Data access method, soc and device

By dividing multiple storage areas in the SoC and setting access conditions, the problem of system firmware in flash memory being attacked by malicious programs is solved, and differentiated security management of flash memory is realized to effectively prevent attacks.

WO2025112927A1PCT designated stage expired Publication Date: 2025-06-05HUAWEI TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/123910
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-28
Filing Date
2024-10-10
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

The prior art is difficult to effectively protect the system firmware stored in flash memory from being attacked by malicious programs, resulting in security issues such as the inability to start the operating system normally.

Method used

By dividing multiple storage areas in the SoC and setting different access conditions for each storage area, the flash memory controller will determine whether the access conditions of the target storage area are met based on the access information. If it is met, the access request will be executed, otherwise access will be blocked.

Benefits of technology

Differentiated security management of different storage areas is realized, effectively preventing malicious programs from accessing areas where system firmware is stored, thereby protecting the firmware stored in flash memory from being attacked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024123910_05062025_PF_FP_ABST
    Figure CN2024123910_05062025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present disclosure are a data access method, a SoC and a device. The method is applied to the SoC. The SoC comprises a flash memory controller and a plurality of processing cores, and a flash memory controlled by the flash memory controller comprises a plurality of storage areas. The method comprises: a flash memory controller receiving an access request from a target processing core; acquiring access information corresponding to the access request, wherein the access information comprises at least one of indication information of the target processing core and an access opportunity; determining a target storage area in a flash memory where an access address corresponding to the access request is located; acquiring a target access condition corresponding to the target storage area; and when the access information meets the target access condition, executing the access request. The present disclosure can effectively protect system firmware stored in a flash memory from being attacked by malicious programs.
Need to check novelty before this filing date? Find Prior Art

Description

Data access method, SoC and device

[0001] This disclosure claims priority to Chinese patent application number 202311623719.6, filed on November 28, 2023, entitled “Method, SoC and Device for Data Access,” the entire contents of which are incorporated by reference into this disclosure. Technical Field

[0002] The present disclosure relates to the field of flash storage technology, and in particular to a data access method, SoC, and device. Background Art

[0003] System firmware is typically stored in flash memory. It's the first program executed after a device is powered on, loading and running before the operating system (OS). If the system firmware is attacked by malicious software, it can cause problems such as the operating system failing to boot properly. Because system firmware plays a crucial role in devices, protecting it from malicious software in flash memory has become a pressing issue.

[0004] Summary of the Invention

[0005] The present disclosure provides a data access method, SoC, and device that can protect firmware stored in flash memory from being attacked by malicious programs. The corresponding technical solutions are as follows:

[0006] In a first aspect, a data access method is provided. The method is applied to a SoC, wherein the SoC includes a flash memory controller and multiple processing cores. The flash memory controlled by the flash memory controller includes multiple storage areas. The method includes:

[0007] The flash memory controller receives an access request from a target processing core. It obtains access information corresponding to the access request, where the access information includes at least one of information indicating the target processing core and an access timing. The flash memory controller determines a target storage area in the flash memory where an access address corresponding to the access request is located. It obtains a target access condition corresponding to the target storage area. If the access information satisfies the target access condition, the flash memory controller executes the access request.

[0008] In the technical solution provided by this disclosure, flash memory is divided into multiple storage areas. Different access conditions can be assigned to different storage areas. These access conditions restrict at least one of accessors and access timing, thereby achieving differentiated security management for different storage areas. For storage areas storing system firmware, access conditions can be restricted to limit the processing cores that can access these storage areas, preventing malicious programs from accessing these storage areas. This protects the firmware stored in the flash memory from malicious attacks.

[0009] In one possible implementation, the SoC further includes an address permission register, which is used to store an address range of each storage area in the multiple storage domains. Accordingly, the flash memory controller may determine the target storage area in the flash memory where the access address corresponding to the access request is located as follows:

[0010] The flash memory controller reads the address range of each storage area in the address permission register and determines the target storage area in the flash memory where the access address corresponding to the access request is located based on the address range of each storage area.

[0011] In a possible implementation, the address permission register is further used to store access conditions corresponding to each storage area in the multiple storage domains. Accordingly, the flash memory controller may obtain the target access conditions corresponding to the target storage area as follows:

[0012] The flash memory controller reads the target access condition corresponding to the target storage area from the address permission register.

