scieee Open visual document viewer

HSP-V: hypervisor-less static partitioning for RISC-V COTS platforms

Sousa, João Miguel Costa; Martins, José Carvalho; Gomes, Tiago Manuel Ribeiro; Pinto, Sandro

Abstract

Virtualization technologies have played a pivotal role in consolidating Mixed-Criticality Systems (MCS) onto a single computing platform. However, not all RISC-V processors present in Commercial Off-The-Shelf (COTS) platforms feature the hypervisor extension, which poses a significant challenge in offering virtualization support. This paper introduces HSP-V, a ready-to-run low-level software stack to provide static partitioning on RISC-V COTS platforms lacking virtualization extensions. HSP-V leverages the Domain feature of the RISC-V Open Source Supervisor Binary Interface (OpenSBI) reference implementation to establish partitions using the capabilities provided by the Physical Memory Protection (PMP) unit. Additionally, it provides other capabilities such as interrupt partitioning, direct interrupt injection, cache partitioning, and platform-level isolation for DMA-capable devices. The conducted evaluation assesses the influence of HSP-V on different performance metrics, including domain boot time, interrupt latency, code size, and execution performance using the MiBench embedded benchmark. HSP-V achieves highly deterministic interrupt latency with an average execution time of 457 ns (with a standard deviation of only 22 ns), with essentially zero traps in the Domain execution. In scenarios with cache interference, the HSP-V keeps the performance overhead as low as 0.39% for the best case scenario.

Full text

Da e o publica ion xxxx 00, 0000, da e o cu en e sion xxxx 00, 0000. Digi al Objec Iden i ie 10.1109/ACCESS.2024.DOI HSP-V: Hype iso -less S a ic Pa i ioning o RISC-V COTS Pla o ms JOÃO SOUSA1, JOSÉ MARTINS1, TIAGO GOMES1, AND SANDRO PINTO1 1Cen o ALGORITMI / LASI - Uni e sidade do Minho, Po ugal (e-mail: [email p o ec ed]; [email p o ec ed]; m [email p o ec ed]; [email p o ec ed]) Co esponding au ho : João Sousa (e-mail: [email p o ec ed]). This wo k has been suppo ed by FCT - Fundação pa a a Ciência e Tecnologia wi hin he R&D Uni s P ojec Scope UIDB/00319/2020, SFRH/BD/00297/2023, and SFRH/BD/138660/2018; and pa ially suppo ed by he Eu opean Union’s Ho izon Eu ope esea ch and inno a ion p og am unde he p ojec C oss-pla o m Open Secu i y S ack o Connec ed De ices (CROSSCON) wi h g an ag eemen No 101070537. ABSTRACT Vi ualiza ion echnologies ha e played a pi o al ole in consolida ing Mixed-C i icali y Sys ems (MCS) on o a single compu ing pla o m. Howe e , no all RISC-V p ocesso s p esen in Comme cial O -The-Shel (COTS) pla o ms ea u e he hype iso ex ension, which poses a signi ican challenge in o e ing i ualiza ion suppo . This pape in oduces HSP-V, a eady- o- un low-le el so wa e s ack o p o ide s a ic pa i ioning on RISC-V COTS pla o ms lacking i ualiza ion ex ensions. HSP-V le e ages he Domain ea u e o he RISC-V Open Sou ce Supe iso Bina y In e ace (OpenSBI) e e ence implemen a ion o es ablish pa i ions using he capabili ies p o ided by he Physical Memo y P o ec ion (PMP) uni . Addi ionally, i p o ides o he capabili ies such as in e up pa i ioning, di ec in e up injec- ion, cache pa i ioning, and pla o m-le el isola ion o DMA-capable de ices. The conduc ed e alua ion assesses he in luence o HSP-V on di e en pe o mance me ics, including domain boo ime, in e up la ency, code size, and execu ion pe o mance using he MiBench embedded benchma k. HSP-V achie es highly de e minis ic in e up la ency wi h an a e age execu ion ime o 457 ns (wi h a s anda d de ia ion o only 22 ns), wi h essen ially ze o aps in he Domain execu ion. In scena ios wi h cache in e e ence, he HSP-V keeps he pe o mance o e head as low as 0.39% o he bes case scena io. INDEX TERMS Mixed-C i icali y Sys ems, Vi ualiza ion, S a ic-pa i ioning, RISC-V, OpenSBI. I. INTRODUCTION Cybe -physical sys ems ha e e ol ed signi ican ly in he pas ew decades [1], ansi ioning om single-pu pose de ices wi h limi ed communica ions and simple in e aces o powe - and compu e-hung y gene al-pu pose sys ems wi h mul iple unc ionali ies and complex in e ac ions [2]. To mee he demands o educed size, weigh , powe , and cos (SWaP-C), he e has been a pa adigm shi owa ds he deploymen o mixed-c i icali y sys ems (MCS), which in eg a e and consolida e di e en applica ions wi h dis inc le els o c i icali y in o a single ha dwa e pla o m [3]–[5]. This app oach equi es spa ial, empo al, and aul isola ion among all subsys ems, ensu ing ha subsys ems wi h lowe - c i icali y do no comp omise he iming, unc ionali y, o pe o mance o he sa e y-c i ical ones. Vi ualiza ion s ands ou as he key enable echnology o consolida ing MCSs, ocusing on wo kload consolida ion and isola ion be ween di e en compu ing en i onmen s, e.g., ope a ing sys ems (OSes), on a single ha dwa e pla o m. Hype iso s ha e been ex ensi ely used o i ualiza ion, p o iding he abili y o e icien ly sha e esou ces, suppo di e en wo kloads acco ding o he c i icali y le el o he applica ions, and assu e s ong isola ion be ween all in- s ances. Cu en ly, hype iso s can span om minimalis app oaches op imized o sa e y and secu i y, e.g., s a ic pa i ioning hype iso s (SPHs) [6], o mo e ea u e- ich and esou ce-e icien solu ions, such as Xen [7] and KVM [8]. SPHs alloca e ixed and dedica ed esou ces o each i ual machine (VM) a he ime o con igu a ion, including cen al p ocessing uni (CPU) co es, memo y, de ices, and in e up s [6], [9]–[11]. This minimal app oach, specially ailo ed o MCS, ensu es he e ec i e isola ion and alloca ion o e- sou ces, which is mainly possible by le e aging ins uc ion- se a chi ec u e (ISA) i ualiza ion ex ensions [10], [12]. Such ex ensions can al eady be ound in well-es ablished compu e a chi ec u es such as A m (since A