes: A resource determination sub-module, configured to determine exclusive resources and shared resources corresponding to the first supervision domain; A second configuration sub-module, configured to configure a first access right of the first tenant to the exclusive resources according to a resource isolation requirement; A third configuration sub-module, configured to configure a second access right of the first tenant to the shared resources according to a resource sharing requirement.

[0017] Optionally, the processor includes a multi-core processor, and each processor core corresponds to a control status register; the writing module includes: A fourth determination sub-module, configured to determine a first processor core corresponding to the first supervision domain; A third writing sub-module, configured to write the supervision domain identifier of the first supervision domain and the first address into the control status register corresponding to the first processor core.

[0018] On the other hand, an embodiment of the present invention further discloses an electronic device, which includes a processor, a memory, a communication interface, and a communication bus. The processor, the memory, and the communication interface complete communication with each other through the communication bus; the memory is used to store executable instructions, and the executable instructions enable the processor to execute the foregoing resource management method.

[0019] An embodiment of the present invention further discloses a readable storage medium. When instructions in the readable storage medium are executed by a processor of an electronic device, the electronic device can execute the foregoing resource management method.

[0020] The embodiments of the present invention have the following advantages: An embodiment of the present invention provides a resource management method, which can divide the memory space into at least one logically isolated area; each area belongs to a unique supervision domain; in the case of receiving an access request from a first tenant, determine the first supervision domain corresponding to the first tenant, and configure the access right of the first tenant to the memory resources corresponding to the first supervision domain; write the supervision domain identifier of the first supervision domain and the first address into the control status register, so that the processor can execute the program corresponding to the first tenant within the first supervision domain according to the access right. The embodiment of the present invention can break through the traditional dual-domain limitation of "secure area / non-secure area", support flexible multi-tenant or multi-security level division, and support independent access right control for each supervision domain, refine the control granularity of access management, and improve the resource management accuracy. Description of the Drawings

[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to these drawings.

[0022] Figure 1 It is a flowchart of the steps of an embodiment of a resource management method of the present invention; Figure 2 It is a schematic diagram of a permission lookup process without hardware acceleration of the present invention; Figure 3 It is a schematic diagram of a permission lookup process without hardware acceleration of the present invention; Figure 4 It is a schematic diagram of a multi-parallel cache lookup method of the present invention; Figure 5 It is a schematic diagram of a permission lookup with hardware acceleration of the present invention; Figure 6 It is a schematic diagram of a permission lookup process with hardware acceleration of the present invention; Figure 7 It is a block diagram of the structure of a resource management device of the present invention; Figure 8 It is a block diagram of the structure of an electronic device provided by an example of the present invention. Detailed Embodiments

[0023] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0024] The terms "first", "second", etc. in the description and claims of the present invention are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of the same category, and do not limit the number of objects. For example, the first object can be one or multiple. In addition, the term "and / or" in the description and claims is used to describe the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after. In the embodiments of the present invention, the term "multiple" refers to two or more, and other quantifiers are similar.

[0025] Method embodiments Refer to Figure 1 , which shows a step flowchart of an embodiment of a resource management method of the present invention. The method can specifically include the following steps: Step 101: Divide the memory space into at least one logically isolated area; each area belongs to a unique supervision domain; Step 102: When receiving an access request from a first tenant, determine the first supervision domain corresponding to the first tenant, and configure the access permission of the first tenant for the memory resources corresponding to the first supervision domain; Step 103: Write the supervision domain identifier and the first address of the first supervision domain into the control status register for the processor to execute the program corresponding to the first tenant within the first supervision domain according to the access permission.

[0026] Wherein, the first address is used to indicate the storage address of the access permission.

[0027] The resource management method provided by the embodiments of the present invention is applied to a processor, and the processor can be a single-core processor or a multi-core processor. The processor can be a processor in a multi-tenant management device with data processing, network communication, and program running functions. The multi-tenant management device can be a big data platform, a cloud computing platform, or other electronic devices that can achieve the same or similar functions.

[0028] The embodiments of the present invention are used to implement resource management in a multi-tenant application architecture, achieving resource isolation and fine-grained permission management among tenants. It can be understood that a tenant refers to an independent logical entity that shares the same system or platform. Each tenant has independent business requirements, data space, and permission boundaries. The underlying hardware and basic software (such as operating systems, databases, etc.) of the same system or platform can be shared by multiple tenants. Exemplarily, in SaaS software services, such as enterprise collaboration tools, different enterprises are independent tenants, using the same set of software but with data isolation. Or, in a cloud computing platform, multiple customers (tenants) share physical servers, but isolation is achieved through virtualization technologies (such as virtual machines, containers, etc.). Or, in a multi-user environment of an operating system, such as different user accounts (tenants) in the Linux system sharing the kernel but each having independent file system permissions.

[0029] In the embodiments of the present invention, the memory space is divided into at least one logically isolated region, and each region belongs to a unique supervision domain. When an access request from a tenant is received, a corresponding supervision domain is allocated to each tenant, and access permissions for the memory resources corresponding to the supervision domain are configured. Exemplarily, for the first tenant, a corresponding supervision domain is allocated to it, denoted as the first supervision domain. Then, the access permissions of the first tenant for the memory resources corresponding to the first supervision domain are configured.

