Autonomous resource tracking for domain isolation
By managing resource tracking tables through domain control isolation units, the challenges of data security management in complex computing environments are addressed, enabling flexible access control and autonomous resource tracking, thereby enhancing system security and scalability.
Patent Information
- Application Number
- CN202480036591.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-18
- Filing Date
- 2024-04-29
- Publication Date
- 2025-12-26
Smart Images

Figure CN121219703A_ABST
Abstract
Description
Cross-reference to related applications
[0001] This application claims priority to U.S. Patent Application No. 18 / 544,153, filed December 18, 2023, entitled “SELF-SOVEREIGN RESOURCE TRACKING FOR DOMAIN ISOLATION,” and U.S. Provisional Patent Application No. 63 / 471,942, filed June 8, 2023, entitled “SELF-PROTECTING RESOURCE TRACKING FOR DOMAIN ISOLATION,” the disclosures of which are expressly incorporated herein by reference in their entirety. Technical Field
[0002] This disclosure relates in various aspects to computing devices, and more specifically to autonomous resource tracking for domain isolation. Background Technology
[0003] The landscape of computing environments is rapidly evolving and includes a growing number of stakeholders employing different trust models. These complex relationships can vary significantly based on different product categories, such as servers, compute, mobile, embedded systems, etc. Some stakeholders may have conflicting security requirements. Static isolation of assets in the physical address space is often not scalable and cannot support use cases with large memory footprints. Therefore, managing data security in complex computing environments is challenging. Summary of the Invention
[0004] The present disclosure is set forth in the independent claims. Some aspects of the present disclosure are described in the dependent claims.
[0005] In some aspects of this disclosure, a method for updating a resource tracking table includes receiving a request from an entity to access a first entry in the resource tracking table by a controller unit (e.g., a domain control isolation unit). The first entry corresponds to a first resource of a computing system. The method also includes detecting a first identifier associated with the entity. The method further includes having the controller unit compare the first identifier with first owner information specified in the first entry of the resource tracking table. The method also includes having the controller unit control access from the entity to the first entry based on the comparison.
[0006] Various aspects of this disclosure relate to an apparatus including components for receiving, by a controller unit (e.g., a domain control isolation unit), a request from an entity to access a first entry in a resource tracking table. The first entry corresponds to a first resource of a computing system. The apparatus also includes components for detecting a first identifier associated with the entity. The apparatus further includes components for the controller unit to compare the first identifier with first owner information specified in the first entry of the resource tracking table. The apparatus also includes components for the controller unit to control access from the entity to the first entry based on the comparison.
[0007] In some aspects of this disclosure, a non-transitory computer-readable medium having non-transitory program code recorded thereon is disclosed. The program code is executed by a processor and includes program code for a controller unit to receive a request from an entity to access a first entry in a resource tracking table. The first entry corresponds to a first resource of the computing system. The program code also includes program code for detecting a first identifier associated with the entity. The program code further includes program code for the controller unit to compare the first identifier with first owner information specified in the first entry of the resource tracking table. The program code also includes program code for the controller unit (e.g., a domain control isolation unit) to control access from the entity to the first entry based on this comparison.
[0008] Various aspects of this disclosure relate to an apparatus having at least one memory for storing a resource tracking table. The apparatus also has a controller unit (e.g., a domain control isolation unit) coupled to the at least one memory. The controller unit is configured to receive a request from an entity to access a first entry in the resource tracking table. The first entry corresponds to a first resource of a computing system. The controller unit is also configured to detect a first identifier associated with the entity. Furthermore, the controller unit is configured to compare the first identifier with first owner information specified in the first entry of the resource tracking table. The controller unit is also configured to control access from the entity to the first entry based on this comparison.
[0009] This has provided a broad overview of the features and technical advantages of this disclosure in order to facilitate a better understanding of the following detailed description. Additional features and advantages of this disclosure will be described below. Those skilled in the art will understand that this disclosure can be readily used as the basis for modifying or designing other structures for implementing the same purposes as this disclosure. Those skilled in the art will also recognize that such equivalent constructions do not depart from the teachings of this disclosure as set forth in the appended claims. Novel features considered characteristic of this disclosure, in both their organization and manner of operation, along with further objects and advantages, will be better understood when the following description is considered in conjunction with the accompanying drawings. However, it is to be clearly understood that each drawing is provided for illustrative and descriptive purposes only and is not intended to be a definition of a limitation of this disclosure. Attached Figure Description
[0010] To gain a more complete understanding of this disclosure, reference is now made to the following description in conjunction with the accompanying drawings.
[0011] Figure 1 Example implementations of a host system-on-a-chip (SoC) including a domain control isolation unit according to various aspects of this disclosure are illustrated.
[0012] Figure 2 This illustrates various uses according to this disclosure. Figure 1 A block diagram of an example architecture for autonomous resource tracking of a domain control isolation unit.
[0013] Figure 3 This is a block diagram illustrating a high-level overview of an example software stack according to various aspects of this disclosure.
[0014] Figure 4 This is an example state diagram illustrating the lifecycle of resource ownership according to various aspects of this disclosure.
[0015] Figure 5 This is a flowchart illustrating example processes performed by a computing device, for example, according to various aspects of this disclosure.
[0016] Figure 6 This is a block diagram illustrating an exemplary wireless communication system in which the configurations of this disclosure may be advantageously employed.
