SYSTEM ON PUCE INTEGRATES A DIRECT ACCESS CIRCUIT IN MEMORY AND CORRESPONDING PROCEEDS

The system-on-chip integrates a direct memory access circuit that autonomously manages access rights via hardware routing, addressing the complexity of conventional controllers by ensuring secure and efficient data transfers without software reconfiguration.

FR3135334B1Active Publication Date: 2025-07-18STMICROELECTRONICS (ROUSSET) SAS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2022004276
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-05-05
Publication Date
2025-07-18
Estimated Expiration
2042-05-05

AI Technical Summary

Technical Problem

Conventional direct memory access controllers in systems-on-chip require complex programming to manage access rights, leading to performance deterioration due to frequent reassignment of channels and interrupts, which complicates the design and use.

Method used

A system-on-chip design with a direct memory access circuit that autonomously manages access rights through hardware routing, eliminating the need for secure software configuration and allowing dynamic coupling of peripherals to appropriate controllers based on their access levels.

Benefits of technology

This approach simplifies the design and operation of direct memory access controllers by avoiding the need for reprogramming, enhancing reliability and performance by securely routing requests based on hardware-defined access rights.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000018_0000
    Figure 00000018_0000
  • Figure 00000019_0000
    Figure 00000019_0000
Patent Text Reader

Abstract

The system on chip (SYS) comprising a memory circuit (CT_MEM) comprising memory regions (MEM_S, MEM_NS), and a direct memory access circuit (CT_DMA) capable of generating direct memory accesses (DMA_S, DMA_NS). The direct memory access circuit (CT_DMA) comprises at least one first direct memory access controller (CTRL_S) having the first access right level and at least one second direct memory access controller (CTRL_NS) having the second access right level, the system on chip (SYS) comprising a routing circuit (CT_RTG) configured to hardware couple a first peripheral (PER_S) having the first access right level with said at least one first controller (CTRL_S) and to hardware couple a second peripheral (PER_NS) having the second access right level with said at least one second controller (CTRL_NS). Figure for abstract: Fig 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: SYSTEM ON CHIP INTEGRATING A DIRECT MEMORY ACCESS CIRCUIT AND CORRESPONDING METHOD

[0001] Embodiments and implementations relate to systems-on-chip, including a direct memory access controller integrated into systems-on-chip.

[0002] Microcontrollers and processors within a system-on-chip typically have functions that can be used by certain applications when executed by the processor. Some of these functions need to be protected against unauthorized actions, such as unauthorized intrusion into the system's memory allowing access to sensitive data, or blocking of critical system functions.

[0003] To prevent such unauthorized actions, these functions are divided into separate secure and non-secure access right level contexts. The functions in the secure context are only accessible by a secure system-on-chip program, which is only possible when the system processor is in a secure state.

[0004] Secure and non-secure contexts should be defined so that the system-on-chip context can adapt to the application to be executed. Indeed, some peripherals implement secure functions and the system must be in the secure context to use them, while other peripherals implement non-secure functions and the system must be in the non-secure context to use them. There are also peripherals whose access right level, secure or non-secure, can change depending on their uses.

[0005] Devices with a "secure" access right level are only accessible by the secure program, while devices with a "non-secure" access right level can be accessible by the secure program or also by a non-secure program of the system when they are executed by the processor.

[0006] Typically, certain peripherals can be accessed by a direct memory access controller (better known by the acronym "DMA" from the common English terms "Direct Memory Access") which is a master device of a communication bus of the system, on which the processors, peripherals and memories can be connected. Upon receipt of a direct memory access transfer request from a peripheral, the direct memory access controller performs one or more accesses to the registers of this peripheral. When the peripheral has a "secure" access right level, the access controller direct memory access must have the "secure" access level, the same as the processor.

[0007] The direct memory access controller is therefore often used in systems on chip to perform data transfers between a peripheral and a memory region independently of the processor in order to avoid interruptions which could slow down the operation of the processor.

[0008] Indeed, a direct memory access controller may be required by secure applications to transfer data between secure devices and a secure memory region, and also by non-secure applications to transfer data between non-secure devices and a non-secure memory region.

[0009] To prevent loss or theft of sensitive data, non-secure applications should not be allowed to configure the direct memory access controller in a secure state, which would allow them to access secure memory regions and secure peripherals. Furthermore, direct memory access requests from secure access right level peripherals should typically not be routed to a direct memory access controller in an unsecure state.

