Microprocessor
Abstract
Problem to be solved.To provide a microprocessor capable of safely managing information used by a task executed by a pipeline.
Solution.In a microprocessor that executes a program by a pipeline, when a switching instruction to a second task is issued when a plurality of units 1121 to 1125 are executing a first task. After the execution of the first task is completed, the value of the task register 115 is switched to the second register information used when the second task is executed. The task register management means 131 and the second register information are switched to. After that, the value of the task identification information register 114 is switched to the second task identifier, and each unit 1121 to 1125 is provided with the task management means 161 for permitting the execution of the second task. [Selection diagram] Fig. 1
Term
Term ended
Projected expiry passed 7 July 2024, 2.2 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
11 claims: 4 independent, 7 dependent
- 1パイプライン方式によりタスクを実行するマイクロプロセッサであって、 第1のタスクを実行する複数のユニットと、 前記マイクロプロセッサが前記第1のタスクを識別する第1のタスク識別情報を保持するタスク識別情報レジスタと、 前記複数のユニットが第1のタスクを実行するときに利用する第1のレジスタ情報を保持するタスクレジスタと、 前記複数のユニットのうち命令実行ユニットが前記第1のタスクを実行しているときに第2のタスクへの切替命令が発行された場合に前記第1のタスクを実行しているユニットに既にエントリされている前記第1のタスクの実行が総て完了したことを検出するタスク完了検出手段と、 前記タスク完了検出手段が前記第1のタスクの実行が完了したことを検出した場合に、前記タスクレジスタの値を前記第2のタスクを実行するときに利用する第2のレジスタ情報に切り替えるタスクレジスタ管理手段と、 前記タスクレジスタ管理手段が前記第2のレジスタ情報に切り替えた場合に、前記タスク識別情報レジスタの値を前記第2のタスクを識別する第2のタスク識別情報に切り替え、前記各ユニットに対し前記第2のタスクの実行を許可するタスク管理手段とを備えたことを特徴とするマイクロプロセッサ。
- 2前記切替命令が発行されてから前記タスクレジスタ管理手段が前記第2のレジスタ情報への切り替えが完了するまでの間に、前記ユニットに対して命令フェッチの待ち合わせを設定するタスク設定手段をさらに備えたことを特徴とするマイクロプロセッサ。
- 3前記切替命令が発行されたときに、前記複数のユニットのうち命令を実行する実行ユニットが実行していた前記第1のタスクに対して切替フラグを付与する切替フラグ付与手段をさらに備え、 前記実行ユニットは、前記第1のタスクを当該第1のタスクとともに、前記切替フラグ付与手段によって付与された前記切替フラグを次のユニットに受け渡し、 前記タスク完了検出手段は、前記パイプラインの最終ユニットが前記切替フラグを取得した場合に、前記第1のタスクの実行が完了したことを検出することを特徴とする請求項1または2に記載のマイクロプロセッサ。
- 4パイプラインによりプログラムを実行するマイクロプロセッサであって、 タスクを実行する複数のユニットと、 各ユニットが実行している前記タスクを識別するタスク識別情報を、対応するユニットを認識可能な形式で保持するタスク識別情報レジスタと、 前記ユニットから所定の処理要求を取得した場合に、前記タスク識別情報レジスタが前記ユニットに対して保持している前記タスク識別情報を特定するタスク識別情報特定手段と、 前記タスク識別情報特定手段が特定した前記タスク識別情報に基づいて、前記処理要求にかかる処理を制御する制御手段とを備えたことを特徴とするマイクロプロセッサ。
- 5前記複数のユニットが前記タスクを実行するときに利用するレジスタ情報を保持するタスクレジスタをさらに備え、 前記タスク識別情報特定手段は、前記ユニットから前記レジスタ情報へのアクセス要求を取得した場合に、前記タスク識別情報レジスタが保持している前記ユニットの前記タスク識別情報を特定し、 前記制御手段は、前記タスク識別情報特定手段が特定した前記タスク識別情報に基づいて前記タスクレジスタに保持されている前記レジスタ情報へのアクセスを制御することを特徴とする請求項4に記載のマイクロプロセッサ。
- 6前記制御手段は、前記タスクレジスタが保持している前記レジスタ情報に対応付けて予め設定されたタスク識別情報以外のタスク識別情報に対応する前記ユニットから前記タスクレジスタへのアクセスを禁止することを特徴とする請求項5に記載のマイクロプロセッサ。
- 7前記タスクレジスタを複数備え、 前記タスクレジスタが保持する前記レジスタ情報を識別するレジスタ情報識別情報と、前記タスク識別情報とを対応付けて保持するレジスタテーブルをさらに備え、 前記制御手段は、前記レジスタテーブルにおいて前記タスク識別情報に対応付けられた前記レジスタ情報識別情報で識別される前記レジスタ情報以外のレジスタ情報を保持する前記タスクレジスタへのアクセスを禁止することを特徴とする請求項6に記載のマイクロプロセッサ。
- 8前記レジスタ情報識別情報と前記タスク識別情報をと対応付けて前記レジスタテーブルに設定するレジスタテーブル設定手段をさらに備え、 前記レジスタテーブルは、前記レジスタテーブル設定手段によって設定された前記レジスタ情報識別情報と、前記タスク識別情報とを対応付けて保持することを特徴とする請求項7に記載のマイクロプロセッサ。
- 9前記複数のユニットが前記タスクを実行するときに利用する情報を保持するメモリをさらに備え、 前記タスク識別情報特定手段は、前記ユニットから前記メモリへのアクセス要求を取得した場合に、前記タスク識別情報レジスタが保持している前記ユニットの前記タスク識別情報を特定し、 前記制御手段は、前記タスク識別情報特定手段が特定した前記タスク識別情報に基づいて前記メモリに保持されている前記メモリ情報へのアクセスを制御することを特徴とする請求項4に記載のマイクロプロセッサ。
- 10パイプラインによりプログラムを実行するマイクロプロセッサであって、 タスクを実行する複数のユニットと、 各ユニットが利用するレジスタセットを識別するレジスタ情報識別情報を、対応するユニットを認識可能な形式で保持するレジスタ情報識別情報レジスタと、 前記ユニットから所定の処理要求を取得した場合に、前記レジスタ情報識別情報レジスタが前記ユニットに対して保持している前記レジスタ情報識別情報を特定するレジスタ情報識別情報特定手段と、 前記レジスタ情報識別情報特定手段が特定した前記レジスタ情報識別情報に基づいて、メモリアクセス処理要求にかかる処理を制御する制御手段とを備えたことを特徴とするマイクロプロセッサ。
- 11前記複数のユニットが前記タスクを実行するときに利用する情報を保持するメモリを備え、前記タスク識別子情報と前記タスクレジスタの対応付けをするタスク識別情報テーブル設定手段と、 レジスタ識別情報とタスク識別情報を対応付けて保持するタスク識別情報テーブルと、 前記ユニットから前記メモリへのアクセス要求を取得した場合に、前記タスク識別情報テーブルにおいて前記レジスタ識別情報に対応付けられた前記タスク識別情報を特定するタスク識別情報特定手段とをさらに備え、 前記制御手段はタスク識別情報特定手段が特定したタスク識別情報を用いてメモリアクセスを制御することを特徴とする 請求項9に記載のマイクロプロセッサ。
Independent claims11
110 paragraphs, as filed
The present invention relates to a microprocessor that performs tasks in a pipeline.
