System on chip comprising a resource isolation system and corresponding resource isolation management method.
The resource isolation system on SoC addresses inefficient access rights violation communication by generating specific error signals and interrupts, ensuring efficient and targeted notification of violations to microprocessor domains, enhancing the management of illegal access events.
Patent Information
- Application Number
- FR2022012349
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-11-25
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-11-25
AI Technical Summary
Existing system-on-chip (SoC) technologies face challenges in efficiently distributing and managing access rights violation events across microprocessors and operating systems, particularly in asymmetric and symmetric multi-microprocessor architectures, leading to complex and inefficient communication of illegal access events.
A resource isolation system with a filtering module is implemented for each resource to detect violations of security, privilege, and compartmentalization access rights, generating specific error signals and interrupts to inform the affected microprocessor domains about the nature and origin of the violation.
The solution enables precise identification and direct notification of access rights violations to the relevant microprocessor environments, improving communication efficiency and enabling effective management of illegal access events without relying on a centralized secure environment.
Smart Images

Figure 00000024_0000 
Figure 00000025_0000 
Figure 00000026_0000
Abstract
Description
Title of the invention: System on chip comprising a resource isolation system and corresponding resource isolation management method.
[0001] Embodiments and implementations relate to techniques for isolating resources belonging to a system-on-chip, provided for security and / or safety reasons.
[0002] Indeed, in terms of safety, for example to help guarantee the reliability of a system on chip, or in terms of security, for example to help protect information kept secret, it may be provided to restrict the access of one or more master devices to specific slave resources. Such a restriction is designated by those skilled in the art by the English term "isolation".
[0003] For example, publication FR 3103586 Al (05 / 28 / 2021) describes a technique for managing these access restrictions that is simple to implement and implement, in particular when this management is dynamic, i.e. it depends on different applications of the system on chip.
[0004] In particular, security-enabled systems-on-chip typically comprise a secure environment and a non-secure environment, each environment being able to have a privileged or non-privileged state. In addition, the resources (e.g., master devices and slave devices) of this type of system-on-chip may be isolated according to compartmentalizations. These three dimensions "security-privilege-compartmentalization" make it possible to isolate certain resources in terms of safety or security. To access the resources, rules are defined according to "access rights" corresponding to a "security-privilege-compartmentalization" triplet for each resource.
[0005] If access rights rules are violated, it is important to notify it in order to record the event and take the necessary measures. The detection and processing of illegal access, for example as described in publication FR 3103586 Al (28 / 05 / 2021), makes it possible to detect such violations.
[0006] That being said, in conventional isolation techniques, the management of illegal access events is centralized by a central processing unit of a “trusted domain” (for example the secure environment in the privileged state of a so-called “trusted” central microprocessor).
[0007] According to a classic example in an “asymmetric” multi-microprocessor architecture (i.e. where one of the microprocessors is considered hierarchical Although the trusted microprocessor is technically superior to others in terms of security and is called "trusted"), the communication of illegal access events between the trusted microprocessor and the others is typically complex and slowed down by functional latencies.
[0008] According to another classic example in a "symmetric" multi-microprocessor architecture (i.e., where the microprocessors have no particular hierarchy among themselves and where none is designated "trusted"), communication of illegal access events may not be possible because the objective is typically to provide completely independent microprocessor domains.
[0009] Thus, there is a need to provide a solution for distributing access rights violation events to the microprocessors and operating systems respectively affected by these events.
[0010] Embodiments and implementations propose generating new signals by a resource isolation system in order to identify which properties (security, privilege, and / or compartmentalization) of the access rights in question are involved during an event of violation of the access rights of a resource.
[0011] Embodiments and implementations propose generating new interrupts by the resource isolation system to the microprocessor(s), in order to inform the operating software ("OS" for "Operating System" in English) concerned of the existence and properties of an access rights violation event.
[0012] According to one aspect, there is provided a system on chip comprising: - at least one microprocessor domain comprising a microprocessor and at least one resource; and - a resource isolation system comprising a filtering module for each resource and configured to detect a violation of security access rights, privileges, and possibly compartmentalization of the resource, by transactions arriving at the resource, the filtering module being configured, in the event of violation of at least one access right of the resource by a transaction, to generate a first error signal representative of the violated access right of the resource, and a second error signal representative of at least one access right of this transaction.
[0013] It will be noted in fact that the aspect defined above can be applied without necessarily providing compartmentalization access rights.
[0014] For example, the second error signal is advantageously representative of at least one access right other than said violated access right of the resource. For example, the second error signal is advantageously representative of at least the security access right of the transaction. For example, the second error signal is advantageously representative of the security access rights and compartmentalization of the transaction.
[0015] Security access rights and privilege access rights are concepts well known to those skilled in the art. For example, for a microprocessor in secure mode, operating software can be used with resources that are not accessible in a non-secure mode. In the privileged mode, the microprocessor can benefit from privileged rights for access to resources that it will not have in the non-privileged mode.
[0016] The compartmentalization access right makes it possible, for example, to define an assignment of at least one master device to at least some of the resources (slaves), or an assignment of at least some of the resources to at least one master device. The compartmentalization access right applies in particular when the system-on-chip comprises several microprocessor domains, but also several master devices in the same domain, such as, for example, a microprocessor and a direct memory access circuit (DMA).
[0017] Thus, the first error signal and the second error signal, combined with knowledge of the isolation rules defined by the access rights, advantageously makes it possible to deduce whether the event of violation of the access rights occurred between the secure environment and the non-secure environment, or between the privileged state and the non-privileged state in the non-secure environment, or between the privileged state and the non-privileged state in the secure environment, and also the identification of the origin of the transaction in question of the event.
[0018] According to one embodiment, the resource isolation system further comprises an illegal access management unit configured to code, from the first error signal and the second error signal, in a status register accessible in readability by the microprocessor, a violation of the security access rights of a resource, a violation of the privilege access rights of a resource of a secure environment, and a violation of the privilege access rights of a resource of a non-secure environment.
