Integrated circuits, resource access control methods, equipment, and media
The integrated circuit with a resource access control device addresses the challenge of varying security levels in multi-OS systems by authenticating and authorizing access requests, enhancing security and performance in vehicle functions.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- XG TECHNOLOGIES PTE LTD
- Filing Date
- 2025-04-30
- Publication Date
- 2026-05-15
AI Technical Summary
In scenarios where multiple operating systems run on a single chip to implement driving-related and intelligent cockpit functions, different functions have different security level requirements, necessitating effective control of resource access to ensure corresponding functional safety and information security.
An integrated circuit with a resource access control device that authenticates and authorizes access requests from hardware modules based on pre-configured access and security control information, ensuring that only authorized parties with appropriate operational rights can access resources, thereby preventing unauthorized access and data leakage.
This approach enhances the security of functions with high security requirements by preventing unauthorized access, avoiding data leakage, and reducing resource contention, thus ensuring real-time performance and functional security.
Smart Images

Figure 2026079683000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to computer technology and security technology, and in particular, to integrated circuits, resource access control methods, equipment, and media.
Background Art
[0002] With the development of chip technology and autonomous driving technology, vehicles can provide increasingly rich driving-related functions and intelligent cockpit functions. With the continuous improvement of the computing power of intelligent driving chips, it is possible to execute multiple operating systems (Operating System, OS) on one chip (i.e., a single chip) to centrally realize the driving-related functions and intelligent cockpit functions of the vehicle, realize chip resource sharing, improve the multiplexing efficiency of the chip and peripheral circuits, and help reduce the overall cost of the chips in the vehicle cockpit.
[0003] In vehicle driving-related functions, different functions may have different requirements for security levels. In the scenario of executing multiple operating systems on a single chip to realize driving-related functions and intelligent cockpit functions, different functions have different requirements for security levels, and correspondingly, the operating systems for realizing different functions have different information security requirements.
Summary of the Invention
Problems to be Solved by the Invention
[0004] Embodiments of the present disclosure provide an integrated circuit, a resource access control method, equipment, and media to solve the above technical problems.
Means for Solving the Problems
[0005] An integrated circuit according to one embodiment of the present disclosure includes a plurality of hardware modules and a resource access control device connected to the plurality of hardware modules via a bus, wherein at least one of the plurality of hardware modules is located in corresponding at least one operating system. The resource access control device described above is We receive a resource access request from the requesting party, which includes the requesting party identifier, security attribute information, and access address. Based on pre-configured access control information, it is determined whether the requesting party has access rights to the resource corresponding to the access address, and a first determination result is obtained. In response to the first confirmation result indicating that the requesting party has access rights to the resource, the requesting party determines whether or not it has operational rights to the access address based on pre-configured security control information and security attribute information, thereby obtaining a second confirmation result. Based on the second confirmed result, the system is configured to process the resource access request. The requesting party is one of the at least one hardware modules, The requesting party is located in the corresponding operating system. The resource side is one hardware module other than the at least one hardware module among the plurality of hardware modules.
[0006] A resource access control method according to another embodiment of the present disclosure is: The steps include receiving a resource access request to identify the requesting party that initiates the resource access request, The steps include determining whether the requesting party has access rights to the resource corresponding to the access address based on pre-configured access rights control information, and obtaining a first determination result, The first confirmation result indicates that the requesting party has access rights to the resource side. The steps include determining whether the requesting party has operational rights to the access address based on pre-configured security control information and security attribute information, and obtaining a second confirmation result. The step of processing the resource access request based on the second confirmed result is included, The requesting party is deployed on the corresponding operating system.
[0007] A computer-readable storage medium according to a further embodiment of the present disclosure stores a computer program, and when the computer program is executed, it implements the method described in any of the above embodiments of the present disclosure.
[0008] A further embodiment of the embodiments of the present disclosure, a computer program product having processor-executable instructions, when the processor executes the executable instructions in the computer program product, realizes the method described in any of the above embodiments.
[0009] Further embodiments of the embodiments of this disclosure include an electronic device comprising a processor, memory, and a resource access control device. The memory stores the processor-executable instructions, The processor reads and executes the executable instructions from the memory, thereby controlling the resource access control device to implement the method described in any of the above embodiments. [Effects of the Invention]
[0010] According to embodiments of this disclosure, an integrated circuit includes a plurality of hardware modules and a resource access control device connected to the plurality of hardware modules via a bus, wherein at least one of the plurality of hardware modules is configured to correspond to at least one operating system, and when any hardware module configured to the operating system requests access to a resource at an access address, it initiates a resource access request as the requesting party, carries its own security attribute information with this resource access request, transmits this resource access request to the resource access control device, and the resource access control device determines, based on pre-configured access authority control information, whether the requesting party has access authority to the resource corresponding to this access address, thereby achieving authentication to the requesting party, preventing non-secure worlds from accessing the secure world, or relatively low security in the secure world from accessing the secure world. Access from a low-security module to a higher-security module can be restricted, effectively ensuring the security of functions with relatively high security requirements. If the requesting party has access rights to this resource, it is determined whether the requesting party has operational rights to this access address based on pre-configured security control information and the requesting party's security attribute information, and the resource access request is processed accordingly. This restricts the requesting party's operational rights to the requested resource, effectively preventing the leakage of private data from an information security perspective and effectively preventing the rewriting of important data related to security functions from a functional security perspective, thereby improving the security of the function. On the other hand, it avoids resource contention problems caused by operating systems without operational rights simultaneously accessing the same resource, effectively ensuring the real-time performance and security of related functions. [Brief explanation of the drawing]
[0011] [Figure 1]It is a schematic application overview diagram of an embodiment of the present disclosure. [Figure 2] It is a schematic structural diagram of an integrated circuit according to an exemplary embodiment of the present disclosure. [Figure 3] It is a schematic structural diagram of an integrated circuit according to another exemplary embodiment of the present disclosure. [Figure 4] It is a schematic diagram of an access right of one of the resource side or the address space accessible thereto in an embodiment of the present disclosure. [Figure 5] It is a schematic structural diagram of an integrated circuit according to yet another exemplary embodiment of the present disclosure. [Figure 6] It is a schematic structural diagram of an integrated circuit according to yet another exemplary embodiment of the present disclosure. [Figure 7] It is a schematic flowchart of a resource access control method according to an exemplary embodiment of the present disclosure. [Figure 8] It is a schematic flowchart of a resource access control method according to another exemplary embodiment of the present disclosure. [Figure 9] It is a schematic flowchart of a resource access control method according to yet another exemplary embodiment of the present disclosure. [Figure 10] It is a schematic flowchart of a resource access control method according to yet another exemplary embodiment of the present disclosure. [Figure 11] It is a schematic flowchart of a resource access control method according to yet another exemplary embodiment of the present disclosure. [Figure 12] It is a schematic flowchart of a resource access control method according to yet another exemplary embodiment of the present disclosure. [Figure 13] It is a schematic structural diagram of an electronic device according to an exemplary embodiment of the present disclosure.
Modes for Carrying Out the Invention
[0012] Hereinafter, in order to interpret the present disclosure, exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. The described embodiments are only some embodiments of the present disclosure, not all embodiments, and the present disclosure is not limited by the exemplary embodiments.
[0013] The relative arrangements, numerical expressions, and numerical values of the components and steps described in these embodiments do not limit the scope of the present disclosure unless otherwise specified.
[0014] [Application Summary] With the development of chip technology and autonomous driving technology, vehicles can provide increasingly rich driving-related functions and intelligent cockpit functions. Here, the driving-related functions include instrument display in the control layer, perception and control of autonomous driving, decision-making and execution of autonomous driving, etc., and the intelligent cockpit functions can include entertainment, map navigation, etc. In these driving-related functions and intelligent cockpit functions, different functions may have different requirements for security levels. Here, the driving-related functions are related to driving safety and require a relatively high security level. For example, the instrument display function and the perception and control function of autonomous driving usually require an ASIL-B security level, and the decision-making and execution function of autonomous driving usually requires an ASIL-D security level. The intelligent cockpit functions do not have very high requirements for security levels. By executing multiple operating systems that meet the requirements on a single chip (which can be called a cockpit-driving integrated chip) that realizes the driving-related functions and intelligent cockpit functions, the corresponding functions can be realized and the security of the related functions can be ensured. At the same time, the multiple operating systems can share chip resources to improve the multiplexing efficiency of the chip and peripheral circuits and reduce the overall cost of the chips in the vehicle cockpit.
[0015] However, in scenarios where multiple operating systems run on a single chip to implement driving-related and intelligent cockpit functions, different functions have different security level requirements, and correspondingly, the operating systems that implement these different functions have different information security requirements. To ensure corresponding functional safety and information security, how to control access to resources within the chip accessed by different operating systems is a technical problem that needs to be solved.
[0016] [Examples of application] Embodiments of this disclosure can be applied to any equipment such as vehicles, mobile devices, and servers that provide different functions through different applications, where the multiple different functions may have different or not identical security level requirements. For example, a vehicle may provide multiple driving-related functions such as instrument display, entertainment, map navigation, driver monitoring, and driver assistance, where the security level requirements for these different functions may vary.
[0017] Figure 1 is an illustrative schematic diagram of an embodiment of the present disclosure. As shown in Figure 1, taking the embodiment of the present disclosure as an example, an electronic system of this vehicle is provided with a heterogeneous system on chip (SOC) 102, on which multiple operating systems 104 that can run are installed, and different operating systems can implement corresponding functions of driving-related functions.
[0018] Here, SOC102 may include processor resources 1022, hardware resources 1024, and resource access control devices 1026.
[0019] Here, the processor resource 1022 may include a Central Processing Unit (CPU) and at least one type of processor from among graphics processing units (GPUs), application-specific integrated circuits (ASICs), tensor processing units (TPUs), deep learning processing units (DPUs), neural network processors (NPUs), digital signal processors (DSPs), and the like. In embodiments of this disclosure, the processor resource 1022 may include different types and different numbers of processors depending on the actual demand, and is not limited thereto.
[0020] The hardware resource 1024 may include, but is not limited to, at least one of the following: memory resources, cache resources, storage resources, register resources, interface resources, etc. Here, the memory resource may include, but is not limited to, random access memory (RAM), for example. The cache resource may include, but is not limited to, high-speed cache memory, for example. The storage resource may include, but is not limited to, solid-state drives (SSDs), universal flash storage (UFS), embedded multimedia cards (eMMCs), secure digital cards (SDs), flash memory, etc. The interface resource is an input / output (I / O) interface that connects to an external device. In embodiments of this disclosure, the hardware resource 1024 may include different types and different numbers of hardware depending on the actual demands, and is not limited to embodiments of this disclosure.