[0030] After allocating the supervision domain and access permissions for the first tenant, the supervision domain identifier and the first address of the first supervision domain corresponding to the first tenant can be written into the control status register for the processor to execute the program corresponding to the first tenant within the first supervision domain according to the access permissions.

[0031] It should be noted that the supervision domain in the embodiments of the present invention refers to an independent secure execution environment divided by a hardware-level memory isolation mechanism in a multi-tenant or multi-security-level environment.

[0032] In the related art, the memory resources of a processor are usually divided into two domains: a secure area and a non-secure area, and the secure area and the non-secure area are completely independent. Only one-way access from the secure area to the non-secure area can be achieved, and two-way cross-area sharing cannot be achieved.

[0033] In the embodiments of the present invention, the memory resources can be divided into multiple supervision domains, and each supervision domain can be independently configured with access permissions, such as read, write, execute, etc. For example, a certain supervision domain can be configured to be readable and executable but not writable for a certain page. And, in the embodiments of the present invention, shared resources can also be set for two or more supervision domains to achieve cross-domain shared memory.

[0034] If cross - supervised - domain memory sharing is to be achieved, shared resources can be configured for at least two supervised domains based on resource sharing requirements, such that at least two supervised domains can map the shared resources, but different permissions are configured for each supervised domain. For example, the same physical page is mapped in the page tables of two supervised domains, and different permissions are configured for each. For instance, assume that for tenant a, supervised domain A is configured, and for tenant b, supervised domain B is configured. The access permission for the shared page in the page table of supervised domain A is "read + write", and the access permission for the shared page in the page table of supervised domain B is "read", realizing one - way sharing where A can write and B can read; if both are configured with "read + write", two - way sharing is realized.

[0035] In the embodiments of the present invention, the memory space is divided into multiple logically isolated regions, and each region belongs to a unique supervised domain. Codes, data, etc. of different supervised domains may be adjacent in physical memory, but logical isolation is achieved through configured access permissions and supervised - domain identifiers, which can ensure that each tenant runs within an independent supervised domain, prevent interference between tenants and data leakage caused by unauthorized access, and improve the accuracy of resource management.

[0036] In addition, in the traditional solution, the access permission of the secure area to the non - secure area is global, such as "accessible" or "inaccessible", while in the embodiments of the present invention, access permissions can be configured separately for each page within each supervised domain based on the supervised domain, and even different access permissions can be configured for different pages within the same supervised domain. For example, the code segment is configured to be executable but not writable, and the data segment is configured to be writable but not executable.

[0037] As an example, assume that there are 3 tenants (tenant A, tenant B, and public service domain C) running on a cloud server, and the requirements are as follows: Isolation requirement: The business data of tenant A and tenant B must be completely isolated and not accessible to each other.

[0038] Sharing requirement: Both tenant A and tenant B need to read the configuration files provided by the public service domain C, but cannot modify them.

[0039] Permission requirement: The code segment of tenant A is allowed to be executed but not writable, and the data segment is allowed to be read and written but not executable.

[0040] Adopting the resource management method provided by the embodiments of the present invention, first create 3 supervised domains and allocate them to these three tenants respectively. Among them, tenant A corresponds to supervised domain Domain_A, tenant B corresponds to supervised domain Domain_B, and the public service domain C corresponds to supervised domain Domain_C.

[0041] Next, configure page tables for each tenant respectively, and identify the supervised domain to which each page belongs and the access permission corresponding to this supervised domain (or tenant) in each page - table entry: Private data page of Tenant A: Domain ID = A, Permission = Read / Write, accessible only by Domain_A.

[0042] Private data page of Tenant B: Domain ID = B, Permission = Read / Write, accessible only by Domain_B.

[0043] Public configuration file page: Domain ID = C, Permission = Read, both Domain_A and Domain_B can map and read this page, but cannot write.

[0044] Code page of Tenant A: Domain ID = A, Permission = Execute + Read, not writable to prevent code tampering.

[0045] When the process of Tenant A attempts to access the private page of Tenant B, the access permission corresponding to the supervision domain identifier of Tenant A does not support access to the private page of Tenant B, and the processor can directly intercept the access.

[0046] When Tenant A and B access the public configuration page, they can obtain the corresponding access permissions according to the supervision domain identifiers corresponding to the tenants. Since both Tenant A and B are allowed to access the public page of C and the permission is "Read", the read operation is allowed.

[0047] The resource management method provided by the embodiments of the present invention breaks through the traditional dual-domain limitation of "secure area / non-secure area", supports flexible multi-tenant or multi-security level partitioning, and supports independent access permission control for each supervision domain, refining the control granularity of access management and improving the accuracy of resource management. Moreover, the embodiments of the present invention support the configuration of shared resources for at least two supervision domains, and can achieve controllable cross-domain data exchange on the basis of tenant isolation, which is beneficial to improving resource utilization.