[0019] According to one embodiment, the illegal access management unit is configured to communicate a first interrupt to an unsecured environment of the microprocessor, and / or a second interrupt to a secure environment of the microprocessor, depending on the detected case of violation of access rights.
[0020] According to one embodiment, the illegal access management unit is configured to generate the first interrupt in the event of violation of the access rights of a resource of the non-secure environment, and to generate the second interrupt in the event of violation of the access rights of a resource of the secure environment.
[0021] According to one embodiment, said filtering module is configured, in the event of violation of the security access rights and / or privilege of a resource by a transaction, to generate the second error signal representative of the security access right of this transaction.
[0022] According to one embodiment, the system-on-chip comprises the first microprocessor domain and at least one second microprocessor domain, and the resources of said first microprocessor domain and said at least one second microprocessor domain have respective compartmentalization access rights.
[0023] According to one embodiment, the first microprocessor domain is qualified as trusted, and the illegal access management unit is configured to code in the status register, accessible in reading by the microprocessor of said first trusted domain, each of said cases of violation of the access rights of a resource of any one of said domains, by a transaction initiated from any one of said domains.
[0024] According to one embodiment, the illegal access management unit is configured to communicate said first interrupt and said second interrupt to the microprocessor of said first trusted domain.
[0025] According to one embodiment, the illegal access management unit is configured to code in a status register respectively dedicated to each of the domains, accessible in reading by the microprocessor of the respective domain, each of said cases of violation of the access rights of a resource of any one of said domains, by a transaction initiated from said respective domain.
[0026] According to one embodiment, the illegal access management unit is configured to communicate said first interrupt and said second interrupt to the microprocessor of said respective domain.
[0027] According to one embodiment, the first microprocessor domain is qualified as trusted, and the illegal access management unit is configured to communicate a third interrupt to the microprocessor of the first trusted domain, in the event of detection of a violation of the compartmentalization access rights.
[0028] According to one embodiment, said filtering module is configured, in the event of violation of the security and / or privilege access rights of a resource by a transaction, to generate the second error signal further representing the compartmentalization access right of this transaction.
[0029] According to another aspect, there is provided a method of managing the isolation of resources of a system on chip, in which: - the system-on-chip comprises at least one microprocessor domain comprising a microprocessor and at least one resource; and - the method comprises, for each resource, a detection of a violation of security, privilege, and possibly compartmentalization access rights of the resource, by transactions arriving at the resource, and, in the event of violation of at least one access right of the resource by a transaction, generation of a first error signal representative of the violated access right of the resource, and of a second error signal representative of at least one access right of this transaction.
[0030] According to one embodiment, the method further comprises coding, from the first error signal and the second error signal, in a status register accessible in readability by the microprocessor, a violation of the security access rights of a resource, a violation of the privilege access rights of a resource of a secure environment, and a violation of the privilege access rights of a resource of a non-secure environment.
[0031] According to one embodiment, the method further comprises communicating a first interrupt to a non-secure environment of the microprocessor, and / or a second interrupt to a secure environment of the microprocessor, depending on the detected case of violation of access rights.
[0032] According to one embodiment, the first interruption is generated in the event of a violation of the access rights of a resource of the non-secure environment, and the second interruption is generated in the event of a violation of the access rights of a resource of the secure environment.
[0033] According to one embodiment, in the event of a violation of the security and / or privilege access rights of a resource by a transaction, the second error signal is representative of the security access right of this transaction.
[0034] According to one embodiment, the system-on-chip comprises the first microprocessor domain and at least one second microprocessor domain, and the resources of said first microprocessor domain and said at least one second microprocessor domain have respective compartmentalization access rights.
[0035] According to one embodiment, the first microprocessor domain being qualified as trusted, said coding is done in the status register accessible in reading by the microprocessor of said first trusted domain, for each of said cases of violation of the access rights of a resource of any one of said domains, by a transaction initiated from any one of said domains.
[0036] According to one embodiment, the communications of said first interrupt and said second interrupt are made to the microprocessor of said first trusted domain.
[0037] According to one mode of implementation, said coding is done in a status register respectively dedicated to each of the domains, accessible in reading by the microprocessor of the respective domain, for each of said cases of violation of the rights access to a resource of any of said domains, by a transaction initiated from said respective domain.
[0038] According to one embodiment, the communications of said first interrupt and said second interrupt are made to the microprocessor of said respective domain.
[0039] According to one embodiment, the first microprocessor domain being qualified as trusted, the method further comprises communicating a third interrupt to the microprocessor of the first trusted domain, in the event of detection of a violation of the compartmentalization access rights.
[0040] According to one embodiment, in the event of a violation of the security and / or privilege access rights of a resource by a transaction, the second error signal is furthermore representative of the compartmentalization access right of this transaction.
[0041] Other advantages and characteristics of the invention will appear on examining the detailed description of the embodiment and implementation, which is in no way limiting, and the appended drawings, in which:
[0042] [Fig. 1] and
[0043] [Fig.2] and
[0044] [Fig.3] and
[0045] [Fig.4] and
[0046] [Fig.5A] and
[0047] [Fig.5B] and
[0048] [Fig.5C] and
[0049] [Fig.6] and
[0050] [Fig.7A] and
[0051] [Fig.7B] and
[0052] [Fig.8] and
[0053] [Fig.9] illustrate embodiments and implementations of the invention.
[0054] [Fig.l] illustrates an example of a system on chip SOC comprising a microprocessor domain CPU_DMN1 and a resource isolation system RIF.
[0055] The microprocessor domain CPU_DMN1 comprises a central processing unit CPU1, called microprocessor, and one or more resources PRPH, MEM, RIF_AW, which will also be called resource RES.
[0056] For example, the RES resources of the SOC system on chip may include PRPH peripherals of the FC (“Inter Integrated Circuit”) type, of the SPI (“Serial Peripheral Interface”) type, of the UART (“Universal Asynchronous Receiver Transmitter”) type, or even internal MEM memories or interfaces for external memories.
[0057] The microprocessor CPU1 comprises a secure environment SEC and an environment NSEC unsecured operation, which can cumulatively have a privileged PRIV or non-privileged NPRIV state.
