Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

38 results about "Memory protection unit" patented technology

Memory protection unit. A memory protection unit (MPU), is a computer hardware unit that provide memory protection.

Task stack protection method and device, electronic equipment, chip and medium

The invention provides a task stack protection method and device, electronic equipment, a chip and a medium, and relates to the technical field of computer security. The task stack protection method comprises the following steps: in response to starting of an operating system, initializing a memory protection unit; based on the memory protection unit, the first task is removed from a stack protection memory area, the stack protection memory area is a stack top space of a task stack memory area of an operating system memory, and the first task is a process or a thread operated by an operating system in the stack protection memory area; setting attributes of a stack protection memory area of a second task, the second task being a task executed after the first task and being an active task; and moving the second task into the stack protection memory area. Through the technical scheme provided by the invention, the problem that the task stack protection of the memory area by the memory protection unit is unsafe and unreliable is solved, and the safety and reliability of the task stack protection of the memory area by the memory protection unit are improved.
Owner:SHANGHAI LIXIANG AUTOMOBILE CO LTD

Hardware virtual machine for controlling access to physical memory space

A system controls access to a physical address (PA) space. The system includes multiple system resources addressable within the PA space, and multiple processing circuits executing multiple virtual machines (VMs). A given region of the PA space is dedicated to addressing the VMs. The system also includes multiple memory management units (MMUs) coupled to corresponding processing circuits. A given MMU is operative to translate a virtual address indicated in an access request from a processing circuit into a requested PA that is accessible by the processing circuit according to a configurable setting of the given MMU. The system further includes multiple memory protection units (MPUs). A given MPU, which is coupled to a target system resource allocated with the requested PA, is operative to grant or deny the request based on information indicating whether the requested PA is accessible to a requesting VM executed on the processing circuit.
Owner:MEDIATEK INC

Brushing method for flashing Bootloader software

The invention belongs to the technical field of program updating, and particularly relates to a method for flashing Bootloader software, which comprises the following steps of: judging the validity of an application program by an operation starting manager, judging the validity of a programming mark if the application program is valid, and skipping to the operation of the application program if the programming mark is invalid; flashing the software of the second version of the boot loader and the effective copy mark into the flash area, and resetting the micro-control unit; the application program judges whether the copy effective mark is effective or not, if yes, the software of the second-version boot loader is copied to the position where the software of the first-version boot loader is located, after copying is completed, the copy effective mark is removed, and the software of the second-version boot loader is copied. And starting a memory protection unit preset by the micro-control unit to perform write access protection of all memories except for using the EEPROM, and enabling the application program to wait for other tasks. According to the method, the problem that the brick is damaged due to power failure when the power failure occurs in the process of flashing the Bootloader by running the APP is solved.
Owner:领科汇智科技有限公司 +1

Method for ensuring heap memory space safety of embedded system, and embedded system using same

A method for ensuring heap memory space security of an embedded system, according to some embodiments of the present invention, may comprise the steps of: receiving a source code; generating an instrumentation code for the source code; compiling the instrumentation code and executing a program; setting a plurality of memory protection units for a heap area; and performing memory boundary checking before performing a read / write command included in the program, wherein the step of performing the memory boundary checking can include the steps of: using a base pointer and a pointer for the read / write command, and specifying one of the plurality of memory protection units by using the base pointer; and using the base pointer and the pointer so as to determine whether to exceed the heap size for the specified memory protection unit.
Owner:PUSAN NAT UNIV IND UNIV COOPERATION FOUND

System, method and apparatus for accessing shared memory

A system, apparatus, and method for protecting coherent memory content in a coherent data processing network by filtering data access requests and snoop responses based on read / write (R / W) access permissions. Requests are augmented with access permissions in a memory protection unit, and the access permissions are used to control memory accesses by master nodes of the network.
Owner:ARM LTD

Null pointer access detection method and device, equipment and storage medium

The invention discloses a null pointer access detection method and device, equipment and a storage medium, and the method comprises the steps: obtaining error information of abnormal interruption of a memory protection unit MPU when null pointer access of a current program is detected; determining an error type and an error position according to the error information; and positioning the specific position of the access null pointer according to the error type and the error position, so that value writing or operation execution on a zero address can be prevented, the stability and the safety of a system can be protected, the specific position of a problem can be quickly positioned, debugging and repairing are facilitated, developers are helped to quickly position the point and the reason of the problem, and the development efficiency is improved. The speed and efficiency of null pointer access detection are improved.
Owner:ECARX (HUBEI) TECHCO LTD

