Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

19 results about "Memory protection unit" patented technology

Memory protection unit. A memory protection unit (MPU), is a computer hardware unit that provide memory protection.

Hardware virtual machine for controlling access to physical memory space

A system controls access to a physical address (PA) space. The system includes multiple system resources addressable within the PA space, and multiple processing circuits executing multiple virtual machines (VMs). A given region of the PA space is dedicated to addressing the VMs. The system also includes multiple memory management units (MMUs) coupled to corresponding processing circuits. A given MMU is operative to translate a virtual address indicated in an access request from a processing circuit into a requested PA that is accessible by the processing circuit according to a configurable setting of the given MMU. The system further includes multiple memory protection units (MPUs). A given MPU, which is coupled to a target system resource allocated with the requested PA, is operative to grant or deny the request based on information indicating whether the requested PA is accessible to a requesting VM executed on the processing circuit.
Owner:MEDIATEK INC

System, method and apparatus for accessing shared memory

A system, apparatus, and method for protecting coherent memory content in a coherent data processing network by filtering data access requests and snoop responses based on read / write (R / W) access permissions. Requests are augmented with access permissions in a memory protection unit, and the access permissions are used to control memory accesses by master nodes of the network.
Owner:ARM LTD

Memory access method, memory protection unit, system on chip, and storage medium

The application discloses a memory access method, a memory protection unit, a system on chip and a storage medium, and belongs to the chip technical field. The method is applied to the memory protection unit, the memory protection unit comprises at least one arbitration node, a plurality of input / output bridges and a plurality of checkers, the arbitration node is arranged between the plurality of input / output bridges and the plurality of checkers, and the method comprises the following steps: receiving a memory access request sent by an external device through an input / output bridge and sending the memory access request to the arbitration node; determining a target checker from the plurality of checkers according to traffic information of the plurality of checkers through the arbitration node, and forwarding the memory access request to the target checker; checking the memory access permission of the external device through the target checker, obtaining a checking result, and returning the checking result to the input / output bridge through the arbitration node; and the checking result is used to represent whether the external device passes the permission check. The application can solve the problem that the existing physical memory input / output protection method is low in efficiency.
Owner:BEIJING INSTITUTE OF OPEN SOURCE CHIP

Memory vulnerability repair method, computer device and readable storage medium

ActiveCN120910872BPlatform integrity maintainanceOperating systemMemory protection unit
The application provides a vulnerability repair method of a memory, a computer device and a readable storage medium. The method comprises the following steps: obtaining an exception type corresponding to hardware exception trigger information, such as memory protection unit exception; obtaining information of a fault address recorded by a fault address register; when the exception type is a breakpoint exception, querying information of a breakpoint address triggering the breakpoint exception; querying address information of a repair function from a vulnerability modification mapping table; obtaining a first vulnerability type of a vulnerability corresponding to a current exception condition, such as a function-level vulnerability; extracting function parameters from a stack register and calling the repair function when the first vulnerability type is the function-level vulnerability; analyzing a vulnerability instruction and calling the repair function when the first vulnerability type is an instruction-level vulnerability; and executing the called repair function. The application also provides a computer device and a readable storage medium for implementing the above method. The application implements vulnerability repair by reusing a memory protection unit and a breakpoint module of an original processor.
Owner:CORE TREND (ZHUHAI) TECH CO LTD

A memory out-of-bounds detection method, device, medium and program product

This invention relates to the field of chip technology and discloses a method, device, medium, and program product for memory out-of-bounds detection. The method includes: obtaining the operator semantics and input parameters corresponding to a target operator, and generating initial address attribute entries based on the operator semantics and input parameters; obtaining the computing core corresponding to the target operator, and storing each initial address attribute entry in a fine-grained memory protection unit corresponding to the computing core; and performing memory out-of-bounds detection on memory access requests of the computing core based on each initial address attribute entry to obtain the detection result. By pre-deriving the address attribute entries corresponding to the target operator based on the operator semantics and input parameters, adding a fine-grained memory protection unit for storing the address attribute entries, and implementing real-time memory out-of-bounds detection of memory access requests based on the address attribute entries, efficient and accurate memory out-of-bounds detection under a memory pool mechanism can be achieved, ensuring memory data security.
Owner:SHANGHAI SUIYUAN TECH CO LTD