[0021] Multiple operating systems 104 can provide execution environments for higher-layer applications to implement different functions, thereby enabling corresponding functions. Each operating system can manage and schedule corresponding processor and hardware resources according to the task processing needs of the higher-layer applications it possesses, thereby processing corresponding tasks. Because the security level requirements for vehicle driving-related functions and intelligent cockpit functions differ, multiple operating systems 104 can include multiple operating systems that match the security level requirements of corresponding functions so that applications with different functions perform better on the corresponding operating system. For example, in a specific embodiment, a lower-layer real-time operating system (e.g., a system such as QNX, RTOS, or AUTOSAR) may be responsible for applications and services related to driving-related functions that require high real-time performance, high reliability, and high security (e.g., instrument display, autonomous driving perception and control, autonomous driving decision-making and execution), while a system such as Linux or Android may be responsible for applications and services related to intelligent cockpit functions that do not have high security requirements (e.g., infotainment). The types and number of operating systems specifically included in the multiple operating systems 104 in embodiments of this disclosure can be set according to actual needs and are not limited thereto in embodiments of this disclosure.
[0022] In specific embodiments, multiple hosts can be obtained by partitioning and isolating the processor resources 1022 in the SOC 102 using hardware isolation technology, or multiple virtual machines (VMs) can be obtained by partitioning the processor resources 1022 using virtualization technology or time-division multiplexing. Each of the multiple hosts and / or virtual machines can then be placed in a corresponding operating system, and appropriate security attribute information can be placed for each of the hosts and / or virtual machines.
[0023] Hardware isolation technology allows for the partitioning of hardware resources 1024 in SOC102, or, when the vehicle's electronic system starts up, hardware virtualization technology (e.g., middle-tier software Hypervisor) can partition hardware resources 1024 in SOC102, allocating appropriate amounts of memory, CPU, network, storage, and other hardware resources to hosts or virtual machines running each operating system. By loading and running different operating systems 104 on each host or virtual machine, privilege isolation of multiple operating systems 104 is achieved, isolating the hardware / software corresponding to the respective functions implemented by different operating systems from one another, thereby ensuring the security of driving-related functions.
[0024] When one of the hosts or virtual machines performs a task, it can initiate a resource access request as the requesting party. This resource access request includes a requesting party identifier, security attribute information pre-configured on the requesting party, and an access address. After the resource access control device 1026 receives the resource access request from the requesting party, it determines, based on pre-configured access permission control information, whether the requesting party has access rights to the resource corresponding to this access address, and obtains a first determination result. If the first determination result indicates that the requesting party has access rights to the resource, it determines, based on pre-configured security control information and the security attribute information, whether the requesting party has operational rights to this access address, and obtains a second determination result. Based on this second determination result, it performs processing corresponding to the resource access request.
[0025] This enables authentication for the requesting party, restricting access from the non-secure world to the secure world, or from relatively low-security-level modules accessing relatively high-security-level modules in the secure world. This effectively guarantees the security of functions with relatively high security requirements and restricts operational privileges to resources requested by the requesting party. On the one hand, it effectively avoids the leakage of private data from an information security perspective, and on the other hand, it effectively prevents the modification of important data related to security functions from a functional security perspective, thereby improving the security of functions (e.g., vehicle operation security). On the other hand, it avoids resource contention problems caused by operating systems without operational privileges simultaneously accessing the same resource, effectively guaranteeing the real-time performance and security of related functions.
[0026] [Example System] Figure 2 is a schematic diagram of the structure of an integrated circuit according to an exemplary embodiment of the present disclosure. This embodiment can be applied to any equipment such as mobile terminals, servers, and vehicles. In the embodiments of this disclosure, the application to an integrated circuit in a vehicle is described as an example, and applications to other equipment can be realized by referring to the above example. As shown in Figure 2, the integrated circuit of this embodiment includes a plurality of hardware modules 202 and a resource access control device 204, the plurality of hardware modules 202 and the resource access control device 204 being connected via a bus 206. At least one of the plurality of hardware modules 202 is arranged to correspond to at least one operating system.
[0027] Optionally, in some of these embodiments, the integrated circuit in the embodiments of the present disclosure may include, for example, a SOC or other heterogeneous multicore chip. The hardware module 202 in the integrated circuit may include processor resources and hardware resources.
[0028] Here, processor resources may include a CPU and multiple processors of any type, such as GPUs, ASICs, TPUs, DPUs, NPUs, DSPs, etc. Processor resources may include different types and different numbers of processors depending on the actual demand, and are not limited to the embodiments of this disclosure.
[0029] In specific embodiments, depending on the specific type of processor in the processor resources, multiple hosts can be obtained by partitioning and isolating processor resources using hardware isolation technology, or multiple virtual machines can be obtained by partitioning processor resources using virtualization technology or time-division multiplexing, and each of the multiple hosts and / or virtual machines can be placed in a corresponding operating system. In specific embodiments, if a single processor (e.g., VPU, BPU, etc.) can be partitioned into different hardware channels using hardware isolation technology (i.e., hardware isolation virtualization method), this processor can be partitioned into multiple hosts by channel dimension. If a single processor (e.g., DPU) cannot be distinguished into different hardware channels, multiple virtual machines can be obtained by partitioning resources for this processor using virtualization technology or time-division multiplexing. The multiple hosts and / or multiple virtual machines obtained by partitioning and isolating processor resources using this method are at least one hardware module from the above-mentioned multiple hardware modules 202.
[0030] Hardware resources may include, but are not limited to, at least one of memory resources, cache resources, storage resources, register resources, and interface resources, and the number of each type of hardware resource may be determined according to actual demand, and is not limited to the embodiments of this disclosure. Here, memory resources may include, but are not limited to, random access memory. Cache resources may include, but are not limited to, high-speed cache memory. Storage resources may include, but are not limited to, solid-state drives. Register resources may include at least one register for implementing different information placement functions. Interface resources are I / O interfaces connected to external devices. In embodiments of this disclosure, hardware resources may include different types and different numbers of hardware, depending on actual demand, and is not limited to the embodiments of this disclosure.
[0031] In specific embodiments, hardware resources can be partitioned using hardware isolation technology, or, when the vehicle electronic system starts up, hardware resources can be partitioned using hardware virtualization technology (e.g., middle-tier software hypervisor), and appropriate amounts of memory, CPU, network, storage, and other hardware resources can be allocated to the host or virtual machine running each operating system.
[0032] Multiple operating systems can run on an integrated circuit, each providing an operating environment for higher-layer applications that perform corresponding functions, thereby enabling the orderly and efficient execution of each task that performs the corresponding function, and thus achieving the corresponding function. Each operating system can schedule resources on the integrated circuit (including processor resources and hardware resources) to process corresponding tasks according to the task processing needs of the higher-layer applications it possesses. Since vehicle driving-related functions and intelligent cockpit functions may have different security level requirements, multiple operating systems can include operating systems that meet the security level requirements for performing corresponding functions, thereby enabling applications with different functions to perform better on the corresponding operating system. For example, in a specific embodiment, a lower-layer real-time operating system may be responsible for applications and services related to driving-related functions with high real-time, reliability, and security requirements (e.g., instrument display, autonomous driving perception and control, autonomous driving decision-making and execution), while a system such as Linux or Android may be responsible for applications and services related to intelligent cockpit functions with lower security requirements (e.g., infotainment). In embodiments of this disclosure, the specific types and number of multiple operating systems can be set according to actual needs and are not limited thereto.
[0033] Here, each hardware module in the above-mentioned at least one hardware module, which is a host or virtual machine, acts as a Master, loading and executing a different operating system to achieve privilege isolation between multiple operating systems, isolating hardware / software corresponding to the functions implemented by different operating systems from each other, thereby ensuring the security of different functions when applied to a vehicle. In a specific embodiment, one middle-tier software can be used, for example, privilege management software that manages integrated circuits, such as a Hypervisor. Alternatively, after the startup initialization of the integrated circuit is completed, a facility ID is assigned to each master in the integrated circuit to uniquely identify this facility, and depending on whether this master is obtained by hardware isolation technology or virtualization technology, this facility ID can be a host identifier (Master ID, MID) or a virtual host identifier (VMID). Subsequently, each master can be assigned to the corresponding operating system by a configuration register, and corresponding security attribute information can be assigned to the master assigned to the corresponding operating system.
[0034] Here, each hardware unit obtained by partitioning the hardware resources can be designated as a slave.
[0035] When a master needs to perform a task corresponding to an application in the operating system, it can initiate a communication request (e.g., a resource access request) and control the operation of bus 206 to communicate with and exchange data with a slave. For example, it can read or write data to the slave. In this case, the master that initiated the communication request becomes the requesting party, and the slave that responds to this request becomes the resource party corresponding to this communication request.
[0036] Optionally, in some of these embodiments, the bus 206 in the embodiments of the Disclosure may adopt a bus of any bus standard, depending on the actual demand (e.g., data transmission demand, hardware connectivity, etc.). These bus standards include, but are not limited to, buses of the Advanced Micro-Controller Bus Architecture (AMBA) specification, Peripheral Component Interface Express (PCIe) standard, or any other bus standard. Here, the AMBA specification bus may include, but is not limited to, at least one type of bus such as the Advanced High-Performance Bus (AHB), Advanced Peripheral Bus (APB), Advanced Extensible Interface (AXI), AXI Coherency Extensions (ACE), or Advanced System Bus (ASB), and the embodiments of the Disclosure do not specifically limit the bus adopted.
[0037] Here, the resource access control device 204, Upon receiving a resource access request from the requesting party, Based on pre-configured access control information, it is determined whether the requesting party has access rights to the resource corresponding to the access address of the resource access request, and a first determination result is obtained. In response to the first confirmation result indicating that the requesting party has access rights to the resource, the second confirmation result is obtained by determining whether the requesting party has operational rights to the access address of the resource access request, based on pre-configured security control information and security attribute information in the resource access request. It is configured to process resource access requests based on the second confirmation result. The resource access request includes a requesting party ID, security attribute information, and an access address. Here, the resource access request is used to request access to the access address, for example, to read data within the access address or write data to the access address. Here, the requesting party is one of the at least one hardware module 202, and this requesting party is placed as a master in the corresponding operating system. The requesting party ID is used to uniquely identify the requesting party initiating the resource access request, and this requesting party ID can be a MID or VMID (hereinafter referred to as MID / VMID). Since each master is placed in the corresponding operating system, the corresponding operating system can be uniquely determined based on the requesting party ID, and thereby the master and operating system initiating this resource access request can be determined. In a specific embodiment, if the requesting party obtains processor resources by dividing them using a time-division multiplexing scheme, one requesting party can be placed in a different operating system according to the time-division multiplexing scheme, so the requesting party ID corresponds to a different operating system in a different period. The resource side, acting as a slave, is one of the multiple hardware modules 202 other than the requesting one.