In recent years, open systems have become widespread. In the open system, the source code of the hardware and operating system (OS) of a computer for general users such as a personal computer (PC) is disclosed. The end user can change or improve the operating program by using the source code or the like to obtain the desired program.
On the other hand, it is necessary to protect the copyright of the information handled by the application program and the copyright of the program itself. For this purpose, a mechanism for protecting the confidentiality of the program, that is, a mechanism for preventing modification of the program is required. As an attack on the application program, it is assumed that the OS program is modified to attack the application program. Therefore, it is difficult to prevent the intrusion of a third party simply by performing a process on the OS to prevent an attack on the application program. Therefore, hardware that can keep the program secret is required. In general, it is extremely difficult for the end user to modify the hardware as compared to modifying the OS.
Anti-tamper processors have already been proposed as hardware having such characteristics, particularly microprocessors (see, for example, "Patent Document 1"). The anti-tamper processor has a function of encrypting a program and the information used in the program in a multitasking environment. This prevents the program and information from being leaked to a third party and the program and the like from being modified.
Further, in recent years, in order to effectively utilize the instruction execution function, there is a technique for executing an instruction of another thread when a waiting time for memory access occurs to eliminate free time and improve throughput. One of the technologies is hyper-threading technology that recognizes one physical processor as two virtual processors (see, for example, "Non-Patent Document 1").
In this technology, the instruction execution function is shared between virtual processors, but each processor has the necessary resources such as registers and TLB. Then, an appropriate one is selected according to the switching. In addition, threads that are not waiting targets operate during the waiting time for memory access, and other threads are executed alternately.
In order to perform the above processing, it has a register rename function for changing the register number written in the instruction to a physical register number. Each virtual processor also holds a register alias table (RAT) for renaming registers.
<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2001-230770</text></patcit><nplcit num="1"><text>Deborah T. Marr et al., Hyper-Threading Technology Architecture and Microarchitecture, Intel Technology Journal (February 2002)</text></nplcit>
<p> In order to realize the confidentiality of a task, it is necessary to prohibit unauthorized reference from other tasks to the resources of a certain protected task, such as registers and memory. For example, a malicious third party can use the OS to access protected tasks.</p><p> Therefore, conventionally, when an interrupt / task restart instruction is generated, the instruction execution unit saves the contents of the task register set before the interrupt / restart by the processor hardware, and saves the contents of the task register set after the interrupt / restart. Was restored. At the same time, the value of the task ID register is updated. This makes it possible to prevent other tasks from accessing the contents of the protected task's register set and memory information.</p><p> However, many high-performance processors are composed of a pipeline in which a plurality of instructions are executed in parallel at the same time. In the pipeline, there is a period in which instructions belonging to each task before and after interrupt / resume are mixed.</p><p> If the register is referenced or rewritten while the instructions are mixed, the register contents of the protection task cannot be controlled safely and appropriately. For example, if the register is switched immediately after the interrupt, the task before the interrupt may write to the register of the task after the interrupt.</p><p> Further, if the value of the task ID register is updated immediately after the interrupt, the task before the interrupt may perform cache access or memory access using the value of the task ID register after the interrupt. Further, by accessing the cache or memory using a different task ID, reading and writing are performed by a value encrypted / decrypted by a key different from the key corresponding to the task.</p><p> In addition, as a method of switching the register set corresponding to the task, the register rename function used to effectively utilize the instruction execution function in hyper-threading technology etc. is used, and the RAT is held for each task. There is a way to do it.</p><p> However, even if this technology is used, since there is only one task ID register, when the task before interrupt / restart and the task after interrupt / restart coexist, the value of the above task ID register and the interrupt / restart Inconsistency occurs in either the value of the task ID before or after interrupt / restart. As a result, there is a problem that it is not possible to control cache access or prevent memory access using different task ID registers.</p><p> The present invention has been made in view of the above, and an object of the present invention is to improve the security of information related to a task in a microprocessor that executes a task by a pipeline.</p>
<p> In order to solve the above-mentioned problems and achieve the object, the present invention is a microprocessor that executes a task by a pipeline method, and a plurality of units that execute the first task, and the microprocessor is the first. A task identification information register that holds the first task identification information that identifies one task, a task register that holds the first register information that the plurality of units use when executing the first task, and the above. If a switch command to the second task is issued while the instruction execution unit of the plurality of units is executing the first task, the unit already executing the first task is already entered. When the task completion detecting means for detecting that the execution of the first task has been completed and the task completion detecting means have detected that the execution of the first task has been completed, the task The task register management means for switching the register value to the second register information used when executing the second task, and the task when the task register management means switches to the second register information. The feature is that the value of the identification information register is switched to the second task identification information for identifying the second task, and the task management means for permitting each unit to execute the second task is provided. To do.