scieee Science in your language
[en] (orig)

HSP-V: hypervisor-less static partitioning for RISC-V COTS platforms

Abstract

Virtualization technologies have played a pivotal role in consolidating Mixed-Criticality Systems (MCS) onto a single computing platform. However, not all RISC-V processors present in Commercial Off-The-Shelf (COTS) platforms feature the hypervisor extension, which poses a significant challenge in offering virtualization support. This paper introduces HSP-V, a ready-to-run low-level software stack to provide static partitioning on RISC-V COTS platforms lacking virtualization extensions. HSP-V leverages the Domain feature of the RISC-V Open Source Supervisor Binary Interface (OpenSBI) reference implementation to establish partitions using the capabilities provided by the Physical Memory Protection (PMP) unit. Additionally, it provides other capabilities such as interrupt partitioning, direct interrupt injection, cache partitioning, and platform-level isolation for DMA-capable devices. The conducted evaluation assesses the influence of HSP-V on different performance metrics, including domain boot time, interrupt latency, code size, and execution performance using the MiBench embedded benchmark. HSP-V achieves highly deterministic interrupt latency with an average execution time of 457 ns (with a standard deviation of only 22 ns), with essentially zero traps in the Domain execution. In scenarios with cache interference, the HSP-V keeps the performance overhead as low as 0.39% for the best case scenario.

Read accessible full text

HSP-V: hypervisor-less static partitioning for RISC-V COTS platforms

Author: Sousa, João Miguel Costa; Martins, José Carvalho; Gomes, Tiago Manuel Ribeiro; Pinto, Sandro
Publisher: Institute of Electrical and Electronics Engineers (IEEE)
Year: 2024
DOI: 10.1109/ACCESS.2024.3399601
Source: https://repositorium.uminho.pt/bitstreams/f9aabd6a-8f90-43ff-a780-f6e9def04f69/download
Da e o publica ion xxxx 00, 0000, da e o cu en e sion xxxx 00, 0000.
Digi al Objec Iden i ie 10.1109/ACCESS.2024.DOI
HSP-V: Hype iso -less S a ic
Pa i ioning o RISC-V COTS Pla o ms
JOÃO SOUSA1, JOSÉ MARTINS1, TIAGO GOMES1, AND SANDRO PINTO1
1Cen o ALGORITMI / LASI - Uni e sidade do Minho, Po ugal (e-mail: [email p o ec ed]; [email p o ec ed]; m [email p o ec ed];
[email p o ec ed])
Co esponding au ho : João Sousa (e-mail: [email p o ec ed]).
This wo k has been suppo ed by FCT - Fundação pa a a Ciência e Tecnologia wi hin he R&D Uni s P ojec Scope UIDB/00319/2020,
SFRH/BD/00297/2023, and SFRH/BD/138660/2018; and pa ially suppo ed by he Eu opean Union’s Ho izon Eu ope esea ch and
inno a ion p og am unde he p ojec C oss-pla o m Open Secu i y S ack o Connec ed De ices (CROSSCON) wi h g an ag eemen No
101070537.
ABSTRACT Vi ualiza ion echnologies ha e played a pi o al ole in consolida ing Mixed-C i icali y
Sys ems (MCS) on o a single compu ing pla o m. Howe e , no all RISC-V p ocesso s p esen in
Comme cial O -The-Shel (COTS) pla o ms ea u e he hype iso ex ension, which poses a signi ican
challenge in o e ing i ualiza ion suppo . This pape in oduces HSP-V, a eady- o- un low-le el so wa e
s ack o p o ide s a ic pa i ioning on RISC-V COTS pla o ms lacking i ualiza ion ex ensions. HSP-V
le e ages he Domain ea u e o he RISC-V Open Sou ce Supe iso Bina y In e ace (OpenSBI) e e ence
implemen a ion o es ablish pa i ions using he capabili ies p o ided by he Physical Memo y P o ec ion
(PMP) uni . Addi ionally, i p o ides o he capabili ies such as in e up pa i ioning, di ec in e up injec-
ion, cache pa i ioning, and pla o m-le el isola ion o DMA-capable de ices. The conduc ed e alua ion
assesses he in luence o HSP-V on di e en pe o mance me ics, including domain boo ime, in e up
la ency, code size, and execu ion pe o mance using he MiBench embedded benchma k. HSP-V achie es
highly de e minis ic in e up la ency wi h an a e age execu ion ime o 457 ns (wi h a s anda d de ia ion
o only 22 ns), wi h essen ially ze o aps in he Domain execu ion. In scena ios wi h cache in e e ence, he
HSP-V keeps he pe o mance o e head as low as 0.39% o he bes case scena io.
INDEX TERMS Mixed-C i icali y Sys ems, Vi ualiza ion, S a ic-pa i ioning, RISC-V, OpenSBI.
I. INTRODUCTION
Cybe -physical sys ems ha e e ol ed signi ican ly in he
pas ew decades [1], ansi ioning om single-pu pose
de ices wi h limi ed communica ions and simple in e aces
o powe - and compu e-hung y gene al-pu pose sys ems wi h
mul iple unc ionali ies and complex in e ac ions [2]. To
mee he demands o educed size, weigh , powe , and
cos (SWaP-C), he e has been a pa adigm shi owa ds
he deploymen o mixed-c i icali y sys ems (MCS), which
in eg a e and consolida e di e en applica ions wi h dis inc
le els o c i icali y in o a single ha dwa e pla o m [3]–[5].
This app oach equi es spa ial, empo al, and aul isola ion
among all subsys ems, ensu ing ha subsys ems wi h lowe -
c i icali y do no comp omise he iming, unc ionali y, o
pe o mance o he sa e y-c i ical ones. Vi ualiza ion s ands
ou as he key enable echnology o consolida ing MCSs,
ocusing on wo kload consolida ion and isola ion be ween
di e en compu ing en i onmen s, e.g., ope a ing sys ems
(OSes), on a single ha dwa e pla o m.
Hype iso s ha e been ex ensi ely used o i ualiza ion,
p o iding he abili y o e icien ly sha e esou ces, suppo
di e en wo kloads acco ding o he c i icali y le el o he
applica ions, and assu e s ong isola ion be ween all in-
s ances. Cu en ly, hype iso s can span om minimalis
app oaches op imized o sa e y and secu i y, e.g., s a ic
pa i ioning hype iso s (SPHs) [6], o mo e ea u e- ich and
esou ce-e icien solu ions, such as Xen [7] and KVM [8].
SPHs alloca e ixed and dedica ed esou ces o each i ual
machine (VM) a he ime o con igu a ion, including cen al
p ocessing uni (CPU) co es, memo y, de ices, and in e up s
[6], [9]–[11]. This minimal app oach, specially ailo ed o
MCS, ensu es he e ec i e isola ion and alloca ion o e-
sou ces, which is mainly possible by le e aging ins uc ion-
se a chi ec u e (ISA) i ualiza ion ex ensions [10], [12].