[0038] According to embodiments of this disclosure, an integrated circuit includes a plurality of hardware modules and a resource access control device connected to the plurality of hardware modules via a bus, wherein at least one of the plurality of hardware modules is configured to correspond to at least one operating system, and when any hardware module configured to the operating system requests access to a resource at an access address, it initiates a resource access request as the requesting party, carries its own security attribute information with this resource access request, transmits this resource access request to the resource access control device, and the resource access control device determines, based on pre-configured access authority control information, whether the requesting party has access authority to the resource corresponding to this access address, thereby achieving authentication to the requesting party, preventing non-secure worlds from accessing the secure world, or relatively low security in the secure world from accessing the secure world. Access from a low-security module to a higher-security module can be restricted, effectively ensuring the security of functions with relatively high security requirements. If the requesting party has access rights to this resource, it is determined whether the requesting party has operational rights to this access address based on pre-configured security control information and the requesting party's security attribute information, and the resource access request is processed accordingly. This restricts the operational rights of the requesting party to the resource for which access has been requested. On the one hand, from an information security perspective, the leakage of private data can be effectively avoided, and from a functional security perspective, the rewriting of important data related to security functions can be effectively avoided, thereby improving the security of the function. On the other hand, resource contention problems caused by operating systems without operational rights simultaneously accessing the same resource can be avoided, effectively ensuring the real-time performance and security of the related functions.
[0039] Optionally, in some of these embodiments, the security attribute information may include, but is not limited to, security status information and at least one of data rights management (DRM) attribute information. Here, security status information indicates whether the requesting party originates from a security attribute (i.e., the requesting party is in a Secure World), thereby indicating whether the requesting party initiating the resource access request is a security operation or a non-security operation. In some specific embodiments, the specific value of this security status information may be a security status (Sec) identifier 1 or a non-security status (Non-sec) identifier 0, correspondingly indicating whether the resource access request from this requesting party is a security operation or a non-security operation. DRM attribute information indicates whether the requesting party has a DRM attribute, and in some specific embodiments, if the specific value of the DRM attribute information is pre-set to DRM attribute identifiers 1 and 0, it correspondingly indicates whether the requesting party has a DRM attribute or not.
[0040] According to this embodiment, security attribute information can include security status information and DRM attribute information. Based on the security status information, it is possible to determine whether the requesting party initiated a resource access request is a security operation or a non-security operation. Based on the DRM attribute information, it is possible to determine whether the requesting party has data authority management attributes. Based on the security status information and DRM attribute information, it is possible to control the requesting party's operational privileges and more accurately restrict the requesting party's operational privileges, thereby improving information security and functional security. It also avoids resource contention problems caused by operating systems that do not have operational privileges accessing the same resource simultaneously, further improving the security of related functions.
[0041] Figure 3 is a schematic diagram of the structure of an integrated circuit according to another exemplary embodiment of the present disclosure. As shown in Figure 3, in addition to the embodiment shown in Figure 2, the integrated circuit of this embodiment further includes a configuration register 208 configured to place security attribute information for each of the at least one hardware module 202 (i.e., the master hardware module).
[0042] Optionally, the configuration register 208 can be further configured to place security attribute information for a slave hardware module among a plurality of hardware modules 202.
[0043] In a specific embodiment, the configuration register 208 can be used to implement requests for the security level of a function for the operating system running on each master, and to assign corresponding security attribute information, including security status information (Sec identifier / Non-sec identifier) and DRM attribute information (DRM attribute identifier / Non-DRM attribute identifier), to each master. Similarly, depending on the resource access control needs of each slave, corresponding security attribute information, including security status information (Sec identifier / Non-sec identifier) and DRM attribute information (DRM attribute identifier / Non-DRM attribute identifier), can be assigned to each slave or each address space within it.
[0044] According to this embodiment, after assigning security attribute information to each master, when a master issues a resource access request to a slave, the security attribute information can be carried over by the resource access request and used to control access rights and operation rights for this resource access request, thereby improving the security of information and related functions in the slave.
[0045] After security attribute information has been placed on each master, when a resource access request is initiated, the security attribute information of this master may be carried by existing signals on bus 206, or by using spare signal bits on bus 206, depending on the method of transmitting the resource access request and the bus standard specifically adopted by bus 206. Alternatively, at least a portion of this security attribute information may be carried by other data in the resource access request, and the remaining portion of this security attribute information may be carried by existing signals or spare signal bits on bus 206. The embodiments of this disclosure do not limit the specific method by which bus 206 carries the security attribute information.
[0046] For example, in a specific embodiment, when a resource access request is transmitted between the requesting party and the resource party using the AMBA standard bus as bus 206, security status information (Sec identifier 1 or Non-sec identifier 0) can be carried by security status read / write signal bits (secure bit) in signals such as PPROT and HPROT in bus APB or Axprot in bus AXI. Alternatively, the Secure Stream Identifier for a write / read transaction (secsid) can be carried in bus AXI to identify that the corresponding write / read transaction belongs to a secure type, and the Non-Secure Stream Identifier (NSID) in bus AXI can be used to identify that the current write / read transaction belongs to a non-secure type. The requesting party ID (MID / VMID) and DRM attribute information (DRM attribute identifier 1 / non-DRM attribute identifier 0) can be transmitted by signals such as NSAID and USER in bus AXI, and the embodiments of this disclosure are not limited thereto.
[0047] When transmitting DRM attribute information via the NSAID signal in bus AXI, the DRM attribute information is used to identify whether the requesting party possesses DRM attributes, that is, to distinguish whether the operation corresponding to the current resource access request is a DRM operation. Therefore, it is sufficient to carry 1 bit for the DRM attribute identifier 1 and 0 for the non-DRM attribute identifier.
[0048] In the AMBA specification, USER is a custom signal primarily used for transmitting additional information. Here, the User signal includes AWUSER and ARUSER, which are associated with the write address (AW) and read address (AR) channels, respectively. AWUSER is used for write operations, and ARUSER is used for read operations. These signals can be designed to transmit any user-defined information, such as control signals, status information, or data identifiers, thereby enhancing the efficiency and functionality of transactions. In embodiments of this disclosure, depending on whether the operation type of the current resource access request is a read operation or a write operation, AWUSER or ARUSER is appropriately adopted to carry DRM attribute information (DRM attribute identifier 1 / non-DRM attribute identifier 0), and the functionality of the USER signal is extended to realize the transmission of the requesting ID (MID / VMID) and DRM attribute information, which is subsequently used for operation authority control.
[0049] Optionally, in some of these embodiments, a resource access request may further include an operation type ID, which is used to identify the operation type corresponding to the resource access request, and which may include a read operation (Read, R) or a write operation (Write, W). In some specific embodiments, if the specific value of the operation type ID is set to R, W, or 0, 1, it indicates that the operation type corresponding to the resource access request is a read operation or a write operation, and the embodiments of this disclosure are not limited to the operation type represented by the operation type ID and the corresponding specific value.
[0050] Referencing Figure 3 as optional, in some of these embodiments, the resource access control device 204 may include at least one of a system memory manage unit (SMMU) 2042 and an authorization control module (Firewall) 2044, i.e., the integrated circuit may be provided with only an SMMU or an authorization control module, or with both an SMMU 2042 and an authorization control module 2044, to control resource access requests originating from different masters and operating systems, and not limited to the embodiments of this disclosure.
[0051] In some specific embodiments, the number of resource access control devices 204 can be one or more, depending on the actual requirements, and each SMMU 2042 is connected to at least one master by bus 206.
[0052] In some specific embodiments, the number of authorization control modules 2044 may be one or more. In specific applications, the authorization control module 2044 may be located on the slave resource side, on the master requesting side, or independently at any position between the requesting side and the resource side in the integrated circuit, and is not limited to these embodiments of the Disclosure. In specific applications, if the authorization control module 2044 is located on a slave, depending on the actual demand, one authorization control module 2044 may be located upstream of each slave or on each slave, or the authorization control module 2044 may be located upstream of or only on slaves where authorization control using the authorization control module 2044 is required. If the authorization control module 2044 is located on a master, depending on the actual demand, one authorization control module 2044 may be located downstream of each master or on each master, or the authorization control module 2044 may be located downstream of or only on masters of master-slave systems where authorization control using the authorization control module 2044 is required. The embodiments of the Disclosure are not limited to the arrangement of the authorization control module 2044.
[0053] Figure 3 illustrates only one example of an implementation of the SMMU2042 and the authorization control module 2044, and embodiments employing other numbers, locations, and structures of the SMMU2042 and authorization control module 2044 can be implemented by reference. In embodiments in which the resource access control device 204 includes only the SMMU2042 and does not include the authorization control module 2044, each slave is connected directly to the SMMU2042 via the bus.
[0054] Optionally, in some of these embodiments, if the resource access control device 204 includes an SMMU 2042, the resource access request may include a stream identifier (Stream ID, SID), security status information, and an access address. Here, the stream identifier includes a requesting party ID and DRM attribute information based on a preset format, for example, the stream ID is a MID / VMID-DRM attribute identifier, and in this embodiment, the requesting party may carry the DRM attribute information by the stream identifier and the security status information by security status read / write signal bits in the signal separately. In some specific embodiments, when the requesting party generates a resource access request, the DRM attribute information may be written to a preset position before or after the requesting party ID in the stream identifier according to a preset format, and the embodiments of this disclosure do not limit the specific position of the DRM attribute information in the stream identifier.
[0055] Optionally, in some of these embodiments, the configuration register 208 can be used to assign a unique Stream ID to each master that employs SMMU and performs privilege restrictions; that is, the Stream ID is obtained by encoding the MID / VMID and DRM attribute information (whether or not each master has DRM attributes) according to a preset format.
[0056] Since the integrated circuit contains multiple masters, each SMMU may be connected to multiple masters via the bus, and each device uniquely corresponds to one MID / VMID, thereby uniquely corresponding to one stream ID, and the SMMU can distinguish between multiple masters connected to the SMMU based on this stream ID. In this embodiment, the MID / VMID in the Stream ID can distinguish between different operating systems and the tasks that implement their corresponding functions, and the DRM attribute information in the Stream ID can distinguish between the DRM attributes of the masters.
[0057] In this embodiment, the stream ID is extended to write the requesting party ID and DRM attribute information to the stream ID, and the requesting party ID and DRM attribute information are carried by the stream ID, thereby enabling the transmission of the requesting party ID and DRM attribute information. The SMMU can then obtain the requesting party ID and DRM attribute information from the stream identifier in order to perform access control for the requesting party.
[0058] Accordingly, in this embodiment, the SMMU2042 is further configured to obtain a stream identifier, security status information, and access address from the resource access request, and to obtain the requesting party ID and DRM attribute information from the stream identifier based on a preset format.
