Method for managing resource isolation of a system on chip, and corresponding system on chip.

The system on chip addresses silent illegal access errors by using a protection circuit to generate notification signals on an error channel, ensuring immediate reaction and configurable precision, thereby stabilizing the system and enhancing error handling.

FR3142569B1Active Publication Date: 2025-07-04STMICROELECTRONICS (GRAND OUEST) SAS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2022012348
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-11-25
Publication Date
2025-07-04
Estimated Expiration
2042-11-25

AI Technical Summary

Technical Problem

Existing resource isolation techniques in systems on chip fail to provide immediate notification to master devices about illegal access errors, leading to silent detections and potential system destabilization due to repeated errors, without allowing for configurable precision in error notification.

Method used

A system on chip design that includes a protection circuit generating a notification signal on an error notification channel for master devices, allowing immediate reaction to illegal access, with configurable options for notification precision through configuration registers.

Benefits of technology

Enables immediate notification of illegal access errors to master devices, preventing system destabilization and allowing for dynamic configuration of error handling precision based on user needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000014_0000
    Figure 00000014_0000
  • Figure 00000014_0001
    Figure 00000014_0001
  • Figure 00000015_0000
    Figure 00000015_0000
Patent Text Reader

Abstract

The system on chip (SOC) comprises at least one master device (MSTR), at least one slave resource (RES), an interconnect bus (BUS) comprising an error notification channel (RREP), and a resource isolation system (RIF) comprising, for each resource, a protection circuit (RISUP) configured to block or transmit transactions addressed to the resource by the interconnect bus (BUS), depending on access rights of the resource and the transaction. The protection circuit (RISUP) is capable of generating a notification signal (ILAC_BUS) on the error notification channel (RREP) of the interconnect bus (BUS) in the event of a transaction blocking. Figure for abstract: Fig 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for managing the isolation of resources of a system on chip, and corresponding system on chip.

[0001] Implementations and embodiments of the invention relate to integrated circuits, in particular systems on chip (System on Chip), for example a microcontroller or a microprocessor, and more particularly to techniques for isolating resources belonging to the system on chip.

[0002] To help ensure the reliability of a system-on-chip, resource isolation techniques are used to restrict access by one or more master devices to specific slave resources. "Illegal" access occurs when a transaction issued by a master device to a slave resource does not comply with established access restrictions.

[0003] For example, publication FR 3103586 Al (28 / 05 / 2021) describes a technique for managing these access restrictions that is simple to implement and implement, in particular when this management is dynamic, i.e. it depends on different applications of the system on chip.

[0004] In conventional resource isolation techniques, typically only a "trusted domain", usually in charge of managing restrictions and access rights, is informed of illegal access to a resource, by an illegal access management mechanism.

[0005] Detections of illegal access are thus typically silent, from the point of view of the device having issued the transaction in question, because an illegal write access is typically ignored, and an illegal read access typically receives a “0” which can be seen as read content.

[0006] This can cause difficulties in debugging, since it is possible to know which resource was accessed illegally, but not by which context (i.e. by which master device and / or in which access rights).

[0007] Additionally, in some products, it may be desirable to immediately shut down a failed master device, which is typically not possible without delay because the trusted domain must first address the error before deciding what to do.

[0008] Finally, when the faulty master device is not informed of the error, it may repeat the same error and may destabilize the system, for example by accumulating bad configurations in registers. This behavior may not be acceptable in certain situations.

[0009] Thus, there is a need to address the above-mentioned problems, in particular to provide a solution for immediately notifying the master device affected by the illegal access error, and to identify the context, or even the line of code, which generated the illegal access error.

[0010] Furthermore, there is a need for illegal access management solutions to be configurable, for example by a user, in particular in order to configure the degree of precision in the manner of notifying a detection of illegal access.

[0011] Embodiments and implementations propose in this regard to generate a notification signal, in the event of illegal access, directly transmitted to the master device concerned on an error notification channel of an interconnection bus of the system on chip.

[0012] Further, embodiments and implementations provide for being able to select the behavior for each resource to decide whether an illegal access should be silent or cause the notification signal to be generated.

[0013] According to one aspect, a system on a chip is thus proposed comprising at least one master device, at least one slave resource, an interconnection bus comprising an error notification channel, and a resource isolation system comprising, for each resource, a protection circuit configured to block or transmit transactions addressed to the resource by the interconnection bus, depending on access rights of the resource and the transaction. The protection circuit is capable of generating a notification signal on the error notification channel of the interconnection bus in the event of a transaction being blocked.