</p><p> Further, the present invention is a microprocessor that executes a program by a pipeline, and recognizes a plurality of units that execute a task and task identification information that identifies the task that each unit is executing, and recognizes the corresponding unit. A task identification information register held in a possible format, and a task identification information that identifies the task identification information held by the task identification information register for the unit when a predetermined processing request is acquired from the unit. It is characterized by including a specific means and a control means for controlling a process related to the process request based on the task identification information specified by the task identification information specifying means.</p><p> Further, the present invention is a microprocessor that executes a program by a pipeline, and can recognize a plurality of units that execute a task and register information identification information that identifies a register set used by each unit. Register information identification information register held in various formats, and a register that specifies the register information identification information held by the register information identification information register for the unit when a predetermined processing request is acquired from the unit. The information identification information identifying means and the control means for controlling the processing related to the memory access processing request based on the register information identification information specified by the register information identification information identifying means are provided.</p>
<p> In the microprocessor according to the present invention, the task completion detecting means is when an instruction execution unit among a plurality of units issues a switching instruction to a second task while the instruction execution unit is executing the first task. It is detected that the execution of the first task already entered in the unit executing the first task has been completed, and the task register management means is such that the task completion detection means executes the first task. When it is detected that the task has been completed, the first register information used when executing the first task and the second register information used when executing the second task are obtained. The switching and task management means switch between the first task identification information and the second task identification information that identifies the second task after the task register management means switches to the second register information, and the task management means switches to each unit. On the other hand, since the execution of the second task is permitted, the first task and the second task are not entered in one of the units at the same time, and the predetermined task accesses the information used in the other task. This has the effect of improving the security of the information that the task should use.</p>
Hereinafter, embodiments of the microprocessor according to the present invention will be described in detail with reference to the drawings. The present invention is not limited to this embodiment.
(Embodiment 1) FIG. 1 is a diagram showing an overall configuration of the microprocessor of the first embodiment. FIG. 1 is a diagram showing the entire system according to the present embodiment. The processor 101 includes a processor core 111, a cache controller 121, a secure context switch unit 131, a bus interface unit (BIU) 141, and a task management unit 161.
BIU141 has a key table 142 and a cryptographic decryptor 143. BIU141 acquires the task ID and access type from the cache controller 121. Here, the task ID is identification information that identifies the task to be executed by the processor core 111. The access type is identification information that identifies whether the information to be accessed is a program or data.
FIG. 2 schematically shows the data structure of the key table 142. The key table 142 holds a program key, a data key, and a context key, which are encryption / decryption keys for encrypting / decrypting the program, data, and context, respectively, in association with the task ID.
BIU141 uses the key table 142 to select the encryption / decryption key from the task ID and access type acquired from the cache controller 121. Then, the selected encryption / decryption key is used to encrypt or decrypt the target program or data. Then, the decrypted instruction or data is output to the cache controller 121.
The cache controller 121 has an instruction cache 122 and a data cache 123. The cache controller 121 acquires an instruction or data via the BIU 141 in response to an instruction from the processor core 111.
The instruction cache 122 holds the plaintext instructions obtained from BIU141. FIG. 3 schematically shows the data structure of the instruction cache 122. The instruction cache 122 holds a task ID tag and an address tag in association with the instruction. The task ID tag is the identification information of the task related to the decryption of the instruction. The address tag is information indicating an address in which the instruction is stored. The instruction cache 122 also controls access to each instruction based on the address and task ID.
The data cache 123 holds the task ID corresponding to the plaintext data acquired from BIU141. The data structure of the data cache 123 is the same as the data structure of the instruction cache 122 described with reference to FIG. Data cache 123 also controls access to each piece of data based on address and task ID.
Return the description to Figure 1. The processor core 111 has a 5-stage pipeline 112, an instruction execution synchronization function 116, a current task ID register 114, and a register set 115.
The current task ID register 114 holds identification information of the task being executed in the 5-stage pipeline 112. The register set 115 holds information that should be used by the task being executed in the five-stage pipeline 112. Here, the current task ID register 114 corresponds to the task identification information register described in the claims. In addition, the register set 115 corresponds to the task register described in the claims.
The 5-stage pipeline 112 includes a program counter (PC) 1120, an instruction fetch unit (IFU) 1121, a decode unit (DEC) 1122, an execution unit (EXU) 1123, a memory access unit (MEM) 1124, and registers. It has a write unit (WBU) 1125. Further, the 5-stage pipeline 112 has an EXU switching flag register 1133, a MEM switching flag register 1134, and a WBU switching flag register 1135. The 5-stage pipeline 112 acquires an instruction from the cache controller 121 and executes the acquired instruction.
The program counter 1120 holds the address of the instruction fetch destination. The instruction fetch unit 1121 performs instruction fetch. The decoding unit 1122 decodes the instruction. Execution unit 1123 executes the instructions decoded by the decoding unit 1122. The memory access unit 1124 accesses the cache controller 121 to read and write data. The register write unit 1125 writes data to the register set 115.
The EXU switching flag register 1133, the MEM switching flag register 1134, and the WBU switching flag register 1135 are set with switching flags corresponding to the tasks executed by the units 1123, 1124, and 1125 in the pipeline, respectively. The switching flag takes two values, "0" and "1". The switching flag "1" indicates that it is the last instruction before switching when the task is switched.
