Systems, devices, and methods for dynamic allocation

JP7926894B2Active Publication Date: 2026-09-30INFINEON TECHNOLOGIES AG
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2022184653
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-11-19
Filing Date
2022-11-18
Publication Date
2026-09-30
Estimated Expiration
2042-11-18

Smart Images

  • Figure 0007926894000001
    Figure 0007926894000001
  • Figure 0007926894000002
    Figure 0007926894000002
  • Figure 0007926894000003
    Figure 0007926894000003
Patent Text Reader

Abstract

To provide a method for dynamic allocation regarding a semiconductor device including a shared resource.SOLUTION: An electronic hardware circuitry device of a semiconductor chip includes a plurality of partitionable hardware resources that each include a corresponding resource allocation state. A logic control circuit controls access to the hardware resources based on the hardware resource allocation states and based on input from authorized agents. A processor core of the semiconductor chip implements a plurality of applications belonging to a first group or to a second group, each of the applications being configured to access and interact with a corresponding hardware resource assigned to the respective application, implement assigning software agents each authorized and configured to cause the electronic hardware circuitry device to assign one or more unassigned hardware resources only to one or more of the applications belonging to certain groups.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Various embodiments generally relate to semiconductor devices including shared resources. [Background Art]

[0002] A semiconductor system or device including a system-on-chip can include a plurality of applications that require sharing of resources. However, since software application tasks are developed by a plurality of different entities or companies, the use of static allocation of resource assignments can be disadvantageous. Meanwhile, dynamic allocation of resources to application software or software tasks may not be suitable from the perspective of ensuring the safety and security of such systems or devices.

[0003] In the drawings, like reference numerals generally refer to the same parts throughout the various views. The drawings are not necessarily drawn to scale, and the emphasis is generally placed on illustrating the basic principles of the present invention. In the following description, various embodiments of the present invention will be described with reference to the following drawings. [Brief Description of the Drawings]

[0004] [Figure 1] FIG. 1 is a diagram illustrating a semiconductor device according to at least one exemplary embodiment of the present disclosure. [Figure 2] FIG. 2 is a diagram illustrating a hardware peripheral device according to at least one exemplary embodiment of the present disclosure. [Figure 3] FIG. 3 is a state diagram of a resource partition according to at least one exemplary embodiment of the present disclosure. [Mode for Carrying Out the Invention]

[0005] The following detailed description refers by way of example to the accompanying drawings, which show specific details and embodiments in which the present invention may be practiced.

[0006] The term “exemplary” is used herein to mean “serving as an example, case, or illustration.” Any embodiment or design described herein as “exemplary” should not necessarily be construed as being preferable or advantageous to other embodiments or designs.

[0007] In this specification or in the claims, the terms “plurality” and “multiple” explicitly refer to a quantity greater than one. In this specification or in the claims, terms such as “group,” “set,” “collection,” “series,” “sequence,” and “grouping” refer to a quantity equal to or greater than one, i.e., one or more. Any term expressed in the plural form that does not explicitly state “plurality” or “multiple” similarly refers to a quantity equal to or greater than one. The terms “preferred subset,” “reduced subset,” and “fewer subset” refer to a subset of a set that is not equal to the set, i.e., a subset of a set that contains fewer elements than the set.

[0008] The terms "at least one" and "one or more" can be understood to include quantities equal to or greater than 1 (e.g., 1, 2, 3, 4 [...]).

[0009] Where used herein, unless otherwise specified, the use of ordinal adjectives such as “first,” “second,” “third,” etc., to describe a common object merely indicates that different instances of a similar object are being referred to, and is not intended to suggest that the objects thus described must be in a given order, temporally, spatially, in rank, or in any other way.

[0010] As used herein, the term “data” may be understood to include information in any preferred analog or digital format, provided, for example, as a file, a portion of a file, a set of files, a signal or stream, a portion of a signal or stream, or a set of signals or streams. Furthermore, the term “data” may be used to mean, for example, a reference to information in the form of a pointer. However, the term “data” can take various forms and represent any information as understood in the art, and is not limited to the examples given herein.

[0011] The terms “processor” or “processing circuit” can be understood, for example, as used herein, as any kind of entity that enables the handling of data, signals, etc. Data, signals, etc. may be processed according to one or more specific functions performed by the processor or controller.

[0012] Therefore, a processor or controller may be, or include, analog circuits, digital circuits, mixed-signal circuits, logic circuits, processors, microprocessors, central processing units (CPUs), neuromorphic computer units (NCUs), graphics processing units (GPUs), digital signal processors (DSPs), field-programmable gate arrays (FPGAs), integrated circuits, application-specific integrated circuits (ASICs), or any combination thereof. Any other type of implementation of each function, which will be described in more detail below, may also be understood as a processor, controller, or logic circuit. Any two (or more) of the processors, controllers, or logic circuits detailed herein may be implemented as a single entity with equivalent functionality or equivalents, and conversely, any single processor, controller, or logic circuit detailed herein may be implemented as two (or more) separate entities with equivalent functionality or equivalents.