[0013] In one possible implementation, the SoC further includes a multi-port arbiter, and the multi-port arbiter is respectively connected to the flash memory controller and the plurality of processing cores;

[0014] Before the flash memory controller receives the access request from the target processing core, the method further includes:

[0015] The multi-port arbiter receives an access request sent by a target processing core, determines the indication information of the target processing core according to the port receiving the access request, and then sends the access request and the indication information of the target processing core to the flash memory controller.

[0016] In the technical solution provided by the present disclosure, multi-port arbitration is used to allocate indication information to the target processing core that sends the access request based on the connection port of the target processing core. The indication information is used to indicate the target processing core that sent the access request. The method of allocating indication information is simple, direct, and more efficient.

[0017] In a possible implementation, the multiple storage areas include a first storage area. The first storage area corresponds to a first access condition, and the first access condition includes: the processing core indicated by the indication information in the access information is a security subsystem.

[0018] In the technical solution provided by the present disclosure, the first storage area may have the highest security level among multiple storage areas, and this storage area is only accessible to the security subsystem. In this way, the security subsystem firmware may be stored in the first storage area.

[0019] In a possible implementation, the multiple storage areas include a second storage area. The second storage area corresponds to a second access condition, and the second access condition includes: the access timing in the access information is before entering the operating system OS.

[0020] In the technical solution provided by the present disclosure, the access condition of the second storage area is that access is only allowed before entering the OS, and malicious programs can only attack the system firmware during the OS operation. In this way, the data stored in the second storage area is relatively safe and can be protected from attacks by malicious programs. The second storage area can store BIOS.

[0021] In one possible implementation, the multiple storage areas include a third storage area, and the third storage area corresponds to a third access condition, and the third access condition includes: the processing core indicated by the indication information in the access information is any one of the security subsystem, the management subsystem, and the application processor in a secure state.

[0022] In the technical solution provided herein, access to the third storage area is restricted to processing cores with a high security level, such as the security subsystem, management subsystem, and secure application processors. Malicious programs can only attack the system firmware through application processors in an unsecured state. This ensures that data stored in the third storage area is relatively secure and protected from malicious attacks. Management subsystem firmware can be stored in the third storage area.

[0023] In a possible implementation, the multiple storage areas include a fourth storage area, and the fourth storage area corresponds to a fourth access condition, where the fourth access condition includes: the processing core indicated by the indication information in the access information is any one of the multiple processing cores.

[0024] In the technical solution provided by the present disclosure, the security level of the third storage area can be relatively low, and can be used to store configuration data of the system firmware. These configuration data can be information that will not affect the operation of the system even if attacked.

[0025] In a possible implementation, the access request further carries operation type indication information. Before the flash memory controller obtains access information corresponding to the access request, the method further includes:

[0026] The flash memory controller determines whether the operation type indicated by the operation type indication information is a read operation or a write operation.

[0027] In the technical solution provided by the present disclosure, only access requests corresponding to read operations and write operations may be restricted.

[0028] In one possible implementation, the method further includes:

[0029] If it is determined that the operation type indicated by the operation type indication information is not a read operation or a write operation, the flash memory controller executes the access request.

[0030] In the technical solution provided by the present invention, for access requests corresponding to operations other than read operations and write operations, access conditions do not need to be judged, and the access request can be directly executed. For example, operations such as querying the flash memory model, setting the flash memory operation mode, and flash memory quality inspection will not read or write the system firmware in the flash memory, that is, they will not affect the security of the system firmware.

[0031] In a second aspect, a system-on-chip (SoC) is provided. The SoC includes a flash memory controller and multiple processing cores. The flash memory controlled by the flash memory controller includes multiple storage areas. The flash memory controller is configured to:

[0032] receiving an access request from a target processing core;

[0033] Obtaining access information corresponding to the access request, wherein the access information includes at least one of indication information of the target processing core and access timing;

[0034] Determining a target storage area in the flash memory where an access address corresponding to the access request is located;

[0035] Obtaining a target access condition corresponding to the target storage area;

[0036] In a case where the access information satisfies the target access condition, the access request is executed.

[0037] In a possible implementation, the SoC further includes an address permission register, wherein the address permission register is used to store an address range of each storage area in the plurality of storage domains;

[0038] The flash memory controller is used to read the address range of each storage area in the address permission register, and determine the target storage area in the flash memory where the access address corresponding to the access request is located based on the address range of each storage area.

[0039] In a possible implementation, the address permission register is further configured to store an access condition corresponding to each storage area in the plurality of storage domains;

[0040] The flash memory controller is configured to read the target access condition corresponding to the target storage area from the address permission register.