[0058] For example, secure services SSRV and services SRV can be implemented in the non-privileged state NPRIV of the secure environments SEC and non-secure NSEC; real-time operating software RTOS (for example for real-time control of an external device) can be implemented in the non-secure domain NSEC in the privileged state PRIV, and the software part that deals with the management of the secure environment SPM can be implemented in the secure domain SEC in the privileged state PRIV.
[0059] Furthermore, a compartmentalization identification CID makes it possible, for example, to define an assignment of the microprocessor CPU1 (or of another master device of the system on chip SOC, such as, for example, a direct memory access circuit "DMA") to at least some of the resources PRPH, MEM, RIF_AW, or an assignment of at least some of the resources PRPH, MEM, RIF_AW to the microprocessor (or to another master device).
[0060] The three security dimensions SEC, privilege PRIV, and compartmentalization CID make it possible to isolate certain RES resources for safety or security reasons.
[0061] To access RES resources, rules are defined based on “access rights” corresponding to a security triplet SEC, privilege PRIV, compartmentalization CID, for each RES resource.
[0062] The master devices of the CPU_DMN1 domain, i.e. for example the microprocessor CPU1, are able to initiate a transaction with the slave devices of the CPU_DMN1 domain, i.e. the RES resources.
[0063] A transaction has for example the same security access rights SEC, privilege PRIV, compartmentalization CID as the master device which generated it.
[0064] The transactions are communicated on an integrated circuit bus (not shown), usually an “AHB” type bus (for “Advanced High-performance Bus” in English), and, from a more global point of view, via an interconnection network of the system on chip SOC.
[0065] The RIF resource isolation system is configured to implement resource isolation based on the security access rights SEC, NSEC, privilege PRIV, NPRIV, and compartmentalization CID of each resource PRPH, MEM, RIF_AW. The RIF resource isolation system is in particular capable of detecting a violation of said access rights by transactions arriving at said resources.
[0066] The RIF resource isolation system comprises in this respect a RIS filtering module for each PRPH, MEM resource, as well as for example in particular an illegal access management unit IAC and an IRQ interrupt management unit.
[0067] The RIS filtering module can for example be implemented by a dedicated circuit, located between the PRPH resource, respective MEM and the interconnection network or the “AHB” bus, or else integrated into the RIF_AW resource, the latter then being able to be described as “aware of resource isolation”.
[0068] The RIF resource isolation system is not exclusively dedicated to a CPU_DMN1 microprocessor domain, and, in the case where the system on chip SOC comprises several domains, the RIF resource isolation system is common to said several domains and in particular makes it possible to implement the isolation of resources between respective domains.
[0069] We refer to Figures 2 and 3, illustrating examples where the system on chip SOC, as described in relation to [Fig.l], comprises the first microprocessor domain CPU_DMN1 and furthermore at least one second microprocessor domain CPU_DMN2. These cases of systems on chip SOC comprising several microprocessors CPU1, CPU2 can be described as “multi-core”.
[0070] The resources of said first microprocessor domain CPU_DMN1 and of said at least one second microprocessor domain CPU_DMN2 may have respective compartmentalization access rights CID1, CID2 for each domain.
[0071] The case of [Fig.2] corresponds to an “asymmetric” multi-core architecture in which the second microprocessor CPU2 is only intended to provide non-privileged services (NPRIV), in the non-secure SRV or secure SSRV environments. Alternatively, the asymmetry may come from the fact that the second microprocessor CPU2 would only be intended to provide non-secure services (NSEC), according to non-privileged or privileged states.
[0072] As a result, the first microprocessor CPU1 has a higher isolation capacity than the second microprocessor CPU2, and the first microprocessor CPU1, as well as the first domain CPU_DMN1, are qualified as "trusted" TDCID.
[0073] The case of [Fig.3] corresponds to a multi-core architecture “symmetrical” in which the second microprocessor CPU2 has a configuration substantially identical to that of the first microprocessor CUP1, in particular with regard to the configuration of the secure / non-secure environments and cumulatively the privileged / non-privileged states.
[0074] For example, the description given so far in relation to figures 1 to 3 of the RIF resource isolation systems may correspond to the resource isolation technique described in publication FR 3103586 A1 (05 / 28 / 2021) to which those skilled in the art may refer for any useful purpose.
[0075] Furthermore, in each of the cases of Figures 1 to 3, the RIS filtering module of each resource is advantageously configured, in the event of violation of at least one access right of the resource by a transaction, to generate a first error signal. ILAC_SEC, ILAC_PRIV, ILAC_CID representing the violated access right of the resource, and a second error signal ILAC_TRS_SEC, ILAC_TRS_CID ([Fig.4]) representing at least one access right of this transaction TRS_SEC, TRS_CID ([Fig.4]).
[0076] For example, the second error signal TRS_SEC, TRS_CID may be representative of at least one access right other than said violated access right of the ILAC_SEC, ILAC_PRIV, ILAC_CID resource. For example, the second error signal ILAC_TRS_SEC is advantageously representative of at least the security access right of the TRS_SEC transaction. For example, the second error signal ILAC_TRS_CID may also be representative of the compartmentalization access right of the TRS_CID transaction. For example, it may be considered that "the second error signal" contains both the ILAC_TRS_SEC error signal representative of the security access right of the TRS_SEC transaction and the ILAC_TRS_CID error signal representative of the compartmentalization access right of the TRS_CID transaction.
[0077] The mechanism implemented by the RIS filtering module will be described in more detail below in relation to [Fig.4] and Figures 5A-5C.
[0078] The error signals ILAC_SEC, ILAC_PRIV, ILAC_CID, ILAC_TRS_SEC, ILAC_TRS_CID can be communicated to the illegal access management unit IAC.
[0079] From said error signals ILAC_SEC, ILAC_PRIV, ILAC_CID, ILAC_TRS_SEC, ILAC_TRS_CID, the illegal access management unit IAC is advantageously configured to code, in a status register ILAC_STAT_FLG ( [Fig.6]) accessible in read mode by the microprocessor CPU1, digital information (for example on 3 bits) representative of the following cases of violations, which can be accumulated: a violation of the security access rights of a resource FLG_SEC; a violation of the privilege access rights of a resource of a secure environment FLG_PRIV_SEC; and a violation of the privilege access rights of a resource of a non-secure environment FLG_PRIV_NSEC ([Fig.7A]).
