Heterogeneous processor-based trusted computing system and method with remote attestation and information independence via open connector
By using a standard open connector and a cryptographic processor between the central processing unit and heterogeneous processing units, the problems of complex hardware design and insufficient information independence in the prior art are solved, and secure information exchange and authentication between heterogeneous processors are realized.
Patent Information
- Application Number
- CN202080057426.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-08-16
- Filing Date
- 2020-08-14
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2040-08-14
AI Technical Summary
Existing technologies require dedicated chip network hardware designs for information exchange between heterogeneous processors, resulting in complex designs with insufficient flexibility, and failing to effectively achieve information independence and security protection.
By establishing static links between the central processing unit and heterogeneous processing units, using standard open connectors such as Ethernet, USB, and SPI, and avoiding dedicated chip networks in hardware design, an information-independent computing architecture is achieved, and secure communication and authentication are provided through encrypted processors.
It achieves protection of the authenticity, confidentiality and integrity of information between heterogeneous processors, simplifies the design and reduces the dependence on dedicated hardware, and is suitable for secure computing in embedded systems.
Smart Images

Figure CN114600108B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to a trusted computing for executing programs with remote attestation and information independence by heterogeneous processors through open connectors. In particular, the present disclosure relates to a secure and trusted computing architecture and method thereof. The present disclosure is directed to ensuring the authenticity, confidentiality and integrity of programs, analysis modules and processing data executed by heterogeneous processing units (e.g., Graphic Processing Unit (GPU), Neural Processing Unit (NPU), Video Processing Unit (VPU), etc.) and Central Processing Unit (CPU) through standard open connectors (e.g., Ethernet, Universal Serial Bus (USB), Serial Peripheral Interface Bus (SPI), etc.). BACKGROUND
[0002] In some researches, the idea of creating domains with specific access rights for protecting heterogeneous processors is proposed. However, such proposals usually require hardware design of a dedicated Network On Chip (NoC), e.g., a chip network firewall. As reducing the need for using dedicated hardware chips is a technical problem to be solved by those skilled in the art, in the present disclosure, by establishing static links between the cluster of Central Processing Units and heterogeneous processing units, the need for hardware design of a dedicated chip network can be reduced. Moreover, the simpler (and more limited) design in the present disclosure is not limited by the need for modification of any firmware, thus the design of the present disclosure is more suitable for use in embedded systems. In some researches, the idea of executing critical, trusted and untrusted applications in three distinct execution environments is proposed. However, in the aforementioned researches, a hardware design of a dedicated chip network (e.g., a single-write multiple-read chip network) is also used to enable the processors to freely contact different execution environments. In the present disclosure, by linking specific processors among multiple processor systems to respective execution environments, the mechanism of information independence is simplified and the use of dedicated hardware chips is thereby avoided. SUMMARY
[0003] The present disclosure provides a computer architecture and a method of operating a computer for ensuring authenticity, confidentiality and integrity of programs, deep learning (DL) or machine learning (ML) executed by a heterogeneous processing unit (XPU). The computer architecture includes a heterogeneous processing unit, an open connector and a central processing unit (CPU). The "X" in the abbreviation "XPU" for the heterogeneous processing unit stands for various types of special processing units, including but not limited to a graphic processing unit (GPU), a neural processing unit (NPU), a tensor processing unit (TPU) and a video processing unit (VPU). The standard open connector includes but is not limited to Ethernet, a peripheral component interconnect (PCI), a universal serial bus (USB) and a serial peripheral interface (SPI). The aforementioned heterogeneous processing unit is connected to the central processing unit through the aforementioned standard open connector to achieve information independence without using a hardware memory management unit (MMU) or a bus arbitration unit (BAU) and a bus multiplexing unit (BMU).
[0004] The computer architecture and the method of operating a computer of the present disclosure run the XPU as if performing a computing task in a CPU with information independence protection, and provide remote authentication support for the CPU and the XPU in an execution state. Therefore, programs, deep learning modules, machine learning modules and data among processing units (e.g., XPU, NPU and VPU) have authenticity, confidentiality and integrity guarantees, and can perform different computing tasks.
[0005] The present disclosure discloses a computer operation method for establishing a Trusted Rich Execution Environment (TREE) in a Virtual Machine (VM) implemented in a non-protected area of a system hardware platform. The non-protected area of the system hardware platform includes one or more dedicated CPUs and a dedicated area of shared memory connected to shared buses. The TREE provides protection for the authenticity, confidentiality and integrity of programs, modules and data processed in the TREE, to separate the programs, modules and data processed in the TREE from other similar methods established in the TREE and from the programs processed in the REE without the security support from the TEE. The protected area of the hardware platform includes one or more dedicated CPUs, a cryptographic processor and a protected area of memory.
[0006] The present disclosure also discloses a computer operation method for extending the information independence provided by the TREE. In order to include the TREE in an XPU connected to the CPU by an open connector, a secure communication channel is successfully established between the cryptographic processor associated with the CPU and the cryptographic processor associated with the XPU and mutual authentication is successfully completed. After that, the TREE is established in the XPU connected to the dedicated CPU by the open connector.
[0007] The present disclosure also discloses a computer operation method. By using the cryptographic processor associated with the XPU and by establishing a secure communication between the XPU and the dedicated CPU in the TREE, remote authentication of the execution state of the XPU is performed.