[0017] Figure 7 This is a block diagram illustrating a design workstation for circuit, layout, and logic design of components according to various aspects of this disclosure. Detailed Implementation
[0018] The detailed description following, taken in conjunction with the accompanying drawings, is intended as a description of various configurations and not as representing only configurations in which the described concepts can be practiced. To provide a comprehensive understanding of the various concepts, the detailed description includes specific details. However, it will be apparent to those skilled in the art that these concepts can be practiced without these specific details. In some instances, to avoid obscuring such concepts, well-known structures and components are shown in block diagram form.
[0019] As described, the use of the term "and / or" is intended to indicate "inclusive or," and the use of the term "or" is intended to indicate "exclusive or." As described, the term "exemplary" as used throughout the description means "used as an example, instance, or illustration" and is not necessarily to be construed as preferred or advantageous over other exemplary configurations. As described, the term "coupled" as used throughout the description means "directly or indirectly connected via an intermediary connection (e.g., a switch), electrical, mechanical, or otherwise," and is not necessarily limited to physical connections. Furthermore, a connection can result in objects being permanently or releasably connected. Connections can be made via switches. As described, the term "proximity" as used throughout the description means "adjacent, very close, adjacent, or near." As described, the term "on" as used throughout the description means "directly on" in some configurations and "indirectly on" in others.
[0020] A domain refers to a collection of resources within a platform or System-on-a-Chip (SoC) that are under the control of different control mechanisms and isolated from other domains on the same platform. Resources may include, but are not limited to, peripherals, internal or external memory regions (e.g., pages in memory), registers, direct memory access (DMA) channels, or input / output (I / O) ports. Resources can be addressed within the platform using system physical addresses (sPAs) decoded by various interconnect components. A system physical address (sPA) uniquely addresses resources within the system.
[0021] An initiator is a hardware (HW) entity that can issue transactions to system interconnects to access resources. Access to resources can involve reading from or writing to the resource.
[0022] A legitimate use of a resource by an initiator refers to the permission to access a resource in read-only (RO), read-write (RW), or execute-only (XO) mode, such that the permitted use policy (regarding the use of RO, RW, or XO) is specified by the domain "owner". Legitimate use can also include RO, RW, or XO access to resources in a specific domain from another domain (e.g., a sharing policy).
[0023] Domain isolation in computing refers to separating different computing environments or domains to enhance security and prevent unauthorized access or data leakage. Domain isolation involves creating distinct boundaries between resources, such as systems, networks, or applications, to isolate them from each other, for example, for access control or security reasons. Isolation aims to ensure the confidentiality and integrity of private or shared resources within a specific domain.
[0024] In a conventional architecture, there is no explicit separation between resource ownership and resource access control policies (e.g., who can access the resource). Furthermore, there is no central authorizing body for tracking resource ownership. Instead, access control policies and ownership can be enforced by higher-privileged software entities.
[0025] Several conventional approaches aim to create a Trusted Execution Environment (SPA). An SPA is a secure zone within a processor where code and data can be protected against replacement or modification by unauthorized entities. However, trust relationships can be complex and may involve multiple stakeholders with conflicting security needs. For example, content protection, health management, biometric authentication, and other business areas may require higher levels of data security guarantees. Therefore, determining which entities can be trusted to access and modify information within the SPA can be challenging. Furthermore, static or hard isolation in an SPA can hinder availability. For instance, performance may degrade, while memory footprint and power consumption may increase.
[0026] Therefore, to address these and other challenges, aspects of this disclosure relate to autonomous resource tracking for domain isolation. According to various aspects of this disclosure, a scalable technique for creating untrusted execution environments is provided. That is, rather than creating trusted execution environments, aspects of this disclosure provide stakeholders with the ability to minimize trust attainment, focusing instead on resource attributes such as owner identity, sharing policies, and security attributes to be implemented.
[0027] Resource tracking can separate the owner of a resource from the legitimate users or consumers of that resource, where consumption can refer to read-only, read-write, or execution-only access to the resource. It allows the resource owner to specify limits on legitimate consumers or users. In some respects, for example, the owner can temporarily revoke their own access to the resource if they deem it necessary.
[0028] Various aspects of this disclosure provide domain identifier constructions that are immutable to prevent higher-privilege-level attacks on lower-privilege-level users, for example, by impersonating the victim's identifier. Furthermore, the techniques disclosed herein can be scalable to support the concept of a world, which may be analogous to a trusted zone, etc.
[0029] To implement domain boundaries, some have attempted to protect tables to track access to pages, but this may lack the concept of page ownership. Aspects of this disclosure utilize hardware to implement properties of resource tracking tables (rather than higher-privileged software (SW) entities) that can only be modified by the owner.
[0030] Specific aspects of the subject matter described in this disclosure can be implemented to achieve one or more of the following potential advantages. In some examples, the described techniques, such as domain control isolation units for managing access to resource tracking tables, can achieve increased access control capabilities and data security.
[0031] Figure 1 Example implementations of a host system-on-a-chip (SoC) 100, including a domain control isolation unit 150, are illustrated according to various aspects of this disclosure. The host SoC 100 includes processing blocks tailored for specific functions, such as a connectivity block 110. The connectivity block 110 may include fifth-generation (5G) connectivity, fourth-generation LTE (4G LTE) connectivity, Wi-Fi connectivity, Universal Serial Bus (USB) connectivity, and Bluetooth. ® Connectivity, Secure Digital (SD) connectivity, etc.
