Migration of trusted security attributes to a security engine co-processor
Abstract
A system-on-chip (SoC) includes a host CPU on a CPU fabric, the host CPU including multiple processor cores, each associated with multiple security attributes. The SoC includes a secure asset on a network-on-chip and a security co-processor. The security co-processor includes circuitry to detect requests from the processor cores targeting the secure asset and security function processing requests, to determine, based on associated security attributes, whether the core or function is authorized to access the secure asset, to allow the request to be issued, if the core or function is so authorized, and to prevent its issuance, if not. The determination may be dependent on a signal from the CPU fabric indicating whether the host CPU can modify its security attributes or they are locked down. The security co-processor may have the highest security level and may be the only master on the SoC that can access the secure asset.
Claims
exact text as granted — not AI-modified1 . A system, comprising:
a central processing unit (CPU) fabric communicatively coupled to a processor core, the CPU fabric comprising a first storage location to store a first security identifier value associated with the processor core; and a security engine, comprising:
a processor to execute instructions; and
circuitry to:
obtain a request from the processor core to perform a security function targeting a secure asset;
determine that access to the secure asset by the security function is authorized based on the security identifier associated with the processor core; and
allow the request to be issued over the on-chip network.
2 . The system of claim 1 , wherein
the CPU fabric further comprises a second storage location to store a security identifier lock value associated with the processor core; wherein the security engine further comprises circuitry to obtain a security confirmation signal from the CPU fabric, where the security confirmation signal, when equal to a first value, indicates a determination that the first security identifier value represents a security state other than a highest privilege state supported in the system and that the security identifier lock value indicates that the first security identifier value is not modifiable; and wherein to determine that access to the secure asset by the security function is authorized, the security engine further comprises circuitry to:
receive the security confirmation signal from the CPU fabric; and
determine that the security confirmation signal is equal to the first value.
3 . The system of claim 2 , wherein:
the CPU fabric further comprises a third storage location to store a value of a boot mode indicator associated with the processor core; and when the security confirmation signal is equal to the first value, the security confirmation signal further indicates that the value of the boot mode indicator indicates that the processor core is not in boot mode.
4 . The system of claim 2 , wherein:
the processor core is one of a plurality of processor cores communicatively coupled to the CPU fabric, wherein each processor core is associated with a respective security identifier value, a respective security identifier lock value, and a respective boot mode indicator value; and when the security confirmation signal is equal to the first value, the security confirmation signal indicates that, for each of the plurality of processor cores:
the respective security identifier value represents a security state other than the highest privilege state supported in the system;
the respective security identifier lock value indicates that the respective security identifier value is not modifiable; and
the respective boot mode indicator value indicates that the processor core is not in boot mode.
5 . (canceled)
6 . The system of claim 1 , wherein:
the security engine is associated with a second security identifier value representing a highest privilege state supported in the system; the secure asset is associated with a first security identifier requirement that specifies that requests targeting the secure asset must include an encoding of the second security identifier; the security engine further comprising circuitry to:
provide, to the security asset, the request comprising an encoding of the second security identifier value representing the highest privilege state supported in the system.
7 . (canceled)
8 . (canceled)
9 . (canceled)
10 . (canceled)
11 . A method comprising:
obtaining, by a security co-processor in a system-on-chip (SoC), a request to perform a security function targeting a secure asset on an on-chip network of the SoC, the request obtained from a processor core of a host central processing unit (CPU); and determining, by the security co-processor that access to the secure asset is authorized based on stored values of one or more security attributes associated with the processor core of the host CPU.
12 . The method of claim 11 , further comprising:
determining that access to the security asset by the security function is not authorized; and preventing issuing of the request over the on-chip network.
13 . The method of claim 11 , further comprising:
obtaining, from a CPU fabric of the SoC, an indication of a security state of the host CPU; and wherein determining that access to the secure asset by the security function is authorized comprises determining that the processor core is able to modify the stored values of the one or more security attributes associated with the processor core based on the indication of the security state of the host CPU.
14 . (canceled)
15 . The method of claim 11 , wherein the security co-processor is associated with a second security identifier value representing a highest privilege state supported in the SoC;
a security requirement assigned to the secure asset specifies that access requests targeting the secure asset require an encoding of the second security identifier; and the method further comprises:
issuing, by the security co-processor, an access request targeting the secure asset, the access request comprising an encoding of the second security identifier value representing the highest privilege state supported in the system.
16 . (canceled)
17 . (canceled)
18 . A security co-processor on a system-on-chip (SoC), comprising:
a processor including circuitry to execute instructions; and circuitry to:
obtain an access request associated with a secure asset of the SoC;
determine that a security mechanism on a host CPU of the SoC has been successfully initialized; and issue the access request over the on-chip network.
19 . The security co-processor of claim 18 , wherein:
to determine that the security mechanism on the host CPU on the SoC has been successfully initialized, the security co-processor comprises circuitry to:
receive a security confirmation signal from the SoC; and
determine that the security confirmation signal is equal to a first value, wherein when the security confirmation signal being equal to the first value indicates that the host CPU is in a security state in which security attributes of the host CPU cannot be modified by the host CPU.
20 . The security co-processor of claim 18 , wherein
the security co-processor further comprises circuitry to generate the access request during performance of a security function, the access request comprising an encoding of a security identifier value associated with the security co-processor, wherein
the security identifier value meets a security requirement associated with the secure asset that allows access requests targeting the secure asset to be granted.
21 . The method of claim 11 , further comprising:
responsive to a determination that access to the secure asset by the security function is authorized, issuing, by the security engine, an access request over the on-chip network to the secure asset; and receiving, by the security engine, a security confirmation signal indicating a determination that a first security identifier value associated with the processor core represents a highest privilege state supported in the SoC and that a security identifier lock value indicates that the first security identifier value is not modifiable.
22 . The system of claim 1 , wherein a security mechanism is extended to the security co-processor from a CPU fabric of the SoC.
23 . The system of claim 1 , wherein the security co-processor is outside the CPU fabric and distinct from a host CPU on the CPU fabric.
24 . The system of claim 2 , wherein the first value indicates that the value of the security confirmation signal is asserted.
25 . The method of claim 11 , wherein the request is provided by a processor core of a host central processing unit (CPU).
26 . The method of claim 11 , further comprising:
determining that access to the security asset by the security function is not authorized based on the security identifier associated with the processor core; and preventing issuance of the request over the on-chip network.Join the waitlist — get patent alerts
Track US2020151364A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.