[0008] The computing system of the present disclosure requires the provision of two cryptographic processors, one of which is associated with the dedicated CPU and the other of which is associated with the XPU. Both cryptographic processors must be able to perform the following security functions: (1) secure boot of software executed in the TEE and the TREE; (2) mutual authentication between the dedicated CPU and the XPU; (3) secure channel between the dedicated CPU and the XPU providing protection for data source verification, data authenticity and integrity.
[0009] The computing system of the present disclosure also requires standard performance to execute the operating system functions of the processor and to interrupt the exchange of information between the XPU and the CPU through the open connector, directing the aforementioned exchange of information to the dedicated CPU in the TREE. This performance is a standard feature of the operating system.
[0010] The operating system in the present disclosure also needs to have standard performance to support secure information exchange between the dedicated CPU in the TREE and the dedicated CPU in the TEE with the cryptographic processor. Such standard performance is the basis of the TEE standard specification of the International Standardization Organization (GlobalPlatform).
[0011] The present disclosure provides an operating system, which includes a first device. The first device includes a first processing resource group and a second processing resource group. The first processing resource group is located in a protected area of a hardware platform, wherein the first processing resource group includes a first dedicated processor, a first cryptographic processor, and a first memory protection section. The second processing resource group is located in an unprotected area of the hardware platform, wherein the second processing resource group includes a second dedicated processor and a second memory protection section. A trusted specific operating system is executed in a trusted execution environment, and the trusted execution environment is implemented in the first processing resource group, wherein a first trusted specific service program is run in the trusted execution environment with the support of the trusted specific operating system. A trusted open operating system is executed in a trusted open execution environment, wherein the trusted open execution environment is implemented in the second processing resource group, wherein a first trusted open application is run in the trusted open execution environment with the support of the trusted specific operating system.
[0012] In some embodiments of the present disclosure, the trusted open execution environment of the second processing resource group is implemented by a virtual machine.
[0013] In some embodiments of the present disclosure, data transmission between the trusted execution environment implemented in the first processing resource group and the trusted open execution environment implemented in the second processing resource group is protected by confidentiality, integrity, and authentication services. Programs and data stored in the first memory protection section in the first processing resource group and used in the trusted execution environment, and programs and data stored in the second memory protection section in the second processing resource group and used in the trusted open execution environment are protected by confidentiality, integrity, and authentication services.
[0014] In some embodiments of the present disclosure, the first device further includes a third processing resource group in the unprotected area of the hardware platform, and the third processing resource group includes a first non-dedicated processor and a first memory unprotected section, wherein a general operating system is executed in an open execution environment, and the open execution environment is implemented in the third processing resource group.
[0015] In some embodiments of the present disclosure, programs and data run in the open execution environment implemented in the third processing resource group are not protected by confidentiality, integrity, and authentication services.
[0016] In some embodiments of the present disclosure, in response to the trusted open execution environment being idle or deactivated, the virtual machine implemented in the trusted open execution environment is terminated and the second set of processing resources is released while the second dedicated processor becomes a non-dedicated processor and the second memory protection segment becomes a memory unprotected segment.
[0017] In some embodiments of the present disclosure, the first device further comprises a shared bus connected with the open connector, the first memory protection segment, the second memory protection segment and the first memory unprotected segment are connected to the shared bus and wherein the first cryptographic processor is connected to the shared bus.
[0018] In some embodiments of the present disclosure, a second device is further included. The second device is statically connected to the first device through the open connector. The second device comprises a fourth set of processing resources. The fourth set of processing resources is disposed in a protected area of the hardware platform. The fourth set of processing resources comprises a third dedicated processor, a second cryptographic processor and a dedicated memory.
[0019] In some embodiments of the present disclosure, the second device further comprises a dedicated bus connected with the open connector, a dedicated memory connected with the dedicated bus and a second cryptographic processor connected with the dedicated bus, the first cryptographic processor in the first set of processing resources is used to perform mutual authentication between the first device and the second device and to provide confidentiality, integrity and authentication service protection to data transmitted through the open connector. The second cryptographic processor in the fourth set of processing resources is used to perform mutual authentication between the first device and the second device and to provide confidentiality, integrity and authentication service protection to data transmitted through the open connector.
[0020] In some embodiments of the present disclosure, the open connector is a communication channel implemented by a standardized protocol to support bidirectional exchange of information between two devices.
[0021] In some embodiments of the present disclosure, the trusted execution environment is a software execution environment for performing specific cryptographic functions, the trusted execution environment is a protected area of a hardware platform implemented in the device, and the trusted execution environment runs a trusted specific operating system.
[0022] In some embodiments of the present disclosure, the trusted open execution environment is a software execution environment for executing trusted general-purpose applications, the trusted open execution environment in the unprotected area of the hardware platform of the device is implemented as a virtual machine, and the trusted open execution environment runs a trusted general-purpose operating system.
[0023] In some embodiments of the present disclosure, a trusted specific operating system is an operating system constructed to support the execution of cryptographic and security functions, the authenticity and integrity of the target code of the trusted specific operating system is verified by a trusted authority and certified by a digital signature of the target code, wherein the trusted specific operating system is loaded into a trusted execution environment in a first secure boot procedure, and the trusted specific operating system is started and the digital signature of the trusted specific operating system is certified when the device is started or reset.