[0041] In a possible implementation, the SoC further includes a multi-port arbitrator, and the multi-port arbitrator is connected to the flash memory controller and the multiple processing cores respectively;

[0042] The multi-port arbiter is configured to receive an access request sent by the target processing core; determine indication information of the target processing core according to the port receiving the access request; and send the access request and indication information of the target processing core to the flash memory controller.

[0043] In a possible implementation, the multiple storage areas include a first storage area. The first storage area corresponds to a first access condition, and the first access condition includes: the processing core indicated by the indication information in the access information is a security subsystem.

[0044] In a possible implementation, the multiple storage areas include a second storage area. The second storage area corresponds to a second access condition, and the second access condition includes: an access timing in the access information is before entering the operating system OS.

[0045] In one possible implementation, the multiple storage areas include a third storage area, and the third storage area corresponds to a third access condition, and the third access condition includes: the processing core indicated by the indication information in the access information is any one of a security subsystem, a management subsystem, and an application processor in a secure state.

[0046] In one possible implementation, the multiple storage areas include a fourth storage area, and the fourth storage area corresponds to a fourth access condition, and the fourth access condition includes: the processing core indicated by the indication information in the access information is any one of the multiple processing cores.

[0047] In a possible implementation, the access request further carries operation type indication information, and before the flash memory controller obtains the access information corresponding to the access request, it is further configured to:

[0048] It is determined whether the operation type indicated by the operation type indication information is a read operation or a write operation.

[0049] In a possible implementation, the flash memory controller is further configured to:

[0050] If it is determined that the operation type indicated by the operation type indication information is not a read operation or a write operation, the access request is executed.

[0051] In a third aspect, an electronic device is provided, comprising the SoC and flash memory as described in the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] FIG1 is a schematic structural diagram of a SoC provided by an embodiment of the present disclosure;

[0053] FIG2 is a flow chart of a method for data access provided by an embodiment of the present disclosure;

[0054] FIG3 is a schematic structural diagram of a SoC provided by an embodiment of the present disclosure;

[0055] FIG4 is a schematic structural diagram of a SoC provided by an embodiment of the present disclosure;

[0056] FIG5 is a schematic structural diagram of a chip system provided by an embodiment of the present disclosure. DETAILED DESCRIPTION

[0057] In order to make the objectives, technical solutions and advantages of the present disclosure more clear, the embodiments of the present disclosure will be further described in detail below with reference to the accompanying drawings.

[0058] An embodiment of the present disclosure provides a method for data access, which can be applied to a system on chip (SoC). SoC can be a chip in electronic devices such as base stations, routers, servers, desktops, and laptops. Referring to FIG1 , a schematic diagram of the structure of a SoC is shown. The SoC includes multiple processing cores, such as a security subsystem (Security module), a management subsystem (Management module), and an application processor (Application CPU). Among them, the security subsystem is used to handle system security-related matters, the management subsystem is used to manage the system status, and the application processor is used to run the operating system (OS) and application programs. The application processor is also called a business core. When the application processor is running, it can be in a secure state and a non-secure state.

[0059] The SoC also includes a flash controller, which is connected to the flash memory. System firmware, such as the security module firmware (SM firmware), the management module firmware (MM firmware), and the basic input and output system (BIOS), are stored in the flash memory. The security module firmware is run by the security subsystem to provide system security functions, the management module firmware is run by the management subsystem to provide system management functions, and the BIOS is run by the application processor to initialize the system and start the OS.

[0060] The SoC also includes a memory controller (DDR controller) and a hard disk controller (SATA controller). The DDR controller connects to the DDR, while the SATA controller connects to the Serial Advanced Technology Attachment hard disk (SATA hard disk). The DDR provides system memory, while the SATA hard disk stores the operating system.

[0061] Since system firmware with different system permissions are all stored in the flash memory, during the OS running phase, if the OS is attacked or there is a security vulnerability, malicious programs may access the flash memory and tamper with the system firmware stored in the flash memory, causing the OS to fail to run normally or cause serious security vulnerabilities.

[0062] The present disclosure provides a data access method implemented by a SoC. In this method, a flash memory is divided into multiple storage areas. Different storage areas may have different access conditions. The access conditions restrict at least one of the accessor and the access timing, thereby achieving differentiated security management of the different storage areas. The method is described below with reference to the accompanying drawings. Referring to FIG2 , the method may include the following steps:

[0063] Step 201: The flash memory controller receives an access request from a target processing core.

