System, device, and method for dynamic allocation
Patent Information
- Application Number
- JP2022184653
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-11-19
- Filing Date
- 2022-11-18
- Publication Date
- 2025-09-29
AI Technical Summary
Existing semiconductor systems face challenges in dynamically allocating resources among software applications developed by different entities, compromising safety and security due to static allocation methods.
A semiconductor device with a system-on-chip architecture implements hardware partitions and logic control circuitry to dynamically allocate shared resources, ensuring secure and separate execution of safety and security applications by using unique transaction identifiers and hardwired logic to manage access and ownership.
This approach ensures secure, reliable allocation of resources, preventing interference between safety and security applications, thereby enhancing the safety and security of the semiconductor system.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical Field]
[0001] Various embodiments relate generally to semiconductor devices that include shared resources. [Background technology]
[0002] A semiconductor system or device including a system-on-chip may include multiple applications that are required to share resources. However, because software application tasks are developed by multiple different entities or companies, using static allocation of resource allocation may be disadvantageous. However, dynamic allocation of resources to application software or software tasks may not be desirable from the perspective of ensuring the safety and security of such a system or device.
[0003] In the drawings, like reference numerals generally refer to the same parts throughout the various views. The drawings are not necessarily drawn to scale, emphasis instead being placed generally on illustrating the principles of the invention. In the following description, various embodiments of the invention are described with reference to the following drawings: [Brief explanation of the drawings]
[0004] [Figure 1] FIG. 1 illustrates a semiconductor device in accordance with at least one example embodiment of the present disclosure. [Figure 2] FIG. 1 illustrates a hardware peripheral device in accordance with at least one example embodiment of the present disclosure. [Figure 3] FIG. 1 is a state diagram of a resource partition in accordance with at least one example embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0005] The following detailed description refers to the accompanying drawings that show, by way of illustration, specific details and embodiments in which the invention may be practiced.
[0006] The word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment or design described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments or designs.
[0007] The terms "plurality" and "multiple" as used herein or in the claims expressly refer to an amount greater than one. The terms "group," "set," "collection," "series," "sequence," "grouping," and the like as used herein or in the claims refer to an amount equal to or greater than one, i.e., one or more. Any term expressed in the plural that does not explicitly state "plurality" or "multiple" similarly refers to an amount equal to or greater than one. The terms "preferred subset," "reduced subset," and "lesser subset" refer to a subset of a set that is not equal to the set, i.e., that contains fewer elements than the set.
[0008] The terms "at least one" and "one or more" may be understood to include quantities equal to or greater than one (e.g., 1, 2, 3, 4 [...], etc.).
[0009] As used herein, unless otherwise specified, the use of ordinal adjectives "first," "second," "third," etc. to describe a common object merely indicates that different instances of the same object are being referred to and is not intended to imply that the objects so described must be in a given order, temporally, spatially, by ranking, or in any other way.
[0010] The term "data" as used herein may be understood to include information in any suitable analog or digital format, for example, provided as a file, a portion of a file, a set of files, a signal or stream, a portion of a signal or stream, a set of signals or streams, etc. Furthermore, the term "data" may be used to mean a reference to information, for example, in the form of a pointer. However, the term data is not limited to the foregoing examples and may take various forms and represent any information as understood in the art.
[0011] The terms "processor" or "processing circuitry," for example, as used herein, may be understood as any kind of entity capable of manipulating data, signals, etc. The data, signals, etc. may be processed according to one or more specific functions that are performed by the processor or controller.
[0012] Thus, a processor or controller may be or include analog circuitry, digital circuitry, mixed-signal circuitry, logic circuitry, processor, microprocessor, central processing unit (CPU), neuromorphic computer unit (NCU), graphics processing unit (GPU), digital signal processor (DSP), field programmable gate array (FPGA), integrated circuit, application specific integrated circuit (ASIC), etc., or any combination thereof. Any other types of implementations of the respective functions, described in further detail below, may also be understood as a processor, controller, or logic circuit. It should be understood that any two (or more) of the processors, controllers, or logic circuits detailed herein may be implemented as a single entity with equivalent functionality or equivalents, and conversely, any single processor, controller, or logic circuit detailed herein may be implemented as two (or more) separate entities with equivalent functionality or equivalents.
[0013] Unless otherwise specified, a "circuit," as used herein, is understood to refer to any type of logic-implemented entity, which may include dedicated hardware. Accordingly, a circuit may be an analog circuit, a digital circuit, a mixed-signal circuit, a logic circuit, an integrated circuit, an application-specific integrated circuit ("ASIC"), etc., or any combination thereof. Any other types of implementations of respective functions, as described in further detail below, may also be understood as a "circuit." It is understood that any two (or more) of the circuits detailed herein may be implemented as a single circuit having substantially equivalent functionality. Conversely, any single circuit detailed herein may be implemented as two (or more) separate circuits having substantially equivalent functionality. Furthermore, references to a "circuit" may refer to two or more circuits that collectively form a single circuit. Sets of elements or other circuits may be described herein, and the term "set" may be interpreted as "one or more."