For example, in the EXU switching flag register 1133, the switching flag "1" is set at the time of interrupt and at the time of task restart. Then, the contents of the switching flag set in the EXU switching flag register 1133 are transmitted to the MEM switching flag register 1134 and the WBU switching flag register 1135 in conjunction with the pipeline. That is, it can be determined whether or not the task before the interrupt is completed depending on whether or not the switching flag of the WBU switching flag register 1135 is "1".
FIG. 4 is a state transition diagram held by the instruction execution synchronization function 116. The instruction execution synchronization function 116 transitions between the IDLE state 411, the WAIT1 state 412, and the WAIT2 state 413. The instruction execution synchronization function 116 synchronizes each unit in each state.
When an interrupt is generated or a task restart instruction is issued, the instruction execution synchronization function 116 shifts from the IDLE state 411 to the WAIT1 state 412. In this case, the instruction fetch unit 1121 is requested to wait for the instruction fetch. That is, the reading of the task related to the interrupt or task restart instruction is prohibited.
Further, when the instruction execution synchronization function 116 receives the task execution completion notification, it shifts from the WAIT1 state 412 to the WAIT2 state 413. In this case, a register switching request is output to the secure context switch unit 131 in order to switch the value of the register set 115.
Further, when the instruction execution synchronization function 116 receives the task switching completion notification, the instruction execution synchronization function 116 shifts from the WAIT2 state 413 to the IDLE state 411. In this case, the instruction fetch wait request is stopped for the instruction fetch unit 1121. Then, the task management unit 161 sets the task ID of the switched task in the current task ID register 114.
The instruction execution synchronization function 116 and the WBU switching flag register 1135 according to the present embodiment correspond to the task completion detecting means described in the claims. That is, the instruction execution synchronization function 116 and the WBU switching flag register 1135 cooperate with each other to process the task completion detecting means described in the claims.
The secure context switch unit 131 has a context control unit 133 that controls between the context buffer 132 for holding the context and the register set 115. The context control unit 133 reads the register set 115 in the processor core 111 and holds it in the context buffer 132 in response to the register switching request of the instruction execution synchronization function 116. Also, the context corresponding to the task after interrupt / return is returned from the context buffer 132 to the register set 115 in the processor core 111. Here, the secure context switch unit 131 according to the present embodiment corresponds to the task register management means described in the claims.
The task management unit 161 manages the tasks executed by the processor core 111. The task management unit 161 sets the task ID in the current task ID register 114 when the switching of the register contents is completed. Here, the task management unit 161 according to the present embodiment corresponds to the task management means described in the claims.
Hereinafter, the processing of the processor 101 when interrupt processing occurs while the protection task 1 is being executed in the 5-stage pipeline 112 will be described.
FIG. 5 schematically shows how the 5-stage pipeline 112 is performing protection task 1. The left side of the figure shows the value of the program counter 1120, the value of the current task ID register 114, and the status of the instruction execution synchronization function 116 at each time.
First, the processor core 111 sets the state of the instruction execution synchronization function 116 to the IDLE state 411 in the initialization process. Next, when the execution of the protection task 1 is started, the task management unit 161 sets "1" in the current task ID register 114 and the start address in the program counter 1120. Here, the task ID "1" is a task ID that identifies the protection task 1.
At the time t1 shown in FIG. 3, the program counter 1120 is at the address E and the value of the current task ID register is 1. The instruction fetch unit 1121 refers to the value of the program counter 1120 and the current task ID register 114, and sends a read request for the instruction of the protection task 1 at the address E to the cache controller 121 (step S2111).
Further, the decoding unit 1122 decodes the instruction at the read address D (step S2112). Execution unit 1123 executes the instruction of protection task 1 corresponding to address C (step S2113). The memory access unit 1124 performs memory access by the instruction of protection task 1 corresponding to address B (step S2114).
The register write unit 1125 writes information to the register set 115 according to the instruction of the protection task 1 corresponding to the address A. In this way, when the processing of the register write unit 1125, which is the final unit of the pipeline, is completed, the execution of the protection task 1 corresponding to the address A is completed (step S2115).
At time t2, the program counter 1120 changes to address F. Then, the instruction fetch unit 1121 reads the instruction of the protection task at the address F (step S2121). The decoding unit 1122, the execution unit 1123, and the memory access unit 1124 are executed respectively, and each instruction moves to the next stage of the pipeline (step S2122 to step S2124). The register write unit 1125 completes the execution of the instruction of protection task 1 corresponding to address B (step S2125). Similarly, after time t3, each unit executes the task according to the value set in the program counter.
FIG. 6 schematically shows how the five-stage pipeline 112 executes a task when an interrupt occurs for some reason before the processing at time t3 described with reference to FIG. 5 starts. .. The protection task 1 that was executed before the interrupt is called the previous task. In addition, the task related to the interrupt is called a post-task.
In this case, the 5-stage pipeline 112 sets the start address X of the OS interrupt handler in the program counter 1120 at time t3. Then, the processor core 111 invalidates the instructions set in the instruction fetch unit 1121 and the decode unit 1122 (step S2231, step S2232).
Further, "1" is set in the EXU switching flag register 1133 corresponding to the execution unit 1123 (step S2233). The switching flag "1" indicates that it is the last instruction in the previous task. In addition, the switching flag "1" is linked with the pipeline and shifts to the memory access unit 1124 and the register write unit 1125.
Here, the processing of the 5-stage pipeline 112, the instruction execution synchronization function 116, the secure context switch unit 131, and the cache controller 121 when an interrupt occurs will be described. FIG. 7 is a flowchart showing the processing of the 5-stage pipeline 112, the instruction execution synchronization function 116, the secure context switch unit 131, and the cache controller 121 when an interrupt occurs.