Such ex ensions can al eady be ound in well-es ablished
compu e a chi ec u es such as A m (since A m 7 [13]),
In el (in oduced wi h In el VT [14]), and mo e ecen ly in
RISC-V wi h he hype iso ex ension speci ica ion [12].
VOLUME 1, 2024 1
This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and
con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601
This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/
The RISC-V ISA [15] has been gaining ac ion ac oss
a wide ange o compu ing domains, including MCS [12],
[16], [17]. In compa ison o o he a chi ec u es, RISC-V
is highly modula , ese ing pa o he encoding o cus-
om ex ensions, enabling highly specialized implemen a-
ions ha can scale om simple mic ocon olle s o su-
pe compu e s. Rega ding i ualiza ion suppo , he hype -
iso ex ension [18], a i ied in Q4 2021, is de ined by
he p i ileged a chi ec u e speci ica ion o RISC-V. Despi e
he ex ension being al eady suppo ed in QEMU and se -
e al open-sou ce so -co e RISC-V p ocesso s deployed in
ield-p og ammable ga e a ay (FPGA) [9], [10], [19], i s
suppo in comme cial o - he-shel (COTS) pla o ms e-
mains sca ce, whe e only one silicon-based implemen a ion
is known o be a ailable [20], limi ing he widesp ead u iliza-
ion o hype iso s wi h his a chi ec u e.
Ta ge ing RISC-V ha dwa e pla o ms lacking i ual-
iza ion suppo , his pape p esen s HSP-V, a hype iso -
less s a ic pa i ioning solu ion ha allows he deploymen
o MCS sys ems in scena ios whe e using a hype iso is
no easible. HSP-V is based on OpenSBI1, he de ac o
Supe iso Bina y In e ace (SBI) i mwa e implemen a ion
o RISC-V. By le e aging he OpenSBI Domain ea u e, a
sys em-le el pa i ion o unde lying ha dwa e ha ing ded-
ica ed memo y egions and ha s (i.e., ha dwa e h eads,
essen ially co es in RISC-V lingo), HSP-V can un a he
highes p i ilege mode, i.e., machine mode, while keep-
ing each pa i ion unning a he supe iso /use modes.
Pa i ioning is achie ed using memo y isola ion p imi i es
widely a ailable on RISC-V p ocesso s, such as he Physical
Memo y P o ec ion (PMP) uni . Al hough OpenSBI domains
al eady embody he co e equi emen s o a s a ic pa i ion-
ing sys em, some ea u es a e s ill missing, hampe ing he
ully deploymen o he unc ionali ies p o ided by an SPH:
(i) in e up pa i ioning and domain assignmen ; (ii) in e -
VM in e e ence mi iga ion; and (iii) pla o m-le el memo y
isola ion o di ec memo y access (DMA) de ices2.
The main con ibu ions o his a icle a e summa ized as
ollows:
•The in oduc ion o a hype iso -less s a ic pa i ioning
solu ion based on he OpenSBI e e ence implemen a ion,
specially designed o RISC-V COTS ha dwa e pla o ms
ha lack he hype iso ex ension;
•Se e al con ibu ions o he OpenSBI e e ence implemen-
a ion, such as: (i) in e up pa i ioning by media ing he
access o he pla o m-le el in e up con olle (PLIC); (ii)
sha ed cache pa i ioning; and (iii) assignmen o DMA-
capable de ices o di e en domains by using he pla o m-
speci ic inpu -ou pu memo y p o ec ion Uni (IOMPU);
•A comp ehensi e e alua ion o he HSP-V ega ding code
size, boo ime and pe o mance o e head, in e e ence,
and in e up la ency.
1OpenSBI: h ps://gi hub.com/ isc -so wa e-s c/opensbi
2OpenSBI suppo o echnologies such as he IOPMP [21] is no ye
a ailable, bu i is on he p ojec ’s oadmap.
II. BACKGROUND
A. PARTITIONING TECHNOLOGIES
Pa i ioning echnologies, such as TEEs and SPHs, play a
pi o al ole in mode n compu ing sys ems. While a TEE p o-
ides a secu e and isola ed en i onmen o sensi i e ope a-
ions and da a wi h high le els o con iden iali y and in eg i y,
i ualiza ion can be le e aged o wo kload consolida ion
and isola ion be ween di e en compu ing en i onmen s on
a single ha dwa e pla o m.
1) T us ed Execu ion En i onmen s (TEEs)
A TEE in ol es spli ing he sys em in o wo dis inc
wo lds [22], i.e., a non-secu e wo ld mainly used o ich-
OS suppo and applica ions, and a secu e wo ld ha is
commonly esponsible o execu ing c i ical unc ionali ies
such as da a enc yp ion, inge p in au hen ica ion, mone a y
ansac ion se ices, e c. Such secu e se ices usually exe-
cu e unde a us ed applica ion (TA) suppo ed by a us ed
OS. The main goal is o ensu e ha applica ions unning in
he secu e wo ld a e p o ec ed and isola ed om any in e -
ac ion by any o he componen p esen in he sys em. Ex-
amples o TEE implemen a ions include In el SGX [23] and
A m T us Zone [24]. In el SGX p o ides ha dwa e-assis ed
us ed execu ion, c ea ing secu e encla es o p o ec appli-
ca ion code and da a om any access om o he so wa e
componen , e en hose wi h oo p i ileges. Simila ly, A m
T us Zone o e s ha dwa e-based access con ol by enabling
a p ocesso o un in wo isola ed execu ion en i onmen s,
i.e., he secu e and non-secu e wo ld. T us Zone is widely
used in mobile de ices and ARM-based se e s [25], hos -
ing secu e ke nels such as T us onic3, Qualcomm’s QSEE4,
and Lina o’s OP-TEE 5, ensu ing he p o ec ion o secu i y-
c i ical da a, and acili a ing he deploymen o a ious TAs
wi h dis inc unc ionali ies.
2) S a ic Pa i ioning Hype iso s (SPHs)
Mode n SPHs include Jailhouse [26], Xen Dom0-less [27],
and Bao [10]. They all ollow a minimalis implemen a ion,
on he o de o a ew housand Sou ce Lines o Code (SLoC),
and hey mainly pe o m he pa i ioning and assignmen
(wi h no sha ing) o pla o m ha dwa e esou ces, such as
CPU, memo y, de ices, and in e up s, among he exis -
ing VMs. Since each i ual CPU ( CPU) is pinned o a
single physical CPU, SPHs do no include a schedule as
pa o he hype iso in e nals, achie ing educed size and
complexi y. All hese ea u es a e mainly possible by le e -
aging dedica ed ISA i ualiza ion ex ensions [10], [12].