[0032] In this configuration, the host SoC 100 includes various processing units that support multi-threaded operation. Figure 1 The configuration shown includes a multi-core central processing unit (CPU) 102, a graphics processing unit (GPU) 104, a digital signal processor (DSP) 106, and a neural processing unit (NPU) 108. The host SoC 100 may also include a sensor processor 114, an image signal processor (ISP) 116, a navigation module 120, and a memory 118, which may include a Global Positioning System (GPS). The multi-core CPU 102, GPU 104, DSP 106, NPU 108, and multimedia engine 112 support various functions such as video, audio, graphics, games, artificial intelligence, and networking. Each processor core of the multi-core CPU 102 can be a Reduced Instruction Set Computing (RISC) architecture (such as an Advanced RISC Machine (ARM) and RISC-V (RISC-5)), a microprocessor, or some other type of processor. The NPU 108 may be based on the ARM instruction set or a RISC machine.
[0033] Figure 2 This illustrates various uses according to this disclosure. Figure 1 A block diagram of an example architecture 200 for autonomous resource tracking of the domain control isolation unit 150. (See diagram 200 for details.) Figure 2 As shown, a SoC such as SoC 100 may be adapted to include a hardware block domain control isolation unit 150. The domain control isolation unit 150 may manage a resource trace table 204. The resource trace table 204 may be stored in memory such as dynamic random access memory (DRAM) 202, or in a register file associated with one or more initiators (e.g., CPU 102, GPU 104, or NPU 108).
[0034] Resource tracking table 204 may include entries 206a-206z for resources (e.g., applications) in the system. For example, resources may include memory (e.g., internal memory, etc.). Figure 1 Resources can be addressed by the processor of the computing system (e.g., CPU 102) or external memory regions (e.g., pages in DRAM), registers, direct memory access (DMA) channels, input / output (I / O) ports, peripherals, or other devices that can be addressed by the processor of the computing system (e.g., CPU 102). Each resource can be addressed in the system's physical address space. Each entry 206a-206z in resource trace tables 204 can specify the owner of the resource and a set of attributes associated with the resource. For example, these attributes can include the resource's access control policy (e.g., RO, RW, XO, or shared), encryption information (e.g., encryption key identifiers for encrypted memory), resource attributes, and other resource attributes. Resource trace table 204 can separate the concept of resource ownership from the legally permitted consumers of the corresponding resource. Consumption can refer to access to the resource (e.g., RO, RW, or XO), and the owner of the resource can specify the legal consumers and the types of access permitted.
[0035] Ownership of the resources listed in Resource Tracking Table 204 can be considered self-protected. That is, unlike conventional methods, the resources listed in Resource Tracking Table 204 are not protected by higher-privileged software entities. Instead, ownership of the resources can be enforced by Domain Control Isolation Unit 150 at each agent or initiator attempting to access or modify entries in Resource Tracking Table 204. For example, Resource Tracking Table 204 can be populated at system startup of the computing system including SoC 100, or in the order in which domains are established within the computing system.
[0036] After a resource has been added to resource trace table 204, it can be accessed at that location based on the domain and the system's physical address. Each domain can have a unique domain identifier. In some respects, the domain identifier may include a portion that identifies the privilege level. For example, in one example, a 16-bit domain identifier may include two bits indicating the privilege level in the software stack. Of course, for example, any number of bits can be allocated to identify the privileges or other attributes of each resource, depending on design preferences.
[0037] Domain control isolation unit 150 can check the domain identifier of the entity attempting to access the resource. This check can be performed at the initiator (e.g., CPU 102) used for such access. Domain control isolation unit 150 can use a system physical address to perform a trace table lookup. Domain control isolation unit 150 can check whether the entity is the owner of the resource. For example, domain control isolation unit 150 can receive the domain identifier attempting to access from the initiator. Domain control isolation unit 150 can also read owner information included in a resource trace table entry (e.g., 206a). Domain control isolation unit 150 can then compare the received domain identifier with the owner information in resource trace table 204. If the domain identifier matches the owner information, domain control isolation unit 150 can grant access to the resource. If the domain identifier does not match the owner information, domain control isolation unit 150 can determine whether the access control policy of the resource in resource trace table 204 (including in entry (e.g., 206a)) permits the domain identifier to access. If access is granted, the domain control isolation unit 150 may permit access based on access control policies (e.g., RO, RW, XO, or shared). Otherwise, the domain control isolation unit 150 may deny access to the resource.
[0038] Domain control isolation unit 150 can also control access to or modification of resource tracking table 204. In this case, only the owner of the resource can update the entry (e.g., 206a) for the corresponding resource in resource tracking table 204 used for the computing system. For example, domain control isolation unit 150 may receive domain identifier information from an initiator (e.g., CPU 102) through which it attempts to access the entry (e.g., 206a) in resource tracking table 204. In response, domain control isolation unit 150 may perform a check operation, whereby it compares the domain identifier with the owner information included in the entry (e.g., 206a) of resource tracking table 204. If domain control isolation unit 150 determines that the domain identifier matches the owner information in the entry of resource tracking table 204, it may grant access to the entry (e.g., 206a). For example, domain control isolation unit 150 may allow access to and / or modification of attributes (e.g., access control or encryption keys) in the entry (e.g., 206a) of the corresponding resource.
[0039] On the other hand, if the domain control isolation unit 150 determines that the domain identifier does not match the owner information in the entry (e.g., 206a) of the resource tracking table 204, the domain control isolation unit 150 may refuse access to or update the entry of the resource tracking table 204.
