Apparatus and method for controlling access to a set of memory mapped control registers

By utilizing a lockdown register to restrict write operations to memory-mapped control registers through specific subsets of store instructions, the system effectively mitigates the risk of unauthorized access and enhances security.

JP7695943B2Active Publication Date: 2025-06-19ARM LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2022546038
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-01-30
Filing Date
2020-12-21
Publication Date
2025-06-19
Estimated Expiration
2040-12-21

AI Technical Summary

Technical Problem

Existing systems face a significant risk of security breaches where an attacker can modify memory-mapped control registers, compromising system security by potentially altering memory protection boundaries.

Method used

The implementation of a lockdown register that stores a lockdown value, which prevents write operations to memory-mapped control registers unless performed by specific subsets of store instructions, thereby reducing the risk of unauthorized access.

Benefits of technology

This solution significantly reduces the likelihood of attackers exploiting software bugs to modify memory-mapped control registers, thereby enhancing system security by restricting unauthorized access to critical control information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007695943000001
    Figure 0007695943000001
  • Figure 0007695943000002
    Figure 0007695943000002
  • Figure 0007695943000003
    Figure 0007695943000003
Patent Text Reader

Abstract

A technique for controlling access to a set of memory-mapped control registers is described. The apparatus includes a processing circuit that executes program code to perform data processing operations and a set of memory-mapped control registers that store control information used to control operation of the processing circuit when executing the program code. Furthermore, a lockdown register is used to store a lockdown value. The processing circuit is configured to execute store instructions to perform write operations in a memory address space, the store instructions being of multiple types. However, when the lockdown value is set, the processing circuit is configured to prevent a write operation from being performed to modify the control information in the memory-mapped control registers unless the write operation is caused by execution of a store instruction from a first subset of the multiple types of store instructions. This significantly reduces the likelihood that an attacker will exploit a software vulnerability to modify the control information in the memory-mapped control registers.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] This technique relates to an apparatus and method for controlling access to a set of memory-mapped control registers.

[0002] A data processing apparatus may have a processing circuit that executes program code, and may be provided with control registers for storing control information used to control the operation of the processing circuit during the execution of the program code. Conventionally, such control registers have sometimes been provided as hardware registers that can be accessed directly by the processing circuit, but recently it has become common for one or more of the control registers to be provided as memory-mapped registers. Therefore, when a region of the memory address space is allocated to those control registers, by preparing a memory access instruction used to access the memory to specify the address corresponding to the relevant memory-mapped control register, it is possible to access those memory-mapped control registers by executing the memory access instruction. By using memory-mapped control registers, it becomes possible to reduce the internal logic within the data processing apparatus, and thus can contribute to the production of a smaller, less expensive, and more efficient data processing apparatus. This may also mean that programming of the apparatus becomes easier because it is possible to access the control registers from a high-level language such as C without the need to use dedicated instructions from assembly code.

[0003] To control access to various memory-mapped control registers, a well-known memory access control mechanism can be used to control which items of software running on a data processing device can access which regions of memory. However, if there is a bug in the software running in the system, an attacker may be able to modify the contents of a certain memory-mapped control register, thus putting the system at risk. For example, a specific memory-mapped control register is only allowed to be updated by software running at a specific trusted level. However, if there is a bug in the trusted software, an attacker running untrusted software may be able to access a memory write gadget in the trusted software, and thus may be able to update the contents of one or more memory-mapped control registers that should not be accessible from untrusted software. Such an act may put the system at significant risk. For example, control information used to enforce memory protection boundaries between different items of software running in the system may be provided by one or more of the memory-mapped control registers. If an attacker can modify that control information, it may allow the attacker to obtain access to the confidential data of other software running in the system, and the security of the system may be significantly put at risk.

[0004] Therefore, it would be desirable to reduce the possibility that an attacker can perform such an attack while allowing the trusted software to update the contents of the control register. Summary of the Invention

[0005] In one configuration example, an apparatus is provided that includes a processing circuit that executes program code to perform data processing operations, a set of memory-mapped control registers that store control information used to control the operation of the processing circuit when the program code is executed, and a lockdown register that stores a lockdown value. The processing circuit is configured to execute a store instruction to perform a write operation in a memory address space, the store instruction consists of multiple types, and the processing circuit is configured to prevent a write operation from being performed to change the control information in the memory-mapped control register when the lockdown value is set, unless the write operation is caused by the execution of a store instruction from a first subset of the multiple types of store instructions.

[0006] In another configuration example, a method for controlling access to a set of memory-mapped control registers in an apparatus is provided. The method includes executing program code in a processing circuit to perform data processing operations, storing control information used to control the operation of the processing circuit when the program code is executed in the set of memory-mapped control registers, storing a lockdown value in a lockdown register, and executing a store instruction in the processing circuit to perform a write operation in a memory address space, where the store instruction consists of multiple types. The method also includes preventing a write operation from being performed to change the control information in the memory-mapped control register when the lockdown value is set, unless the write operation is caused by the execution of a store instruction from a first subset of the multiple types of store instructions by the processing circuit.

[0007] In yet another configuration example, a computer program is provided for controlling a host data processing device to provide an instruction execution environment. This program includes a processing program logic that executes program code to perform data processing operations, and a control program logic that maintains a set of memory-mapped control data structures for storing control information used to control the operation of the processing program logic when the program code is executed, and also maintains a lockdown data structure for storing a lockdown value. The processing program logic is configured to execute a store instruction to perform a write operation in a memory address space. The store instruction consists of multiple types. The processing program logic is configured to prevent a write operation from being performed to change the control information in the memory-mapped control data structure when the lockdown value is set, unless the write operation is caused by the execution of a store instruction from a first subset of the multiple types of store instructions. A computer-readable medium may be provided for storing such a computer program, and the computer-readable medium may be in a non-transitory or transitory form.

Brief Description of the Drawings

[0008] This technique will be further described by way of example only with reference to the examples of this technique shown in the accompanying drawings.

Figure 1

Figure 2

Figure 3A

Figure 3B

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8A

Figure 8B

Figure 9

[0009] According to one implementation example, an apparatus is provided that includes a processing circuit that executes program code to perform data processing operations, and a set of memory-mapped control registers that store control information used to control the operation of the processing circuit when the program code is executed. As described above, it is desirable that the content of such memory-mapped control registers can be updated using memory access instructions. However, it may also be desirable to reduce the possibility that an attacker can utilize a bug in the software running on the apparatus to change the content of one or more of the memory-mapped control registers using a memory write gadget in trusted software, thereby significantly endangering the security of the system as described above.

[0010] To reduce the risk of such attacks, the device may be provided with a lockdown register used to store a lockdown value. The processing circuit is configured to execute store instructions to perform write operations in the memory address space, and these store instructions consist of multiple types. When the lockdown value is set, the processing circuit is configured to prevent a write operation from being performed to change control information in the memory-mapped control register, unless the write operation is caused by the execution of a store instruction from a first subset of the multiple types of store instructions. Therefore, when the lockdown value is set, only store instructions within the first subset can be used to change the control information in the memory-mapped control register. This greatly reduces the possibility that an attacker can utilize a memory write gadget that can be used to change the control information in the memory-mapped control register. The reason is that when the lockdown value is set, any memory write gadget that uses a store instruction not within the first subset cannot be used to achieve this purpose.