Fo ins ance, A m’s ha dwa e i ualiza ion p o ides a new
highe p i ilege mode o he hype iso , o e ing suppo o
in e up i ualiza ion, inpu –ou pu memo y managemen
uni (IOMMU) ha secu ely allows VMs o di ec ly con ol
DMA-capable de ices [21], [28], [29], and he wo-s age
3T us onic:h ps://www. us onic.com/
4Qualcomm: h ps://www.qualcomm.com/p oduc s/snap-d agon/secu i y
5OP-TEE: h ps://gi hub.com/OP-TEE/
2VOLUME 1, 2024
This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and
con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601
This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/
memo y add ess ansla ion. None heless, his la e may
ep esen a po en ial challenge o he secu i y and eal- ime
equi emen s o MCS.
Besides logical space and empo al isola ion, MCS-
o ien ed hype iso s mus also ake in o accoun he sha ed
mic o-a chi ec u al esou ces p esen in complex memo y
hie a chies o mode n mul i-co e pla o ms, e.g., las -le el
caches, in e connec s, and memo y con olle s, as c i ical
subsys ems can be sensi i e o he iming a ia ions esul ing
om con en ion on such componen s [30]–[32]. To mi iga e
in e -co e in e e ence a he hype iso le el [33], se e al
echniques ha e been p oposed by he eal- ime esea ch
communi y, such as cache colo ing [34]–[36], DRAM bank
colo ing [37], memo y h o ling [35], [38], [39], and I/O
egula ion [40], [41].
B. RISC-V
RISC-V is an open-s anda d ISA c ea ed as a esea ch p ojec
in 2010 a he Uni e si y o Cali o nia, Be keley [15], and
cu en ly managed by he non-p o i RISC-V In e na ional.
Wi h a highly pe missi e license ha allows o bo h open
and p op ie a y implemen a ions, i s highly lexible and mod-
ula design enables di e en ea u es, e.g., loa ing poin ,
a omic and ec o ins uc ions, e c., o be added as ex ensions
on op o he base in ege ins uc ion se (bo h on 32-bi and
64-bi ins uc ions). Wi hin he scope o his a icle, he e a e
some key componen s ha , wo king oge he , a e essen ial
o p o ide a lexible and secu e compu ing en i onmen ha
allows he deploymen o he HSP-V a chi ec u e.
1) RISC-V P i ileged Modes
The RISC-V p i ileged a chi ec u e speci ica ion [18] de ines
h ee base p i ilege modes ( om highe o lowe p i ilege):
Machine mode (M-mode), Supe iso mode (S-mode), and
Use mode (U-mode). The only manda o y p i ileged le el
is he M-mode, commonly in ended o hos ing he i mwa e
and ha ope a es only wi h physical add esses, i.e., wi hou
i ual add ess ansla ion. The S-mode and he U-mode a e
used o un OSes and applica ions, espec i ely. Typically,
mic ocon olle s implemen only he U-mode, while appli-
ca ion class p ocesso s also implemen he S-mode, which
p o ides suppo o i ual memo y and enables he exe-
cu ion o Unix-like OSes. In addi ion o hese p i ileged
le els, he p i ileged spec de ines he hype iso ex ension,
which in oduces he concep o supe iso i ualiza ion
mode by adding wo o hogonal, bu less p i ileged, modes:
he Vi ual-Supe iso (VS) and he Vi ual-Use (VU). Fu -
he mo e, he S-mode is ex ended wi h hype iso unc ion-
ali ies such as con ol o e wo-s age ansla ion and enamed
Hype iso -ex ended Supe iso mode (HS-mode) [12], [42].
While QEMU and se e al open-sou ce so -co e RISC-V
p ocesso s deployed in FPGA al eady suppo he hype i-
so ex ension, i s adop ion in COTS pla o ms is cu en ly
limi ed [20]. Table 1 summa izes he landscape o widely
used linux-capable RISC-V COTS pla o ms ha lack he
hype iso ex ension. None heless, se e al secu i y ea u es
TABLE 1: RISC-V Linux-capable pla o ms wi hou he
hype iso ex ension.
Pla o m SoC Secu i y
Fea u es
In e up
Con olle
Pola Fi e SoC Icicle Ki Pola Fi e SoC FPGA PMP, MMU, IOMPU, Waymasking PLIC
BeagleV-Ahead Alibaba T-Head TH1520 SoC PMP, MMU, OTP, TEE Sys em PLIC
SiFi e HiFi e Unleashed SiFi e F eedom U540 SoC PMP, MMU, OTP, Waymasking PLIC
SiFi e Unma ched SiFi e F eedom U740 SoC PMP, MMU, OTP, Waymasking PLIC
Nezha Allwinne D1 SoC PMP, MMU, IOMMU PLIC
VisionFi e S a Fi e JH7100 64-bi Soc PMP, MMU, OTP, TRNG PLIC
VisionFi e 2 S a Fi e JH7110 64-bi Soc PMP, MMU PLIC
Lichee RV Dock Allwinne D1 SoC PMP, MMU PLIC
a e s ill suppo ed, e.g., PMP, MMU, IOMPU (a ailable in
he Pola Fi e SoC Icicle Ki o p o ec ing DMA-capable
de ices), WayMasking (a ailable in he Pola Fi e SoC Icicle
Ki , in he Si i e Hi i e Unleashed and in he Si i e Un-
ma ched o cache pa i ioning) and o he s. Fo he in e up
con olle , hey all implemen PLIC, which p o ides no in e -
up pa i ioning o i ualiza ion suppo .
2) Physical Memo y P o ec ion (PMP)
The RISC-V p o ides a memo y p o ec ion mechanism
called PMP [18] ha is capable o limi ing supe iso and
use (and op ionally machine) mode accesses o he physical
memo y add ess space. Fo his eason, when i ual memo y
is p esen (enabled by he MMU), and a ansla ion is needed,
he PMP akes only e ec a e he memo y ansla ion. PMP
is con olled om M-mode, allowing he de ini ion o a
whi elis o add ess space egions, each wi h di e en access
igh s (i.e., ead, w i e, and execu e) by con igu ing a se
o Con ol and S a us Regis e s (CSRs). Depending on he
implemen a ion, he PMP uni can use ei he 16 o 64 CSRs,
hus limi ing he maximum numbe o cu en ly accessible
memo y egions. An access o a memo y add ess no in-
cluded in he whi elis ed memo y egions, o ha iola es i s
pe missions, will cause an access aul and subsequen ap
o M-mode.
3) In e up s and PLIC
The RISC-V a chi ec u e includes h ee main classes o in e -
up s: (i) so wa e in e up s, compa able o in e -p ocesso
in e up (IPI); (ii) ime -based in e up s; and (iii) ex e nal
in e up s. While so wa e- and ime -based in e up s a e
conside ed local in e up s and managed by pe -ha in e up
con olle s, such as he Co e-local In e up (CLINT6) o he
Co e-local In e up Con olle (CLIC7), ex e nal in e up s
a e pla o m-wide and sha ed among all ha s. The Pla o m-
Le el In e up Con olle (PLIC8) is esponsible o ou ing
and mul iplexing pe iphe al in e up s o all ha s in he
sys em, depending on how i is con igu ed h ough an MMIO
in e ace. The PLIC is able o mul iplex up o 1023 dis inc
ex e nal in e up s o one o mo e ha con ex s, i.e., a com-
bina ion o a ha and i s associa ed p i ilege le el. As only
M- and S-mode can ecei e in e up s, he PLIC ypically has
wo con ex s pe -ha .
