Implementing access control by system-on-chip
Abstract
Systems and methods for implementing access control by systems-on-chip (SoCs). An example SoC may comprise: an access control unit comprising a secure memory for storing access control data, the access control unit to: receive a message comprising an access control data item; store the access control data item in the secure memory; perform at least one of: authenticating the message using a message digest function, or validating contents of the secure memory by comparing a stored reference value with a calculated value of a message digest function of the contents of the secure memory; and control, in view of the access control data item, access by an initiator device to a target device.
Claims
exact text as granted — not AI-modified1 . A system-on-chip (SoC), comprising:
an access control unit comprising a secure memory for storing access control data, the access control unit to: receive a message comprising an access control data item; store the access control data item in the secure memory; update a state variable by applying a predetermined function to a current value of the state variable and a hash of contents of the secure memory; calculate a message digest by applying a cryptographic hash function to contents of the message and the state variable; authenticate the message using the message digest; and control, in view of the access control data item, access by an initiator device to a target device.
2 . The SoC of claim 1 , wherein the access control data item comprises an access control rule including at least one of: an identifier of the initiator device, an identifier of the target device, an address range, an access permission, or an access authorization type.
3 . (canceled)
4 . The SoC of claim 1 , wherein the access control unit is implemented by a network-on-chip (NoC) comprising a filtering firewall to enforce access control in view of the access control data item while transporting at least one of data frames or electric signals between the initiator device and the target device.
5 . The SoC of claim 1 , wherein the access control unit is implemented by a memory management unit (MMU) to enforce access control in view of the access control data item while translating a first address to a second address referencing a memory location on the target device.
6 - 7 . (canceled)
8 . A system-on-chip (SoC), comprising:
an access control unit comprising a first secure memory and a second secure memory for storing access control data, the access control unit to:
receive a message comprising an access control data item;
store the access control data item in the secure memory;
update a state variable by applying a predetermined function to a current value of the state variable and a hash of contents of the secure memory;
calculate a secure memory digest by applying a cryptographic hash function to contents of the message and the state variable;
validate the contents of the secure memory by comparing a stored reference value to the secure memory digest; and
control, in view of the access control data item, access by an initiator device to a target device.
9 . (canceled)
10 . A method, comprising:
receiving, by a system-on-chip (SoC), a message comprising an access control data item; storing the access control data item in a secure memory; updating a state variable by applying a predetermined function to a current value of the state variable and a hash of contents of the secure memory; calculating a message digest by applying a cryptographic hash function to contents of the message and the state variable; authenticating the message using the message digest; and controlling, in view of the access control data item, access by an initiator device to a target device.
11 - 12 . (canceled)
13 . The method of claim 10 , wherein the access control data item comprises an access control rule including at least one of: an identifier of the initiator device, an identifier of the target device, an address range, an access permission, or an access authorization type.
14 - 17 . (canceled)
18 . The method of claim 10 , wherein controlling the access further comprises:
translating a virtual address to a physical address, wherein the physical address references a memory location on the target device.
19 - 20 . (canceled)
21 . The SoC of claim 1 , wherein the initiator device is provided by one of: a central processing unit (CPU), a graphical processing unit (GPU), or a cryptographic core.
22 . The SoC of claim 1 , wherein the target device is provided by one of: a memory device, a storage device, or an input/output (I/O) device.
23 . The SoC of claim 1 , wherein the access control unit is further to:
validate the contents of the secure memory by comparing a stored reference value to the message digest.
24 . The SoC of claim 8 , wherein the access control data item comprises an access control rule including at least one of: an identifier of the initiator device, an identifier of the target device, an address range, an access permission, or an access authorization type.
25 . The SoC of claim 8 , wherein the access control unit is implemented by a network-on-chip (NoC) comprising a filtering firewall to enforce access control in view of the access control data item while transporting at least one of data frames or electric signals between the initiator device and the target device.
26 . The SoC of claim 8 , wherein the access control unit is implemented by a memory management unit (MMU) to enforce access control in view of the access control data item by translating a first address to a second address referencing a memory location on the target device.
27 . The SoC of claim 8 , wherein the initiator device is provided by one of: a central processing unit (CPU), a graphical processing unit (GPU), or a cryptographic core.
28 . The SoC of claim 8 , wherein the target device is provided by one of: a memory device, a storage device, or an input/output (I/O) device.
29 . The method of claim 10 , further comprising:
validating the contents of the secure memory by comparing a stored reference value to the message digest.
30 . The method of claim 10 , wherein the initiator device is provided by one of: a central processing unit (CPU), a graphical processing unit (GPU), or a cryptographic core.
31 . The method of claim 10 , wherein the target device is provided by one of: a memory device, a storage device, or an input/output (I/O) device.
32 . The method of claim 10 , wherein authenticating the message further comprises:
calculating a hash message authentication code (HMAC) using the message digest functionJoin the waitlist — get patent alerts
Track US2020125756A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.