[0011] It is understood that the actual value used to indicate the set state of the lockdown value may vary depending on the implementation. In one particular implementation example, the lockdown value is set when it has a value of "1" and is clear when it has a value of zero. Alternatively, it is understood that the lockdown value may be considered set when it has a value of zero and clear when it has a value of "1".

[0012] By setting a lockdown value, the possibility that a tracker attempts to update a memory-mapped control register by exploiting a software vulnerability in a trusted code can be significantly reduced. On the other hand, backward compatibility can be provided by enabling the lockdown value to be cleared. Specifically, when the lockdown value is cleared, the processing circuit may permit a write operation to be performed using a second subset in addition to a first subset of multiple types of store instructions to change control information in the memory-mapped control register, where the second subset does not overlap with the first subset.

[0013] In one implementation example, the first subset and the second subset may collectively identify all different types of store instructions that can be used. However, in an alternative implementation, there may be one or more types of store instructions that are not in the first subset or the second subset and thus cannot be used to update the control information in the memory-mapped control register regardless of whether the lockdown value is set or cleared.

[0014] When the lockdown value is set, the processing circuit prevents any writing to the memory-mapped control register using store instructions within a second subset of multiple types of store instructions. In some implementations, the processing circuit may be further configured to issue a fault exception when a store instruction from the second subset attempts to perform a write operation to a set of the memory-mapped control register.

[0015] Similar techniques may also be used in relation to load instructions used to read the contents of memory-mapped control registers. Thus, for example, the processing circuit, when the lockdown value is set, allows the reading of control information in the memory-mapped control register only if the reading is generated by a load instruction from a first subset of multiple types of load instructions, and further configures to prevent the reading of control information in the memory-mapped control register when the reading is generated by a load instruction from a second subset that does not overlap with the first subset of multiple types of load instructions.

[0016] Similar to the above-described processing of store instructions, the processing circuit can also be configured to issue a fault exception when a load instruction from the second subset attempts to perform a read operation on the memory-mapped control register set in a situation where the lockdown value is set.

[0017] The first subset of multiple types of store instructions can take various forms. In one embodiment, it includes store instructions specific to the control register. Thus, the processing circuit is configured to ignore the lockdown value when determining whether to permit the associated write operation to the memory-mapped control register when executing a store instruction specific to the control register. In some cases, the execution of a store instruction specific to the control register may always be permitted to update the memory-mapped control register, but in some implementations, it may be necessary to pass one or more other access checks before proceeding with the write operation. For example, a certain memory-mapped control register may be accessible only by software executed at a specific level of privilege or within a specific security domain. Therefore, it may be checked whether the software currently executing the store instruction specific to the control register is permitted to access the specific memory-mapped control register targeted by that store instruction specific to the control register before proceeding with the write operation.

[0018] In one implementation example, when the processing circuit executes a store instruction specific to a control register, if the memory address specified by the store instruction specific to that control register is outside the memory address range associated with the set of memory-mapped control registers, the processing circuit is configured to issue a fault exception. Since using a store instruction specific to a control register for a software developer to access other areas not related to the memory-mapped control register within the memory address space may increase the likelihood of finding a suitable memory write gadget that can be exploited by an attacker, it is desirable to deter the developer from such usage. For this purpose, issuing this fault exception can be convenient. In contrast, by ensuring that the store instruction specific to a control register is used conservatively, specifically, only when attempting to access a memory-mapped control register, the possibility of a write vulnerability that can be exploited by an attacker can be significantly reduced. Specifically, it is less likely that a memory write gadget that can be exploited by an attacker will include one or more instances of the store instruction specific to a control register.

[0019] There are several ways in which a memory address can be specified by a store instruction specific to a control register. In one implementation example, the memory address is determined based on the value stored in the register specified by the store instruction specific to the control register and the immediate value specified by the store instruction specific to the control register.

[0020] Therefore, in such an implementation, the store instruction specific to a control register does not directly specify the address of the memory-mapped control register to be accessed. Instead, based on the content of the register (typically a general-purpose register) specified by the store instruction and the immediate value specified by the store instruction, the address of the required memory-mapped control register is calculated when the store instruction specific to the control register is executed. For example, the general-purpose register may store a value used as a base address, and an immediate value may be added to the base address to determine the address of the memory-mapped control register to be accessed.

[0021]

[0021] In one particular implementation, after the address is calculated, the calculated address may be written back to the general-purpose register identified by the execution of the store instruction specific to the control register. This allows, for example, multiple iterations of a loop including the store instruction specific to the control register to be executed without the need for separate instructions to change the base address value used by that instruction.

[0022]

[0021] In a further implementation, there may be multiple variants of the register-specific store instruction that can perform store operations of various sizes. For example, there may be a variant of the register-specific store instruction that stores a 32-bit value in the register, a variant that stores a 16-bit value in the register, and another variant that stores an 8-bit value in the register. These variants may be useful when it is only necessary to update a portion of a large register.

[0023] In addition to the store instructions specific to the control register described above, load instructions specific to the control register may also be provided. Thus, when the processing circuit is executing a load instruction specific to the control register, the lockdown value may be ignored when determining whether to permit the associated read operation to be performed on the memory-mapped control register. As described above, here too, it may be necessary to pass one or more access checks before the read is permitted. Further, similar to when a store instruction specific to the control register is processed, when the processing circuit is executing a load instruction specific to the control register, if the memory address specified by the load instruction specific to the control register is outside the memory address range associated with the set of memory-mapped control registers, the processing circuit may be configured to issue a fault exception. Similar to the register-specific store instruction, the register-specific load instruction does not directly specify the address of the memory-mapped control register to be accessed. Instead, based on the content of the register (typically a general-purpose register) specified in the instruction and the immediate value specified in the instruction, the address of the necessary memory-mapped control register may be calculated by executing the load instruction specific to the control register. Similarly, there may be variants of the register-specific load instruction that perform load operations of various sizes.

[0024] In one implementation example, the lockdown register may be a hardware register directly accessible to the processing circuit. However, in an alternative implementation, the lockdown register may be provided within a set of memory-mapped control registers. This can simplify the processing of accesses to the memory-mapped control registers as it can avoid the need for a synchronization barrier that would otherwise be used when the lockdown value is changed. Specifically, the memory address region reserved for the memory-mapped control registers can be considered similar to device memory, and as a result, store instructions executed with respect to that address region cannot be reordered and must be performed sequentially. Thus, for example, if the code being executed by the processing circuit attempts to clear the lockdown value to permit the use of a subsequent standard store instruction to update the contents of a certain memory-mapped control register, when the lockdown register is provided within the set of memory-mapped control registers, the store instruction will be executed in the correct order without the need for a synchronization barrier, and thus it can be guaranteed that the lockdown value will be cleared before subsequent standard memory access instructions are executed, and thus the desired behavior with respect to the update of the memory-mapped control register will be adhered to.

[0025] In a situation where the lockdown register is provided within a set of memory-mapped control registers, the processing circuit may be configured to change the lockdown value within the lockdown register by executing one instance of a control-register-specific store instruction at a specified memory address corresponding to the lockdown register. In one implementation example, the lockdown value can only be changed by software executing at a particular trust level, and thus if software that is not at that trust level attempts to update the lockdown register using a control-register-specific store instruction, the update will fail.