6CLINT: h ps://gi hub.com/pulp-pla o m/clin
7CLIC: h ps://gi hub.com/ isc / isc - as -in e up
8PLIC: h ps://gi hub.com/ isc / isc -plic-spec
VOLUME 1, 2024 3
This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and
con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601
This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/
The e a e wo main MMIO egions in he PLIC: (i) a
global con igu a ion egion; and (ii) a pe -con ex egion
o de ining he ha s p io i y mask and handling in e up s.
Al hough he PLIC has been he s anda d in e up con olle
o RISC-V since i s incep ion, he new Ad anced In e -
up A chi ec u e (AIA)9[43] is now he e e ence in e up
con olle ha will supe sede he PLIC. The AIA con olle
includes a edesigned PLIC, called he Ad anced PLIC
(APLIC), which despi e including he e y same unc ionali-
ies, i does no p o ide backwa d compa ibili y, i.e., sys ems
o applica ions designed o wo k wi h he o iginal PLIC a e
no compa ible wi h he APLIC. Despi e he eme gence o
AIA, cu en Linux-capable RISC-V COTS pla o ms s ill
ely on he PLIC, as seen in Table 1.
C. OPENSBI
The RISC-V non-ISA SBI speci ica ion aims a p o iding
an abs ac ion o e low-le el, implemen a ion-de ined, and
pla o m-le el componen s and mechanisms o ease he im-
plemen a ion and po ing o supe iso y so wa e. I de-
ines a numbe o un- ime se ices mean o be p o ided
by M-mode i mwa e, such as ha -s a e managemen , IPI-
issuing, TLB in alida ion, and shoo down. The OpenSBI
p ojec is an open-sou ce e e ence implemen a ion o he
RISC-V SBI designed o be highly modula and easily
adap able o a wide ange o RISC-V pla o ms, suppo ing
di e en ISA ex ensions and non-ISA componen s. I can
be di ec ly used as he un- ime i mwa e (o as a lib a y
included in ex e nal i mwa e o boo loade s), suppo ing he
handling o misaligned memo y accesses and he emula ion
a M-mode o Ex ensions ha a e no implemen ed (e.g.,
Legacy and IPI Ex ension [44]), equi ed by supe iso o
use so wa e.
The OpenSBI Domain sys em, is capable o pa i ioning
he unde lying ha dwa e by assigning dedica ed memo y
egions o one o mo e ha s. Besides pa i ioning ha s and
memo y/MMIO egions, OpenSBI also es ic s he e ec o
he se ices i p o ides o he in oking domain’s ha s. Fo
example, i will deny eques s o send IPIs o ha s which
a e pa o o he calling ha ’s domain. Figu e 1 depic s an
example OpenSBI domain sys em con igu a ion comp ising
wo domain ins ances unning in S-mode: (i) one wi h a
Unix-like OS wi h i s applica ions unning in U-mode; and
(ii) he o he wi h an RTOS con igu a ion (F eeRTOS).
The ini ial boo s ages a e esponsible o loading bo h
OpenSBI’s and he domains’ images o he main memo y,
being he con igu a ion passed in he o m o a De ice T ee
(DT) node ollowing a cus om binding. I his node is no
p esen , OpenSBI assumes a single " oo " domain con aining
all ha s, de ices, and memo y (excluding i s own memo y).
Nex , he OpenSBI domain ins ances a e c ea ed wi h hei
ha s and memo y egions wi h espec i e access pe mis-
sions, ollowed by some sani y checks o a oid any use mis-
con igu a ion such as domains’ memo y o e lapping. Finally,
9AIA:h ps://gi hub.com/ isc / isc -aia
Ha 1
M
S
PMP
APPAPPAPP
OpenSBI
U
PLIC
De nDe n-1De ice 1
H n-1... H n
...
GPOS RTOS
DOMAIN 2DOMAIN 1
FIGURE 1: GPOS and RTOS con igu a ion wi h anilla
OpenSBI.
i assigns each memo y o i s domains h ough he PMP en y
se up and jumps o a p e-con igu ed add ess in he domain’s
boo ha . The o he domain’s ha s may be la e woken up
ia he ha powe -s a e managemen se ice.
D. CHALLENGES OF STATIC PARTITIONING WITHOUT
VIRTUALIZATION EXTENSIONS ON RISC-V COTS.
Designing a s a ic pa i ioning solu ion wi hou elying on
i ualiza ion ex ensions is no di ec ly possible on cu en
a ailable RISC-V COTS pla o ms. Despi e OpenSBI al-
eady implemen ing he co e unc ionali ies owa ds he goal
o s a ic pa i ioning wi h he domains sys em, he mos
impo an challenges s ill need o be add essed:
•In e up pa i ioning by media ing a domain’s ac-
cess o he PLIC: Some PLIC egis e s include he
con igu a ion o mul iple in e up s and con ex s, wi h
a ew egis e s being sha ed be ween bo h domains. The
sha ed PLIC add ess space ac oss domains, as depic ed
in Figu e 1, highligh s he challenge o p e en ing one
domain om in e e ing wi h he in e up s o adjacen
domains. Addi ionally, i is c i ical o p o ide mecha-
nisms o allow he execu ion o OSes wi h unmodi ied
PLIC d i e s (e.g., wi h ap-and-emula e).
•Assignmen o DMA-capable de ices o di e en do-
mains ia he IOMPU: I is manda o y o p o ide
memo y isola ion a he sys em-le el, i.e., including
DMA de ices in isola ed domains.
•Sha ed cache pa i ioning: I is necessa y o deploy
mechanisms o mi iga e in e -ha in e e ence, namely
con en ion o sha ed cache lines.
The ollowing sec ions de ail how hese con ibu ions we e
added o he OpenSBI using he Mic ochip’s Pola Fi e SoC
FPGA Icicle Ki [45], a widely-a ailable RISC-V ha dwa e
pla o m ea u ing he i e-co e Linux capable RISC-V mi-
c op ocesso subsys em.
4VOLUME 1, 2024
This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and
con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601
This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/
DOMAIN 1
DT
De ice ID=10
Comple e
Th eshold
Mem- egions
DOMAIN 2
De ice ID=35
Comple e
Th eshold
Mem- egions
Domain 2 isibili y Domain 1 isibili y
Applica ion1
Applica ion2
Pending
Enable
Claim/Comple e
Th eshold
Claim/Comple e
Th eshold
P io i y
Applica ion1
Applica ion2
Pending
Enable
Claim/Comple e
Th eshold
Claim/Comple e
Th eshold
P io i y
Applica ion1
Applica ion2
ID=35
ID=10
ID=35
ID=10
FIGURE 2: Two HSP-V domain sys ems and hei espec i e
memo y access pe missions.
