US2023252156A1PendingUtilityA1

Artificial reality system with multi-stage boot process

Assignee: META PLATFORMS TECH LLCPriority: Jul 1, 2020Filed: Apr 6, 2023Published: Aug 10, 2023
Est. expiryJul 1, 2040(~13.9 yrs left)· nominal 20-yr term from priority
G06F 21/575G06F 1/04G06F 21/552G06F 21/62G06F 21/74G06F 21/64G06F 2221/034G06F 3/011G06F 3/012G06F 3/017G06F 3/0304G06F 9/4401G06F 9/4411G06F 1/163G06F 1/1686
67
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques are described for improving security of a boot sequence of a system, such as an artificial reality system. In some examples, a method includes configuring, by a boot sequencing system, attack detection circuitry based on configuration information accessed from a first storage device; after configuring the attack detection circuitry, starting, by the boot sequencing system, a root of trust processor to initiate a boot sequence; enabling access, by the root of trust processor during the boot sequence, to secret information stored in a second storage device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system comprising a processor, attack detection circuitry, a storage device, and a boot sequencer, wherein the boot sequencer is configured to:
 configure, using a first internal clock signal, the attack detection circuitry;   after configuring the attack detection circuitry, configure a second internal clock signal;   clock the processor using the second internal clock signal; and   enable access, by the processor, to information stored in the storage device.   
     
     
         2 . The system of  claim 1 , wherein the storage device is a secure storage device, and wherein to configure the attack detection circuitry, the boot sequencer is further configured to:
 configure the attack detection circuitry using information accessed from a non-secure storage device.   
     
     
         3 . The system of  claim 2 , wherein to configure the attack detection circuitry using the information accessed from the non-secure storage device, the boot sequencer is further configured to:
 adjust sensitivity of the attack detection circuitry.   
     
     
         4 . The system of  claim 2 , wherein to configure the attack detection circuitry using the information accessed from the non-secure storage device, the boot sequencer is further configured to enable detection of at least one of:
 frequency, sequencing, or temperature attacks.   
     
     
         5 . The system of  claim 2 , wherein the boot sequencer is further configured to:
 prior to configuring the attack detection circuitry using the information accessed from a non-secure storage device, enable operation of the attack detection circuitry to monitor for voltage glitching attacks.   
     
     
         6 . The system of  claim 2 , wherein to configure the second internal clock signal, the boot sequencer is further configured to:
 configure the second internal clock signal using trim information accessed from the non-secure storage.   
     
     
         7 . The system of  claim 6 , wherein to configure the second internal clock signal using trim information accessed from the non-secure storage, the boot sequencer is further configured to:
 adjust the second internal clock signal to operate within a narrower frequency range than the first internal clock signal.   
     
     
         8 . The system of  claim 1 , wherein the processor is a root of trust processor, and wherein the boot sequencer is further configured to:
 enable efficient access to the root of trust processor for testing purposes.   
     
     
         9 . The system of  claim 1 , wherein the system further comprises a port, and wherein the boot sequencer is further configured to:
 receive a voltage on the port; and   responsive to receiving the voltage on the port, generate an internal reset signal and the first internal clock signal.   
     
     
         10 . A system comprising a storage device and processing circuitry, wherein the processing circuitry is capable of accessing the storage device and is configured to:
 configure, using a first internal clock signal, attack detection circuitry;   after configuring the attack detection circuitry, configure a second internal clock signal;   clock a processor using the second internal clock signal; and   enable access, by the processor, to information stored in a secure storage device.   
     
     
         11 . The system of  claim 10 , wherein to configure the attack detection circuitry, the processing circuitry is further configured to:
 configure the attack detection circuitry using information accessed from a non-secure storage device.   
     
     
         12 . The system of  claim 11 , wherein to configure the attack detection circuitry using the information accessed from the non-secure storage device, the processing circuitry is further configured to:
 adjust sensitivity of the attack detection circuitry.   
     
     
         13 . The system of  claim 11 , wherein to configure the attack detection circuitry using the information accessed from the non-secure storage device, the processing circuitry is further configured to enable detection of at least one of:
 frequency, sequencing, or temperature attacks.   
     
     
         14 . The system of  claim 11 , wherein to configure the second internal clock signal, the processing circuitry is further configured to:
 configure the second internal clock signal using trim information accessed from the non-secure storage.   
     
     
         15 . The system of  claim 14 , wherein to configure the second internal clock signal using trim information accessed from the non-secure storage, the processing circuitry is further configured to:
 adjust the second internal clock signal to operate within a narrower frequency range than the first internal clock signal.   
     
     
         16 . The system of  claim 11 , wherein the processing circuitry is further configured to:
 prior to configuring the attack detection circuitry using the information accessed from a non-secure storage device, enable operation of the attack detection circuitry to monitor for voltage glitching attacks.   
     
     
         17 . The system of  claim 10 , wherein the processor is a root of trust processor, and wherein the processing circuitry is further configured to:
 enable efficient access to the root of trust processor for testing purposes.   
     
     
         18 . The system of  claim 10 , wherein the system further comprises a port, and wherein the processing circuitry is further configured to:
 receive a voltage on the port; and   responsive to receiving the voltage on the port, generate an internal reset signal and the first internal clock signal.   
     
     
         19 . A non-transitory computer-readable medium comprising instructions that, when executed, configure processing circuitry of a computing system to:
 configure, using a first internal clock signal, attack detection circuitry;   after configuring the attack detection circuitry, configure a second internal clock signal;   clock a processor using the second internal clock signal; and   enable access, by the processor, to information stored in a secure storage device.   
     
     
         20 . The non-transitory computer-readable medium of  claim 19 , wherein the instructions further configure processing circuitry to:
 configure the attack detection circuitry using information accessed from a non-secure storage device; and   configure the second internal clock signal using trim information accessed from the non-secure storage.

Join the waitlist — get patent alerts

Track US2023252156A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.