[0048] Optionally, in the case of receiving an access request from a first tenant in step 102, determining the first supervision domain corresponding to the first tenant includes: Step S11, in the case of receiving an access request from a first tenant, query the unallocated supervision domain from the supervision domain configuration table; the supervision domain configuration table is used to record the corresponding relationship between the supervision domain and the tenant; Step S12, determine a supervision domain from the unallocated supervision domains as the first supervision domain corresponding to the first tenant; Step S13, update the supervision domain configuration table according to the tenant identifier of the first tenant and the supervision domain identifier of the first supervision domain.

[0049] In an embodiment of the present invention, the supervisor domains corresponding to each tenant can be managed through a supervisor domain configuration table. When a new first tenant accesses, a supervisor domain can be determined from the unallocated supervisor domains as the first supervisor domain corresponding to the first tenant by querying the supervisor domain configuration table, and the tenant identifier of the first tenant and the supervisor domain identifier of the first supervisor domain are updated to the supervisor domain configuration table.

[0050] Among them, the supervisor domain identifier (Supervisor Domain Identifier, SDID) is a unique identifier for each supervisor domain, used to identify the isolation environment. The tenant identifier can be determined according to the unique identity information of the tenant, such as tenant ID, tenant account name, and so on.

[0051] Exemplarily, in a cloud computing environment, a cloud service provider may have multiple customers, and each customer has to run its own application programs, and some also have to run one or more virtual machines of their own. Each cloud service host of the cloud management platform needs to maintain a supervisor domain configuration table. When a customer logs in and uses it, the cloud management platform assigns a supervisor domain and its supervisor domain identifier to him according to the unique identity information of the tenant (such as tenant ID, account name, etc.), and puts the tenant and the supervisor domain identifier into the table. When another customer logs in, the cloud management platform needs to assign the unallocated supervisor domain in the supervisor domain configuration table to him and record it in the table until the supervisor domain identifiers are all assigned, so as to maintain the uniqueness of the supervisor domain identifiers. Generally speaking, it starts to be assigned from 0. For each additional tenant, the supervisor domain identifier is incremented by 1. When a tenant exits, the smallest idle supervisor domain identifier is preferentially assigned.

[0052] If the situation where the SDID has been allotted but there are still new tenants joining occurs, a feasible countermeasure is to perform a hash operation on the specific information of the tenant by using the SHA-256 algorithm to generate a unique identifier. Then, the tenant identifier obtained by this hash operation is combined with the SDID for use. In the actual use process, first match the hash identifier of the tenant, and then match the SDID. Only when both match successfully will the corresponding access permission be read, and access control will be performed based on the read access permission. If either the hash identifier of the tenant or the SDID does not match, this access can be directly intercepted.

[0053] After allocating the supervisor domain for the tenant, the access permissions of the first tenant to various memory resources corresponding to the first supervisor domain can be configured.

[0054] Modern operating systems adopt a paged memory management mechanism, which divides the address space into multiple pages in units of "pages". The default page size is 4K, but large pages of 2M, 1G, or 512G can also be selected. Therefore, the RISC-V memory protection table can choose to divide memory resources in units of "pages" of 4K, 2M, 1G, or 512G. Different supervisor domains can have different page allocations.

[0055] In addition, within the same supervisor domain, through virtual machine technology and by means of memory isolation based on page tables, further permission-based isolation between different components or tasks can be achieved. For example, different access permissions can be configured for different pages within the same supervisor domain. For instance, the code segment can be configured to be executable but not writable, and the data segment can be configured to be writable but not executable.

[0056] Optionally, configuring the access permission of the first tenant to the memory resources corresponding to the first supervisor domain in step 102 includes: Step S21: Determine the table entries corresponding to each page of the first supervisor domain in the memory protection table, determine these table entries as leaf nodes, and determine the page directory entries corresponding to these table entries as intermediate nodes; Step S22: Determine the first base address corresponding to the intermediate node according to the address space corresponding to the intermediate node, and determine this first base address as the first address; Step S23: Determine the second base address corresponding to the leaf node according to the address space corresponding to the leaf node, and determine this second base address as the second address; Step S24: Write the second address into the intermediate node, and configure the access permission of the first tenant to each page corresponding to the first supervisor domain in the leaf node.

[0057] In the embodiment of the present invention, the access permissions corresponding to each supervisor domain can be recorded through a multi-level page table. Exemplarily, after allocating the first supervisor domain to the first tenant, the access permissions of the first tenant to each page corresponding to the first supervisor domain can be written into the memory protection table. Specifically, the table entries used to store access permissions are denoted as leaf nodes, the base address corresponding to the leaf node is written into the intermediate node, and the base address of the intermediate node is written into the control status register. When querying the access permission, first jump to the corresponding intermediate node based on the first address (the first base address) stored in the control status register, read the base address of the leaf node from the intermediate node, that is, the second address (the second base address), and jump to the corresponding leaf node according to the second address to read the access permission.

[0058] Assume the level is one. If the physical address for which permission needs to be queried is 0x123 and the base address is 0x10000000, then the physical address of the corresponding table entry with that permission can be obtained by adding the base address and the offset, i.e., 0x10000123. Then the permission for the address 0x123 can be read from 0x10000123.