III. HSP-V IMPLEMENTATION
A. OPENSBI DOMAIN CONFIGURATION
ENHANCEMENTS
Domain con igu a ion is done by adding an opensbi-domains
node unde he chosen node o he pla o m’s ha dwa e
desc ip ion DT ile. Lis ing 1 includes he se ings o he
con igu a ion illus a ed in Figu e 2, which is composed o
wo ba e-me al applica ion domains, each s a ically pinned
o a single CPU and o a single de ice. The cus om binding
o his node includes wo ypes o subnodes: memo y egions
and domain ins ances. A memo y egion node essen ially de-
ines a base add ess (base) and a size (o de ) which may e e
o ac ual memo y size o MMIO egions, while a domain
ins ance de ines a domain’s con igu a ion wi h ou impo -
an p ope ies: (i) possible-ha s, (ii) egions, (iii) possible-
de ices, and (i ) cache-pa i ions, which a e de ailed below.
O he domain ins ance node p ope ies include (i) he boo -
ha , (ii) he nex -mode (nex p i ileged le el), and (iii) he
nex -add (en y poin add ess) o he domain10.
possible-ha s: his p ope y con ains he poin e handle
(phandle) o each ha assigned o he domain. In his
speci ic con igu a ion, Domain1 is assigned o cpu1 and
has o al access ( ead, w i e, and execu e pe missions) o
i s applica ion memo y egion (Dom1MainMem), while Do-
main2 is assigned o cpu3 and has o al access o i s dis inc
applica ion memo y egion (Dom2MainMem).
egions: his p ope y de ines he physical add ess space
ca ings assigned o he domain wi h an a ay o uples,
each con aining a phandle o he memo y egion node, plus
a bi map o he assigned pe missions ( ead, w i e, execu e).
possible-de ices: his p ope y con ains an a ay o phandles
o de ices assigned o ha domain ins ance. This p ope y
10Vanilla OpenSBI Domain con igu a ion: h ps://gi hub.com/ isc -
so wa e-s c/opensbi/blob/mas e /docs/domain_suppo .md
1 chosen{
2 opensbi−domains {
3 Dom1MainMem: Dom1MainMem {
4 compa ible ="opensbi,domain,mem egion";
5 base =<0x0 0x8020000>;
6 o de =<20>;
7 };
8 Dom2MainMem: Dom2MainMem {
9 compa ible ="opensbi,domain,mem egion";
10 base =<0x0 0x8010000>;
11 o de =<20>;
12 };
13 Dom1ins ance: Dom1ins ance {
14 compa ible ="opensbi,domain,ins ance ";
15 possible −ha s =<&cpu1>;
16 egions =<&Dom1MainMem 0x7>;
17 possible −de ices =<&pe iph_wi h_id10>;
18 cache− pa i ions =<0x0F>;
19 ...
20 };
21 Dom2ins ance: Dom2ins ance {
22 compa ible ="opensbi,domain,ins ance ";
23 possible −ha s =<&cpu3>;
24 egions =<&Dom2MainMem 0x7>;
25 possible −de ices =<&pe iph_wi h_id35>;
26 cache− pa i ions =<0xF0>;
27 ...
28 };};};
Lis ing 1: HSP-V con igu a ion o he sys em in Figu e 2.
was added o he anilla OpenSBI con igu a ion since a
domain ins ance lacks de ice in e up de ails and DMA-
capable de ice’s in o ma ion. In he de aul con igu a ion,
o assign a de ice o a domain ins ance, i was necessa y o
c ea e a dedica ed memo y egion o ha de ice. Howe e ,
his in o ma ion can be di ec ly e ie ed om he de ice
node eg p ope y. Thus, in he new con igu a ion, he do-
main ins an ia ion is able o e ie e he memo y egion o
he de ice and i s associa ed in e up s (assigning hem o
he pa i ion as discussed in Sec ion III-B), and o iden i y
DMA-capable de ices and hei espec i e IOMPU ID (as
discussed in Sec ion III-D). This op imized de ice MMIO
egion assignmen mechanism is able o s eamline and sim-
pli y he con igu a ion o domains, educing he possibili y
o use miscon igu a ions.
cache-pa i ions: This p ope y ep esen s a bi map o he
cache pa i ions assigned o a gi en domain, independen ly
o he me hod used o pa i ion he cache. Fo his speci ic
con igu a ion, he cache pa i ioning is done h ough domains
by assigning ou cache ways o Domain1 (cache-pa i ions
p ope y wi h 0x0F), and di e en ou cache ways o
Domain2 ( cache-pa i ions p ope y wi h 0xF0).
B. INTERRUPT PARTITIONING
When de ices a e assigned o domains, hese mus access
he PLIC o con igu e and handle espec i e de ice’s in-
e up s. Howe e , concu en and unsynch onized accesses
o PLIC egis e s migh esul in unp edic able beha iou
o he in ol ed domains. E en i di e en domains coop-
e a e o pe o m such accesses, his would s ill be a majo
VOLUME 1, 2024 5
This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and
con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601
This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/

secu i y/sa e y ulne abili y, as a malicious domain could
in en ionally in e e e and ampe wi h o he domains’ in-
e up s. To p e en his, a PLIC pa i ioning mechanism in
OpenSBI was implemen ed. The app oach is based on he
p inciple ha , as explained in Sec ion II-B, PLIC con ex
MMIO egions a e speci ic o a gi en ha , while he global
con igu a ion egions mus be sha ed among all domains.
The implemen ed mechanism s a s by e i ying i no
PLIC MMIO egions a e de ined in he egions p ope ies,
ollowed by con igu ing he PMP o allow domain access
o i s ha s supe iso con ex MMIO egion. As o he
global con igu a ion egis e , and o a ealis ic numbe o
de ice in e up s and due o he limi ed numbe o PMP
CSRs, i would be impossible o con igu e he PMP o
g an access o he egis e s which pe ain only o hose
in e up s. Fu he mo e, some egis e s con igu e mul iple
in e up s simul aneously on a pe -bi basis - his p o ec ion
g anula i y canno be en o ced by he PMP - and, he e o e,
o p o ec and media e access o his c i ical PLIC egion
(memo y egions ep esen ed wi h colo ed in Figu e 2, i.e.,
he P io i y,Pending and Enable PLIC egions), he p oposed
mechanism uses he classical ap-and-emula e echnique.
Since he RISC-V access con ol aul s gene a e p ecise
excep ions, when a domain ies o access he global PLIC
egion i aps o M-mode. OpenSBI uses he excep ion in-
o ma ion CSRs (e.g., mcause,m al,mepc) o ead he aul
ins uc ion and decode he access o e ie e key in o ma ion
such as he access ype (load o s o e), he des ina ion/sou ce
egis e , and he access wid h. Since he excep ion p og am
coun e (mepc) ca ies in o ma ion abou he i ual add ess,
i is equi ed o se he ms a us.MPRV bi o ead he ins uc-
ion. When his bi is enabled, M-mode memo y accesses
a e execu ed as i hey we e coming om he p i ilege le el
ha gene a ed he ap. Hence, when he domain has i ual
memo y enabled, he access is subjec o add ess ansla ion
using he domain’s page ables.