[0014] The protection circuit is for example configured to address said notification signal to the master device at the origin of said blocked transaction.

[0015] The interconnection bus is for example a system coupled between the master devices and the slave resources which makes it possible to route transactions, for example write or read transactions, between the master devices and the slave resources.

[0016] For example, the notification signal communicated on the error notification channel of the interconnection bus may be provided to generate a reaction, advantageously immediate, from the master device at the origin of the blocked transaction.

[0017] The reaction of the master device may include an interruption of the current data transfer, and / or a termination of the current process (at the origin of the illegal access) by forcing a generation of a data abort exception.

[0018] The reaction of the master device can advantageously make it possible to recover the address which generated the illegal access. In particular, the forced generation of the data abandonment exception can in fact make it possible to identify the address which generated the data abandonment exception. For example, data abandonment management processes can usually be provided for respective access rights levels (for example non-secure and secure).

[0019] The use (or reuse) of the error notification channel existing on the interconnection bus by the protection circuit also makes it possible to avoid multiplying the connection wires dedicated to the resource isolation system. It will be noted in particular that it is the protection circuit which is capable of using said error notification channel of the bus, and not the resource. It is in fact in the event of a transaction being blocked, and therefore for a resource which is totally unaware of the existence of this transaction, that the protection circuit is capable of generating a notification signal on the error notification channel of the bus.Thus, the error notification channel of the bus is for example "overloaded" by the protection circuit, in addition to the resource, because the protection circuit is able to use this channel independently of the resource, whereas this channel can normally be intended to be used by the resource independently of the protection circuit.

[0020] According to one embodiment, the resource isolation system comprises, in a set of configuration registers, for each resource a location for containing notification configuration data, the protection circuit of each resource being configured to generate or not generate said notification signal in the event of blocking of a transaction addressed to the resource, depending on the notification configuration data for this resource.

[0021] Thus, the additional degree of precision in the detection of illegal accesses, obtained by the notification signal on the bus error notification channel, can be activated or deactivated depending on the resource isolation needs, for example chosen by a user. Indeed, for each resource and depending on the use of a product, it may be desirable to benefit from great control and high security and thus to activate the notification signal in the event of a transaction being blocked; or conversely, to favor simplicity and / or performance and deactivate this signal so as not to use the bus error notification channel or interrupt the master device.

[0022] According to one embodiment, the system on chip comprises a trusted master device, and the resource isolation system comprises a central management unit capable of generating an interrupt signal addressed to the trusted master device, in the event of a transaction being blocked by any one of said at least one protection circuit.

[0023] Indeed, the use of the notification signal on the error notification channel of the interconnection bus is compatible in combination with central management of illegal accesses using an interrupt transmitted to the trusted master device.

[0024] According to one embodiment, the resource isolation system comprises, in a set of configuration registers, for each resource, a location provided to contain data for configuring the interrupts, the central management unit being configured to generate or not generate said interrupt signal in the event of blocking of a transaction addressed to a resource, depending on the interrupt configuration data for this resource.

[0025] Thus, again the interrupt signal can be activated or deactivated depending on the resource isolation needs, for example chosen by a user.

[0026] And, in combination with the notification setting data, the system-on-chip may have four levels of accuracy in detecting illegal access, which may be selected, for example by a user, depending on resource isolation needs.

[0027] According to another aspect, there is also provided a method of managing the isolation of resources of a system on chip, in which: - the system-on-chip comprises at least one master device, at least one slave resource, and an interconnect bus comprising an error notification channel; and - the method comprises, for each resource, an implementation of a protection comprising a blocking or a transmission of transactions addressed to the resource by the interconnection bus, depending on access rights of the resource and of the transaction, and a generation of a notification signal on the error notification channel of the interconnection bus in the event of a transaction being blocked.

[0028] According to one embodiment, said notification signal is addressed to the master device at the origin of said blocked transaction.

[0029] According to one embodiment, a notification configuration data item, for each resource, is contained in a set of configuration registers, and said notification signal is generated or not in the event of blocking of a transaction addressed to a resource, depending on the notification configuration data item for this resource.

[0030] According to one embodiment, the system on chip comprises a trusted master device, and the method comprises generating an interrupt signal addressed to the trusted master device, in the event of a transaction addressed to any one of said at least one resource being blocked.