[0013] Unless otherwise specified, the term “circuit” as used herein is understood to mean any type of logic implementation entity that may include dedicated hardware. Thus, a circuit can be an analog circuit, a digital circuit, a mixed-signal circuit, a logic circuit, an integrated circuit, an application-specific integrated circuit (“ASIC”), or any combination thereof. Any other type of implementation of each function, which will be described in more detail below, may also be understood as a “circuit.” Any two (or more) of the circuits detailed herein may be implemented as a single circuit having substantially equivalent functionality. Conversely, any single circuit detailed herein may be implemented as two (or more) separate circuits having substantially equivalent functionality. Furthermore, a reference to “circuit” may refer to two or more circuits that collectively form a single circuit. A set of elements or other sets of circuits may be described herein, and the term “set” may be interpreted as “one or more.”

[0014] As used herein, “signal” can be transmitted or conducted through a signal chain in which the signal is processed to alter its characteristics, such as phase, amplitude, and frequency. A signal may still be referred to as the same signal even after such characteristics have been adapted. In general, a signal can be considered the same signal as long as it continues to encode the same information.

[0015] As used herein, a signal “indicating” a value or other information may be a digital or analog signal that encodes or otherwise communicates a value or other information in a manner that can be decoded by a receiving component and / or trigger a response action in that component. The signal may be stored or buffered in a computer-readable storage medium before being received by the receiving component. The receiving component may retrieve the signal from the storage medium. Furthermore, a “value” “indicating” some quantity, state, or parameter may be physically embodied as a digital signal, an analog signal, or a stored bit that encodes or otherwise communicates a value.

[0016] When an element is referred to as being “connected” or “coupled” to another element, it should be understood that the element may be physically connected or coupled to the other element so that current and / or electromagnetic radiation (e.g., signals) can flow along the conductive path formed by the element. Intervening conductive, inductive, or capacitive elements may exist between elements when each element is described as being coupled or connected to one another. Furthermore, when coupled or connected to one another, one element may induce a flow of voltage or current or propagation of electromagnetic waves in the other element without physical contact or intervening components. Furthermore, when a voltage, current, or signal is referred to as being “applied” to an element, the voltage, current, or signal may be conducted to the element by physical connection, or by capacitive coupling, electromagnetic coupling, or inductive coupling without physical connection.

[0017] As used herein, “memory” is understood as a non-temporary, computer-readable medium that can store data or information for retrieval. Therefore, references to “memory” included herein may be understood as referring to volatile or non-volatile memory, including random-access memory (RAM), read-only memory (ROM), flash memory, solid-state storage, magnetic tape, hard disk drives, optical drives, etc., or any combination thereof. Furthermore, registers, shift registers, processor registers, data buffers, etc., are also included in the term “memory” herein. A single component referred to as “memory” or “a memory” may consist of two or more different types of memory, and therefore may refer to a collective component containing one or more types of memory. Any single memory component may be separated into multiple collectively equivalent memory components, and vice versa. Furthermore, memory may be shown separately from one or more other components (in drawings, etc.), but may be integrated with other components such as a controller with a general integrated chip or embedded memory.

[0018] The term "software" refers to any type of executable instruction, including firmware.

[0019] Exemplary embodiments of this disclosure may be realized by one or more computers (e.g., computing devices, processors, processor cores, etc.) reading and executing computer-executable instructions recorded on a storage medium (e.g., non-volatile computer-readable storage medium) to perform one or more functions of the embodiments described herein. A computer may include one or more central processing units (CPUs), microprocessing units (MPUs), or other circuits, and may include separate computers or a network of separate computer processors. Computer-executable instructions may be provided to the computer from, for example, a network or a non-volatile computer-readable storage medium. The storage medium may include one or more of the following: hard disks, random access memory (RAM), read-only memory (ROM), storage in a distributed computing system, optical drives (compact discs (CDs), digital versatile discs (DVDs), or Blu-ray discs (BDs)), flash memory devices, memory cards, etc. Specific details and embodiments of the invention that can be practiced are shown as examples.

[0020] Where used herein, unless otherwise specified, the use of ordinal adjectives such as “first,” “second,” “third,” etc., to describe a common object merely indicates that different instances of similar objects are being referred to, and is not intended to suggest that the objects described in this manner must be in a given order, temporally, spatially, in rank, or in any other way.

[0021] The terms “semiconductor substrate” or “semiconductor die” are defined to mean any structure containing semiconductor material, such as a silicon substrate with or without an epitaxial layer, a silicon-on-insulator substrate with an embedded insulating layer, or a substrate having a silicon-germanium layer. As used herein, the term “integrated circuit” refers to an electronic circuit having multiple individual circuit elements, such as transistors, diodes, resistors, capacitors, inductors, and other active and passive semiconductor devices. Conductive regions formed inside and / or on top of a semiconductor substrate or semiconductor die are part of a conductive path and have exposed surfaces that can be treated by planarization processes such as chemical mechanical polishing. Suitable materials for conductive regions may include, but are not limited to, copper, aluminum, copper alloys, or other movable conductive materials. The copper interconnect level may be the first or any subsequent metal interconnect level of the semiconductor device.