[0014] As used herein, a "signal" may be transmitted or conducted through a signal chain in which the signal is processed to change characteristics such as phase, amplitude, frequency, etc. A signal may be referred to as the same signal even if such characteristics are adapted. Generally, as long as a signal continues to encode the same information, it can be considered the same signal.
[0015] As used herein, a signal that "indicates" a value or other information may be a digital or analog signal that encodes or otherwise communicates the value or other information in a manner that can be decoded by and / or cause a responsive action in a component receiving the signal. The signal may be stored or buffered in a computer-readable storage medium before being received by the receiving component. The receiving component may retrieve the signal from the storage medium. Furthermore, a "value" that "indicates" some quantity, state, or parameter may be physically embodied as a digital signal, an analog signal, or stored bits that encode or otherwise communicate a value.
[0016] When an element is referred to as being "connected" or "coupled" to another element, it is understood that the element may be physically connected or coupled to the other element such that current and / or electromagnetic radiation (e.g., a signal) can flow along the conductive path formed by the element. Intervening conductive, inductive, or capacitive elements may exist between the elements and the other elements when the elements are described as being coupled or connected to each other. Furthermore, when coupled or connected to each other, one element may be capable of inducing a voltage or current flow or electromagnetic wave propagation in the other element without physical contact or intervening components. Furthermore, when a voltage, current, or signal is referred to as being "applied" to an element, the voltage, current, or signal may be conducted to the element by a physical connection or by capacitive, electromagnetic, or inductive coupling without a physical connection.
[0017] As used herein, "memory" is understood to mean a non-transitory computer-readable medium capable of storing data or information for retrieval. Accordingly, references to "memory" contained herein may be understood to refer to volatile or non-volatile memory, including random access memory (RAM), read-only memory (ROM), flash memory, solid-state storage, magnetic tape, hard disk drives, optical drives, etc., or any combination thereof. Furthermore, registers, shift registers, processor registers, data buffers, etc., are also encompassed by the term memory herein. A single component referred to as "memory" or "a memory" may be comprised of two or more different types of memory and thus may refer to a collective component comprising one or more types of memory. Any single memory component may be separated into multiple collectively equivalent memory components, and vice versa. Furthermore, a memory may be depicted (e.g., in a drawing) as separate from one or more other components, but may be integrated with other components, such as a common integrated chip or a controller having embedded memory.
[0018] The term "software" refers to any type of executable instructions, including firmware.
[0019] Exemplary embodiments of the present disclosure may be realized by one or more computers (e.g., computing devices, processors, processor cores, etc.) reading and executing computer-executable instructions recorded on a storage medium (e.g., a non-transitory computer-readable storage medium) to perform one or more functions of the embodiments of the present disclosure described herein. The computer may include one or more central processing units (CPUs), microprocessing units (MPUs), or other circuits, and may include separate computers or a network of separate computer processors. The computer-executable instructions may be provided to the computer, for example, from a network or a non-volatile computer-readable storage medium. The storage medium may include, for example, one or more of a hard disk, random access memory (RAM), read-only memory (ROM), storage in a distributed computing system, an optical drive (compact disc (CD), digital versatile disc (DVD), or Blu-ray disc (BD)), a flash memory device, a memory card, etc. For illustrative purposes, specific details and embodiments in which the present invention may be practiced are provided.
[0020] As used herein, unless otherwise specified, the use of ordinal adjectives "first," "second," "third," etc. to describe a common object merely indicates that different instances of similar objects are being referred to and is not intended to imply that the objects so described must be in a given order, temporally, spatially, by ranking, or in any other way.
[0021] The terms "semiconductor substrate" or "semiconductor die" are defined to mean any structure containing semiconductor material, such as a silicon substrate with or without an epitaxial layer, a silicon-on-insulator substrate with a buried insulator layer, or a substrate with a silicon germanium layer. The term "integrated circuit," as used herein, refers to an electronic circuit having multiple individual circuit elements, such as transistors, diodes, resistors, capacitors, inductors, and other active and passive semiconductor devices. Conductive regions formed within and / or on a semiconductor substrate or die are part of a conductive path and have exposed surfaces that can be treated by a planarization process, such as chemical-mechanical polishing. Suitable materials for conductive regions can include, but are not limited to, copper, aluminum, copper alloys, or other mobile conductive materials. A copper interconnect level can be the first or any subsequent metal interconnect level of a semiconductor device.
[0022] 1 includes a diagram illustrating an example of a semiconductor device 100. The semiconductor device may be a semiconductor chip, such as a single semiconductor chip that includes multiple hardware components configured to run or perform various tasks or applications. Additionally, the semiconductor chip may be implemented as a system-on-chip, i.e., the entire system 100 may be implemented on a single or common semiconductor substrate.
[0023] Semiconductor device 100 may include multiple processor cores designated 110a through 110N (where N is any number). Device 100 may include multiple hardware peripheral devices. As shown in FIG. 1, device 100 includes a direct memory access (DMA) controller 120, an interrupt router 130, a memory or memory device 140, and other hardware peripherals designated 150a through 150M.