[0031] According to one embodiment, for each resource, an interrupt configuration data item is contained in a set of configuration registers, and said interrupt signal is generated or not in the event of blocking of a transaction addressed to a resource, depending on the interrupt configuration data item for this resource. resource.

[0032] Other advantages and characteristics of the invention will appear on examining the detailed description of embodiments and implementations, which are in no way limiting, and the appended drawings, in which the figures:

[0033] [Fig. 1] and

[0034] [Fig.2] and

[0035] [Fig.3] and

[0036] [Fig.4] illustrate embodiments and implementations of the invention.

[0037] [Fig.l] schematically illustrates an exemplary embodiment of a system on chip SOC, such as for example a microcontroller or a microprocessor, comprising at least one master device MSTR, and at least one slave resource RES capable of communicating via an interconnection bus BUS.

[0038] The master devices TDMSTR, MSTR may for example be processors or central processing units “CPU” (for “Central Processing Unit” in English), adapted to implement software functionalities; or other master devices such as direct memory access means “DMA” (for “Direct Memory Access” in English).

[0039] In this example, the system on chip SOC further comprises a master device TDMSTR qualified as “trusted”, in particular in charge of the configuration and management of access rights defining the isolation rules, implemented by a RIF resource isolation system described in more detail below.

[0040] The resources may for example comprise a peripheral of the I2C type (for “Inter Integrated Circuit” in English), of the SPI type (for “Serial Peripheral Interface” in English), of the UART type (for “Universal Asynchronous Receiver Transmitter” in English), of the real-time clock type “RTC” (for “Real Time Clock” in English), or of the memory type such as a memory internal to the system on chip or an interface for memory external to the system on chip.

[0041] The interconnection bus BUS is coupled between the master devices and the slave resources and makes it possible to route transactions, for example write or read transactions, and more generally information, on channels which may have dedicated functionalities, between the master devices MSTR and the slave resources RES.

[0042] The interconnection bus may for example be a bus of the “AXI” type for “Advanced extensible Interface” in English, or of the “AHB” type for “Advanced High-performance Bus” in English, which are types of “AMBA” microcontroller bus for “Advanced Microcontroller Bus Architecture”.

[0043] In particular, the interconnection bus BUS comprises an error notification channel RREP, for example provided to communicate response information from the slave resources, following reception of a read or write transaction. The response information can for example be coded on 2 bits, so as to allow communication of 4 different states. For example, one of the possible information RREP can be provided to communicate a notification error by a slave resource, in case of a transaction received successfully but which is not understood by the slave resource.

[0044] The system on chip SOC further comprises a resource isolation system RIF configured to restrict access of one or more master devices to specific slave resources, in particular based on access rights defined in this regard.

[0045] For example, among the access rights that can define the resource isolation rules, it is possible to define privileged and non-privileged environments, and possibly cumulatively secure and non-secure environments, as well as possibly also a compartmentalization identifier.

[0046] The concepts of secure / non-secure and privileged / non-privileged environments and access rights are well known to those skilled in the art, and the concept of compartmentalization identifier is notably taught in publication FR 3103586 Al (05 / 28 / 2021).

[0047] We speak of “illegal” access when the access rights of a transaction do not comply with those of the recipient resource.

[0048] For example, the RIF resource isolation system of the system on chip may be part of the resource isolation technique described in publication FR 3103586 Al (05 / 28 / 2021).

[0049] The RIF resource isolation system comprises in particular for each RES resource, a RISUP protection circuit (sometimes called a “firewall”), configured to block or transmit transactions addressed to the RES resource by the BUS interconnection bus, depending on said access rights of the resource and of the transaction.

[0050] Furthermore, according to a general characteristic of the present description, the RISUP protection circuit is capable of generating an ILAC_BUS notification signal on the RREP error notification channel of the BUS interconnection bus, in the event of a transaction being blocked.

[0051] In this regard, reference is made to [Fig.2].

[0052] [Fig.2] illustrates the method 200 implemented by the RISUP protection circuit, in the management of the RIF resource isolation of the SOC system on chip described in relation to [Fig.l].

[0053] Thus, the implementation of the protection 200 of each resource comprises, upon reception 210 of a transaction from the interconnection bus BUS, a verification 220 of the access rights of this transaction with respect to the access rights of the resource.

[0054] Depending on the verification 220, the transaction 210 can be transmitted 230 to the downstream resource RES, or blocked 240 by the protection circuit RISUP in upstream.