m 7 [13]), In el (in oduced wi h In el VT [14]), and mo e ecen ly in RISC-V wi h he hype iso ex ension speci ica ion [12]. VOLUME 1, 2024 1 This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601 This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/ The RISC-V ISA [15] has been gaining ac ion ac oss a wide ange o compu ing domains, including MCS [12], [16], [17]. In compa ison o o he a chi ec u es, RISC-V is highly modula , ese ing pa o he encoding o cus- om ex ensions, enabling highly specialized implemen a- ions ha can scale om simple mic ocon olle s o su- pe compu e s. Rega ding i ualiza ion suppo , he hype - iso ex ension [18], a i ied in Q4 2021, is de ined by he p i ileged a chi ec u e speci ica ion o RISC-V. Despi e he ex ension being al eady suppo ed in QEMU and se - e al open-sou ce so -co e RISC-V p ocesso s deployed in ield-p og ammable ga e a ay (FPGA) [9], [10], [19], i s suppo in comme cial o - he-shel (COTS) pla o ms e- mains sca ce, whe e only one silicon-based implemen a ion is known o be a ailable [20], limi ing he widesp ead u iliza- ion o hype iso s wi h his a chi ec u e. Ta ge ing RISC-V ha dwa e pla o ms lacking i ual- iza ion suppo , his pape p esen s HSP-V, a hype iso - less s a ic pa i ioning solu ion ha allows he deploymen o MCS sys ems in scena ios whe e using a hype iso is no easible. HSP-V is based on OpenSBI1, he de ac o Supe iso Bina y In e ace (SBI) i mwa e implemen a ion o RISC-V. By le e aging he OpenSBI Domain ea u e, a sys em-le el pa i ion o unde lying ha dwa e ha ing ded- ica ed memo y egions and ha s (i.e., ha dwa e h eads, essen ially co es in RISC-V lingo), HSP-V can un a he highes p i ilege mode, i.e., machine mode, while keep- ing each pa i ion unning a he supe iso /use modes. Pa i ioning is achie ed using memo y isola ion p imi i es widely a ailable on RISC-V p ocesso s, such as he Physical Memo y P o ec ion (PMP) uni . Al hough OpenSBI domains al eady embody he co e equi emen s o a s a ic pa i ion- ing sys em, some ea u es a e s ill missing, hampe ing he ully deploymen o he unc ionali ies p o ided by an SPH: (i) in e up pa i ioning and domain assignmen ; (ii) in e - VM in e e ence mi iga ion; and (iii) pla o m-le el memo y isola ion o di ec memo y access (DMA) de ices2. The main con ibu ions o his a icle a e summa ized as ollows: •The in oduc ion o a hype iso -less s a ic pa i ioning solu ion based on he OpenSBI e e ence implemen a ion, specially designed o RISC-V COTS ha dwa e pla o ms ha lack he hype iso ex ension; •Se e al con ibu ions o he OpenSBI e e ence implemen- a ion, such as: (i) in e up pa i ioning by media ing he access o he pla o m-le el in e up con olle (PLIC); (ii) sha ed cache pa i ioning; and (iii) assignmen o DMA- capable de ices o di e en domains by using he pla o m- speci ic inpu -ou pu memo y p o ec ion Uni (IOMPU); •A comp ehensi e e alua ion o he HSP-V ega ding code size, boo ime and pe o mance o e head, in e e ence, and in e up la ency. 1OpenSBI: h ps://gi hub.com/ isc -so wa e-s c/opensbi 2OpenSBI suppo o echnologies such as he IOPMP [21] is no ye a ailable, bu i is on he p ojec ’s oadmap. II. BACKGROUND A. PARTITIONING TECHNOLOGIES Pa i ioning echnologies, such as TEEs and SPHs, play a pi o al ole in mode n compu ing sys ems. While a TEE p o- ides a secu e and isola ed en i onmen o sensi i e ope a- ions and da a wi h high le els o con iden iali y and in eg i y, i ualiza ion can be le e aged o wo kload consolida ion and isola ion be ween di e en compu ing en i onmen s on a single ha dwa e pla o m. 1) T us ed Execu ion En i onmen s (TEEs) A TEE in ol es spli ing he sys em in o wo dis inc wo lds [22], i.e., a non-secu e wo ld mainly used o ich- OS suppo and applica ions, and a secu e wo ld ha is commonly esponsible o execu ing c i ical unc ionali ies such as da a enc yp ion, inge p in au hen ica ion, mone a y ansac ion se ices, e c. Such secu e se ices usually exe- cu e unde a us ed applica ion (TA) suppo ed by a us ed OS. The main goal is o ensu e ha applica ions unning in he secu e wo ld a e p o ec ed and isola ed om any in e - ac ion by any o he componen p esen in he sys em. Ex- amples o TEE implemen a ions include In el SGX [23] and A m T us Zone [24]. In el SGX p o ides ha dwa e-assis ed us ed execu ion, c ea ing secu e encla es o p o ec appli- ca ion code and da a om any access om o he so wa e componen , e en hose wi h oo p i ileges. Simila ly, A m T us Zone o e s ha dwa e-based access con ol by enabling a p ocesso o un in wo isola ed execu ion en i onmen s, i.e., he secu e and non-secu e wo ld. T us Zone is widely used in mobile de ices and ARM-based se e s [25], hos - ing secu e ke nels such as T us onic3, Qualcomm’s QSEE4, and Lina o’s OP-TEE 5, ensu ing he p o ec ion o secu i y- c i ical da a, and acili a ing he deploymen o a ious TAs wi h dis inc unc ionali ies. 2) S a ic Pa i ioning Hype iso s (SPHs) Mode n SPHs include Jailhouse [26], Xen Dom0-less [27], and Bao [10]. They all ollow a minimalis implemen a ion, on he o de o a ew housand Sou ce Lines o Code (SLoC), and hey mainly pe o m he pa i ioning and assignmen (wi h no sha ing) o pla o m ha dwa e esou ces, such as CPU, memo y, de ices, and in e up s, among he exis - ing VMs. Since each i ual CPU ( CPU) is pinned o a single physical CPU, SPHs do no include a schedule as pa o he hype iso in e nals, achie ing educed size and complexi y. All hese ea u es a e mainly possible by le e - aging dedica ed ISA i ualiza ion ex ensions [10], [12]. Fo ins ance, A m’s ha dwa e i ualiza ion p o ides a new highe p i ilege mode o he hype iso , o e ing suppo o in e up i ualiza ion, inpu –ou pu memo y managemen uni (IOMMU) ha secu ely allows VMs o di ec ly con ol DMA-capable de ices [21], [28], [29], and he wo-s age 3T us onic:h ps://www. us onic.com/ 4Qualcomm: h ps://www.qualcomm.com/p oduc s/snap-d agon/secu i y 5OP-TEE: h ps://gi hub.com/OP-TEE/ 2VOLUME 1, 2024 This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601 This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/ memo y add ess ansla ion. None heless, his la e may ep esen a po en ial challenge o he secu i y and eal- ime equi emen s o MCS. Besides logical space and empo al isola ion, MCS- o ien ed hype iso s mus also ake in o accoun he sha ed mic o-a chi ec u al esou ces p esen in complex memo y hie a chies o mode n mul i-co e pla o ms, e.g., las -le el caches, in e connec s, and memo y con olle s, as c i ical subsys ems can be sensi i e o he iming a ia ions esul ing om con en ion on such componen s [30]–[32]. To mi iga e in e -co e in e e ence a he hype iso le el [33], se e al echniques ha e been p oposed by he eal- ime esea ch communi y, such as cache colo ing [34]–[36], DRAM bank colo ing [37], memo y h o ling [35], [38], [39], and I/O egula ion [40], [41]. B. RISC-V RISC-V is an open-s anda d ISA c ea ed as a esea ch p ojec in 2010 a he Uni e si y o Cali o nia, Be keley [15], and cu en ly managed by he non-p o i RISC-V In e na ional. Wi h a highly pe missi e license ha allows o bo h open and p op ie a y implemen a ions, i s highly lexible and mod- ula design enables di e en ea u es, e.g., loa ing poin , a omic and ec o ins uc ions, e c., o be added as ex ensions on op o he base in ege ins uc ion se (bo h on 32-bi and 64-bi ins uc ions). Wi hin he scope o his a icle, he e a e some key componen s ha , wo king oge he , a e essen ial o p o ide a lexible and secu e compu ing en i onmen ha allows he deploymen o he HSP-V a chi ec u e. 1) RISC-V P i ileged Modes The RISC-V p i ileged a chi ec u e speci ica ion [18] de ines h ee base p i ilege modes ( om highe o lowe p i ilege): Machine mode (M-mode), Supe iso mode (S-mode), and Use mode (U-mode). The only manda o y p i ileged le el is he M-mode, commonly in ended o hos ing he i mwa e and ha ope a es only wi h physical add esses, i.e., wi hou i ual add ess ansla ion. The S-mode and he U-mode a e used o un OSes and applica ions, espec i ely. Typically, mic ocon olle s implemen only he U-mode, while appli- ca ion class p ocesso s also implemen he S-mode, which p o ides suppo o i ual memo y and enables he exe- cu ion o Unix-like OSes. In addi ion o hese p i ileged le els, he p i ileged spec de ines he hype iso ex ension, which in oduces he concep o supe iso i ualiza ion mode by adding wo o hogonal, bu less p i ileged, modes: he Vi ual-Supe iso (VS) and he Vi ual-Use (VU). Fu - he mo e, he S-mode is ex ended wi h hype iso unc ion- ali ies such as con ol o e wo-s age ansla ion and enamed Hype iso -ex ended Supe iso mode (HS-mode) [12], [42]. While QEMU and se e al open-sou ce so -co e RISC-V p ocesso s deployed in FPGA al eady suppo he hype i- so ex ension, i s adop ion in COTS pla o ms is cu en ly limi ed [20]. Table 1 summa izes he landscape o widely used linux-capable RISC-V COTS pla o ms ha lack he hype iso ex ension. None heless, se e al secu i y ea u es TABLE 1: RISC-V Linux-capable pla o ms wi hou he hype iso ex ension. Pla o m SoC Secu i y Fea u es In e up Con olle Pola Fi e SoC Icicle Ki Pola Fi e SoC FPGA PMP, MMU, IOMPU, Waymasking PLIC BeagleV-Ahead Alibaba T-Head TH1520 SoC PMP, MMU, OTP, TEE Sys em PLIC SiFi e HiFi e Unleashed SiFi e F eedom U540 SoC PMP, MMU, OTP, Waymasking PLIC SiFi e Unma ched SiFi e F eedom U740 SoC PMP, MMU, OTP, Waymasking PLIC Nezha Allwinne D1 SoC PMP, MMU, IOMMU PLIC VisionFi e S a Fi e JH7100 64-bi Soc PMP, MMU, OTP, TRNG PLIC VisionFi e 2 S a Fi e JH7110 64-bi Soc PMP, MMU PLIC Lichee RV Dock Allwinne D1 SoC PMP, MMU PLIC a e s ill suppo ed, e.g., PMP, MMU, IOMPU (a ailable in he Pola Fi e SoC Icicle Ki o p o ec ing DMA-capable de ices), WayMasking (a ailable in he Pola Fi e SoC Icicle Ki , in he Si i e Hi i e Unleashed and in he Si i e Un- ma ched o cache pa i ioning) and o he s. Fo he in e up con olle , hey all implemen PLIC, which p o ides no in e - up pa i ioning o i ualiza ion suppo . 2) Physical Memo y P o ec ion (PMP) The RISC-V p o ides a memo y p o ec ion mechanism called PMP [18] ha is capable o limi ing supe iso and use (and op ionally machine) mode accesses o he physical memo y add ess space. Fo his eason, when i ual memo y is p esen (enabled by he MMU), and a ansla ion is needed, he PMP akes only e ec a e he memo y ansla ion. PMP is con olled om M-mode, allowing he de ini ion o a whi elis o add ess space egions, each wi h di e en access igh s (i.e., ead, w i e, and execu e) by con igu ing a se o Con ol and S a us Regis e s (CSRs). Depending on he implemen a ion, he PMP uni can use ei he 16 o 64 CSRs, hus limi ing he maximum numbe o cu en ly accessible memo y egions. An access o a memo y add ess no in- cluded in he whi elis ed memo y egions, o ha iola es i s pe missions, will cause an access aul and subsequen ap o M-mode. 3) In e up s and PLIC The RISC-V a chi ec u e includes h ee main classes o in e - up s: (i) so wa e in e up s, compa able o in e -p ocesso in e up (IPI); (ii) ime -based in e up s; and (iii) ex e nal in e up s. While so wa e- and ime -based in e up s a e conside ed local in e up s and managed by pe -ha in e up con olle s, such as he Co e-local In e up (CLINT6) o he Co e-local In e up Con olle (CLIC7), ex e nal in e up s a e pla o m-wide and sha ed among all ha s. The Pla o m- Le el In e up Con olle (PLIC8) is esponsible o ou ing and mul iplexing pe iphe al in e up s o all ha s in he sys em, depending on how i is con igu ed h ough an MMIO in e ace. The PLIC is able o mul iplex up o 1023 dis inc ex e nal in e up s o one o mo e ha con ex s, i.e., a com- bina ion o a ha and i s associa ed p i ilege le el. As only M- and S-mode can ecei e in e up s, he PLIC ypically has wo con ex s pe -ha . 