Fo he accessed add ess a ailable h ough m al, i i ual
memo y is enabled, i is necessa y o pe o m a manual page-
able walk o e ie e he ac ual physical add ess. Then, i
his accessed physical add ess is indeed pa o he c i i-
cal PLIC egion, he OpenSBI in okes he PLIC emula ion
ou ines. Based on ha add ess, he ype o PLIC egis e
being accessed is decoded. This access is hen pass h ough
(o igno ed) based on he accessing domain con ex s and
assigned in e up s. A he end o his p ocess, he execu-
ion e u ns o he p e ious execu ion con ex and esumes
om i s las ins uc ion. None heless, ap-and-emula ing his
PLIC egion will only esul in signi ican o e heads when
con igu ing in e up s. These MMIO egis e s a e no on he
c i ical pa h o he in e up handling, as hey a e ypically
only accessed du ing domain’s ini ializa ion. The in e up s
a e s ill deli e ed di ec ly o S-mode, and he PLIC egis e s
ouched du ing in e up handling a e di ec ly accessible o
domains wi hou any aps. The e o e, he p oposed app oach
o in e up pa i ioning does no cause any no iceable o e -
heads in he in e up la ency.
C. CACHE PARTITIONING
In he ealm o MCS, o comply wi h secu i y and eal- ime
equi emen s, minimizing de ia ions in he execu ion ime is
c ucial o main aining a de e minis ic beha io . Howe e ,
con en ion a in e -ha ( he e o e a in e -domain) memo y
hie a chy could esul in signi ican and unp edic able ex-
ecu ion ime, i.e., a sha ed mic o-a chi ec u al esou ces.
Speci ically, ega ding sha ed Las -Le el Caches (LLCs), a
gi en domain execu ing a memo y in ensi e wo kload migh
inad e en ly e ic he cache lines o a c i ical domain,
incu ing in high memo y access la ency and low memo y
bandwid h, and po en ially esul ing in missing he execu-
ion deadlines. In a wo se case, a malicious domain migh
in en ionally e ic such lines o pe o m Denial-o -Se ice
a acks (DoS) [46], [47] o e en apply cache-side iming
channel echniques (e.g., P ime+P obe [48], [49]) o e ie e
in o ma ion on he ic im domain’s da a o execu ion low.
The Mic ochip’s Pola i e SoC ea u es a Physically-
Index/Physically-Tagged (PIPT) 2MiB sha ed and a uni ied
L2 LLC ollowing a 16-way se -associa i e opology [45].
Besides allowing he use o ca e-ou s di ec ly as sc a chpad
memo ies, wi h essen ially cons an access imes, i also
p o ides a mechanism o lock cache ways wi h a pe -mas e
g anula i y, whe e each ha has wo mas e s one o he
ins uc ion cache, and ano he o he da a cache. A cache
con olle in e ace p o ides a WayMask egis e o each
mas e , whe e each bi in he mask co esponds o one o
he cache ways [45]. When a bi is clea in a mas e ’s
mask, i indica es ha his speci ic way canno be e ic ed by
ha mas e . None heless, his mechanism does no p o ide
any logical isola ion, as a ha can s ill ead i s masked
ways. Fo he isola ion equi emen s, he PMP uni is always
needed. Thus, his locking mechanism is used o pa i ion he
LLC among he mul iple domains acco ding o he cache-
pa i ions p ope y o he domain’s DT binding, i.e., a bi map
ep esen a ion o he assigned cache pa i ions o ha do-
main. Gi en he way-locking mechanism a ailable in he
Mic ochip’s Pola i e SoC, each o he 16 leas -signi ican
bi s in he cache-pa i ions p ope y ep esen s e ic ion igh s
o e one o he cache ways.
A ini ializa ion ime, and o each domain, he WayMask
egis e s a e se o he assigned ha s ins uc ion and da a
caches wi h he alue o cache-pa i ions. The excep ion is
he case when cache-pa i ions is no se in he domain’s
con igu a ion. Hence, i is assumed ha all cache ways a e as-
signed o all domain’s ha s and consequen ly sha ed among
hem. Despi e he ad an ages o including he WayMask
egis e in he cache con olle in e ace, ega ding he DMA
de ices i essen ially g oups he di e en DMA channels in o
a single WayMask mas e . As a esul , i is no possible o
achie e a ully pa i ioned cache o ce ain de ice assign-
men combina ions, i.e., locking ways o a speci ic DMA
channel, will also lock he same ways o o he channels
alloca ed o adjacen domains.
6VOLUME 1, 2024
This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and
con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601
This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/
TABLE 2: SLoC and bina y size (by es).
SLoC Size (by es)
c asm To al . ex .da a .bss To al
OpenSBI
u ils 6236 27 6263 41597 1240 13224 56061
pla o m 373 0 373 2247 192 544 2983
sbi 8507 229 8736 52010 816 128376 181202
i mwa e 33 860 893 49695 120 0 49815
To al 15149 1116 16265 145549 2368 142144 290061
HSP-V
u ils 7159 27 7186 44532 1240 15624 61396
pla o m 480 0 480 2273 320 40 2633
sbi 9130 229 9359 54680 824 128376 183880
i mwa e 33 863 896 49691 120 0 49811
To al 16802
(+10.9%)
1119
(+0%)
17921
(+10.2%)
151176
(+3.8%)
2504
(+6%)
144040
(+1.3%)
297720
(+2%)
D. DMA PROTECTION
Unmedia ed access o he main memo y by a domain’s non-
CPU bus mas e (i.e., a DMA-capable de ice) can esul in
da a co up ion (and hus he s a e and/o sensi i e in o ma-
ion) o o he domains. To a oid his, he Mic ochip’s Po-
la i e SoC includes a buil -in IOMPU o each o hese mas-
e s, including E he ne , eMMC, and USB pe iphe als [45].
The IOMPU con igu a ion egis e s essen ially ollow he
same s uc u e as he PMP CSRs. Howe e , he numbe o
egions o each IOMPU de ice a ies om 2 o 16, e.g., 4
con igu a ion en ies o he MMC mas e block and 8 en ies
o E he ne mas e blocks. As a esul , since a domain is a se
o ha s and memo ies and each ha suppo s a maximum o
16 egions (i.e., 16 PMP en ies), he numbe o egions o a
gi en block mas e migh be less han he numbe o egions
assigned o i s domain. Facing his, he HSP-V app oach
con igu es he memo y egions o hese mas e s acco dingly
o he domains ha will le e age he de ice. I he e a e s ill
no enough egis e s o con igu e he domain’s egion, a aul
is igge ed and he sys em is ully hal ed be o e s a ing
any domain. A un ime, in case a pe iphe al ies o access
a egion no p esen in i s IOMPU egions, an in e up is
issued o OpenSBI, which ac s by hal ing all ha s belonging
o a de ice’s domain.