[0024] In some embodiments of the present disclosure, a trusted generic operating system is constructed to support the execution of trusted generic applications, wherein the authenticity and integrity of the target code of the trusted generic operating system is certified by a trusted authority and verified by a digital signature of the target code, the trusted generic operating system is loaded into a trusted open execution environment in a second secure boot procedure and the trusted generic operating system is started and executed by a security function of the trusted execution environment when the virtual machine of the trusted open execution environment is implemented.
[0025] In some embodiments of the present disclosure, a trusted specific service program is software with authenticity and integrity, the trusted specific service program is verified by a trusted authority and certified by a digital signature of the target code, and the trusted specific service program executes cryptographic or security functions, the output of the trusted specific service program is trusted not to be maliciously modified when the trusted specific service program is executed in a trusted execution environment.
[0026] In some embodiments of the present disclosure, a trusted generic application is software with authenticity and integrity, the trusted generic application is verified by a trusted authority and certified by a digital signature of the trusted generic application, and the output of the trusted generic application is trusted not to be maliciously modified when the trusted application is executed in a trusted open execution environment.
[0027] The present disclosure provides an operation method, the operation method includes the following steps. A trusted execution environment including a trusted specific operating system is established, wherein the trusted execution environment is implemented in a first processing resource group in a protected area of a hardware platform in a first device during a first secure boot procedure after the first device is started or the system is reset, and the first processing resource group includes a first dedicated processor and a first memory protection segment and the first cryptographic processor; a trusted open execution environment including a trusted generic operating system is established, wherein the trusted open execution environment in a second processing resource group in the protected area of the hardware platform in the first device is implemented by a virtual machine during a second secure boot procedure after the first secure boot procedure of the trusted execution environment in the first processing resource group is successful, and the second processing resource group includes a second dedicated processor and a second memory protection segment.
[0028] In some embodiments of the present disclosure, the trusted general purpose operating system of the trusted open execution environment of the first device is implemented through a second secure boot after a first secure boot of the trusted execution environment is successfully completed, the trusted general purpose operating system is authenticated through verification of a digital signature generated by a trusted authority, and is trusted by a trusted specific operating system in the trusted execution environment.
[0029] In some embodiments of the present disclosure, wherein data communicated between the trusted open execution environment and the trusted execution environment through the trusted execution environment communication agent of the first device is protected by confidentiality, integrity, and authentication services.
[0030] In some embodiments of the present disclosure, further comprising the step of establishing a trusted association between the first device and the second device by performing a mutual authentication procedure between the first cryptographic processor in the first processing resource set of the first device and the second cryptographic processor in the fourth processing resource set of the second device after successful establishment of the trusted execution environment of the first processing resource set in the first device.
[0031] In some embodiments of the present disclosure, further comprising the step of establishing secure communication between the first cryptographic processor in the first device and the second cryptographic processor in the second device with protection of confidentiality, integrity, and authentication after successful mutual authentication between the first device and the second device.
[0032] In some embodiments of the present disclosure, further comprising the step of establishing secure transmission of programs and data between the second specialized processor in the second processing resource set of the first device and the third specialized processor in the fourth processing resource set of the second device with protection of confidentiality, integrity, and authentication between the first cryptographic processor in the first processing resource set of the first device and the second cryptographic processor in the fourth processing resource set of the second device.
[0033] In some embodiments of the present disclosure, the state of a program executed by the third specialized processor in the fourth processing resource set of the second device is verified by using a signed hash value of specialized memory content generated by the second cryptographic processor, and the signed hash value is transmitted from the third specialized processor in the second device to the second specialized processor in the second processing resource set of the first device, the trusted open execution environment is implemented in the second processing resource set.
[0034] In some embodiments of the present disclosure, the first cryptographic processor of the first device is configured to perform a first secure boot of a trusted operating system in a trusted execution environment, and to perform mutual authentication between the first device and the second device, and to provide confidentiality and integrity protection for data stored in the first memory protection region and the second memory protection region, and to provide confidentiality, integrity and authenticity protection for data transmitted through the shared bus and the open connector. The second cryptographic processor of the second device is configured to perform mutual authentication between the first device and the second device, and to provide confidentiality, integrity and authenticity protection for data transmitted through the open connector.
[0035] In some embodiments of the present disclosure, the first secure boot and the second secure boot verify the authenticity and integrity of the system firmware and software by verifying the electronic signature of the hash value of the target code sent by a trusted authority, and the trusted authority is different from the provider or user of the target code.
[0036] In summary, the present disclosure extends the trusted execution environment to the second device by establishing a trusted open execution environment between the first processing resource group in the protected region of the first device and the second processing resource group in the unprotected region, thereby enabling edge computing of data processed by the processing unit in the second device in the trusted execution environment.
[0037] It should be noted that the foregoing general description and the following detailed description are examples, and are intended to provide further explanation of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0038] In order to make the above and other purposes, features, advantages and embodiments of the present disclosure more obvious and easy to understand, the drawings are described as follows:
[0039] Figure 1 FIG. 1 is a schematic diagram of the functional architecture of a heterogeneous computing system according to an embodiment of the present disclosure, the heterogeneous computing system comprising a host computing subsystem, a heterogeneous computing subsystem, and an open connector connecting the two subsystems.