6CLINT: h ps://gi hub.com/pulp-pla o m/clin 7CLIC: h ps://gi hub.com/ isc / isc - as -in e up 8PLIC: h ps://gi hub.com/ isc / isc -plic-spec VOLUME 1, 2024 3 This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601 This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/ The e a e wo main MMIO egions in he PLIC: (i) a global con igu a ion egion; and (ii) a pe -con ex egion o de ining he ha s p io i y mask and handling in e up s. Al hough he PLIC has been he s anda d in e up con olle o RISC-V since i s incep ion, he new Ad anced In e - up A chi ec u e (AIA)9[43] is now he e e ence in e up con olle ha will supe sede he PLIC. The AIA con olle includes a edesigned PLIC, called he Ad anced PLIC (APLIC), which despi e including he e y same unc ionali- ies, i does no p o ide backwa d compa ibili y, i.e., sys ems o applica ions designed o wo k wi h he o iginal PLIC a e no compa ible wi h he APLIC. Despi e he eme gence o AIA, cu en Linux-capable RISC-V COTS pla o ms s ill ely on he PLIC, as seen in Table 1. C. OPENSBI The RISC-V non-ISA SBI speci ica ion aims a p o iding an abs ac ion o e low-le el, implemen a ion-de ined, and pla o m-le el componen s and mechanisms o ease he im- plemen a ion and po ing o supe iso y so wa e. I de- ines a numbe o un- ime se ices mean o be p o ided by M-mode i mwa e, such as ha -s a e managemen , IPI- issuing, TLB in alida ion, and shoo down. The OpenSBI p ojec is an open-sou ce e e ence implemen a ion o he RISC-V SBI designed o be highly modula and easily adap able o a wide ange o RISC-V pla o ms, suppo ing di e en ISA ex ensions and non-ISA componen s. I can be di ec ly used as he un- ime i mwa e (o as a lib a y included in ex e nal i mwa e o boo loade s), suppo ing he handling o misaligned memo y accesses and he emula ion a M-mode o Ex ensions ha a e no implemen ed (e.g., Legacy and IPI Ex ension [44]), equi ed by supe iso o use so wa e. The OpenSBI Domain sys em, is capable o pa i ioning he unde lying ha dwa e by assigning dedica ed memo y egions o one o mo e ha s. Besides pa i ioning ha s and memo y/MMIO egions, OpenSBI also es ic s he e ec o he se ices i p o ides o he in oking domain’s ha s. Fo example, i will deny eques s o send IPIs o ha s which a e pa o o he calling ha ’s domain. Figu e 1 depic s an example OpenSBI domain sys em con igu a ion comp ising wo domain ins ances unning in S-mode: (i) one wi h a Unix-like OS wi h i s applica ions unning in U-mode; and (ii) he o he wi h an RTOS con igu a ion (F eeRTOS). The ini ial boo s ages a e esponsible o loading bo h OpenSBI’s and he domains’ images o he main memo y, being he con igu a ion passed in he o m o a De ice T ee (DT) node ollowing a cus om binding. I his node is no p esen , OpenSBI assumes a single " oo " domain con aining all ha s, de ices, and memo y (excluding i s own memo y). Nex , he OpenSBI domain ins ances a e c ea ed wi h hei ha s and memo y egions wi h espec i e access pe mis- sions, ollowed by some sani y checks o a oid any use mis- con igu a ion such as domains’ memo y o e lapping. Finally, 9AIA:h ps://gi hub.com/ isc / isc -aia Ha 1 M S PMP APPAPPAPP OpenSBI U PLIC De nDe n-1De ice 1 H n-1... H n ... GPOS RTOS DOMAIN 2DOMAIN 1 FIGURE 1: GPOS and RTOS con igu a ion wi h anilla OpenSBI. i assigns each memo y o i s domains h ough he PMP en y se up and jumps o a p e-con igu ed add ess in he domain’s boo ha . The o he domain’s ha s may be la e woken up ia he ha powe -s a e managemen se ice. D. CHALLENGES OF STATIC PARTITIONING WITHOUT VIRTUALIZATION EXTENSIONS ON RISC-V COTS. Designing a s a ic pa i ioning solu ion wi hou elying on i ualiza ion ex ensions is no di ec ly possible on cu en a ailable RISC-V COTS pla o ms. Despi e OpenSBI al- eady implemen ing he co e unc ionali ies owa ds he goal o s a ic pa i ioning wi h he domains sys em, he mos impo an challenges s ill need o be add essed: •In e up pa i ioning by media ing a domain’s ac- cess o he PLIC: Some PLIC egis e s include he con igu a ion o mul iple in e up s and con ex s, wi h a ew egis e s being sha ed be ween bo h domains. The sha ed PLIC add ess space ac oss domains, as depic ed in Figu e 1, highligh s he challenge o p e en ing one domain om in e e ing wi h he in e up s o adjacen domains. Addi ionally, i is c i ical o p o ide mecha- nisms o allow he execu ion o OSes wi h unmodi ied PLIC d i e s (e.g., wi h ap-and-emula e). •Assignmen o DMA-capable de ices o di e en do- mains ia he IOMPU: I is manda o y o p o ide memo y isola ion a he sys em-le el, i.e., including DMA de ices in isola ed domains. •Sha ed cache pa i ioning: I is necessa y o deploy mechanisms o mi iga e in e -ha in e e ence, namely con en ion o sha ed cache lines. The ollowing sec ions de ail how hese con ibu ions we e added o he OpenSBI using he Mic ochip’s Pola Fi e SoC FPGA Icicle Ki [45], a widely-a ailable RISC-V ha dwa e pla o m ea u ing he i e-co e Linux capable RISC-V mi- c op ocesso subsys em. 4VOLUME 1, 2024 This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601 This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/ DOMAIN 1 DT De ice ID=10 Comple e Th eshold Mem- egions DOMAIN 2 De ice ID=35 Comple e Th eshold Mem- egions Domain 2 isibili y Domain 1 isibili y Applica ion1 Applica ion2 Pending Enable Claim/Comple e Th eshold Claim/Comple e Th eshold P io i y Applica ion1 Applica ion2 Pending Enable Claim/Comple e Th eshold Claim/Comple e Th eshold P io i y Applica ion1 Applica ion2 ID=35 ID=10 ID=35 ID=10 FIGURE 2: Two HSP-V domain sys ems and hei espec i e memo y access pe missions. III. HSP-V IMPLEMENTATION A. OPENSBI DOMAIN CONFIGURATION ENHANCEMENTS Domain con igu a ion is done by adding an opensbi-domains node unde he chosen node o he pla o m’s ha dwa e desc ip ion DT ile. Lis ing 1 includes he se ings o he con igu a ion illus a ed in Figu e 2, which is composed o wo ba e-me al applica ion domains, each s a ically pinned o a single CPU and o a single de ice. The cus om binding o his node