[0026] Updates to the contents of the memory-mapped control registers can each time be carried out by one instance of a store instruction specific to the control register, but in some cases it may also be desirable to enable bulk changes to multiple memory-mapped control registers using standard store instructions. For example, the standard store instructions may include a store multiple instruction that provides an efficient mechanism for updating data over a range of memory addresses, and thus it may be possible to update multiple memory-mapped control registers in response to the execution of a single store multiple instruction. In one implementation example, rather than providing a store multiple variant of the store instruction specific to the control register, a lockdown value can be temporarily cleared to enable the standard store instruction to perform the requested update to the memory-mapped control register.

[0027] Specifically, the processing circuit may be controllable by software to perform a series of accesses to the memory-mapped control register by executing a store instruction specific to the control register to clear the lockdown value, executing one or more standard access instructions to access the memory-mapped control register, and then executing a store instruction to set the lockdown value.

[0028] In one implementation example, only the store instruction specific to the control register may be used to clear the lockdown value, but any type of store instruction may be able to set the lockdown value, and thus it may be possible to reset the lockdown value using a standard store instruction after accessing the memory-mapped control register using a standard access instruction.

[0029] The control information stored in the memory-mapped control register can take various forms, but in one implementation example it at least includes control information used to control which regions of the memory address space can be accessed by trusted program code and untrusted program code.

[0030] In one implementation example, the processing circuit is configured to permit a trusted program code to update a lockdown value in a lockdown storage, and to control the execution of a write operation to a memory-mapped control register by both an untrusted program code and a trusted program code using the lockdown value. Thus, in such an implementation, the trusted program code that updates the lockdown value is not only used to restrict access to the memory-mapped control register by software with a lower level of privilege or a lower security state, but it should also be noted that the lockdown value itself set by the trusted program code affects how the trusted program code can access the memory-mapped control register.

[0031] In other embodiments, the processing circuit is configured to permit a trusted program code to update a lockdown value in a lockdown storage, and while controlling the execution of a write operation to a memory-mapped control register by the trusted program code using the lockdown value, to control the execution of a write operation to the memory-mapped control register by an untrusted program code regardless of the state of the lockdown value. Thus, it should also be noted that the lockdown value is not used only to restrict access to the memory-mapped control register by software with a lower level of privilege or a lower security state. Such a configuration may be useful in a situation where there are non-critical registers that it is desirable to make accessible from untrusted program code while preventing other access checks from preventing an untrusted program code from accessing critical registers, and while locking access to critical registers that are accessible from trusted program code.

[0032] Trusted program code and untrusted program code can take various forms. In one implementation example, the processing circuit is configured to execute program code in one of a plurality of states including at least a privileged state and a non-privileged state, the trusted program code is the program code executed by the processing circuit in the privileged state, and the untrusted program code is the program code executed by the processing circuit in the non-privileged state.

[0033] Alternatively, or in addition, the processing circuit may be configured to execute program code in one of a plurality of security domains including at least a secure domain and a less secure domain, the trusted program code is the program code executed by the processing circuit in the secure domain, and the untrusted program code is the program code executed by the processing circuit in the less secure domain.

[0034] In an implementation where the processing circuit can execute program code in various security domains and also in various privileged states, in each of the security domains, the processing circuit may be configured to execute program code in one of a plurality of states including at least a non-privileged state and a privileged state. In such an implementation, the lockdown register can be configured to provide a lockdown value for each security domain. Thus, for example, the lockdown register may be partitioned to provide different lockdown values for each security domain.

[0035] As described above, in one embodiment, for example, during context switching, the lockdown value can be temporarily cleared to allow a grouped access to the memory-mapped control register. However, if an interrupt occurs during such a context switch, the interrupt handler responsible for handling the interrupt may unintentionally execute with the ability to access the memory-mapped control register using standard load and store instructions. Although it is relatively difficult to take advantage of this, there is also a possibility of providing an attacker with an opportunity to update the memory-mapped control register, thereby jeopardizing the security of the system. In one implementation example, in order to avoid such a situation, a lockdown value management process is performed in relation to exceptions. In one embodiment, the lockdown value management process includes saving the lockdown value currently stored in the lockdown register so that it can be restored when returning from the exception. However, in addition to that, the lockdown value in the lockdown register is then set before triggering the execution of the exception handling routine to process the exception. This means that when the exception handling routine is executing, only the exception handling routine can access the memory-mapped control register using the memory access instructions within the first subset. Then, when returning from the exception handling routine, the lockdown value in the lockdown register can be restored to the saved lockdown value, and thus, the code that was being executed before the exception can continue to execute using the lockdown value that existed before the exception was trapped.

[0036] In some implementations, the above behavior can always be implemented when an exception is caught. However, in an alternative implementation, an auto-lock register can be used to store an auto-lock value, and the processing circuit may be configured to set a lockdown value in relation to a lockdown value management process only when the auto-lock value is set, upon the occurrence of an exception. Thus, when the auto-lock value is set, not only is the current lockdown value present in the lockdown register saved before exception handling is performed so that it can be restored upon returning from the exception, but the lockdown value is also set in the lockdown register before triggering the execution of the exception handling routine. However, when the auto-lock value is clear, the current lockdown value is still saved and restored before and after returning from the exception handling routine, but the lockdown value is not set before triggering the execution of the exception handling routine. This makes it possible to configure the behavior of lockdown value management that occurs in response to an exception.

[0037] Similar to the lockdown register, the auto-lock register may be provided as a hardware register directly accessible from the processing circuit, or it may itself be provided as one of the memory-mapped control registers.

[0038] When an exception occurs, there are several ways in which the lockdown value currently stored in the lockdown register can be saved during the lockdown value management process. In one implementation example, when an exception occurs, the lockdown value currently stored in the lockdown register is saved as a field within a link register. The link register may typically be used to capture a return address, and the lockdown value may be provided as additional bits within the link register. In some implementations, a portion of the address space is reserved and not executable. Thus, a branch to an address within such a portion of the address space can be used to signal a special condition, such as a requirement to cause the hardware to perform an exception return to the background state. In one implementation example, when entering an exception, the return address captured in the link register is set to a dummy return address that specifies an address within the reserved non-executable address space, and instead, the actual return address may be saved on the stack. In such a situation, the lockdown value currently stored in the lockdown register can be saved as part of the dummy return address within the link register.

[0039] Here, a specific example will be described with reference to the figures.

[0040] FIG. 1 schematically shows an example of a data processing system 2 including a processing circuit that performs data processing in response to instructions fetched from a memory system 26. The memory system 26 may include a cache (e.g., one or more levels of data cache and / or instruction cache) and a main memory. In some larger systems, the main memory may include a single type of memory such as DRAM, for example, and in some smaller systems (e.g., microcontrollers), the main memory may include different types of memory such as flash memory for storing program code and constant values, and SRAM for storing values such as a stack that is changed during execution. The processing circuit includes a processing pipeline including several pipeline stages, and these pipeline stages include, for example, a fetch stage 12 that fetches instructions to be executed from the memory system 26, a decode stage 14 that decodes the fetched instructions to generate control signals for controlling the remaining pipeline stages to perform data processing, and an execution stage including an execution unit 4 that executes the decoded instructions to perform data processing operations. A register 6 is provided for storing source data (source operands) for access by the processing circuit during execution of instructions, and for storing result data (destination operands) generated by execution of these instructions.

[0041] Various different execution units may be provided, for example, a vector execution unit 16 that performs vector processing operations, an arithmetic logic unit (ALU) 17 that performs arithmetic operations, a load / store unit 18 that performs load and store operations to load data from the memory 26 to the register 6 or store data from the register 6 to the memory 26, and the like.