[0080] Furthermore, depending on the detected case(s) of violation of the access rights FLG_SEC, FLG_PRIV_SEC, FLG_PRIV_NSEC, the illegal access management unit IAC is advantageously configured to communicate, for example via the interrupt management unit IRQ, a first interruption IT_NSEC to the non-secure environment NSEC of the microprocessor concerned CPU1 / CPU2, and / or a second interruption IT_SEC to the secure environment SEC of the microprocessor concerned CPU1 / CPU2.
[0081] In the case of [Fig.l], the microprocessor concerned is the only microprocessor CPU1 of the system on chip SOC. In the case of [Fig.2], the microprocessor concerned may be the first trusted microprocessor CPU1. In the case of [Fig.3], the affected microprocessor CPU1 / CPU2 may be the one belonging to the CPU_DMN 1 / CPU_DMN2 domain from which the transaction that caused the violation originated or possibly to the TDCID trusted domain.
[0082] Thus, the RIF resource isolation system described above advantageously makes it possible to directly notify the relevant environment of the microprocessor concerned, depending on the particular access rights violation detected.
[0083] In other words, the RIF resource isolation system is capable of developing precise identification information and communicating it to the master entity best qualified to take action and manage the violation, and in particular without systematically having recourse to the secure environment in the privileged state.
[0084] The mechanism implemented by the illegal access management unit IAC will be described in more detail below in relation to [Fig.6] and figures 7A-7B.
[0085] [Fig.4] illustrates an example of one of the RIS filtering modules dedicated to each RES resource, to generate the first error signals ILAC_SEC, ILAC_PRIV, ILAC_CID and the second error signals ILAC_TRS_SEC, ILAC_TRS_CID.
[0086] This example falls in particular, but not necessarily, within the context of a symmetrical multi-core architecture described in relation to [Fig.3].
[0087] On the one hand, the RIF resource isolation system is configured to provide the RIS filtering module with information on the security access right levels RES_SEC, privilege RES_PRIV and compartmentalization RES_CID of the respective RES resource.
[0088] On the other hand, the RIS filtering module can for example be connected between the AHB bus routing the transactions and the RES resource, so as to acquire information on the security access right levels TRS_SEC, privilege TRS_PRIV and compartmentalization TRS_CID of the transactions arriving at this RES resource.
[0089] The RIS filtering module comprises a first logic circuit LOG (SEC), configured to generate the first error signal relating to the security access right ILAC_SEC, in a manner conditioned by the value of the security access right of the resource RES_SEC and by the value of the security access right of the transaction TRS_SEC.
[0090] Reference is made to [Fig.5A] to describe the logic operations of the first logic circuit LOG (SEC).
[0091] The security access rights of the RES_SEC resource and the TRS_SEC transaction may have a value S representing the secure level, or a value NS representing the non-secure level. This value is for example coded on 1 bit.
[0092] The first logic circuit LOG (SEC) is configured according to the truth table of [Fig.5A], that is to say in such a way as to generate at output OUTPT the error signal ILAC_SEC to a first value, for example "1", when the INPT entries communicate that a non-secure level NS TRS_SEC transaction has reached the secure level S RES_SEC resource.
[0093] Furthermore, when the RES resource is a MEM memory, the ILAC_SEC error signal is generated at the first value "1", when the INPT inputs communicate that a TRS_SEC transaction of secure level S has arrived at the RES_SEC resource of non-secure level NS.
[0094] The ILAC_SEC error signal is not generated, or is generated at a second value, for example “0”, in the other possible cases on the INPT input values.
[0095] We refer again to [Fig.4].
[0096] The RIS filtering module comprises a second logic circuit LOG (PRIV), configured to generate the first error signal relating to the privilege access right ILAC_PRIV, in a manner conditioned by the value of the privilege access right of the resource RES_PRIV and by the value of the privilege access right of the transaction TRS_PRIV.
[0097] Reference is made to [Fig.5B] to describe the logic operations of the second logic circuit LOG (PRIV).
[0098] The privilege access rights of the RES_PRIV resource and the TRS_PRIV transaction may have a value P representing the privileged level, or a value NP representing the non-privileged level NS. This value is for example coded on 1 bit.
[0099] The second logic circuit LOG (PRIV) is configured according to the truth table of [Fig.5B], that is to say so as to generate at output OUTPT the error signal ILAC_PRIV at the first value “1”, when the inputs INPT communicate that a transaction TRS_SEC of non-secure level NS has reached the resource RES_SEC of secure level S.
[0100] The ILAC_SEC error signal is not generated, or is generated at the second value “0”, in the other possible cases on the INPT input values.
[0101] We refer again to [Fig.4].
[0102] The RIS filtering module comprises a third logic circuit LOG (CID), configured to generate the first error signal relating to a violation of the ILAC_CID compartmentalization, in a manner conditioned by the compartmentalization identifier of the resource RES_CID and by the compartmentalization identifier of the transaction TRS_CID.
[0103] Reference is made to [Fig.5C] to describe the logic operations of the third logic circuit LOG (CID).
[0104] The second logic circuit LOG (CID) is configured according to the truth table of [Fig.5C], that is to say in such a way as to generate at output OUTPT the error signal ILAC_CID to the first value "1", when the INPT entries communicate that the transaction bucket identifier TRS_CID is not the same as the resource bucket identifier "!=RES_CID".
[0105] The ILAC_CID error signal is not generated, or is generated with the second value "0", when the compartment identifier of the transaction TRS_CID is the same as that of the resource "==RES_CID".
[0106] We refer again to [Fig.4].
[0107] The RIS filtering module is further configured to transfer the value S, or NS, of the security access right of the TRS_SEC transaction to provide the second error signal ILAC_TRS_SEC.
[0108] The RIS filtering module may also be configured to transfer the compartmentalization identifier of the transaction TRS_CID to provide the second error signal ILAC_TRS_CID.