[0059] In the case of a multi-level page table, one conversion may not be sufficient and multiple conversions are required. At this time, what is stored inside the table entry is not the permission, but the base address of the next-level page table. In this way, it is possible to gradually navigate from the base address to the leaf node that finally stores the permission information.

[0060] For intermediate nodes, in addition to storing the base address of the next-level page table (leaf node), a node flag can also be created to indicate whether the node is an intermediate node or a leaf node. For leaf nodes, in addition to storing the access permission, a corresponding flag can also be set to indicate that the node is a leaf node.

[0061] As an example, the table entry corresponding to the intermediate node in the memory protection table can be:

[0062] The table entry corresponding to the leaf node in the memory protection table can be:

[0063] Among them, 16 three-bit permissions are used to indicate the three permissions of read, write, and execute. Specifically, they can be:

[0064] During the operation of the processor, the memory resources can be dynamically managed. Specifically, at least one of the size and permission of the exclusive memory and shared memory of each supervision domain can be changed during operation. Specifically, the memory protection table can be managed by the root domain security manager, and the tenant can apply to the root domain security manager to change the content of the memory protection table to change the size and access permission of the exclusive memory or shared memory.

[0065] Optionally, configuring the access permission of the first tenant for the memory resources corresponding to the first supervision domain in step 102 includes: Step S31: Determine the exclusive resources and shared resources corresponding to the first supervision domain; Step S32: Configure the first access permission of the first tenant for the exclusive resources according to the resource isolation requirements; Step S33: Configure the second access permission of the first tenant for the shared resources according to the resource sharing requirements.

[0066] It can be understood that the allocation of permissions is related to the exclusive memory and shared memory of the supervision domain. In the embodiments of the present invention, the first access permission of the first tenant to the exclusive resources corresponding to the first supervision domain can be configured according to the resource isolation requirement, and the second access permission of the first tenant to the shared resources of the first supervision domain can be configured according to the resource sharing requirement.

[0067] Exemplarily, for the exclusive resources of supervision domain A, only supervision domain A has read or higher permissions, and the memory permissions of the remaining supervision domains are all non-readable, non-writable, and non-executable. For the shared resources, in addition to supervision domain A, supervision domain B can also have readable permissions.

[0068] Optionally, the method further includes: Step S41: When receiving the access request of the first tenant, determine the supervision domain identifier corresponding to the first tenant; Step S42: Query the memory protection table according to the supervision domain identifier to determine the access permission of the first tenant to the target address carried in the access request; Step S43: Perform access control on the access request according to the access permission.

[0069] When receiving the access request of the first tenant, the access permission of the first tenant can be obtained by querying the memory protection table, and access control is performed according to the access permission.

[0070] Exemplarily, assume that the target memory is shared memory and is only readable for supervision domain A and readable and writable for supervision domain B. When supervision domain B initiates a write operation on the target memory, it is necessary to compare the permission of this memory address in the memory protection table. When it is read that the permission is readable and writable, the operation is allowed, and supervision domain B can write to this memory. When supervision domain A initiates a write operation on the target memory, it is read that the permission of this memory address in the memory protection table is only readable, so the write operation of supervision domain A will be blocked.

[0071] Optionally, step S42 of querying the memory protection table according to the supervision domain identifier to determine the access permission of the first tenant to the target address carried in the access request includes: Sub-step S421: Divide the memory resources into a first address segment, a second address segment, and a third address segment, and divide the cache into a first cache, a second cache, and a third cache; wherein, the first cache is used to store the intermediate nodes corresponding to the first address segment, the second cache is used to store the intermediate nodes corresponding to the second address segment, and the third cache is used to store the leaf nodes corresponding to the third address segment; Sub-step S422: Access the third cache according to the target address carried in the access request; Sub-step S423: When the access request hits the third cache, read the access permission from the leaf node corresponding to the target address; Sub-step S424: When the access request misses the third cache, access the first cache and the second cache respectively according to the target address; Sub-step S425: When the first cache hits or the second cache hits, write the base address stored in the intermediate node corresponding to the target address into the miss status register, so that the processor reads the access permission from the memory according to the base address stored in the miss status register; Sub-step S426: When both the first cache and the second cache miss, write the first address in the control status register into the miss status register, so that the processor reads the access permission from the memory according to the first address stored in the miss status register.

[0072] It should be noted that the first address segment, the second address segment, and the third address segment can all store leaf nodes. The embodiment of the present invention introduces a cache to improve the search rate of access permissions. Specifically, if there are caches numbered from 1 to n, then the memory resources need to be divided into address segments 1 to n + offset. Suppose the memory resources are divided into 3 address segments, that is, the first address segment, the second address segment, and the third address segment. The base address of the second address segment is obtained by looking up a table after combining the first base address stored in the first address segment and the control status register. The base address of the third address segment is obtained by looking up a table with the second address segment and the base address of the second address segment. The leaf node is found by the third address segment and the base address of the third address segment, and then the access permission corresponding to the query address in the leaf node is selected by offset.

