JPH04199341A - Memory access protective device - Google Patents

Memory access protective device

Info

Publication number
JPH04199341A
JPH04199341A JP2332645A JP33264590A JPH04199341A JP H04199341 A JPH04199341 A JP H04199341A JP 2332645 A JP2332645 A JP 2332645A JP 33264590 A JP33264590 A JP 33264590A JP H04199341 A JPH04199341 A JP H04199341A
Authority
JP
Japan
Prior art keywords
access
memory
memory access
address
management table
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
JP2332645A
Other languages
Japanese (ja)
Inventor
Satoshi Hakomori
箱守 聰
Hideo Taniguchi
秀夫 谷口
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
N T T DATA TSUSHIN KK
NTT Data Group Corp
Original Assignee
N T T DATA TSUSHIN KK
NTT Data Communications Systems Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by N T T DATA TSUSHIN KK, NTT Data Communications Systems Corp filed Critical N T T DATA TSUSHIN KK
Priority to JP2332645A priority Critical patent/JPH04199341A/en
Publication of JPH04199341A publication Critical patent/JPH04199341A/en
Pending legal-status Critical Current

Links

Landscapes

  • Storage Device Security (AREA)

Abstract

PURPOSE:To perform memory access protection between mutual processes by limiting an accessible area with the process in address space. CONSTITUTION:An access right management table 3 storing a memory access key corresponding to the address and an access key register 4 holding the memory access key of the current process are provided. An access right decision circuit 2 deciding the accessibility of the address required from a processor 1 with the use of the contents of the access right management table 3 and the access key register 4 is provided. The access space is divided into individually accessible areas for each process, and the accessibility of the process issuing the request against the memory content at the time of issuing memory access request is decided. Thus, the memory access protection is performed between mutual processes at the time of travelling plural processes in one address space.

Description

【発明の詳細な説明】[Detailed description of the invention]

〔産業上の利用分野〕 本発明は、プロセラ勺およびメモリを有する電子計1′
機(コンビコータ)において、オペレーティングシステ
ムが制御の基本四位とするプロセスがメモリにアクセス
する際のアクセス保護を行なう制御部t4−関するもの
である。 〔もY−来技術] 従来、メモリアクセス保護制御の枝体は、メモリ空間を
ページあるい1」セグメンl−を中位どじで管理し、メ
モリアクセス要求が発行されると、)′クセスする71
ヘレスな含む領域毎に設定さ才またアクセス情報p1?
理テーブルを参照することにより、アクセスの可否を判
定している。このどき、アクセス情報管理テーブルは、
読み出り、 tj、るいは書き込ツノ番コ関するii工
否情報しか持っていないため、メモリアクセス時の保護
は、読み出しあるいは書き込ツノについてのみしか?)
なオ〕れない。すなわち、メモリアクセス要求を発行
[Industrial Application Field] The present invention relates to an electronic meter 1' having a processor and a memory.
The present invention relates to a control unit t4 which protects access when a process, which is one of the four basic control points of an operating system, accesses memory in a combination coater. [MoY-Next Technology] Conventionally, a branch of memory access protection control manages the memory space in pages or 1" segment l- in the middle level, and when a memory access request is issued, the memory access is accessed. 71
Access information p1 set for each area including Jerez?
Access is determined by referring to the management table. These days, the access information management table is
Since it only has the success/failure information related to the read, tj, or write corner number, is the protection during memory access limited to the read or write corner? )
I can't. In other words, issuing a memory access request