[0010] Since multiple devices may be programmed to have a secure or non-secure access right level, the state of the direct memory access controller is typically defined by the secure or non-secure access right level of the request generated by each device and addressed to the controller. The access right level of the request is typically defined by the secure or non-secure access right level of the device originating the request.

[0011] For this purpose, conventional direct memory access controllers have several channels for routing requests from peripherals to the controller, and the access rights level of the direct memory access controller is typically programmable for each channel. Conventionally, the secure program is provided to configure the access rights level of each channel of the direct memory access controller, according to the access rights level of the request received by the controller.

[0012] Furthermore, the channels of conventional controllers are typically few in number compared to the number of devices in the system. As a result, the secure program must dynamically assign channels to the various devices and set their access right levels based on which devices are active and their respective access right levels. In addition, the regular reassignment of channels to devices systematically generates interrupts and implementations of the secure program, which deteriorates the overall performance of the system.

[0013] Therefore, conventional direct memory access controllers are complex in design and use.

[0014] Thus, there is a need to propose solutions that do not suffer from the aforementioned drawbacks.

[0015] Implementations and embodiments provide a simple direct memory access controller capable of managing direct memory accesses autonomously without configuration of the controller by the secure software of the system on chip.

[0016] According to one aspect, there is provided a system-on-chip comprising a memory circuit comprising a first memory region accessible with a first access right level and a second memory region accessible with the first access right level or a second access right level, at least one first peripheral having the first access right level, at least one second peripheral having the second access right level, and a direct memory access circuit capable of generating direct memory accesses.

[0017] The direct memory access circuit comprises at least one first direct memory access controller having the first access right level and at least one second direct memory access controller having the second access right level.

[0018] The system-on-chip comprises a routing circuit configured to hardware couple said at least one first peripheral with said at least one first controller and to hardware couple said at least one second peripheral with said at least one second controller.

[0019] In other words, this aspect allows the use of a simple direct memory access circuit and supports security partitioning per channel instead of a conventional controller requiring programming of access rights for each use of the channels, which is complex to design and use. Indeed, it is not necessary to link, via the secure program, the security state of the peripherals to the direct memory access controller, since this is done in hardware by the routing circuit. Thus, it is not necessary to program the security state of the direct memory access controller in addition to the security state of the peripherals. Furthermore, non-secure functions do not need to request a secure service from the secure program to allocate input channels to the direct memory access controller.

[0020] Thus, it is not necessary to reconfigure each controller to generate a new direct memory access to a peripheral according to the access right level of the peripheral, which makes it possible to design a simpler and more reliable direct memory access circuit.

[0021] In particular, the state of each controller is not reprogrammed by the secure program of the system according to the access right level of each peripheral, which makes it possible, for example, to avoid erroneous programming of the state of the controller during direct access to the memory of a memory region by an unauthorized peripheral.

[0022] According to one embodiment, the system-on-chip further comprises at least one third peripheral adapted to have an access right level dynamically assigned between the first access right level and the second access right level, and an access right level management means configured to assign the access right level to said at least one third peripheral, wherein said routing circuit comprises switching means configured to physically couple said at least one third peripheral with said at least one first controller when the first access right level is assigned to the third peripheral, and to physically couple said at least one third peripheral with said at least one second controller when the second access right level is assigned to the third peripheral.

[0023] The routing circuit thus makes it possible to physically and automatically redirect the request generated by a device according to its access right level, either to the first controller or to the second controller.

[0024] According to one embodiment, said peripherals are configured to generate requests having the access right level identical to the access right level of the respective peripheral, said at least one first direct memory access controller is configured to generate a direct memory access, in response to a request having the first access right level, comprising a transfer of a burst of data between the peripheral that generated the request and the first memory region or the second memory region, and said at least one second direct memory access controller is configured to generate a direct memory access, in response to a request having the second access right level, comprising a transfer of a burst of data between the peripheral that generated the request and the second memory region.

[0025] Each direct memory access controller can therefore perform a data transfer corresponding to a conventional direct memory access technique between the memory regions and the peripherals, in a known and controlled manner while benefiting from more reliable behavior.

[0026] According to one embodiment, the routing circuit is adapted to dynamically couple a number N of said peripherals having the first level of access rights to said at least one first direct memory access controller and to dynamically couple a number M of said peripherals having the second level of access rights to said at least one second direct memory access controller.