[0022] Figure 1 includes a diagram showing an example of a semiconductor device 100. A semiconductor device can be a single semiconductor chip, for example, a single semiconductor chip containing multiple hardware components configured to run or execute various tasks or applications. Furthermore, the semiconductor chip can be implemented as a system-on-a-chip; that is, the entire system 100 can be implemented on a single or common semiconductor substrate.

[0023] The semiconductor device 100 may include multiple processor cores designated 110a to 110N (where N is any number). The device 100 may include multiple hardware peripheral devices. As shown in Figure 1, the device 100 includes a direct memory access (DMA) controller 120, an interrupt router 130, a memory or memory device 140, and other hardware peripherals designated 150a to 150M.

[0024] In addition, the device 100 may include a system interconnect 160 coupled to all or part of the components to enable the components to communicate with each other. The system interconnect 160 may be configured to distinguish between various components, for example, to distinguish signals or communications between different cores 110. Accordingly, signals or communications from different types or kinds of software applications can also be distinguished using the system interconnect 160.

[0025] Although not shown in FIG. 1, other connections between components of the device 100 may be implemented.

[0026] According to an exemplary embodiment of the present invention, the semiconductor device 100 may be a system-on-chip configured to implement or execute a plurality of applications. More specifically, one or more of the processor cores 110a to 110N or the processor core 110 may execute or implement applications. The processor core 110 may execute program instructions, which may be stored on the memory 140 or other suitable components, to execute the plurality of applications.

[0027] In some cases, the semiconductor device 100 may implement safety-related applications that may be designed to operate in accordance with one or more safety standards or protocols. Furthermore, the device 100 may also implement security-based or security-related applications. Security-related applications may include or implement software tasks such as authentication, encryption, and key provisioning, to name a few examples.

[0028] Different types of software applications implemented by device 100 (e.g., safety and security-related applications) may be developed by different entities or companies. Therefore, the software applications, when run by core 110 on device 100, may lack reliability in that sense and may not be designed to work in conjunction with one another. Multiple applications running on device 100 may require access to and use some of the same resources, such as interrupt routers, DMA, etc., in order to perform the intended functions of the applications and device 100. The hardware of the embodiment of the present invention enables multiple software applications to control shared hardware resources without requiring a comprehensive hardware or software instance that can allocate and control the resources. Where a single hardware or software instance cannot control different groups of software applications, the proposed hardware enables accurate and reliable resource allocation without such a common allocation agent.

[0029] According to at least one exemplary embodiment of this disclosure, applications running on or on the processor core 110 of the semiconductor device 100 may be considered to be in different groups. In one example, software applications may be grouped into secure / non-secure applications or into security applications. Thus, the semiconductor device 100 may be configured to allow secure software applications to remain uninterfered with by security software applications, and vice versa. Security applications may not be developed according to the same security standards, and furthermore, security application software tasks may be configured to ensure confidentiality, integrity against interference, and the ability to prevent spoofing from non-secure application software tasks that are not developed according to the same security standards. In other words, the semiconductor device 100 may operate to protect one group of applications from interference with another group of applications, particularly with respect to shared resources, and vice versa.

[0030] In at least one exemplary embodiment, different grouped applications or assigned software agents described herein may run or be implemented separately from one another, for example, on separate partitions. Hardware partitions can be realized or implemented in multiple ways. Hardware partitions may reflect or correspond to divisions of hardware on which applications are implemented. In some cases, a partition may be a virtual machine implemented by core 110, that is, core 110 may run a hypervisor and implement multiple virtual machines. Virtual machines may run or implement multiple software applications. One group of software applications / agents (e.g., security applications) may run on a different virtual machine than the virtual machines running another group of software applications / agents (e.g., security applications).

[0031] In another example, core 110 can be split or used in a split state. In such a case, one or more cores can run only one group of software applications (e.g., security applications), and one or more different groups of core 110 can run only another group.

[0032] In yet another case, partitioning can be achieved within the core 110. A single core 110 can be divided into multiple (e.g., logical) partitions. Furthermore, one or more partitions can be configured to run only software applications or agents from a specific group (e.g., security), and another or different partitions can be configured to run only software applications / agents from another group of software applications / agents (e.g., security).

[0033] Furthermore, device 100 may be divisible to ensure a degree of freedom of interference between groups of applications, such as safety applications and security applications, with respect to one or more of the system or device peripherals, such as DMAs and interrupt routers. That is, some of the resources of the device peripherals may be divided and, at least temporarily, allocated to specific applications or components.

[0034] Figure 2 is a diagram of an exemplary electronic hardware circuit device 200. Referring to Figure 1, the electronic hardware circuit device 200 may be a DMA 120, an interrupt router 130, or any other suitable peripheral device. The peripheral device or electronic hardware circuit device 200 may be a hardware system device containing divisible resources. The electronic hardware circuit device 200 may include an interface 210, such as a slave interface, for communicating with other components.

[0035] In addition, in the example of Figure 2, the resources 240 of the electronic hardware circuit device 200 may be divided into, for example, up to N resource partitions (RPs). Each resource or resource partition may be a hardware circuit component or circuit of the electronic hardware circuit device 200, which is configured to form an interface with the execution mode or execution engine 260 of the electronic hardware circuit device 200. Each resource partition may have a configuration or configuration that indicates or instructs how the resource partition forms an interface with the execution engine 260. The configuration may specify how the data received by the partition should be used with the execution engine.