[0109] It will be noted in particular that the RIS filtering module is configured, in the event of violation of the PRIV, NPRIV privilege access rights of the resource by a transaction, to generate the second ILAC_SEC error signal representative of the security access right of this transaction ILAC_TRS_SEC.
[0110] Thus, it will be possible in particular, for example by the illegal access management unit IAC, to distinguish whether a violation of the PRIV / NPRIV privilege access rights occurs in the secure SEC or non-secure NSEC environment.
[0111] It will further be possible to distinguish more specifically whether an illegal transaction in terms of privilege access rights comes from a secure environment.
[0112] Reference is made in this regard to Figures 6 and 7A-7B.
[0113] [Fig.6] illustrates an exemplary embodiment of the resource isolation system RIF, in particular from the IAC illegal access management unit.
[0114] This example falls in particular, but not necessarily, within the context of a symmetrical multi-core architecture described in relation to [Fig.3].
[0115] In this example, the system on chip SOC comprises a number “n” of microprocessors CPU1, CPU2, CPUn and associated domains, each having a respective compartmentalization identifier CPU_CID1, CPU_CID2, CPU_CIDn; and a number “m” of resources RES1, RESm each having a RIS filtering module as described previously in relation to [Fig.4].
[0116] The illegal access management unit IAC receives and processes the first and second error signals ILAC_SEC, ILAC_PRIV, ILAC_CID, ILAC_TRS_SEC, ILAC_TRS_CID coming from all the RIS filtering modules of the different resources RES1 - RESm, in a manner dedicated to each microprocessor domain, for example by illegal access management sub-units IAC1, IAC2, IACn respective to each domain.
[0117] In practice, the illegal access management sub-units IAC1, IAC2, IACn are not necessarily sectorized in the global illegal access management circuit IAC.
[0118] The illegal access management unit IAC may comprise a LOG logic circuit (SEC & PRIV) for managing security and privilege violations, and a LOG logic circuit (CID) for managing compartmentalization violations.
[0119] From said error signals ILAC_SEC, ILAC_PRIV, ILAC_CID, ILAC_TRS_SEC, ILAC_TRS_CID, the illegal access management unit IAC (the logic circuit “LOG (SEC & PRIV)”) is advantageously configured to code, in a status register ILAC_STAT_FLG, digital information (for example on 3 bits) representing at least the following cases of violations, possibly cumulative: a violation of the security access rights of a resource FLG_SEC; a violation of the privilege access rights of a resource of a secure environment FLG_PRIV_SEC; and a violation of the privilege access rights of a resource of a non-secure environment FLG_PRIV_NSEC ([Fig.7A]).
[0120] For example, the status register ILAC_STAT_FLG includes sub-registers respectively dedicated to each of the resources RES1 - RESm. For example, the status register ILAC_STAT_FLG is accessible in read mode by the microprocessor CPU1 - CPUn belonging to the same domain as the illegal access management sub-unit IAC1 - lACn.
[0121] Furthermore, the illegal access management unit IAC is configured to communicate a first interrupt IT_NSEC and / or a second interrupt IT_SEC to the non-secure environment NSEC or secure environment SEC of the microprocessor CPU1, depending on the detected case of violation of the access rights FLG_SEC, FLG_PRIV_SEC, FLG_PRIV_NSEC (see [Fig.7A]).
[0122] The illegal access management unit IAC can more particularly be configured to communicate said first interruption IT_NSEC_CID1 - IT_NSEC_CIDn and said second interruption IT_SEC_CID1 - IT_SEC_CIDn, respectively to the non-secure environment NS and to the secure environment S of the microprocessor CPU 1 - CPUn of the domain corresponding to the transaction in question of the violation.
[0123] As mentioned previously, the interrupts IT_NSEC_CID1 - IT_NSEC_CIDn, IT_SEC_CID1 - IT_SEC_CIDn can be communicated via the AHB bus and via the IRQ interrupt management unit, in particular via respectively non-secure NS and secure S environments of the IRQ interrupt management unit.
[0124] Reference is made to [Fig.7A] to describe the logical operations of the LOG (SEC & PRIV) logic circuit for managing security and privilege violations of the IAC unit.
[0125] Said logic circuit LOG (SEC & PRIV) is configured according to the truth table of the [Fig.7A], that is to say in order to generate two types of outputs OUTPT, from the aforementioned error signals at the input INTP.
[0126] It is recalled that the first ILAC error signals are representative of a violation of the security of the resource if ILAC_SEC=1 and / or a violation of the privilege of the resource if ILAC_PRIV=1.
[0127] It is recalled that one of the second TRS error signals is representative of the security access right of the TRS_SEC transaction, of secure level S if ILAC_TRS_SEC=1 and non-secure NS if ILAC_TRS_SEC=0; and that the other of the second TRS error signals is representative of the compartmentalization identifier of the ILAC_TRS_CID transaction, i.e. the compartmentalization identifier CPU_CIDl-CPU_CIDn ([Fig.6]) of the domain from which this transaction originates.
[0128] On the one hand, the outputs OUTPT of the logic circuit LOG (SEC & PRIV) comprise said digital information from the status register ILAC_STAT_FLG, for example coded on 3 bits, representative of the aforementioned violation cases, that is to say: a violation of the security access rights of a resource if a first bit FLG_SEC is at "1"; a violation of the privilege access rights of a resource of a secure environment if a second bit FLG_PRIV_SEC is at "1"; and a violation of the privilege access rights of a resource of a non-secure environment if a third bit FLG_PRIV_NSEC is at "1".
[0129] On the other hand, the outputs OUTPT of the logic circuit LOG (SEC & PRIV) comprise said first interruption IT_NSEC and said second interruption IT_SEC generated when at the value “1” and communicated to the domain corresponding to the compartmentalization identifier IT_CID communicated in the second error signal ILAC_TRS_CID.
[0130] The first line of the truth table in [Fig.7A] means that no OUTPT output is generated when the compartmentalization identifier of the transaction ILAC_TRS_CID does not correspond to that of the domain “!=CPU_CID” of this lACl-IACn management sub-unit.
