IP Library › Granted Patent US 12,346,488
Granted Patent B2
US 12,346,488 · App. 17/697,203 · Granted Jul 1, 2025

Methods and systems to restrict usage of a DMA channel

Inventor: Gregory R. Conti (St. Paul, FR)
Assignee: TEXAS INSTRUMENTS INCORPORATED
G06F21/85
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,346,488
App. No.
17/697,203
Granted
Jul 1, 2025
Kind
B2
Abstract

In at least some embodiments, a system comprises a processor and a direct memory access (DMA) subsystem coupled to the processor. The system further comprises a component coupled to the DMA subsystem via an interconnect employing security rules, wherein, if the component requests a DMA channel, the DMA subsystem restricts usage of the DMA channel based on the security rules.

Claims (79)

1. A system comprising:

a target;

an interconnect coupled to the target;

a direct memory access (DMA) subsystem coupled to the interconnect, wherein the DMA subsystem includes an internal register and a DMA channel, wherein the DMA channel is operable to make a transaction to transfer information to the target via the interconnect, wherein the internal register is operable to specify a plurality of qualifiers, and wherein a first qualifier of the plurality of qualifiers designates whether the transaction is a secure mode transaction or a normal mode transaction; and

an initiator coupled to the DMA subsystem,

wherein the initiator is operable to:

issue a DMA request to the DMA subsystem to cause the DMA subsystem to make the transaction; and

issue an access request to the DMA subsystem to configure the internal register.

2. The system of claim 1 , wherein a second qualifier of the plurality of qualifiers designates whether the transaction is a data transaction or an instruction transaction.

3. The system of claim 2 , wherein a third qualifier of the plurality of qualifiers designates whether the transaction is a privilege mode transaction or a public mode transaction.

4. The system of claim 3 , wherein a fourth qualifier of the plurality of qualifiers designates whether the transaction is a functional mode transaction or a debug mode transaction.

5. The system of claim 1 ,

wherein the internal register is accessible only when the access request to the DMA subsystem is a secure mode access request, and

wherein at least a first part of the internal register is configurable to specify the first qualifier.

6. The system of claim 5 , further comprising a processor,

wherein the DMA subsystem is configurable to detect a security violation based on the access request, and

wherein the DMA subsystem is configurable to cause an interrupt to the processor in response to detecting the security violation.

7. The system of claim 6 , wherein the DMA subsystem is further configurable to send an error response to the initiator in response to detecting the security violation.

8. The system of claim 5 ,

wherein the internal register further includes a second part configurable to specify a second qualifier of the plurality of qualifiers, and

wherein the second qualifier designates whether the transaction is a data transaction or an instruction transaction.

9. The system of claim 8 ,

wherein the internal register further includes a third part configurable to specify a third qualifier of the plurality of qualifiers, and

wherein the third qualifier designates whether the transaction is a privilege mode transaction or a public mode transaction.

10. The system of claim 9 ,

wherein the internal register comprises a DMA rights register including the first part, the second part, and the third part, and

wherein the first part, the second part, the third part are configurable all at once by one access request issued by the initiator.

11. The system of claim 9 ,

wherein the internal register further includes a fourth part configurable to specify a fourth qualifier of the plurality of qualifiers, and

wherein the fourth qualifier designates whether the transaction is a functional mode transaction or a debug mode transaction.

12. The system of claim 1 , wherein the DMA subsystem comprises a firewall configurable to:

receive a fifth qualifier with the access request from the initiator; and

in response to receiving the fifth qualifier, configure the DMA channel for read operations and write operations.

13. The system of claim 12 , wherein the fifth qualifier comprises an MReqSecure bit in the access request.

14. The system of claim 1 , wherein the DMA subsystem comprises a firewall configurable to:

receive the access request from the initiator;

determine that the access request includes no qualifiers; and

in response to determining that the access request includes no qualifiers, configure the DMA channel for only read operations.

15. The system of claim 1 , wherein the access request comprises an Open Core Protocol access request.

16. The system of claim 1 , wherein the initiator comprises a digital signal processor.

17. The system of claim 1 , wherein the target comprises a synchronous dynamic random-access memory scheduler.

18. A method comprising:

receiving, by a direct memory access (DMA) subsystem coupled to an interconnect, a DMA request from an initiator;

making, by a DMA channel of the DMA subsystem, a transaction to transfer information to a target via the interconnect in response to the DMA request, wherein an internal register of the DMA subsystem specifies a plurality of qualifiers, and wherein a first qualifier of the plurality of qualifiers designates whether the transaction is a secure mode transaction or a normal mode transaction; and

receiving, by the DMA subsystem from the initiator, an access request to configure the internal register.