[0027] The number N and M of peripherals corresponds to the limit number of channels that the routing circuit can allocate to the peripherals respectively to the first controller and to the second controller. For example, each controller has 8 or 16 channels. A channel represents a physical link established between a peripheral and a controller allowing routing of requests coming from the peripheral to the controller. Thus, the dynamic coupling of the routing circuit allows each controller to be coupled to a greater number of peripherals than the number of input channels, while still benefiting from the simplicity of use according to the aspect defined above, that is to say the absence of the need to reprogram the access rights of the channels of the controller by the secure program.

[0028] According to one embodiment, the first level of access right is a secure access right level corresponding to secure functions and the second level of access right is a non-secure access right level corresponding to non-secure functions, the system on chip comprising hardware means for physical separation between the elements having the secure access right level and the elements having the non-secure access right level.

[0029] According to one embodiment, the system-on-chip further comprises a processor capable of defining the access right level of said at least one third peripheral, and a bus configured to route communication signals between the processor, said peripherals and the memory circuit.

[0030] According to another aspect, there is provided a method for direct memory access to a first memory region accessible with a first access right level and to a second memory region accessible with the first access right level or a second access right level, by at least one first peripheral having the first access right level and by at least one second peripheral having the second access right level, said direct memory accesses by said at least one first peripheral being generated by at least one first direct memory access controller having the first access right level of a direct memory access circuit, and said direct memory accesses by said at least one second peripheral being generated by at least one second direct memory access controller having the second access right level.

[0031] According to one embodiment, the method comprises direct memory access to the first memory region and to the second memory region by at least one third peripheral capable of having a dynamically assigned access right level between the first access right level and the second access right level, the direct memory access by said at least one third peripheral being generated by said at least one first direct access controller when the first access right level is assigned to the third peripheral and by said at least one second direct memory access controller when the second level of access rights is assigned to the third device.

[0032] According to one embodiment, requests are generated by the peripherals, the requests having the access right level identical to the access right level of the respective peripheral, and the direct memory accesses generated by said at least one first controller, in response to a request having the first access right level, comprise a transfer of a burst of data between the peripheral that generated the request and the first memory region or the second memory region, and, the direct memory accesses generated by said at least one second controller, in response to a request having the second access right level, comprise a transfer of a burst of data between the peripheral that generated the request and the second memory region.

[0033] According to one embodiment, the first level of access rights is a secure access right level corresponding to secure functions and the second level of access rights is a non-secure access right level corresponding to non-secure functions, the elements having the secure access right level and the elements having the non-secure access right level being physically separated by physical separation hardware means.

[0034] According to one embodiment, the method comprises a dynamic coupling of a number N of said peripherals having the first level of access rights to said at least one first direct memory access controller and a dynamic coupling of a number M of said peripherals having the second level of access rights to said at least one second direct memory access controller.

[0035] According to one embodiment, the first level of access rights is a secure access right level corresponding to secure functions and the second level of access rights is a non-secure access right level corresponding to non-secure functions, the elements having the secure access right level and the elements having the non-secure access right level being physically separated by physical separation hardware means.

[0036] According to one embodiment, the method comprises routing communication signals via a bus between said peripherals, the memory circuit and a processor capable of defining the access right level of said at least one third peripheral.

[0037] Other advantages and characteristics of the invention will appear on examining the detailed description of embodiments and implementations, which are in no way limiting, and the appended drawings, in which:

[0038] [Fig.l]

[0039] [Fig.2] schematically illustrate embodiments and implementations of the invention.

[0040] [Fig.l] illustrates a system on chip SYS. The system SYS comprises a memory circuit CT_MEM, at least one first peripheral PER_S and at least one second peripheral PER_NS.

[0041] The memory circuit CT_MEM comprises a first memory region MEM_S accessible with a first access right level and a second memory region MEM_NS accessible with the first access right level or a second access right level. The memory circuit CT_MEM may be an SRAM or DRAM memory for example which comprises several memory regions defined at different memory addresses. Alternatively, the memory circuit CT_MEM may also be designed from at least two separate memories including a memory MEM_S accessible with the first access right level and a memory MEM_NS accessible with the second access right level.