[0040] Figure 2 FIG. 2 is a schematic diagram of three different execution environments of the software architecture of the heterogeneous computing system according to an embodiment of the present disclosure, the three different execution environments comprising a trusted execution environment (TEE), a trusted rich execution environment (TREE), and an extension range of the trusted rich execution environment along the hardware platform and the virtual machine monitor.
[0041] Figure 3This disclosure provides a flowchart illustrating the process of extending the scope of the Trusted Open Execution Environment (TEE) to encompass heterogeneous processing units after a system startup or reset, and after the establishment of secure communication between the central processing unit and the heterogeneous processing unit and successful mutual authentication. The TEE also includes a flowchart of the startup sequence of the TEE. Detailed Implementation
[0042] The following examples are described in detail with reference to the accompanying drawings. However, the provided examples are not intended to limit the scope of this disclosure, and the description of the structural operation is not intended to limit the order of execution. Any structure resulting from the recombination of elements and producing a device with equivalent functionality is within the scope of this disclosure. Furthermore, the accompanying drawings are for illustrative purposes only and are not drawn to their original dimensions. For ease of understanding, the same or similar elements will be designated with the same symbols in the following description.
[0043] The embodiments of this disclosure will be described in more detail below, with reference to the accompanying drawings. The same reference numerals in the drawings and description are used to denote the same or similar parts. With the advent of the Internet of Things (IoT), massive amounts of data are collected by various sensors and analyzed by computing nodes embedded in the environment. In the emerging paradigm of edge computing, heterogeneous computing systems, such as edge computing nodes equipped with CPUs, GPUs, NPUs, and VPUs (collectively referred to as XPUs), are often used to perform real-time data analysis for multiple users from nearby data sources. To support the needs of multi-tenancy, such as allowing multiple users to perform computing tasks on a shared platform while maintaining information privacy and independence and adhering to individual user usage policies, heterogeneous computing systems are required to implement information independence with authenticity, confidentiality, and integrity across the computing tasks of different users. However, due to the lack of hardware virtualization support in embedded heterogeneous computing systems, system-level information independence cannot be fully implemented in edge computing nodes.
[0044] A software system architecture and a program method are provided in the present disclosure to exchange information through Input / Output Channel (I / O Channel) and without using shared memory, thereby implementing information authenticity, confidentiality and integrity protection for information exchanged between a CPU and an XPU. The present disclosure includes a method for establishing a Trusted Relaxed Execution Environment (TREE) as a Virtual Machine (VM) in an unprotected area of a hardware platform in a host computer. The host computer is provided with a CPU that can support confidential computing and trusted computing of general application programs. The method further includes extending the protection range of the TREE to cover a heterogeneous computer configured with an XPU, wherein the XPU configured in the heterogeneous computer is connected to the host computer through an open connector. Furthermore, the method further includes performing remote authentication on the state of the CPU in the host computer and on the state of the XPU in the heterogeneous computer.
[0045] The following embodiments relate to a system architecture.
[0046] Reference is made to Figure 1 . Figure 1 A schematic diagram of a functional architecture of a heterogeneous computing system 100 according to an embodiment of the present disclosure is shown. The heterogeneous computing system 100 includes a host computing subsystem 110 (e.g., a first device), a heterogeneous computing subsystem 120 (e.g., a second device), and an open connector 130 connecting the two subsystems. The heterogeneous computing subsystem 120 is statically connected to the host computing subsystem 110 through the open connector 130. The open connector 130 is defined as a communication channel implemented by a standard protocol supporting bidirectional information exchange between two devices. The open connector 130 includes, but is not limited to, a standard communication channel that can be used for information exchange by multiple subsystems at the same time and does not have inherent information protection, such as Ethernet, Universal Serial Bus (USB), and Serial Peripheral Interface (SPI).
[0047] As shown in Figure 1 , the host computing subsystem 110 includes a first dedicated processor (e.g., a dedicated central processing unit 112A as shown in Figure 1 ), a second dedicated processor (e.g., a dedicated central processing unit 112B as shown in Figure 1 ), a first non-dedicated processor (e.g., a non-dedicated central processing unit 112C as shown in Figure 1 ), a shared bus 115, a first encryption processor (e.g., an encryption processor 113 as shown in Figure 1 ), a first memory protection section (e.g., a memory protection section 114A as shown in Figure 1the shared memory protection segment 111A), a second memory protection segment (e.g. Figure 1 the shared memory protection segment 111B), a first memory protection segment (e.g. Figure 1 the shared memory unprotected segment 111C). The shared bus 115 is connected to the open connector 130. The dedicated central processing unit 112A, the encryption processor 113, the memory protection segments 111A and 111B, and the memory unprotected segment 111C are connected to the shared bus 115.
[0048] The memory protection segments 111A and 111B are protected by memory encryption performed by the encryption processor 113, or by access control implemented by memory management hardware integrated to the shared memory.
[0049] With respect to the main computing subsystem 110, the encryption processor 113 performs two sets of functions as explained below. First, the encryption processor 113 acts as a hardware root-of-trust that can perform secure boot of system software and remote attestation of the state of the central processing unit and the shared memory with a remote verifier. The encryption processor 113 acts as a cryptographic processor that can provide data encryption and integrity protection of data stored in the protected region of the shared memory.