[0059] Optionally, in some of these embodiments, the access rights control information described above may include a page table located in the SUMM for each of the at least one requesting parties. That is, within the SMMU, a page table corresponding to each master is pre-configured, each page table includes at least one accessible address space and access rights attribute information for each accessible address space, each accessible address space includes at least one access address, and the access rights attribute information represents the current operation rights restriction information. For example, in some of these specific embodiments, the access rights attribute information may include, but is not limited to, at least one of the following: readable, writable, unreadable, unwritable, securely accessible, not securely accessible, non-securely accessible, not securely accessible, DRM attribute accessible, not DRM attribute accessible. In a specific application, if one master requests access from a slave (the resource), and the slave does not grant the master access, the page table corresponding to the master will not contain the accessible address space corresponding to the slave. If the master is allowed to access the slave, but its operational authority over the slave's different accessible address spaces is restricted, the appropriate access permission attribute information for each accessible address space can be set to, for example, read-only or write-only. Similarly, if the master is allowed to access the slave, but the access address requested by the master is currently inaccessible (for example, accessed by another master or the operating system), the access permission attribute information for the corresponding accessible address space can be set to read-only or write-only.
[0060] Optionally, in some of these embodiments, the access rights attributes of each accessible address space can be determined based on the security attribute information of the resource corresponding to each accessible address space, depending on the security needs of the relevant functions and information protection, or further determined in combination with the current state of the corresponding resource. For example, as shown in Figure 4, in one embodiment, the access rights attributes of the resource or its accessible address space are as follows:
[0061] If the security status information of the resource or its accessible address space is a Sec identifier, the access permission attributes of that accessible address space are secure access (including secure read and secure write), non-secure access (including non-secure read and non-secure write), and DRM attribute access (including DRM attribute read and DRM attribute write). Access to this accessible address space is only possible (data can be read and written to this accessible address space) if the security status information in the resource access request is a Sec identifier (indicating that the master originates from a secure world or that the operation in question is a security operation). If the security status information is a Non-sec identifier (indicating that the master originates from a non-secure world or that the operation in question is a non-secure operation) and the DRM attribute information is a DRM attribute (indicating that this master has a DRM attribute or that the operation in question is a DRM attribute operation), then access to this accessible address space is not possible (data cannot be read or written to this accessible address space). If the security status information of the resource or its accessible address space is a Non-sec identifier, the access permission attributes of that accessible address space are secure access (including secure read and secure write), non-secure access (including non-secure read and non-secure write), DRM attribute readable, and DRM attribute write-incompatible. If the security status information in the resource access request is a Sec identifier, it indicates that this accessible address space can be accessed. If the security status information is a Non-sec identifier, it indicates that this accessible address space can be accessed. If the DRM attribute information is a DRM attribute, it indicates that data can be read from this accessible address space, but data cannot be written to this accessible address space. If the DRM attribute information of the resource or its accessible address space is a DRM attribute, the access permission attributes of that accessible address space are: secure access (including secure read and secure write), non-secure access (including non-secure read and non-secure write), and DRM attribute access (including DRM attribute read and DRM attribute write). If the security status information in the resource access request is a Sec identifier, it indicates that this accessible address space can be accessed; if the security status information is a Non-sec identifier, it indicates that this accessible address space cannot be accessed; and if the DRM attribute information is a DRM attribute, it indicates that this accessible address space can be accessed.
[0062] When a resource access request carries both security status information and DRM attribute information, and / or when the resource side possesses both security status information and DRM attribute information, the access rights attribute of each accessible address space on the resource side can be determined based on preset rules. For example, if an accessible address space is determined to be accessible based on all determination methods, this accessible address space can be determined to be accessible, or if an accessible address space is determined to be inaccessible based on all determination methods, this accessible address space can be determined to be inaccessible.
[0063] Furthermore, the SMMU, in combination with the current state of the resource, can set the access permission attribute of each accessible address space to "inaccessible" when a particular accessible address space is being accessed by another master. This avoids resource contention and resource consistency problems caused by different masters accessing the same resource. As a result, the dynamic setting of access permission control information by the SMMU enables accurate and effective control of hardware resources in integrated circuits, improving the overall security and resource utilization of the system.
[0064] In a specific embodiment, a single Stream Table Entry (STE) can record a page table identifier corresponding to each master identifier, and a page table located in the SMMU can be associated with the master identifier (MID / VMID). In the SMMU, a page table is placed for each master that contains only the accessible address space that each master is authorized to access. In this way, each master can index only the page tables it can access and cannot access page tables to which other masters or operating systems belong.
[0065] Accordingly, in this embodiment, the SMMU2042 further comprises From the resource access request, obtain an operation type ID to identify whether the operation type corresponding to the resource access request is a read operation or a write operation. Retrieve the first page table corresponding to the requesting party ID, Based on whether the access address in the resource access request belongs to at least one accessible address space in the first page table, it is determined whether the requesting party has access rights to the resource, and the first determination result is obtained. The first confirmation result confirms that the access address in the resource access request belongs to at least one accessible address space in the security control information, confirming that the requesting party has access rights to this access address, and obtaining access rights attribute information for the target accessible address space to which this access address belongs from the security control information. Based on the access permission attribute information of the target accessible address space, the operation type ID in the resource access request, and one of the DRM attribute information and security status information in the resource access request, it is determined whether the requesting party has the authority to perform an operation on this access address by identifying the operation type by the operation type ID (i.e., whether the requesting party has the authority to perform the read or write operation it requested on the access address), and a second determination result is obtained. The second confirmation result is configured to translate this access address from a virtual address (VA) to a physical address (PA) based on the first page table, in response to the requesting party having the authority to perform an operation type with the operation type ID on the access address in the resource access request, so that the operation requested by the resource access request is performed on the physical address (i.e., the corresponding data read or write operation is performed on this access address), and then forward this resource access request to this physical address. The first page table is a page table to which the requesting party has access rights, and the first page table includes at least one accessible address space corresponding to at least one resource side and access rights attribute information for each accessible address space. If the access address in a resource access request belongs to at least one accessible address space in the first page table, it is determined that the requesting party has access rights to this access address, and the page table entry corresponding to this access address can be indexed. If the access address in a resource access request does not belong to at least one accessible address space in the first page table, it is determined that the requesting party does not have access rights to this access address, and the indexing of the page table entry corresponding to this access address is not permitted. The security control information may include access permission attribute information for at least one of the accessible address spaces, and the target accessible address space is an accessible address space in which an access address is included in the resource access request in the security control information.
[0066] Each page table in SUMM contains at least one Page Table Entry (PTE), each PTE representing a mapping rule from one virtual page to a physical page (a Page is the smallest unit of mapping from VA to PA). SMMU2042 can determine the actual PA to which the access address VA is mapped by searching the PTE in the first page table corresponding to the requester, if the requester has the authority to identify the operation type by operation type ID for the access address in the resource access request, and can then forward the resource access request to this PA.
[0067] Optionally, SMMU2042 further, The system can be configured to: if the first confirmation result is in response to the access address in the resource access request not belonging to at least one accessible address space in the security control information, it confirms that the requester does not have access rights to the access address; or if the second confirmation result is in response to the requester not having the authority to perform an operation by identifying the operation type with the operation type ID for the access address in the resource access request, it can reject the resource access request and provide feedback to the requester with an error message (response err) and / or, if the operation type identified by the operation type ID is a read operation, it can return all zero data; and if the operation type identified by the operation type ID is a write operation, it can discard the data requested to be written to the access address carried in the resource access request.
[0068] According to this embodiment, the SMMU obtains a requester ID from the stream identifier, indexes the corresponding first page table based on this requester ID, and prevents the requester from accessing page tables to which other masters or operating systems belong, that is, prevents the requester from accessing address spaces allocated to other masters or operating systems (i.e., hardware resources allocated to other masters or operating systems). This restricts non-secure worlds from accessing secure worlds, or equipment with a relatively low security level in a secure world from accessing hardware resources with a relatively high security level. This helps to ensure different functional requirements for functional security levels. If the requester has access rights to the access address it has requested, the requester determines the operational rights to the access address it has requested access to, and prevents the requester from performing data read / write operations beyond its authority on the access address it has requested. This helps to avoid information security breaches caused by such breaches, and functional security breaches implemented by other masters or operating systems caused by data leakage or modification, thereby improving the overall security and reliability of the system.
[0069] Figure 5 is a schematic diagram of the structure of an integrated circuit according to yet another exemplary embodiment of the present disclosure. As shown in Figure 5, in addition to the embodiments shown in any of Figures 2 to 3, the resource access control device 204 includes an authorization control module 2044, and if the authorization control module 2044 is provided on the resource side, the access authorization control information may include a requesting list that permits access to the resource side, and this requesting list may be pre-configured by a configuration register, and this requesting list includes at least one master ID, each master ID used to uniquely identify one master that can be a requesting party.
[0070] In this embodiment, security status information (Sec identifier 1 or Non-sec identifier 0) can be carried by security status read / write signal bits in signals such as PPROT and HPROT in the bus APB or Axprot in the bus AXI. Alternatively, the secsid that carries the write / read transaction in the bus AXI identifies that the corresponding write / read transaction belongs to a secure type, and the NSID in the bus AXI identifies that the current write / read transaction belongs to a non-secure type. The requesting party ID (MID / VMID) and DRM attribute information (DRM attribute identifier 1 / non-DRM attribute identifier 0) can be transmitted by signals such as NSAID and USER in the bus AXI, and the embodiments of this disclosure are not limited thereto.
[0071] Accordingly, in this embodiment, the authorization control module 2044 further, From the resource access request, the requester ID, security status information, DRM attribute information, resource ID, operation type ID, and access address are obtained respectively. Based on whether the requesting party ID is included in the list of requesting parties permitted to access the resource in the access rights control information, it is determined whether the requesting party has access rights to the resource, and a first determination result is obtained. The first confirmation result confirms that the requesting party ID is included in the requesting party list, thus confirming that the requesting party has access rights to the resource. From the security control information, access rights attribute information for the target accessible address space to which the access address in the resource access request belongs is obtained. Based on the access rights attribute information of the target accessible address space, the operation type ID in the resource access request, and one of the DRM attribute information and security status information in the resource access request, it is determined whether the requesting party has the operation rights to identify the operation type with the above operation type ID for the access address, and a second determination result is obtained. The second confirmation result is configured to forward the resource access request to the access address in the resource access request in response to the requesting party having the authority to perform an operation type on the access address using the operation type ID, so that the operation requested by the resource access request is performed on this access address (i.e., the corresponding data read or write operation is performed on this access address). The resource-side ID is used to identify the resource on which access has been requested by the resource access request, and the operation type ID is used to identify whether the operation type corresponding to the resource access request is a read operation or a write operation. If the requesting party ID is included in the requesting party list, it is determined that the requesting party has access rights to the resource, and this resource access request can be allowed to enter the resource. If the requesting party ID is not included in the requesting party list, it is determined that the requesting party does not have access rights to the resource, and this resource access request cannot be allowed to enter the resource. In this embodiment, the security control information includes access permission attribute information for at least one accessible address space, each accessible address space includes at least one access address, and the target accessible address space is an accessible address space in which an access address is included in the resource access request in the security control information. In the security control information, the access permission attribute information for each accessible address space can be determined based on the security attribute information of the corresponding resource, or further determined in combination with the current state of this accessible address space. Specifically, refer to the description in the embodiment shown in Figure 4 above, which will be omitted here.