[0040] In some respects, the owner lock bit can provide further security for resource tracking table 204. For example, each entry may include an owner lock bit that, when set, can restrict modifications to attributes (e.g., access control policies) in an entry (e.g., 206a) of resource tracking table 204. For example, domain control isolation unit 150 can check the entry to be accessed (e.g., 206a), and if the owner lock bit is set (e.g., set to 1), updates to attributes (e.g., access control policies) by the owner may be restricted. This can, for example, reduce unintentional attribute modifications. In some respects, the resource owner can also reset the lock bit (e.g., set to zero) to re-enable modifications to attributes in the entry (e.g., 206a).
[0041] In some respects, entries for a specific resource (e.g., 206a-206z) can be stored in a cache memory for that specific resource (e.g., 212a-212z). For example, as... Figure 2 As shown, entries (e.g., 206a-206z) in the resource trace table 204 for CPU 102 can be provided via system interconnect 214 and can be stored in local memory (e.g., cache memory of CPU 102, e.g., memory indicated by double-ended arrows). System interconnect 214 may include (but is not limited to) a system bus coupling domain control isolation unit 150 to each initiator (e.g., 102, 104, 108) and the corresponding local memory (e.g., 212a-212z). Thus, each initiator (e.g., CPU 102, GPU 104, or NPU 108) can implement access control policies for each resource (e.g., pages in memory, registers, or peripherals) by implementing a resource grant check (RGTCHECK) operation.
[0042] In some respects, each initiator (e.g., CPU 102, GPU 104, or NPU 108) can also implement access control policies by performing a trace table lookup for resources to be accessed by consumers. If the owner grants access to an entry (e.g., RO), the access control policies listed in the entry can be checked. For example, the consumer's domain identifier can be compared with a shared access list in the access control policy. If the domain identifier is included in the shared access list, the consumer can be allowed access to the resource. Otherwise, access to the resource can be denied. However, it should be understood that although initiators (e.g., CPU 102, GPU 104, or NPU 108) can be allowed to implement access control policies for resources, the domain control isolation unit 150 continues to impose restrictions on access to and modification of entries in the resource trace table 204 (e.g., 206a-206z).
[0043] Figure 3 This is a block diagram illustrating a high-level overview of an example software stack 300 according to various aspects of this disclosure. (Reference) Figure 3 Example software stack 300 can be divided into multiple domains 302a-302n. These domains 302a-302n can be managed by a root security manager 304. Each domain in 302a-302n can include multiple resources and multiple privilege levels 306a-306z. The root security manager 304 can be the highest privileged entity in the system. That is, the root security manager 304 can be at the highest privilege level 306a (e.g., exception level (EL) 3 or monitoring mode), followed by privilege levels 306b (e.g., EL2 or hypervisor mode) to privilege levels 306z (e.g., EL0 (for applications) or virtual user mode).
[0044] like Figure 3As shown, access control can be maintained across each privilege level (e.g., 306a-306z) and domain (e.g., 302a-302z). However, unlike conventional methods, higher privileged entities and levels may also be subject to access control. That is, higher privilege levels may not be considered trusted environments with permitted access. For example, an entity (e.g., a hypervisor) accessing resources in privilege level 306b may be denied access to resources in privilege level 306c. In another example, an entity in privilege level 306a (e.g., root security manager 304) may be denied access to resources at the lowest privilege level 306z (e.g., EL0). Further access control can be implemented because resources in the same domain (e.g., 302a-302z) and / or privilege level (e.g., 306a-306z) can be subject to access control relative to other resources in the domain / privilege level. For example, in domain 302a, an entity of the first resource (e.g., an application) may be denied access to other resources (e.g., applications) in the same privilege level 306z.
[0045] That is, aspects of this disclosure can enable increased granularity in access control. For example, domain isolation (illustrated by locking elements 308a-308z (one of the locking elements is labeled (308a) for ease of illustration)) can be implemented, for example, between any number of resources within a computing system, regardless of privilege levels. Instead, ownership of each resource can be defined, and access can be controlled individually using a resource tracking table (e.g., 204). Thus, aspects of this disclosure can increase the flexibility of configuring isolation boundaries.
[0046] Figure 4 This is an example resource ownership lifecycle 400 state diagram illustrating various aspects of this disclosure. Reference Figure 4 In state 402, a resource can be initialized to an ownerless state. For example, a resource can be initialized to an ownerless state when the system starts up. In an ownerless state, any domain can update the corresponding entry for the resource in the resource tracking table (e.g., 204) (e.g., 206a). For example, any entity in the system can change the owner field of a resource. For example, an entity can assign a resource to itself or assign a resource to another domain.
[0047] In some respects, the owner and resource attributes of a resource can be initialized to predetermined default settings. For example, an entry for a resource in a resource tracking table (e.g., 204) can be initialized to a "no owner" state (e.g., the owner field in an entry (e.g., 206z) can be set to "no owner").
[0048] In state 404, a resource can be assigned to an owner. In this state, only the assigned owner can be permitted to accept ownership of the resource. If the assigned owner accepts, the owner can modify entries including resource attributes (e.g., access control policies). In state 406, the assigned owner of a resource can reassign ownership to another domain. Therefore, the newly assigned domain can be permitted to access and modify entries in the resource tracking table (e.g., 204). However, in some respects, assignment can be offered on an opt-in basis. That is, the assigned entity (domain) may not become the owner until the entity accepts the assignment. This can reduce attack scenarios and, in some respects, prevent attack scenarios in which resources are silently assigned to a domain without consent and the domain is compromised to use those resources.