[0131] The second line of the truth table in [Fig.7A] means that no OUTPT output is generated when no violation is detected ILAC_SEC=0, ILAC_PRIV=0 for this resource.
[0132] The third line of the truth table of [Fig.7A] means that at OUTPT, the interruption of the non-secure environment is generated IT_NSEC=1 and the status register ILAC_STAT_FLG contains a code representing a violation of the privilege of a non-secure resource FLG_PRIV_NSEC=1; when at INPT, there is a violation of privilege ILAC_PRIV=1 but not of security ILAC_SEC=0, by an unsecured transaction ILAC_TRS_SEC=0.
[0133] The fourth line of the truth table of [Fig.7A] means that at output OUTPT, the secure environment interruption is generated IT_SEC=1 and the status register ILAC_STAT_FLG contains a code representing a violation of the privilege of a secure resource FLG_PRIV_SEC=1; when entering INPT, there is a violation of privilege ILAC_PRIV=1 but not of security ILAC_SEC=0, by a secure transaction ILAC_TRS_SEC=1.
[0134] The fifth line of the truth table of [Fig.7A] means that at output OUTPT, the interruption of the secure environment is generated IT_SEC=1 and the status register ILAC_STAT_FLG contains a code representing a violation of the security of a resource FLG_SEC=1; when input INPT, there is a violation of security ILAC_SEC=1 but no privilege ILAC_PRIV=0, by any security transaction ILAC_TRS_SEC=X.
[0135] The sixth line of the truth table of [Fig.7A] means that at output OUTPT, the interruption of the secure environment is generated IT_SEC=1 and the status register ILAC_STAT_FLG can include a code representing a violation of the security and privilege of a non-secure resource FLG_SEC=1, FLG_PRIV_NSEC=1; when at input INPT, there is a violation of security ILAC_SEC=1 and of privilege ILAC_PRIV=1, by a non-secure transaction ILAC_TRS_SEC=0.
[0136] That being said, in this case in practice, it will be possible not to code the violation of the resource privilege (i.e. FLG_SEC=1, and FLG_PRIV_NSEC=0), to limit the complexity of the information provided. Indeed, it can be considered that a treatment of the security violation is hierarchically superior to a treatment of the privilege violation.
[0137] The seventh line of the truth table of [Fig.7A] means that at output OUTPT, the interruption of the secure environment is generated IT_SEC=1 and the status register ILAC_STAT_FLG contains a code representing a violation of the security and privilege of a secure resource FLG_SEC=1, FLG_PRIV_SEC=1; when input INPT, there is a violation of security ILAC_SEC=1 and privilege ILAC_PRIV=1, by a secure transaction ILAC_TRS_SEC=1.
[0138] That being said, in this case in practice, it will be possible not to code the violation of the resource privilege (i.e. FLG_SEC=1, and FLG_PRIV_SEC=0), to limit the complexity of the information provided. Indeed, here again we can consider that a treatment of the security violation is hierarchically superior to a treatment of the privilege violation.
[0139] For example, in practice, the following three cases can be coded in the ILAC_STAT_FLG status register: - a violation of privilege of an insecure resource (i.e., insecure and unprivileged access to an insecure and privileged resource) with the bit FLG_PRIV_NSEC=1 ; or - a violation of the privilege of a secure resource (i.e., secure, non-privileged access to a secure, privileged resource) with the FLG_PRIV_SEC bit=1; or - a violation of the security of a resource (i.e., unsecured access to a secure resource, such as a peripheral or memory, or secure access to unsecured memory) with the FLG_SEC bit=1.
[0140] We refer again to [Fig.6].
[0141] In the symmetric multi-core system on chip SOC, the first microprocessor CPU 1 may, further and in particular, be termed "trusted" and will be notified of the violation of the access rights relating to the compartmentalization identifiers CID.
[0142] The illegal access management unit IAC comprises in this respect the logic circuit LOG (CID) for managing compartmentalization violations ILAC_CID, and is for example informed of the identification of said trust domain TDCID, by a control circuit RIFSC of the RIF resource isolation system.
[0143] The illegal access management unit IAC (the logic circuit LOG (CID) for managing compartmentalization violations) is configured to communicate a third interruption IT_SEC_CID1 to the microprocessor CPU1 of the first trusted domain TDCID, in the event of detection of a violation of the compartmentalization access rights ILAC_CID. It is advantageously to the secure environment S of the microprocessor CPU1 of the first trusted domain TDCID that the third interruption IT_SEC_CID1 is communicated.
[0144] Reference is made to [Fig.7B] to describe the logical operations of the LOG logic circuit (CID) for managing compartmentalization violations of the IAC unit.
[0145] Said logic circuit LOG (CID) is configured according to the truth table of [Fig.7B], meaning on the one hand that no output OUTPT is generated in the absence of compartmentalization violation ILAC_CID=0 and when the compartmentalization identifier of the management sub-unit CPU_CID does not correspond to that of the trust domain TDCID, “CPU_CID != TDCID”.
[0146] The truth table of [Fig.7B], also means that the third secure environment interruption IT_CID is generated towards the microprocessor CPU1 of the trusted domain TDCID, in the event of detection of a violation of the compartmentalization access rights by a transaction “ILAC_CID=1”, whatever the identifier of this transaction “ILAC_TRS_CID=X”.
[0147] That being said, in the alternatives described previously in relation to [Fig.l] and in relation to [Fig.2], there is in particular no particular condition on the compartmentalization identifier “ILAC_TRS_CID” and all the OUTPT outputs of the logic circuits LOG (SEC & PRIV), LOG (CID) of the access management unit Illegal IACs are communicated to the CPU1 microprocessor of the TDCID trust domain.
[0148] In this regard, reference is made to Figures 8 and 9.
[0149] [Fig.8] illustrates an example of a RES - RIS filtering module for a RES resource, while [Fig.9] illustrates an example of an IAC illegal access management unit; which are particularly suitable in the case of the single-core alternative (with a single microprocessor CPU1) described in relation to [Fig.1], and in the case of the asymmetric multi-core alternative described in relation to [Fig.2].