[0064] The target processing core is any processing core in the SoC, such as any one of the security subsystem, management subsystem, and application processor.

[0065] Step 202: The flash memory controller determines whether the operation type indication information carried in the access request is in the command control whitelist.

[0066] In practice, for operations other than read or write operations, the system firmware will not be modified or read. In this case, the operation type indication information of these operations can be added to the command control whitelist. For example, for operations such as querying the flash memory model, setting the flash memory operation mode, and flash memory quality inspection, the operation type indication information corresponding to these operations can be added to the command control whitelist.

[0067] After receiving the access request, the flash memory controller may read the operation type indication information in the access request and determine whether the operation type indication information is in the command control whitelist.

[0068] Step 203: If the operation type indication information carried in the access request is in the command control whitelist, the flash memory controller executes the access request.

[0069] In implementation, if the flash memory controller determines that the operation type indication information carried in the access request is in the command control whitelist, it executes the operation indicated by the operation type indication information in the access request.

[0070] Step 204: If the operation type indication information carried in the access request is not in the command control whitelist, determine whether the access address corresponding to the access request is in any storage area of ​​the multiple storage areas.

[0071] In practice, to achieve different security levels for data stored in flash memory, such as system firmware, the flash memory can be divided into multiple storage areas, each corresponding to a different security level. Data requiring protection, such as system firmware, stored in the flash memory is stored in these multiple storage areas based on the required security level. For example, the flash memory can be divided into four storage areas, each of which can be a single continuous storage area or composed of multiple discontinuous sub-storage spaces.

[0072] If the operation type indication information carried in the access request is not in the command control whitelist, the flash memory controller may obtain the address range of each of the multiple storage areas and then determine whether the access address corresponding to the access request is within the address range of any storage area.

[0073] The following describes how the flash memory controller obtains the address range of each of the multiple storage areas.

[0074] Referring to FIG3 , in an embodiment of the present disclosure, an address permission register may be configured in the SoC, in which the address range of each storage space is stored. For each storage area, if the storage area is a continuous storage area, the address range of the storage area refers to: the starting address of the storage area and the size of the storage area. If the storage area is composed of multiple discontinuous sub-storage areas, the address range of the storage area refers to: the starting address of each sub-storage area in the storage area and the size of the sub-storage area.

[0075] Furthermore, the starting address in the address range can be a relative address in the flash memory, which can also be called an offset address in the flash memory. After obtaining the access address carried in the access request, the access address can be converted into a relative address in the flash memory, and then, based on the address range of each storage area, it can be determined whether the access address is within any storage area.

[0076] Step 205: If the access address corresponding to the access request is not within any storage area among the multiple storage areas, the flash memory controller executes the access request.

[0077] In implementation, if the flash memory controller determines that the access address corresponding to the access request is not within any storage area among the multiple storage areas, the flash memory controller executes the operation indicated by the operation type indication information in the access request.

[0078] Step 206: If the access address corresponding to the access request is within the target storage area among the multiple storage areas, the flash memory controller obtains the access condition corresponding to the target storage area.

[0079] In practice, the address permission register also stores access conditions corresponding to each storage area. The access conditions are used to restrict at least one of the accessor and the access timing. The access conditions are described below using an example.

[0080] For example, as shown in Table 1 below, the flash memory includes four storage areas, namely the secure area, the boot area, the critical area, and the normal area. The access condition corresponding to the secure area is that only the security subsystem can access it. The access condition corresponding to the boot area is that it can only be accessed before entering the OS. The access condition corresponding to the critical area is that only the security subsystem, the management subsystem, and the application processor in a secure state can access it. The access condition corresponding to the normal area is that all processing cores in the SoC can access it. Here, all processing cores include the security subsystem, the management subsystem, the application processor in a secure state, and the application processor in a non-secure state.

[0081] Table 1

[0082] When it is determined that the access address corresponding to the access request is within the target storage area, the flash memory controller reads the access condition corresponding to the target storage area from the address permission register.

[0083] Step 207: The flash memory controller determines whether the access information of the access request satisfies the access condition corresponding to the target storage area.

[0084] In implementation, the flash memory controller may obtain access information of the access request, where the access information includes indication information of the target processing core and access timing. The indication information of the target processing core and the access timing are respectively described below.