Register dynamic allocation method and system based on RISC-V architecture

The invention provides a dynamic register allocation method and system based on an RISC-V architecture, and belongs to the technical field of computers. The method comprises the steps that task characteristic data are received in real time; predicting a register demand corresponding to the task based on the task characteristic data; determining a partition decision of a self physical register based on the register demand; and dividing the register based on the partition decision, controlling the partition control register to dynamically configure the physical address range and the access authority of each physical register partition, and controlling the physical memory protection unit to configure the access rule of each physical register partition. According to the invention, the register demand is predicted based on the task characteristic data, the register is partitioned based on the register demand, and the dynamic allocation of the register is realized by expanding the type of the control and state register and the function of the physical memory protection unit, so that the allocation of the register adapts to the dynamic change of the task load during operation; and resource waste or conflict is avoided.
Owner:YUANQIXIN (SHANDONG) SEMICONDUCTOR TECHNOLOGY CO LTD

A control logic runtime verification and security recovery method for embedded real-time systems

PendingCN122308328AOperational systemSafety property
This invention discloses a method for runtime verification and safety recovery of control logic in embedded real-time systems, relating to the fields of embedded real-time control and functional safety technology. This invention constructs an independent safety monitoring layer outside the operating system kernel, defines runtime contracts containing safety invariance and timing logic constraints for critical control tasks, and performs real-time contract verification through periodic data collection. When a contract violation is detected, a layered recovery mechanism is initiated according to fault levels, including output clamping, task rollback and restart, and algorithm degradation switching. A memory protection unit is used to achieve spatiotemporal isolation protection for tasks. This invention achieves non-intrusive real-time monitoring and hierarchical safety recovery of critical control tasks, improving the functional safety and operational stability of embedded real-time systems. The monitoring overhead is controllable and does not affect real-time system scheduling, making it widely applicable to safety-critical scenarios such as vehicle control and industrial robots.
Owner:CHINA YANGTZE POWER

An ECU-guided dynamic self-healing system, method, and device based on vehicle diagnostic communication protocol and physical perception.

PendingCN122309225AMicrocontrollerIn vehicle
This invention relates to the field of ECU management technology, and discloses an ECU boot dynamic self-healing system, method, and device based on vehicle diagnostic communication protocols and physical sensing. The key technical features include a microcontroller, non-volatile memory, a memory protection unit, and a power supply voltage detection unit. The microcontroller runs a boot protection module, a logic evolution module, a dynamic driving unit, and a snapshot management and power-down hardening unit. The boot protection module is used for power-on priority startup, reading snapshot status, performing fault self-healing, and resuming interrupted data transfer. The logic evolution module is used to execute the main business of the bootloader program. The dynamic driving unit is loaded into the running memory and used to perform erase / write operations on the updatable boot area, updating the snapshot information in the running memory in real time during the flashing process. The power supply voltage detection unit is used to trigger power-down processing. The snapshot management and power-down hardening unit is used to respond to power-down signals and write snapshot information to the snapshot storage area.
Owner:NANJING CHUHANG TECH CO LTD

Data management and consistency synchronization method and system for flexible direct control protection device