When an interrupt occurs, the 5-stage pipeline 112 notifies the instruction execution synchronization function 116 of the occurrence of the interrupt (step S300). The instruction execution synchronization function 116 shifts from the IDLE state 411 to the WAIT1 state 412 according to FIG. 4 (step S302). Next, the instruction fetch unit 1121 is requested to wait for the instruction fetch (step S304). The instruction fetch wait request is made until the IDLE state 411 is returned.
At the same time as the notification of the occurrence of the interrupt, the task management unit 161 updates the program counter 1120, and the instruction fetch unit 1121 attempts to make an instruction fetch request to the subsequent task. However, since the 5-stage pipeline 112 has acquired the instruction fetch wait request of the instruction execution synchronization function 116 in step S304, it is in the instruction fetch waiting state.
Since the instruction fetch to the subsequent task cannot be fetched due to the instruction fetch wait request, the instruction fetch unit 1121 does not advance the program counter 1120 and fills the pipeline with a NULL instruction and remains in the pipeline at time t3 in FIG. Executes the instruction of the previous task (step S2231, step S2241, step S2251). Here, the NULL instruction is an instruction that does not affect the register or the memory even if it is executed.
In FIG. 7, when the previous task remaining in the 5-stage pipeline 112 is a datastore instruction, the memory write request for data D1 is sent to the cache controller 121 by designating the task ID 1 (step S310). The cache controller 121 returns an ACK to the processor core 111 when it writes data into the data cache 123 (step S312).
At time t5 in FIG. 6, the instruction corresponding to the switching flag 1 reaches the register write unit 1125. As a result, the execution of the previous task is completed, and the register set 115 can be switched (step S2251 to step S2255).
At this time, in FIG. 7, the 5-stage pipeline 112 sends a previous task execution completion notification to the instruction execution synchronization function 116 (step S320). The instruction execution synchronization function 116 shifts from the WAIT1 state 412 to the WAIT2 state 413 according to FIG. 4 (step S322). Then, a register switching request is sent to the secure context switch unit 131 (step S324).
The secure context switch unit 131 reads the value from the register set 115 and saves the register in the context buffer 132. Alternatively, it is encrypted and the register is saved in the external memory 102. Further, the context read and decrypted from the external memory 102 and the context read from the context buffer 132 are returned to the register set 115 (step S326).
When the register value switching is completed, the instruction execution synchronization function 116 is notified of the register switching completion (step S328). The instruction execution synchronization function 116 shifts from the WAIT2 state 413 to the IDLE state 411 according to FIG. 4 (step S330). Further, the instruction fetch wait request for the instruction fetch unit 1121 is stopped (step S332). At this time, the task management unit 161 sets "0" in the current task ID register 114. Here, the task ID "0" is the task ID of the task to be interrupted, that is, the task ID of the subsequent task.
As shown at time t6 in FIG. 6, the instruction fetch unit 1121 continues to set the NULL instruction while there is an instruction fetch wait request (step S2261 to step S2265). Then, when the switching completion notification is issued and the instruction fetch wait request disappears, the instruction fetch unit 1121 specifies the current task ID "0" and reads the instruction corresponding to the address X, as shown at time t7 in FIG. The request is sent to the instruction execution synchronization function 116 (step S2271 to step S2275).
When the instruction fetch unit 1121 outputs an instruction read request to the address X, as shown in FIG. 7, the instruction execution synchronization function 116 receives the instruction fetch request from the 5-stage pipeline 112 (step S340), and the instruction fetch request is sent to the cache controller 121. Send an instruction read request (step S342). If there is no instruction at the address X in the cache, the cache controller 121 reads the instruction from the external memory 102 via BIU141 in plain text and writes it to the cache. The cache controller 121 sends an instruction read from the cache into the processor core 511 (step S344). This completes the interrupt process.
In this way, the processor core 111 according to the present embodiment completes the execution of the pre-task already registered in the 5-stage pipeline 112 before the interrupt interrupt, and obtains the register information of the pre-task and the register information of the post-task. Wait for the instruction fetch of the later task until switching. This prevents register access from other tasks. In addition, the current task ID is switched at the same time when the register information switching is completed. As a result, cache access can be performed by the task ID corresponding to the task, so that access control by the cache controller 121 functions effectively. Therefore, the register information and memory area of the task to be protected can be protected from the OS and the task.
In addition, since all the processing such as switching the register value and the current task ID for the interrupt request is executed by the hardware, it is possible to prevent a third party from reading and writing the register information and the memory information via the OS. ..
The processing when an interrupt occurs has been described with reference to FIGS. 6 and 7, but the return processing when a task restart instruction is issued from an interrupt is the same as the processing described with reference to FIG. is there.
In the first embodiment, the case where the five-stage pipeline 112 has a five-stage pipeline has been described, but the number of stages of the pipeline is not limited to this, and may be more than five stages. , And at least good.
Further, in the first embodiment, the processor core 111 has one register set 115, but may have a plurality of register sets 115 instead. When having a plurality of register sets 115, the register value of the post-task after switching may be returned to another register set in advance, and the register set may be switched after the execution of the pre-task executed before switching is completed. .. This eliminates the need to save and restore registers during task switching. Therefore, the stall time due to saving and returning the register set can be reduced.
(Embodiment 2) Next, the processor 101 according to the second embodiment will be described. FIG. 8 is a block diagram showing a configuration of the processor core 511 according to the second embodiment.
The processor core 511 has a 5-stage pipeline 512, a first register set 5151, a second register set 5152, a register access control function 516, and a register set table 514.