[0050] With respect to the main computing subsystem 110 and the heterogeneous computing subsystem 120, the encryption processor 113 performs mutual authentication between the main computing subsystem 110 and the heterogeneous computing subsystem 120. The encryption processor 113 provides protection of the integrity, confidentiality, and authenticity of programs, modules, and data transmitted over the open connector 130.
[0051] The main computing subsystem 110 and the heterogeneous computing subsystem 120 transmit programs, modules, and data over the open connector 130.
[0052] The heterogeneous computing subsystem 120 includes a third dedicated processor (e.g. Figure 1 the heterogeneous processing unit 122), a dedicated bus 125, a second encryption processor (e.g. Figure 1 the encryption processor 123), and a dedicated memory 121 used by the heterogeneous processing unit 122. The heterogeneous processing unit 122, the encryption processor 123, and the dedicated memory 121 are internally connected to the dedicated bus 125.
[0053] The encryption processor 123 in the processing resource group 124A performs mutual authentication between the heterogeneous computing subsystem 120 and the main computing subsystem 110, and provides protection of the integrity, confidentiality, and authenticity of programs, modules, and data transmitted over the open connector 130.
[0054] Further, the elements in the main computing subsystem 110 in the system 100 can be divided into a first processing resource group (e.g. the processing resource group 114A), a second processing resource group (e.g. the processing resource group 114B), and a third processing resource group (e.g. the processing resource group 114C) according to the execution environment. Figure 1 Figure 1 Figure 1 Figure 2 The elements in the heterogeneous computing subsystem 120 in the system 100 can be divided into a fourth processing resource group (e.g. the processing resource group 124A).
[0055] The processing resource group 114A includes the dedicated central processing unit 112A, the protected section of memory 111A, and the cryptographic processor 113. The dedicated central processing unit 112A, the protected section of memory 111A, and the cryptographic processor 113 are in the protected region of the main computing subsystem 110. The protection of the processing resource group 114A should be implemented in hardware, whereby the processing resource group 114A can be implemented as a hardware root of trust for the entire heterogeneous processing system 100.
[0056] The processing resource group 114B includes the dedicated central processing unit 112B and the protected section of memory 111B. The dedicated central processing unit 112B and the protected section of memory 111B are in the unprotected region of the main computing subsystem 110. The protected section of the processing resource group 114B should be implemented on the software executed by the processing resource group 114A and the dedicated central unit.
[0057] The processing resource group 114C includes the non-dedicated central processing unit 112C and the unprotected section of memory 111C. The non-dedicated central processing unit 112C and the unprotected section of memory 111C are also in the unprotected region of the main computing subsystem 110. The processing resource group 114C does not implement protection of resources.
[0058] The processing resource group 124A includes the heterogeneous processing unit 122, the dedicated bus 125, the cryptographic processor 123, and the dedicated memory 121. The heterogeneous processing unit 122, the dedicated bus 125, the cryptographic processor 123, and the dedicated memory 121 are in the dedicated region of the heterogeneous computing subsystem 120. The processing resource group 124A is protected by the physical isolation of the heterogeneous computing subsystem 120 in conjunction with the exchange of the cryptographic, integrity, and authenticity protection provided through the open connector 130.
[0059] The following embodiments will describe the different architectures and functions between the trusted execution environment and the trusted open execution environment.
[0060] Please refer to Figure 2 .Figure 2 This diagram illustrates three different execution environments of the software architecture 200 of a heterogeneous computing system 100 according to an embodiment of this disclosure. The three different execution environments of the software architecture 200 include a Trusted Execution Environment (TEE) 210, a Trusted Rich Execution Environment (TREE) 220, and an extension 230 of the Trusted Rich Execution Environment. The extension 230 of the Trusted Rich Execution Environment extends along the hardware platform and the hypervisor 222. It should be noted that the unprotected Rich Execution Environment (REE) is not part of the invention of this disclosure and is therefore not shown in the diagram. However, in some embodiments, the execution environment of the system and method utilizing this disclosure may also include a Rich Execution Environment, and therefore this disclosure is not limited thereto. Programs running and data processed in the Rich Execution Environment implemented in the processing resource group 114C are not protected by encryption, integrity, or authenticity services.
[0061] like Figure 3 As shown, processing resource group 114A, located within the protected region of the hardware platform of the main computing subsystem 110, is used to implement a trusted execution environment 210. Processing resource group 114B, located in the unprotected region of the hardware platform, is used to implement a trusted open execution environment 220. Processing resource group 114C, located in the unprotected region of the hardware platform, is used to implement an open execution environment (not shown). The general-purpose operating system executes within the open execution environment implemented by processing resource group 114C.
[0062] The Trusted Execution Environment 210 includes a Trusted Specific Operating System 211, a Trusted Execution Environment Communication Agent 212, and one or more Trusted Specific Service Programs 213. The Trusted Specific Operating System 211 executes within the Trusted Execution Environment 210. The Trusted Specific Service Programs 213 run with the support of the Trusted Specific Operating System within the Trusted Execution Environment 210.
[0063] The Trusted Execution Environment 210 is a software execution environment used to perform specific security functions. The Trusted Execution Environment 210 is implemented within a protected area of the device's hardware platform and runs a trusted specific operating system.
