System, Apparatus and Method for Secure Monotonic Counter Operations in a Processor
Abstract
In one embodiment, an apparatus includes: at least one core to execute instructions, the at least one core formed on a semiconductor die; a first memory formed on the semiconductor die, the first memory comprising a non-volatile random access memory, the first memory to store a first entry to be a monotonic counter, the first entry including a value field and a status field; and a control circuit, wherein the control circuit is to enable access to the first entry if the apparatus is in a secure mode and otherwise prevent the access to the first entry. Other embodiments are described and claimed.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An apparatus comprising:
at least one core to execute instructions, the at least one core formed on a semiconductor die; a first memory formed on the semiconductor die, the first memory comprising a non-volatile random access memory, the first memory to store a first entry comprising a monotonic counter, the first entry including a value field and a status field; and a control circuit coupled to the first memory, wherein the control circuit is to enable access to the first entry when the apparatus is in a secure mode and otherwise prevent the access to the first entry.
2 . The apparatus of claim 1 , wherein the control circuit is to update a value stored in the value field responsive to a first user-level monotonic counter instruction.
3 . The apparatus of claim 2 , wherein the status field comprises a rollover indicator to indicate whether the value stored in the value field has rolled over and a second indicator to indicate whether a backup storage for the monotonic counter is corrupt.
4 . The apparatus of claim 2 , wherein the control circuit is to cause the value field to be set to a first value received from a second computing system responsive to a second user-level monotonic counter instruction, wherein the first value comprises a consumption level for a secure content.
5 . The apparatus of claim 4 , wherein the apparatus is to prevent access to the secure content if the first value at least meets a policy threshold.
6 . The apparatus of claim 2 , wherein the first entry further comprises an address field, wherein the control circuit is to access the first entry when the first user-level monotonic counter instruction includes an identifier corresponding to an address stored in the address field.
7 . The apparatus of claim 1 , wherein the control circuit comprises a policy manager to enable access to a secure content if a value stored in the value field is less than a policy threshold, and otherwise to prevent the access to the secure content.
8 . The apparatus of claim 1 , wherein the non-volatile random access memory comprises a spin torque transfer memory.
9 . The apparatus of claim 1 , wherein the apparatus is to execute in a trusted execution environment, and a trusted computing base including the monotonic counter is wholly included in the semiconductor die.
10 . The apparatus of claim 1 , wherein the at least one core comprises the control circuit.
11 . A system comprising:
a processor comprising:
at least one core to execute instructions;
at least one cache memory;
a non-volatile random access memory to store a table of monotonic counters, wherein the monotonic counters include an identifier field, a value field and a status field; and
a logic, responsive to a request by a first application, to atomically update a first monotonic counter of the table of monotonic counters and provide an updated value of the first monotonic counter to the first application, wherein the first application is to allow secure content associated with the first monotonic counter to be output via a display when the updated value of the first monotonic counter is less than a threshold;
a storage to store the secure content; and the display to output the secure content.
12 . The system of claim 11 , wherein the non-volatile random access memory comprises a spin transfer torque memory and the at least one core comprises the logic.
13 . The system of claim 11 , wherein the threshold is based on a license associated with the secure content.
14 . The system of claim 11 , wherein the logic is to atomically update the first monotonic counter and provide the updated value to the first application when the first application is of a first privilege level and the at least one core is in the first privilege level.
15 . A system on chip (SoC) comprising:
a semiconductor device comprising:
at least one core to execute instructions;
at least one cache memory;
a non-volatile random access memory to store a table of monotonic counters, wherein the monotonic counters include an identifier field, a value field and a status field; and
a control circuit coupled to the non-volatile random access memory, the control circuit to:
responsive to receipt of a request from a requester to update a first monotonic counter of the plurality of monotonic counters, determine whether the SoC is in a first security mode;
when it is determined that the SoC is in the first security mode, access the first monotonic counter using an identifier associated with the request;
increment a value of the first monotonic counter; and
output the value of the first monotonic counter to the requester.
16 . The SoC of claim 15 , wherein the control circuit is to prevent the access to the first monotonic counter when the SoC is not in the first security mode.
17 . The SoC of claim 15 , wherein the control circuit is to:
determine, after the increment to the value of the first monotonic counter, whether the value of the first monotonic counter has rolled over; and responsive to the rollover of the value of the first monotonic counter, set a rollover indicator in the status field included in the first monotonic counter.
18 . The SoC of claim 15 , wherein the control circuit is enable access to secure content if the value of the first monotonic counter has not met a policy threshold, and otherwise to prevent the access to the secure content.
19 . The SoC of claim 15 , wherein the control circuit is to encrypt the first monotonic counter and send the encrypted first monotonic counter to a second computing system, responsive to a request to provide secure content to the second computing system.
20 . The SoC of claim 19 , wherein the control circuit is to enable the secure content and the encrypted monotonic counter to be sent to the second computing system, based at least in part on a license associated with the secure content.Join the waitlist — get patent alerts
Track US2020167294A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.