Memory management system, memory management method, and information processing apparatus with reduced power consumption
Provided is a memory management system that efficiently protects data in a cache memory adopting a virtual address cache method. The memory management system includes a cache memory that temporarily stores data for which memory access is requested by a processor core; a state storage unit that stores a security state communicated simultaneously with the memory access request from the processor core; and a memory management unit that manages access to a main memory. In a case where there is a change in the security state when memory access is requested by the processor core, a cache flush is performed for a cache line that hits the request.
1. A memory management system, comprising:
a cache memory configured to temporarily store data for which a memory access request is received from a processor core, wherein the memory access request is received concurrently with a security state of a process for which the memory access request is received from the processor core;
a state storage unit configured to store a security state of each cache line of the cache memory; and
circuitry configured to:
determine a difference between the security state of the process and the stored security state satisfies a determined rule in the cache memory in a case where the security state of the process does not match the stored security state; and
permit access of a cache line that hits the memory access request based on the determination that the difference satisfies the determined rule.
2. The memory management system according to claim 1 , wherein
the state storage unit is further configured to store a plurality of security states in units of cache lines of the cache memory, and
the plurality of security states includes the stored security state of the cache line.
3. The memory management system according to claim 1 , wherein
the state storage unit comprises one of a tag memory in the cache memory, a register disposed separately from the tag memory in the cache memory, a memory outside a cache line body, or a register outside the cache line body, and
the state storage unit is further configured to store the security state for each cache line of the cache memory.
4. The memory management system according to claim 1 , further comprising a memory management unit configured to manage access to a main memory, wherein the memory management unit is further configured to:
store permission information that indicates whether access is permitted for each security state in each entry of a page table in a translation lookaside buffer; and
determine whether access is permitted for the security state of the process based on the permission information stored in an entry that hits the memory access request.
5. The memory management system according to claim 1 , further comprising a memory management unit configured to manage access to a main memory, wherein
the memory management unit is further configured to perform a protection check; and
the state storage unit is further configured to:
write, based on the memory access request from the processor core, data read from the main memory to the cache memory based on the protection check by the memory management unit; and
store the security state in association with a corresponding cache line of the cache memory.
6. The memory management system according to claim 1 , wherein
in a case where the security state of the process for which the memory access request is received does not match the stored security state, the circuitry is further configured to perform a cache flush for the cache line that hits the memory access request, based on the determination that the difference does not satisfy the determined rule.
7. The memory management system according to claim 1 , further comprising a memory management unit configured to manage access to a main memory, wherein
in a case where the security state of the process for which the memory access request is received does not match the stored security state,
the memory management unit is further configured to perform a protection check, and
in a case where the memory access request is permitted, the circuitry is further configured to:
control access of the cache line that hits the memory access request; and
control update of the security state stored in the state storage unit.
8. The memory management system according to claim 1 , wherein the circuitry is further configured to
update the security state stored in the state storage unit based on the determination that the difference satisfies the determined rule.
9. The memory management system according to claim 1 , wherein
in a case where the security state of the process for which the memory access request is received is higher in authority than the stored security state, the circuitry is further configured to permit the access of the cache line that hits the memory access request.
10. The memory management system according to claim 1 , wherein the cache memory is configured to adopt a virtual address cache method.
11. A memory management method, comprising:
reading, from a main memory, data for which a memory access request is received from a processor core;
storing the data temporarily in a cache memory, wherein the memory access request is received concurrently with a security state of a process for which the memory access request is received from the processor core;
storing, by a state storage unit, a security state of each cache line of the cache memory;
determining, by circuitry, a difference between the security state of the process and the stored security state satisfies a determined rule in the cache memory in a case where the security state of the process does not match the stored security state; and
permitting, by the circuitry, access of a cache line that hits the memory access request based on the determination that the difference satisfies the determined rule.
12. An information processing apparatus, comprising:
a processor core;
a main memory;
a cache memory configured to temporarily store data for which a memory access request is received from the processor core, wherein the memory access request is received concurrently with a security state of a process for which the memory access request is received from the processor core;
a state storage unit configured to store a security state of each cache line of the cache memory;
circuitry configured to:
determine a difference between the security state of the process and the stored security state satisfies a determined rule in the cache memory in a case where the security state of the process does not match the stored security state; and
permit access of a cache line that hits the memory access request based on the determination that the difference satisfies the determined rule; and
a memory management unit configured to manage access to the main memory.