[0024] Additionally, device 100 may include a system interconnect 160 that couples to all or some of the components and enables the components to communicate with each other. System interconnect 160 may be configured to distinguish between various components, such as distinguishing signals or communications between different cores 110. Thus, signals or communications from different types or kinds of software applications may also be distinguished using system interconnect 160.
[0025] Although not shown in FIG. 1, other connections between components of device 100 may be implemented.
[0026] According to an exemplary embodiment of the present invention, semiconductor device 100 may be a system-on-chip configured to implement or execute multiple applications. More specifically, one or more processor cores 110a-110N or processor core 110 may execute or implement applications. Processor core 110 may execute program instructions, which may be stored on memory 140 or other suitable components, to execute the multiple applications.
[0027] In some cases, semiconductor device 100 may implement safety-related applications that may be designed to operate in accordance with one or more safety standards or protocols. Additionally, device 100 may also implement security-based or security-related applications. Security-related applications may include or implement software tasks such as authentication, encryption, and key provisioning, to name a few.
[0028] Different types of software applications (e.g., safety and security-related applications) implemented by device 100 may be developed by different entities or companies. Therefore, the software applications may not be trusted in the sense that they are designed to work in conjunction with one another when executed by core 110 on device 100. Multiple applications running on device 100 may require access to and use some of the same resources, such as interrupt routers, DMA, etc., in order to perform the intended functions of the applications and device 100. The hardware of embodiments of the present invention allows multiple software applications to control shared hardware resources without requiring a comprehensive hardware or software instance that can allocate and control the resources. In cases where a single hardware or software instance cannot control different groups of software applications, the proposed hardware allows resources to be allocated accurately and reliably without the need for such a common allocation agent.
[0029] According to at least one example embodiment of the present disclosure, applications executing or running on the processor core 110 of the semiconductor device 100 may be considered to be different groups. In one example, software applications are grouped into security / non-security applications or security applications. Accordingly, the semiconductor device 100 may be configured to allow security software applications to be free from interference from security software applications, and vice versa. Security applications may not be developed according to the same security standards and may further be configured such that security application software tasks must guarantee confidentiality, integrity against interference, and the ability to prevent spoofing from non-security application software tasks not developed according to the same security standards. That is, the semiconductor device 100 may operate to protect one group of applications from interference with another group of applications, and vice versa, particularly with respect to shared resources.
[0030] In at least one exemplary embodiment, different grouped applications or assigned software agents described herein may be executed or implemented separately from one another, e.g., implemented in separate partitions. Hardware partitions can be realized or implemented in multiple ways. A hardware partition can reflect or correspond to a division of the hardware that implements the applications. In some cases, a partition may be a virtual machine implemented by core 110. That is, core 110 can execute a hypervisor to implement multiple virtual machines. A virtual machine can execute or implement multiple software applications. One group of software applications / agents (e.g., safety applications) can execute on a different virtual machine than a virtual machine that executes another group of software applications / agents (e.g., security applications).
[0031] In another example, cores 110 may be partitioned or used in a partitioned manner, where one or more cores may execute (only) one group of software applications (e.g., safety applications), and another different group of one or more cores 110 may execute (only) another group.
[0032] In yet another case, division may be implemented within core 110. A single core 110 may be divided into multiple (e.g., logical) partitions. Furthermore, one or more partitions may be configured to run only software applications or agents from a particular group (e.g., safety), while another or different one or more partitions may be configured to run only software applications / agents from another group of software applications / agents (e.g., security).
[0033] Additionally, device 100 may be partitionable to ensure freedom from interference between groups of applications, such as safety and security applications, for one or more of the system or device peripherals, e.g., DMA, interrupt router, etc. That is, some resources of the device peripherals may be partitioned and allocable, at least temporarily, to specific applications or components.
[0034] 2 is a diagram of an exemplary electronic hardware circuit device 200. Referring to FIG. 1, the electronic hardware circuit device 200 may be a DMA 120, an interrupt router 130, or any other suitable peripheral device. The peripheral device or electronic hardware circuit device 200 may be a hardware system device that includes divisible resources. The electronic hardware circuit device 200 may include an interface 210, such as a slave interface, for communicating with other components.
[0035] 2, the resources 240 of the electronic hardware circuit device 200 may be divided into, for example, up to N resource partitions (RPs). Each resource or resource partition may be a hardware circuit component or circuit of the electronic hardware circuit device 200 configured to interface with the execution engine 260 or execution aspect of the electronic hardware circuit device 200. Each resource partition may have a configuration that indicates or instructs how the resource partition interfaces with the execution engine 260. The configuration may specify how data received by the partition should be used with the execution engine.
[0036] Resources or resource partitions RP 240 can be selectively or dynamically allocated to software applications, for example. An assigned software application can be referred to as or considered to be the owner of a resource partition (RP). An application owner can use a resource partition to accomplish one or more software tasks. For example, an application can modify or specify the configuration of a resource partition. Thus, resource partition 240 can include storage element components, such as registers, that can indicate the configuration. Additionally, the storage elements can indicate whether an application is assigned, and if assigned, can indicate its owner, or can indicate that it is unassigned.