[0150] It is recalled that these two cases do not take into account any particular condition on the compartmentalization identifier ILAC_TRS_CID and all the OUTPT outputs of the LOG (SEC) LOG (PRIV) logic circuits are communicated to the microprocessor CPU 1 of the (“first”) TDCID trust domain.
[0151] Thus, on the one hand, the RIS filtering module of [Fig.8] comprises the first logic circuit LOG (SEC) configured according to the truth table of [Fig.5A], the second logic circuit LOG (PRIV) configured according to the truth table of [Fig.5B], as described above in relation to [Fig.4], and does not necessarily comprise the third logic circuit LOG (CID). The RIS filtering module is further configured to transfer the value of the security access right of the transaction TRS_SEC to provide the second error signal ILAC_TRS_SEC.
[0152] And, on the other hand, the illegal access management unit IAC of [Fig.9] is configured so that the status register ILAC_STAT_FLG, ILAC_STAT_FLG is accessible in reading by the microprocessor CPU1 of the (“first”) trusted domain TDCID, and contains said digital information representative of said cases of violations relating to all the resources RES1 - RESm of any one of said domains, by a transaction initiated from any one of said domains.
[0153] Furthermore, the illegal access management unit IAC is configured so that said first IT_NSEC interrupt and said second IT_SEC interrupt are always communicated to the microprocessor CPU1 of the ("first") TDCID trust domain.
[0154] In the alternative corresponding to the asymmetric multi-core architecture described previously in relation to [Fig.2], the logical operations of the LOG logic circuit (CID) for managing compartmentalization violations of the IAC unit are also defined by the truth table of [Fig.7B].
[0155] Finally, in the case of figures 1 or 2, a violation of the compartmentalization access right ILAC_CID may nevertheless be detected by the RES - RIS resource filtering module and communicated to the illegal access management unit IAC. The illegal access management unit may in particular be configured, in the event of a violation of the compartmentalization, to generate an IT_SEC interruption to the environment secure of the (“first”) CPU1 microprocessor of the TDCID trust domain.
Claims
Claims
1. System on chip (SOC) comprising: - at least one microprocessor domain (CPU_DMN) comprising a microprocessor (CPU) and at least one resource (RES); and - a resource isolation system (RIF) comprising a filtering module (RIS) for each resource and configured to detect a violation of security access rights (SEC, NSEC), privilege (PRIV, NPRIV), and possibly compartmentalization (CID) of the resource, by transactions arriving at the resource (RES), the filtering module (RIS) being configured, in the event of violation of at least one access right of the resource by a transaction, to generate a first error signal (ILAC_SEC, ILAC_PRIV, ILAC_CID) representative of the violated access right of the resource, and a second error signal (ILAC_TRS_SEC, ILAC_TRS_CID) representative of at least one access right of this transaction (TRS_SEC, TRS_CID).
2. System on chip according to claim 1, wherein the resource isolation system (RIF) further comprises an illegal access management unit (IAC) configured to encode, from the first error signal (ILAC_SEC, ILAC_PRIV, ILAC_CID) and the second error signal (ILAC_TRS_SEC, ILAC_TRS_CID), in a status register (ILAC_STAT_FLG) accessible in read by the microprocessor (CPU), a violation of the security access rights of a resource (FLG_SEC), a violation of the privilege access rights of a resource of a secure environment (FLG_PRIV_SEC), and a violation of the privilege access rights of a resource of a non-secure environment (FLG_PRIV_NSEC).
3. System on chip according to claim 2, wherein the illegal access management unit (IAC) is configured to communicate a first interrupt (IT_NSEC) to a non-secure environment (NSEC) of the microprocessor (CPU), and / or a second interrupt (IT_SEC) to a secure environment (SEC) of the microprocessor (CPU), depending on the detected case of violation of the access rights (FLG_SEC, FLG_PRIV_SEC, FLG_PRIV_NSEC).
4. System on chip according to claim 3, in which the illegal access management unit (IAC) is configured to generate the first interrupt (IT_NSEC) in the event of violation of the access rights of a resource of the non-secure environment (FLG_PRIV_NSEC), and to generate the second interrupt (IT_SEC) in case of violation of access rights of a resource of the secure environment (FLG_SEC, FLG_PRIV_SEC).
5. System on chip according to one of claims 1 to 4, wherein said filtering module (RIS) is configured, in the event of violation of the security access rights (SEC, NSEC) and / or privilege (PRIV, NPRIV) of a resource by a transaction, to generate the second error signal (ILAC_SEC) representative of the security access right of this transaction (ILAC_TRS_SEC).
6. System on chip according to one of claims 1 to 5, comprising the first microprocessor domain (CPU_DMN) and at least one second microprocessor domain (CPU_DMN2), wherein the resources of said first microprocessor domain (CPU_DMN1) and said at least one second microprocessor domain (CPU_DMN2) have respective compartmentalization access rights (CID1, CID2).
7. System on chip according to claim 6 taken in combination with claim 2, the first microprocessor domain (CPU_DMN1) being qualified as trusted (TDCID), in which the illegal access management unit (IAC) is configured to code in the status register (ILAC_STAT_FLG1, ILAC_STAT_FLG2), accessible in reading by the microprocessor (CPU1) of said first trusted domain (TDCID), each of said cases of violation of the access rights (FLG_SEC, FLG_PRIV_SEC, FLG_PRIV_NSEC) of a resource of any one of said domains, by a transaction initiated from any one of said domains.
8. System on chip according to claim 7 taken in combination with claim 3, wherein the illegal access management unit (IAC) is configured to communicate said first interrupt (IT_NSEC) and said second interrupt (IT_SEC) to the microprocessor (CPU1) of said first trust domain (TDCID).
9. System on chip according to claim 6 taken in combination with claim 2, wherein the illegal access management unit (IAC) is configured to code in a status register (ILAC_STAT_FLG1, ILAC_STAT_FLG2) respectively dedicated to each of the domains (CPU_DMN1, CPU_DMN2), accessible in reading by the microprocessor (CPU1, CPU2) of the respective domain, each of said cases of violation of access rights (FLG_SEC, FLG_PRIV_SEC, FLG_PRIV_NSEC) of a resource of any of said domains, by a transaction initiated from said respective domain (CPU_DMN1, CPU_DMN2).