[0085] Instructions for the target processing core:

[0086] The target processing core indication information is used to indicate the target processing core to which the access is being sent. For example, the first indication information indicates that the target processing core is the security subsystem, the second indication information indicates that the target processing core is the management subsystem, the third indication information indicates that the target processing core is an application processor in a secure state, and the fourth indication information indicates that the target processing core is an application processor in a non-secure state. Because malicious programs run on application processors in a non-secure state, for application processors, the secure and non-secure application processors can be treated as two different accessors, identified using two different indication information.

[0087] There are multiple methods for obtaining the indication information of the target processor, and two of them are exemplified below for illustration.

[0088] Method 1:

[0089] The access request carries the indication information of the target processing core. Accordingly, after receiving the access request, the flash memory controller can obtain the indication information of the target processing core carried in the access request.

[0090] Method 2:

[0091] Referring to FIG4 , in an embodiment of the present disclosure, the SoC may further include a multi-port arbiter, which is connected to the flash memory controller and multiple processing cores respectively. When the target processing core sends an access request to the flash memory controller, the multi-port arbiter first receives the access request and determines the indication information of the target processing core based on the port that receives the access request. Specifically, if the access request is received through the first port, the indication information of the target processing core is determined to be the first indication information, such as port0, and the first indication information is used to indicate that the target processing core sending the access request is the security subsystem. If the access request is received through the second port, the indication information of the target processing core is determined to be the second indication information, such as port1, and the second indication information is used to indicate that the target processing core sending the access request is the management subsystem. If the access request is received through the third port and a first status identifier sent by the application processor is received, the first status identifier is used to indicate that the operating state of the application processor is a secure state, the indication information of the target processing core is determined to be the third indication information, such as port2, and the third indication information is used to indicate that the target processing core sending the access request is an application processor in a secure state. If an access request is received through the third port, and the status identifier sent by the application processor is the second status identifier, and the second status identifier is used to indicate that the operating state of the application processor is a non-secure state, then the indication information of the target processing core is determined to be the fourth indication information, such as port3, and the fourth indication information is used to indicate that the target processing core sending the access request is an application processor in a non-secure state.

[0092] After determining the indication information of the target processing core, the multi-port arbiter sends an access request and the indication information of the target processing core to the flash memory controller. Correspondingly, the flash memory controller can receive the access request and the indication information of the target processing core.

[0093] Regarding visit timing:

[0094] When receiving an access request, the flash memory controller determines whether the current time is before entering the OS or after entering the OS, wherein before entering the OS and after entering the OS are two access opportunities. After entering the OS is also during the OS running process.

[0095] The following describes how to determine whether the access information of an access request satisfies the access condition corresponding to the target storage area by taking the storage areas and corresponding access conditions shown in Table 1 as an example.

[0096] If the target storage area is a secure area and the corresponding access condition is that only the secure subsystem can access it, the flash memory controller determines whether the indication information of the target processing core is indication information for indicating the secure subsystem. If the indication information of the target processing core is the first indication information for indicating the secure subsystem, the access information of the access request is determined to meet the access condition corresponding to the target storage area. If the indication information of the target processing core is not indication information for indicating the secure subsystem, the access information of the access request is determined to not meet the access condition corresponding to the target storage area.

[0097] If the target storage area is a boot area and the corresponding access condition is that it is accessible only before entering the OS, the flash memory controller determines whether the access timing is before entering the OS. If the access timing is before entering the OS, the access information of the access request is determined to satisfy the access condition corresponding to the target storage area. If the access timing is not before entering the OS, the access information of the access request is determined to not satisfy the access condition corresponding to the target storage area.

[0098] If the target storage area is a critical area and the corresponding access condition is that only the security subsystem, the management subsystem, and the application processor in a secure state can access it, the flash memory controller determines whether the indication information of the target processing core is any of the first indication information for indicating the security subsystem, the second indication information for indicating the management subsystem, and the third indication information for indicating the application processor in a secure state. If the indication information of the target processing core is any of the first indication information for indicating the security subsystem, the second indication information for indicating the management subsystem, and the third indication information for indicating the application processor in a secure state, the access information of the access request is determined to meet the access condition corresponding to the target storage area. If the indication information of the target processing core is not any of the first indication information for indicating the security subsystem, the second indication information for indicating the management subsystem, and the third indication information for indicating the application processor in a secure state, the access information of the access request is determined to not meet the access condition corresponding to the target storage area.

[0099] If the target storage area is a common area, the corresponding access condition is that all processing cores in the SoC can access it, and the flash memory controller determines that the access information of the access request satisfies the access condition corresponding to the target storage area.

