Nova Patents
GB2503583B

Memory Protection

Abstract

This record has no abstract on file.

GB2503583B, drawing sheet 1
Sheet 1 of 4

Term

5.8 yearsleft in the term

Expires 27 June 2032.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

10 claims: 9 independent, 1 dependent

  1. 1
    - 1730 03 15 Claims 1. An integrated-circuit device comprising a processor, non-volatile memory, non-volatile memory control logic, and memory protection logic, wherein:the memory protection logic is arranged to control access to a protectable 5 region of the non-volatile memory in dependence on protection configuration data stored in a protection-configuration region of the non-volatile memory;the non-volatile memory is of a type that has a natural erased state;the non-volatile memory control logic is arranged to prevent writing to any portion of the protection-configuration region unless that portion is in an erased 10 state by, in response to receiving an instruction to write to a portion of the protection-configuration region, reading the portion and checking that the portion is in the natural erased state before allowing the write;and the non-volatile memory control logic is arranged to allow the protectionconfiguration region to be erased only if the protectable region is in an erased state.
  2. 2
    An integrated-circuit device comprising a processor, non-volatile memory, non-volatile memory control logic, and memory protection logic, wherein:the memory protection logic is arranged to control access to a protectable region of the non-volatile memory in dependence on protection configuration data 20 stored in a protection-configuration region of the non-volatile memory;the non-volatile memory comprises regions containing erased-state flags;the device is configured to reset a respective erased-state flag when each region is erased;the non-volatile memory control logic is arranged to set a respective erased25 state flag when a first write operation is performed into each region after the region is erased;the non-volatile memory control logic is arranged to prevent writing to any portion of the protection-configuration region unless that portion is in an erased state by, in response to receiving an instruction to write to a portion of the 30 protection-configuration region, checking one or more erased-state flags for the portion before allowing the write;and the non-volatile memory control logic is arranged to allow the protectionconfiguration region to be erased only if the protectable region is in an erased state. - 1830 03 15
  3. 4
    A device as claimed in any preceding claim, wherein the non-volatile memory control logic is configured so that the only mechanism provided by the nonvolatile memory control logic for erasing the protection-configuration region is an instruction that erases both the protectable region and the protection-configuration 10 region.
  4. 5
    A device as claimed in any preceding claim, wherein the protectionconfiguration region and the protectable region comprise different pages or erasable blocks of memory, and the non-volatile memory control logic is configured 15 to erase all pages or blocks forming the protectable region before erasing any page or block forming part of the protection-configuration region.
  5. 6
    A device as claimed in any preceding claim, wherein the memory protection logic is configured such that, when the protection-configuration region is in an 20 erased state, access to the protectable region is in the highest of an ordered set of restriction levels.
  6. 7
    A device as claimed in any preceding claim, arranged to store, in the memory-protection configuration region, one or more values that define the 25 protectable region of non-volatile memory and/or that define a protectable region of volatile memory.
  7. 8
    A device as claimed in any preceding claim, wherein the protection configuration data comprises a read protection flag for the protectable region of the 30 non-volatile memory, and wherein the memory protection logic is configured to:determine the state of the read protection flag;detect a memory read request by the processor;determine whether the read request is for an address in the protectable region;- 1930 03 15 determine whether the processor issued the read request while executing code stored in the protectable region;and deny read requests for addresses in the protectable region if the read protection flag for the protectable region is set, unless at least one of one or more 5 access conditions is met, wherein one of said access conditions is that the processor issued the read requests while executing code stored in the protectable region.
  8. 9
    A method of controlling memory access on an integrated-circuit device 10 comprising a processor and non-volatile memory, wherein the non-volatile memory is of a type that has a natural erased state, the method comprising:controlling access to a protectable region of the non-volatile memory in dependence on protection configuration data stored in a protection-configuration region of the non-volatile memory;15 preventing writing to any portion of the protection-configuration region unless that portion is in an erased state by receiving an instruction to write to a portion of the protection-configuration region and, in response, reading the portion and checking that the portion is in the natural erased state before allowing the write;and 20 allowing the protection-configuration region to be erased only when the protectable region is in an erased state.
  9. 10
    A method of controlling memory access on an integrated-circuit device comprising a processor, non-volatile memory and non-volatile memory control logic, 25 wherein:the non-volatile memory comprises regions containing erased-state flags;the device is configured to reset a respective erased-state flag when each region is erased;and the non-volatile memory control logic is arranged to set a respective erased30 state flag when a first write operation is performed into each region after the region is erased, the method comprising: controlling access to a protectable region of the non-volatile memory in dependence on protection configuration data stored in a protection-configuration 35 region of the non-volatile memory;-20preventing writing to any portion of the protection-configuration region unless that portion is in an erased state by receiving an instruction to write to a portion of the protection-configuration region and, in response, checking one or more erased-state flags for the portion before allowing the write;and 5 allowing the protection-configuration region to be erased only when the protectable region is in an erased state. 30 03 15