[0042] Furthermore, the apparatus 2 may be provided with control registers for storing control information used to control the operation of the apparatus 2. According to the techniques described herein, at least some of the control registers are provided as memory-mapped control registers 30 that are accessed using load and store instructions executed by the processing circuit. As shown in FIG. 2A, an area 55 of the memory address space 50 may be reserved for the memory-mapped control registers, which is denoted as the PPB (Private Peripheral Bus) address space in FIG. 2. Thus, access to a given memory-mapped control register may be performed by using a load or store instruction that specifies an address within the area 55 that stores the control information of the given memory-mapped control register. Optionally, one or more additional control registers 32 may be provided as hardware registers that can be directly accessed by the apparatus without executing a load or store instruction.

[0043] The pipeline stages shown in FIG. 1 are a simplified representation, and it is understood that other types of pipeline stages may also be provided, such as a renaming stage that performs register renaming, an issue stage that queues instructions waiting for execution and issues the instructions for execution when the source operands required for those instructions become available, and a write-back stage that processes the commit of the instructions and writes the results back to register 6. The pipeline can be an in-order or out-of-order pipeline.

[0044] The apparatus 2 can be configured in various ways. For example, even if the apparatus operates in a single security domain, the processing circuit may be able to operate in both privileged and non-privileged states. Alternatively, the apparatus may have a secure domain and a less secure domain, and each security domain may have only a single processing state. In a further example, the apparatus 2 may operate only in a single security domain and at a privileged level.

[0045] However, for the purposes of the examples considered in this specification, in the system, the processing circuit can operate in a plurality of security domains including a secure domain and a less secure domain, and within each of the security domains, the processing circuit is considered to be able to operate in a plurality of processing states including a non-privileged state and a privileged state.

[0046] Such a device 2 may also include a memory access check circuit 20 to check whether access to the memory system 26 is permitted based on the attribute data specified in various regions of the memory address space. The memory access check circuit may include a Security Attribute Unit (SAU) 24 that stores security domain definition data that defines the security domain associated with each corresponding region of the memory address space. Based on the security attribute data, the security attribute unit 24 can check whether the memory access is permitted according to the current security domain of the operation of the processing circuit and the security domain associated with the region including the target address of the memory access. In other implementations, the SAU 24 may access security domain definition data stored elsewhere to perform a memory access check instead of directly storing the security domain definition data. In some systems, the security domain definition data may be stored in a control register, such as a memory-mapped control register 30 for example.

[0047] The processing circuit may operate within the current security domain of operation, which may generally correspond to the security domain associated with the address of the currently executed instruction (although there may be some exceptions, for example when handling transitions between domains). When an instruction branches from an address within a region designated to be in one domain by the SAU24 to an address within a region associated with another domain, this may trigger a transition of the current security domain in which the processing circuit is operating. In other implementations, such a branch may not directly trigger a transition of the current security domain, but may trigger additional security checks such as the existence of a gateway instruction. In these implementations, the gateway instruction itself may trigger a change in the current security domain. For some other types of security domain transitions, special branch instructions may be used to branch to the execution of an instruction in another security state at the address specified by that instruction. Generally, while operating in a secure domain, the processing circuit can access data in memory regions associated with both the secure domain and the less secure domain, and when operating in the less secure domain, the processing circuit can access data in regions associated with the less secure domain, but may not be permitted to access data in the region of the address space designated by the SAU24 to be associated with the secure domain. This enables the protection of confidential data against unauthorized access from code operating in the less secure domain.

[0048] In addition, the memory access check circuit may include a Memory Protection Unit (MPU) 22 that checks whether a memory access to the memory system 26 meets the access permission. These access permissions may specify, for example, which privilege level of the processing circuit is permitted to access a given area of the memory, or whether a memory area in the address space is accessible by both read and write operations, or whether it is a read-only area where writing is prohibited. The access permissions used by the MPU 22 may be specified, for example, by a highly privileged process (such as a hypervisor or an operating system) to control which areas of the memory and how (read-only or read / write) a less privileged process (such as an application) is permitted to access. The permissions provided by the MPU 22 may be independent of the permissions provided by the SAU 24. Therefore, for a given memory access to be permitted, it must pass the checks based on the access permissions defined for both the MPU 22 and the SAU 24. Although the MPU 22 is shown as a single entity in FIG. 1, in some examples, there may be separate secure MPU 22 and less secure MPU 22, each associated with one of the security domains. Thus, depending on whether the current domain is a secure domain or a less secure domain, different memory access permissions can be specified for a given area of the memory (for example, an area is read-only in the less secure domain but readable and writable in the secure domain).

[0049] Access to the memory system 26 typically undergoes checking by the memory access check circuit 20. Access to the memory mapped control register 30 may also undergo checking by the memory access check circuit 20, or, in some cases, the memory mapped control register 30 may be accessed without performing a memory access check (as indicated by the dashed line in FIG. 1). In some embodiments where access to the memory mapped control register 30 is permitted, it may be possible to perform a detailed access control check by the memory mapped control register 30 itself by bypassing the memory access check circuit 20. For example, an untrusted software map may be able to access only some bits in a single register. General structures such as the SAU 24 or the MPU 22 may be restricted by a minimum area such as 32 bytes, for example, and it may be impractical to provide such a detailed access permission check for such structures.

[0050] As shown in FIG. 3A, the apparatus 2 may correspond to performing data processing in one of several security domains including at least a secure domain (S) and a low secure domain (LS). Although FIG. 3A shows a system having only two security domains, it is also possible to provide three or more domains related to different levels of security.

[0051] Also, within a given security domain, as shown in Figure 3A, the device may perform data processing in one of several modes, including a handler mode (H) and a thread mode (T). The handler mode is typically used for exception handling, and thus, for example, an exception handling routine may be executed in the handler mode. The thread mode is typically used to execute multiple different threads, e.g., multiple different application threads. When operating in the handler mode H, the processing circuit is assumed, by default, to have a relatively high-privilege operating mode, and thus, access to memory and control registers is controlled according to a privilege level at a level other than the low privilege level. On the other hand, in the thread mode T, the processing circuit may have one of several different privilege levels depending on other architectural states stored in the control registers.

[0052] Thus, as shown in Figure 3A, the combination of the mode in which the processing circuit is operating and the security domain may determine how processing is performed by the processing circuit. Figure 3A shows four different combinations of these modes, including the following combinations. · Secure thread mode (abbreviated representation of the combination of the secure domain and the thread mode) · Low-secure thread mode (combination of the low-secure domain and the thread mode) · Secure handler mode (combination of the secure domain and the handler mode) · Low-secure handler mode (combination of the low-secure domain and the handler mode) As described above, due to some of the control registers being memory-mapped control registers, in a situation where an attacker can use a memory write gadget in software at a trust level where access to such memory-mapped control registers is permitted, there is a possibility of creating an opportunity for the attacker to put the system at risk. This can be particularly problematic when some of the control registers store control information that controls which items of software can access which regions of memory. Specifically, such an attack or attacker can potentially put the security of the system at risk by appropriately modifying the control information used to control the operation of those memory access check components, by removing or modifying a part of the memory protection boundary enforced by the MPU22 and / or SAU24. As discussed in more detail herein, the possibility of an attacker being able to perform such an attack can be significantly reduced by using the lockdown value in the lockdown register 34 shown in FIG. 1. As shown in FIG. 1, in some implementations, an autolock register 36 may also be provided to enhance protection when handling exceptions. Both the lockdown register 34 and the autolock register 36 can be provided as hardware control registers directly accessible by the device, but in one particular implementation example, they are provided as control registers within the memory-mapped control register 30 and can thus be accessed using memory access instructions. As shown in FIG. 1, the processing circuit may include a control register access check circuit 38 that can be used to control access to at least some of the memory-mapped control registers 30 depending on the value of the lockdown value in the lockdown register 34.