The 5-stage pipeline 512 has a program counter 5120 that holds the address of the instruction fetch destination, an instruction fetch unit 5121, a decode unit 5122, an execution unit 5123, a memory access unit 5124, and a register write unit 5125. are doing. Further, each unit 5121 to 5125 has a task ID register 5131 to 5135. The task ID registers 5131 to 5135 hold identification information of the task executed by each unit 5121 to 5125.
Here, the task ID register according to the present embodiment corresponds to the task identification information register according to the claims. Further, the register access control function 516 according to the present embodiment corresponds to the task identification information identifying means and the control means described in the claims. Further, the cache controller 121 according to the present embodiment corresponds to the task identification information identifying means and the controlling means described in the claims.
Each unit 5121 to 5125 is connected to the register access control function 516 by buses 711 to 715, respectively. The instruction fetch unit 5121 and the memory access unit 5124 are connected to the cache controller 121 by buses 720 and 722, respectively.
The register set table 514 holds the task ID and the register ID in association with each other. Here, the register ID is identification information that identifies a register set. In the register set table 514 according to the present embodiment, the register ID 1 that identifies the first register set 5151 is associated with the task ID 0. In addition, the register ID "2" that identifies the second register set 5152 is associated with the task ID "1".
The register access control function 516 uses the register set table 514 to control access from each unit 5121 to 5125 to the first register set 5151 and the second register set 5152. Specifically, the access control function 516 receives an access request from each unit 5121 to 5125 of the 5-stage pipeline 512 to the first register set 5151 and the second register set 5152. Then, the task ID held in the task ID register of the unit requesting the access request is specified.
Further, in the register set table 514, the register ID associated with the task ID is specified. Then, access to the specified register ID is permitted from the access request source. In addition, access to a register set that is not associated with the register set table 514 is prohibited.
As a result, even when different tasks are executed in the plurality of units, it is possible to prohibit each task from accessing a register set other than the corresponding register set.
Hereinafter, the processing of the processor 101 when interrupt processing occurs while the protection task 1 is being executed in the 5-stage pipeline 512 will be described. Here, the task ID of the protection task 1, that is, the previous task is "1", and the task ID of the post-interrupt task is "0". The task after the interrupt is assumed to be a task by the OS.
FIG. 9 schematically shows how the processor core 511 is executing the first protection task. The value of the program counter 5120 at each time is shown on the left side of the figure.
The processor core 511 first registers the task ID "0" corresponding to the OS and plaintext and the register ID "1" that identifies the first register set 5151 in the register set table 514.
At the start of execution of the protected task, the task management unit 161 sets "1" in the task ID register 5131 of the instruction fetch unit 5121. Further, the task ID "1" and the register ID "2" that identifies the second register set 5152 are registered in the register set table 514.
At time 10 shown in FIG. 9, the instruction fetch unit 5121 refers to the value of the program counter 5120 and sends a read request for the instruction of the protection task 1 at the address E to the cache controller 121 (step S6111).
Hereinafter, the processing performed by each unit 5122 to 5125 in steps S6112 to S6115 is the same as the processing of each unit 1122 to 1125 at time t1 described with reference to FIG. 5 in the first embodiment.
In step S6111, the instruction fetch unit 5121 uses the address E and the task ID "1" of the protection task 1 held by the task ID register 5131 of the instruction fetch unit 5121 to the cache controller 121 when executing the protection task 1. Request an instruction fetch.
The cache controller 121 acquires an instruction corresponding to the address E and the task ID "1" from the instruction cache 122 or the external memory 102. Then, the acquired instruction is sent to the processor core 511 (step S6111, step S6121).
The read instruction and the task ID are synchronized on the pipeline. For example, the instruction read from the instruction cache 122 is held in the instruction fetch unit 5121, and the task ID corresponding to the instruction is held in the task ID register 5131 of the instruction fetch unit 5121. Then, when the instruction is transferred to the decoding unit 5122, the task ID corresponding to the instruction is also transferred to the task ID register 5132 of the decoding unit 5122.
When each unit 5121 to 5125 accesses the register set 5151, 5152, an access request is made to the register access control function 516 using the value of the task ID registers 5131 to 5135 of each unit 5121 to 5125.
The register access control function 516 selects the corresponding register set from the register set table 514 and the task ID. That is, the first register set 5151 or the second register set 5152 is selected. Then, the register access control function 516 makes an access request to the selected register set 5151, 5152.
Specifically, for example, at time t10, the register access control function 516 makes an access request to the register set 5151 or 5152 according to the value of the task ID register 5132 in the decoding unit in response to the access request from the decoding unit 5122. Do (step S6112). Further, the register access control function 516 makes an access request to the register set 5151 or 5152 according to the value of the task ID register 5135 in the register write unit in response to the access request from the register write unit 5125 (step S6115).
In this way, each unit 5121 to 5125 of the 5-stage pipeline 512 accesses the register access control function 516 using the values of the task ID registers 5131 to 5135, respectively. Therefore, even if register access occurs from different tasks at the same time when different tasks exist in the 5-stage pipeline 512, the register set 5151, 5152 corresponding to each task can be accessed. Therefore, it is possible to prevent each task from accessing a register set that is not allowed access.
When each unit 5121 to 5125 accesses the cache controller 121, the value of the task ID registers 5131 to 5135 of each unit 5121 to 5125 is notified and an access request is made.
Specifically, for example, at time t10, the memory access unit 5124 notifies the task ID 1 in the memory access unit and makes an access request to the cache controller 121 (step S6114). In this way, each unit 5121 to 5125 of the 5-stage pipeline 512 accesses the cache memory using the values of the task ID registers 5131 to 5135, respectively. Therefore, even if memory access occurs from different tasks at the same time when different tasks exist in the 5-stage pipeline 512, the cache controller 121 should control access using the task identifier corresponding to each task. Can be done. Therefore, it is possible to prevent each task from accessing the plaintext data in the cache memory that is not permitted to be accessed.