7たプロセスをf:r!iぜず、アクセス要求がとのプ
[lセスから発行されたかの′iJi定夕行なオ]ない
。 〔発明が解決しようとする課題〕 従−)で、従来の技術では、プロセスの切り換え処理を
高速に行なうために1一つのアドレス空間に各プロセス
のデータ部やスタック部を複数配置した場合、互いに固
有なデータ部やスタック部を保護できないという問題が
あった。 本発明は、前記問題点を解決するためになされたもので
ある。 本発明の目的は、1つのアドレス空間内で複数のプロセ
スを走行させる際、従来の技術では不可能であったプロ
セス間相互のメモリアクセス保護を実現することが可能
な技術を提供することにある。 本発明の前記ならびにその他の目的と新規な特徴は1本
明細書の記述及び添付図面によって明らかになるであろ
う。 〔課題を解決するための手段〕 前記目的を達成するために、本発明は、プロセッサおよ
びメモリを有する電子計算機における、プロセッサとメ
モリの間でメモリアクセス保護制御を行なうメモリアク
セス保護装置であって、アドレスに対応してメモリアク
セスキーを格納しているアクセス権管理テーブルと、現
在走行しているプロセスのメモリアクセスキーを保持す
るアクセスキーレジスタと、アクセス管理テーブルとア
クセスキーレジスタの内容を利用してプロセッサから要
求されたアドレスがアクセス可能であるかを判定するア
クセス権判定回路とを備えたことを最も主要な特徴とす
る。 〔作 用〕 前述した手段によれば、71〜レス空間を、各プロセス
で個別にアクセス可能な領域に分け、メモリアクセス要
求が発行さ九た際に、要求を発行したプロセスがそのア
ドレスに示されるメモリ内容に対してアクセス可能であ
るかどうかを判定するので、1つのアドレス空間内で複
数のプロセスを走行させる際、従来の技術では不可能で
あったプロセス間相互のメモリアクセス保護を実現する
ことができる。従来技術とは、71〜レス空間内で。 プロセス毎にアクセスできる領域を限定する点が異なる
。 〔発明の実施例〕 以下、本発明の一実施例を図面を用いて具体的に説明す
る。 なお、実施例を説明するための全図において、同一機能
を有するものは同一符号を付け、その繰り返しの説明は
省略する。 第1図は、本発明゛の一実施例の概略構成を示すブロッ
ク図であり、1はプロセッサ(c p U)、2はアク
セス権判定回路、3はアクセス権管理テーブル、4はア
クセスキーレジスタ、5はメモリ、6は表示装置である
、 前記アクセス権管理テーブル3は、アドレスで示される
メモリ内容にアクセス可能なプロセスを示すメモリアク
セスキーを格納するものである。 前記アクセスキーレジスタ4は、現在走行するプロセス
のメモリアクセスキーを保持するものである。 第2図は、アクセス権判定回路2の構成を示すブロック
図である。 第2図において、11はアドレス送出回路であり、プロ
セッサ(CPU)1からのアクセス要求アドレスが入力
され、アドレスを送出するものである。 12はメモリアクセスキー抽出回路であり、前記アクセ
ス要求アドレスからアドレスに対応したメモリアクセス
キーを抽出して、それをメモリアクセスキー比較口g1
3へ送出するものである。 メモリアクセスキー比較回路コ3は、前記メモリアクセ
スキー抽出回路12から入力されたメモリアクセスキー
とアクセスキーレジスタ4から入力された現在走行中の
プロセスが持つメモリアクセスキー(メモリ5の中に内
蔵されていたもの)とを比較して許可信号又は不許可信
号を出力し、それを前記アドレス送出回路11及びプロ
セッサ(CPU)]に送出するものである。 前記アクセスキーレジスタ4に設定される現在走行中の
プロセスが持つメモリアクセスキーは、プロセッサが走
行を開始する時にプロセッサ(CPU)1に設定される
。 第3図は、ページテーブルを例としたアクセス情報管理
テーブルの内容を示す図であり、実アドレスとnビット
からなる属性からなっている。このうち】″クセス保護
に関係する属性はR/WおよびS/l+データである。 R,/ W +:jその領域に書き込みi”i1能かど
うかを示すデータであり、例えば、○/l、」10.O
lo、、i/lで表わされる。 S / t、Jは:1−ザモー1へのどきアクセス可能
■能かどうかを示すデータであり、例えば、1のときは
ニー ザモ−1・でアクセス可能、Oのときはユーザモ
ー何で7クセ人不iiJ能と表わさ才しる。 第・1図は、前記】′クセ人権管理テーブル3の内容を
示す図であり、従来の属性とmピノ[・のメモリア9セ
スギ・−からなっている。 次に、本実施例の動作について説明する。 第5図は、本実施例の処理動作を説明するたぬの処理)
1“1〜ヂヤー 1へである。 本実施例のメモリアクセス保護装置は、第5図に示1よ
うに、プロセッサ1がアクセスし、たいアト1ノスをア
クセス権判定回路21ニー送る(10丁)。 アク十り人権判定回g2ば、よす送られたア1へレスを
もとにアクセス権管理デープル3を参照し、ア1<’ 
L=スに対応し7たメモリアクレスキーを取得Jる(1
02)、、次に、取得したメモリアクセスキーを7クセ
スキーレジスタ4の内容と比較し2、現在走行L4いる
プロセスに対しでアクセスが許可されて−いるかどうか
の判定を?−iなう(103)。アクセスがシ乍町され
ていると判定した(前房の)場合(,1,2y トレス
をメモり5に送る( 1.04. )。メモリ5は、ア
1ヘレスし示されるメモリの内容をブI」ゼノサ1に送
る( 10 iT、 )。アクセスが許可されでいろ・
いと判定した(不許可の)場合は、ア1−Iノスをメモ
リ5へ送出せず、プロセッサ1に対し、不Y1アクセス
要求であることを通知する(106)。 以ヒの4(2明かられかるように、本実施例(こよれば
、ア!・lノス空間を、各プロセスで個)11Jにアク
セス可能な領域にづ)(−す、メモリアクセス要求が発
行された際に、要求に発行したブ「]セスがそのア[・
レスに示されるメモり13の内容に対してアクセス可能
J能でj))るかどうかを判定するので、]つのアアク
セス可能で複数のブし」セスを走行させる際、従来の技
術では不可能であったブI−1セス間相互のメモリアク
セス保護を実現することができる。 以)、本発明を実施例【−もど−づき71L体的に説明
L7たが、本発明は、曲屈実施例に限定されるものC′
は!4′:<、その要旨に逸脱し2ない範囲1: !;
いて種J(、を変更i”i、T f炬て:、i;ること
はiRうまでもない1゜〔発明の効果〕 以し、説明[7,たよ)に、本発明に−よれば、ア]・
1、・ス空間内7?プ1−1セスによりアク1ノスii
7能な領域を限定するノーめ、ブIコセスを意識せずア
I−L−ス空間内で 様に゛?タセス+i’、f能とす
る場合にltノ\、1つのアドレス空間内に複数のブ[
lセス5・配置−4イ)K(にプロセス間相互C′メモ
リアクセス保護を行ろ−)二とかで・きる、1
[
f:r! There is no access request issued from the same process. [Problems to be Solved by the Invention] In the conventional technology, when multiple data parts and stack parts of each process are placed in one address space in order to perform process switching at high speed, they are not connected to each other. There was a problem that the unique data section and stack section could not be protected. The present invention has been made to solve the above problems. An object of the present invention is to provide a technology that can realize mutual memory access protection between processes, which was impossible with conventional technology, when multiple processes run within one address space. . The above and other objects and novel features of the present invention will become apparent from the description of this specification and the accompanying drawings. [Means for Solving the Problems] In order to achieve the above object, the present invention provides a memory access protection device that performs memory access protection control between a processor and a memory in an electronic computer having a processor and a memory, comprising: An access right management table that stores memory access keys corresponding to addresses, an access key register that stores the memory access keys of currently running processes, and the contents of the access management table and access key register are used. The most important feature is that it includes an access right determination circuit that determines whether an address requested by a processor can be accessed. [Operation] According to the above-mentioned means, the 71~res space is divided into areas that can be accessed individually by each process, and when a memory access request is issued, the process that issued the request accesses the address indicated by the address. Since it determines whether or not the memory contents can be accessed, when multiple processes are running within one address space, it is