includes wo ypes o subnodes: memo y egions and domain ins ances. A memo y egion node essen ially de- ines a base add ess (base) and a size (o de ) which may e e o ac ual memo y size o MMIO egions, while a domain ins ance de ines a domain’s con igu a ion wi h ou impo - an p ope ies: (i) possible-ha s, (ii) egions, (iii) possible- de ices, and (i ) cache-pa i ions, which a e de ailed below. O he domain ins ance node p ope ies include (i) he boo - ha , (ii) he nex -mode (nex p i ileged le el), and (iii) he nex -add (en y poin add ess) o he domain10. possible-ha s: his p ope y con ains he poin e handle (phandle) o each ha assigned o he domain. In his speci ic con igu a ion, Domain1 is assigned o cpu1 and has o al access ( ead, w i e, and execu e pe missions) o i s applica ion memo y egion (Dom1MainMem), while Do- main2 is assigned o cpu3 and has o al access o i s dis inc applica ion memo y egion (Dom2MainMem). egions: his p ope y de ines he physical add ess space ca ings assigned o he domain wi h an a ay o uples, each con aining a phandle o he memo y egion node, plus a bi map o he assigned pe missions ( ead, w i e, execu e). possible-de ices: his p ope y con ains an a ay o phandles o de ices assigned o ha domain ins ance. This p ope y 10Vanilla OpenSBI Domain con igu a ion: h ps://gi hub.com/ isc - so wa e-s c/opensbi/blob/mas e /docs/domain_suppo .md 1 chosen{ 2 opensbi−domains { 3 Dom1MainMem: Dom1MainMem { 4 compa ible ="opensbi,domain,mem egion"; 5 base =<0x0 0x8020000>; 6 o de =<20>; 7 }; 8 Dom2MainMem: Dom2MainMem { 9 compa ible ="opensbi,domain,mem egion"; 10 base =<0x0 0x8010000>; 11 o de =<20>; 12 }; 13 Dom1ins ance: Dom1ins ance { 14 compa ible ="opensbi,domain,ins ance "; 15 possible −ha s =<&cpu1>; 16 egions =<&Dom1MainMem 0x7>; 17 possible −de ices =<&pe iph_wi h_id10>; 18 cache− pa i ions =<0x0F>; 19 ... 20 }; 21 Dom2ins ance: Dom2ins ance { 22 compa ible ="opensbi,domain,ins ance "; 23 possible −ha s =<&cpu3>; 24 egions =<&Dom2MainMem 0x7>; 25 possible −de ices =<&pe iph_wi h_id35>; 26 cache− pa i ions =<0xF0>; 27 ... 28 };};}; Lis ing 1: HSP-V con igu a ion o he sys em in Figu e 2. was added o he anilla OpenSBI con igu a ion since a domain ins ance lacks de ice in e up de ails and DMA- capable de ice’s in o ma ion. In he de aul con igu a ion, o assign a de ice o a domain ins ance, i was necessa y o c ea e a dedica ed memo y egion o ha de ice. Howe e , his in o ma ion can be di ec ly e ie ed om he de ice node eg p ope y. Thus, in he new con igu a ion, he do- main ins an ia ion is able o e ie e he memo y egion o he de ice and i s associa ed in e up s (assigning hem o he pa i ion as discussed in Sec ion III-B), and o iden i y DMA-capable de ices and hei espec i e IOMPU ID (as discussed in Sec ion III-D). This op imized de ice MMIO egion assignmen mechanism is able o s eamline and sim- pli y he con igu a ion o domains, educing he possibili y o use miscon igu a ions. cache-pa i ions: This p ope y ep esen s a bi map o he cache pa i ions assigned o a gi en domain, independen ly o he me hod used o pa i ion he cache. Fo his speci ic con igu a ion, he cache pa i ioning is done h ough domains by assigning ou cache ways o Domain1 (cache-pa i ions p ope y wi h 0x0F), and di e en ou cache ways o Domain2 ( cache-pa i ions p ope y wi h 0xF0). B. INTERRUPT PARTITIONING When de ices a e assigned o domains, hese mus access he PLIC o con igu e and handle espec i e de ice’s in- e up s. Howe e , concu en and unsynch onized accesses o PLIC egis e s migh esul in unp edic able beha iou o he in ol ed domains. E en i di e en domains coop- e a e o pe o m such accesses, his would s ill be a majo VOLUME 1, 2024 5 This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601 This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/ secu i y/sa e y ulne abili y, as a malicious domain could in en ionally in e e e and ampe wi h o he domains’ in- e up s. To p e en his, a PLIC pa i ioning mechanism in OpenSBI was implemen ed. The app oach is based on he p inciple ha , as explained in Sec ion II-B, PLIC con ex MMIO egions a e speci ic o a gi en ha , while he global con igu a ion egions mus be sha ed among all domains. The implemen ed mechanism s a s by e i ying i no PLIC MMIO egions a e de ined in he egions p ope ies, ollowed by con igu ing he PMP o allow domain access o i s ha s supe iso con ex MMIO egion. As o he global con igu a ion egis e , and o a ealis ic numbe o de ice in e up s and due o he limi ed numbe o PMP CSRs, i would be impossible o con igu e he PMP o g an access o he egis e s which pe ain only o hose in e up s. Fu he mo e, some egis e s con igu e mul iple in e up s simul aneously on a pe -bi basis - his p o ec ion g anula i y canno be en o ced by he PMP - and, he e o e, o p o ec and media e access o his c i ical PLIC egion (memo y egions ep esen ed wi h colo ed in Figu e 2, i.e., he P io i y,Pending and Enable PLIC egions), he p oposed mechanism uses he classical ap-and-emula e echnique. Since he RISC-V access con ol aul s gene a e p ecise excep ions, when a domain ies o access he global PLIC egion i aps o M-mode. OpenSBI uses he excep ion in- o ma ion CSRs (e.g., mcause,m al,mepc) o ead he aul ins uc ion and decode he access o e ie e key in o ma ion such as he access ype (load o s o e), he des ina ion/sou ce egis e , and he access wid h. Since he excep ion p og am coun e (mepc) ca ies in o ma ion abou he i ual add ess, i is equi ed o se he ms a us.MPRV bi o ead he ins uc- ion. When his bi is enabled, M-mode memo y accesses a e execu ed as i hey we e coming om he p i ilege le el ha gene a ed he ap. Hence, when he domain has i ual memo y enabled, he access is subjec o add ess ansla ion using he domain’s page ables. Fo he accessed add ess a ailable h ough m al, i i ual memo y is enabled, i is necessa y o pe o m a manual page- able walk o e ie e he ac ual