[0053] As shown in FIG. 3B, when considering the plurality of different operating modes shown in FIG. 3A, FIG. 3B shows how memory access boundaries can be enforced between different items of software running within the system using control information within one of the memory mapped control registers 30. For example, within the low security thread mode, the processing circuitry may be configured to execute a plurality of threads 60, 62, 64, and if desired, the MPU control information for the low security domain provided in the memory mapped control register may be used to enforce access boundaries between different threads. This can be used, for example, to ensure that data processed by one thread is kept confidential from other threads, if considered appropriate. As further shown in FIG. 3B, such MPU control information for the low security domain can also enforce an access boundary between the low security thread mode and the low security handler mode, and data processed by software 66 running in the low security handler mode is kept confidential from any of the threads 60, 62, 64 running in the low security thread mode.

[0054] Similarly, equivalent MPU control information may be provided within the memory mapped control register 30 for the secure domain, and thus may be used to enforce a partition between different threads 70, 72, 74 running in the secure thread mode and to enforce an access boundary between a thread running in the secure thread mode and software 76 running in the secure handler mode.

[0055] As further shown in FIG. 3B, for example, SAU control information may be stored in the memory mapped control register to enforce an access boundary between the secure domain and the low security domain so that software running within the low security domain is reliably prevented from accessing data related to the secure domain.

[0056] These access boundaries enforced by the control information in the corresponding memory-mapped control register can provide a fine-grained level of protection for the data accessed by various items of software running on the processor. However, if there are any bugs in the software that can be exploited by an attacker, problems may occur. As an example, an attacker may configure non-privileged software 60 to run in a low-security handler mode. However, due to a software bug, software 60 may be able to trigger a memory write gadget in software 66 running in the low-security domain, whereby, for example, software 60 may use that memory write gadget to update the corresponding memory-mapped control register 30 and change the access boundaries enforced by the MPU control information in the low-security domain. This may, for example, effectively remove the boundary between the low-security thread mode and the low-security handler mode.

[0057] As another example, an attacker may exploit a software bug to enable software 66 operating in the low-security handler mode to trigger a memory write gadget in software 76 running in the secure handler mode and update the memory-mapped control register to change the access boundaries enforced by the SAU control information. In the worst-case scenario, this may effectively remove the boundary between the secure domain and the low-security domain, after which software in the low-security domain may be able to access data applicable to the secure domain.

[0058] However, as will be discussed in more detail herein, by using the lockdown value in the lockdown register 34, it is possible to significantly reduce an attacker's ability to attempt to carry out any of the above attacks.

[0059] FIG. 4 is a flowchart showing how a store instruction can be executed according to a lockdown value set in the lockdown register 34 according to one implementation example. At step 100, a store instruction to be executed by the processing circuit, specifically by the load / store unit 18, is encountered. At step 105, it is determined whether the store instruction specifies an address mapped to one of the control registers 30. As described above, the address applicable to the store instruction can be determined in a variety of ways. For example, the store instruction may specify a source register that includes a base address, and an immediate value used to adjust the base address may also be specified to determine the address accessed by the store instruction. Next, it can be determined whether the address is within the address range 55 associated with the memory-mapped control register 30, and thus it can be determined where the store instruction is requesting access to one of those control registers.

[0060] Otherwise, the process proceeds to step 110 where it is determined whether a store instruction specific to a control register is being used. Specifically, according to the techniques described herein, in addition to the normal types of store instructions that can be used to perform write operations with respect to memory, one or more types of store instructions specific to control registers can be defined. To maximize the ability to suppress the aforementioned attacks, it is desirable that such control register-specific store instructions be used very sparingly, and specifically, it is desirable that they be used only when accessing memory-mapped control registers. Therefore, if it is determined at step 110 that a control register-specific store instruction is not being used, and if it was determined at step 105 that the store instruction is not attempting to access one of the memory-mapped control registers, this is the expected behavior and the process may proceed to step 115 where the requested write operation may be performed. Whether the write operation is actually performed may be subject to an access check that is required to pass for the memory address being accessed, and such a memory check may be performed, for example, by the memory access check circuit 20 described above.

[0061] However, if it is determined at step 110 that a control register-specific store instruction is being used, in the example shown in FIG. 4, since the address being accessed is not mapped to one of the control registers, this is unauthorized behavior and thus the process proceeds to step 130 where the write operation is not performed and instead a fault exception is issued.

[0062] In step 105, if it is determined that the store instruction specifies an address mapped to one of the memory-mapped control registers, then in step 120, the processing circuit (in the example of FIG. 1, the control register access check circuit 38) determines whether the lockdown value is set. If not, the system operates in standard mode where the additional protection provided by this technique is not utilized, and thus the process proceeds to step 115, where the write operation is performed on the condition that the corresponding access check, if any, is passed.

[0063] However, if it is determined that the lockdown value is set, access is only permitted to proceed if a store instruction specific to the control register is being used. Accordingly, this is checked in step 125, and if a store instruction specific to the control register is being used, the process proceeds to step 115 where the write operation is performed, and here too, it undergoes any access checks that may be required. As described above, in one implementation, access to the memory-mapped control register may not be subject to checking by the memory access check circuit 20, and instead, the access path follows the path indicated by the dotted line in FIG. 1. In such a case, the access may be checked by a fine-grained check circuit that is part of the memory-mapped control register 30.

[0064] However, if it is determined in step 125 that a store instruction specific to the control register is not being used, the write operation is prevented and the process proceeds to step 130 where the write operation is not executed and instead a fault exception is issued.

[0065] The process of FIG. 4 is shown with respect to the execution of a store instruction, but a similar process can be performed to handle a load instruction, and here too, at least one control register-specific variant of the load instruction is provided, and when the lockdown value is set, reading from the memory-mapped control register is only possible using such a control register-specific load instruction.

[0066] Such an approach can significantly reduce the attack target area available to an attacker attempting to exploit attacks of the type described above. Specifically, when the lockdown value is set, the attacker needs to find a suitable memory write gadget that can be utilized via a software bug, and in this case, the memory write gadget needs to include one or more of the store instructions specific to the control register. The reason is that otherwise, the presence of the set lockdown value prevents the write operation initiated by the attacker using that memory write gadget from being performed on the content of the memory-mapped control register. Similarly, if the attacker attempts to use a memory read gadget by exploiting a bug to gain access to confidential information (such as an encryption key) within the memory-mapped control register 30, the attacker needs to identify an instance of the memory read gadget that includes one or more of the store instructions specific to the control register.