possible to protect mutual memory access between processes, which was impossible with conventional technology. be able to. The conventional technology is within the 71~res space. The difference is that the areas that each process can access are limited. [Embodiment of the Invention] An embodiment of the present invention will be specifically described below with reference to the drawings. In addition, in all the figures for explaining the embodiment, parts having the same functions are given the same reference numerals, and repeated explanations thereof will be omitted. FIG. 1 is a block diagram showing a schematic configuration of an embodiment of the present invention, in which 1 is a processor (CPU), 2 is an access right determination circuit, 3 is an access right management table, and 4 is an access key register. , 5 is a memory, and 6 is a display device. The access right management table 3 stores memory access keys indicating processes that can access the memory contents indicated by the address. The access key register 4 holds the memory access key of the currently running process. FIG. 2 is a block diagram showing the configuration of the access right determination circuit 2. As shown in FIG. In FIG. 2, 11 is an address sending circuit, which receives an access request address from the processor (CPU) 1 and sends out the address. Reference numeral 12 denotes a memory access key extraction circuit, which extracts a memory access key corresponding to the address from the access request address and applies it to the memory access key comparison port g1.
3. The memory access key comparison circuit 3 compares the memory access key inputted from the memory access key extraction circuit 12 with the memory access key (built in the memory 5) held by the currently running process inputted from the access key register 4. The address sending circuit 11 and the processor (CPU) output a permission signal or a non-permission signal by comparing the data with the previous address (which had previously been issued). The memory access key held by the currently running process, which is set in the access key register 4, is set in the processor (CPU) 1 when the processor starts running. FIG. 3 is a diagram showing the contents of an access information management table taking a page table as an example, and consists of a real address and an attribute consisting of n bits. Among these, the attributes related to access protection are R/W and S/l+ data. ,”10. O
It is expressed as lo,,i/l. S/t, J are data indicating whether or not it is possible to access 1-zamo-1 at any time.For example, if it is 1, it can be accessed from knee-zamo-1, and when it is O, it is possible to access 7 quirks in user mode. He is known for his talent. FIG. 1 is a diagram showing the contents of the habitual human rights management table 3, which is composed of conventional attributes and memoria 9 of m pino [. Next, the operation of this embodiment will be explained. Fig. 5 is a tanu process explaining the processing operation of this embodiment)
The memory access protection device of this embodiment, as shown in FIG. ).If human rights judgment time G2 is sent, refer to access rights management table 3 based on the reply sent to A1, and find A1<'
Obtain the memory access key corresponding to L=S (1
02) Next, compare the obtained memory access key with the contents of the 7 access key register 4 and determine whether access is permitted to the currently running process L4? -i Now (103). If it is determined that the access has been accessed (in the anterior chamber) (, 1, 2y), send the trace to memory 5 (1.04.). Send it to Zenosa 1 (10 iT, ). Access is not allowed.
If it is determined that the Y1 access request is not allowed (disallowed), the A1-Inos is not sent to the memory 5, and the processor 1 is notified that it is an invalid Y1 access request (106). 4(2) As can be seen, in this embodiment (according to this example, each process has an area that can be accessed by each process) (-), memory access request When the request was issued, Seth who issued the request
Since the content of the memory 13 indicated in the response is determined whether it is accessible or not, it is difficult to use the conventional technology when running a multiple memory access. Mutual memory access protection between the bus I-1 processes, which was previously possible, can be realized. Hereinafter, the present invention will be described in detail with reference to Examples C'.
teeth! 4':<, Range 1: ! that does not deviate from the gist. ;
Therefore, according to the present invention, according to the explanation [7. ,a]·
1. 7 in space? Ac1 Nos II by Pu1-1 Seth
7. Don't limit the area where you can function, do you do something like that in the space space without being aware of your own personality? If the address space + i', f function is used, multiple block [
l process 5/placement-4 a) K (protect mutual C' memory access between processes-) 2, etc., 1