[0064] The trusted open execution environment 220 includes a virtual machine monitor 222, a trusted general purpose operating system 221, and one or more trusted general purpose applications 223. The trusted open execution environment 220 is implemented as a virtual machine in the processing resource group 114B. The trusted general purpose operating system is executed in the trusted open execution environment 220. The trusted general purpose applications 223 are run under the support of the trusted general purpose operating system 221 in the trusted open execution environment 220.
[0065] The trusted open execution environment is a software execution environment for executing trusted general purpose applications. The trusted open execution environment 220 is implemented as a virtual machine in an unprotected area in the hardware platform of the device, and the trusted open execution environment 220 runs the trusted general purpose operating system 221.
[0066] The trusted general purpose applications 223 are verified and confirmed by a trusted authority with their digital signatures, so the trusted general purpose applications 223 are software programs with authenticity and integrity. When the trusted general purpose applications 223 are executed in the trusted open execution environment 220, the output of the trusted general purpose applications 223 cannot be maliciously modified and can be trusted.
[0067] The trusted general purpose operating system 221 is an operating system constructed for supporting the execution of the trusted general purpose applications 223. The authenticity and integrity of the object code of the trusted general purpose operating system 221 are verified by a trusted authority and certified by the digital signature of the object code. The trusted general purpose operating system 221 is downloaded to the trusted open execution environment 220 in the second boot program, and the trusted general purpose operating system 221 is started when the trusted open execution environment 220 is implemented as a virtual machine, and the trusted general purpose operating system 221 runs the security function in the trusted execution environment 210.
[0068] The trusted specific service program 213 is verified by a trusted authority and certified by the digital signature of the object code, so the trusted specific service program 213 is a program with authenticity and integrity, and the trusted specific service program 213 performs encryption or security functions. When the trusted specific service program is run in the trusted execution environment 210, the trusted specific service program 213 can be trusted not to be maliciously modified.
[0069] The following embodiments will describe the trusted execution environment 210 and the trusted open execution environment 220.
[0070] Please refer to Figure 3 . After the successful completion of the mutual authentication of the host computing subsystem 110 and the heterogeneous computing subsystem 120 and the establishment of secure communication between the dedicated central processing units 112A and 112B and the heterogeneous processing unit 122, the trusted execution environment 210 and the trusted open execution environment 220 are initiated from the system start or reset, and the scope of the trusted open execution environment 220 is extended to cover the flowchart 300 of the start-up sequence of the heterogeneous computing subsystem 120.
[0071] The next step is to establish the trusted execution environment 210. After the host computing subsystem 110 is started or the system is reset, the secure start-up is initiated by the cryptographic processor 113, and the trusted execution environment runs the trusted specific operating system 211 implemented by the processing resource group 114A in the protected area of the hardware platform in the host computing subsystem 110.
[0072] The secure start-up is a mechanism for checking the authenticity and integrity of the system firmware and software, and the secure start-up is verified by the digital signature of the hash value of the target code issued by the trusted authority, rather than the digital signature of the hash value of the target code issued by the provider or customer of the target code.
[0073] The processing resource group 114A includes the dedicated central processing unit 112A, the protected section of memory 111A, and the cryptographic processor 113 in the host computing subsystem 110. The cryptographic processor 113 is used to perform the first secure start-up of the trusted specific operating system 211 in the trusted execution environment 210, and to provide protection for the data stored in the protected section of memory 111A to have encryption and integrity.
[0074] In step S310, the read-only memory start-up program is executed: in this step, the system is checked and the bootstrapping process is performed.
[0075] In step S311, the first phase of the first secure start-up is performed: in this step, the trusted firmware is installed to the processing resource group 114A.
[0076] In step S312, a second phase of the first secure boot is performed: in this step, the trusted specific operating system 211 is verified and installed to the processing resource group 114A. The trusted specific operating system 211 is an operating system constructed for supporting encryption technology and security functions according to a standard operating procedure. The authenticity and integrity of the target code of the trusted specific operating system 211 is verified by a trusted authority and is certified by a digital signature of the target code. In performing the first secure boot procedure, the trusted specific operating system 211 is loaded to the processing resource group 114A. In the booting and resetting of the main computing subsystem, the first secure boot procedure verifies the digital signature of the target code of the trusted specific operating system 211. The trusted execution environment 210 is established after the successful completion of the second phase of the first secure boot.
[0077] A subsequent step is used to establish a trusted open execution environment 220. The trusted open execution environment 220 runs a trusted general operating system 221, which is implemented as a virtual machine by the processing resource group 114B of the unprotected region of the hardware platform in the main computer subsystem 110, wherein the processing resource group 114B includes the second dedicated processor 112B and the memory protection section 111B.
[0078] In step S313, a first phase of the second secure boot is performed: in this step, a virtual machine monitor is installed.
[0079] In step S314, a second phase of the second secure boot is performed: in this step, the installation and verification of the trusted general operating system 221 in the processing resource group 114B is performed. The trusted general operating system 221 is installed in the second phase of the second secure boot after the successful completion of the first secure boot of the trusted execution environment 210, wherein the authentication of the trusted general operating system 221 is authenticated by verifying the digital signature generated by the trusted authority, so that the trusted general operating system 221 is trusted by the trusted specific operating system 211 in the trusted execution environment 210. The trusted open execution environment is established after the successful completion of the second phase of the second secure boot.