The invention discloses a data management and consistency synchronization method and system for a flexible direct-current control protection device, and relates to the technical field of flexible direct-current transmission, and the method comprises the steps: generating a memory allocation table of a global resource pool through the static analysis of a compiler, pre-dividing a fixed memory space according to the resource type, forbidding the dynamic memory operation, and storing the memory allocation table; dividing privileged areas through the memory protection unit; dynamically adjusting a transmission dead zone through a differential transmission mechanism and an adaptive transmission arbitration mechanism based on the pre-allocated global resource pool and the characteristics of data in the pool, and synchronizing the data in the global resource pool to a corresponding memory area of a target core from a source core; based on synchronized cross-domain data, multi-core data atomic update is ensured through clock synchronization and dual-mode consistency control. According to the method, dynamic balance of memory access efficiency, data integrity and task real-time performance is realized in a microsecond-level control period through technologies of static memory allocation, hardware isolation, multi-mode consistency control and the like.
Owner:GUODIAN NANJING AUTOMATION

Stack protection method and device for embedded real-time operating system and storage medium

The embodiment of the invention provides a stack protection method and device for an embedded real-time operating system and a storage medium, and relates to the technical field of computers. The method comprises the steps of calling a stack protection configuration function under the condition that a task switching function is executed to determine a target task; configuring an inaccessible area at the tail of a target task stack corresponding to the target task in a memory protection unit through a stack protection configuration function; and under the condition that the configuration of the inaccessible area is completed, executing the target task. According to the method, the stack protection area is dynamically configured during task switching, and stack space requirements of different tasks can be met; after the inaccessible area, corresponding to the tail of the target task stack, of the target task is configured in the memory protection unit, stack protection can be achieved through the memory protection unit, extra runtime resources do not need to be occupied, software polling detection is not needed, response delay is low, and reliability and safety of the embedded real-time operating system are improved.
Owner:CHANGSHA HAIGE BEIDOU INFORMATION TECH CO LTD

Memory access method, memory protection unit, system on chip and storage medium

The invention discloses a memory access method, a memory protection unit, a system on chip and a storage medium, and belongs to the technical field of chips. The method is applied to a memory protection unit, the memory protection unit comprises at least one arbitration node, a plurality of input / output bridges and a plurality of checkers, the arbitration node is deployed between the plurality of input / output bridges and the plurality of checkers, and the method comprises the following steps: receiving a memory access request sent by external equipment through the input / output bridges and sending the memory access request to the arbitration node; determining a target checker from the plurality of checkers through the arbitration node according to the traffic information of the plurality of checkers, and forwarding the memory access request to the target checker; checking the memory access permission of the external equipment through the target checker to obtain a check result, and returning the check result to the input / output bridge through the arbitration node; the checking result is used for representing whether the external equipment passes the permission checking. The problem that an existing physical memory input and output protection method is low in efficiency can be solved.
Owner:BEIJING INSTITUTE OF OPEN SOURCE CHIP

Granular access control for secure memory

A secure processing system includes a memory having a secure partition and a non-secure partition, a neural processing unit (NPU) configured to initiate transactions with the memory, and a memory protection unit (MPU) configured to filter the transactions. Each of the transactions includes at least an address of the memory to access, one of a plurality of first master part identifiers (IDs) associated with the NPU, and security information indicating whether the NPU was in a secure state or a non-secure state when the transaction was initiated. The MPU selectively denies access to the secure partition of the memory based at least in part on the memory address, the first master part ID, and the security information associated with each of the transactions.
Owner:SYNAPTICS INC

Method, system, and circuit for memory protection unit configuration and content generation

System, method, and circuitry for generating content for a programmable computing device based on user-selected memory regions. Contiguous regions that share memory access attributes are merged, interleaved contiguous regions that share at least one nested attribute are defined into combined regions, and remaining regions are defined as separate independent regions. A memory protection unit (MPU) region size closest to a size of each defined region is identified. If the start address of each region aligns with the address structure of the MPU region size, then those regions are assigned to MPU regions having the MPU region size; otherwise, another MPU size that aligns with the size of the regions is selected and those regions are assigned to MPU regions having that size. Content is generated to configure settings of MPU regions of the programmable computing device for the merged contiguous regions, the combined region, and the independent regions.
Owner:STMICROELECTRONICS (GRAND OUEST) SAS

An apparatus, a method of operating an apparatus, and a non-transitory computer readable medium to store computer-readable code for fabrication of an apparatus