【図面の簡単な説明】[Brief explanation of the drawing]

第+−i図は、本発明の 実施例の概酩構成を示・1−
ブUUツク図、 第2図N’A−2本実施例σ)アう゛セス柊判定回路:
ぞパフ)構成を小すブロックM、 第3[Y]は、ページテーブルを例としたアクセ!、情
報管列(T・−プルの内容に示J−図、第=q [51
1+t、本実施例のj′シセス権管J!I]j−−−プ
ルの内容を夙す図、 第5図は、本実施例の処理動作を説明するだめの処理フ
ローを示した図である。 図中、l ゾロセラ1す、27′クセス権判定回路、r
3  アクセス権管理デープル、・1 アクセスキーL
’:/ノ、ツノ、:3 メモり、に 表示V、λ置1゜
代、[111人 弁理1 秋[1!収喜第1図 L−、−−、、、、、、、、、、、−、、、、、−−−
一、、−−−−=−−−−一−−−コ第2図 7.1) \ 第3図 第4図 第5図
Figures +-i show the general configuration of the embodiment of the present invention.
Block diagram, Figure 2 N'A-2 Example σ) Access judgment circuit:
Puff) Block M to reduce the configuration, 3rd [Y] is an access page table example! , information tube array (T-pull contents shown in J-figure, number = q [51
1+t, j′ ccess rights control J! of this embodiment! FIG. 5 is a diagram showing a processing flow for explaining the processing operation of this embodiment. In the figure, l Zorocera 1, 27' access right determination circuit, r
3 Access rights management table, 1 Access key L
':/ノ, horn, :3 Memorize, display V, λ position 1゜ generation, [111 people patent attorney 1 fall [1! Figure 1 L-, ---,,,,,,,,,,-,,,,,,--
1,, ----=-----1----Co Fig. 2 7.1) \ Fig. 3 Fig. 4 Fig. 5