[0042] In particular, the first access right level may be a “secure” access right level and the second access right level may be a “non-secure” access right level. The “secure” access right level corresponds to secure functions that can be implemented by the first peripherals PER_S and the first memory region MEM_S for example. The “non-secure” access right level corresponds to non-secure functions that can be implemented by the second peripherals PER_NS and the second memory region MEM_NS for example. The system on chip SYS comprises hardware means for physical separation SEC between the elements having the secure access right level, such as the first peripherals PER_S and the first memory region MEM_S, and the elements having the non-secure access right level, such as the second peripherals PER_NS and the second memory region MEM_NS.For example, the hardware means of physical separation include SEC security interfaces which will be described later in relation to [Fig.2].

[0043] The system SYS as shown in [Fig.l] comprises several first PER_S devices, for example two, and several second PER_NS devices, for example three. The first PER_S devices have the first level of access rights and the second PER_NS devices have the second level of access rights.

[0044] The SYS system also comprises at least one third PER_SNS device, for example three. The third PER_SNS devices are capable of having a dynamically assigned access right level between the first access right level and the second access right level.

[0045] The first PER_S devices are configured to generate a request having the first access right level and the second PER_NS devices are configured to generate a request having the second access right level. The third PER_SNS devices are configured to generate a request having the first access right level or a request having the second access right level depending on the access right level assigned to them. The request may be a direct memory access request to transfer data between a device and a memory region.

[0046] The system on chip SYS further comprises a CT_SNS access right level management means. The CT_SNS access right level management means is configured to assign the respective access right levels of the third PER_SNS devices.

[0047] For example, the CT_SNS access right level management means may assign the first access right level or the second access right level to each of the third PER_SNS devices. The third PER_SNS device(s) having the first access right level are configured to generate a request having the first access right level and the third device(s) having the second access right level are configured to generate a request having the second access right level.

[0048] The access right level management means CT_SNS can for example be implemented in software by a secure program of the SYS system (see the description below in relation to [Fig.2]).

[0049] Furthermore, the system SYS comprises a direct memory access circuit CT_DMA capable of generating direct memory accesses DMA_S and DMA_NS and a routing circuit CT_RTG capable of routing the requests generated by the peripherals PER_S, PER_NS, PER_SNS to the direct memory access circuit CT_DMA.

[0050] The direct memory access circuit CT_DMA comprises at least a first direct memory access controller CTRL_S and at least a second direct memory access controller CTRL_NS. The first direct memory access controller CTRL_S has the first access right level which can be the "secure" access right level, and the second direct memory access controller CTRL_NS has the second access right level which can be the "non-secure" access right level.

[0051] The routing circuit CT_RTG is configured to hardware couple said at least one first peripheral PER_S with said at least one first controller CTRL_S and to hardware couple said at least one second peripheral PER_NS with said at least one second controller CTRL_NS.

[0052] The first PER_S peripherals are hardware coupled by the CT_RTG routing circuit with the first direct memory access controller CTRL_S and the second PER_NS peripherals are hardware coupled by the CT_RTG routing circuit with the second CTRL_NS direct memory access controller. The CT_RTG routing circuit may be a circuit comprising electrical wires soldered between the first PER_S peripherals and the first CTRL_S direct memory access controller and other electrical wires soldered between the second PER_NS peripherals and the second CTRL_NS direct memory access controller. The wires of the CT_RTG routing circuit notably allow communication between the peripherals and the controllers to which they are coupled, such as for example a transmission of a request between a peripheral and a controller.

[0053] The routing circuit CT_RTG comprises switching means SW_SNS, such as conventional switching circuits provided with transistors for example.

[0054] The switching means SW_SNS are configured to hardware couple said at least one first controller CTRL_S with the third peripherals PER_SNS having the first level of access rights, and to hardware couple said at least one second controller CTRL_NS with the third peripherals PER_SNS having the second level of access rights.

[0055] To achieve this coupling of the third peripherals PER_SNS with the first controller CTRL_S and with the second controller CTRL_NS, each switching means SW_SNS may comprise an input connected to a respective third peripheral PER_SNS and two outputs connected respectively to the first controller CTRL_S and to the second controller CTRL_NS by electrical wires of the routing circuit CT_RTG. The switching means SW_SNS are configured to switch to one or the other of their outputs to transmit the request to the corresponding direct memory access controller CTRL_S, CTRL_NS, according to the access right level of the request received on their inputs. The number of outputs of the switching means SW_SNS may obviously be adapted to the number of first controllers CTRL_S and to the number of second controllers CTRL_NS.As described previously, the wires of the CT_RTG routing circuit allow in particular communication between the peripherals and the controllers to which they are coupled, in particular a transmission of a request between a peripheral and a controller for example.