[0072] Optionally, the authorization control module 2044 further: The system can be configured to reject the resource access request and provide feedback to the requester in response to the resource access request. This can be done if the first confirmation result indicates that the requester ID is not included in the requester list, thus confirming that the requester does not have access rights to the resource, or if the second confirmation result indicates that the requester does not have the authority to perform an operation by identifying the operation type with the operation type ID for the access address. The system can also be configured to return all zero data if the operation type identified by the operation type ID is a read operation, or to discard the data requested to be written to the access address carried in the resource access request if the operation type identified by the operation type ID is a write operation.
[0073] According to this embodiment, the authorization control module can determine whether a requesting party has access rights to a resource based on a pre-configured list of requesting parties, thereby preventing the requesting party from accessing hardware resources located on other masters or operating systems. This restricts access from a non-secure world to a secure world, or from equipment with a relatively low security level accessing hardware resources with a relatively high security level in a secure world, helping to ensure different functional requirements for functional security levels. If the requesting party has access rights to the access address it has requested, the module determines the requesting party's operational rights to that access address, preventing the requesting party from performing data read / write operations beyond its authority on the access address it has requested. This avoids information security breaches caused by such breaches, as well as functional security breaches implemented by other masters or operating systems caused by data leakage or modification, thereby improving the overall security and reliability of the system.
[0074] Figure 6 is a schematic diagram of the structure of an integrated circuit according to yet another exemplary embodiment of the present disclosure. As shown in Figure 6, in addition to the embodiments shown in any of Figures 2 to 3, the resource access control device 204 includes an authorization control module 2044, and if this authorization control module 2044 is provided on the requesting side, the access authorization control information may include a resource-side list that permits access from the requesting side, the resource-side list may be pre-configured by a configuration register, the resource-side list includes at least one slave ID, each slave ID is used to uniquely identify one slave that can be on the resource side.
[0075] In this embodiment, security status information (Sec identifier 1 or Non-sec identifier 0) can be carried by security status read / write signal bits in signals such as PPROT and HPROT in the bus APB or Axprot in the bus AXI. Alternatively, the secsid that carries the write / read transaction in the bus AXI identifies that the corresponding write / read transaction belongs to a secure type, and the NSID in the bus AXI identifies that the current write / read transaction belongs to a non-secure type. The requesting party ID (MID / VMID) and DRM attribute information (DRM attribute identifier 1 / non-DRM attribute identifier 0) can be transmitted by signals such as NSAID and USER in the bus AXI, and the embodiments of this disclosure are not limited thereto.
[0076] Accordingly, in this embodiment, the authorization control module 2044 further, From the resource access request, the requester ID, security status information, DRM attribute information, resource ID, access address, and operation type ID are obtained respectively. Based on whether the resource ID in the resource access request is included in the pre-configured resource list, it is determined whether the requesting party has access rights to the resource, and a first determination result is obtained. The first confirmation result confirms that the resource-side ID is included in the resource-side list, confirming that the requesting party has access rights to the resource-side, and obtaining access rights attribute information for the target accessible address space to which the access address in the resource access request belongs from the pre-configured security control information. Based on the access permission attribute information of the target accessible address space, the operation type ID in the resource access request, and one of the DRM attribute information and security status information in the resource access request, it is determined whether the requesting party has the operation permission to identify the operation type by the operation type ID for the access address, and a second determination result is obtained. The second confirmation result is configured to forward the resource access request to the access address in the resource access request, in response to the requesting party having the authority to perform the operation type identified by the operation type ID on the access address, so that the operation requested by the resource access request is performed on the access address. The resource-side ID is used to identify the resource on which access has been requested by the resource access request, and the operation type ID is used to identify whether the operation type corresponding to the resource access request is a read operation or a write operation. If the resource-side ID in the resource access request is included in the resource-side list, it is determined that the requesting party has access rights to the resource, and the resource access request can be allowed to enter the resource. If the resource-side ID in the resource access request is not included in the resource-side list, it is determined that the requesting party does not have access rights to the resource, and the resource access request cannot be allowed to enter the resource. The security control information may include access permission attribute information for at least one accessible address space corresponding to each resource-side ID in the resource-side list, and the access permission attribute information may include operation permission attributes and DRM attributes. The target accessible address space is an accessible address space in which an access address is included in the resource access request in the security control information. In the security control information, the access permission attribute information for each accessible address space can be determined based on the security attribute information of the corresponding resource-side, or further determined in combination with the current state of the accessible address space, and for specifics, refer to the description in the above embodiment, which is omitted here.
[0077] Optionally, the authorization control module 2044 further: The system can be configured to reject the resource access request and to provide feedback to the requester in response to the resource access request. This can be done if the first confirmation result is that the resource-side ID in the resource access request is not included in the resource-side list, thus confirming that the requester does not have access rights to the resource-side, or if the second confirmation result is that the requester does not have the authority to perform an operation by identifying the operation type with the operation type ID for the access address, and / or to return all zero data if the operation type identified by the operation type ID is a read operation, and to discard the data requested to be written to the access address carried in the resource access request if the operation type identified by the operation type ID is a write operation.
[0078] According to this embodiment, the authorization control module can determine whether the requesting party has access rights to a resource based on a pre-configured list of resource sides, thereby preventing the requesting party from accessing hardware resources located in other masters or operating systems. This restricts access from the non-secure world to the secure world, or access from equipment with a relatively low security level to hardware resources with a relatively high security level in the secure world, helping to ensure different functional requirements for functional security levels. If the requesting party has access rights to the access address they requested, the module further determines the requesting party's operational rights to that access address, preventing the requesting party from performing data read / write operations beyond their authority on the access address they requested. This helps to improve the overall security and reliability of the system by avoiding information security breaches caused by such breaches, as well as functional security breaches implemented by other masters or operating systems caused by data leakage or modification.
[0079] Furthermore, if the resource access control device 204 includes both the SMMU 2042 and the authorization control module 2044, the configuration register 208 can be used to configure, depending on the actual demand, to set up a master that uses the SMMU 2042 to perform authorization control (in this case, the stream identifier and DRM attribute information are placed on this master), a master that uses the authorization control module to perform authorization control (in this case, the master identifier, security status information and DRM attribute information are placed on this master), or a slave. Alternatively, all masters may be configured to use the SMMU 2042 to perform authorization control, or all masters may be configured to use the authorization control module 2044 to perform authorization control. In actual applications, the configuration can be dynamically set up according to the demand, and the embodiments of this disclosure are not limited to this. If the resource access control device 204 includes both an SMMU 2042 and an authorization control module 2044, and authorization control is performed by employing one of the SMMU 2042 or the authorization control module 2044, it is possible to bypass the other of the SMMU 2042 or the authorization control module 2044.
[0080] In some of these embodiments, when bus 206 employs a PCIe bus, virtualization technology can be employed to arrange a single host (hardware path) connected to the PCIe bus as multiple virtual machines, thereby assigning multiple stream identifiers to the multiple virtual machines, and the SMMU2042 can control the resource access requests of these multiple virtual machines. When bus 206 employs an AMBA bus, the SMMU2042 or the authorization control module 2044 can control the resource access requests of each host or virtual machine, and the embodiments of this disclosure are not limited thereto.
[0081] [Example Method] Figure 7 is a schematic flowchart of a resource access control method according to an exemplary embodiment of the present disclosure. This embodiment can be applied to any equipment equipped with a chip, such as a mobile terminal, server, or vehicle, and more specifically, to an integrated circuit in the equipment. In this embodiment of the present disclosure, the application to an integrated circuit in a vehicle is described as an example, and implementations for other equipment can be implemented by reference. As shown in Figure 7, the resource access control method of this embodiment includes the following steps 302 to 308.
[0082] In step 302, a resource access request is received, which includes the requesting party ID, security attribute information, and access address.
[0083] Here, a resource access request is used to request access to the access address mentioned above, for example, to read data within the access address or to write data to the access address. The requesting party ID is used to identify the requesting party that initiates the resource access request, and this requesting party is located in the corresponding OS.
[0084] Optionally, in some of these embodiments, the integrated circuit in the embodiments of the Disclosure may include, for example, a System of Core (SOC) or other heterogeneous multicore chip. In some of these embodiments, the integrated circuit may include processor resources and hardware resources, where the processor resources may include a CPU and a plurality of any of the following types of processors (GPU, ASIC, TPU, DPU, NPU, DSP, etc.). The processor resources may include different types and numbers of processors depending on the actual demands, and are not limited to the embodiments of the Disclosure.
[0085] In this embodiment, depending on the specific type of processor in the processor resources, multiple hosts can be obtained by partitioning and isolating the processor resources using hardware isolation technology, or multiple virtual machines can be obtained by partitioning the processor resources using virtualization technology or time-division multiplexing, and each of the multiple hosts and / or virtual machines can be placed in a corresponding operating system.
[0086] Hardware resources may include, but are not limited to, at least one of memory resources, cache resources, storage resources, register resources, and interface resources, and the number of each type of hardware resource may be set according to actual demand, and is not limited thereto in the embodiments of this disclosure. In embodiments, hardware resources can be partitioned by hardware isolation technology, or, at startup of the vehicle electronic system, hardware resources can be partitioned by hardware virtualization technology, and appropriate amounts of memory, CPU, network, storage, and other hardware resources can be allocated to hosts or virtual machines running each operating system, respectively.
[0087] Multiple operating systems can run on an integrated circuit, providing an operating environment for higher-layer applications that perform corresponding functions, enabling the orderly and efficient execution of each task that performs the corresponding function, thereby realizing the corresponding function.
[0088] Here, each hardware module in the above-mentioned at least one hardware module, which is a host or virtual machine, acts as a master, loading and running a different operating system to achieve privilege isolation between multiple operating systems, isolating the hardware / software corresponding to the functions implemented by different operating systems from each other, thereby ensuring the security of related functions when applied to a vehicle. In this embodiment, one middle-tier software can be used, for example, privilege management software that manages integrated circuits, such as a hypervisor. Alternatively, after initialization is completed during the startup of the integrated circuit, a facility ID that uniquely identifies this facility is assigned to each master in the integrated circuit, and depending on the master, this facility ID can be a host identifier or a virtual host identifier, depending on whether it is obtained by hardware isolation technology or virtualization technology. Subsequently, each master can be assigned to the corresponding operating system by a configuration register, and corresponding security attribute information can be assigned to the master assigned to the corresponding operating system.
[0089] Here, each hardware unit obtained by partitioning the hardware resources can be treated as a slave.
[0090] When a master needs to perform a task corresponding to an application in the operating system, it can initiate a communication request (e.g., a resource access request) and control the operation of the bus to communicate with and exchange data with a slave. For example, it can read or write data to the slave. In this case, the master that initiated the communication request becomes the requesting party, and the slave that responds to this request becomes the resource party corresponding to this communication request.