[0100] Step 208: If it is determined that the access information of the access request does not meet the access condition corresponding to the target storage area, the flash memory controller does not execute the access request.

[0101] Step 209: If it is determined that the access information of the access request meets the access condition corresponding to the target storage area, the flash memory controller executes the access request.

[0102] In an implementation, if the flash memory controller determines that the access information of the access request meets the access condition corresponding to the target storage area, the flash memory controller executes the operation indicated by the operation type indication information in the access request.

[0103] In one possible implementation, the security subsystem firmware can be stored in the above-mentioned security area, the BIOS can be stored in the boot area (if the BIOS supports restart update), the management subsystem firmware can be stored in the critical area, and the configuration data of the system firmware can be stored in the ordinary area. These configuration data can be information that will not affect the system operation even if attacked.

[0104] In another possible implementation, when the BIOS does not support reboot updates, the BIOS may be stored in a critical area, and updates and upgrades of the BIOS may be implemented by a security subsystem, a management subsystem, or an application processor in a secure state.

[0105] In one possible implementation, the aforementioned command control whitelist may also be replaced with a command control list, which may include read operation indication information and write operation indication information. Accordingly, step 202 may be replaced with the following: the flash memory controller determines whether the operation type indication information carried in the access request is in the command control list.

[0106] The above step 203 may be replaced by: if the operation type indication information carried in the access request is not in the command control list, the flash memory controller executes the access request.

[0107] The above step 204 may be replaced by: if the operation type indication information carried in the access request is in the command control list, determining whether the access address corresponding to the access request is in any storage area among the multiple storage areas.

[0108] The following describes the execution of the data access method provided by the embodiment of the present disclosure in the scenario where a malicious program wants to tamper with the system firmware stored in the flash memory and in the scenario where the system firmware is normally upgraded, in combination with the storage areas and corresponding access conditions shown in Table 1 above.

[0109] Scenario 1: A malicious program attempts to tamper with the storage system firmware in the flash memory. In this scenario, the data access method provided by the embodiment of the present disclosure may have the following processing flow.

[0110] Step 301: The flash memory controller receives an access request from an application processor in a non-secure state.

[0111] In practice, a malicious program could hijack the OS to send a request to access the flash memory. The request carries a write instruction and an access address, which is the address where the system firmware is stored in the flash memory. The system firmware can be security subsystem firmware, management subsystem firmware, BIOS, etc.

[0112] In this case, the application processor in the non-secure state sends the above access request to the flash memory controller.

[0113] Step 302: The flash memory controller determines whether the write operation instruction information carried in the access request is in the command control whitelist.

[0114] Step 303: The flash memory controller determines that the write operation instruction information is not in the command control whitelist, and determines whether the access address corresponding to the access request is in any storage area of ​​the multiple storage areas.

[0115] Step 304: The flash memory controller determines that the write operation instruction information is within the security area, and obtains access conditions corresponding to the security area.

[0116] Step 305: The flash memory controller determines the access information of the access request, and if the access information does not meet the access conditions corresponding to the security area, the access request is not executed.

[0117] In practice, the access conditions for the secure zone are such that only the secure subsystem can access it. The flash memory controller determines that the instruction information from the processing core sending the access request indicates that the application processor is in a non-secure state. Furthermore, it determines that the access information of the access request does not meet the access conditions for the secure zone and does not execute the access request. This effectively prevents malicious programs from tampering with the system firmware.

[0118] Scenario 2: Normally upgrading the system firmware. In this scenario, the data access method provided by the embodiment of the present disclosure may have the following processing flow.

[0119] Step 401: The flash memory controller receives an access request from the security subsystem.

[0120] In practice, when the OS needs to update the system firmware, it calls the security subsystem firmware upgrade interface and sends the upgrade data to the security subsystem. The security subsystem verifies the integrity of the upgrade data using the public key. If the verification passes, it sends an access request to the flash memory controller. The access request carries the access address, which is the address where the system firmware is stored in the flash memory. The system firmware can be security subsystem firmware, management subsystem firmware, BIOS, etc.

[0121] Step 402: The flash memory controller determines whether the write operation instruction information carried in the access request is in the command control whitelist.

[0122] Step 403: The flash memory controller determines that the write operation instruction information is not in the command control whitelist, and determines whether the access address corresponding to the access request is in any storage area of ​​the multiple storage areas.

[0123] Step 404: The flash memory controller determines that the write operation indication information is within the secure area, and obtains access conditions corresponding to the secure area.