[0067] As described above, the lockdown register 34 used to store the lockdown value may be a hardware control register directly accessible by the device, but in one example, it is implemented as one of the memory-mapped control registers 30. By providing the lockdown register using one of the memory-mapped control registers, the need for any synchronization barriers is avoided. Specifically, the address space 55 reserved for the memory-mapped control register can be considered device memory, and for such memory, it is not possible to reorder instructions. In such a scenario, since a store instruction needs to be used to update the content of the lockdown register, this ensures that the change in the value of the lockdown value occurs at the correct time with respect to the preceding and subsequent read and write operations regarding the memory-mapped control register. Therefore, it is possible to ensure the intended access behavior without any need to synchronize the time when the lockdown value is changed and the time when the memory access operation is executed with respect to the memory-mapped control register.

[0068] FIG. 5 is a flow diagram showing how the lockdown value in a lockdown register can be updated when the lockdown register is implemented by one of the memory-mapped control registers. At step 150, it is determined whether the currently executing store instruction specifies the address of the lockdown register. If such a scenario is encountered, at step 155, it is determined whether the processor is operating in the required privileged state. Specifically, it is assumed that only software running in a certain privileged state is permitted to update the content of the lockdown register. If the processor is not operating in the required privileged state, a fault exception is issued at step 160.

[0069] However, if the processor is operating in the required privileged state, at step 165, it is determined whether the current lockdown value is set. If not, in one implementation example, the lockdown value can be set using any store instruction, and thus the process proceeds to step 175 where the lockdown value is updated in the lockdown register. However, if the current lockdown value is set, the lockdown value is only permitted to be updated using a store instruction specific to the control register, also referred to herein as the STRPPB instruction. Thus, if it is determined at step 165 that the current lockdown value is set, at step 170, it is determined whether the store instruction attempting to update the lockdown register is the STRPPB instruction. If not, a fault exception is issued at step 160. However, if the STRPPB instruction is being used, the process proceeds to step 175 where the lockdown value in the lockdown register is updated to reflect the new value specified by the store instruction. Thereafter, as shown in step 180, the updated lockdown value controls future accesses to the memory-mapped control register, at least depending on the privileged state.

[0070] In any case, although most of the access control registers may be accessed only from a privileged state, one or more of the control registers may be accessible from a non-privileged state. In some implementations, when the lockdown bit is set, regardless of whether the software is running in a non-privileged state or a privileged state, it is necessary to use a store instruction specific to the control register or a load instruction specific to the control register to access those control registers. In other implementations, the lockdown bit affects only access from the privileged state. Thus, when this bit is set, it is necessary to use a store instruction specific to the control register or a load instruction specific to the control register to access these control registers from the privileged state, but any load and store instructions may be permitted to access the control registers from the non-privileged state (subject to passing other access checks if any).

[0071] If access is required only to a single memory-mapped control register while the lockdown value is set, in one implementation example, the above-described store (STRPPB) instruction specific to the control register and load (LDRPPB) instruction are used.

[0072] However, it is considered inappropriate to attempt to provide control register specific variants for all possible types of store and load instructions. For example, typically, the instruction encoding space may be precious, and thus it may not be possible to provide control register specific variants for each of those instructions. Some memory access instructions contemplate bulk access to memory, and such instructions may also be referred to herein as store multiple instructions or load multiple instructions. They provide an efficient mechanism for performing bulk updates to memory, and thus it may be efficient to use such instructions to perform bulk updates to multiple memory mapped control registers. FIG. 6 is a flow diagram showing a mechanism that may be used to perform such bulk access when control register specific variants of the bulk store or load instructions are not provided.

[0073] In step 200, a STRPPB instruction is executed to clear the lockdown value in the lockdown register. This then opens a window through which the memory mapped control registers can be accessed using any store or load instruction. Thus, in step 205, one or more standard store or load instructions can be executed to perform the requested access to the memory mapped control registers. For example, at this point, the store multiple instruction or load multiple instruction described above may be used to improve the efficiency of the access.

[0074] After the required bulk access has occurred, a further store instruction can be executed at step 210 to set the lockdown flag. At this point, in the implementations described herein, note that the store instruction at step 210 need not be a STRPPB instruction; instead, any suitable store instruction can be used to set the lockdown flag. The reason for this is that setting the lockdown flag simply serves to enhance the security of the system and thus need not be restricted. In contrast, however, clearing the lockdown value can allow any memory access instruction to be used to access the memory mapped control register if the corresponding memory access check is performed. Therefore, it is desirable that clearing the lockdown value be tightly controlled, and hence, in the implementations described herein, it is necessary to use the STRPPB instruction to clear the lockdown value in the lockdown register.

[0075] As described above, the apparatus may be operable in different security domains including at least a secure domain and a less secure domain. It is possible to provide different lockdown values for each security domain, and thus the lockdown register may be partitioned as shown in FIG. 7 so that the lockdown value for each of the security domains can be stored. Thus, a lockdown value 250 for the secure domain may be provided, and a separate lockdown value 255 for the less secure domain may be provided. In one implementation, the lockdown value 250 for the secure domain can be set from a privileged state within the secure domain, and the lockdown value 255 for the less secure domain can be set from a privileged state within the less secure domain or from a privileged state within the secure domain. In other implementations, the lockdown register is partitioned between privileged and non-privileged states, and both states can independently control whether a unique variant of the load and store instructions is required when accessing the memory-mapped control register 30 from that state. In a further implementation, the lockdown register is partitioned between the security domain and the privileged state, and each of the four states shown in FIG. 3A can independently control whether a unique variant of the load and store instructions is required when accessing the memory-mapped control register 30 from that state.

[0076] As described above, in one embodiment, to perform a grouped register access (e.g., context switching), access to the PPB memory address space used to provide the memory-mapped control register can be temporarily unlocked. However, if an interrupt occurs during context switching, the interrupt handler may inadvertently execute with access to the PPB address space. Although it is relatively difficult for an attacker to exploit an attack based on this scenario, it may be desirable to suppress the ability for such an attack to occur. FIGS. 8A and 8B show how this is achieved in one implementation through the use of the auto-lock register 36 described above.

[0077] FIG. 8A shows a situation where thread T1 is operating as a background thread, and then a timer interrupt is triggered at point 300 to transfer to exception handler at point 305 used to perform the context switching and bulk access to the memory-mapped control register described above. Following the process described above with reference to FIG. 6, the exception handler code unlocks the PPB address space by clearing the lockdown value at this point, then performs the bulk access necessary to perform the context switching, after which the lockdown value is set again to lock the PPB address space again, after which the exception is processed at point 330 and the process returns to the execution of another background thread T2 at point 335.

[0078] However, if a higher-priority interrupt occurs at point 310 and this interrupt is taken in the middle of the execution of the context-switch interrupt handler code that is performing a bulk access, this interrupt is accepted at point 310, causing a transfer to another exception handler code necessary to process the interrupt at point 315. At this point, the memory-mapped control register address space is unlocked, and therefore, it should be noted that although the exception handler in operation between points 315 and 320 may not intentionally access the memory-mapped control register, it has the access right. When the exception handler code is completed at point 320, the process returns to point 325, and then the context-switch exception handler routine being processed in response to the original timer interrupt continues the bulk access, and then relocks the PPB address space by resetting the lockdown value, and then transfers to the background code T2 between points 330 and 335.

