IP Library Granted Patent US 9,619,405
Granted Patent B2
US 9,619,405 · App. 14/551,577 · Granted Apr 11, 2017

Device having memory access protection

Inventors: Nir Atzmon (Netanya, IL); Eran Glickman (Rishon le Zion, IL); Tal Siton (Kiryat Ono, IL)
Assignee: NXP USA, INC.
G06F12/14G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,619,405
App. No.
14/551,577
Granted
Apr 11, 2017
Kind
B2
Abstract

A device has a protection unit for controlling access to a memory. Indirect memory access requests have control data indicative of a memory access control register to be written to provide indirect access to a target memory and requested address data indicative of at least one memory address of the target memory to be accessed. The protection unit contains protection data defining access rights of source units to access specified address ranges of the target memory, and a system bus interface interfacing to a source unit and a memory bus interface interfacing to the target memory via a controller. The protection unit has a control monitor for detecting an indirect memory access request, and an indirect address monitor for comparing requested address data to specified address ranges and subsequently grant the indirect memory access in accordance with access rights of the respective source unit.

Claims (31)

1. A system, comprising:

a system bus connectable to a target memory and to a source of indirect memory access requests, the indirect memory access requests comprising control data indicative of a memory access control register to be written to provide access to the target memory and requested address data indicative of at least one memory address of the target memory to be accessed, and

a protection unit for controlling access to the target memory, comprising:

a data storage for containing protection data defining access rights of source units to access specified address ranges of the target memory,

a system bus interface arranged to interface to at least one source unit via the system bus and a memory bus interface arranged to interface to the target memory via a memory bus,

a control monitor to monitor the system bus for detecting a respective indirect memory access request issued by a respective source unit, and

an indirect address monitor arranged to, upon said detecting, compare requested address data of the respective indirect memory access request to respective specified address ranges and subsequently grant the indirect memory access as requested by the respective indirect memory access request in accordance with respective access rights of the respective source unit.

2. System as claimed in claim 1 , wherein the access rights comprise, for a specific specified address range, a list of source units that are allowed to access the specific specified address range, and the indirect address monitor is arranged to only grant access when the comparison shows that the requested address is in the specific specified address range and the respective source unit is in the list of source units.

3. System as claimed in claim 1 , wherein the indirect address monitor is arranged to provide a violation signal upon said comparing and subsequently not granting the indirect memory access as requested by the respective indirect memory access request.

4. System as claimed in claim 1 , wherein the control monitor is arranged to provide a match signal upon said detecting, and the indirect address monitor is arranged to receive the match signal to enable said comparing of the requested address data of the respective indirect memory access request to respective specified address ranges.

5. System as claimed in claim 1 , wherein the control monitor is arranged to configure said detecting based on monitor configuration data.

6. System as claimed in claim 5 , wherein the control monitor is arranged to receive the monitor configuration data via the system bus.

7. System as claimed in claim 1 , wherein the protection unit comprises a memory for storing the protection data.

8. System as claimed in claim 1 , wherein the respective indirect memory access request comprises a source indication of the respective source unit, and the protection unit is arranged to retrieve the source indication.

9. System as claimed in claim 8 , wherein the control monitor is arranged to adapt said detecting based on the source indication.

10. System as claimed in claim 9 , wherein the indirect address monitor is arranged to adapt said comparing based on the source indication.

11. System as claimed in claim 1 , wherein the protection data comprises a privilege level required for accessing a respective specified address range, and the indirect address monitor is arranged to grant the indirect memory access to the respective specified address range only if a source privilege level of the respective source unit is at least as high as the privilege level.

12. System as claimed in claim 1 , wherein the indirect address monitor comprises a lookup table for storing the specified address ranges and corresponding access rights of source units.

13. System as claimed in claim 1 , wherein the protection data comprises a specified access type for accessing a specified address range, and the indirect address monitor is arranged only to grant the indirect memory access to the respective specified address range if the indirect memory access request has an access type allowed by the specified access type.

14. System as claimed in claim 13 , wherein the specified access type comprises one of read access, write access, and full access including read and write access.

15. System as claimed in claim 1 , comprising the at least one target memory coupled to the memory bus.

16. System as claimed in claim 1 , comprising the at least one source unit coupled to the system bus.

17. Integrated circuit comprising at least one device according to claim 1 .

18. Processing system for processing data comprising at least one device according to claim 1 , and the at least one source unit coupled to the system bus and the at least one target memory coupled to the memory bus.

19. Method of controlling access to a memory in a protection unit,

indirect memory access requests as transferred via a system bus providing indirect memory access to a target memory, the indirect memory access requests comprising control data indicative of a memory access control register to be written to provide access to the target memory and requested address data indicative of at least one memory address of the target memory to be accessed,

the protection unit being arranged to contain protection data defining access rights of source units to access specified address ranges of the target memory,

the method comprising

monitoring the system bus for detecting a respective indirect memory access request issued by a respective source unit, and

comparing, upon said detecting, requested address data of the respective indirect memory access request to respective specified address ranges and subsequently granting the indirect memory access as requested by the respective indirect memory access request in accordance with respective access rights of the respective source unit.

20. Method as claimed in claim 19 , said granting comprising blocking the indirect memory access when the requested address is within the specified address range and the access rights of the respective source issuing the request are insufficient, and enabling the indirect memory access when the requested address is within the specified address range and the access rights of the respective source issuing the request are sufficient, or when the requested address is outside any protected specified address range.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050744/0097 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 040626 FRAME: 0683. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER AND CHANGE OF NAME EFFECTIVE NOVEMBER 7, 2016. Recorded Jan 12, 2017
From: NXP SEMICONDUCTORS USA, INC. (MERGED INTO); FREESCALE SEMICONDUCTOR, INC. (UNDER)
To: NXP USA, INC.
Reel/Frame 041414/0883 →
CHANGE OF NAME Recorded Nov 16, 2016
From: FREESCALE SEMICONDUCTOR INC.
To: NXP USA, INC.
Reel/Frame 040626/0683 →
SUPPLEMENT TO THE SECURITY AGREEMENT Recorded Jun 16, 2016
From: FREESCALE SEMICONDUCTOR, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039138/0001 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 5, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037444/0444 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 5, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037444/0535 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037358/0001 →
SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Feb 18, 2015
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035033/0001 →
SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Feb 18, 2015
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035034/0019 →
SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Feb 18, 2015
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035033/0923 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2014
From: ATZMON, NIR; GLICKMAN, ERAN; SITON, TAL
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 034250/0903 →
Continuity (1)
Related Publication 20160147672A1 · May 26, 2016