[0049] In some respects, an owner can relinquish ownership of a resource by releasing it. Releasing a resource can refer to changing the owner in an entry (e.g., 206a) to "no owner" (returning to state 402). If a current owner exists for the resource, only that owner can mark the resource as owned by "no owner" to release it. Then, if the owner of the resource is listed as "no owner" in an entry (e.g., 206a), any entity can claim ownership of the resource.
[0050] Figure 5 This is a flowchart illustrating an example process 500 performed, for example, by a computing device, according to various aspects of this disclosure. Process 500 may be performed by a controller unit, such as a domain control isolation unit 150. At block 502, example process 500 includes the controller unit receiving a request for a first entry in an entity access resource tracking table. The first entry corresponds to a first resource of the computing system.
[0051] At box 504, process 500 includes detecting a first identifier associated with the entity. For example, as referenced... Figure 2 As described, the domain control isolation unit 150 can receive domain identifier information from an initiator (e.g., CPU 102) through which it attempts to access entries (e.g., 206a) in the resource trace table 204. In some aspects, detection can also be performed by the initiator (e.g., CPU 102).
[0052] At box 506, process 500 includes the controller unit comparing a first identifier with first owner information specified in a first entry of the resource tracking table. For example, as referenced Figure 2As described, in response to a request to access an entry (e.g., 206a) of resource tracking table 204, domain control isolation unit 150 can perform a check operation, wherein domain control isolation unit 150 can compare a domain identifier with owner information included in an entry (e.g., 206a) of resource tracking table 204.
[0053] Domain control isolation unit 150 can then perform a check operation that compares the domain identifier with the owner information included in an entry (e.g., 206a) of resource tracking table 204.
[0054] At box 508, process 500 includes controlling access to the first entry from the entity by the controller unit based on a comparison. For example, as referenced... Figure 2 As described, if the domain control isolation unit 150 determines that the domain identifier matches the owner information in an entry of resource tracking table 204, the domain control isolation unit 150 may grant access to the entry (e.g., 206a). For example, the domain control isolation unit 150 may allow access to and / or modification of attributes (e.g., access control or encryption keys) in the corresponding resource entry (e.g., 206a). On the other hand, if the domain control isolation unit 150 determines that the domain identifier does not match the owner information in an entry of resource tracking table 204 (e.g., 206a), the domain control isolation unit 150 may deny access to or update the entry of resource tracking table 204.
[0055] Figure 6 This is a block diagram illustrating an exemplary wireless communication system 600 in which aspects of this disclosure may be advantageously employed. For illustrative purposes, Figure 6 Three remote units 620, 630, and 650, and two base stations 640 are shown. It should be understood that the wireless communication system may have more remote units and base stations. Remote units 620, 630, and 650 include integrated circuit (IC) devices 625A, 625B, and 625C, which include the disclosed domain control isolation unit. It should be understood that other devices may also include the disclosed domain control isolation unit, such as base stations, switching devices, and network equipment. Figure 6 The forward link signal 680 from base station 640 to remote units 620, 630 and 650 is shown, as well as the reverse link signal 690 from remote units 620, 630 and 650 to base station 640.
[0056] exist Figure 6In this design, remote unit 620 is shown as a mobile phone, remote unit 630 is shown as a portable computer, and remote unit 650 is shown as a fixed-location remote unit in a wireless local loop system. For example, a remote unit may be a mobile phone, a handheld personal communication system (PCS) unit, a portable data unit (such as a personal data assistant), a GPS-enabled device, a navigation device, a set-top box, a music player, a video player, an entertainment unit, a fixed-location data unit (such as a meter reading device), or other devices that store or retrieve data or computer instructions, or combinations thereof. Figure 6 Remote units according to aspects of this disclosure are illustrated, but this disclosure is not limited to these exemplary illustrated units. Aspects of this disclosure may be adapted for use in a variety of devices, including the disclosed domain control isolation unit.
[0057] Figure 7 This is a block diagram illustrating a design workstation for circuit, layout, and logic design of semiconductor components, such as the domain control isolation unit disclosed above. Design workstation 700 includes a hard disk 701 containing operating system software, support files, and design software (such as Cadence or OrCAD). Design workstation 700 also includes a display 702 to facilitate circuit design 710 or radio frequency integrated circuit (RFIC) 712. Storage medium 704 is provided for tangibly storing circuit design 710 or RFIC 712. Circuit design 710 or RFIC 712 can be stored on storage medium 704 in file formats such as GDSII or GERBER. Storage medium 704 can be a CD-ROM, DVD, hard disk, flash memory, or other suitable device. Furthermore, design workstation 700 includes a drive device 703 for accepting input from storage medium 704 or writing output to storage medium 704.
[0058] Data recorded on storage medium 704 may specify logic circuit configurations, pattern data for photolithography masks, or mask pattern data for serial writing tools such as electron beam lithography. The data may also include logic verification data, such as timing diagrams or network circuits associated with logic simulations. Providing data on storage medium 704 facilitates the design of circuit design 710 or RFIC 712 by reducing the number of processes used to design semiconductor wafers.
[0059] Specific implementation examples are included in the following numbered clauses.