[0124] Step 405: The flash memory controller determines the access information of the access request and executes the access request if it meets the access conditions corresponding to the security area.

[0125] In practice, the access condition for the secure region is that only the secure subsystem can access it. The flash memory controller determines that the instruction information from the processing core sending the access request is the instruction information of the secure subsystem. It then determines that the access information of the access request meets the access condition for the secure region and executes the access request. This allows for a normal upgrade of the system firmware.

[0126] FIG5 is a schematic diagram of the structure of a chip system provided by the present disclosure. As shown in FIG5 , chip 1800 includes a processor 1801 and an interface circuit 1802, wherein interface circuit 1802 is configured to receive instructions and transmit them to processor 1801. Chip 1800 may be the SoC described in the above-mentioned embodiment, configured to execute the data access method provided by the embodiment of the present disclosure. Processor 1801 is coupled to memory 1803, which may include flash memory, internal memory, a hard disk, etc.

[0127] In one possible implementation, the chip system includes at least one processor 1801. It should be understood that in the present disclosure, the processor 1801 may be a CPU or other general-purpose processor. The processor 1801 may also be one or more integrated circuits, such as a digital signal processor (DSP), an ASIC, a PLD, an FPGA, or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. A general-purpose processor may be a microprocessor or any conventional processor.

[0128] In one possible implementation, the memory 1803 in the chip system may also be one or more. The memory 1803 may be integrated with the processor 1801 or may be separately provided with the processor 1801, which is not limited in this disclosure. For example, the memory 1803 may be integrated with the processor 1801 on the same chip, as shown in FIG5 . The memory 1803 may also be provided on different chips from the processor 1801. This disclosure does not specifically limit the type of memory 1803 or the configuration of the memory 1803 and the processor 1801.

[0129] The memory 1803 may include a read-only memory and a random access memory, and provides instructions and data to the processor 1801. The memory 1803 may also include a non-volatile random access memory. The memory 1803 may also be a volatile memory, or may include both volatile and non-volatile memory.

[0130] Among them, the non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0131] Exemplarily, the chip may be an FPGA, an ASIC, a SoC, a CPU, a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a PLD or other integrated chip.

[0132] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present disclosure, rather than to limit them. Although the present disclosure has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the protection scope of the technical solutions of the various embodiments of the present disclosure.

Claims

1. A method for data access, characterized in that: The method is applied to a system on chip (SoC), wherein the SoC includes a flash memory controller and a plurality of processing cores, and the flash memory controlled by the flash memory controller includes a plurality of storage areas. The method includes: The flash memory controller receives an access request from a target processing core; The flash memory controller obtains access information corresponding to the access request, wherein the access information includes at least one of indication information of the target processing core and access timing; The flash memory controller determines a target storage area in the flash memory where an access address corresponding to the access request is located; The flash memory controller obtains a target access condition corresponding to the target storage area; In a case where the access information satisfies the target access condition, the flash memory controller executes the access request.

2. The method according to claim 1, characterized in that The SoC further includes an address permission register, the address permission register being used to store an address range of each storage area in the plurality of storage domains, and the flash memory controller determining a target storage area in the flash memory where an access address corresponding to the access request is located, including: The flash memory controller reads the address range of each storage area in the address permission register; According to the address range of each storage area, a target storage area in the flash memory where the access address corresponding to the access request is located is determined.

3. The method according to claim 2, characterized in that The address permission register is further used to store the access condition corresponding to each storage area in the multiple storage domains, and the flash memory controller obtains the target access condition corresponding to the target storage area, including: The flash memory controller reads the target access condition corresponding to the target storage area in the address permission register.

4. The method according to any one of claims 1 to 3, characterized in that The SoC further includes a multi-port arbitrator, and the multi-port arbitrator is respectively connected to the flash memory controller and the multiple processing cores; Before the flash memory controller receives the access request from the target processing core, the flash memory controller further includes: The multi-port arbiter receives an access request sent by the target processing core; The multi-port arbiter determines the indication information of the target processing core according to the port receiving the access request; The multi-port arbiter sends the access request and indication information of the target processing core to the flash memory controller.

5. The method according to any one of claims 1 to 4, characterized in that The multiple storage areas include a first storage area. The first storage area corresponds to a first access condition, and the first access condition includes: the processing core indicated by the indication information in the access information is a security subsystem.

6. The method according to any one of claims 1 to 5, characterized in that The plurality of storage areas include a second storage area. The second storage area corresponds to a second access condition. The second access condition includes: an access timing in the access information is before entering the operating system OS.