Tool security system

Systems, methods, and circuitries are disclosed for providing security for tool access in a device. In one example, a device includes a bus master, a memory protection unit, and protection agent circuitry. The bus master is configured to store, in a first range of memory locations, request messages received from a tool interface of the device, each request message encapsulating a tool-related command. The memory protection unit is configured to prevent the bus master from accessing memory locations outside of the first range of memory locations. The protection agent circuitry is configured to access the first range of memory locations to identify one or more request messages, and send each respective request message to one of a plurality of component circuitries based on a component circuitry identified by the request message.
Owner:INFINEON TECHNOLOGIES AG

Memory access method, memory protection unit, system on chip, and storage medium

The application discloses a memory access method, a memory protection unit, a system on chip and a storage medium, and belongs to the chip technical field. The method is applied to the memory protection unit, the memory protection unit comprises at least one arbitration node, a plurality of input / output bridges and a plurality of checkers, the arbitration node is arranged between the plurality of input / output bridges and the plurality of checkers, and the method comprises the following steps: receiving a memory access request sent by an external device through an input / output bridge and sending the memory access request to the arbitration node; determining a target checker from the plurality of checkers according to traffic information of the plurality of checkers through the arbitration node, and forwarding the memory access request to the target checker; checking the memory access permission of the external device through the target checker, obtaining a checking result, and returning the checking result to the input / output bridge through the arbitration node; and the checking result is used to represent whether the external device passes the permission check. The application can solve the problem that the existing physical memory input / output protection method is low in efficiency.
Owner:BEIJING INSTITUTE OF OPEN SOURCE CHIP

Memory vulnerability repairing method, computer device and readable storage medium

ActiveCN120910872APlatform integrity maintainanceOperating systemMemory protection unit
The invention provides a vulnerability repair method of a memory, a computer device and a readable storage medium, the method comprises the following steps: obtaining an exception type corresponding to hardware exception trigger information, if the exception type is exception of a memory protection unit, obtaining information of a fault address recorded by a fault address register; if the exception type is breakpoint exception, inquiring information of a breakpoint address triggering the breakpoint exception; querying address information of the repair function from the vulnerability modification mapping table; obtaining a first vulnerability type of a vulnerability corresponding to the current abnormal condition, if the first vulnerability type is a function-level vulnerability, extracting a function parameter from a push register, and calling a repair function; if the first vulnerability type is an instruction-level vulnerability, analyzing a vulnerability instruction and calling a repair function; and executing the called repair function. The invention further provides a computer device and a readable storage medium for implementing the method. According to the method, bug repair is realized by multiplexing the original memory protection unit and the breakpoint module of the processor.
Owner:CORE TREND (ZHUHAI) TECH CO LTD

A memory protection unit, an electronic device, and an access monitoring method

The present application discloses a memory protection unit, an electronic device, and an access monitoring method, relating to the technical field of access control. The memory protection unit is configured to receive an access signal sent by an access unit when the access unit needs to access memory; after determining that the main controller in the access unit has valid access and determining that the access unit is restricted from accessing memory based on the access signal sent by the access unit, send a bus exception signal to the main controller, so that the main controller performs exception access processing after receiving the bus exception signal. Since the bus exception signal is not affected by the interrupt enable and the interrupt signal, the main controller can quickly receive the bus exception signal; the time delay from when the main controller receives the bus exception signal to when it enters the bus exception handling program is short, so as to perform exception access processing in a timely manner.
Owner:ACTIONS ZHUHAI TECH CO

Sandbox-based electric power agent process isolation protection method and system