IV. EVALUATION
The e alua ion o he HSP-V was conduc ed on a Mic ochip
Pola Fi e SoC Icicle Ki boa d [45], which ea u es a SiFi e
E51 pla o m managemen ha , a quad-co e U54 applica ion
clus e wi h pe -co e 32 KiB L1 da a and ins uc ion caches,
and a 2 MiB sha ed L2 cache. The pe o med es s include
HSP-V code size, boo o e head, execu ion pe o mance and
in e -domain in e e ence, and in e up la ency.
A. CODE SIZE
This wo k ex ends he OpenSBI 1.0, adding signi ican
ea u es p o ided by HSP-V while main aining he o iginal
code s uc u e. Table 2 p esen s he SLoC and he inal bina y
size o subsys em o bo h he anilla OpenSBI and HSP-V,
e ie ed wi h he compile op imiza ions se o -O2. The
HSP-V adds abou 1656 SLoC o he 16265 SLoC o he
anilla OpenSBI, which co esponds o an inc ease o a ound
10%. Mos o he addi ional SLoC a e in (i) he u ils di ec-
o y, speci ically, in he DT pa sing logic; (ii) he pla o m-
dependen code wi h he d i e implemen a ion o applying
he cache pa i ioning and he IOMPU egis e se up; and
OpenSBI ini
Domain (ii) Domain (i)
S-mode
M-mode
OpenSBI
HSP-V
F eeRTOS
boo T&E F eeRTOS
boo
Linux
boo T&E Linux
boo
F eeRTOS boo ime
Linux boo ime
OpenSBI ini
FIGURE 3: Boo sequence o a con igu a ion wi h wo
domains unde he same pla o m.
TABLE 3: Boo ime (ms) o anilla OpenSBI and HSP-V.
Scena io OpenSBI ini . ime (ms) To al boo ime (ms)
a g s d-de a g s d-de
OpenSBI
ee os 80.134 0.303 94.140 0.748
linux 6734.653 5.026
ee os lock 80.202 0.200 94.049 0.200
linux lock 6800.564 6.043
HSP-V
ee os 112.051 (+40%) 0.197 154.517 (+63%) 0.438
linux 8375.438 (+24%) 5.510
ee os lock 112.102 0.205 154.385 0.207
linux lock 8417.998 5.358
(iii) he sbi co e ha was enhanced wi h he PLIC ap-
and-emula ion code. On he o he hand, he inal bina y ile
wi h he ea u es added by he HSP-V is a ound 298 KiB,
which co esponds o an addi ional 8 KiB (mos ly on he
. ex sec ion) o he o iginal OpenSBI bina y ile (290 KiB).
Despi e no comple ely negligible, he modi ica ions equi ed
by he HSP-V do no signi ican ly impac he sys em’s
T us ed Code Base (TCB).
B. BOOT OVERHEAD
This e alua ion consis s in measu ing he o al boo ime o
a con igu a ion wi h wo single-ha domains ha ollows he
boo sequence illus a ed by Figu e 3. Domain (i) consis s
o a F eeRTOS con igu a ion wi h a bina y size o 57 KiB,
while Domain (ii) includes a Linux-based sys em wi h an
image size 104 MiB. The measu emen s include he o al
boo ime (label: OpenSBI ini ) o bo h he HSP-V wi h he
enhanced e sion o he OpenSBI, and he anilla OpenSBI,
as well as he boo execu ion ime (labels F eeRTOS boo ime
and Linux boo ime) o each domain, bo h ep esen ed by
ed a ows. Addi ionally, i was measu ed he execu ion ime
o he ap-and-emula ion (label T&E) mechanism, which
co esponds o he PLIC accesses o in e up pa i ioning
a e se ing up he domains, as well as he in luence o
enabling he cache pa i ioning ea u e. To ca y ou hese
measu es (in clock cycles) he dcycle pseudo-ins uc ion was
used, and he collec ed esul s a e summa ized in he Table 3.
Rega ding he ini ializa ion ime wi hou he cache lock,
he anilla OpenSBI akes on a e age 80.134 ms o comple e,
while he OpenSBI wi h he HSP-V equi es 112.051 ms
o inish he ini ializa ion, co esponding o a boo ime
o e head o a ound 40%. Wi h he cache locking mechanism
enabled, hese alues u he inc ease o 80.202 ms o he
anilla OpenSBI, and 112.102 ms o he HSP-V. Fo he o al
VOLUME 1, 2024 7
This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and
con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601
This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/
FIGURE 4: MiBench au omo i e benchma k sui e pe o mance esul s.
boo ime wi hou cache locking, he HSP-V equi es a ound
154.517 ms o boo ing he F eeRTOS, and 8375.438 ms
o boo ing he Linux sys em. These alues, when compa ed
o he na i e e sions o bo h domains, co espond o an
o e head o nea ly 63% and 24%, espec i ely. This is mainly
due o he ap-and-emula ing ope a ions equi ed by he
HSP-V o con igu ing he PLIC MMIO egions, which a e
no equi ed in he anilla OpenSBI.
C. PERFORMANCE OVERHEAD AND INTERFERENCE
To assess he pe o mance o e head and he in e -ha /in e -
domain in e e ence, i was used he MiBench Embedded
Benchma k Sui e’s au omo i e subse , a e e ence bench-
ma k widely used in he e alua ion o MCS [6], [10], [12],
and he LMbench [50], a sui e o po able mic o-benchma ks
designed o measu e a ious aspec s o a compu ing sys em’s
pe o mance.
MiBench. This benchma k sui e consis o six di e en es s
ha execu e in a single-ha Linux-based domain, con aining
ou memo y-in ensi e algo i hms suscep ible o in e e ence
caused by he LLC and memo y con en ion, such as qso ,
susan co ne s, and susan edges. The in e e ence be ween
ha s/domains is in oduced by a ba e-me al applica ion ha
uns on o he h ee ha s and execu es a memo y-in ensi e
wo kload ha con inuously pe o ms sequen ial w i es o a
1.5 MiB a ay wi h a s ide equal o he cache line size
(64 by es). Each benchma k execu ed o ou di e en
sys em con igu a ions: (i) hos ed execu ion (solo), (ii) solo
wi h cache locking enable (solo-lock), (iii) hos ed execu ion
unde in e e ence om mul iple domains (in e ), and (i )
in e wi h cache locking enable (in e -lock). Fo he es s
including he cache locking mechanism, ou cache ways
(512 KiB) we e alloca ed o he ba e-me al applica ion, and
eigh cache ways (1 MiB) o he Linux-based domain. The
las ou emaining cache ways (512 KiB) a e ese ed o be
used as sc a chpad memo y by OpenSBI. Figu e 4 depic s
he pe o mance esul s using he solo con igu a ion as he
baseline, whe e each ba ep esen s he a e age execu ion
ime o 1000 samples.