[0091] This requesting ID can be either an MID or a VMID (hereinafter referred to as MID / VMID), and since each master is located in the corresponding operating system, the requesting ID uniquely determines the corresponding operating system, thereby determining the master and operating system initiating this resource access request.
[0092] In step 304, based on pre-configured access control information, the requesting party determines whether or not it has access rights on the resource side corresponding to the access address in the resource access request, and obtains the first determination result.
[0093] In step 306, in response to the first confirmation result indicating that the requesting party has access rights to the resource side, the second confirmation result is obtained by determining whether the requesting party has operational rights to the access address in the resource access request, based on pre-configured security control information and security attribute information in the resource access request.
[0094] In step 308, the resource access request is processed based on the second confirmed result.
[0095] According to the embodiments of this disclosure, authentication of the requesting party is achieved, restricting access from the non-secure world to the secure world, or from a module with a relatively low security level accessing a module with a higher security level in the secure world. This effectively guarantees the security of a relatively high level of functionality relative to security level requirements. If the requesting party has access rights to this resource, it is determined whether the requesting party has operational rights to this access address based on pre-configured security control information and the requesting party's security attribute information, and the resource access request is processed accordingly. This restricts the requesting party's operational rights to the requested resource. On the one hand, from an information security perspective, the leakage of private data is effectively avoided, and from a functional security perspective, the rewriting of important data related to security functions is effectively avoided, thereby improving the security of the functionality. On the other hand, resource contention problems caused by operating systems without operational rights simultaneously accessing the same resource are avoided, effectively guaranteeing the real-time performance and security of the related functionality.
[0096] Optionally, in some of these embodiments, the resource access control method of any embodiment of the present disclosure may further include an operation type ID, which is used to identify the operation type corresponding to the resource access request, and which may include read (R) or write (W). In some specific embodiments, if the specific value of the operation type ID is preset to R, W, or 0, 1, it indicates that the operation type corresponding to the resource access request is read or write, and the embodiments of the present disclosure are not limited to the operation type represented by the operation type ID and the corresponding specific value.
[0097] Optionally, in some of these embodiments, the security attribute information may include, but is not limited to, security status information and DRM attribute information, for example, at least one of these. Here, security status information indicates the security attribute of the requesting party (i.e., whether the requesting party originated in a Secure World) and thereby indicates whether the requesting party initiating the resource access request is a security operation or a non-security operation. In some specific embodiments, the specific value of this security status information may be a security status (Sec) identifier 1 or a non-security status (Non-sec) identifier 0, correspondingly indicating whether the resource access request sent by the requesting party is a security operation or a non-security operation. DRM attribute information indicates whether the requesting party has a DRM attribute, and in some specific embodiments, if the specific value of the DRM attribute information is pre-set to DRM attribute identifiers 1 and 0, it correspondingly indicates whether the requesting party has a DRM attribute or not.
[0098] Figure 8 is a schematic flowchart of a resource access control method according to another exemplary embodiment of the present disclosure. In some of these embodiments, the resource access control method can be applied to an SMMU, i.e., an SMMU can be provided in an integrated circuit to implement the embodiments of the resource access control method. In this embodiment, the resource access request may include a stream identifier, security status information, and an access address. Here, the stream identifier includes a requesting ID and DRM attribute information based on a preset format, and in this embodiment, the DRM attribute information is carried by the stream identifier. In some specific embodiments, the DRM attribute information may be written to a predetermined position before or after the requesting ID in the stream identifier according to a preset format, and the embodiments of the present disclosure do not limit the specific position of the DRM attribute information in the stream identifier.
[0099] As shown in Figure 8, in addition to the embodiment shown in Figure 7 above, this embodiment further includes the following steps 402 to 404 after step 302. In step 402, the stream identifier, security status information, and access address are obtained from the resource access request. In step 404, the requesting party ID and DRM attribute information are obtained from the stream identifier based on the preset format.
[0100] According to this embodiment, by extending the stream ID and writing the requesting party ID and DRM attribute information to the stream ID, and by carrying the requesting party ID and DRM attribute information through the stream ID, transmission of the requesting party ID and DRM attribute information is realized, and the SMMU can obtain the requesting party ID and DRM attribute information from the stream identifier in order to perform access control to the requesting party.
[0101] Optionally, in some of these embodiments, the access rights control information described above may include a page table located in SUMM for each of the at least one requesting parties. Each page table includes at least one accessible address space and access rights attribute information for each accessible address space, the access rights attribute information representing the current operation rights restriction information. For example, in some of these specific embodiments, the access rights attribute information may include, but is not limited to, at least one of the following: readable, writable, unreadable, unwritable, securely accessible, securely inaccessible, non-securely accessible, non-securely inaccessible, DRM attribute accessible, non-DRM attribute inaccessible. In a specific application, if one master requests access to one slave (the resource), and the slave does not grant the master access, the page table corresponding to the master will not contain the accessible address space corresponding to the slave. If the master is allowed to access the slave, but its operational authority over the slave's different accessible address spaces is restricted, the appropriate access permission attribute information for each accessible address space can be set to, for example, read-only or write-only. If the master is allowed to access the slave, but the access address requested by the master is currently inaccessible (for example, another master is accessing the operating system), the access permission attribute information for the corresponding accessible address space can be set to read-only or write-only.
[0102] Optionally, in some of these embodiments, the access rights attributes of each accessible address space can be determined based on the security attribute information of the resource corresponding to each accessible address space, depending on the security requirements of the relevant functions and information protection, or further determined in combination with the current state of the corresponding resource. For specifics, please refer to the relevant introductions in the embodiments described above, which are omitted here.
[0103] Figure 9 is a schematic flowchart of a resource access control method according to yet another exemplary embodiment of the present disclosure. As shown in Figure 9, in addition to the embodiment shown in Figure 8, the present embodiment may further include the step 402 of obtaining an operation type ID from a resource access request, which identifies the operation type that the operation type ID corresponds to in the resource access request.
[0104] Accordingly, in this embodiment, step 304 may specifically include the following steps 3042 to 3044.
[0105] In step 3042, the first page table corresponding to the requesting party ID is retrieved. This first page table is the page table to which the requesting party has access rights.
[0106] Here, the first page table includes at least one accessible address space corresponding to at least one resource side, and access permission attribute information for each accessible address space.
[0107] In step 3044, the first determination result is obtained by determining whether the requesting party has access rights to the resource based on whether the access address belongs to at least one accessible address space in the first page table.
[0108] In some embodiments of this embodiment, the security control information described above may include access permission attribute information for at least one of the accessible address spaces described above.
[0109] Accordingly, referring to Figure 9, in this embodiment, step 306 may specifically include the following steps 3062 to 3064.
[0110] In step 3062, the first confirmation result is determined to be in response to the access address in the resource access request belonging to at least one accessible address space in the security control information. The requesting party is then determined to have access rights to this access address, and access rights attribute information for the target accessible address space to which this access address belongs is obtained from the security control information.
[0111] The aforementioned target accessible address space is the accessible address space in which the access address is included in the resource access request in the security control information.
[0112] Specifically, if the access address in a resource access request belongs to at least one accessible address space in the first page table, it can be determined that the requesting party has access rights to this access address, and the page table entry corresponding to this access address can be indexed. If the access address in a resource access request does not belong to at least one accessible address space in the first page table, it can be determined that the requesting party does not have access rights to this access address, and the indexing of the page table entry corresponding to this access address is not permitted.
[0113] In step 3064, based on the access rights attribute information of the target accessible address space, the operation type ID in the resource access request, and one of the DRM attribute information and security status information in the resource access request, it is determined whether the requesting party has the authority to perform an operation on this access address by identifying the operation type by the operation type ID (i.e., whether the requesting party has the authority to perform the read or write operation it requested on the access address), and a second determination result is obtained.
[0114] Optionally, referring to Figure 9, in some of these embodiments, in addition to the embodiments shown in Figure 8, step 308 may specifically include the following step 3082.
[0115] In step 3082, the second confirmation result, in response to the requesting party having the authority to perform an operation by identifying the operation type with the operation type ID for the access address in the resource access request, translates this access address from a virtual address to a physical address based on the first page table, and forwards this resource access request to this physical address, so that the operation requested by the resource access request is performed on the physical address.
[0116] Optionally, in addition to the embodiment shown in Figure 9, step 308 may further include the following steps. If the first confirmation result determines that the requester does not have access rights to the access address, in response to the access address in the resource access request not belonging to at least one of the accessible address spaces in the security control information, or if the second confirmation result determines that the requester does not have the authority to perform an operation on the access address in the resource access request by identifying the operation type with the operation type ID, the resource access request may be rejected, an error message may be fed back to the requester for this resource access request, and / or, if the operation type identified by the operation type ID is a read operation, all zero data may be returned, and if the operation type identified by the operation type ID is a write operation, the data requested to be written to the access address carried in the resource access request may be discarded.
[0117] Optionally, in some other embodiments, additional hardware for implementing authority control may be provided on the integrated circuit to carry out an embodiment of the resource access control method, and this additional hardware will hereafter be referred to as an authority control module. In specific applications, this authority control module may be provided on the slave, which is the resource side, on the master, which is the requesting side, or independently at any position between the requesting side and the resource side in the integrated circuit, and is not limited to the embodiments of this disclosure.
[0118] Figure 10 is a schematic flowchart of a resource access control method according to yet another exemplary embodiment of the present disclosure. This embodiment can be applied to an authorization control module. As shown in Figure 10, in addition to the embodiment shown in Figure 7 above, this embodiment further includes the following step 502 after step 302. In step 502, the requester ID, security status information, DRM attribute information, resource ID, and access address are obtained from the resource access request.
[0119] The aforementioned resource-side ID is used to identify the resource on which the resource access request originated.
[0120] Optionally, in some of these embodiments, if an access control module is provided on the resource side, the access control information described above may include a requesting party list that is permitted to access the resource side, and this requesting party list includes at least one master ID, each master ID used to uniquely identify one master that can be a requesting party.
[0121] Figure 11 is a schematic flowchart of a resource access control method according to yet another exemplary embodiment of the present disclosure, which can be applied to an authorization control module installed on the resource side. As shown in Figure 11, in addition to the embodiment shown in Figure 10, step 502 is: The process may further include a step of obtaining an operation type ID from the resource access request to identify the operation type corresponding to the resource access request.
[0122] Accordingly, referring to Figure 11, in this embodiment, step 304 may specifically include the following step 3046. In step 3046, the first determination result is obtained by determining whether the requesting party has access rights to the resource based on whether the requesting party ID is included in the list of requesting parties that are permitted to access the resource in the access rights control information.
[0123] In some embodiments of this embodiment, the security control information described above may include access permission attribute information for at least one accessible address space.