[0036] A resource or resource partition RP240 can be selectively or dynamically allocated to, for example, a software application. An allocated software application may be referred to as, or considered to be, the owner of the resource partition (RP). The application owner can use the resource partition to accomplish one or more software tasks. For example, an application can modify or specify the configuration of the resource partition. Therefore, resource partition 240 may include storage element components that can indicate its configuration, such as registers. Furthermore, the storage element may indicate whether an application is allocated to it, and if allocated, it may indicate its owner, or it may indicate that it is unallocated.

[0037] The logic control circuit 220 can be responsible for controlling access and for dividing and assigning ownership to the hardware resource partition 240. Furthermore, the logic control circuit 220 may be responsible for controlling access to hardware resources, or may be configured to control access to hardware resources. For example, the logic control circuit 220 may be configured to provide or deny access to one or more of multiple hardware resources.

[0038] The logic control circuit 220 can be a hardwired electronic component. In other words, the logic control circuit 220 can be implemented as a permanent physical component, but its operation cannot be electronically reconfigured or reprogrammed. Therefore, the operation or rules governing how the logic control circuit 220 operates are built into the physical circuit component (e.g., a transistor) and cannot be changed.

[0039] Each resource or resource partition may be associated with or contain an allocation status. For example, the allocation status or allocation status data may indicate whether the resource or resource partition is allocated (e.g., to an owner) or unallocated (e.g., free). The allocation status or allocation status data may further indicate the owner of each allocated resource partition. The allocation status data for each resource partition may be stored in any preferred format, such as being stored in one or more registers.

[0040] Initially, or after a reset performed by a hardware electronic circuit device, the resource allocation state of each resource or resource partition can be updated or changed to unallocated. For example, the logic control circuit 220 can be configured to change the allocated state or resource allocation state to unallocated in response to a system reset.

[0041] According to exemplary embodiments of the present disclosure, the logic control circuit 220 may be configured to write or specify resource allocation states. In response to a reset (e.g., initiated by a semiconductor device 200), the logic control circuit 220 may, for example, set or change the resource allocation state of each resource partition to unassigned (e.g., no owner).

[0042] Furthermore, the logic control circuit 220 can also be configured to set or specify resource allocation states in response to requests, commands, or communications from authorized entities. For example, the logic control circuit 220 can be configured to change the allocation of unallocated resource partitions to a specific owner in response to requests, commands (e.g., signals) from authorized entities, applications, or agents.

[0043] In at least one exemplary embodiment of the present disclosure, the system 100 may implement agents, such as software or master assignment agents. These assignment agents are configured, for example, to use a logic control circuit 220 to assign owners to unassigned or unallocated resources / resource partitions of an electronic hardware circuit device 200. These assignment agents may be implemented or run by one or more cores 110, which may be divided or separated into, for example, separate cores, virtual machines, etc., as described above.

[0044] The logic control circuit 220 of the electronic hardware circuit device 200 can be configured to allow these allocation agents to allocate or map unallocated resource partitions 240 only to designated owners, such as software applications. The core 110 can run multiple allocation software agents, each configured to allocate hardware resources or resource partitions 240 to applications belonging to a particular group or type of application. That is, allocation agents can be restricted or configured to allocate only one type or group of applications to unallocated resource partitions 240. The system interconnect 160 can be configured to provide communication or requests (e.g., in the form of signals) to enable the electronic hardware circuit 200 and the logic control circuit 220 to distinguish between different types of applications of different software agents.

[0045] In at least one instance, the system interconnect 160 may provide communications or requests from a specific application or core 110 on a specific or predefined connection point. These connections may be configured so that communications are provided to a specific or known port input of an electronic hardware circuit device 200. As a result, the electronic hardware circuit device 200 can recognize the component or core from which the request or communication originated. This information can be useful for verifying the origin of the request or communication, for example, whether they came from a group to which an application or software agent belongs. For example, a request received at a particular input may be recognized as originating from a particular software agent (e.g., a security software agent).

[0046] In addition, requests or communications (e.g., signals) from each type of application or software agent may include identification information or transaction identification information (TAG-ID). Furthermore, the TAG-ID can be used by the electronic hardware circuit device 200 to verify / identify a type or specific software agent that interacts with or requests access to the electronic hardware circuit device 200. Based on this verification or identification, the electronic hardware circuit device 200 provides access. The TAG-ID may be uniquely assigned to a software application or agent. The TAG-ID may be assigned statically or, in other cases, dynamically.

[0047] Therefore, TAG-ID provides, or can be, a mapping between hardware such as cores, virtual machines, applications, or agents and hardware resource partitions (RPs).