[0060] 1. An apparatus comprising: At least one memory, said at least one memory for storing a resource tracking table; and A controller unit, coupled to the at least one memory, is configured to: Receive a request from an entity to access the first entry in the resource tracking table, the first entry corresponding to a first resource of the computing system; Detect the first identifier associated with the entity; The first identifier is compared with the first owner information specified in the first entry of the resource tracking table; and Access to the first entry from the entity is controlled based on the comparison.
[0061] 2. The apparatus according to Clause 1, wherein the entity has a higher privilege level than the privilege level associated with the first resource of the first entry, and the controller unit denies the entity access to the first entry if the first identifier does not match the first owner information.
[0062] 3. The apparatus according to Clause 1 or 2, wherein the controller unit permits the entity to access or modify the first entry if the first identifier matches the first owner information.
[0063] 4. The apparatus according to any one of Clauses 1 to 3, wherein the entity has access privileges to at least a second resource in the same domain as the first resource of the first entry, and the controller unit denies the entity's access.
[0064] 5. The apparatus according to any one of clauses 1 to 4, wherein the entity has a lower privilege level than the privilege level of the first resource of the first entry, and the controller unit permits the entity to update the first entry based on the comparison.
[0065] 6. The apparatus according to any one of clauses 1 to 5, wherein the first entry comprises a set of attributes associated with the first resource, and the controller unit denies access to the first entry corresponding to the first resource if the first identifier does not match the first owner information.
[0066] 7. The apparatus according to any one of Clauses 1 to 6, wherein the set of attributes includes one or more of an access control policy or an encryption key associated with the first resource.
[0067] 8. The apparatus according to any one of Clauses 1 to 7, wherein the access control policy specifies that the entity has access privileges to the first resource, and the controller unit denies access to the first entry if the first identifier does not match the first owner information.
[0068] 9. The apparatus according to any one of clauses 1 to 8, wherein the first entry is stored in a memory file or register file associated with the initiator.
[0069] 10. The apparatus according to any one of clauses 1 to 9, wherein the resource tracking table includes a second entry corresponding to a second resource, and the first owner information of the first entry is different from the second owner information of the second entry.
[0070] 11. A method for updating a resource tracking table, the method comprising: The controller unit receives a request from an entity to access the first entry in the resource tracking table, the first entry corresponding to the first resource of the computing system; Detect the first identifier associated with the entity; The controller unit compares the first identifier with the first owner information specified in the first entry of the resource tracking table; and The controller unit controls access to the first entry from the entity based on the comparison.
[0071] 12. The method according to Clause 11, wherein the entity has a higher privilege level than the privilege level associated with the first resource of the first entry, and the controller unit denies the entity access to the first entry if the first identifier does not match the first owner information.
[0072] 13. The method according to Clause 11 or 12, wherein the controller unit permits the entity to access or modify the first entry if the first identifier matches the first owner information.
[0073] 14. The method according to any one of Clauses 11 to 13, wherein the entity has access privileges to at least a second resource in the same domain as the first resource of the first entry, and the controller unit denies the entity's access.
[0074] 15. The method according to any one of clauses 11 to 14, wherein the entity has a lower privilege level than the privilege level of the first resource of the first entry, and the controller unit permits the entity to update the first entry based on the comparison.
[0075] 16. The method according to any one of Clauses 11 to 15, wherein the first entry comprises a set of attributes associated with the first resource, and the controller unit denies access to the first entry corresponding to the first resource if the first identifier does not match the first owner information.
[0076] 17. The method according to any one of Clauses 11 to 16, wherein the set of attributes includes one or more of an access control policy or an encryption key associated with the first resource.
[0077] 18. The method according to any one of Clauses 11 to 17, wherein the access control policy specifies that the entity has access privileges to the first resource, and the controller unit denies access to the first entry if the first identifier does not match the first owner information.
[0078] 19. The method according to any one of Clauses 11 to 18, wherein the first entry is stored in a memory file or register file associated with the initiator.
[0079] 20. The method according to any one of Clauses 11 to 19, wherein the resource tracking table includes a second entry corresponding to a second resource, and the first owner information of the first entry is different from the second owner information of the second entry.
[0080] 21. A non-transitory computer-readable medium having program code recorded thereon, the program code being executed by a processor and comprising: Program code for receiving a request from the controller unit for an entity to access a resource tracking table for a first entry, the first entry corresponding to a first resource of the computing system; Program code used to detect the first identifier associated with the entity; Program code for the controller unit to compare the first identifier with the first owner information specified in the first entry of the resource tracking table; and Program code for controlling access to the first entry from the entity by the controller unit based on the comparison.
[0081] 22. The non-transitory computer-readable medium according to Clause 21, wherein the entity has a higher privilege level than the privilege level associated with the first resource of the first entry, and the controller unit denies the entity access to the first entry if the first identifier does not match the first owner information.
[0082] 23. A non-transitory computer-readable medium as described in Clause 21 or 22, wherein the controller unit permits the entity to access or modify the first entry if the first identifier matches the first owner information.
[0083] 24. A non-transitory computer-readable medium according to any one of clauses 21 to 23, wherein the entity has access privileges to at least a second resource in the same domain as the first resource of the first entry, and the controller unit denies access to the entity.
[0084] 25. A non-transitory computer-readable medium according to any one of clauses 21 to 24, wherein the entity has a lower privilege level than the privilege level of the first resource of the first entry, and the controller unit permits the entity to update the first entry based on the comparison.