[0056] The CT_RTG routing circuit thus makes it possible to redirect the request generated by the PER_SNS device according to its access right level either to the first controller CTRL_S or to the second controller CTRL_NS.

[0057] Said at least one first direct memory access controller CTRL_S and said at least one second direct memory access controller CTRL_NS comprise channels through which they can receive requests from the peripherals. A channel represents a physical link established between a peripheral and a controller allowing routing of requests from the peripheral to the controller.

[0058] Since the PER_S, PER_NS, PER_SNS devices are not all coupled to the same controller, the channels are distributed between the first controller CTRL_S and the second controller CTRL_NS, thus allowing security partitioning by channel. Security partitioning by channel corresponds to a routing of requests having the first level of access rights by the channels of the first controller CTRL_S, also having the first level of access rights, and to a routing of requests having the second level of access rights by the channels of the second controller CTRL_NS, also having the second level of access rights.

[0059] The first controller CTRL_S may comprise, for example, 8 or 16 channels used by the first peripherals PER_S and the third peripherals PER_SNS, and the second controller CTRL_NS may comprise, for example, 8 or 16 channels used by the second peripherals PER_NS and the third peripherals PER_SNS.

[0060] The direct memory access requests generated by the PER_S, PER_SNS and PER_NS peripherals are part of the process allowing the CT_DMA direct memory access circuit to generate the various direct memory accesses.

[0061] The first direct memory access controller CTRL_S is configured to generate a direct memory access DMA_S in response to a request having the first access right level. The direct memory access DMA_S comprises a transfer of a burst of data between the first device PER_S or the third device PER_SNS that generated the request and the first memory region MEM_S or the second memory region MEM_NS.

[0062] The second direct memory access controller CTRL_NS is configured to generate a direct memory access DMA_NS in response to a request having the second access right level. The direct memory access DMA_NS comprises a transfer of a data burst between the second PER_NS device or the third PER_SNS device that generated the request and the second memory region MEM_NS.

[0063] Each direct memory access controller can therefore perform a DMA_S or DMA_NS data transfer corresponding to a conventional direct memory access technique between the MEM_S and MEM_NS memory regions and the peripherals. PER_S, PER_SNS and PER_S, in a known and controlled manner while benefiting from more reliable behavior.

[0064] The direct memory access controllers CTR_S and CTRL_NS typically have a limited number of channels for communicating with peripherals and receiving a direct memory access request. To be able to generate direct memory access for all peripherals coupled to a direct memory access controller, the CT_RTG routing circuit can be adapted to dynamically couple peripherals to the controllers.

[0065] Advantageously, the routing circuit CT_RTG is adapted to dynamically couple a number N of peripherals PER_S and PER_SNS having the first level of access rights to said at least one first direct memory access controller CTRL_S and to dynamically couple a number M of peripherals PER_NS and PER_SNS having the second level of access rights to said at least one second direct memory access controller CTRL_NS.

[0066] The number N and M of peripherals corresponds to the limit number of channels that the CT_RTG routing circuit can allocate to the peripherals respectively to the first CTRL_S controller and to the second CTRL_NS controller. For example, each controller has 8 or 16 channels. Thus, the dynamic coupling of the CT_RTG routing circuit allows each CTRL_S and CTRL_NS controller to be coupled to a greater number of peripherals than the number of input channels, while benefiting from the simplicity of use of the controller, i.e. the absence of the need to reprogram the access rights of the controller channels by the secure program.

[0067] We now refer to [Fig.2].

[0068] [Fig.2] illustrates the system on chip SYS described previously in relation to [Fig.l], which further comprises a processor PROC and a bus BS.

[0069] The processor PROC is capable of defining the access right level of said at least one third PER_SNS peripheral, via the access right level management means CT_SNS during the execution of the secure software for example. For example, the access right level management means CT_SNS can be implemented in software by the secure program of the processor PROC which is alone capable of individually managing the access right level of a PER_SNS peripheral, for example by modifying the value of a dedicated bit corresponding to the access right level of the PER_SNS peripheral.

[0070] The processor PROC, the controllers CTRL_S and CTRL_NS, the memory circuit CT_MEM as well as the peripherals PER_S, PER_SNS and PER_NS are coupled to the bus BS. The security interface SEC belonging to the hardware means of physical separation can be provided between the bus BS and the secure elements of the system SYS, such as the memory region MEM_S, the access right level management means CT_SNS, the first controller CTRL_S, the first peripherals PER_S and the third peripherals PER_SNS. The security interface SEC makes it possible, for example, to authorize or prevent access to a secure element of the system depending on the access right level.