[0037] Logic and control circuitry 220 may be responsible for controlling access and dividing and assigning ownership to hardware resource partitions 240. Additionally, logic and control circuitry 220 may be responsible for controlling access to hardware resources or may be configured to control access to hardware resources. For example, logic and control circuitry 220 may be configured to provide or deny access to one or more of a plurality of hardware resources.
[0038] Logic control circuitry 220 may be hardwired electronic components. In other words, logic control circuitry 220 may be implemented as permanent physical components, but its operation cannot be electronically reconfigured or reprogrammed. Thus, the operations or rules that govern how logic control circuitry 220 operates are hardwired into the physical circuit components (e.g., transistors) and cannot be changed.
[0039] Each resource or resource partition may be associated with or include an allocation state. In one example, the allocation state or allocation state data may indicate whether the resource or resource partition is allocated (e.g., to an owner) or unallocated (e.g., free). The allocation state or allocation state data may further indicate the owner of each allocated resource partition. The allocation state data for each resource partition may be stored in any suitable format, such as stored in one or more registers.
[0040] Initially, or after a reset performed by the hardware electronics device, the resource allocation state of each of the resources or resource partitions may be updated or changed to unallocated. For example, logic and control circuitry 220 may be configured to change the allocation state or resource allocation state to unallocated in response to a system reset.
[0041] According to an example embodiment of the present disclosure, logic control circuitry 220 may be configured to write or specify resource allocation states. In response to a reset (e.g., initiated by semiconductor device 200), for example, logic control circuitry 220 may set or change the resource allocation state of each of the resource partitions to unallocated (e.g., no owner).
[0042] Additionally, logic and control circuitry 220 may be configured to set or specify resource allocation states in response to requests, instructions, or communications from authorized entities. For example, logic and control circuitry 220 may be configured to modify an unallocated resource partition to be allocated to a particular owner in response to a request, instruction (e.g., a signal) from an authorized entity, application, or agent.
[0043] In at least one exemplary embodiment of the present disclosure, system 100 may implement agents, e.g., software or master allocation agents, configured to assign owners to unassigned or unallocated resources / resource partitions of electronic hardware circuit device 200, e.g., using logic control circuitry 220. These allocation agents may be implemented or executed by one or more cores 110, and may be split or separated, e.g., into separate cores, virtual machines, etc., as described above.
[0044] The logic control circuitry 220 of the electronic hardware circuit device 200 can be configured to only allow these allocation agents to allocate or map unallocated resource partitions 240 to designated owners, e.g., software applications. The core 110 can execute multiple allocation software agents, each configured to allocate hardware resources or resource partitions 240 to applications belonging to a particular group or type of application. That is, the allocation agents can be restricted or configured to assign only one type or group of applications to an unallocated resource partition 240. The system interconnect 160 can be configured to provide communications or requests (e.g., in the form of signals) to enable the electronic hardware circuit 200 and the logic control circuitry 220 to distinguish between different types of applications of different software agents.
[0045] In at least one instance, the system interconnect 160 can provide communications or requests from specific applications or cores 110 on specific or predefined connections. These connections can be configured so that communications are provided to specific or known port inputs of the electronic hardware circuit device 200. As a result, the electronic hardware circuit device 200 can recognize the component or core from which the request or communication originated. This information can be useful for verifying the originator of the request or communication, such as whether it came from a group to which the application or software agent belongs. For example, a request received on a specific input can be recognized as coming from a specific software agent (e.g., a security software agent).
[0046] Additionally, requests or communications (e.g., signals) by each type of application or software agent may include identification information or transaction identification information (TAG-ID). The TAG-ID may also be used by the electronic hardware circuit device 200 to verify / identify the type or specific software agent interacting with or requesting access to the electronic hardware circuit device 200. Based on such verification or identification, the electronic hardware circuit device 200 provides access. The TAG-ID may be uniquely assigned to the software application or agent. Note that the TAG-ID may be assigned statically or dynamically in other cases.
[0047] Thus, the TAG-ID provides or can be a mapping between hardware, such as a core, a virtual machine, an application, or an agent, and a hardware resource partition (RP).
[0048] In at least one example, device 100 may implement a security software / master agent and a non-security or safety software / master agent that may be executed by core 110. Additionally, core 110 may also execute multiple applications that may be categorized or identified as either security applications or non-security / safety applications. Logic control circuitry 220 may obtain / receive requests or instructions, e.g., in the form of signals, from each of the master agents. Despite reset, logic in logic control circuitry 220 may only allow these authorized software agents to allocate or assign unallocated resource partitions to applications. That is, logic control circuitry 220 may only allow security software agents and non-security / safety software agents, respectively, to assign owners to unallocated hardware resources. Furthermore, logic in logic control circuitry 220 may only allow or ensure that security and non-security software agents are used to assign unallocated resource partitions to their respective groups. The TAG-ID may be used by logic control circuitry 220 to implement logic or rules.