[0079] It may be desirable to prevent the unintentional results of an exception handling routine that has unrestricted access to a memory-mapped control register, which is executed between points 315 and 320. As shown in FIG. 8B, this can be accomplished through the use of the autolock value in the autolock register 36. At step 400, it is determined whether an exception has occurred, and if so, at step 405, the current lockdown value is saved. There are several ways to save the current lockdown value. In one example, the current lockdown value is stored as a field within the exception return value stored in the link register. The link register can be used to capture the exception return address when entering an exception. However, in some implementations, a portion of the address space is reserved and not executable. Therefore, a branch to an address within such a portion of the address space can be used to notify special conditions, such as a requirement for the hardware to perform an exception return to the background state. In one implementation example, when entering an exception, the exception return address captured in the link register is set to a dummy return address that specifies an address within the reserved non-executable address space. Instead, the actual return address may be saved on the stack, and thus the current lockdown value can be included as part of the dummy return address in the link register.

[0080] Therefore, considering FIG. 8A, at point 300, the current lockdown value applicable to the background thread T1 can be saved at step 405. Thereafter, at step 410, it is determined whether the autolock flag is set in the autolock register 36. If not, no additional protection is implemented for the exception, and the process may proceed as specifically described above with reference to FIG. 8A. At step 420, an exception handling routine can be triggered to handle the exception, and then at step 425, upon exception return, the lockdown value can be restored to the lockdown value stored in the lockdown register.

[0081] However, when the autolock flag is set, as shown in Figure 8B, the process first proceeds to step 415 where the lockdown value is set in the lockdown register. Referring to Figure 8A, this means that the lockdown value is set at point 305 regardless of the value of the lockdown value applicable to thread T1 at point 300. Therefore, the exception handler used to process the SVC can continue as normal by unlocking the PPB address space, performing bulk access, and relocking the PPB address space by resetting the lockdown value.

[0082] However, when the autolock flag is set, the problem that occurs when a high-priority interrupt is received at point 310 is removed. Specifically, by performing the process shown in Figure 8B, it can be seen that the current lockdown value (in this case, it is clear because the context switch exception handling routine executed in response to the timer interrupt has cleared the lockdown value up to this point) can be saved. In addition, it is determined that the autolock flag is set. Therefore, when transitioning to point 315 for the execution of the exception handling routine required by the interrupt detected at point 310, the lockdown value in the lockdown register is reset. This means that the lockdown value is set during the execution period of the exception handling routine between points 315 and 320, thus avoiding any unintended ability to freely access the memory-mapped control register while performing that exception handling routine. When returning from the exception at point 325, as shown by step 425 in Figure 8B, the lockdown value in the lockdown register is restored. In the context of the example in Figure 8A, this means that the lockdown value is cleared again, and after bulk access is performed by the context switch exception handler, the PPB memory address space is relocked.

[0083] FIG. 9 shows a simulator implementation that can be used. The foregoing examples implement the present invention in terms of an apparatus and method for operating specific processing hardware that supports the technique, but it is also possible to provide an instruction execution environment according to the examples described herein, and the instruction execution environment is implemented by the use of a computer program. Such a computer program is often referred to as a simulator insofar as the computer program provides a software-based implementation of a hardware architecture. Various simulator computer programs include binary translators including emulators, virtual machines, models, and dynamic binary translators. Typically, the simulator implementation may be executed on a host processor 515, which optionally executes a host operating system 510, and the host operating system 510 supports a simulator program 505. In some configurations, there may be multiple layers of simulation between the hardware and the provided instruction execution environment, and / or multiple different instruction execution environments may be provided on the same host processor. Conventionally, a powerful processor has been required to provide a simulator implementation that runs at a reasonable speed, but such an approach may be justified in certain situations, such as when it is desired to execute the native code of another processor for reasons of compatibility or reuse. For example, the simulator implementation may provide an instruction execution environment having additional features not supported by the host processor hardware, or may typically provide an instruction execution environment associated with a different hardware architecture. An overview of simulation is described in "Some Efficient Architecture Simulation Techniques", Robert Bedichek, Winter 1990, USENIX Conference, pages 53-63.

[0084] To the extent that examples have been described above with reference to specific hardware constructs or features, in a simulated implementation, equivalent functionality may be provided by suitable software constructs or features. For example, a particular circuit may be provided as computer program logic in a simulated implementation. Similarly, memory hardware such as registers or caches may be provided as software data structures in a simulated implementation. Also, the physical address space used to access memory 26 within hardware device 2 may be emulated as a simulated address space, and the simulated address space is mapped by simulator 505 to the virtual address space used by host operating system 510. In configurations where one or more of the hardware elements referred to in the foregoing examples are present in host hardware (e.g., host processor 515), some simulated implementations may use the host hardware if appropriate.

[0085] The simulator program 505 may be stored in a computer-readable storage medium (which may be a non-transitory medium), and provides a virtual hardware interface (instruction execution environment) to the target code 500 (which may include an application, a guest operating system, and a hypervisor). This virtual hardware interface is the same as the hardware interface of the hardware architecture modeled by the simulator program 505. Thus, the program instructions of the target code 500 may be executed from within the instruction execution environment using the simulator program 505. For this reason, a host computer 515 that does not actually have the hardware features of the aforementioned apparatus 2 can emulate these features. The simulator program may include processing program logic 520 for emulating the behavior of the processing pipeline 4, and control program logic 525 for maintaining a set of memory-mapped control data structures that emulate the memory-mapped control registers 30 including the lockdown data structure for storing the lockdown value. The architecture registers 6 of the system 2 may also be emulated using data structure emulating program logic (not shown) maintained by the simulator code 505 for mapping the architecture registers of the target architecture to the memory space used by the host hardware 515. Thus, in the example of FIG. 9, the techniques described herein for controlling access to the set of memory-mapped control registers according to the lockdown value can be performed in software by the simulator program 505.

[0086] By using the techniques described herein, the ability of an attacker who attempts to utilize software bugs to change the content of the memory-mapped control registers can be significantly suppressed. Thus, the likelihood of the attacker putting the system at risk by changing the control information within these memory-mapped control registers can be reduced.

[0087] In the present application, the term "configured to..." is used to mean that an element of a device has a configuration capable of performing a defined operation. In this context, "configuration" means an arrangement or pattern of interconnection of hardware or software. For example, a device may have dedicated hardware that provides a defined operation, or a processor or other processing device may be programmed to execute a function. "Configured to" does not in any way imply that an element of a device needs to be modified to provide a defined operation.

[0088] Exemplary embodiments of the present invention have been described in detail herein with reference to the accompanying drawings, but it is understood that the present invention is not limited to those exact embodiments, and that various changes, additions, and modifications may be made by those skilled in the art without departing from the scope and spirit of the present invention as defined by the appended claims. For example, various combinations of the features of the independent claims may be made with the features of the dependent claims without departing from the scope of the present invention.

Claims

1. A processing circuit that executes program code to perform data processing operations, A set of memory-mapped control registers that store control information used to control the operation of the processing circuit when executing the program code, A lockdown register that stores a lockdown value, and The processing circuit is configured to execute a store instruction to perform a write operation in a memory address space, and the store instruction consists of multiple types, When the lockdown value is set, the processing circuit prevents a write operation from being performed to change the control information in the memory-mapped control register, unless the write operation is generated by the execution of a store instruction from a first subset of the multiple types of store instructions. An apparatus.

2. When the lockdown value is cleared, the processing circuit is configured to perform a write operation using a second subset in addition to the first subset of the multiple types of store instructions and to allow changing the control information in the memory-mapped control register, and the second subset does not overlap with the first subset. The apparatus according to claim 1.

3. When the lockdown value is set, the processing circuit is configured to issue a fault exception when a store instruction from the second subset of the multiple types of store instructions attempts to perform a write operation to the set of memory-mapped control registers. The apparatus according to claim 2.