[0048] In at least one example, device 100 can implement security software / master agents and non-security or security software / master agents that may be executed by core 110. Furthermore, core 110 may also run multiple applications that may be classified or identified as either security applications or non-security / security applications. The logic control circuit 220 can obtain / receive requests or commands from each of the master agents, for example, in the form of signals. Despite resets, the logic of the logic control circuit 220 may only allow these authorized software agents to allocate or assign unallocated resource partitions to applications. That is, the logic control circuit 220 may only allow security software agents and non-security / security software agents to assign owners to unallocated hardware resources, respectively. Furthermore, the logic of the logic control circuit 220 may only allow or guarantee that security and non-security software agents allocate unallocated resource partitions to their respective groups. TAG-IDs may be used by the logic control circuit 220 to implement logic or rules.

[0049] In response to a valid command or request from the software agent, the logical control circuit 220 updates the resource allocation status of unallocated resources to reflect valid ownership assignments. Therefore, the resource allocation status of previously unallocated resource partitions is updated to "allocated" by the logical control circuit 220, and the owner of the resource partition is further specified. Furthermore, the assigned owner can be identified by specifying resource owner transaction identification information or the "RP owner TAG-ID" in the request, and can also indicate the group or type of application that is the assignor or application owner of the resource partition.

[0050] After a resource partition is allocated, the logical control circuit 220 uses allocation status data to control further access to the resource partition. Specifically, after a resource partition is allocated, the logical control circuit 220 may only allow a designated application owner to control the resource partition or interface with it. In particular, the logical control circuit 220 may only allow a designated or allocated application owner to relinquish a resource partition. That is, the logical control circuit 220 is configured to accept only requests or commands from allocated application owners to release the resource partition and change its allocation status to unallocated.

[0051] The logical control circuit 220 may be further configured to allow only the assigned owner to access the resource partition 240. For example, the logical control circuit 220 may be configured to allow the currently assigned resource owner to grant or relinquish ownership of the currently assigned resource. That is, the logical control circuit 220 can release the resource allocation state and change it to unallocated only in response to requests or commands (e.g., signals) sent from the owner of the allocated resource partition (e.g., the application owner). Other components or applications are not permitted to unallocate the resource partition. In such cases, resource release requests (requests to change the allocation state to "unallocated") or attempts (e.g., requests from applications not designated as owners) by unauthorized components are rejected or ignored by the logical control circuit 220.

[0052] An application designated as the owner of an allocated resource partition can access and configure the resource partition via the logic circuit 220. For example, the application owner can configure or specify how data is moved or how data provided to the resource partition is processed or used by the electronic hardware circuit 200. Each resource partition 240 can access the execution engine 260 of the electronic hardware circuit 200 (via the crossbar 250).

[0053] The execution engine 260 can perform specific tasks or processes according to the configuration specified in the resource partition. For example, if the electronic hardware circuit device 200 is a DMA controller, the execution engine can be configured to perform DMA controller tasks. If the electronic hardware circuit device 200 is an interrupt controller, the execution engine can be configured to perform specific interrupt routines.

[0054] The resource partition 240 can individually access the execution engine 260 in a time-slice manner, for example, using a crossbar switch component 250. Other peripheral devices are also possible, and the electronic hardware circuit device 200 can be adapted or modified to operate according to the embodiments described herein.

[0055] In various examples, the semiconductor device 100 has been described as implementing two application groups, such as security applications and non-security applications, but this is merely illustrative, as the number or type of application groups and corresponding assigned software agents may vary.

[0056] Figure 3 shows a state diagram 300 illustrating possible states of a resource partition (RP) in an electronic hardware circuit device described herein. In the example in Figure 3, the resource partition (RP) may operate within a semiconductor device, such as semiconductor device 100. Thus, the semiconductor device includes a core 110 that implements multiple software applications. In this example, the software applications are either two different application groups or types, namely security applications or non-security applications.

[0057] Furthermore, the core 110 implements two assignment software agents: a security assignment software agent and a non-security assignment software agent. As shown in the figure, in the initial event or reset event 310, the resource partition (RP) transitions to the unassigned state 320, becoming unassigned and without an owner. In the unassigned state 320, the RP can transition to one of two possible states. In one case, transition 330 occurs when the non-security assignment software agent assigns a non-security application as the owner of the resource partition RP. Thus, the RP transitions to the non-security assigned state 350. In the other case, transition 340 occurs when the security assignment software agent assigns a security application as the owner of the resource partition RP. Thus, the RP transitions to the security assigned state 360. As illustrated and described in the embodiments herein, each assignment software agent can assign only applications belonging to a particular group of applications. In this example, the non-security assignment software agent can assign only non-security software applications as owners of the resource partition RP, and the security assignment software agent can assign only security software applications as owners of the resource partition RP.

[0058] The resource partition RP remains in an allocated state, for example, an unsecured allocated state 350 or a secure allocated state 360, until the current allocated application owner relinquishes or discards ownership, as described in the embodiments herein. Transition 370 occurs when the unsecured application that is the current owner of the resource partition relinquishes ownership. Thus, the resource partition transitions back from the unsecured allocated state 350 to the unallocated state 320. Similarly, transition 380 occurs when the secure application that is the current owner of the resource partition relinquishes ownership. Thus, the resource partition transitions back from the unsecured allocated state 360 ​​to the unallocated state 320.

[0059] In other cases, the state diagram 300 can be appropriately modified with the necessary changes for different configurations of the semiconductor device, and the number of application groups and assigned software agents can be changed, for example, increased with the necessary changes.