[0049] In response to a valid command or request from the software agent, logic control circuitry 220 updates the resource allocation state of the unallocated resource to reflect the valid ownership assignment. Thus, the resource allocation state of a previously unallocated resource partition is updated by logic control circuitry 220 to "allocated," and the owner of the resource partition is further designated. Additionally, a resource owner transaction identification or "RP owner TAG-ID" may be specified in the request to identify the assigned owner and may also indicate the group or type of application that is the allocator or application owner of the resource partition.
[0050] After a resource partition is assigned, logic and control circuitry 220 uses the allocation status data to control further access to the resource partition. Specifically, after a resource partition is assigned, logic and control circuitry 220 may only allow designated application owners to control or interface with the resource partition. In particular, logic and control circuitry 220 may only allow designated or assigned application owners to relinquish the resource partition. That is, logic and control circuitry 220 is configured to only accept requests or commands from assigned application owners to release the resource partition and change its allocation status to unallocated.
[0051] The logic and control circuitry 220 may be further configured to only allow assigned owners to access the resource partition 240. In one example, the logic and control circuitry 220 may be configured to allow a currently assigned resource owner to grant or relinquish ownership of the currently assigned resource. That is, the logic and control circuitry 220 may release and change the resource allocation state to unallocated only in response to a request or command (e.g., a signal) sent from an owner (e.g., an application owner) of the assigned resource partition. No other component or application is authorized to unallocate the resource partition. In such a case, a resource release request (a request to change the allocation state to “unallocated”) or attempt (e.g., a request by an application not designated as the owner) by an unauthorized component is denied or ignored by the logic and control circuitry 220.
[0052] An application designated as an assigned owner of a resource partition can access and configure the resource partition through logic circuitry 220. For example, an application owner can configure or specify data movement or how data provided to a resource partition is processed or utilized by electronic hardware circuitry 200. Each resource partition 240 can access (through crossbar 250) an execution engine 260 of electronic hardware circuitry 200.
[0053] The execution engine 260 can execute specific tasks or processes according to the configuration specified in the resource partition. For example, if the electronic hardware circuit device 200 is a DMA controller, the execution engine can be configured to execute a DMA controller task. If the electronic hardware circuit device 200 is an interrupt controller, the execution engine can be configured to execute a specific interrupt routine.
[0054] Resource partitions 240 may individually access execution engines 260 in a time-sliced manner, for example, using crossbar switch component 250. Other peripheral devices are possible, and electronic hardware circuit device 200 may be adapted or modified to operate in accordance with embodiments described herein.
[0055] In various examples, semiconductor device 100 has been described as implementing two application groups, e.g., security applications and non-security applications, but this is merely exemplary as the number or type of application groups and corresponding assigned software agents may vary.
[0056] 3 illustrates a state diagram 300 depicting the possible states of a resource partition (RP) of an electronic hardware circuit device described herein. In the example of FIG. 3, the resource partition (RP) may operate within a semiconductor device, such as semiconductor device 100. Accordingly, the semiconductor device includes core 110 that implements multiple software applications. In this example, the software applications are one of two different application groups or types: security applications or non-security applications.
[0057] Additionally, core 110 implements two allocation software agents: a security allocation software agent and a non-security allocation software agent. As shown, upon an initial or reset event 310, a resource partition (RP) transitions to an unallocated state 320, becoming unallocated with no owner. In the unallocated state 320, the RP can transition to one of two possible states. In one case, transition 330 occurs when the non-security allocation software agent assigns a non-security application as the owner of the resource partition RP. Thus, the RP transitions to a non-security assigned state 350. In the other case, transition 340 occurs when the security allocation software agent assigns a security application as the owner of the resource partition RP. Thus, the RP transitions to a security assigned state 360. As shown and described in the embodiments herein, each allocation software agent can only assign applications that belong to a particular group of applications. In this example, the non-security allocation software agent can only assign non-security software applications as owners of the resource partition RP, and the security allocation software agent can only assign security software applications as owners of the resource partition RP.
[0058] A resource partition RP remains in an assigned state, e.g., either the non-security assigned state 350 or the security assigned state 360, until the currently assigned application owner relinquishes or abandons ownership, as described in embodiments herein. Transition 370 occurs when the current resource partition owner, a non-security application, relinquishes ownership. Thus, the resource partition transitions from the non-security assigned state 350 back to the unallocated state 320. Similarly, transition 380 occurs when the current resource partition owner, a security application, relinquishes ownership. Thus, the resource partition transitions from the non-security assigned state 360 back to the unallocated state 320.
[0059] In other cases, the state diagram 300 may be suitably modified, mutatis mutandis, for different variations of semiconductor devices, and the number of application groups and assigned software agents may be changed, e.g., increased, mutatis mutandis.
[0060] The following examples relate to further aspects of the present disclosure.