[0073] Refer to Figure 2 , which shows a schematic diagram of a permission search process without hardware acceleration. As Figure 2 shown, add the base address of the control status register and the high-order address segment to get the address of the highest-level node, and then read the node content from the memory. If the table entry is an intermediate node, add the next-level base address in the intermediate node and the next-level address segment to continue searching for the next-level node. If the table entry is a leaf node, use the next-level address segment for chip selection to obtain the access permission of the query address.

[0074] Refer to Figure 3 , which shows a schematic diagram of a permission search flow without hardware acceleration. As Figure 3As shown, after receiving a memory operation request, first read the base address in the control status register, combine the base address with the physical address segment of the memory to be operated (the target address carried in the access request) to generate a node address, and then access the memory based on the node address to read the node content and determine whether it is a leaf node. If it is not a leaf node, that is, the node is an intermediate node, set the node content (the base address stored in the node) as the new base address, and recombine the physical address segment to generate a node address. If it is a leaf node, select the three-bit permission stored in the leaf node corresponding to the address using the physical address, and determine whether the memory operation is allowed based on the permission. If the permission allows the memory operation, perform the corresponding operation; if the operation is prohibited, intercept it.

[0075] Since the data marking the permission attribute is stored in the physical memory, each time the load accesses the memory resources, it is necessary to search for the security attribute in the corresponding address space according to the physical address. Reading data directly from the memory space will increase the latency of memory access, resulting in a significant drop in performance.

[0076] In the embodiment of the present invention, the memory resources (physical addresses) can be divided into multiple address segments, and a cache is introduced for hardware acceleration to shorten the search latency of access permissions. Specifically, the cache in the embodiment of the present invention is divided into a first cache (first-stage cache), a second cache (second-stage cache), and a third cache; wherein, the first cache is used to store the intermediate nodes corresponding to the first address segment, the second cache is used to store the intermediate nodes corresponding to the second address segment, and the third cache is used to store the leaf nodes corresponding to the third address segment. Further, the third cache can also be divided into a small-page cache and a large-page cache, where the small-page cache is used to store the leaf nodes of 4k pages, and the large-page cache is used to store the leaf nodes of 2M1G or 512G.

[0077] Refer to Figure 4 , which shows a schematic diagram of a multi-parallel cache search method provided by the embodiment of the present invention. As Figure 4 shown, in the case of receiving an access request, first query the third cache (small-page cache and large-page cache). If the small-page or large-page cache hits, that is, there is a leaf node corresponding to the target address (physical address) carried in the access request in the small-page or large-page cache, directly send the hit leaf node, select the access permission stored in the leaf node corresponding to the address using the target address, and perform access control based on the access permission.

[0078] If the small page or large page cache misses, that is, the leaf node corresponding to the target address (physical address) carried in the access request does not exist in the small page or large page cache, the first cache (phase-one cache) and the second cache (phase-two cache) can be further queried. If at least one of the first cache and the second cache hits, the hit cache content is sent to the miss status handling register as the base address. If both the first cache and the second cache miss, the base address recorded in the control status register is used, and the base address in the control status register is sent to the miss status register.

[0079] The miss status handling register (MSHR) is used to specifically record the information of cache misses, so that the cache can continue to respond to other memory access requests without being blocked. In addition, when multiple requests access the same page table, the miss status handling register can merge these requests into one entry. This can avoid sending duplicate requests to the memory and reduce the memory load. The miss status handling register also records the status information of each unfinished transaction, enabling the processor to effectively manage the cache miss status.

[0080] Refer to Figure 5 , which shows a schematic diagram of privilege lookup with hardware acceleration provided by an embodiment of the present invention. The specific lookup process is as Figure 6 shown. Refer to Figure 6 , in an embodiment of the present invention, when a memory operation request, such as an access request, is received, first query whether the request result is in the cache. For the cache query method, reference can be made to Figure 4 . If it is in the cache, directly use the physical address carried in the memory operation request, such as the target address carried in the access request, to select the three-bit privilege stored in the leaf node corresponding to this address, and determine whether the memory operation is allowed based on the privilege. If the privilege allows the memory operation, execute the corresponding operation. If the operation is prohibited, intercept it.

[0081] If it is not in the cache, read the base address in the control status register, combine the base address with the physical address segment of the memory to be operated (such as the target address carried in the access request) to generate a node address. Then, based on the node address, access the memory to read the node content and determine whether it is a leaf node. If it is not a leaf node, that is, the node is an intermediate node, set the node content (the base address stored in the node) as the new base address, and combine it with the physical address segment to regenerate the node address. If it is a leaf node, use the physical address to select the three-bit privilege stored in the leaf node corresponding to this address, and determine whether the memory operation is allowed based on the privilege.

[0082] By Figure 5 and Figure 6It can be seen that when cache hardware acceleration is adopted, when looking up permissions, first look up in the cache. If the cache is hit, directly read the corresponding access permission from the cache. If the cache is not hit, then access the memory and backfill the cache.

[0083] Due to the temporal and spatial locality characteristics of the program, the hit rate of the cache is extremely high, and the access latency of the cache is much smaller than that of accessing memory, which is beneficial to improving the access rate.