10. System on chip according to claim 9 taken in combination with claim 3, wherein the illegal access management unit (IAC) is configured to communicate said first interrupt (IT_NSEC) and said second interrupt (IT_SEC) to the microprocessor (CPU1, CPU2) of said respective domain.
11. System on chip according to one of claims 6 to 10 taken in combination with claim 2, the first microprocessor domain (CPU_DMN1) being qualified as trusted (TDCID), in which the illegal access management unit (IAC) is configured to communicate a third interrupt (IT_CID) to the microprocessor (CPU) of the first trusted domain (TDCID), in the event of detection of a violation of the compartmentalization access rights (ILAC_CID).
12. System on chip according to one of claims 6 to 10 taken in combination with claim 5, wherein said filtering module (RIS) is configured, in the event of violation of the security access rights (SEC, NSEC) and / or privilege (PRIV, NPRIV) of a resource by a transaction, to generate the second error signal (ILAC_TRS_CID) further representing the compartmentalization access right of this transaction (TRS_CID).
13. Method for managing the isolation of resources of a system on chip (SOC), in which: - the system on chip (SOC) comprises at least one microprocessor domain (CPU_DMN) comprising a microprocessor (CPU) and at least one resource (RES); and - the method comprises, for each resource, a detection of a violation of security access rights (SEC, NSEC), privilege (PRIV, NPRIV), and possibly compartmentalization (CID) of the resource, by transactions arriving at the resource (RES), and, in the event of violation of at least one access right of the resource by a transaction, a generation of a first error signal (ILAC_SEC, ILAC_PRIV, ILAC_CID) representative of the violated access right of the resource, and of a second error signal (ILAC_TRS_SEC, ILAC_TRS_CID) representative of at least one access right of this transaction (TRS_SEC, TRS_CID).
14. The method of claim 13, further comprising encoding, at from the first error signal (ILAC_SEC, ILAC_PRIV, ILAC_CID) and the second error signal (ILAC_TRS_SEC, ILAC_TRS_CID), in a status register (ILAC_STAT_FLG) accessible in read by the microprocessor (CPU), of a violation of the security access rights of a resource (FLG_SEC), of a violation of the privilege access rights of a resource of a secure environment (FLG_PRIV_SEC), and of a violation of the privilege access rights of a resource of a non-secure environment (FLG_PRIV_NSEC).
15. Method according to claim 14, further comprising communicating a first interrupt (IT_NSEC) to a non-secure environment (NSEC) of the microprocessor (CPU), and / or a second interrupt (IT_SEC) to a secure environment (SEC) of the microprocessor (CPU), depending on the detected case of violation of the access rights (FLG_SEC, FLG_PRIV_SEC, FLG_PRIV_NSEC).
16. The method of claim 15, wherein the first interrupt (IT_NSEC) is generated in the event of a violation of the access rights of a resource of the non-secure environment (FLG_PRIV_NSEC), and the second interrupt (IT_SEC) is generated in the event of a violation of the access rights of a resource of the secure environment (FLG_SEC, FLG_PRIV_SEC).
17. Method according to one of claims 13 to 16, in which, in the event of violation of the security access rights (SEC, NSEC) and / or privilege (PRIV, NPRIV) of a resource by a transaction, the second error signal (ILAC_SEC) is representative of the security access right of this transaction (ILAC_TRS_SEC).
18. Method according to one of claims 13 to 17, the system on chip comprising the first microprocessor domain (CPU_DMN) and at least one second microprocessor domain (CPU_DMN2), wherein the resources of said first microprocessor domain (CPU_DMN1) and said at least one second microprocessor domain (CPU_DMN2) have respective compartmentalization access rights (CID1, CID2).
19. Method according to claim 18 taken in combination with claim 14, the first microprocessor domain (CPU_DMN1) being qualified as trusted (TDCID), in which said coding is done in the status register (ILAC_STAT_FLG1, ILAC_STAT_FLG2) accessible in reading by the microprocessor (CPU1) of said first trusted domain (TDCID), for each of said cases of violation of access rights (FLG_SEC, FLG_PRIV_SEC, FLG_PRIV_NSEC) of a resource of any of said domains, by a transaction initiated from any of said domains.
20. Method according to claim 19 taken in combination with claim 15, wherein the communications of said first interrupt (IT_NSEC) and said second interrupt (IT_SEC) are made to the microprocessor (CPU1) of said first trust domain (TDCID).
21. Method according to claim 18 taken in combination with claim 14, wherein said coding is done in a status register (ILAC_STAT_FLG1, ILAC_STAT_FLG2) respectively dedicated to each of the domains (CPU_DMN1, CPU_DMN2), accessible in reading by the microprocessor (CPU1, CPU2) of the respective domain, for each of said cases of violation of the access rights (FLG_SEC, FLG_PRIV_SEC, FLG_PRIV_NSEC) of a resource of any one of said domains, by a transaction initiated from said respective domain (CPU_DMN1, CPU_DMN2).
22. A method according to claim 21 taken in combination with claim 15, wherein the communications of said first interrupt (IT_NSEC) and said second interrupt (IT_SEC) are made to the microprocessor (CPU1, CPU2) of said respective domain.
23. Method according to one of claims 18 to 22 taken in combination with claim 14, the first microprocessor domain (CPU_DMN1) being qualified as trusted (TDCID), further comprising a communication of a third interrupt (IT_CID) to the microprocessor (CPU) of the first trusted domain (TDCID), in the event of detection of a violation of the compartmentalization access rights (ILAC_CID).
24. Method according to one of claims 18 to 22 taken in combination with claim 17, in which, in the event of violation of the security access rights (SEC, NSEC) and / or privilege (PRIV, NPRIV) of a resource by a transaction, the second error signal (ILAC_TRS_CID) is furthermore representative of the compartmentalization access right of this transaction (TRS_CID).