MPU add-on
The sandboxing feature for embOS
- Adds task-level memory protection and isolation to embOS-Classic and embOS-Ultra
- Uses the privilege level and hardware memory protection of supported microcontrollers to improve system robustness
- Restricts memory access between tasks to detect faults and prevent interference

Key features

Memory protection
The MPU add-on ensures that unprivileged tasks operate within strictly defined boundaries for memory and resources, preventing these tasks from affecting other tasks or an operating system. All unprivileged tasks are fully sandboxed.

High reliability
Through the strict separation of privileged and unprivileged tasks, a system remains stable even in the event of failure. Critical functions can continue running independently.

Impressive flexibility
Unprivileged tasks can be granted controlled access to memory regions, peripherals, and RTOS objects. This allows developers to define permissions precisely, ensuring both security and efficient resource utilization.
Use cases
From battery-powered single-chip products to systems that demand ultra-fast responses, flexibility, and the ability to schedule multiple tasks, the MPU add-on provides a robust foundation for system security and efficiency. The range of potential application areas is diverse, and includes medical equipment, automation, avionics, and any other application area where safety is critical.

Reliability in safety-critical systems
In safety-critical systems, such as those found in medical devices, automotive control units, and industrial automation, reliability is paramount. the MPU add-on enhances system integrity, ensuring that faults in one task do not compromise an entire system. This guarantees continued operation even in the presence of software errors.

Data integrity in embedded applications
For IoT and connected devices, security is a top priority. The MPU add-on enforces strict memory access rules, protecting sensitive data and preventing unauthorized code execution. The result? Significantly reduced risk of a security breach.

Stability in consumer electronics
For consumer electronics, such as smart home devices, wearables, and infotainment systems, the MPU add-on enhances reliability by preventing faults in one task from affecting an entire system. This ensures smooth and uninterrupted device operation, even if individual tasks encounter issues.
How the MPU add-on works
Memory protection is a mechanism for controlling memory-access rights. It is part of most modern processor architectures and operating systems, and it prevents possible bugs or even malware contained in a task from affecting an entire system. For memory protection to work, certain application tasks must be restricted from accessing key system components like memory, special function registers, and the operating system's control structures, which could affect other tasks or the operating system itself.
To enhance safety and security, MPU applications consist of two parts: a privileged section, responsible for system initialization and driver management, and an unprivileged section. If an unprivileged task violates access restrictions or triggers a fault, the MPU add-on detects the violation, automatically terminates it, and, if needed, executes a callback function to handle the event.
The MPU add-on is available for embOS-Classic and embOS-Ultra.
MPU support in embOS-Safe

For safety-oriented system designs, memory isolation plays a key role. Where applicable, embOS-Safe already integrates MPU-based task isolation into its certified safety concept.
embOS-Safe is the safety-certified edition of embOS for applications requiring compliance with standards such as IEC 61508 SIL 3, IEC 62304 Class C, and ISO 26262 ASIL D, helping developers build reliable and secure embedded systems.
Latest news
Get in touch with us
Have questions or need assistance? Our Embedded Experts are here to help!
Reach out to us for:
- Licensing quotes
- Technical inquiries
- Project support