[0085] 26. A non-transitory computer-readable medium according to any one of clauses 21 to 25, wherein the first entry comprises a set of attributes associated with the first resource, and the controller unit denies access to the first entry corresponding to the first resource if the first identifier does not match the first owner information.
[0086] 27. A nontransitory computer-readable medium according to any one of Clauses 21 to 26, wherein the set of attributes includes one or more of an access control policy or an encryption key associated with the first resource.
[0087] 28. A non-transitory computer-readable medium according to any one of clauses 21 to 27, wherein the access control policy specifies that the entity has privileged access to the first resource, and the controller unit denies access to the first entry if the first identifier does not match the first owner information.
[0088] 29. An apparatus comprising: A component for receiving a request from the controller unit for an entity to access a first entry in a resource tracking table, the first entry corresponding to a first resource of the computing system; Components used to detect a first identifier associated with the entity; A component for comparing the first identifier with the first owner information specified in the first entry of the resource tracking table by the controller unit; and A component for controlling access to the first entry from the entity by the controller unit based on the comparison.
[0089] 30. The apparatus according to Clause 29, wherein if the first identifier does not match the first owner information, the control component denies the entity access to the first entry.
[0090] For specific firmware and / or software implementations, these methodologies can be implemented using modules (e.g., procedures, functions, etc.) that perform the described functions. Machine-readable media that tangibly embody instructions can be used to implement the described methodologies. For example, software code can be stored in memory and executed by a processor unit. Memory can be implemented within or outside the processor unit. As used, the term "memory" refers to any type of long-term, short-term, volatile, non-volatile, or other memory, and is not limited to a particular type or quantity of memory, or the type of medium on which memory is stored.
[0091] If implemented in firmware and / or software, the functionality may be stored as one or more instructions or code on a computer-readable medium. Examples include computer-readable media encoding data structures and computer-readable media encoding computer programs. Computer-readable media include physical computer storage media. Storage media can be any available medium that a computer can access. By way of example and not limitation, such computer-readable media may include random access memory (RAM), read-only memory (ROM), electrically erasable read-only memory (EEPROM), compressed optical disc read-only memory (CD-ROM) or other optical disc storage, disk storage or other magnetic storage devices, or other media that may be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer. As used, disks and optical discs include: compressed optical discs (CD), laser discs, optical discs, digital versatile discs (DVD), floppy disks, and Blu-ray discs. ® Optical discs, where magnetic disks typically reproduce data magnetically, utilize lasers to optically reproduce data. Combinations of these should also be included within the scope of computer-readable media.
[0092] In addition to being stored on a computer-readable medium, instructions and / or data may also be provided as signals included on a transmission medium in a communication apparatus. For example, a communication apparatus may include a transceiver having signals indicating instructions and data. These instructions and data are configured to cause one or more processors to perform the functions outlined in the claims.
[0093] Although this disclosure and its advantages have been described in detail, it should be understood that various changes, substitutions, and modifications can be made without departing from the technology of this disclosure as defined in the appended claims. For example, relational terms such as "above" and "below" are used for substrates or electronic devices. Of course, if the substrate or electronic device is inverted, above becomes below, and vice versa. Additionally, if it is laterally oriented, above and below may refer to the sides of the substrate or electronic device. Furthermore, the scope of this disclosure is not intended to be limited to the specific configurations of the processes, machines, manufactures, material compositions, components, methods, and steps described in the specification. As will be readily understood by those skilled in the art from the content of this disclosure, processes, machines, manufactures, material compositions, components, methods, or steps that currently exist or will be developed later can be utilized to perform substantially the same function or achieve substantially the same result as the corresponding configuration described. Therefore, the appended claims are intended to include such processes, machines, manufactures, material compositions, components, methods, or steps within their scope.
[0094] Those skilled in the art will further understand that the various exemplary logic blocks, modules, circuits, and algorithm steps described in connection with this disclosure can be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability between hardware and software, various exemplary components, blocks, modules, circuits, and steps have been described above in general terms of their functionality. Whether this functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the system as a whole. Those skilled in the art may implement the described functionality in different ways for each specific application, but such specific implementation decisions should not be construed as departing from the scope of this disclosure.
[0095] The various exemplary logic blocks, modules, and circuits described in this disclosure may be implemented or executed using a general-purpose processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof, designed to perform the described functions. While the general-purpose processor may be a microprocessor, in alternative embodiments, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration.
[0096] The steps or algorithms of the methods described in this disclosure may be directly embodied in hardware, a software module executed by a processor, or a combination of both. The software module may reside in RAM, flash memory, ROM, erasable programmable read-only memory (EPROM), EEPROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Alternatively, the storage medium may be integral with the processor. The processor and storage medium may reside in an ASIC. The ASIC may reside in a user terminal. Alternatively, the processor and storage medium may reside as discrete components in the user terminal.
[0097] The prior description of this disclosure is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to this disclosure will be apparent to those skilled in the art, and the general principles defined may be applied to other variations without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not intended to be limited to the described examples and designs, but is accorded the widest scope consistent with the disclosed principles and novel features.
Claims
1. An apparatus comprising: At least one memory, the at least one memory being used to store a resource tracking table; and A controller unit, coupled to the at least one memory, is configured to: Receive a request from an entity to access the first entry in the resource tracking table, the first entry corresponding to a first resource of the computing system; Detect the first identifier associated with the entity; The first identifier is compared with the first owner information specified in the first entry of the resource tracking table; as well as Access to the first entry from the entity is controlled based on the comparison.