physical add ess. Then, i his accessed physical add ess is indeed pa o he c i i- cal PLIC egion, he OpenSBI in okes he PLIC emula ion ou ines. Based on ha add ess, he ype o PLIC egis e being accessed is decoded. This access is hen pass h ough (o igno ed) based on he accessing domain con ex s and assigned in e up s. A he end o his p ocess, he execu- ion e u ns o he p e ious execu ion con ex and esumes om i s las ins uc ion. None heless, ap-and-emula ing his PLIC egion will only esul in signi ican o e heads when con igu ing in e up s. These MMIO egis e s a e no on he c i ical pa h o he in e up handling, as hey a e ypically only accessed du ing domain’s ini ializa ion. The in e up s a e s ill deli e ed di ec ly o S-mode, and he PLIC egis e s ouched du ing in e up handling a e di ec ly accessible o domains wi hou any aps. The e o e, he p oposed app oach o in e up pa i ioning does no cause any no iceable o e - heads in he in e up la ency. C. CACHE PARTITIONING In he ealm o MCS, o comply wi h secu i y and eal- ime equi emen s, minimizing de ia ions in he execu ion ime is c ucial o main aining a de e minis ic beha io . Howe e , con en ion a in e -ha ( he e o e a in e -domain) memo y hie a chy could esul in signi ican and unp edic able ex- ecu ion ime, i.e., a sha ed mic o-a chi ec u al esou ces. Speci ically, ega ding sha ed Las -Le el Caches (LLCs), a gi en domain execu ing a memo y in ensi e wo kload migh inad e en ly e ic he cache lines o a c i ical domain, incu ing in high memo y access la ency and low memo y bandwid h, and po en ially esul ing in missing he execu- ion deadlines. In a wo se case, a malicious domain migh in en ionally e ic such lines o pe o m Denial-o -Se ice a acks (DoS) [46], [47] o e en apply cache-side iming channel echniques (e.g., P ime+P obe [48], [49]) o e ie e in o ma ion on he ic im domain’s da a o execu ion low. The Mic ochip’s Pola i e SoC ea u es a Physically- Index/Physically-Tagged (PIPT) 2MiB sha ed and a uni ied L2 LLC ollowing a 16-way se -associa i e opology [45]. Besides allowing he use o ca e-ou s di ec ly as sc a chpad memo ies, wi h essen ially cons an access imes, i also p o ides a mechanism o lock cache ways wi h a pe -mas e g anula i y, whe e each ha has wo mas e s one o he ins uc ion cache, and ano he o he da a cache. A cache con olle in e ace p o ides a WayMask egis e o each mas e , whe e each bi in he mask co esponds o one o he cache ways [45]. When a bi is clea in a mas e ’s mask, i indica es ha his speci ic way canno be e ic ed by ha mas e . None heless, his mechanism does no p o ide any logical isola ion, as a ha can s ill ead i s masked ways. Fo he isola ion equi emen s, he PMP uni is always needed. Thus, his locking mechanism is used o pa i ion he LLC among he mul iple domains acco ding o he cache- pa i ions p ope y o he domain’s DT binding, i.e., a bi map ep esen a ion o he assigned cache pa i ions o ha do- main. Gi en he way-locking mechanism a ailable in he Mic ochip’s Pola i e SoC, each o he 16 leas -signi ican bi s in he cache-pa i ions p ope y ep esen s e ic ion igh s o e one o he cache ways. A ini ializa ion ime, and o each domain, he WayMask egis e s a e se o he assigned ha s ins uc ion and da a caches wi h he alue o cache-pa i ions. The excep ion is he case when cache-pa i ions is no se in he domain’s con igu a ion. Hence, i is assumed ha all cache ways a e as- signed o all domain’s ha s and consequen ly sha ed among hem. Despi e he ad an ages o including he WayMask egis e in he cache con olle in e ace, ega ding he DMA de ices i essen ially g oups he di e en DMA channels in o a single WayMask mas e . As a esul , i is no possible o achie e a ully pa i ioned cache o ce ain de ice assign- men combina ions, i.e., locking ways o a speci ic DMA channel, will also lock he same ways o o he channels alloca ed o adjacen domains. 6VOLUME 1, 2024 This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601 This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/ TABLE 2: SLoC and bina y size (by es). SLoC Size (by es) c asm To al . ex .da a .bss To al OpenSBI u ils 6236 27 6263 41597 1240 13224 56061 pla o m 373 0 373 2247 192 544 2983 sbi 8507 229 8736 52010 816 128376 181202 i mwa e 33 860 893 49695 120 0 49815 To al 15149 1116 16265 145549 2368 142144 290061 HSP-V u ils 7159 27 7186 44532 1240 15624 61396 pla o m 480 0 480 2273 320 40 2633 sbi 9130 229 9359 54680 824 128376 183880 i mwa e 33 863 896 49691 120 0 49811 To al 16802 (+10.9%) 1119 (+0%) 17921 (+10.2%) 151176 (+3.8%) 2504 (+6%) 144040 (+1.3%) 297720 (+2%) D. DMA PROTECTION Unmedia ed access o he main memo y by a domain’s non- CPU bus mas e (i.e., a DMA-capable de ice) can esul in da a co up ion (and hus he s a e and/o sensi i e in o ma- ion) o o he domains. To a oid his, he Mic ochip’s Po- la i e SoC includes a buil -in IOMPU o each o hese mas- e s, including E he ne , eMMC, and USB pe iphe als [45]. The IOMPU con igu a ion egis e s essen ially ollow he same s uc u e as he PMP CSRs. Howe e , he numbe o egions o each IOMPU de ice a ies om 2 o 16, e.g., 4 con igu a ion en ies o he MMC mas e block and 8 en ies o E he ne mas e blocks. As a esul , since a domain is a se o ha s and memo ies and each ha suppo s a maximum o 16 egions (i.e., 16 PMP en ies), he numbe o egions o a gi en block mas e migh be less han he numbe o egions assigned o i s domain. Facing his, he HSP-V app oach con igu es he memo y egions o hese mas e s acco dingly o he domains ha will le e age he de ice. I he e a e s ill no enough egis e s o con igu e he domain’s egion, a aul is igge ed and he sys em is ully hal ed be o e s a ing any domain. A un ime, in case a pe iphe al ies o access a egion no p esen in i s IOMPU egions, an in e up is issued o OpenSBI, which ac s by hal ing all ha s belonging o a de ice’s domain. IV. EVALUATION The e alua ion o he HSP-V was conduc ed on a Mic