[0060] The following examples relate to further aspects of this disclosure.

[0061] Example 1 is a semiconductor chip, Multiple hardware resources, each containing a corresponding resource allocation state, where the divisible hardware resource indicates whether the hardware resource is allocated or unallocated, and if allocated, indicates the allocated application owner. Control access to the aforementioned multiple hardware resources, and Based on the resource allocation status of each of the aforementioned hardware resources, access to one or more of the plurality of hardware resources may be granted or denied. The resource allocation status is specified for each of the hardware resources based on input from one or more authorized agents. A logic control circuit configured as follows, An electronic hardware circuit device comprising, Memory containing program instructions, A processor core coupled to the memory and coupled to the at least one electronic hardware circuit device, The system comprises, and the at least one processor executes the program instructions, Implementing a plurality of software applications belonging to a first group or a second group, wherein each of the plurality of applications is configured to access and interact with at least one corresponding hardware resource assigned to the respective application, Implementing a first allocation software agent in the electronic hardware circuit device, which is authorized and configured to allocate one or more unallocated hardware resources to only one or more software applications belonging to the first group, Implementing a second allocation software agent in the aforementioned electronic hardware circuit device, which is authorized and configured to allocate one or more unallocated hardware resources to only one or more applications belonging to the second group, Perform Here, for each allocated hardware resource, the logic control circuit is a semiconductor chip further configured to allow the requesting software application to relinquish ownership of the allocated hardware resource only if the requesting software application is the application to which the hardware resource is currently allocated.

[0062] Example 2 is the subject of Example 1, and the first and second assignment software agents may be implemented on separate partitions by the at least one processor core.

[0063] Example 3 is the subject of Example 2, and at least one processor core may be configured to implement multiple virtual machines. The first and second assignment software agents, implemented on separate partitions, include the first assignment software agent implemented on a first virtual machine among the plurality of virtual machines, and the second assignment software agent implemented on a second virtual machine among the plurality of virtual machines.

[0064] Example 4 is the subject of Example 2, and at least one processor core may include multiple processor cores. The first and second assignment software agents, implemented on separate partitions, include the first assignment software agent being implemented on a first processor core among the plurality of processor cores, and the second assignment software agent being implemented on a second processor core among the plurality of processor cores.

[0065] Example 5 is the subject of Example 2, wherein the first and second assignment software agents may be implemented on a single processor core, and the single processor core includes multiple processor partitions. The first allocation software agent is implemented on the first processor partition among the plurality of processor partitions, and the second allocation software agent is implemented on the second processor partition among the plurality of processor partitions.

[0066] Example 6 is the subject of any of Examples 2 to 5, and the software applications belonging to the first group and the applications belonging to the second group may be implemented on separate partitions provided by the at least one core.

[0067] Example 7 is the subject of any of the above examples, wherein the logic control circuit may be configured to allow the first allocation software agent to allocate one or more of the unallocated hardware resources to one or more of the software applications belonging to the first group, and the second allocation software agent may be configured to allow one or more of the unallocated hardware resources to one or more of the software applications belonging to the second group.

[0068] Example 8 is the subject of any of the above examples, wherein the first allocation software agent and the second allocation software agent may each be configured to request access to one or more of the unallocated hardware resources using one or more unique transaction identification codes in order to allocate the unallocated resources of the electronic hardware circuit device.

[0069] Example 9 is the subject of any of the above examples, wherein the logic control circuit may be configured to provide the first or second assigning software agent with access to one or more of the unassigned hardware resources by verifying the one or more unique transaction identification codes provided by the first or second assigning software agent.

[0070] Example 10 is the subject of Example 8 or 9, wherein the one or more unique transaction identification codes may indicate a mapping of the first or second assignment software agent to one or more partitions implemented by the at least one processor core.

[0071] Example 11 is the subject of any of the above examples, and for each allocated hardware resource, the logic control circuit may be further configured to allow only the corresponding currently allocated software application to access the hardware resource.

[0072] Example 12 is the subject of any of the above examples, wherein for each allocated hardware resource, the corresponding application may be configured to access the allocated hardware resource by providing one or more unique transaction identification codes that identify the application, and the logic control circuit is configured to verify the corresponding software application based on the one or more transaction identification codes and to provide access to the allocated hardware resource.

[0073] Example 13 is the subject of any of the preceding examples, and for each allocated hardware resource, the logic control circuit may be further configured to allow only the corresponding currently allocated software application to move data or specify processing configurations within the hardware resource.

[0074] Example 14 is the subject of any of the aforementioned examples, and at least one electronic hardware circuit device may include multiple execution engines, each execution engine including a circuit that performs one or more tasks.

[0075] Example 15 is the subject of Example 14, and each of the hardware resources may be configured to be coupled to the execution engine in a time-slice manner and to form an interface with the execution engine.

[0076] Example 16 is the subject of any of the aforementioned examples, wherein at least one electronic hardware circuit device may further include an interrupt controller, and the hardware resource includes multiple interrupts.

[0077] Example 17 is the subject of any of the aforementioned examples, in which at least one electronic hardware circuit may include a direct memory access (DMA) controller, and the hardware resources may include multiple DMA channels.