The invention discloses a sandbox-based electric power agent process isolation protection method and system, and relates to the technical field of electric power agent process isolation protection, and the method comprises the following steps: obtaining power frequency time sequence data of an electric power system, extracting a frequency fluctuation curve to construct a first query sequence, screening the sequence through a DTW algorithm, and obtaining a reference sequence; frequency feature vectors are constructed for Fourier transform, and a granularity matrix is generated; inputting the granularity matrix into a multi-objective optimization function, and evaluating the memory allocation granularity by adopting an NSGA-III algorithm; dividing a process memory space into a plurality of isolation regions according to an evaluation result, and optimizing the memory capacity of each region by using a quantum annealing algorithm to obtain an optimal capacity; and deploying the optimal capacity to a memory protection unit to form an isolation barrier, and integrating the isolation barrier to a sandbox to realize security isolation. According to the method, the problem that the memory allocation granularity and capacity are not matched in the traditional process isolation is solved, and the problems of micro-granularity memory attacks such as cross-region access and cache injection are avoided.
Owner:HEFEI D2S INFORMATION TECH CO LTD

Memory vulnerability repair method, computer device and readable storage medium

ActiveCN120910872BPlatform integrity maintainanceOperating systemMemory protection unit
The application provides a vulnerability repair method of a memory, a computer device and a readable storage medium. The method comprises the following steps: obtaining an exception type corresponding to hardware exception trigger information, such as memory protection unit exception; obtaining information of a fault address recorded by a fault address register; when the exception type is a breakpoint exception, querying information of a breakpoint address triggering the breakpoint exception; querying address information of a repair function from a vulnerability modification mapping table; obtaining a first vulnerability type of a vulnerability corresponding to a current exception condition, such as a function-level vulnerability; extracting function parameters from a stack register and calling the repair function when the first vulnerability type is the function-level vulnerability; analyzing a vulnerability instruction and calling the repair function when the first vulnerability type is an instruction-level vulnerability; and executing the called repair function. The application also provides a computer device and a readable storage medium for implementing the above method. The application implements vulnerability repair by reusing a memory protection unit and a breakpoint module of an original processor.
Owner:CORE TREND (ZHUHAI) TECH CO LTD

A memory out-of-bounds detection method, device, medium and program product

This invention relates to the field of chip technology and discloses a method, device, medium, and program product for memory out-of-bounds detection. The method includes: obtaining the operator semantics and input parameters corresponding to a target operator, and generating initial address attribute entries based on the operator semantics and input parameters; obtaining the computing core corresponding to the target operator, and storing each initial address attribute entry in a fine-grained memory protection unit corresponding to the computing core; and performing memory out-of-bounds detection on memory access requests of the computing core based on each initial address attribute entry to obtain the detection result. By pre-deriving the address attribute entries corresponding to the target operator based on the operator semantics and input parameters, adding a fine-grained memory protection unit for storing the address attribute entries, and implementing real-time memory out-of-bounds detection of memory access requests based on the address attribute entries, efficient and accurate memory out-of-bounds detection under a memory pool mechanism can be achieved, ensuring memory data security.
Owner:SHANGHAI SUIYUAN TECH CO LTD

Register dynamic allocation method and system based on RISC-V architecture

The invention provides a dynamic register allocation method and system based on an RISC-V architecture, and belongs to the technical field of computers. The method comprises the steps that task characteristic data are received in real time; predicting a register demand corresponding to the task based on the task characteristic data; determining a partition decision of a self physical register based on the register demand; and dividing the register based on the partition decision, controlling the partition control register to dynamically configure the physical address range and the access authority of each physical register partition, and controlling the physical memory protection unit to configure the access rule of each physical register partition. According to the invention, the register demand is predicted based on the task characteristic data, the register is partitioned based on the register demand, and the dynamic allocation of the register is realized by expanding the type of the control and state register and the function of the physical memory protection unit, so that the allocation of the register adapts to the dynamic change of the task load during operation; and resource waste or conflict is avoided.
Owner:YUANQIXIN (SHANDONG) SEMICONDUCTOR TECHNOLOGY CO LTD

Memory protection unit with secure delegation

A memory protection unit (MPU) configuration request may be received, where the MPU configuration request may include a memory protection rule. A first entry in a first MPU circuit may be determined which matches the memory protection rule. A compliance result may be determined based on checking if the memory protection rule complies with the first entry. The memory protection rule may be written in a second MPU circuit based on the compliance result.
Owner:MIPS HLDG INC