[0061] Example 1 is a semiconductor chip, a plurality of hardware resources, each of which includes a corresponding resource allocation state indicating whether the respective hardware resource is allocated or unallocated, and if allocated, indicating an assigned application owner; Controlling access to the plurality of hardware resources; and providing or denying access to one or more of the plurality of hardware resources based on a resource allocation state of each of the hardware resources; assigning the resource allocation state for each of the hardware resources based on input from one or more authorized agents; a logic control circuit configured as follows: At least one electronic hardware circuit device comprising: a memory containing program instructions; at least one processor core coupled to the memory and coupled to the at least one electronic hardware circuit device; wherein the at least one processor executes the program instructions to implementing a plurality of software applications belonging to a first group or a second group, each of the plurality of applications configured to access and interact with at least one corresponding hardware resource allocated to the respective application; implementing a first allocation software agent authorized and configured to cause the electronic hardware circuit device to allocate one or more unallocated hardware resources only to one or more software applications belonging to the first group; implementing a second allocation software agent authorized and configured to cause the electronic hardware circuit device to allocate one or more unallocated hardware resources only to one or more applications belonging to the second group; and wherein, for each allocated hardware resource, the logic control circuitry is a semiconductor chip further configured to enable a requesting software application to cause relinquish ownership of the allocated hardware resource only if the requesting software application is the currently allocated application of the hardware resource.
[0062] Example 2 is the subject matter of Example 1, wherein the first allocation software agent and the second allocation software agent may be implemented on separate partitions by the at least one processor core.
[0063] Example 3 is the subject matter of Example 2, wherein at least one processor core may be configured to implement multiple virtual machines; The first allocation software agent and the second allocation software agent implemented on separate partitions include the first allocation software agent implemented on a first virtual machine of the plurality of virtual machines and the second allocation software agent implemented on a second virtual machine of the plurality of virtual machines.
[0064] Example 4 is the subject matter of Example 2, wherein the at least one processor core may include multiple processor cores; The first allocation software agent and the second allocation software agent implemented on separate partitions include the first allocation software agent being implemented on a first processor core of the plurality of processor cores and the second allocation software agent being implemented on a second processor core of the plurality of processor cores.
[0065] Example 5 is the subject matter of Example 2, wherein the first allocation software agent and the second allocation software agent may be implemented on a single processor core, the single processor core including multiple processor partitions; The first allocation software agent is implemented on a first processor partition of the plurality of processor partitions, and the second allocation software agent is implemented on a second processor partition of the plurality of processor partitions.
[0066] Example 6 is the subject matter of any of Examples 2 to 5, wherein the software applications belonging to the first group and the applications belonging to the second group may each be implemented on separate partitions provided by the at least one core.
[0067] Example 7 is the subject matter of any of the preceding examples, wherein the logic control circuitry may be configured to only allow the first allocation software agent to allocate one or more of the unallocated hardware resources to one or more of a plurality of software applications belonging to the first group, and may be configured to only allow the second allocation software agent to allocate one or more of the unallocated hardware resources to one or more of a plurality of software applications belonging to the second group.
[0068] Example 8 is the subject matter of any of the preceding examples, wherein the first allocation software agent and second allocation software agent may each be configured to request access to one or more of the unallocated hardware resources using one or more unique transaction identification codes to allocate the unallocated resources of the electronic hardware circuit device.
[0069] Example 9 is the subject matter of any of the preceding examples, wherein the logic control circuitry may be configured to provide the first allocating software agent or the second allocating software agent access to the one or more of the unallocated hardware resources by verifying the one or more unique transaction identification codes provided by the first allocating software agent or the second allocating software agent.
[0070] Example 10 is the subject matter of Example 8 or 9, wherein the one or more unique transaction identification codes may indicate a mapping of the first assigned software agent or the second assigned software agent to one or more partitions implemented by the at least one processor core.
[0071] Example 11 is the subject matter of any of the preceding examples, wherein, for each allocated hardware resource, the logic control circuitry can be further configured to allow only a corresponding currently assigned software application to access the hardware resource.
[0072] Example 12 is the subject matter of any of the preceding examples, wherein, for each allocated hardware resource, the corresponding application may be configured to access the allocated hardware resource by providing one or more unique transaction identification codes that identify the application, and the logic control circuitry is configured to validate the corresponding software application based on the one or more transaction identification codes to provide access to the allocated hardware resource.
[0073] Example 13 is the subject matter of any of the preceding examples, wherein, for each allocated hardware resource, the logic control circuitry can be further configured to allow only a corresponding currently allocated software application to specify data movement or processing configuration within the hardware resource.
[0074] Example 14 is the subject matter of any of the preceding examples, wherein the at least one electronic hardware circuit device can include multiple execution engines, each execution engine including circuitry to perform one or more tasks.
[0075] Example 15 is the subject matter of Example 14, wherein each of the hardware resources is coupled to the execution engine in a time-sliced manner and can be configured to form an interface with the execution engine.
[0076] Example 16 is the subject matter of any of the preceding examples, wherein the at least one electronic hardware circuit device can further include an interrupt controller, and the hardware resource includes a plurality of interrupts.