[0071] The bus BS is configured to carry communication signals, for example digital signals, between the processor PROC, the peripherals PER_S, PER_SNS and PER_NS, and the memory circuit CT_MEM.

[0072] The transfer of DMA_S or DMA_NS data can therefore be done via the CT_DMA direct memory access circuit between a peripheral and a memory region in both directions through the BS bus.

[0073] Unlike conventional systems on chip in which the access right level of the controller channel must be configured by the secure program of the processor PROC, the system SYS described in relation to Figures 1 and 2 comprises controllers CTRL_S, CTRL_NS having channels whose access right level is already defined by the access right level of the controller.

[0074] It is recalled that the first direct memory access controller CTRL_S has the first access right level which can be the “secure” access right level, and the second direct memory access controller CTRL_NS has the second access right level which can be the “non-secure” access right level.

[0075] Thanks to the SYS system, the first CTRL_S controllers and the second CTRL_NS controllers no longer require actions of the secure program to allow the PER_S peripherals implementing functions of a secure context to access the secure MEM_S and non-secure MEM_NS memory regions and the PER_NS peripherals implementing functions of a non-secure context to access the non-secure MEM_NS memory region.

[0076] In addition, no action of the secure program is also required to reconfigure the access right level of the controller channels when receiving requests from devices having a configurable access right level. Therefore, the SYS system is perfectly suited to the use of third PER_SNS devices having configurable access right levels, which are capable of implementing secure functions and non-secure functions.

[0077] Thus, each direct memory access controller as described above is simple and supports security partitioning per channel. Indeed, the routing circuit CT_RTG is configured to link the security state of the PER_S, PER_SNS and PER_NS devices to the corresponding direct memory access controller. In other words, the security state of the direct memory access controller does not need to be programmed with respect to the security state of the PER_S devices, PER_SNS and PER_NS. Therefore, non-secure functions do not need to request a secure service from the secure program to allocate input channels to the DMA controller.

[0078] Thus, it is not necessary to reconfigure each controller to generate a new direct memory access DMA_S or DMA_NS to a PER_S, PER_SNS or PER_NS peripheral depending on the access right level of the peripheral, which makes it possible to design a simpler controller.

[0079] In particular, the state of each controller is not reprogrammed by the secure program of the system according to the access right level of each peripheral PER_S, PER_SNS or PER_NS, which makes it possible, for example, to avoid erroneous programming of the state of the controller during direct access to DMA_S or DMA_NS memory of a memory region by an unauthorized peripheral.

Claims

1. Claims System on chip (SYS) comprising a memory circuit (CT_MEM) comprising a first memory region (MEM_S) accessible with a first access right level and a second memory region (MEM_NS) accessible with the first access right level or a second access right level, at least one first peripheral (PER_S) having the first access right level, at least one second peripheral (PER_NS) having the second access right level, and a direct memory access circuit (CT_DMA) capable of generating direct memory accesses (DMA_S, DMA_NS), in which the direct memory access circuit (CT_DMA) comprises at least one first direct memory access controller (CTRL_S) having the first access right level and at least one second direct memory access controller (CTRL_NS) having the second access right level,the system on chip (SYS) comprising a routing circuit (CT_RTG) configured to physically couple said at least one first peripheral (PER_S) with said at least one first controller (CTRL_S) and to physically couple said at least one second peripheral (PER_NS) with said at least one second controller (CTRL_NS), the system further comprising at least one third peripheral (PER_SNS) capable of having an access right level dynamically assigned between the first access right level and the second access right level, and an access right level management means (CT_SNS) configured to assign the access right level to said at least one third peripheral (PER_SNS),wherein said routing circuit (CT_RTG) comprises switching means (SW_SNS) configured to physically couple said at least one third peripheral (PER_SNS) with said at least one first controller (CTRL_S) when the first level of access rights is assigned to the third peripheral (PER_SNS), and to physically couple said at least one third peripheral (PER_SNS) with said at least one second controller (CTRL_NS) when the second level of access rights is assigned to the third peripheral (PER_SNS).,