[0124] Optionally, in some of these embodiments, the access rights attributes of each accessible address space can be determined based on the security attribute information of the resource corresponding to each accessible address space, depending on the security requirements of the relevant functions and information protection, or further determined in combination with the current state of the corresponding resource. For specifics, please refer to the relevant introductions in the embodiments described above, which are omitted here.
[0125] Accordingly, referring to Figure 11, in this embodiment, step 306 may specifically include the following steps 3066 to 3068.
[0126] In step 3066, the first confirmation result confirms that the requesting party has access rights to the resource, in response to the requesting party ID being included in the requesting party list. Access rights attribute information for the target accessible address space to which the access address in the resource access request belongs is obtained from the security control information.
[0127] The aforementioned target accessible address space is the accessible address space in which the access address is included in the resource access request in the security control information.
[0128] In step 3068, it is determined whether the requesting party has the authority to perform an operation to identify the operation type by the operation type ID for the access address, based on the access authority attribute information of the target accessible address space, the operation type ID in the resource access request, and one of the DRM attribute information and security status information in the resource access request.
[0129] Optionally, referring to Figure 11, in some of these embodiments, step 308 may specifically include the following step 3084. In step 3084, the second confirmation result, in response to the requesting party having the authority to perform an operation on the access address by identifying the operation type with the operation type ID, forwards the resource access request to the access address in the resource access request so that the operation requested by the resource access request is performed on the access address.
[0130] Optionally, in addition to the embodiment shown in Figure 11, step 308 may further include the following steps. If the first confirmation result is that the requester ID is not included in the requester list, and therefore the requester does not have access rights to the resource, or if the second confirmation result is that the requester does not have the authority to perform an operation by identifying the operation type with the operation type ID for the access address, the resource access request may be rejected, an error message may be fed back to the requester for this resource access request, and / or, if the operation type identified by the operation type ID is a read operation, all zero data may be returned, and if the operation type identified by the operation type ID is a write operation, the data requested to be written to the access address carried in the resource access request may be discarded.
[0131] Optionally, in some of these embodiments, if an authorization control module is provided on the requesting side, the access authorization control information may include a resource-side list that is permitted access on the requesting side, the resource-side list includes at least one slave ID, each slave ID used to uniquely identify one slave that can be a resource.
[0132] Figure 12 is a schematic flowchart of a resource access control method according to a further exemplary embodiment of the present disclosure, which can be applied to an authorization control module provided on the requesting side. As shown in Figure 12, in addition to the embodiment shown in Figure 10, step 502 may further include the step of obtaining an operation type ID to identify the operation type corresponding to the resource access request from the resource access request.
[0133] Accordingly, referring to Figure 12, in this embodiment, step 304 may specifically include the following step 3048. In step 3048, the first determination result is obtained by determining whether the requesting party has access rights to this resource based on whether the resource ID in the resource access request is included in the resource list.
[0134] In some embodiments of this embodiment, the security control information described above may include access permission attribute information for at least one accessible address space corresponding to each resource-side ID in the resource-side list.
[0135] Optionally, in some of these embodiments, the access rights attributes of each accessible address space can be determined based on the security attribute information of the resource corresponding to each accessible address space, depending on the security requirements of the relevant functions and information protection, or further determined in combination with the current state of the corresponding resource. For specifics, please refer to the relevant introductions in the embodiments described above, which are omitted here.
[0136] Accordingly, referring to Figure 12, in this embodiment, step 306 may specifically include the following steps 3070 to 3072.
[0137] In step 3070, in response to the first confirmation result indicating that the resource-side ID is included in the resource-side list, it is confirmed that the requesting party has access rights to the resource-side, and access rights attribute information for the target accessible address space to which the access address in the resource access request belongs is obtained from the security control information.
[0138] The aforementioned target accessible address space is the accessible address space in which the access address is included in the resource access request in the security control information.
[0139] In step 3072, it is determined whether the requesting party has the authority to perform an operation to identify the operation type by the operation type ID for the access address, based on the access authority attribute information of the target accessible address space, the operation type ID in the resource access request, and one of the DRM attribute information and security status information of the resource access request.
[0140] Optionally, referring to Figure 12, in some of these embodiments, step 308 may specifically include the following step 3086. In step 3086, the second confirmation result, in response to the requesting party having the authority to perform an operation on the access address by identifying the operation type with the operation type ID, forwards the resource access request to the access address in the resource access request so that the operation requested by the resource access request is performed on the access address.
[0141] Optionally, in addition to the embodiment shown in Figure 12, step 308 is: The first confirmation result may, in response to the resource-side list not containing the resource-side ID in the resource access request, confirm that the requester does not have access rights to the resource-side, or the second confirmation result may, in response to the requester not having the authority to perform an operation to identify the operation type by operation type ID for the access address, reject the resource access request and provide feedback to the requester regarding the resource access request, and / or, if the operation type identified by the operation type ID is a read operation, return all zero data, and if the operation type identified by the operation type ID is a write operation, discard the data requested to be written to the access address carried in the resource access request.
[0142] The exemplary embodiments of the method and the exemplary embodiments of the system correspond to each other in their embodiments, and relevant content can be referenced from each other. The beneficial technical effects of the exemplary method can be referenced from the corresponding beneficial technical effects of the exemplary system portion described above, and are not described here.
[0143] [Example equipment] Furthermore, embodiments of this disclosure further provide vehicles including integrated circuits according to any of the above embodiments.
[0144] Furthermore, embodiments of the present disclosure further provide electronic devices including a processor, memory, and a resource access control device. The memory stores executable instructions for the processor. The processor reads and executes the executable instruction from memory, thereby controlling the resource access control device to execute the resource access control method of any embodiment of the present disclosure.
[0145] Figure 13 is a structural diagram of an electronic device according to an embodiment of the present disclosure, which includes at least one processor 11, at least one memory 12, and a resource access control device 13 connected by a bus 10.
[0146] The processor 11 can be a central processing unit (CPU) or another form of processing unit having data processing capability and / or instruction execution capability, and can control other components in an electronic device to perform desired functions.
[0147] The memory 12 may include one or more computer program products, which may include various forms of computer-readable storage media such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or high-speed cache memory (cache). Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. The computer-readable storage media may store one or more computer program instructions, and one of the processors 11 may execute one or more computer program instructions to realize the resource access control method and / or other desired functions of each embodiment of the present disclosure described above.
[0148] As an example, the electronic equipment may further include input devices 14 and output devices 15 that are interconnected by a bus system and / or other forms of connection mechanisms (not shown).
[0149] The input device 14 may include, for example, a touchscreen, an audio input unit, a sensor, and the like.
[0150] The output device 15 can output various types of information to the outside. This output device 15 may include a display, speaker, printer, communication network, and remote output devices connected thereto.
[0151] For simplicity, Figure 13 shows only some of the components of the electronic device relating to this disclosure, omitting components such as buses and input / output interfaces. Further components may be provided as needed, depending on the specific application.
[0152] [Examples of computer program products and computer-readable storage media] Embodiments of the present disclosure may further provide a computer program product including computer program instructions, in addition to the methods and equipment described above. When these computer program instructions are executed by a processor, the processor can be caused to perform steps in the resource access control methods of the various embodiments of the present disclosure described in the “Exemplary Methods” portion above.
[0153] A computer program product can be created using any combination of one or more programming languages to produce program code for performing operations of the embodiments of the present disclosure, and such programming languages may include object-oriented programming languages such as Java and C++, and may also include general procedural programming languages such as the C language or similar programming languages. The program code may be executed as follows: it may be executed entirely on a user computing device, partially on a user device, as a standalone software package, partially on a user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0154] Furthermore, embodiments of the present disclosure can provide a computer-readable storage medium in which computer program instructions are stored. When these computer program instructions are executed by a processor, the processor can be caused to perform steps in the resource access control methods of the various embodiments of the present disclosure described in the “Exemplary Methods” portion above.
[0155] Any combination of one or more types of readable media can be used as a computer-readable storage medium. A readable medium can be a readable signal medium or a readable storage medium. A readable storage medium may include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any combination thereof. More specific examples (non-exclusive list) of readable storage media include electrical connections with one or more wires, portable disks, hard drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.
[0156] While the basic principles of this disclosure have been explained above with reference to specific embodiments, the advantages, merits, and effects mentioned herein are illustrative and not limiting, and various embodiments of this disclosure do not necessarily possess these advantages, merits, and effects. Furthermore, the specific details of the above disclosure are illustrative and for ease of understanding purposes only, and are not limiting, and the above details do not necessarily restrict this disclosure to being realized by such specific details.
[0157] The above description is provided for illustrative and illustrative purposes only. Furthermore, this description is not intended to limit embodiments of the present disclosure to the forms disclosed herein. While several exemplary aspects and embodiments have been described above, those skilled in the art will be able to recognize certain variations, modifications, changes, additions, and subcombinations thereof.
Claims
1. The system includes a plurality of hardware modules and a resource access control device connected to the plurality of hardware modules via a bus, wherein at least one of the plurality of hardware modules is an integrated circuit arranged to correspond to at least one operating system, The resource access control device described above is The system receives a resource access request from the requesting party, which includes a requesting party identifier for identifying the requesting party that initiated the resource access request, security attribute information, and an access address. Based on pre-configured access control information, it is determined whether the requesting party has access rights to the resource corresponding to the access address, and a first determination result is obtained. In response to the first confirmation result indicating that the requesting party has access rights to the resource side, the requesting party determines whether or not it has operational rights to the access address based on pre-configured security control information and security attribute information, and obtains a second confirmation result. Based on the second confirmed result, the system is configured to process the resource access request. The requesting party is one of the at least one hardware modules, The requesting party is located in the corresponding operating system. The resource side is one hardware module other than the at least one hardware module among the plurality of hardware modules. An integrated circuit characterized by the following features.
2. The integrated circuit according to claim 1, further comprising a configuration register configured to assign the security attribute information to the at least one hardware module.
3. The security attribute information includes at least one of the following: security status information representing the security attributes of the requesting party, and data access control attribute information representing the data access control attributes of the requesting party. The integrated circuit according to any one of claims 1 to 2.
4. The resource access control device includes at least one of a system memory management unit and an authorization control module. The integrated circuit according to feature 3.
5. If the resource access control device includes a system memory management unit, the resource access request includes a stream identifier, security status information, and access address, and the stream identifier includes the requesting identifier based on a preset format and data authority management attribute information. The system memory management unit is further configured to obtain a stream identifier, security status information, and access address from the resource access request, and to obtain the requesting identifier and data authority management attribute information from the stream identifier based on the preset format. The integrated circuit according to feature 4.