[0055] And, if the transaction is blocked 240, the notification signal ILAC_BUS is generated 250 on the error notification channel RREP of the interconnection bus BUS, by the protection circuit RISUP.

[0056] We refer again to [Fig.l].

[0057] The ILAC_BUS notification signal is advantageously addressed to the master device MSTR at the origin of said blocked transaction, by the bus routing mechanisms.

[0058] For example, the notification signal may in this regard be the information, mentioned previously, intended to communicate on the RREP error notification channel an error notification of the slave resource, in the event of a transaction received successfully.

[0059] It will be noted that in this example, the RREP error notification channel of the bus is normally intended to be used by the RES resource (as represented by the broken arrow), and not by the RISUP protection circuit itself.

[0060] However, in this case, it is indeed the RISUP protection circuit itself which generates the ILAC_BUS notification signal on the error notification channel of the BUS bus. Indeed, in the event of a blocking 240 of the transaction, the RES resource is not informed of the existence of this transaction and is therefore not able to generate the ILAC_BUS notification signal.

[0061] Thus, the error notification channel of the RREP bus is said to be “overloaded” since it is connected and usable independently by two separate circuits, both by the RISUP protection circuit and by the RES resource.

[0062] The use, or "reuse", of the RREP error notification channel of the BUS interconnection bus by the RISUP protection circuit, makes it possible in particular to avoid introducing additional connection wires for the RIF resource isolation system.

[0063] Furthermore, the ILAC_BUS notification signal can be provided to generate a reaction, advantageously immediate, from the master device MSTR at the origin of the blocked transaction.

[0064] The reaction of the master device MSTR may include an interruption of the current data transfer, and / or a stopping of the current process (at the origin of the illegal access) by forcing a generation of a data abandonment exception. The forced generation of the data abandonment exception advantageously makes it possible to identify the address which generated it, which thus makes it possible to identify the address which generated the illegal access. For example, data abandonment management processes may usually be provided for respective access rights levels (for example respectively non-secure and secure).

[0065] On the other hand, the RIF resource isolation system can in parallel be configured to generate an ILAC_INTRPT interrupt signal addressed to the trusted master device TDMSTR, in the event of a transaction being blocked by any of the RISUP protection circuits of the different peripherals (at least one) of the system on chip SOC.

[0066] The ILAC_INTRPT interrupt signal can for example be communicated to the trusted master device TDMSTR by the routing mechanism of the interconnection bus BUS.

[0067] The RIF resource isolation system may in this respect comprise a central management unit for illegal access IAC, for example within a control device of the RIFSC resource isolation system.

[0068] In this case, the RISUP protection circuits of the RES resources are configured to generate a signal for detecting illegal access ILAC (and / or blocking of the corresponding transaction) and communicate it to the central management unit for illegal access IAC.

[0069] The central illegal access management unit IAC is configured to generate the ILAC_INTRPT interrupt addressed to the trusted master device TDMSTR, in the event of receipt of an ILAC illegal access detection signal communicated by any of the RISUP protection circuits.

[0070] Furthermore, the RIF resource isolation system can advantageously comprise configuration registers CFGREG, for example within the control device of the RIFSC resource isolation system, capable of containing configuration information CONFIG of the elements of the RIF resource isolation system (in particular the RISUP protection circuits and the central management unit IAC).

[0071] In this regard, reference is made to [Fig.3]

[0072] [Fig.3] illustrates an example of a configuration register CFGREG_RESy, respectively dedicated to a resource “RESy” of the system on chip SOC.

[0073] The configuration register CFGREG_RESy contains 32 locations "0" to "31" to contain setting data relating to resource isolation, for the respective RES resource.

[0074] For example and arbitrarily, location "0" can be used to define the secure or non-secure SEC access right of the resource, while location "1" can be used to define the privileged or non-privileged PRIV access right of the resource.

[0075] For example also, locations “4” to “6” can be used to contain the resource compartmentalization identifier.

[0076] In an advantageous embodiment of the resource isolation system RIF, the CFGREG_RESy configuration register contains a location “8” intended to contain data for configuring ILAC_BUS_CFG notifications.

[0077] The ILAC_BUS_CFG notification configuration data makes it possible to activate or deactivate (for example when it is recorded at the value “1”, or respectively “0”) the ILAC_BUS illegal access notification functionality via the RREP error notification channel of the BUS interconnection bus.