By enabling he cache pa i ioning (solo-lock), he o e all
pe o mance dec eases when compa ed wi h he solo con-
igu a ion, which can be explained by he dec easing o he
amoun o a ailable cache memo y ha is alloca ed o each
domain. When s essing he sys em wi h in e e ence (in e )
caused by he ba e-me al applica ion unning on he h ee e-
maining ha s, he pe o mance s a s dec easing, especially
in he memo y-in ensi e benchma ks, i.e., he qso small
akes a ound 95.50 ms o comple e (+50%), he susan co ne s
small equi es a ound 20.82 ms (+79.73%), and he susan
edges small akes nea ly 22.80 ms (+71.27%) o inish. Wi h
he in e -lock con igu a ion, he cache pa i ioning mecha-
nism mi iga es he e ec o his in e e ence, which educes
he execu ion ime o he p e iously men ioned memo y-
in ensi e benchma ks, i.e., he qso small akes now a ound
78.90 ms o comple e (+25.72%), he susan co ne s small e-
qui es now a ound 15.16 ms (+30.87%), and he susan edges
small akes nea ly 16.89 ms (+26.86%) o inish. O e all,
he benchma ks handling smalle da a se s (-small) a e mo e
suscep ible o cache in e e ence han he la ge e sions.
LMBench. This benchma k sui e a ge s UNIX sys ems and
aims a measu ing a ious aspec s o a compu e sys em’s
pe o mance, such as memo y la ency and bandwid h, con-
ex swi ching, ile sys em ope a ions, and in e -p ocess com-
munica ion, among o he s. This e alua ion only uses he
bw_mem benchma k, which was used o e alua e memo y
ope a ions bandwid h o di e en block sizes, i.e., 512KiB,
1MiB, and 1.5MiB, execu ed o he same sys em con igu a-
ions as MiBench, i.e., o solo,solo-lock,in e , and in e -
lock. The in e e ence was caused by he same ba e-me al
( o in e con igu a ions), and he cache locking mechanism
ollowed he same way alloca ion as o MiBench, i.e., ou
cache ways o he ba e-me al applica ion and eigh cache
ways o he Linux-based domain. Figu e 5 depic s he pe -
o mance esul s using he solo con igu a ion as he baseline,
whe e each ba ep esen s an a e age memo y bandwid h
in megaby es pe second (MiB/s) o 100 samples. Fo each
sample, he mic o-benchma k was con igu ed wi h 10 wa m-
ups and 1000 epe i ions (–W 10 –N 1000), encompassing
100000 samples (pe ba ).
LMBench esul s ein o ce he same conclusions as
MiBench, wi h he beha iou o solo,solo-lock,in e and
in e -lock con igu a ions ollowing he same pa e n. Ne -
e heless, he esul s show ha he ela i e pe o mance o
he sys em dec eases wi h he inc ease o he wo kload
8VOLUME 1, 2024
This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and
con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601
This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/
FIGURE 5: LMbench au omo i e benchma k sui e pe o -
mance esul s.
(excep o he copy ope a ions). Fo he copy ope a ions,
he ela i e pe o mance deg ada ion can be explained by he
wo kload being equal (512KiB) o highe (1 and 1.5 MiB)
han he a ailable LLC cache o each domain. As he copy
ope a ion uses wo bu e s ( he sou ce and des ina ion bu e s
a e cacheable), he size o necessa y memo y doubles (e.g.,
he wo kload o cp is wo imes he size o w ), making i
he mos memo y-in ensi e mic o-benchma k. Fo 512 KiB
wo kload, he memo y bandwid h a es a e 606 MiB/s in
cp, 390 MiB/s in cp, and 471 MiB/s in bcopy; o 1 MiB
wo kload he memo y bandwid h a es a e 233 MiB/s in cp,
191 MiB/s in cp, and 208 MiB/s in bcopy; and o 1.5 MiB
wo kload he memo y bandwid h a es a e 144 MiB/s in cp,
127 MiB/s in cp, and 135 MiB/s in bcopy.
O he expe imen s we e pe o med wi h bigge memo y
wo kloads ( om 256KiB o 2MiB). Howe e , he achie ed
esul s ollowed he same pa e n.
D. INTERRUPT LATENCY
To measu e he in e up la ency, a c a ed minimal ba e-
me al benchma k applica ion le e ages an ex e nal ime
pe iphe al con igu ed in dec emen mode wi h a 10 ms au o-
eload pe iod, o bo h igge he in e up s and measu e hei
espec i e delay. All measu emen s we e aken wi h cold L1
caches, which, be ween each measu emen , a e in alida ed
wi h he i ence ins uc ion and he da a lushed by eading he
con en o a dummy a ay wi h he size o he cache. Figu e
6 depic s he esul s in he o m o 5000 samples his og am
o wo con igu a ions: (i) he in e up la ency o he anilla
OpenSBI wi hou PLIC pa i ioning (Figu e 6a); and (ii)
he in e up la ency in he HSP-V wi h PLIC pa i ioning
(a) HSP-V in e up la ency (wi h PLIC pa i ioning).
(b) OpenSBI in e up la ency (wi hou PLIC pa i ioning).
FIGURE 6: In e up La ency o e head.
(Figu e 6b). The ob ained esul s show ha he HSP-V do no
impac he in e up la ency, displaying a s anda d de ia ion
o only 22 ns, wi h an a e age execu ion ime o 457 ns.
Such esul s co ela e wi h wha was p e iously explained
in Sec ion III-B, showing ha he PLIC pa i ioning only
causes aps o OpenSBI on in e up con igu a ion and no
on in e up handling, as ex e nal in e up s con inue o be
di ec ly delega ed o he S-mode in he mideleg CSR.
V. HSP-V IN PERSPECTIVE WITH RELATED WORK
This sec ion p o ides an o e iew o exis ing RISC-V
s a ic pa i ioning sys ems, such as Bao [10], Jailhouse
[26], X a uM [51], Dom0-less (Xen) [27], Mul izone [30],
Keys one [52], and VOSySmoni oRV [16], pu ing hem in
pe spec i e wi h he HSP-V solu ion. Table 5 highligh s
hei di e ences conside ing he ollowing ea u es: (i) Vi -
ualiza ion Ex ensions suppo ; (ii) he pa i ion echnology
adop ed, i.e., TEEs, Hype iso s, o o he app oaches explo -
ing ha dwa e RISC-V secu i y p imi i es o s a ically isola e
esou ces ac oss se e al en i onmen s; (iii) he secu i y de-
sign ea u es; (i ) and he so wa e license.
Hype iso echnologies. The mos p ominen open-sou ce
SPHs suppo ing he RISC-V a chi ec u e ( hanks o so -
co e implemen a ions such as Rocke [12], CVA6 [42],
and NOEL-V [53], deployed in FPGA) a e Bao [10],
Jailhouse [26], Xen dom0-less [27], and X a uM [51]. Thei
s a ic pa i ioning design de ines CPU and IO memo y ac-
cesses among all exis ing VMs. I adop s a 1-1 mapping o
i ual o physical CPUs, wi h no need o a schedule o me-
dia e CPU alloca ion and ensu e de e minis ic pe o mance
VOLUME 1, 2024 9
This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and
con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601
This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/