A control logic runtime verification and security recovery method for embedded real-time systems

This invention discloses a method for runtime verification and safety recovery of control logic in embedded real-time systems, relating to the fields of embedded real-time control and functional safety technology. This invention constructs an independent safety monitoring layer outside the operating system kernel, defines runtime contracts containing safety invariance and timing logic constraints for critical control tasks, and performs real-time contract verification through periodic data collection. When a contract violation is detected, a layered recovery mechanism is initiated according to fault levels, including output clamping, task rollback and restart, and algorithm degradation switching. A memory protection unit is used to achieve spatiotemporal isolation protection for tasks. This invention achieves non-intrusive real-time monitoring and hierarchical safety recovery of critical control tasks, improving the functional safety and operational stability of embedded real-time systems. The monitoring overhead is controllable and does not affect real-time system scheduling, making it widely applicable to safety-critical scenarios such as vehicle control and industrial robots.
Owner:CHINA YANGTZE POWER

Self-checking method for memory protection unit

PendingCN120950315AFaulty hardware testing methodsTerm memoryInterrupt vector table
The invention discloses a self-checking method for a memory protection unit. The self-checking method comprises the following steps: setting an original first interrupt configuration table as a second interrupt configuration table which can only respond to self-checking abnormal interrupt and does not respond to other interrupts; remapping the interrupt entry address from the original interrupt vector table to a test interrupt vector table; and executing the test case to perform self-inspection on the memory protection unit. According to the self-checking method for the memory protection unit, the memory protection unit is subjected to self-checking, so that the memory access permission is effectively controlled by the memory protection unit, and the problem of latent faults caused by failure of the memory protection unit is avoided.
Owner:SHANGHAI AUTOMOTIVE CHIP ENG CENT CO LTD

Memory protection unit with security delegation

A memory protection unit with security delegation is provided. A memory protection unit (MPU) configuration request may be received, wherein the MPU configuration request may include a memory protection rule. A first entry in the first MPU circuit that matches the memory protection rule may be determined. A compliance result may be determined based on checking whether the memory protection rule conforms to the first entry. A memory protection rule may be written into the second MPU circuit based on the compliance result.
Owner:MPS HOLDINGS

A memory protection component and method that support multiple general-purpose embedded devices

The present invention provides a memory protection component and method that support multiple general-purpose embedded devices, relating to the technical field of memory protection in embedded operating systems. The present invention provides a general-purpose memory protection component and method, which are applied to an embedded operating system. The memory protection component includes a memory protection component abstraction layer module and a processor with a memory protection unit; the processor with a memory protection unit includes multiple types of processors with memory protection units; the memory protection component abstraction layer module receives a first parameter for identifying a processor with a memory protection unit, and performs identification and matching with the processor. The present invention solves the problem of dependence on a processor with a single memory protection unit, making the program more general-purpose, reducing the transplantation difficulty, increasing the efficiency of program reuse, and reducing the development work of embedded products.
Owner:上海睿赛德电子科技有限公司

Memory protection system

The present application discloses a memory protection system. The system comprises: a bus, and at least one memory controller coupled to the bus, each memory controller being coupled to a memory; a memory protection unit coupled to the bus, connected to the memory controller, the memory protection unit comprising an authentication unit, a control unit, and multiple protection blocks; and a configuration information storage unit, the configuration information storage unit being used to store an authentication key in a programmed state of the memory protection unit and configuration information for the multiple protection blocks; wherein the control unit configures the authentication unit and the multiple protection blocks based on the configuration information; when the memory protection unit is accessed or the configuration information is modified, the authentication unit is used to receive an input key and authenticate the input key with the authentication key stored in the authentication unit; the multiple protection blocks respectively correspond to multiple memory portions that need to be encrypted. The present application can prevent algorithms and software from being easily copied and reverse engineered.
Owner:RUIXING TECH (NANJING) CO LTD

An ECU-guided dynamic self-healing system, method, and device based on vehicle diagnostic communication protocol and physical perception.