[0078] The value of the ILAC_BUS_CFG notification configuration data can, for example, be recorded by a user, in order to choose the degree of precision of illegal access notification that he wishes to benefit from, and furthermore selectively for each RES resource of the system on chip SOC.

[0079] The value of the ILAC_BUS_CFG notification parameter data can also, for example, be recorded by an access rights establishment procedure, usually carried out by the trusted master device TDMSTR when starting the system on chip SOC.

[0080] Thus, the operation of the RISUP protection circuit of each RES resource is configured according to the ILAC_BUS_CFG parameter data contained in the respective location “8” of the configuration register.

[0081] In this regard, the RISUP protection circuit is configured to generate the ILAC_BUS notification signal in the event of a transaction addressed to the resource being blocked, if the ILAC_BUS_CFG notification configuration data for this resource is activated (for example at “1”); and not to generate the ILAC_BUS notification signal if the ILAC_BUS_CFG notification configuration data for this resource is deactivated (for example at “0”).

[0082] Furthermore, in the case where the RIF resource isolation system includes the central illegal access management unit IAC, as mentioned previously, the configuration register CFGREG_RESy can advantageously contain a location “9” provided to contain an ILAC_INTRPT_CFG interrupt parameter data.

[0083] The ILAC_INTRPT_CFG interrupt configuration data makes it possible to activate or deactivate (for example when it is recorded at the value “1”, or respectively “0”) the functionality of the central illegal access management unit IAC generating ILAC_INTRPT interrupts to the trusted master device TDMSTR, in the event of detection of illegal access, and respectively for each of the RES resources.

[0084] The value of the ILAC_INTRPT_CFG interrupt parameter data can for example be recorded by a user, in order to choose the degree of precision of illegal access notification that he wishes to benefit from, and furthermore selectively for each RES resource of the system on chip SOC.

[0085] Thus, the operation of the central illegal access management unit IAC is configured specifically for each RES resource according to the ILAC_INTRPT_CFG configuration data contained in the respective location “9” of the configuration register.

[0086] In this regard, the central illegal access management unit IAC is configured for each resource, so as to generate the ILAC_INTRPT interrupt signal in the event of a transaction addressed to the resource being blocked, if the ILAC_INTRPT_CFG interrupt parameter data for this resource is activated (for example at "1"); and so as not to generate the ILAC_INTRPT interrupt signal if the ILAC_INTRPT_CFG interrupt parameter data for this resource is deactivated (for example at "0").

[0087] [Fig.4] illustrates a table showing the possibilities for selecting the degree of precision in the notifications of illegal access, of an exemplary embodiment of the system on chip SOC described previously in relation to figures 1 to 3.

[0088] The different degrees of precision of the illegal access notifications are defined for each resource respectively, by the configuration of the ILAC_BUS_CFG notification parameter data and the ILAC_INTRPT_CFG interrupt parameter data.

[0089] The four different degrees of precision of the notifications of illegal access are designated in ascending order of numbers 1, 2, 3, 4.

[0090] The first degree "1" corresponds to silence in the event of illegal access and is defined by disabling the interrupt functionality of the trusted master device TDMSTR, ILAC_INTRPT_CFG = 0, and by disabling the notification functionality of the offending master device MSTR (i.e. the master device that generated the transaction causing the illegal access), ILAC_BUS_CFG = 0.

[0091] The second degree "2" corresponds to a notification only to the trusted master device TDMSTR and is defined by the activation of the interrupt functionality of the trusted master device TDMSTR, "ILAC_INTRPT_CFG = 1", and by the deactivation of the notification functionality of the faulty master device MSTR, "ILAC_BUS_CFG = 0".

[0092] The third degree "3" corresponds to a notification only to the faulty master device MSTR and is defined by the deactivation of the interrupt functionality of the trusted master device TDMSTR, "ILAC_INTRPT_CFG = 0", and by the activation of the notification functionality of the faulty master device MSTR, "ILAC_BUS_CFG = 1".

[0093] The fourth degree "4" corresponds to a notification to both the trusted master device TDMSTR and the faulty master device MSTR, and is defined by the activation of the interrupt functionality of the trusted master device TDMSTR, "ILAC_INTRPT_CFG = 1", and by enabling the faulty master device notification feature MSTR, "ILAC_BUS_CFG = 1".