As described above, while the protection task 1 is being executed, the task ID registers 5131 to 5135 of each unit 5121 to 5125 hold the task ID "1" of the protection task 1. Then, access to the first register set 5151 associated with the task ID "1" in the register set table 514 is permitted.
Further, the instruction fetch unit 5121 and the memory access unit 5124 specify the task ID "1" to perform memory access. For example, at time t10, the instruction fetch unit 5121 requests the cache controller 121 via the bus 720 to read data at the address E by designating the task ID 1 (step S6111).
Further, the memory access unit 5124 specifies the task ID 1 to the cache controller 121 via the bus 722 and makes an access request for the address B (step S6114).
In either case, when the task ID "1" is associated with the address indicated by the access request in the cache controller 121, the corresponding data is read out. If the specified task ID is not associated with the address indicated by the access request, access to such data is prohibited. In this way, access to data from each unit is restricted based on the task ID.
FIG. 10 schematically shows how the five-stage pipeline 112 executes a task when an interrupt occurs for some reason before the processing at time t12 described with reference to FIG. 9 starts. .. At this time, the 5-stage pipeline 512 invalidates the instructions of the instruction fetch unit 5121 and the decode unit 5122 (step S6231 and step S6232). Further, the task management unit 161 sets the task ID 0 in the task ID register 5131 of the instruction fetch unit 5121.
FIG. 11 is a flowchart showing a process when the decoding unit 5122 makes a read request to the register to the register access control function 516 in step S6252 of FIG. In this case, the instruction of the OS task is executed in the decoding unit 5122, and the task ID register 5132 in the unit is set to "0". Therefore, the decoding unit 5122 sends a register access request to the register access control function 516 by designating the task ID "0" via the bus 712 (step S700).
When the register access control function 516 acquires the register access request, the register access control function 516 identifies the register corresponding to the task ID "0" included in the register access request in the register set table 514. That is, the first register set 5151 is selected. Then, a read request is made to the first register set 5151 (step S702). When the register access control function 516 acquires the register information from the first register set 5151 (step S704), the register access control function 516 sends the register information to the decoding unit 5122 (step S706).
FIG. 12 is a flowchart showing a process when the register write unit 5125 makes a write request to the register to the register access control function 516 in step S6245 at the time t13 of FIG. At this time, the instruction of protection task 1 is executed in the register writing unit 5125, and the task ID register 5135 in that unit is set to "1". The register write unit 5125 sends a register access request for which the task ID "1" set in the task ID register 5135 of the register write unit 5125 is specified to the register access control function 516 via the bus 715 (step S710).
When the register access control function 516 acquires the register access request, the register access control function 516 identifies the register set corresponding to the task ID "1" included in the register access request in the register set table 514. That is, the second register set 5152 is selected. Then, a write request is made to the second register set 5152 (step S712).
When the writing is completed, the second register set 5152 sends a completion notification to the register access control function 516 (step S714). The register access control function 516 sends a completion notification to the second register set 5152 (step S716). In this way, since the decoding unit 5122 holds the task ID 0, it is possible to access the first register set 5151 associated with the task ID 0 in the register set table 514. However, the second register set 5152 cannot be accessed. Further, since the register writing unit 5125 holds the task ID "1", it is possible to access the second register set 5152 associated with the task ID "1" in the register set table. However, the first register set 5151 cannot be accessed. In this way, access from each unit to the first register set 5151 and the second register set 5152 is controlled by the value of the task ID held in the task ID register of each unit, so that other tasks can use the register information. It can be prevented from accessing.
FIG. 13 is a flowchart showing a process when the instruction fetch unit 5121 performs instruction fetch in step S6241 at time t13 in FIG. At this time, the instruction fetch unit 5121 is executing the instruction of the OS task, and the task ID register 5131 in that unit is set to "0". The instruction fetch unit 5121 makes an access request to the address Y by designating the task ID "0" to the cache controller 121 via the bus 720 (step S720).
When the cache controller 121 acquires the access request, the cache controller 121 searches the instruction cache 122 for the instruction requested to be accessed. If the instruction corresponding to the address Y and task ID "0" is not held in the instruction cache 122 (step S722, No), specify the address Y and task ID "0" for BIU141 and request memory access. (Step S724).
BIU141 sends a read request for the instruction corresponding to address Y to the external memory 102 (step S726). Then, BIU141 acquires an instruction from the external memory 102 (step S728) and sends it to the cache controller 121 (step S730).
In the present embodiment, the instruction corresponding to the task ID "0" in the key table 142 is held in the external memory 102 as an unencrypted plaintext instruction, and therefore is not decrypted by the encryption / decryptor 143. To the cache controller 121. When the instruction corresponding to the task ID is held in the external memory 102 in an encrypted state, the encryption / decryptor 143 decrypts the instruction and sends it to the cache controller 121 as a plaintext instruction.
The cache controller 121 writes the instruction acquired from BIU141 to the instruction cache 122 (step S732). Further, the cache controller 121 sends the instruction read from the instruction cache 122 to the processor core 511 (step S734).
If the instruction requested to be accessed is held in the instruction cache 122 in step S722 (step S722, Yes), the process proceeds to step S734.
FIG. 14 is a flowchart showing a process when the memory access unit 5124 makes a memory access in step S6244 at the time t13 of FIG. At this time, the instruction of protection task 1 is executed in the memory access unit 5124, and the task ID register 5134 in that unit is set to "1". The memory access unit 5124 requests the cache controller 121 via the bus 722 to access data to the address P by designating the task ID 1 (step S740).
When the cache controller 121 acquires the access request, the cache controller 121 searches the data cache 123 for the requested data. If there is no instruction corresponding to address P and task ID "1" in the data cache 123 (step S742, No), specify address P and task ID "1" for BIU141 and make a memory access request (step S742, No). Step S744).