PendingCN122309225AMicrocontrollerIn vehicle
This invention relates to the field of ECU management technology, and discloses an ECU boot dynamic self-healing system, method, and device based on vehicle diagnostic communication protocols and physical sensing. The key technical features include a microcontroller, non-volatile memory, a memory protection unit, and a power supply voltage detection unit. The microcontroller runs a boot protection module, a logic evolution module, a dynamic driving unit, and a snapshot management and power-down hardening unit. The boot protection module is used for power-on priority startup, reading snapshot status, performing fault self-healing, and resuming interrupted data transfer. The logic evolution module is used to execute the main business of the bootloader program. The dynamic driving unit is loaded into the running memory and used to perform erase / write operations on the updatable boot area, updating the snapshot information in the running memory in real time during the flashing process. The power supply voltage detection unit is used to trigger power-down processing. The snapshot management and power-down hardening unit is used to respond to power-down signals and write snapshot information to the snapshot storage area.
Owner:NANJING CHUHANG TECH CO LTD

Data management and consistency synchronization method and system for flexible direct control protection device

The invention discloses a data management and consistency synchronization method and system for a flexible direct-current control protection device, and relates to the technical field of flexible direct-current transmission, and the method comprises the steps: generating a memory allocation table of a global resource pool through the static analysis of a compiler, pre-dividing a fixed memory space according to the resource type, forbidding the dynamic memory operation, and storing the memory allocation table; dividing privileged areas through the memory protection unit; dynamically adjusting a transmission dead zone through a differential transmission mechanism and an adaptive transmission arbitration mechanism based on the pre-allocated global resource pool and the characteristics of data in the pool, and synchronizing the data in the global resource pool to a corresponding memory area of a target core from a source core; based on synchronized cross-domain data, multi-core data atomic update is ensured through clock synchronization and dual-mode consistency control. According to the method, dynamic balance of memory access efficiency, data integrity and task real-time performance is realized in a microsecond-level control period through technologies of static memory allocation, hardware isolation, multi-mode consistency control and the like.
Owner:GUODIAN NANJING AUTOMATION

Stack protection method and device for embedded real-time operating system and storage medium

The embodiment of the invention provides a stack protection method and device for an embedded real-time operating system and a storage medium, and relates to the technical field of computers. The method comprises the steps of calling a stack protection configuration function under the condition that a task switching function is executed to determine a target task; configuring an inaccessible area at the tail of a target task stack corresponding to the target task in a memory protection unit through a stack protection configuration function; and under the condition that the configuration of the inaccessible area is completed, executing the target task. According to the method, the stack protection area is dynamically configured during task switching, and stack space requirements of different tasks can be met; after the inaccessible area, corresponding to the tail of the target task stack, of the target task is configured in the memory protection unit, stack protection can be achieved through the memory protection unit, extra runtime resources do not need to be occupied, software polling detection is not needed, response delay is low, and reliability and safety of the embedded real-time operating system are improved.
Owner:CHANGSHA HAIGE BEIDOU INFORMATION TECH CO LTD

Power intelligent body process isolation protection method and system based on sandbox

The present invention discloses a sandbox-based power intelligent body process isolation protection method and system, which relates to the field of power intelligent body process isolation protection technology, including the following steps: obtaining power system power frequency time series data, extracting frequency fluctuation curve to construct a first query sequence, using DTW algorithm to screen the sequence to obtain a reference sequence, and constructing a frequency feature vector for Fourier transform to generate a granularity matrix; inputting the granularity matrix into a multi-objective optimization function, using NSGA-III algorithm to evaluate memory allocation granularity; dividing the process memory space into several isolated areas according to the evaluation results, optimizing the memory capacity of each area with a quantum annealing algorithm to obtain the optimal capacity; deploying the optimal capacity to a memory protection unit to form an isolation barrier, and integrating it into a sandbox to achieve secure isolation. This method solves the problem of mismatch between memory allocation granularity and capacity in traditional process isolation, and avoids the problem of micro-granular memory attacks such as cross-area access and cache injection.
Owner:HEFEI D2S INFORMATION TECH CO LTD