4. When the lock-down value is set, the processing circuit allows the reading of the control information in the memory-mapped control register only when the reading is caused by a load instruction from a first subset of the plurality of types of load instructions, and prevents the reading of the control information in the memory-mapped control register when the reading is caused by a load instruction from a second subset of the plurality of types of load instructions that does not overlap with the first subset. The processing circuit is further configured as such. The apparatus according to any one of claims 1 to 3.

5. When the lock-down value is set, the apparatus according to claim 4, wherein the processing circuit is configured to issue a fault exception when a load instruction from the second subset of the plurality of types of load instructions attempts to perform a read operation on the set of the memory-mapped control register.

6. The first subset of the plurality of types of store instructions includes store instructions specific to a control register. When the processing circuit is executing a store instruction specific to the control register, the processing circuit is configured to ignore the lock-down value when determining whether to permit a related write operation to be performed on the memory-mapped control register. The apparatus according to any one of claims 1 to 5.

7. When the processing circuit is executing a store instruction specific to the control register, the apparatus according to claim 6, wherein the processing circuit is configured to issue a fault exception when the memory address specified by the store instruction specific to the control register is outside the memory address range related to the set of the memory-mapped control register.

8. The apparatus according to claim 7, wherein the memory address is specified depending on a value stored in a register specified by the store instruction specific to the control register and an immediate value specified by the store instruction specific to the control register. **Claim 9**: When the lock-down value is set, the processing circuit permits the reading of the control information in the memory-mapped control register only when the reading is caused by a load instruction from a first subset of the plurality of types of load instructions, and prevents the reading of the control information in the memory-mapped control register when the reading is caused by a load instruction from a second subset of the plurality of types of load instructions that does not overlap with the first subset. The first subset of the plurality of types of load instructions includes load instructions specific to the control register, and when the processing circuit is executing a load instruction specific to the control register, the processing circuit is configured to ignore the lock-down value when determining whether to permit a related read operation to be performed on the memory-mapped control register. When the processing circuit is executing a load instruction specific to the control register, if the memory address specified by the load instruction specific to the control register is outside the memory address range related to the set of the memory-mapped control register, the processing circuit is configured to issue a fault exception. The apparatus according to any one of claims 1 to 8. **Claim 10**: The first subset of the plurality of types of store instructions includes store instructions specific to the control register, and when the processing circuit is executing a store instruction specific to the control register, the processing circuit is configured to ignore the lock-down value when determining whether to permit a related write operation to be performed on the memory-mapped control register. The lock-down register is provided within the set of the memory-mapped control registers, and when the processing circuit executes an instance of a store instruction specific to the control register at a specified memory address corresponding to the lock-down register, the processing circuit is configured to change the lock-down value in the lock-down register. The apparatus according to any one of claims 1 to 9. **Claim 11** The apparatus according to claim 10, wherein the processing circuit is controllable by software to perform a series of accesses to the memory-mapped control register by executing a store instruction specific to the control register to clear the lockdown value, executing one or more standard access instructions to access the memory-mapped control register, and then executing a store instruction to set the lockdown value.

12. The apparatus according to claim 11, wherein the one or more standard access instructions include at least one store multiple instruction or load multiple instruction.

13. The apparatus according to any one of claims 1 to 12, wherein the control information stored in the memory-mapped control register includes at least control information used to control which regions of the memory address space can be accessed by trusted program code and untrusted program code.

14. The apparatus according to claim 13, wherein the processing circuit is configured to permit the trusted program code to update the lockdown value in the lockdown register and to control the execution of write operations to the memory-mapped control register by both the untrusted program code and the trusted program code using the lockdown value.

15. The apparatus according to claim 13, wherein the processing circuit is configured to permit the trusted program code to update the lockdown value in the lockdown register and to control the execution of write operations to the memory-mapped control register by the trusted program code using the lockdown value, and to ignore the lockdown value when determining whether to permit the execution of write operations to the memory-mapped control register by the untrusted program code.

16. The processing circuit is configured to execute the program code in one of a plurality of states including at least a privileged state and a non-privileged state, the trusted program code is the program code executed by the processing circuit in the privileged state, and the untrusted program code is the program code executed by the processing circuit in the non-privileged state. The apparatus according to claim 14 or 15.

17. The processing circuit is configured to execute the program code in one of a plurality of security domains including at least a secure domain and a less secure domain, the trusted program code is the program code executed by the processing circuit in the secure domain, and the untrusted program code is the program code executed by the processing circuit in the less secure domain. The apparatus according to any one of claims 14 to 16.

18. The processing circuit is configured to execute the program code in one of a plurality of states including at least a privileged state and a non-privileged state, the trusted program code is the program code executed by the processing circuit in the privileged state, and the untrusted program code is the program code executed by the processing circuit in the non-privileged state, In each of the security domains, the processing circuit is configured to execute the program code in one of a plurality of states including at least the non-privileged state and the privileged state, The lockdown register is configured to provide the lockdown value for each of the security domains. The apparatus according to claim 17.

19. The processing circuit is configured to perform a lockdown value management process related to an exception, and the lockdown value management process When an exception occurs, save the lockdown value currently stored in the lockdown register, and set the lockdown value in the lockdown register before triggering the execution of an exception handling routine to process the exception. When returning from the exception handling routine, restore the lockdown value in the lockdown register to the saved lockdown value. The apparatus according to any one of claims 1 to 18. **Claim 20** Further comprising an autolock register for storing an autolock value. The processing circuit is configured to set the lockdown value in relation to the lockdown value management process only when the autolock value is set, when an exception occurs. The apparatus according to claim 19. **Claim 21** During the lockdown value management process, the lockdown value currently stored in the lockdown register is stored as a field in a link register. The apparatus according to claim 19 or 20. **Claim 22** A method for controlling access to a set of memory-mapped control registers in an apparatus, comprising: Executing program code on a processing circuit to perform a data processing operation. Storing control information used to control the operation of the processing circuit when executing the program code in the set of memory-mapped control registers. Storing a lockdown value in a lockdown register. Executing a store instruction by the processing circuit to perform a write operation to a memory address space, the store instruction consisting of multiple types. When the lockdown value is set, preventing a write operation from being performed to change the control information in the memory-mapped control register, unless the write operation is caused by execution by a processing circuit of a store instruction from a first subset of the plurality of types of store instructions, and A method including.

23. A computer program for controlling a host data processing device to provide an instruction execution environment, Processing program logic that executes program code to perform data processing operations, and Control program logic that maintains a set of memory-mapped control data structures that store control information used to control the operation of the processing program logic when the program code is executed, and also maintains a lockdown data structure that stores a lockdown value, The processing program logic is configured to execute a store instruction to perform a write operation in a memory address space, the store instruction consisting of a plurality of types, When the lockdown value is set, the processing program logic is configured to prevent a write operation from being performed to change the control information in the memory-mapped control data structure, unless the write operation is caused by execution of a store instruction from a first subset of the plurality of types of store instructions. Computer program.

24. A computer-readable storage medium storing the computer program according to claim 23.

Citation Information

Patent Citations

  • Information processor

    JP1987131339A

  • Microcomputer

    JP1996235073A

  • microcontroller

    JP2004062550A

  • Semiconductor storage device and its control method

    JP2004199825A

  • Region identification operation for identifying the region of the memory attribute unit corresponding to the target memory address

    JP2017505492A