[0084] In addition, the information in the cache needs to be synchronized with the change when the content of the memory protection table changes. Although the cache can be directly cleared when a change occurs, doing so will cause the performance of the cache to drop severely when the memory protection table changes frequently, because frequent accesses to memory are required due to the internal data being cleared. The present invention can clear only the changed items in the cache according to the physical address and the corresponding supervisor domain identifier where the content of the memory protection table changes, while retaining the remaining items, minimizing the impact of cache refreshing on performance.

[0085] Moreover, if the cache only stores leaf nodes, it will lead to a long process of looking up the table when there is a miss. The present invention has multiple parallel caches. In addition to being responsible for storing leaf nodes, there is also a dedicated cache for storing intermediate nodes at all levels, thereby reducing the number of memory accesses and accelerating the process of looking up the memory protection table.

[0086] Optionally, the processor includes a multi-core processor, and each processor core corresponds to a control status register; the writing of the supervisor domain identifier and the first address of the first supervisor domain into the control status register in step 103 includes: Step S51, determine the first processor core corresponding to the first supervisor domain; Step S52, write the supervisor domain identifier of the first supervisor domain and the first address into the control status register corresponding to the first processor core.

[0087] In the embodiment of the present invention, the supervisor domain identifier and the base address in which the processor hardware thread is located are represented by a specific control status register. By setting the control status register to the value corresponding to the supervisor domain, switching between two supervisor domains can be realized, thereby realizing serial processing of multiple supervisor domain tasks. The status register only allows write operations in the highest privilege mode defined by RISC-V. Each hardware thread has its own independent control status register, which is used to control and manage the supervisor domain where the current hardware thread is located. A processor with multiple hardware threads can thus simultaneously and parallelly process tasks in multiple supervisor domains.

[0088] In the embodiments of the present invention, the Root Domain Security Manager (RDSM) can be used to configure and manage control status registers, memory protection tables, etc., so as to achieve the switching of supervision domains and the dynamic management of permissions.

[0089] It should be noted that a single CPU core / thread (referred to as Hart in riscv) shares a status register because a single core can only execute a program under one supervision domain in a time slice. The RDSM will write the next supervision domain to be executed after the end of this time slice to achieve the switching between supervision domains. Of course, if it is a multi-core CPU, there will be multiple control status registers, and each processor core corresponds to a control status register, so as to be able to execute instructions from multiple supervision domains simultaneously.

[0090] In the case of multi-core and multi-thread, different cores / threads may execute instructions of different supervision domains simultaneously. At this time, the shared scheduling strategy of the same resource by multiple supervision domains depends on the CPU structure, and methods such as cache coherence protocol, lock mechanism, time-sharing writing, etc. can be used to achieve it.

[0091] When the core switches the supervision domain, the CPU will ensure that all instructions of the previous supervision domain are executed before switching, avoiding conflicts of shared resources.

[0092] In summary, the embodiments of the present invention provide a resource management method, which can divide the memory space into at least one logically isolated area; each area belongs to a unique supervision domain; when receiving an access request from a first tenant, determine the first supervision domain corresponding to the first tenant, and configure the access permission of the first tenant for the memory resources corresponding to the first supervision domain; write the supervision domain identifier and the first address of the first supervision domain into the control status register, so that the processor can execute the program corresponding to the first tenant within the first supervision domain according to the access permission. The embodiments of the present invention can break through the traditional dual-domain limitation of "secure area / non-secure area", support flexible multi-tenant or multi-security level division, and support independent access permission control for each supervision domain, refine the control granularity of access management, and improve the resource management accuracy.

[0093] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequence, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0094] Device embodiments Reference Figure 7 , a structural block diagram of a resource management device according to the present invention is shown. The device may specifically include: The isolation module 201 is configured to divide the memory space into at least one logically isolated area; each area belongs to a unique supervision domain; The configuration module 202 is configured to determine the first supervision domain corresponding to the first tenant and configure the access permission of the first tenant to the memory resources corresponding to the first supervision domain when receiving an access request from the first tenant; The writing module 203 is configured to write the supervision domain identifier and the first address of the first supervision domain into the control status register, so that the processor executes the program corresponding to the first tenant within the first supervision domain according to the access permission; Wherein, the first address is used to indicate the storage address of the access permission.

[0095] Optionally, the configuration module includes: The first determination sub-module is configured to determine the entries corresponding to each page of the first supervision domain in the memory protection table, determine the entries as leaf nodes, and determine the page directory entries corresponding to the entries as intermediate nodes; The second determination sub-module is configured to determine the first base address corresponding to the intermediate node according to the address space corresponding to the intermediate node, and determine the first base address as the first address; The third determination sub-module is configured to determine the second base address corresponding to the leaf node according to the address space corresponding to the leaf node, and determine the second base address as the second address; The first configuration sub-module is configured to write the second address into the intermediate node and configure the access permission of the first tenant to each page corresponding to the first supervision domain in the leaf node.

[0096] Optionally, the device further includes: The identifier determination module is configured to determine the supervision domain identifier corresponding to the first tenant when receiving the access request of the first tenant; The query module is configured to query the memory protection table according to the supervision domain identifier to determine the access permission of the first tenant to the target address carried in the access request; The access control module is configured to perform access control on the access request according to the access permission.