6. The aforementioned system memory management unit further, From the resource access request, an operation type identifier is obtained to identify the operation type corresponding to the resource access request. Obtain the first page table corresponding to the requesting identifier, Based on whether the access address belongs to the at least one accessible address space, the requesting party is determined to determine whether it has access rights to the resource, and a first determination result is obtained. In response to the first determination result indicating that the access address belongs to at least one accessible address space among the security control information, the requesting party determines whether or not it has access rights to the access address, and obtains access rights attribute information of the target accessible address space to which the access address belongs from the security control information which includes access rights attribute information of the at least one accessible address space. Based on the access rights attribute information of the target accessible address space, the operation type identifier, and one of the data rights management attribute information and the security status information, it is determined whether the requesting party has the right to perform an operation to identify the operation type using the operation type identifier for the access address, and the second determination result is obtained. The second confirmation result is further configured to, in response to the requesting party having the authority to perform an operation on the access address using the operation type identifier, translate the access address from a virtual address to a physical address based on the first page table, and forward the resource access request to the physical address to perform the operation requested by the resource access request on the physical address. The aforementioned first page table is a page table to which the requesting party has access rights, The first page table includes at least one accessible address space corresponding to at least one resource side and access permission attribute information for each of the said accessible address spaces, The integrated circuit according to feature 5.
7. If the resource access control device includes an authorization control module, and the authorization control module is provided on the resource side, the authorization control module further includes: Each of the following is obtained from the resource access request: the requesting party identifier, the security status information, the data authority management attribute information, the resource-side identifier, the operation type identifier, and the access address. Based on whether the requesting party identifier is included in the requesting party list that permits access to the resource in the access rights control information, it is determined whether the requesting party has access rights to the resource, and the first determination result is obtained. In response to the first confirmation result indicating that the requesting party identifier is included in the requesting party list, it is confirmed that the requesting party has access rights to the resource side, and access rights attribute information of the target accessible address space to which the access address belongs is obtained from the security control information which includes access rights attribute information of at least one accessible address space, Based on the access rights attribute information of the target accessible address space, the operation type identifier, and one of the data rights management attribute information and the security status information, it is determined whether the requesting party has the right to perform an operation to identify the operation type using the operation type identifier for the access address, and the second determination result is obtained. The second confirmation result is configured to forward the resource access request to the access address in response to the requesting party having the authority to perform an operation on the access address using the operation type identifier, so that the operation requested by the resource access request is performed on the access address. The resource-side identifier is for identifying the resource side to which the resource access request is requesting access. The aforementioned operation type identifier is for identifying the operation type corresponding to the resource access request. The integrated circuit according to feature 4.
8. If the resource access control device includes an authorization control module, and the authorization control module is provided on the requesting side, the authorization control module further includes: From the resource access request, the requesting party identifier, the security status information, the data authority management attribute information, the resource-side identifier, the operation type identifier, and the access address are obtained, respectively. Based on whether the resource-side identifier is included in the resource-side list, the requesting party is determined to determine whether it has access rights to the resource-side, and the first determination result is obtained. In response to the first confirmation result indicating that the resource-side identifier is included in the resource-side list, the requesting party is determined to have access rights to the resource-side, and access rights attribute information for the target accessible address space to which the access address belongs is obtained from the security control information, which includes access rights attribute information for at least one accessible address space corresponding to each resource-side identifier in the resource-side list. Based on the access rights attribute information of the target accessible address space, the operation type identifier, and one of the data rights management attribute information and the security status information, it is determined whether the requesting party has the right to perform an operation to identify the operation type using the operation type identifier for the access address, and the second determination result is obtained. The second confirmation result is configured to forward the resource access request to the access address in response to the requesting party having the authority to perform an operation on the access address using the operation type identifier, so that the operation requested by the resource access request is performed on the access address. The aforementioned resource-side identifier is for identifying the resource side to which the resource access request is requesting access. The aforementioned operation type identifier is for identifying the operation type corresponding to the resource access request. The integrated circuit according to feature 4.
9. A resource access control method in which each step is performed by a resource access control device in an integrated circuit, The steps include receiving a resource access request that includes a requesting party identifier, security attribute information, and access address, The steps include determining whether the requesting party has access rights to the resource corresponding to the access address based on pre-configured access rights control information, and obtaining a first determination result, The first confirmation result indicates that the requesting party has access rights to the resource side. In response to this, the second confirmation result is obtained by determining, based on pre-configured security control information and security attribute information, whether the requesting party has operational rights to the access address. The step of processing the resource access request based on the second confirmed result is included, The aforementioned requesting party identifier is for identifying the requesting party that initiates the resource access request. The requesting party is deployed in the corresponding operating system. A resource access control method characterized by the following:
10. The security attribute information includes at least one of security status information representing the security attributes of the requesting party and data access control attribute information representing the data access control attributes of the requesting party. The resource access control method according to feature 9.
11. The resource access control method, after receiving a resource access request, The steps include obtaining, from the resource access request, the requesting party identifier based on a preset format, a stream identifier including the data authority management attribute information, the security status information, and the access address, respectively. The step of obtaining the requesting identifier and the data authorization management attribute information from the stream identifier based on the preset format, further includes: The resource access control method according to claim 10.
12. The resource access control method further includes, after receiving a resource access request, obtaining an operation type identifier from the resource access request to identify the operation type corresponding to the resource access request, The step of determining whether the requesting party has access rights to the access address based on the pre-configured access rights control information and obtaining a first determination result is: A step of obtaining a first page table corresponding to the requesting identifier, wherein the first page table is a page table on which the requesting party has access rights, and the first page table includes at least one accessible address space corresponding to at least one resource side and access rights attribute information for each of the accessible address spaces, The step of determining whether the requesting party has access rights to the resource party based on whether the access address belongs to the at least one accessible address space, and obtaining the first determination result, includes: In response to the first confirmation result indicating that the requesting party has access rights to the resource side, the step of determining whether the requesting party has operational rights to the access address based on pre-configured security control information and security attribute information is: The first confirmation result determines that the access address belongs to at least one accessible address space among the security control information, and the requesting party determines that it has access rights to the access address; the step of obtaining access rights attribute information of the target accessible address space to which the access address belongs from the security control information which includes access rights attribute information of the at least one accessible address space; The step includes determining whether the requesting party has the authority to perform an operation on the access address by identifying the operation type with the operation type identifier, based on the access authority attribute information of the target accessible address space, the operation type identifier, and one of the data authority management attribute information and the security status information. The resource access control method according to feature 11.
13. Based on the second confirmed result, the step of processing the resource access request is: In response to the second confirmation result indicating that the requesting party has the authority to perform an operation on the access address using the operation type identifier, the process includes the steps of translating the access address from a virtual address to a physical address based on the first page table and forwarding the resource access request to the physical address, so as to perform the operation requested by the resource access request on the physical address. The resource access control method according to feature 11.
14. Based on the second confirmed result, the step of processing the resource access request is: In response to the second confirmation result indicating that the requesting party has the authority to perform an operation on the access address using the operation type identifier, the process includes the steps of translating the access address from a virtual address to a physical address based on the first page table and forwarding the resource access request to the physical address, so as to perform the operation requested by the resource access request on the physical address. The resource access control method according to feature 12.
15. The resource access control method, after receiving a resource access request, The process further includes obtaining, from the resource access request, the requesting party identifier, the security status information, the data access management attribute information, the resource-side identifier, and the access address, respectively, for identifying the resource side to which the resource access request is requesting access. The resource access control method according to claim 10.
16. The resource access control method, after receiving a resource access request, The process further includes the step of obtaining an operation type identifier from the resource access request in order to identify the operation type corresponding to the resource access request, The step of determining whether the requesting party has access rights to the access address based on pre-configured access rights control information, and obtaining a first determination result, is: The step of obtaining the first determination result is further included in determining whether the requesting party has access rights to the resource based on whether the requesting party identifier is included in the requesting party list that permits access to the resource in the access rights control information, In response to the first confirmation result indicating that the requesting party has access rights to the resource side, the step of determining whether the requesting party has operational rights to the access address based on pre-configured security control information, security attribute information, and operation type identifier is: The first confirmation result is determined to be in response to the requesting party identifier being included in the requesting party list, and the requesting party has access rights to the resource side; the access address obtains access rights attribute information of the target accessible address space from the security control information which includes access rights attribute information of at least one accessible address space; The step includes determining whether the requesting party has the authority to perform an operation on the access address by identifying the operation type with the operation type identifier, based on the access authority attribute information of the target accessible address space, the operation type identifier, and one of the data authority management attribute information and the security status information. The resource access control method according to feature 15.
17. The resource access control method, after receiving a resource access request, The process further includes obtaining an operation type identifier from the resource access request to identify the operation type corresponding to the resource access request, The step of determining whether the requesting party has access rights to the access address based on pre-configured access rights control information, and obtaining a first determination result, is: The step of determining whether the requesting party has access rights to the resource based on whether the resource identifier is included in the resource list, and obtaining the first determination result, includes the step of determining whether the requesting party has access rights to the resource. In response to the first confirmation result indicating that the requesting party has access rights to the resource side, the step of determining whether the requesting party has operational rights to the access address based on pre-configured security control information, security attribute information, and operation type identifier is: The first confirmation result confirms that the resource-side identifier is included in the resource-side list, and the requesting party has access rights to the resource-side; the security control information includes access rights attribute information for at least one accessible address space corresponding to each resource-side identifier in the resource-side list; and the access rights attribute information for the target accessible address space to which the access address belongs is obtained from the security control information, which includes access rights attribute information for at least one accessible address space corresponding to each resource-side identifier in the resource-side list. The step includes determining whether the requesting party has the authority to perform an operation on the access address by identifying the operation type with the operation type identifier, based on the access authority attribute information of the target accessible address space, the operation type identifier, and one of the data authority management attribute information and the security status information. The resource access control method according to feature 15.
18. Based on the second confirmed result, the step of processing the resource access request is: The second confirmation result includes the step of forwarding the resource access request to the access address so that the access address can perform the operation requested by the resource access request, in response that the requesting party has the authority to perform the operation type by the operation type identifier for the access address. The resource access control method according to feature 15.
19. Based on the second confirmed result, the step of processing the resource access request is: The second confirmation result includes the step of forwarding the resource access request to the access address so that the access address can perform the operation requested by the resource access request, in response that the requesting party has the authority to perform the operation type by the operation type identifier for the access address. The resource access control method according to feature 16.
20. Based on the second confirmed result, the step of processing the resource access request is: The second confirmation result includes the step of forwarding the resource access request to the access address so that the access address can perform the operation requested by the resource access request, in response that the requesting party has the authority to perform the operation type by the operation type identifier for the access address. The resource access control method according to claim 17, characterized by the features described above.
21. A computer-readable storage medium in which a computer program is stored, wherein when the computer program is executed, the method according to any one of claims 9 to 20 is realized. A computer-readable storage medium characterized by the following features.
22. An electronic device including a processor, memory, and a resource access control device, The memory is for storing instructions that the processor can execute, The processor reads and executes the executable instructions from the memory, thereby controlling the resource access control device to perform the method according to any one of claims 9 to 20. An electronic device characterized by the following features.