Memory access method, memory protection unit, system on chip and storage medium

The invention discloses a memory access method, a memory protection unit, a system on chip and a storage medium, and belongs to the technical field of chips. The method is applied to a memory protection unit, the memory protection unit comprises at least one arbitration node, a plurality of input / output bridges and a plurality of checkers, the arbitration node is deployed between the plurality of input / output bridges and the plurality of checkers, and the method comprises the following steps: receiving a memory access request sent by external equipment through the input / output bridges and sending the memory access request to the arbitration node; determining a target checker from the plurality of checkers through the arbitration node according to the traffic information of the plurality of checkers, and forwarding the memory access request to the target checker; checking the memory access permission of the external equipment through the target checker to obtain a check result, and returning the check result to the input / output bridge through the arbitration node; the checking result is used for representing whether the external equipment passes the permission checking. The problem that an existing physical memory input and output protection method is low in efficiency can be solved.
Owner:BEIJING INSTITUTE OF OPEN SOURCE CHIP

Granular access control for secure memory

A secure processing system includes a memory having a secure partition and a non-secure partition, a neural processing unit (NPU) configured to initiate transactions with the memory, and a memory protection unit (MPU) configured to filter the transactions. Each of the transactions includes at least an address of the memory to access, one of a plurality of first master part identifiers (IDs) associated with the NPU, and security information indicating whether the NPU was in a secure state or a non-secure state when the transaction was initiated. The MPU selectively denies access to the secure partition of the memory based at least in part on the memory address, the first master part ID, and the security information associated with each of the transactions.
Owner:SYNAPTICS INC

VEHICLE COMPUTER SYSTEM AND PROCEDURES

A system can comprise data processing hardware and storage hardware that communicates with the data processing hardware. Instructions can be stored in the storage hardware which, when executed on the data processing hardware, cause the data processing hardware to perform operations. These operations include requesting a hardware security module (HSM) via a host module's boot manager to verify the host module's application software and, through the verified application software, configuring a memory protection unit (MPU) to "Do Not Execute" and / or "Do Not Write" for at least one area of ​​the host module's memory. The operations further include executing the application software with the HSM enabled.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Input-output memory management unit with memory protection

A system on chip includes a dynamic random access memory (DRAM) controller, a secure range (SR) permission checker, a plurality of intellectual property (IP) cores. The DRAM controller includes a SR table configured to store a start address, an end address, and enabled registers of each SR and an access identification (AID) permission table configured to store access permissions of SRs of each AID. The SR permission checker is embedded in the DRAM controller or a bus and linked to the SR table and the AID permission table, and configured to check the access permissions of the SRs according to the AID permission table. The plurality of IP cores linked to the DRAM controller, and comprising a translation lookaside buffer (TLB) comprising an input-output memory management unit (IOMMU) table or an input-output memory protection unit (IOMPU) table to store SR information.
Owner:MEDIATEK INC

Method, system, and circuit for memory protection unit configuration and content generation

System, method, and circuitry for generating content for a programmable computing device based on user-selected memory regions. Contiguous regions that share memory access attributes are merged, interleaved contiguous regions that share at least one nested attribute are defined into combined regions, and remaining regions are defined as separate independent regions. A memory protection unit (MPU) region size closest to a size of each defined region is identified. If the start address of each region aligns with the address structure of the MPU region size, then those regions are assigned to MPU regions having the MPU region size; otherwise, another MPU size that aligns with the size of the regions is selected and those regions are assigned to MPU regions having that size. Content is generated to configure settings of MPU regions of the programmable computing device for the merged contiguous regions, the combined region, and the independent regions.
Owner:STMICROELECTRONICS (GRAND OUEST) SAS

An apparatus, a method of operating an apparatus, and a non-transitory computer readable medium to store computer-readable code for fabrication of an apparatus

There is provided an apparatus provided with counter control circuitry to maintain counters associated with data items including: minor counters, middle counters, and a major counter. The apparatus is also provided with a memory protection unit configured, in response to a transfer of a data item from secure storage to off-chip storage, to modify a minor counter associated with the data item, and to encrypt the data item based on counters associated with the data item. The memory protection unit is also responsive to an overflowing minor counter, to perform a middle re-encryption process comprising modifying a middle counter associated with the data item and re-encrypting data items associated with the middle counter. The memory protection unit is also responsive to an overflowing middle counter, to perform a major re-encryption process comprising modifying the major counter, and re-encrypting each of the data items.
Owner:ARM LTD