[0080] Thus, the programs, modules and data stored in the protected region of memory 111A in the processing resource group 114A used by the trusted execution environment 210 are served with confidentiality and integrity. Also, the programs and data stored in the shared memory protection region 114B in the processing resource group 114B used by the trusted open execution environment are also served with confidentiality and integrity.
[0081] Furthermore, programs, modules and data transmitted through the trusted execution environment communication agent 212 in the main computing subsystem 110 in the trusted execution environment 210 and the trusted open execution environment 220 are protected by the services of confidentiality, integrity and authenticity.
[0082] The following embodiment illustrates the range of the trusted open execution environment 220 extended by the secure information exchange established between the dedicated central processing unit 112B and the heterogeneous processing unit 122.
[0083] In step S320, a mutual authentication procedure is performed between the cryptographic processor 113 of the processing resource group 114A in the main computing subsystem 110 and the cryptographic processor 123 of the processing resource group 124A in the heterogeneous computing subsystem 120. Thus, the trusted relationship between the main computing subsystem 110 and the heterogeneous computing subsystem 120 is established.
[0084] In step S321, a secure communication is established between the dedicated central processing unit 112A in the main computing subsystem 110 and the heterogeneous processing unit 122 in the heterogeneous computing subsystem 120. The secure communication is protected by the services of confidentiality, integrity and authenticity provided by the cryptographic processor 113 in the main computing subsystem 110 and the cryptographic processor 123 in the heterogeneous computing subsystem 120 after the mutual authentication between the main computing subsystem 110 and the heterogeneous computing subsystem 120 is successfully completed.
[0085] In step S322, a secure communication is established between the trusted execution environment 210 and the trusted open execution environment 220. The secure communication is performed between the dedicated central processing unit 112A in the processing resource group 114A which has established the trusted execution environment 210 and the dedicated central processing unit 112B in the processing resource group 114B which has established the trusted open execution environment 220. The secure communication is protected by the services of confidentiality, integrity and authenticity.
[0086] In step S323, a secure communication is established between the trusted open execution environment 220 and the heterogeneous computing subsystem 120 by the trusted execution environment 210. The secure communication between the dedicated central processing unit 112B in the processing resource group 114B which has established the trusted open execution environment 220 and the heterogeneous processing unit 122 in the heterogeneous computing subsystem 120 is performed through the secure communication between the cryptographic processor 113 of the processing resource group 114A in the main computing subsystem 110 and the cryptographic processor 123 in the heterogeneous computing subsystem 120 which has established the trusted execution environment 210. The secure communication is protected by the services of confidentiality, integrity and authenticity.
[0087] After the secure communication between the heterogeneous computing subsystem 120 and the trusted open execution environment 220 through the trusted execution environment 210 is successfully established, the heterogeneous computing subsystem 120 is covered to the extended range of the trusted open execution environment 220.
[0088] After the secure communication between the heterogeneous computing subsystem 120 and the trusted open execution environment 220 through the trusted execution environment 210 is successfully established, the program execution state in the heterogeneous processing unit 122 of the heterogeneous computing subsystem 120 can be verified by the signed hash value of the exclusive memory 121 content generated by the cryptographic processor 123. Then, the signed hash value is transmitted from the heterogeneous computing subsystem 120 to the processing resource group 114B in the host computing subsystem. The processing resource group 114B has established the trusted open execution environment 220.
[0089] In summary, the present disclosure establishes the trusted open execution environment 220 between the processing resource group 114A in the protected area and the processing resource group 114B in the unprotected area of the host computing subsystem 110, and then extends the trusted execution environment 220 to the heterogeneous computing subsystem 120 with the heterogeneous processing unit 122, thereby enabling the edge operation of the data processed by the heterogeneous processing unit 122 in the trusted execution environment 220.
[0090] In response to the trusted open execution environment 220 being idle or deactivated, the virtual machine implementing the trusted open execution environment 220 is terminated, and the processing resource group 114B is released, the exclusive processor 112B becomes a non-exclusive processor, and the memory protection section 111B becomes part of the memory unprotected section.
[0091] Although the present disclosure has been disclosed with the above-mentioned embodiments, it is not intended to limit the present disclosure, and any person skilled in the art can make various modifications and improvements without departing from the spirit and scope of the present disclosure, therefore the protection scope of the present disclosure shall be defined by the appended claims.
Claims
1. A computing system, characterized in that, Include: The first device includes: A first processing resource group, within a protected area of the hardware platform, wherein the first processing resource group includes a first dedicated processor, a first encrypted processor, and a first memory protection zone. as well as A second processing resource group, located in an unprotected area of the hardware platform, wherein the second processing resource group includes a second dedicated processor and a second memory protection zone; wherein, A trusted specific operating system (TSS) is executed in a trusted execution environment (TEX), wherein the TEX is implemented in the first processing resource group, and a first trusted specific service program runs in the TEX with the support of the TSS; and A trusted general-purpose operating system is executed in a trusted open execution environment, wherein the trusted open execution environment is implemented in the second processing resource group, and a first trusted general-purpose application runs in the trusted open execution environment with the support of the trusted specific operating system. The trusted open execution environment in the second processing resource group is implemented by a virtual machine; In response to the Trusted Open Execution Environment (TEE) being idle or deactivated, the virtual machine implemented in the TEE is terminated and the second processing resource group is released, the second dedicated processor becomes a non-dedicated processor, and the second memory protected segment becomes a memory unprotected segment.