Claims (1)

【特許請求の範囲】[Claims] (1)プロセッサおよびメモリを有する電子計算機にお
ける、プロセッサとメモリの間でメモリアクセス保護制
御を行なうメモリアクセス保護装置であって、アドレス
に対応してメモリアクセスキーを格納しているアクセス
権管理テーブルと、現在走行しているプロセスのメモリ
アクセスキーを保持するアクセスキーレジスタと、アク
セス権管理テーブルとアクセスキーレジスタの内容を利
用してプロセッサから要求されたアドレスがアクセス可
能であるかを判定するアクセス権判定回路とを備えたこ
とを特徴とするメモリアクセス保護装置。
(1) A memory access protection device that performs memory access protection control between the processor and memory in an electronic computer having a processor and memory, which includes an access right management table that stores memory access keys corresponding to addresses. , an access key register that holds the memory access key of the currently running process, and an access right that uses the access right management table and the contents of the access key register to determine whether the address requested by the processor can be accessed. A memory access protection device comprising: a determination circuit.
JP2332645A 1990-11-29 1990-11-29 Memory access protective device Pending JPH04199341A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
JP2332645A JPH04199341A (en) 1990-11-29 1990-11-29 Memory access protective device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
JP2332645A JPH04199341A (en) 1990-11-29 1990-11-29 Memory access protective device

Publications (1)

Publication Number Publication Date
JPH04199341A true JPH04199341A (en) 1992-07-20

Family

ID=18257275

Family Applications (1)

Application Number Title Priority Date Filing Date
JP2332645A Pending JPH04199341A (en) 1990-11-29 1990-11-29 Memory access protective device

Country Status (1)

Country Link
JP (1) JPH04199341A (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2009042971A (en) * 2007-08-08 2009-02-26 Panasonic Corp Real-time watch apparatus and method

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2009042971A (en) * 2007-08-08 2009-02-26 Panasonic Corp Real-time watch apparatus and method

Similar Documents

Publication Publication Date Title
AU623146B2 (en) Direct input/output in a virtual memory system
JP4295111B2 (en) Memory management system and memory access security grant method based on linear address
EP0979456B1 (en) Memory access protection
JP2003330799A (en) Using limits on address translation to control access to addressable entity
WO2003083672A1 (en) System and method providing region-granular, hardware-controlled memory encryption
JPH05257811A (en) Memory controller
JPS6184755A (en) Data processing system
JPH04199341A (en) Memory access protective device
JPS63240657A (en) Memory protecting device
JP2843329B2 (en) Bank switching device
JPS61195442A (en) Memory protection device
JPH0534042Y2 (en)
JPH0752423B2 (en) Data transfer control method
JP3070056B2 (en) Information processing device
JPS60129860A (en) Detection system for addressing exception
JPS6054691B2 (en) Memory protection method for information processing equipment
JPH04326437A (en) Information processor
JPH02285441A (en) Cache controller
JPS6371749A (en) Memory protecting system
JPH01140255A (en) Memory protecting method
JPH02116939A (en) Address selecting system
JPH04199245A (en) System for controlling main storage key
JPS59208662A (en) Circuit expanding number of addresses of read-only memory
JPS62212852A (en) Storage protecting system
JPH0480845A (en) Integrated circuit device with built-in read/write enable rom