19. The method of claim 18 , further comprising providing access to the internal register only when the access request is a secure mode access request,

wherein at least a first part of the internal register is configurable to specify the first qualifier.

20. The method of claim 19 , further comprising:

detecting a security violation based on the access request; and

sending an interrupt to a processor in response to detecting the security violation.

21. The method of claim 20 , further comprising sending an error response to the initiator in response to detecting the security violation.

22. The method of claim 19 ,

wherein the internal register further includes a second part configurable to specify a second qualifier of the plurality of qualifiers,

wherein the second qualifier designates whether the transaction is a data transaction or an instruction transaction,

wherein the internal register further includes a third part configurable to specify a third qualifier of the plurality of qualifiers,

wherein the third qualifier designates whether the transaction is a privilege mode transaction or a public mode transaction,

wherein the internal register comprises a DMA rights register including the first part, the second part, and the third part, and

wherein the method further comprises configuring the first part, the second part, the third part all at once in response to receiving the access request from the initiator.

23. The method of claim 18 , further comprising:

receiving a fifth qualifier with the access request from the initiator; and

in response to receiving the fifth qualifier, configure the DMA channel for read operations and write operations.

24. The method of claim 18 , further comprising:

receiving the access request from the initiator;

determining that the access request includes no qualifiers; and

in response to determining that the access request includes no qualifiers, configuring the DMA channel for only read operations.

25. A system comprising:

a target;

an interconnect coupled to the target;

an internal register including a first part, a second part, and a third part, wherein the first part is configurable to specify a first qualifier of a plurality of qualifiers, wherein the second part is configurable to specify a second qualifier of the plurality of qualifiers, and wherein the third part is configurable to specify a third qualifier of the plurality of qualifiers;

a direct memory access (DMA) channel coupled to the interconnect, wherein the DMA channel is configurable to make a transaction to transfer information to the target via the interconnect, and wherein the first qualifier designates whether the transaction is a secure mode transaction or a normal mode transaction;

a first initiator configurable to:

issue a DMA request to cause the DMA channel to make the transaction; and

issue a first access request to configure the internal register;

a second initiator configurable to issue a second access request to configure the internal register; and

a firewall configurable to:

receive a fourth qualifier with the first access request from the first initiator;

in response to receiving the fourth qualifier, configure the DMA channel for read operations and write operations;

determine that the second access request includes no qualifiers; and

in response to determining that the second access request includes no qualifiers, configure the DMA channel for only read operations.

Priority Claims (1)
EP 05292788 · Dec 23, 2005 · regional
Continuity (3)
Continuation 15682200 · Aug 21, 2017
Continuation 11557298 · Nov 7, 2006
Related Publication 20220222387A1 · Jul 14, 2022
References Cited (27)
US 5561817A · McCormack et al. · 1996 [cited by applicant]
US 5619727A · Chen et al. · 1997 [cited by applicant]
US 6496934B2 · Suzuki et al. · 2002 [cited by applicant]
US 6658502B1 · Story et al. · 2003 [cited by applicant]
US 6803132B1 · Alford et al. · 2004 [cited by applicant]
US 6820177B2 · Poisner · 2004 [cited by examiner]
US 6854039B1 · Strongin et al. · 2005 [cited by applicant]
US 6883132B1 · Dotson · 2005 [cited by applicant]
US 6898646B1 · Bonola et al. · 2005 [cited by applicant]
US 7555577B2 · Castille · 2009 [cited by examiner]
US 20030200451A1 · Evans et al. · 2003 [cited by applicant]
US 20040123013A1 · Clayton et al. · 2004 [cited by applicant]
US 20040236876A1 · Kondratiev et al. · 2004 [cited by applicant]
US 20040243823A1 · Moyer · 2004 [cited by examiner]
US 20050114616A1 · Tune et al. · 2005 [cited by applicant]
US 20050165783A1 · Hyser · 2005 [cited by applicant]
US 20050193182A1 · Anderson et al. · 2005 [cited by applicant]
US 20050259823A1 · Apostol, Jr. et al. · 2005 [cited by applicant]
US 20060080478A1 · Seigneret et al. · 2006 [cited by applicant]
US 20060090084A1 · Buer · 2006 [cited by applicant]
US 20060101187A1 · Filor · 2006 [cited by examiner]
US 20060129710A1 · O'Connor · 2006 [cited by examiner]
US 20060129747A1 · Weber · 2006 [cited by examiner]
US 20090177830A1 · Orion et al. · 2009 [cited by applicant]
US 20110067114A1 · Weber et al. · 2011 [cited by applicant]
US 20150082413A1 · Spicer et al. · 2015 [cited by applicant]
KR 970004513B1 · 1997 [cited by examiner]