2. The system-on-chip of claim 1, wherein said peripherals (PER_S, PER_NS, PER_SNS) are configured to generate requests having the same access right level as the access right level of the respective peripheral (PER_S, PER_NS, PER_SNS), said at least one first direct memory access controller (CTRL_S) is configured to generate a direct memory access, in response to a request having the first access right level, comprising a transfer of a burst of data between the peripheral (PER_S, PER_SNS) that generated the request and the first memory region (MEM_S) or the second memory region (MEM_NS), and said at least one second direct memory access controller (CTRL_NS) is configured to generate a direct memory access, in response to a request having the second access right level, comprising a transfer of a burst of data between the peripheral that generated the request (PER_NS,PER_SNS) and the second memory region (MEM_NS).,

3. System on chip according to one of claims 1 or 2, wherein the routing circuit (CT_RTG) is adapted to dynamically couple a number N of said peripherals (PER_S, PER_SNS) having the first level of access rights to said at least one first direct memory access controller (CTRL_S) and to dynamically couple a number M of said peripherals (PER_NS, PER_SNS) having the second level of access rights to said at least one second direct memory access controller (CTRL-NS).

4. System on chip according to one of the preceding claims, in which the first level of access right is a secure access right level corresponding to secure functions and the second level of access right is a non-secure access right level corresponding to non-secure functions, the system on chip comprising physical separation hardware means (SEC) between the elements having the secure access right level and the elements having the non-secure access right level.

5. System on chip according to one of the preceding claims, further comprising a processor (PROC) capable of defining the access right level of said at least one third peripheral (PER_SNS), and a bus (BS) configured to route signals communication between the processor (PROC), said peripherals (PER_S, PER_SNS, PER_NS) and the memory circuit (CT_MEM).

6. Method for direct memory access to a first memory region (MEM_S) accessible with a first access right level and to a second memory region (MEM_NS) accessible with the first access right level or a second access right level, by at least one first peripheral (PER_S) having the first access right level and by at least one second peripheral (PER_NS) having the second access right level, said direct memory accesses (DMA_S) by said at least one first peripheral (PER_S) being generated by at least one first direct memory access controller (CTRL_S) having the first access right level of a direct memory access circuit (CT_DMA), and said direct memory accesses (DMA_NS) by said at least one second peripheral (PER_NS) being generated by at least one second direct memory access controller (CTRL_NS) having the second access right level,the method comprising direct memory access (DMA_S, DMA_NS) to the first memory region (MEM_S) and to the second memory region (MEM_NS) by at least one third peripheral (PER_SNS) capable of having a dynamically assigned access right level between the first access right level and the second access right level, the direct memory access by said at least one third peripheral (PER_SNS) being generated by said at least one first direct memory access controller (CTRL_NS) when the first access right level is assigned to the third peripheral (PER_SNS) and by said at least one second direct memory access controller (CTRL_NS) when the second access right level is assigned to the third peripheral (PER_SNS).,

7. The method of claim 6, wherein requests are generated by the peripherals (PER_S, PER_SNS, PER_NS), the requests having the access right level identical to the access right level of the respective peripheral, and the direct memory accesses (DMA_S) generated by said at least one first controller (CTRL_S), in response to a request having the first access right level, comprise a transfer of a burst of data between the peripheral (PER_S, PER_SNS) that generated the request and the first memory region (MEM_S) or the second memory region (MEM_NS), and, the direct memory accesses (DMA_NS) generated by said at least one second controller (CTRL_NS) in response to a request having the second level of access right comprise a transfer of a burst of data between the peripheral (PER_NS, PER_SNS) which generated the request and the second memory region (MEM_NS).

8. Method according to one of claims 6 or 7, comprising a dynamic coupling of a number N of said peripherals (PER_S, PER_SNS) having the first level of access rights to said at least one first direct memory access controller (CTRL_S) and a dynamic coupling of a number M of said peripherals (PER_NS, PER_SNS) having the second level of access rights to said at least one second direct memory access controller (CTRL-NS).

9. Method according to one of claims 6 to 8, in which the first level of access right is a secure access right level corresponding to secure functions and the second level of access right is a non-secure access right level corresponding to non-secure functions, the elements having the secure access right level (PER_S, MEM_S) and the elements having the non-secure access right level (PER_NS, MEM_NS) being physically separated by physical separation hardware means (SEC).

10. Method according to one of claims 6 to 9, comprising a routing of communication signals by a bus (BS) between said peripherals (PER_S, PER_SNS, PER_NS), the memory circuit (CT_MEM) and a processor (PROC) capable of defining the access right level of said at least one third peripheral (PER-SNS).