US2020151364A1PendingUtilityA1

Migration of trusted security attributes to a security engine co-processor

Assignee: INTEL CORPPriority: Jul 1, 2016Filed: Nov 11, 2019Published: May 14, 2020
Est. expiryJul 1, 2036(~9.9 yrs left)· nominal 20-yr term from priority
G06F 21/70
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system-on-chip (SoC) includes a host CPU on a CPU fabric, the host CPU including multiple processor cores, each associated with multiple security attributes. The SoC includes a secure asset on a network-on-chip and a security co-processor. The security co-processor includes circuitry to detect requests from the processor cores targeting the secure asset and security function processing requests, to determine, based on associated security attributes, whether the core or function is authorized to access the secure asset, to allow the request to be issued, if the core or function is so authorized, and to prevent its issuance, if not. The determination may be dependent on a signal from the CPU fabric indicating whether the host CPU can modify its security attributes or they are locked down. The security co-processor may have the highest security level and may be the only master on the SoC that can access the secure asset.

Claims

exact text as granted — not AI-modified
1 . A system, comprising:
 a central processing unit (CPU) fabric communicatively coupled to a processor core, the CPU fabric comprising a first storage location to store a first security identifier value associated with the processor core; and   a security engine, comprising:
 a processor to execute instructions; and 
 circuitry to:
 obtain a request from the processor core to perform a security function targeting a secure asset; 
 determine that access to the secure asset by the security function is authorized based on the security identifier associated with the processor core; and 
 allow the request to be issued over the on-chip network. 
 
   
     
     
         2 . The system of  claim 1 , wherein
 the CPU fabric further comprises a second storage location to store a security identifier lock value associated with the processor core;   wherein the security engine further comprises circuitry to obtain a security confirmation signal from the CPU fabric, where the security confirmation signal, when equal to a first value, indicates a determination that the first security identifier value represents a security state other than a highest privilege state supported in the system and that the security identifier lock value indicates that the first security identifier value is not modifiable; and   wherein to determine that access to the secure asset by the security function is authorized, the security engine further comprises circuitry to:
 receive the security confirmation signal from the CPU fabric; and 
 determine that the security confirmation signal is equal to the first value. 
   
     
     
         3 . The system of  claim 2 , wherein:
 the CPU fabric further comprises a third storage location to store a value of a boot mode indicator associated with the processor core; and   when the security confirmation signal is equal to the first value, the security confirmation signal further indicates that the value of the boot mode indicator indicates that the processor core is not in boot mode.   
     
     
         4 . The system of  claim 2 , wherein:
 the processor core is one of a plurality of processor cores communicatively coupled to the CPU fabric, wherein each processor core is associated with a respective security identifier value, a respective security identifier lock value, and a respective boot mode indicator value; and   when the security confirmation signal is equal to the first value, the security confirmation signal indicates that, for each of the plurality of processor cores:
 the respective security identifier value represents a security state other than the highest privilege state supported in the system; 
 the respective security identifier lock value indicates that the respective security identifier value is not modifiable; and 
 the respective boot mode indicator value indicates that the processor core is not in boot mode. 
   
     
     
         5 . (canceled) 
     
     
         6 . The system of  claim 1 , wherein:
 the security engine is associated with a second security identifier value representing a highest privilege state supported in the system;   the secure asset is associated with a first security identifier requirement that specifies that requests targeting the secure asset must include an encoding of the second security identifier;   the security engine further comprising circuitry to:
 provide, to the security asset, the request comprising an encoding of the second security identifier value representing the highest privilege state supported in the system. 
   
     
     
         7 . (canceled) 
     
     
         8 . (canceled) 
     
     
         9 . (canceled) 
     
     
         10 . (canceled) 
     
     
         11 . A method comprising:
 obtaining, by a security co-processor in a system-on-chip (SoC), a request to perform a security function targeting a secure asset on an on-chip network of the SoC, the request obtained from a processor core of a host central processing unit (CPU); and   determining, by the security co-processor that access to the secure asset is authorized based on stored values of one or more security attributes associated with the processor core of the host CPU.   
     
     
         12 . The method of  claim 11 , further comprising:
 determining that access to the security asset by the security function is not authorized; and   preventing issuing of the request over the on-chip network.   
     
     
         13 . The method of  claim 11 , further comprising:
 obtaining, from a CPU fabric of the SoC, an indication of a security state of the host CPU; and   wherein determining that access to the secure asset by the security function is authorized comprises determining that the processor core is able to modify the stored values of the one or more security attributes associated with the processor core based on the indication of the security state of the host CPU.   
     
     
         14 . (canceled) 
     
     
         15 . The method of  claim 11 , wherein the security co-processor is associated with a second security identifier value representing a highest privilege state supported in the SoC;
 a security requirement assigned to the secure asset specifies that access requests targeting the secure asset require an encoding of the second security identifier; and   the method further comprises:
 issuing, by the security co-processor, an access request targeting the secure asset, the access request comprising an encoding of the second security identifier value representing the highest privilege state supported in the system. 
   
     
     
         16 . (canceled) 
     
     
         17 . (canceled) 
     
     
         18 . A security co-processor on a system-on-chip (SoC), comprising:
 a processor including circuitry to execute instructions; and   circuitry to:
 obtain an access request associated with a secure asset of the SoC; 
   determine that a security mechanism on a host CPU of the SoC has been successfully initialized; and   issue the access request over the on-chip network.   
     
     
         19 . The security co-processor of  claim 18 , wherein:
 to determine that the security mechanism on the host CPU on the SoC has been successfully initialized, the security co-processor comprises circuitry to:
 receive a security confirmation signal from the SoC; and 
   determine that the security confirmation signal is equal to a first value, wherein when the security confirmation signal being equal to the first value indicates that the host CPU is in a security state in which security attributes of the host CPU cannot be modified by the host CPU.   
     
     
         20 . The security co-processor of  claim 18 , wherein
 the security co-processor further comprises circuitry to generate the access request during performance of a security function, the access request comprising an encoding of a security identifier value associated with the security co-processor, wherein
 the security identifier value meets a security requirement associated with the secure asset that allows access requests targeting the secure asset to be granted. 
   
     
     
         21 . The method of  claim 11 , further comprising:
 responsive to a determination that access to the secure asset by the security function is authorized, issuing, by the security engine, an access request over the on-chip network to the secure asset; and   receiving, by the security engine, a security confirmation signal indicating a determination that a first security identifier value associated with the processor core represents a highest privilege state supported in the SoC and that a security identifier lock value indicates that the first security identifier value is not modifiable.   
     
     
         22 . The system of  claim 1 , wherein a security mechanism is extended to the security co-processor from a CPU fabric of the SoC. 
     
     
         23 . The system of  claim 1 , wherein the security co-processor is outside the CPU fabric and distinct from a host CPU on the CPU fabric. 
     
     
         24 . The system of  claim 2 , wherein the first value indicates that the value of the security confirmation signal is asserted. 
     
     
         25 . The method of  claim 11 , wherein the request is provided by a processor core of a host central processing unit (CPU). 
     
     
         26 . The method of  claim 11 , further comprising:
 determining that access to the security asset by the security function is not authorized based on the security identifier associated with the processor core; and   preventing issuance of the request over the on-chip network.

Join the waitlist — get patent alerts

Track US2020151364A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.