[0077] Example 17 is the subject matter of any of the previous examples, wherein the at least one electronic hardware circuit can include a direct memory access (DMA) controller, and the hardware resources can include multiple DMA channels.
[0078] Example 18 is the subject matter of any of the previous examples, wherein each of the hardware resources includes one or more registers indicating its respective resource allocation state and indicating its respective data configuration.
[0079] Example 19 is the subject matter of any of the previous examples and can further include a system interconnect coupled to the at least one electronic hardware circuit, the memory, and the at least the processor core.
[0080] Example 20 is the subject matter of Example 19, wherein the system interconnect can be configured to provide a connection between the electronic hardware circuit device and the at least one core such that the electronic hardware circuit device distinguishes between communications from the first allocation software agent and communications from the second allocation software agent.
[0081] Example 21 is the subject of any of the previous examples, wherein the logic control circuitry can be a hardwired hardware component.
[0082] Example 22 is the subject of any of the previous examples, wherein the semiconductor chip can be a system-on-chip design chip.
[0083] Example 23 is the subject matter of any of the preceding examples, wherein the at least one software application in the first group is a security-related software application configured to perform one or more security-related software tasks.
[0084] Example 24 is the subject matter of any of the previous examples, wherein at least one software application of the second group is a safety-related software application implemented in accordance with one or more predetermined safety standards.
[0085] Example 25 is the subject matter of any of the preceding examples, wherein the at least one electronic hardware circuit device is configured to perform a reset of the hardware resources to cause the resource allocation state of each of the hardware resources to be unallocated.
[0086] Example 26 is a non-transitory computer-readable medium including instructions configured to be executed by at least one processor of at least one electronic hardware circuit device comprising: a plurality of hardware resources, each divisible hardware resource including a corresponding resource allocation state, the corresponding resource allocation state indicating whether the respective hardware resource is allocated or unallocated and, if allocated, indicating an assigned application owner; and logic control circuitry configured to control access to the plurality of hardware resources and to provide or deny access to one or more of the plurality of hardware resources based on the resource allocation state of each of the hardware resources, and to designate the resource allocation state for each of the hardware resources based on input from one or more authorized agents, wherein the instructions, when executed, cause the at least one processor of the at least one electronic hardware circuit device to perform a first and implementing a plurality of software applications belonging to a first group or a second group, each of the plurality of applications configured to access and interact with at least one corresponding hardware resource allocated to the respective application; implementing a first allocation software agent authorized and configured to cause the electronic hardware circuit device to allocate one or more unallocated hardware resources only to one or more of the software applications belonging to the first group; and implementing a second allocation software agent authorized and configured to cause the electronic hardware circuit device to allocate one or more unallocated hardware resources only to one or more of the applications belonging to the second group, wherein for each allocated hardware resource, the logic control circuitry performs the following steps only if the requesting software application is the currently assigned application of the hardware resource:and further configured to enable the requesting software application to cause a relinquishment of ownership of the allocated hardware resource.
[0087] It should be noted that one or more features of any of the above examples may be suitably or appropriately combined with any one of the other examples.
[0088] It will be understood by those skilled in the art that the foregoing description has been used by way of example only and that modifications may be made without departing from the broader spirit or scope of the invention as set forth in the claims. The specification and drawings are, accordingly, to be regarded in an illustrative rather than a restrictive sense.
[0089] The scope of the disclosure is, therefore, indicated by the appended claims and all changes that come within the meaning and range of equivalency of the claims are intended to be embraced therein.
[0090] It should be understood that implementations of the methods detailed herein are demonstrative in nature and, therefore, can be implemented in corresponding devices. Similarly, it should be understood that implementations of the devices detailed herein can be implemented as corresponding methods. Thus, it should be understood that devices corresponding to the methods detailed herein can include one or more components configured to perform each aspect of the associated method.
[0091] All acronyms defined in the above description are further retained in all claims contained herein.
Claims
1. A semiconductor chip, the semiconductor chip comprising: at least one electronic hardware circuit device; a memory containing program instructions; at least one processor core coupled to said memory and said at least one electronic hardware circuit device; Equipped with said at least one electronic hardware circuit device; Multiple hardware resources and a logic control circuit for controlling access to the plurality of hardware resources; Equipped with The plurality of hardware resources are divisible, each hardware resource including a corresponding resource allocation state, the corresponding resource allocation state indicating whether the respective hardware resource is allocated or unallocated, and if allocated, indicating an assigned application owner; The logic control circuit includes: providing or denying access to one or more of the plurality of hardware resources based on a resource allocation state of each of the hardware resources; assigning the resource allocation state for each of the hardware resources based on input from one or more authorized agents; It is structured as follows: The at least one processor core executes the program instructions to implementing a plurality of software applications belonging to a first group or a second group, each of the plurality of software applications configured to access and interact with at least one corresponding hardware resource allocated to the respective software application; implementing a first allocation software agent authorized and configured to cause the electronic hardware circuit device to allocate one or more unallocated hardware resources only to one or more software applications belonging to the first group; implementing a second allocation software agent authorized and configured to cause the electronic hardware circuit device to allocate one or more unallocated hardware resources only to one or more of the software applications belonging to the second group; and For each allocated hardware resource, the logic control circuitry is further configured to allow a requesting software application to cause relinquish ownership of the allocated hardware resource only if the requesting software application is the currently allocated software application of the hardware resource. Semiconductor chip.
