IP Library › Granted Patent US 11,669,620
Granted Patent B2
US 11,669,620 · App. 17/247,480 · Granted Jun 6, 2023

System platform initializer for mixed-critical systems

Inventors: Michele Paolino (Grenoble, FR); Salvatore Daniel Raho (Grenoble, FR)
Assignee: VIRTUAL OPEN SYSTEMS
G06F21/575G06F9/30101G06F9/4411G06F21/53G06F21/54
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,669,620
App. No.
17/247,480
Granted
Jun 6, 2023
Kind
B2
Abstract

The present disclosure relates to a computing architecture configured to run a first operating system ( 512 ) and an isolated operating system ( 520 ), wherein the computing architecture is configured to load and run the isolated operating system before loading and running the first operating system.

Claims (34)

1. A computing architecture configured to run a first operating system and an isolated operating system, the computing architecture comprising a first memory space in a non-system management mode (SMM) domain accessible by the first operating system, and a second memory space in a SMM domain, wherein:

the computing architecture is configured to load and run the isolated operating system in the second memory space before loading the first operating system in the first memory space and running the first operating system concurrently with the isolated operating system, wherein the isolated operating system is authorized to operate in any of a plurality of modes including the SMM while the first operating system is unable to operate in the SMM; and

during loading of the isolated operating system, the computing architecture is configured to lock memory accesses to prevent future access to the second memory space by the first operating system.

2. The computing architecture of claim 1 , wherein the computing architecture is configured to load and run the first operating system using a boot manager, the boot manager being launched after loading and running the isolated operating system using a further operating system loader.

3. The computing architecture of claim 1 , wherein the computing architecture is configured to run the isolated operating system in the system management mode, wherein the computing architecture further comprises a plurality of processing cores, one or more of the plurality of processing cores comprising a context switch configured to store the contents of one or more registers associated with the system management mode to the second memory space upon the isolated operating system exiting the system management mode, the context switch also being configured to restore the contents of the one or more registers upon a subsequent return to the system management mode.

4. The computing architecture of claim 1 , comprising a first memory management unit configured to manage access to the first memory space and a second memory management unit configured to manage access to the second memory space.

5. The computing architecture of claim 1 , wherein the first memory space stores a first system table, and wherein the computing architecture is configured, during booting of the isolated operating system, to run a driver in order to:

fill the first system table with one or more peripherals that are not safety-relevant;

create a second system table; and

fill the second system table with one or more safety-relevant peripherals, such that memory, registers and/or interrupts of safety-relevant peripherals are isolated from and non-accessible by the first operating system.

6. The computing architecture of claim 1 , wherein the isolated operating system is loaded and run in a system management mode, the computing architecture being configured to generate a system management interrupt for causing the system management mode to be entered before or during the loading of the isolated operating system.

7. The computing architecture of claim 1 , configured to give priority to the isolated operating system for decisions relating to hardware power management.

8. A computing system comprising a computer architecture configured to run a first operating system and an isolated operating system, the computing architecture comprising a first memory space in a non-system management mode (SMM) domain accessible by the first operating system, and a second memory space in a SMM domain, wherein:

the computing architecture is configured to load and run the isolated operating system in the second memory space before loading the first operating system in the first memory space and running the first operating system concurrently with the isolated operating system, wherein the isolated operating system is authorized to operate in any of a plurality of modes including the SMM while the first operating system is unable to operate in the SMM; and

during loading of the isolated operating system, the computing architecture is configured to lock memory accesses to prevent future access to the second memory space by the first operating system.

9. The computing system of claim 8 , configured to implement a heterogeneous distributed scalable and secure system.

10. The computing system of claim 8 , configured to monitor and/or control one or more services in an urban environment, wherein the isolated operating system is configured to run security workloads.

11. A method of booting a first operating system and an isolated operating system in a computing architecture, the computing architecture comprising a first memory space in a non-system management mode (SMM) domain accessible by the first operating system, and a second memory space in a SMM domain, the method comprising:

loading and running the isolated operating system in the second memory space; and

after loading and running the isolated operating system, loading the first operating system in the first memory space and running the first operating system concurrently with the isolated operating system,

wherein the isolated operating system is authorized to operate in any of a plurality of modes including the SMM while the first operating system is unable to operate in the SMM, and

wherein during loading of the isolated operating system, the computing architecture is configured to lock memory accesses to prevent future access to the second memory space by the first operating system.

12. The method of claim 11 , wherein the computer architecture comprises a first memory space accessible by the first operating system, and a second memory space, the method further comprising, during loading of the isolated operating system, locking memory accesses to prevent future access to the second memory space by the first operating system.

13. The method of claim 12 , wherein the first memory space stores a first system table, the method further comprising, during loading of the isolated operating system, running a driver in order:

fill the first system table with one or more peripherals that are not safety-relevant;

create a second system table; and

fill the second system table with one or more safety-relevant peripherals, such that memory, registers and/or interrupts of safety-relevant peripherals are isolated from and non-accessible by the first operating system.

14. A non-transitory storage medium storing instructions that cause a method to be implemented when executed by processing hardware, the method comprising:

booting a first operating system and an isolated operating system in a computing architecture, the computing architecture comprising a first memory space in a non-system management mode (SMM) domain accessible by the first operating system, and a second memory space in a SMM domain, the method further comprising:

loading and running the isolated operating system in the second memory space; and

after loading and running the isolated operating system, loading the first operating system in the first memory space and running the first operating system concurrently with the isolated operating system,

wherein the isolated operating system is authorized to operate in any of a plurality of modes including the SMM while the first operating system is unable to operate in the SMM, and

wherein during loading of the isolated operating system, the computing architecture is configured to lock memory accesses to prevent future access to the second memory space by the first operating system.

15. The computing system of claim 8 , configured to control automotive functions in a vehicle.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2021
From: PAOLINO, MICHELE; RAHO, SALVATORE DANIEL
To: VIRTUAL OPEN SYSTEMS
Reel/Frame 054899/0350 →
Priority Claims (1)
EP 19306648 · Dec 13, 2019 · regional
Continuity (1)
Related Publication 20210182401A1 · Jun 17, 2021