[0078] Example 18 is the subject of any of the aforementioned examples, wherein each of the hardware resources includes one or more registers indicating its respective resource allocation state and its respective data configuration.

[0079] Example 19 is the subject of any of the aforementioned examples and may further include at least one electronic hardware circuit, memory, and a system interconnect coupled to at least one processor core.

[0080] Example 20 is the subject of Example 19, wherein the system interconnect may be configured to provide a connection between the electronic hardware circuit device and the at least one core in order for the electronic hardware circuit device to distinguish between communications from the first assignment software agent and communications from the second assignment software agent.

[0081] Example 21 is the subject of one of the aforementioned examples, and the logic control circuit can be a hardwired hardware component.

[0082] Example 22 is the subject of one of the aforementioned examples, and the semiconductor chip may be a system-on-a-chip design chip.

[0083] Example 23 is the subject of any of the above examples, wherein at least one software application in the first group is a security-related software application configured to perform one or more security-related software tasks.

[0084] Example 24 is the subject of any of the aforementioned examples, wherein at least one software application of the second group is a safety-related software application implemented in accordance with one or more predetermined safety standards.

[0085] Example 25 is the subject of any of the above examples, wherein the at least one electronic hardware circuit device is configured to perform a hardware resource reset to unassigned status for each of the hardware resources.

[0086] Example 26 is a non-temporary computer-readable medium containing instructions configured to be executed by at least one processor of at least one electronic hardware circuit device, wherein the hardware circuit device comprises a plurality of hardware resources, each of which divisible hardware resources includes a corresponding resource allocation state, the corresponding resource allocation state indicating whether each hardware resource is allocated or unallocated, and if allocated, indicating the allocated application owner; and a logic control circuit configured to control access to the plurality of hardware resources and to grant or deny access to one or more of the plurality of hardware resources based on the resource allocation state of each of the hardware resources, and to specify the resource allocation state for each of the hardware resources based on input from one or more authorized agents, wherein when the instructions are executed, the at least one processor of the at least one electronic hardware circuit device receives a first Implementing a plurality of software applications belonging to one group or a second group, each of which is configured to access and interact with at least one corresponding hardware resource assigned to the respective application; implementing a first allocation software agent which permits and configures the electronic hardware circuit device to allocate one or more unallocated hardware resources to only one or more software applications belonging to the first group; and implementing a second allocation software agent which permits and configures the electronic hardware circuit device to allocate one or more unallocated hardware resources to only one or more applications belonging to the second group, and for each allocated hardware resource, the logic control circuit shall, only if the requesting software application is the application to which the hardware resource is currently allocated,The requesting software application is further configured to allow the relinquishment of ownership of the allocated hardware resources.

[0087] It should be noted that one or more of the features in any of the above examples can be suitably or appropriately combined with any one of the other examples.

[0088] The foregoing description is provided for illustrative purposes only and can be modified without departing from the broader spirit or scope of the invention as described in the claims, as will be understood by those skilled in the art. Accordingly, this specification and the drawings should be considered illustrative rather than restrictive.

[0089] Accordingly, the scope of this disclosure is indicated by the attached claims, and is therefore intended to encompass all modifications that fall within the meaning and scope of the equivalents of the claims.

[0090] It should be understood that the implementations of the methods detailed herein are inherently empirical and therefore can be implemented in corresponding devices. Similarly, it should be understood that the implementations of the devices detailed herein can be implemented as corresponding methods. Therefore, it should be understood that a device corresponding to a method detailed herein may include one or more components configured to perform each aspect of the relevant method.

[0091] All acronyms defined in the above description are further retained in all claims contained herein.

Claims

1. A semiconductor chip, wherein the semiconductor chip is At least one electronic hardware circuit device, Memory containing program instructions, The memory and at least one processor core coupled to the at least one electronic hardware circuit device, Equipped with, The at least one electronic hardware circuit device is Multiple hardware resources, A logic control circuit that controls access to the aforementioned multiple hardware resources, Equipped with, The aforementioned multiple hardware resources are divisible, and each hardware resource includes a corresponding resource allocation state, the corresponding resource allocation state indicating whether each hardware resource is allocated or unallocated, and if allocated, indicating the allocated application owner. The aforementioned logic control circuit is Based on the resource allocation status of each of the aforementioned hardware resources, access to one or more of the plurality of hardware resources may be granted or denied. Based on input from one or more authorized agents, the resource allocation status is specified for each of the hardware resources. It is configured in such a way, The at least one processor core executes the program instruction, Implementing a plurality of software applications belonging to a first group or a second group, wherein each of the plurality of software applications is configured to access and interact with at least one corresponding hardware resource assigned to the respective software application. Implementing a first allocation software agent in the electronic hardware circuit device, which is authorized and configured to allocate one or more unallocated hardware resources to only one or more software applications belonging to the first group, Implementing a second allocation software agent in the electronic hardware circuit device, which is authorized and configured to allocate one or more unallocated hardware resources to only one or more software applications belonging to the second group, Perform For each allocated hardware resource, the logic control circuit is further configured to allow the requesting software application to relinquish ownership of the allocated hardware resource only if the requesting software application is the software application currently allocated to the hardware resource. Semiconductor chip.