2. the first allocation software agent and the second allocation software agent are implemented on separate partitions by the at least one processor core; The semiconductor chip according to claim 1.
3. the at least one processor core is configured to implement multiple virtual machines; the first allocation software agent and the second allocation software agent implemented on separate partitions include a first allocation software agent implemented on a first virtual machine of the plurality of virtual machines and a second allocation software agent implemented on a second virtual machine of the plurality of virtual machines; The semiconductor chip according to claim 2.
4. the at least one processor core includes a plurality of processor cores; the first allocation software agent and the second allocation software agent implemented on separate partitions include the first allocation software agent being implemented on a first processor core of the plurality of processor cores and the second allocation software agent being implemented on a second processor core of the plurality of processor cores; The semiconductor chip according to claim 2.
5. the first allocation software agent and the second allocation software agent are implemented on a single processor core, the single processor core including multiple processor partitions; the first allocation software agent is implemented on a first processor partition of the plurality of processor partitions, and the second allocation software agent is implemented on a second processor partition of the plurality of processor partitions. The semiconductor chip according to claim 2.
6. the software applications belonging to the first group and the software applications belonging to the second group are implemented on separate partitions provided by the at least one processor core, respectively; The semiconductor chip according to claim 2.
7. the logic control circuitry is configured to enable the first allocation software agent to allocate one or more of the unallocated hardware resources to only one or more of the software applications belonging to the first group, and to enable the second allocation software agent to allocate one or more of the unallocated hardware resources to only one or more of the software applications belonging to the second group; The semiconductor chip according to claim 1.
8. the first allocation software agent and the second allocation software agent are each configured to request access to one or more of the unallocated hardware resources using one or more unique transaction identification codes to allocate the unallocated resources of the electronic hardware circuit device; The semiconductor chip according to claim 1.
9. the logic control circuitry is configured to provide the first or second allocating software agent with access to the one or more of the unallocated hardware resources by verifying the one or more unique transaction identification codes provided by the first or second allocating software agent; The semiconductor chip according to claim 1.
10. the one or more unique transaction identification codes indicate a mapping of the first assigned software agent or the second assigned software agent to one or more partitions implemented by the at least one processor core; 10. The semiconductor chip according to claim 8.
11. and for each allocated hardware resource, the logic control circuitry is further configured to allow only the corresponding currently allocated software application to access the hardware resource. The semiconductor chip according to claim 1.
12. for each allocated hardware resource, the corresponding software application is configured to access the allocated hardware resource by providing one or more unique transaction identification codes that identify the software application; the logic control circuitry is configured to validate the corresponding software application based on the one or more transaction identification codes to provide access to the allocated hardware resource. The semiconductor chip according to claim 1.
13. and for each allocated hardware resource, the logic control circuitry is further configured to allow only a corresponding currently allocated software application to specify data movement or processing configuration within the hardware resource. The semiconductor chip according to claim 1.
14. the at least one electronic hardware circuit device includes a plurality of execution engines, each execution engine including circuitry for performing one or more tasks; The semiconductor chip according to claim 1.
15. each of the hardware resources is coupled to the execution engine in a time-slice manner and configured to form an interface with the execution engine; The semiconductor chip according to claim 14.
16. the at least one electronic hardware circuit device includes an interrupt controller; the hardware resources include a plurality of interrupts; The semiconductor chip according to claim 1.
17. the at least one electronic hardware circuit device includes a direct memory access (DMA) controller; the hardware resources include multiple DMA channels; The semiconductor chip according to claim 1.
18. each of said hardware resources includes one or more registers indicating its respective resource allocation state and indicating a respective data configuration; The semiconductor chip according to claim 1.
19. the semiconductor chip further includes a system interconnect coupled to the at least one electronic hardware circuit device, the memory, and the at least one processor core; The semiconductor chip according to claim 1.
20. the system interconnect is configured to provide a connection between the electronic hardware circuit device and the at least one processor core for the electronic hardware circuit device to distinguish between communications from the first assignment software agent and communications from the second assignment software agent.
20. The semiconductor chip of claim 19.
21. the logic control circuit is a hardwired hardware component; The semiconductor chip according to claim 1.
22. The semiconductor chip is a system-on-chip design. The semiconductor chip according to claim 1.
23. the at least one software application of the first group is a security-related software application configured to perform one or more security-related software tasks; The semiconductor chip according to claim 1.
24. at least one software application of the second group is a safety-related software application implemented in accordance with one or more predetermined safety standards; The semiconductor chip according to claim 1.
25. the at least one electronic hardware circuit device is configured to perform a reset of the hardware resources to cause the resource allocation status of each of the hardware resources to become unallocated. The semiconductor chip according to claim 1.