ochip Pola Fi e SoC Icicle Ki boa d [45], which ea u es a SiFi e E51 pla o m managemen ha , a quad-co e U54 applica ion clus e wi h pe -co e 32 KiB L1 da a and ins uc ion caches, and a 2 MiB sha ed L2 cache. The pe o med es s include HSP-V code size, boo o e head, execu ion pe o mance and in e -domain in e e ence, and in e up la ency. A. CODE SIZE This wo k ex ends he OpenSBI 1.0, adding signi ican ea u es p o ided by HSP-V while main aining he o iginal code s uc u e. Table 2 p esen s he SLoC and he inal bina y size o subsys em o bo h he anilla OpenSBI and HSP-V, e ie ed wi h he compile op imiza ions se o -O2. The HSP-V adds abou 1656 SLoC o he 16265 SLoC o he anilla OpenSBI, which co esponds o an inc ease o a ound 10%. Mos o he addi ional SLoC a e in (i) he u ils di ec- o y, speci ically, in he DT pa sing logic; (ii) he pla o m- dependen code wi h he d i e implemen a ion o applying he cache pa i ioning and he IOMPU egis e se up; and OpenSBI ini Domain (ii) Domain (i) S-mode M-mode OpenSBI HSP-V F eeRTOS boo T&E F eeRTOS boo Linux boo T&E Linux boo F eeRTOS boo ime Linux boo ime OpenSBI ini FIGURE 3: Boo sequence o a con igu a ion wi h wo domains unde he same pla o m. TABLE 3: Boo ime (ms) o anilla OpenSBI and HSP-V. Scena io OpenSBI ini . ime (ms) To al boo ime (ms) a g s d-de a g s d-de OpenSBI ee os 80.134 0.303 94.140 0.748 linux 6734.653 5.026 ee os lock 80.202 0.200 94.049 0.200 linux lock 6800.564 6.043 HSP-V ee os 112.051 (+40%) 0.197 154.517 (+63%) 0.438 linux 8375.438 (+24%) 5.510 ee os lock 112.102 0.205 154.385 0.207 linux lock 8417.998 5.358 (iii) he sbi co e ha was enhanced wi h he PLIC ap- and-emula ion code. On he o he hand, he inal bina y ile wi h he ea u es added by he HSP-V is a ound 298 KiB, which co esponds o an addi ional 8 KiB (mos ly on he . ex sec ion) o he o iginal OpenSBI bina y ile (290 KiB). Despi e no comple ely negligible, he modi ica ions equi ed by he HSP-V do no signi ican ly impac he sys em’s T us ed Code Base (TCB). B. BOOT OVERHEAD This e alua ion consis s in measu ing he o al boo ime o a con igu a ion wi h wo single-ha domains ha ollows he boo sequence illus a ed by Figu e 3. Domain (i) consis s o a F eeRTOS con igu a ion wi h a bina y size o 57 KiB, while Domain (ii) includes a Linux-based sys em wi h an image size 104 MiB. The measu emen s include he o al boo ime (label: OpenSBI ini ) o bo h he HSP-V wi h he enhanced e sion o he OpenSBI, and he anilla OpenSBI, as well as he boo execu ion ime (labels F eeRTOS boo ime and Linux boo ime) o each domain, bo h ep esen ed by ed a ows. Addi ionally, i was measu ed he execu ion ime o he ap-and-emula ion (label T&E) mechanism, which co esponds o he PLIC accesses o in e up pa i ioning a e se ing up he domains, as well as he in luence o enabling he cache pa i ioning ea u e. To ca y ou hese measu es (in clock cycles) he dcycle pseudo-ins uc ion was used, and he collec ed esul s a e summa ized in he Table 3. Rega ding he ini ializa ion ime wi hou he cache lock, he anilla OpenSBI akes on a e age 80.134 ms o comple e, while he OpenSBI wi h he HSP-V equi es 112.051 ms o inish he ini ializa ion, co esponding o a boo ime o e head o a ound 40%. Wi h he cache locking mechanism enabled, hese alues u he inc ease o 80.202 ms o he anilla OpenSBI, and 112.102 ms o he HSP-V. Fo he o al VOLUME 1, 2024 7 This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601 This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/ FIGURE 4: MiBench au omo i e benchma k sui e pe o mance esul s. boo ime wi hou cache locking, he HSP-V equi es a ound 154.517 ms o boo ing he F eeRTOS, and 8375.438 ms o boo ing he Linux sys em. These alues, when compa ed o he na i e e sions o bo h domains, co espond o an o e head o nea ly 63% and 24%, espec i ely. This is mainly due o he ap-and-emula ing ope a ions equi ed by he HSP-V o con igu ing he PLIC MMIO egions, which a e no equi ed in he anilla OpenSBI. C. PERFORMANCE OVERHEAD AND INTERFERENCE To assess he pe o mance o e head and he in e -ha /in e - domain in e e ence, i was used he MiBench Embedded Benchma k Sui e’s au omo i e subse , a e e ence bench- ma k widely used in he e alua ion o MCS [6], [10], [12], and he LMbench [50], a sui e o po able mic o-benchma ks designed o measu e a ious aspec s o a compu ing sys em’s pe o mance. MiBench. This benchma k sui e consis o six di e en es s ha execu e in a single-ha Linux-based domain, con aining ou memo y-in ensi e algo i hms suscep ible o in e e ence caused by he LLC and memo y con en ion, such as qso , susan co ne s, and susan edges. The in e e ence be ween ha s/domains is in oduced by a ba e-me al applica ion ha uns on o he h ee ha s and execu es a memo y-in ensi e wo kload ha con inuously pe o ms sequen ial w i es o a 1.5 MiB a ay wi h a s ide equal o he cache line size (64 by es). Each benchma k execu ed o ou di e en sys em con igu a ions: (i) hos ed execu ion (solo), (ii) solo wi h cache locking enable (solo-lock), (iii) hos ed execu ion unde in e e ence om mul iple domains (in e ), and (i ) in e wi h cache locking enable (in e -lock). Fo he es s including he cache locking mechanism, ou cache ways (512 KiB) we e alloca ed o he ba e-me al applica ion, and eigh cache ways (1 MiB) o he Linux-based domain. The las ou emaining cache ways (512 KiB) a e ese ed o be used as sc a chpad memo y by OpenSBI. Figu e 4 depic s he pe o mance esul s using he solo con igu a ion as he baseline, whe e each ba ep esen s he a e age execu ion ime o 1000 samples. By enabling he cache pa i ioning (solo-lock), he o e all pe o mance dec eases when compa ed wi h he solo con- igu a ion, which can be explained by he dec easing o he amoun o a ailable cache memo y ha is alloca ed o each domain. When s essing he sys em wi h in e e ence (in e ) caused by he ba e-me al applica ion unning on he h ee e- maining ha s, he pe o mance s a s dec