[0097] Optionally, the query module includes: A resource partitioning sub-module, which is used to partition the memory resources into a first address segment, a second address segment, and a third address segment, and partition the cache into a first cache, a second cache, and a third cache; wherein, the first cache is used to store intermediate nodes corresponding to the first address segment, the second cache is used to store intermediate nodes corresponding to the second address segment, and the third cache is used to store leaf nodes corresponding to the third address segment; A first query sub-module, which is used to access the third cache according to the target address carried in the access request; A permission reading sub-module, which is used to read the access permission from the leaf node corresponding to the target address when the access request hits the third cache; A second query sub-module, which is used to access the first cache and the second cache respectively according to the target address when the access request does not hit the third cache; A first writing sub-module, which is used to write the base address stored in the intermediate node corresponding to the target address into the missing status register when the first cache hits or the second cache hits, so that the processor reads the access permission from the memory according to the base address stored in the missing status register; A second writing sub-module, which is used to write the first address in the control status register into the missing status register when both the first cache and the second cache do not hit, so that the processor reads the access permission from the memory according to the first address stored in the missing status register.

[0098] Optionally, the configuration module includes: A supervision domain query sub-module, which is used to query an unallocated supervision domain from the supervision domain configuration table when receiving an access request from a first tenant; the supervision domain configuration table is used to record the corresponding relationship between the supervision domain and the tenant; A supervision domain allocation sub-module, which is used to determine a supervision domain from the unallocated supervision domains as the first supervision domain corresponding to the first tenant; An update sub-module, which is used to update the supervision domain configuration table according to the tenant identifier of the first tenant and the supervision domain identifier of the first supervision domain.

[0099] Optionally, the configuration module includes: A resource determination sub-module, which is used to determine the exclusive resources and shared resources corresponding to the first supervision domain; A second configuration sub-module, which is used to configure the first access permission of the first tenant to the exclusive resources according to the resource isolation requirement; A third configuration sub-module, which is used to configure the second access permission of the first tenant to the shared resources according to the resource sharing requirement.

[0100] Optionally, the processor includes a multi-core processor, and each processor core corresponds to a control status register; the writing module includes: A third determination sub-module, configured to determine a first processor core corresponding to the first supervision domain; A third writing sub-module, configured to write the supervision domain identifier of the first supervision domain and the first address into the control status register corresponding to the first processor core.

[0101] An embodiment of the present invention provides a resource management device, which can divide a memory space into at least one logically isolated area; each area belongs to a unique supervision domain; when an access request of a first tenant is received, determine a first supervision domain corresponding to the first tenant, and configure access rights of the first tenant to the memory resources corresponding to the first supervision domain; write the supervision domain identifier of the first supervision domain and a first address into a control status register, so that the processor executes a program corresponding to the first tenant within the first supervision domain according to the access rights. The embodiment of the present invention can break through the traditional dual-domain limitation of "secure area / non-secure area", support flexible multi-tenant or multi-security-level division, and support independent access right control for each supervision domain, refine the control granularity of access management, and improve the resource management accuracy.

[0102] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the related parts, refer to the partial description of the method embodiment.

[0103] Each embodiment in this specification is described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, refer to each other.

[0104] Regarding the processor in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.

[0105] Refer to Figure 8 , which is a structural block diagram of an electronic device provided by an embodiment of the present invention. As Figure 8 shown, the electronic device includes: a processor, a memory, a communication interface, and a communication bus. The processor, the memory, and the communication interface complete mutual communication through the communication bus; the memory is used to store executable instructions, and the executable instructions cause the processor to execute the resource management method of the foregoing embodiments.

[0106] The processor may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable devices, transistor logic devices, hardware components, or any combination thereof. The processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0107] The communication bus may include a path for transmitting information between the memory and the communication interface. The communication bus may be a PCI (Peripheral Component Interconnect) bus, an EISA (Extended Industry Standard Architecture) bus, or the like. The communication bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 only one line is shown in the figure, but it does not mean that there is only one bus or one type of bus.

[0108] The memory may be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory), or other type of dynamic storage device that can store information and instructions. It may also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), magnetic tape, a floppy disk, and optical data storage devices, etc.

[0109] The embodiment of the present invention also provides a non-transitory computer-readable storage medium. When the instructions in the storage medium are executed by the processor of an electronic device (server or terminal), the processor can execute Figure 1 the resource management method shown.

[0110] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other.

[0111] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, an apparatus, or a computer program product. Therefore, the embodiments of the present invention can take the form of an all-hardware embodiment, an all-software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0112] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0113] These computer program instructions can also be stored in a computer-readable memory that can guide the computer or other programmable data processing terminal devices to work in a predictive manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0114] These computer program instructions can also be loaded onto the computer or other programmable data processing terminal devices, so that a series of operation steps are executed on the computer or other programmable terminal devices to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal devices provide steps for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0115] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concept. Therefore, the appended claims are intended to be interpreted to include the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0116] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising said element.