BIU141 sends a read request for data corresponding to address P to the external memory 102 (step S746). Then, BIU141 acquires the data E [DATA (P)] corresponding to the address P from the external memory 102 (step S748). BIU141 selects the key corresponding to task ID "1" from the key table 142.
Then, the data E [DATA (P)] read by the encryption / decryptor 143 is decrypted to obtain the plaintext data DATA (P) (step S750). BIU141 sends the plaintext data to the cache controller 121 (step S752).
The cache controller 121 writes the plaintext data acquired from BIU141 to the data cache 123 (step S754). In addition, plaintext data is sent to processor core 511 (step S756).
On the other hand, in step S742, if the data requested to be accessed is held in the data cache 123 (step S742, Yes), the process proceeds to step S756. This completes the process in step S6244 at time t13 in FIG.
Since the instruction fetch unit 5121 holds the task ID "0" in this way, the cache memory 121 is accessed using the task ID "0". Further, since the memory access unit 5124 holds the task ID "1", the cache memory 121 is accessed using the task ID "1". Since the cache memory 121 controls access to plaintext instructions and data by the value of the task ID, it is possible to prevent access to plaintext instructions and data from other tasks. Further, in the present embodiment, the execution of the post-interrupt task can be started before the pre-task already registered in the 5-stage pipeline 512 is completed before the interrupt. Therefore, the responsiveness can be improved. In addition, the throughput can be improved.
In the second embodiment, the task ID register of each unit holds the task ID of the task executed by each unit, but instead of this, the access destination of the task executed by each unit The register ID may be retained. In this case, in order to specify the task ID at the time of memory access, it is necessary to keep the task ID correspondence table of the register ID and the task ID. Then, the task ID is selected from the register ID of each unit and the task ID correspondence table to access the memory. In this case as well, access to registers and memory from each unit can be controlled in the same manner.
Although the present invention has been described above using the embodiments, various changes or improvements can be made to the embodiments.
<figref num="1">It is a figure which shows the whole structure of the microprocessor of Embodiment 1.</figref><figref num="2">It is a figure which shows typically the data structure of the key table 142.</figref><figref num="3">It is a figure which shows typically the data structure of the instruction cache 122.</figref><figref num="4">It is a state transition diagram held by the instruction execution synchronization function 116.</figref><figref num="5">It is a figure which shows typically how the 5-stage pipeline 112 executes the 1st protection task.</figref><figref num="6">It is a figure which shows typically how the 5-stage pipeline 112 executes a task when an interrupt occurs for some reason before the processing at time t3 explained with reference to FIG. 5 starts.</figref><figref num="7">It is a flowchart which shows the process of the 5-stage pipeline 112, the instruction execution synchronization function 116, the secure context switch part 131, and the cache controller 121 when an interrupt occurs.</figref><figref num="8">It is a block diagram which shows the structure of the processor core 511 which concerns on Embodiment 2. FIG.</figref><figref num="9">It is a figure which shows typically how the processor core 511 is executing the 1st protection task.</figref><figref num="10">It is a figure which shows typically how the 5-stage pipeline 112 executes a task when an interrupt occurs for some reason before the processing at time t12 explained with reference to FIG. 9 starts.</figref><figref num="11">It is a flowchart which shows the process when the decoding unit 5122 makes a read request to a register to a register access control function 516 in step S6252 of FIG.</figref><figref num="12">FIG. 5 is a flowchart showing a process when the register write unit 5125 makes a write request to the register to the register access control function 516 in step S6245 at time t13 in FIG.</figref><figref num="13">It is a flowchart which shows the process when the instruction fetch unit 5121 performs instruction fetch in step S6241 at time t13 of FIG.</figref><figref num="14">It is a flowchart which shows the process when the memory access unit 5124 performs the memory access in step S6244 at the time t13 of FIG.</figref>
Code description
101 Processor 102 External memory 111,511 Processor core 112,512 5-stage pipeline 114 Current task ID register 115 Register set 116 Instruction execution synchronization function 121 Cache controller 122 Instruction cache 123 Data cache 131 Secure context switch unit 132 Context buffer 133 Context control unit 142 Key table 143 Cryptographic decryptor 161 Task management 514 Register set table 516 Register access control function 1120,5120 Program counter 1121,5121 Instruction fetch unit 1122,5122 Decoding unit 1123,5123 Execution unit 1124,5124 Memory access unit 1125,5125 Register write Unit 1133 EXU switching flag register 1134 MEM switching flag register 1135 WBU switching flag register 5131 to 5135 Task ID register 5151 1st register set 5152 2nd register set
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JPWO2008087779A1 | Cited by | Japan | Examiner |
| US8848532B2 | Cited by | United States of America | Applicant |
| WO2008087779A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN101840328A | Cited by | China | Search report |
8 members in 3 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004200366 | Japan | A | |
| JP20040200366 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| CN1719375A | China | A | |
| US2006010308A1 | United States of America | A1 | |
| JP2006023902AThis record | Japan | A | |
| CN100368954C | China | C | |
| JP4204522B2 | Japan | B2 | |
| US7853954B2 | United States of America | B2 | |
| US2011107336A1 | United States of America | A1 | |
| US8499306B2 | United States of America | B2 |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 2006023902
- Publication, DOCDB
- 2006023902
- Publication, EPODOC
- JP2006023902
- Application
- 200366
- Application, DOCDB
- 2004200366
- Application, EPODOC
- JP20040200366
Titles2
- Japanese
- マイクロプロセッサ
- English
- Microprocessor
Classification
- CPC, 4
- G06F9/3851
- G06F9/3009
- G06F9/30123
- G06F9/485
- IPC, 7
- G06F9 46
- G06F9 34
- G06F9 38
- G06F12 08
- G06F12 14
- G06F21 24
- G06F21 62