2. The apparatus of claim 1, wherein the entity has a higher privilege level than the privilege level associated with the first resource of the first entry, and the controller unit denies the entity access to the first entry if the first identifier does not match the first owner information.
3. The apparatus of claim 1, wherein if the first identifier matches the first owner information, the controller unit permits the entity to access or modify the first entry.
4. The apparatus of claim 1, wherein the entity has access privileges to at least a second resource in the same domain as the first resource of the first entry, and the controller unit denies the entity's access.
5. The apparatus of claim 1, wherein the entity has a lower privilege level than the privilege level of the first resource of the first entry, and the controller unit permits the entity to update the first entry based on the comparison.
6. The apparatus of claim 1, wherein the first entry comprises a set of attributes associated with the first resource, and the controller unit denies access to the first entry corresponding to the first resource if the first identifier does not match the first owner information.
7. The apparatus of claim 6, wherein the set of attributes includes one or more of an access control policy or an encryption key associated with the first resource.
8. The apparatus of claim 7, wherein the access control policy specifies that the entity has access privileges to the first resource, and the controller unit denies access to the first entry if the first identifier does not match the first owner information.
9. The apparatus of claim 1, wherein the first entry is stored in a memory file or register file associated with the initiator.
10. The apparatus of claim 1, wherein the resource tracking table includes a second entry corresponding to a second resource, and the first owner information of the first entry is different from the second owner information of the second entry.
11. A method for updating a resource tracking table, the method comprising: The controller unit receives a request from an entity to access the first entry in the resource tracking table, the first entry corresponding to the first resource of the computing system; Detect the first identifier associated with the entity; The controller unit compares the first identifier with the first owner information specified in the first entry of the resource tracking table; as well as The controller unit controls access to the first entry from the entity based on the comparison.
12. The method of claim 11, wherein the entity has a higher privilege level than the privilege level associated with the first resource of the first entry, and the controller unit denies the entity access to the first entry if the first identifier does not match the first owner information.
13. The method of claim 11, wherein if the first identifier matches the first owner information, the controller unit permits the entity to access or modify the first entry.
14. The method of claim 11, wherein the entity has access privileges to at least a second resource in the same domain as the first resource of the first entry, and the controller unit denies the entity's access.
15. The method of claim 11, wherein the entity has a lower privilege level than the privilege level of the first resource of the first entry, and the controller unit permits the entity to update the first entry based on the comparison.
16. The method of claim 11, wherein the first entry comprises a set of attributes associated with the first resource, and the controller unit denies access to the first entry corresponding to the first resource if the first identifier does not match the first owner information.
17. The method of claim 16, wherein the set of attributes includes one or more of an access control policy or an encryption key associated with the first resource.
18. The method of claim 17, wherein the access control policy specifies that the entity has access privileges to the first resource, and the controller unit denies access to the first entry if the first identifier does not match the first owner information.
19. The method of claim 11, wherein the first entry is stored in a memory file or register file associated with the initiator.
20. The method of claim 11, wherein the resource tracking table includes a second entry corresponding to a second resource, and the first owner information of the first entry is different from the second owner information of the second entry.
21. A non-transitory computer-readable medium having program code recorded thereon, the program code being executed by a processor and comprising: Program code for receiving a request from the controller unit for an entity to access a resource tracking table for a first entry, the first entry corresponding to a first resource of the computing system; Program code used to detect the first identifier associated with the entity; Program code for the controller unit to compare the first identifier with the first owner information specified in the first entry of the resource tracking table; and Program code for controlling access to the first entry from the entity by the controller unit based on the comparison.
22. The non-transitory computer-readable medium of claim 21, wherein the entity has a higher privilege level than the privilege level associated with the first resource of the first entry, and the controller unit denies the entity access to the first entry if the first identifier does not match the first owner information.
23. The non-transitory computer-readable medium of claim 21, wherein the controller unit permits the entity to access or modify the first entry if the first identifier matches the first owner information.
24. The non-transitory computer-readable medium of claim 21, wherein the entity has access privileges to at least a second resource in the same domain as the first resource of the first entry, and the controller unit denies the entity's access.
25. The non-transitory computer-readable medium of claim 21, wherein the entity has a lower privilege level than the privilege level of the first resource of the first entry, and the controller unit permits the entity to update the first entry based on the comparison.
26. The non-transitory computer-readable medium of claim 21, wherein the first entry comprises a set of attributes associated with the first resource, and the controller unit denies access to the first entry corresponding to the first resource if the first identifier does not match the first owner information.
27. The non-transitory computer-readable medium of claim 26, wherein the set of attributes includes one or more of an access control policy or an encryption key associated with the first resource.
28. The non-transitory computer-readable medium of claim 27, wherein the access control policy specifies that the entity has access privileges to the first resource, and the controller unit denies access to the first entry if the first identifier does not match the first owner information.
29. An apparatus comprising: A component for receiving a request from the controller unit for an entity to access a first entry in a resource tracking table, the first entry corresponding to a first resource of the computing system; Components used to detect a first identifier associated with the entity; A component for comparing the first identifier with the first owner information specified in the first entry of the resource tracking table by the controller unit; and A component for controlling access to the first entry from the entity by the controller unit based on the comparison.
30. The apparatus of claim 29, wherein if the first identifier does not match the first owner information, the control component denies the entity access to the first entry.