[0117] The above has introduced in detail a resource management method, apparatus, electronic device and readable storage medium provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A resource management method, characterized in that, Applied to a processor, the method includes: Dividing a memory space into at least one logically isolated region; each region belongs to a unique supervision domain; In the case of receiving an access request from a first tenant, determining the first supervision domain corresponding to the first tenant, and configuring the access right of the first tenant to the memory resources corresponding to the first supervision domain; Writing the supervision domain identifier and the first address of the first supervision domain into a control status register for the processor to execute the program corresponding to the first tenant within the first supervision domain according to the access right; Wherein, the first address is used to indicate the storage address of the access right.

2. The method according to claim 1, wherein The configuring the access right of the first tenant to the memory resources corresponding to the first supervision domain includes: Determining the entries corresponding to each page of the first supervision domain in a memory protection table, determining the entries as leaf nodes, and determining the page directory entries corresponding to the entries as intermediate nodes; According to the address space corresponding to the intermediate node, determining the first base address corresponding to the intermediate node, and determining the first base address as the first address; According to the address space corresponding to the leaf node, determining the second base address corresponding to the leaf node, and determining the second base address as the second address; Writing the second address into the intermediate node, and configuring the access right of the first tenant to each page corresponding to the first supervision domain in the leaf node.

3. The method according to claim 2, characterized in that, The method further includes: In the case of receiving an access request from the first tenant, determining the supervision domain identifier corresponding to the first tenant; Querying the memory protection table according to the supervision domain identifier to determine the access right of the first tenant to the target address carried in the access request; Performing access control on the access request according to the access right.

4. The method according to claim 3, wherein The querying the memory protection table according to the supervision domain identifier to determine the access right of the first tenant to the target address carried in the access request includes: Dividing the memory resources into a first address segment, a second address segment, and a third address segment, and dividing the cache into a first cache, a second cache, and a third cache; wherein, the first cache is used to store the intermediate nodes corresponding to the first address segment, the second cache is used to store the intermediate nodes corresponding to the second address segment, and the third cache is used to store the leaf nodes corresponding to the third address segment; Accessing the third cache according to the target address carried in the access request; In the case that the access request hits the third cache, reading the access right from the leaf node corresponding to the target address; In the case that the access request does not hit the third cache, accessing the first cache and the second cache respectively according to the target address; In the case that the first cache hits or the second cache hits, writing the base address stored in the intermediate node corresponding to the target address into a miss status register, so that the processor reads the access right from the memory according to the base address stored in the miss status register; In the case that neither the first cache nor the second cache hits, write the first address in the control status register into the miss status register, so that the processor reads the access right from the memory according to the first address stored in the miss status register.

5. The method according to claim 1, characterized in that, The determining the first supervision domain corresponding to the first tenant in the case of receiving an access request from the first tenant includes: In the case of receiving an access request from the first tenant, query the unallocated supervision domain from the supervision domain configuration table; the supervision domain configuration table is used to record the corresponding relationship between the supervision domain and the tenant; Determine one supervision domain from the unallocated supervision domains as the first supervision domain corresponding to the first tenant; Update the supervision domain configuration table according to the tenant identifier of the first tenant and the supervision domain identifier of the first supervision domain.

6. The method according to claim 1, characterized in that, The configuring the access right of the first tenant to the memory resources corresponding to the first supervision domain includes: Determine the exclusive resources and shared resources corresponding to the first supervision domain; Configure the first access right of the first tenant to the exclusive resources according to the resource isolation requirement; Configure the second access right of the first tenant to the shared resources according to the resource sharing requirement.

7. The method according to claim 1, characterized in that, The processor includes a multi-core processor, and each processor core corresponds to a control status register; the writing the supervision domain identifier and the first address of the first supervision domain into the control status register includes: Determine the first processor core corresponding to the first supervision domain; Write the supervision domain identifier of the first supervision domain and the first address into the control status register corresponding to the first processor core.

8. A resource management device, characterized in that, Applied to a processor, the device includes: An isolation module, configured to divide the memory space into at least one logically isolated area; each area belongs to a unique supervision domain; A configuration module, configured to determine the first supervision domain corresponding to the first tenant and configure the access right of the first tenant to the memory resources corresponding to the first supervision domain in the case of receiving an access request from the first tenant; A writing module, configured to write the supervision domain identifier and the first address of the first supervision domain into the control status register for the processor to execute the program corresponding to the first tenant within the first supervision domain according to the access right; Wherein, the first address is used to indicate the storage address of the access right.

9. An electronic device, characterized in that, The electronic device includes a processor, a memory, a communication interface, and a communication bus. The processor, the memory, and the communication interface complete communication with each other through the communication bus; the memory is used to store executable instructions, and the executable instructions cause the processor to execute the resource management method according to any one of claims 1 to 7.

10. A readable storage medium, characterized in that, When the instructions in the readable storage medium are executed by the processor of the electronic device, the processor is enabled to execute the resource management method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Memory access and allocation method, memory controller and system

    CN110554911A

  • Memory access control method and device

    CN118235122A

  • Multi-core processor exclusive access control method, multi-core processor and electronic equipment

    CN118656265A

  • Resource control method and device

    CN119127384A

  • Distributed multi-tenant data security isolation system and method

    CN119402233A