[0094] In summary, the particularly advantageous degree of precision in the detection of illegal accesses, obtained by the ILAC_BUS notification signal on the error notification channel of the RREP bus, can be activated or deactivated depending on the needs in terms of resource isolation, for example chosen by a user.

[0095] This choice can also advantageously be made in parallel with the configuration of the ILAC_INTRPT interrupt signal, without generating any information redundancy.

[0096] The choice of the configuration of the degree of precision of the notifications of illegal access can be made dynamically during the use of the system on chip, for example at the maximum level of precision during a design and / or debugging phase of a program using the resources of the system on chip SOC, and at a lesser level during the final use of the system on chip SOC.

[0097] More generally, it is possible to benefit from great control and high security or to favor simplicity and / or performance, depending on the functionality of the resource and dynamically depending on the use made of the system on chip and its resources.

Claims

Claims

1. System on chip (SOC) comprising at least one master device (MSTR), at least one slave resource (RES), an interconnection bus (BUS) comprising an error notification channel (RREP), and a resource isolation system (RIF) comprising, for each resource, a protection circuit (RISUP) configured to block or transmit transactions addressed to the resource by the interconnection bus (BUS), depending on access rights of the resource and the transaction, the protection circuit (RISUP) being capable of generating a notification signal (ILAC_BUS) on the error notification channel (RREP) of the interconnection bus (BUS) in the event of a transaction being blocked;in which the resource isolation system (RIF) comprises, in a set of configuration registers (CFGREG), for each resource a location for containing notification configuration data (ILAC_BUS_CFG), the protection circuit (RISUP) of each resource being configured to generate or not generate said notification signal (ILAC_BUS) in the event of blocking of a transaction addressed to the resource, depending on the notification configuration data (ILAC_BUS_CFG) for this resource.;

2. System on chip (SOC) according to claim 1, wherein the protection circuit (RISUP) is configured to address said notification signal (ILAC_BUS) to the master device (MSTR) at the origin of said blocked transaction.

3. System on chip (SOC) according to one of claims 1 or 2, comprising a trusted master device (TDMSTR), in which the resource isolation system (RIF) comprises a central management unit (IAC) capable of generating an interrupt signal (ILAC_INTRPT) addressed to the trusted master device (TDMSTR), in the event of a transaction being blocked by any of said at least one protection circuit (RISUP).

4. System on chip (SOC) according to claim 3, in which the resource isolation system (RIF) comprises, in a set of configuration registers (CFGREG), for each resource, a location intended to contain an interrupt parameterization data item (ILAC_INTRPT_CFG), the central management unit (IAC) being configured to generate or not generate said interrupt signal (ILAC_INTRPT) if a transaction addressed to a resource is blocked, depending on the interrupt setting data (ILAC_INTRPT_CFG) for this resource.

5. Method for managing the isolation of resources of a system on chip (SOC), in which: - the system on chip (SOC) comprises at least one master device (MSTR), at least one slave resource (RES), and an interconnection bus (BUS) comprising an error notification channel (RREP); and - the method comprises, for each resource, an implementation of a protection (RISUP) comprising a blocking or a transmission of transactions addressed to the resource by the interconnection bus (BUS), according to access rights of the resource and the transaction, and a generation of a notification signal (ILAC_BUS) on the error notification channel (RREP) of the interconnection bus (BUS) in the event of a transaction being blocked;in which a notification configuration data (ILAC_BUS_CFG), for each resource, is contained in a set of configuration registers (CFGREG), and said notification signal (ILAC_BUS) is generated or not in the event of blocking of a transaction addressed to a resource, depending on the notification configuration data (ILAC_BUS_CFG) for this resource.;

6. Method according to claim 5, wherein said notification signal (ILAC_BUS) is addressed to the master device (MSTR) at the origin of said blocked transaction.

7. Method according to one of claims 5 or 6, in which the system on chip (SOC) comprises a trusted master device (TDMSTR), and the method comprises a generation of an interrupt signal (ILAC_INTRPT) addressed to the trusted master device (TDMSTR), in the event of blocking of a transaction addressed to any one of said at least one resource.

8. Method according to claim 7, in which, for each resource, an interrupt parameter data (ILAC_INTRPT_CFG) is contained in a set of configuration registers (CFGREG), and said interrupt signal (ILAC_INTRPT) is generated or not in the event of blocking of a transaction addressed to a resource, depending on the interrupt parameter data (ILAC_INTRPT_CFG) for this resource.