2. The first and second allocation software agents are implemented on separate partitions by the at least one processor core. The semiconductor chip according to claim 1.

3. The aforementioned at least one processor core is configured to implement multiple virtual machines, The first and second assignment software agents implemented on separate partitions include a first assignment software agent implemented on a first virtual machine among the plurality of virtual machines, and a second assignment software agent implemented on a second virtual machine among the plurality of virtual machines. The semiconductor chip according to claim 2.

4. The aforementioned at least one processor core includes a plurality of processor cores, The first and second allocation software agents, implemented on separate partitions, include the first allocation software agent being implemented on a first processor core among the plurality of processor cores, and the second allocation software agent being implemented on a second processor core among the plurality of processor cores, The semiconductor chip according to claim 2.

5. The first and second assignment software agents are implemented on a single processor core, and the single processor core includes a plurality of processor partitions. The first allocation software agent is implemented on the first processor partition among the plurality of processor partitions, and the second allocation software agent is implemented on the second processor partition among the plurality of processor partitions. The semiconductor chip according to claim 2.

6. The software applications belonging to the first group and the software applications belonging to the second group are each implemented on separate partitions provided by the at least one processor core. The semiconductor chip according to claim 2.

7. The logic control circuit is configured such that the first allocation software agent can allocate one or more of the unallocated hardware resources to only one or more of the software applications belonging to the first group, and the second allocation software agent can allocate one or more of the unallocated hardware resources to only one or more of the software applications belonging to the second group. The semiconductor chip according to claim 1.

8. The first and second allocation software agents are each configured to request access to one or more of the unallocated hardware resources of the electronic hardware circuit device using one or more unique transaction identification codes, in order to allocate the unallocated resources of the electronic hardware circuit device. The semiconductor chip according to claim 1.

9. The logic control circuit is configured to provide the first or second allocation software agent with access to one or more of the unallocated hardware resources by verifying one or more unique transaction identification codes provided by the first or second allocation software agent. The semiconductor chip according to claim 1.

10. The one or more unique transaction identification codes indicate a mapping of the first assignment software agent or the second assignment software agent to one or more partitions implemented by the at least one processor core. The semiconductor chip according to claim 8 or 9.

11. For each allocated hardware resource, the logic control circuit is further configured to ensure that only the corresponding currently allocated software application can access the hardware resource. The semiconductor chip according to claim 1.

12. For each allocated hardware resource, the corresponding software application is configured to access the allocated hardware resource by providing one or more unique transaction identification codes that identify the software application. The logic control circuit is configured to verify the corresponding software application based on one or more transaction identification codes and to provide access to the allocated hardware resources. The semiconductor chip according to claim 1.

13. For each allocated hardware resource, the logic control circuit is further configured to allow only the corresponding currently allocated software application to specify data movement or processing configuration within the hardware resource. The semiconductor chip according to claim 1.

14. At least one electronic hardware circuit device includes multiple execution engines, each execution engine includes circuitry that performs one or more tasks. The semiconductor chip according to claim 1.

15. Each of the aforementioned hardware resources is coupled to the execution engine in a time-slice manner and is configured to form an interface with the execution engine. The semiconductor chip according to claim 14.

16. The at least one electronic hardware circuit device includes an interrupt controller, The aforementioned hardware resource includes multiple interrupts, The semiconductor chip according to claim 1.

17. The at least one electronic hardware circuit device includes a direct memory access (DMA) controller. The aforementioned hardware resource includes multiple DMA channels, The semiconductor chip according to claim 1.

18. Each of the aforementioned hardware resources includes one or more registers that indicate the allocation status of that resource and the data configuration of that resource. The semiconductor chip according to claim 1.

19. The semiconductor chip further includes the at least one electronic hardware circuit device, the memory, and a system interconnect coupled to the at least one processor core. The semiconductor chip according to claim 1.

20. The system interconnect is configured to provide a connection between the electronic hardware circuit device and the at least one processor core so that the electronic hardware circuit device can distinguish between communication from the first assignment software agent and communication from the second assignment software agent. The semiconductor chip according to claim 19.

21. The logic control circuit is a hardwired hardware component. The semiconductor chip according to claim 1.

22. The aforementioned semiconductor chip is a system-on-a-chip design. The semiconductor chip according to claim 1.

23. At least one software application in the first group is a security-related software application configured to perform one or more security-related software tasks. The semiconductor chip according to claim 1.

24. At least one software application of the second group is a safety-related software application implemented in accordance with one or more predetermined safety standards. The semiconductor chip according to claim 1.

25. The at least one electronic hardware circuit device is configured to perform a reset of the hardware resources, thereby setting the resource allocation state of each of the hardware resources to unassigned. The semiconductor chip according to claim 1.

Citation Information

Patent Citations

  • System for Dynamic Arbitration of Shared Resources on Devices

    JP2008500648A

  • Computer system

    JP2010250470A

  • Resource protection

    JP2020205050A

  • Method, device, electronic apparatus, and storage medium for resource management

    JP2021028820A

  • Allocation of shared system resources

    US20160092677A1