7. The method according to any one of claims 1 to 6, characterized in that The multiple storage areas include a third storage area, and the third storage area corresponds to a third access condition, and the third access condition includes: the processing core indicated by the indication information in the access information is any one of the security subsystem, the management subsystem, and the application processor in the secure state.

8. The method according to any one of claims 1 to 7, characterized in that The multiple storage areas include a fourth storage area. The fourth storage area corresponds to a fourth access condition. The fourth access condition includes: the processing core indicated by the indication information in the access information is any one of the multiple processing cores.

9. The method according to any one of claims 1 to 8, characterized in that The access request also carries operation type indication information. Before the flash memory controller obtains access information corresponding to the access request, the method further includes: The flash memory controller determines whether the operation type indicated by the operation type indication information is a read operation or a write operation.

10. The method according to claim 9, characterized in that The method further comprises: In a case where it is determined that the operation type indicated by the operation type indication information is not a read operation or a write operation, the flash memory controller executes the access request.

11. A SoC, characterized in that: The SoC includes a flash memory controller and a plurality of processing cores, the flash memory controlled by the flash memory controller includes a plurality of storage areas, and the flash memory controller is used to: receiving an access request from a target processing core; Acquire access information corresponding to the access request, wherein the access information includes at least one of indication information of the target processing core and access timing; Determine a target storage area in the flash memory where an access address corresponding to the access request is located; Obtaining a target access condition corresponding to the target storage area; In a case where the access information satisfies the target access condition, the access request is executed.

12. The SoC according to claim 11, characterized in that: The SoC further includes an address permission register, wherein the address permission register is used to store an address range of each storage area in the plurality of storage domains; The flash memory controller is used to read the address range of each storage area in the address permission register, and determine the target storage area in the flash memory where the access address corresponding to the access request is located according to the address range of each storage area.

13. The SoC according to claim 12, characterized in that: The address permission register is also used to store the access conditions corresponding to each storage area in the multiple storage domains; The flash memory controller is used to read the target access condition corresponding to the target storage area in the address permission register.

14. The SoC according to any one of claims 11 to 13, characterized in that: The SoC further includes a multi-port arbitrator, and the multi-port arbitrator is respectively connected to the flash memory controller and the multiple processing cores; The multi-port arbiter is used to receive an access request sent by the target processing core; and determine the indication information of the target processing core according to the port receiving the access request; The access request and indication information of the target processing core are sent to the flash memory controller.

15. The SoC according to any one of claims 11 to 14, characterized in that: The multiple storage areas include a first storage area. The first storage area corresponds to a first access condition, and the first access condition includes: the processing core indicated by the indication information in the access information is a security subsystem.

16. The SoC according to any one of claims 11 to 15, characterized in that: The plurality of storage areas include a second storage area. The second storage area corresponds to a second access condition. The second access condition includes: an access timing in the access information is before entering the operating system OS.

17. The SoC according to any one of claims 11 to 16, characterized in that: The multiple storage areas include a third storage area, and the third storage area corresponds to a third access condition, and the third access condition includes: the processing core indicated by the indication information in the access information is any one of the security subsystem, the management subsystem, and the application processor in a secure state.

18. The SoC according to any one of claims 11 to 17, characterized in that: The multiple storage areas include a fourth storage area. The fourth storage area corresponds to a fourth access condition. The fourth access condition includes: the processing core indicated by the indication information in the access information is any one of the multiple processing cores.

19. The SoC according to any one of claims 11 to 18, characterized in that: The access request also carries operation type indication information, and before the flash memory controller obtains the access information corresponding to the access request, it is also used to: It is determined that the operation type indicated by the operation type indication information is a read operation or a write operation.

20. The SoC according to claim 19, characterized in that: The flash memory controller is further used for: In a case where it is determined that the operation type indicated by the operation type indication information is not a read operation or a write operation, the access request is executed.

21. An electronic device, characterized in that: The electronic device comprises the SoC and flash memory as described in claims 11 to 20 above.

Citation Information

Patent Citations

  • Data access method, SoC and equipment

    CN120068061A

  • A storage control apparatus and processor which comprises same

    CN112541200A

  • Computer architecture and access control method, data interaction method and secure startup method in computer architecture

    CN113268447A

  • Data access method and device, computer equipment and readable storage medium

    CN113312676A

  • Flash data access method and related equipment

    CN114218129A