easing, especially in he memo y-in ensi e benchma ks, i.e., he qso small akes a ound 95.50 ms o comple e (+50%), he susan co ne s small equi es a ound 20.82 ms (+79.73%), and he susan edges small akes nea ly 22.80 ms (+71.27%) o inish. Wi h he in e -lock con igu a ion, he cache pa i ioning mecha- nism mi iga es he e ec o his in e e ence, which educes he execu ion ime o he p e iously men ioned memo y- in ensi e benchma ks, i.e., he qso small akes now a ound 78.90 ms o comple e (+25.72%), he susan co ne s small e- qui es now a ound 15.16 ms (+30.87%), and he susan edges small akes nea ly 16.89 ms (+26.86%) o inish. O e all, he benchma ks handling smalle da a se s (-small) a e mo e suscep ible o cache in e e ence han he la ge e sions. LMBench. This benchma k sui e a ge s UNIX sys ems and aims a measu ing a ious aspec s o a compu e sys em’s pe o mance, such as memo y la ency and bandwid h, con- ex swi ching, ile sys em ope a ions, and in e -p ocess com- munica ion, among o he s. This e alua ion only uses he bw_mem benchma k, which was used o e alua e memo y ope a ions bandwid h o di e en block sizes, i.e., 512KiB, 1MiB, and 1.5MiB, execu ed o he same sys em con igu a- ions as MiBench, i.e., o solo,solo-lock,in e , and in e - lock. The in e e ence was caused by he same ba e-me al ( o in e con igu a ions), and he cache locking mechanism ollowed he same way alloca ion as o MiBench, i.e., ou cache ways o he ba e-me al applica ion and eigh cache ways o he Linux-based domain. Figu e 5 depic s he pe - o mance esul s using he solo con igu a ion as he baseline, whe e each ba ep esen s an a e age memo y bandwid h in megaby es pe second (MiB/s) o 100 samples. Fo each sample, he mic o-benchma k was con igu ed wi h 10 wa m- ups and 1000 epe i ions (–W 10 –N 1000), encompassing 100000 samples (pe ba ). LMBench esul s ein o ce he same conclusions as MiBench, wi h he beha iou o solo,solo-lock,in e and in e -lock con igu a ions ollowing he same pa e n. Ne - e heless, he esul s show ha he ela i e pe o mance o he sys em dec eases wi h he inc ease o he wo kload 8VOLUME 1, 2024 This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601 This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/ FIGURE 5: LMbench au omo i e benchma k sui e pe o - mance esul s. (excep o he copy ope a ions). Fo he copy ope a ions, he ela i e pe o mance deg ada ion can be explained by he wo kload being equal (512KiB) o highe (1 and 1.5 MiB) han he a ailable LLC cache o each domain. As he copy ope a ion uses wo bu e s ( he sou ce and des ina ion bu e s a e cacheable), he size o necessa y memo y doubles (e.g., he wo kload o cp is wo imes he size o w ), making i he mos memo y-in ensi e mic o-benchma k. Fo 512 KiB wo kload, he memo y bandwid h a es a e 606 MiB/s in cp, 390 MiB/s in cp, and 471 MiB/s in bcopy; o 1 MiB wo kload he memo y bandwid h a es a e 233 MiB/s in cp, 191 MiB/s in cp, and 208 MiB/s in bcopy; and o 1.5 MiB wo kload he memo y bandwid h a es a e 144 MiB/s in cp, 127 MiB/s in cp, and 135 MiB/s in bcopy. O he expe imen s we e pe o med wi h bigge memo y wo kloads ( om 256KiB o 2MiB). Howe e , he achie ed esul s ollowed he same pa e n. D. INTERRUPT LATENCY To measu e he in e up la ency, a c a ed minimal ba e- me al benchma k applica ion le e ages an ex e nal ime pe iphe al con igu ed in dec emen mode wi h a 10 ms au o- eload pe iod, o bo h igge he in e up s and measu e hei espec i e delay. All measu emen s we e aken wi h cold L1 caches, which, be ween each measu emen , a e in alida ed wi h he i ence ins uc ion and he da a lushed by eading he con en o a dummy a ay wi h he size o he cache. Figu e 6 depic s he esul s in he o m o 5000 samples his og am o wo con igu a ions: (i) he in e up la ency o he anilla OpenSBI wi hou PLIC pa i ioning (Figu e 6a); and (ii) he in e up la ency in he HSP-V wi h PLIC pa i ioning (a) HSP-V in e up la ency (wi h PLIC pa i ioning). (b) OpenSBI in e up la ency (wi hou PLIC pa i ioning). FIGURE 6: In e up La ency o e head. (Figu e 6b). The ob ained esul s show ha he HSP-V do no impac he in e up la ency, displaying a s anda d de ia ion o only 22 ns, wi h an a e age execu ion ime o 457 ns. Such esul s co ela e wi h wha was p e iously explained in Sec ion III-B, showing ha he PLIC pa i ioning only causes aps o OpenSBI on in e up con igu a ion and no on in e up handling, as ex e nal in e up s con inue o be di ec ly delega ed o he S-mode in he mideleg CSR. V. HSP-V IN PERSPECTIVE WITH RELATED WORK This sec ion p o ides an o e iew o exis ing RISC-V s a ic pa i ioning sys ems, such as Bao [10], Jailhouse [26], X a uM [51], Dom0-less (Xen) [27], Mul izone [30], Keys one [52], and VOSySmoni oRV [16], pu ing hem in pe spec i e wi h he HSP-V solu ion. Table 5 highligh s hei di e ences conside ing he ollowing ea u es: (i) Vi - ualiza ion Ex ensions suppo ; (ii) he pa i ion echnology adop ed, i.e., TEEs, Hype iso s, o o he app oaches explo - ing ha dwa e RISC-V secu i y p imi i es o s a ically isola e esou ces ac oss se e al en i onmen s; (iii) he secu i y de- sign ea u es; (i ) and he so wa e license. Hype iso echnologies. The mos p ominen open-sou ce SPHs suppo ing he RISC-V a chi ec u e ( hanks o so - co e implemen a ions such as Rocke [12], CVA6 [42], and NOEL-V [53], deployed in FPGA) a e Bao [10], Jailhouse [26], Xen dom0-less [27], and X a uM [51]. Thei s a ic pa i ioning design de ines CPU and IO memo y ac- cesses among all exis ing VMs. I adop s a 1-1 mapping o i ual o physical CPUs, wi h no need o a schedule o me- dia e CPU alloca ion and ensu e de e minis ic pe o mance VOLUME 1, 2024 9 This a icle has been accep ed o publica ion in IEEE Access. This is he au ho 's e sion which has no been ully edi ed and con en may change p io o inal publica ion. Ci a ion in o ma ion: DOI 10.1109/ACCESS.2024.3399601 This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/