There is provided an apparatus provided with counter control circuitry to maintain counters associated with data items including: minor counters, middle counters, and a major counter. The apparatus is also provided with a memory protection unit configured, in response to a transfer of a data item from secure storage to off-chip storage, to modify a minor counter associated with the data item, and to encrypt the data item based on counters associated with the data item. The memory protection unit is also responsive to an overflowing minor counter, to perform a middle re-encryption process comprising modifying a middle counter associated with the data item and re-encrypting data items associated with the middle counter. The memory protection unit is also responsive to an overflowing middle counter, to perform a major re-encryption process comprising modifying the major counter, and re-encrypting each of the data items.
Owner:ARM LTD

Vehicle computer system and method

A system may include data processing hardware and memory hardware in communication with the data processing hardware. The memory hardware may store instructions that when executed on the data processing hardware cause the data processing hardware to perform operations. The operations include requesting, via a boot manager of a host module, a hardware security module (HSM) to verify an application software of the host module and configuring, via the verified application software, a memory protection unit (MPU) to at least one of no execute and no write for at least one area of a memory of the host module. The operations further include executing the application software with the HSM enabled.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

System and method for controlling access to physical address space

A system for controlling access to a physical address (PA) space includes multiple processing circuits executing multiple virtual machines (VMs), multiple system resources addressable within the memory management unit space, multiple memory management units (MMUs) coupled to corresponding processing circuits, and multiple memory protection units (MPUs). A given region of the physical address space is dedicated to addressing the multiple VMs. A given memory management unit translates a virtual address indicated by a request processing circuit in an access request into a requested physical address, which can be accessed by the request processing circuit according to configurable settings of the given memory management unit. A given memory protection unit coupled to a target system resource allocated the requested physical address grants or denies the access request based on sideband signals included in page table entries used for virtual-to-physical address translation by the multiple memory management units.
Owner:MEDIATEK INC

Storage Device, Operating Method of Storage Device, And Computing Device

A storage device includes a plurality of cores respectively including a plurality of memory protection units (MPUs) and a trust core configured to in response to receiving a measurement command from a host device, acquire MPU information of each of the plurality of MPUs, generate a hash result of the plurality of cores based on the MPU information of each of the plurality of MPUs, and transmit the hash result of the plurality of cores to the host device.
Owner:SAMSUNG ELECTRONICS CO LTD

System and method for controlling access to physical address space

A system for controlling access to a physical address (PA) space includes a plurality of processing circuits executing a plurality of virtual machines (VMs), a plurality of system resources addressable within the PA space, a plurality of memory management units (MMUs) coupled to corresponding processing circuits, and a plurality of memory protection units (MPUs). A given region of the PA space is dedicated to addressing the plurality of VMs. A given MMU translates a virtual address indicated in an access request from a requesting processing circuit into a requested PA that is accessible by the requesting processing circuit according to a configurable setting of the given MMU. A given MPU coupled to a target system resource allocated with the requested PA grants or denies the access request according to a sideband signal that is included in a page table entry utilized by the plurality of MMUs for virtual-to-physical address translation.
Owner:MEDIATEK INC

Energy storage battery management system and code separation method

The invention discloses an energy storage battery management system and a code separation method in the technical field of energy storage system security, and aims to solve the problem that a solution for thoroughly isolating secure and non-secure codes in a single kernel environment is not provided in the prior art. The system comprises a single-core processor, the single-core processor is integrated with a memory, and the memory comprises a security code area used for realizing a security key function and a non-security code area used for realizing a non-security function; the secure code area performs data transmission with the non-secure code area through a cross-domain communication interface, and read-write permission isolation is performed between the secure code area and the non-secure code area through a memory protection unit; according to the invention, the memory is divided into the secure code area and the non-secure code area, the security, reliability and maintainability of the system are improved, and the system is designed based on a single-core processor, so that the economical efficiency of the system is ensured.
Owner:HEFEI GUOXUAN HIGH TECH POWER ENERGY