2. The computing system according to claim 1, characterized in that, Data transmission between the trusted execution environment implemented in the first processing resource group and the trusted open execution environment implemented in the second processing resource group is protected by confidentiality, integrity, and authentication services; and The programs and data stored in the first memory protected segment of the first processing resource group and used in the trusted execution environment, as well as the programs and data stored in the second memory protected segment of the second processing resource group and used in the trusted open execution environment, are protected by confidentiality, integrity, and authentication services.
3. The computing system according to claim 1, characterized in that, The first device further includes a third processing resource group, wherein the third processing resource group is located in an unprotected area of the hardware platform, and the third processing resource group includes a first non-dedicated processor and a first unprotected memory area, wherein the general-purpose operating system executes in an open execution environment, and wherein the open execution environment is implemented in the third processing resource group.
4. The computing system according to claim 3, characterized in that, The programs running and the data processed in the open execution environment implemented in the third processing resource group are not protected by confidentiality, integrity and authentication services.
5. The computing system according to claim 1, characterized in that, The first device further includes a shared bus connected to an open connector, the first protected memory segment, the second protected memory segment, and the first unprotected memory segment being connected to the shared bus, and wherein the first encryption processor is connected to the shared bus.
6. The computing system according to claim 1, characterized in that, Also includes: A second device, statically connected to the first device via an open connector, wherein the second device comprises: The fourth processing resource group is located in the protected area of the hardware platform, wherein the fourth processing resource group includes a third dedicated processor, a second encryption processor, and a dedicated memory.
7. The computing system according to claim 6, characterized in that, The second device further includes a dedicated bus connected to the open connector, a dedicated memory connected to the dedicated bus, and a second encryption processor connected to the dedicated bus. The first encryption processor in the first processing resource group is used to perform mutual authentication between the first device and the second device, and to provide confidentiality, integrity, and authentication services to protect data transmitted through the open connector; and The second encryption processor in the fourth processing resource group is used to perform mutual authentication between the first device and the second device, and to provide confidentiality, integrity and authentication services to protect the data transmitted through the open connector.
8. The computing system according to claim 6, characterized in that, The open connector described herein is a communication channel implemented by a standardized protocol to support bidirectional exchange of information between the two devices.
9. The computing system according to claim 1, characterized in that, The trusted execution environment is a software execution environment for performing specific encryption functions. The trusted execution environment is a protected area of the hardware platform implemented in the device, and the trusted execution environment runs a trusted specific operating system.
10. The computing system according to claim 1, characterized in that, The Trusted Open Execution Environment (TEE) is a software execution environment for executing trusted generic applications. The TEE in the unprotected region of the device's hardware platform is implemented as a virtual machine, and the TEE runs a trusted generic operating system.
11. The computing system according to claim 1, characterized in that, The Trusted Specific Operating System (TSOS) is an operating system built to support the execution of encryption and security functions. The authenticity and integrity of the target code of the TOS are verified by a trusted authority and authenticated by the digital signature of the target code. In the first secure boot procedure, the TOS is loaded into the trusted execution environment, and when the device is started or reset, the TOS is activated and the digital signature of the TOS is authenticated.
12. The computing system according to claim 1, characterized in that, The Trusted General Operating System (TGES) is constructed to support the execution of Trusted General Applications. The authenticity and integrity of the target code of the TGES are verified by a trusted authority and through the digital signature of the target code. In the second secure boot process, the TGES is loaded into the Trusted Open Execution Environment (TEE) and, when the TEES is implemented in a virtual machine within the TEES, the TGES is started and executed by the security functions of the TEES.
13. The computing system according to claim 1, characterized in that, The trusted specific service program is software with authenticity and integrity. The trusted specific service program is verified by a trusted organization and certified by digital signature of the target code. The trusted specific service program performs encryption or security functions. When the trusted specific service program is executed in the trusted execution environment, the output of the trusted specific service program is believed to be immune from malicious modification.
14. The computing system according to claim 1, characterized in that, The trusted general application is software with authenticity and integrity. The trusted general application is verified by a trusted organization and certified by the digital signature of the trusted general application. When the trusted general application is executed in the trusted open execution environment, the output of the trusted general application is believed to be immune from malicious modification.
15. A calculation method, characterized in that, Include: A trusted execution environment (PEO) is established, comprising a trusted specific operating system, wherein during a first secure boot initiated by a first cryptographic processor after the startup of the first device or a system reset, the PEO is implemented within a first processing resource group in a protected area of the hardware platform in the first device, and the first processing resource group includes a first dedicated processor, a first memory protected area, and a first cryptographic processor; and A trusted open execution environment containing a trusted general-purpose operating system is established, wherein during a second secure boot after the successful first secure boot of the trusted execution environment of the first processing resource group, the trusted open execution environment of the second processing resource group in the protected area of the hardware platform of the first device is implemented by a virtual machine, wherein the second processing resource group includes a second dedicated processor and a second memory protection zone. The trusted open execution environment in the second processing resource group is implemented by a virtual machine; In response to the Trusted Open Execution Environment (TEE) being idle or deactivated, the virtual machine implemented in the TEE is terminated and the second processing resource group is released, the second dedicated processor becomes a non-dedicated processor, and the second memory protected segment becomes a memory unprotected segment.
16. The calculation method according to claim 15, characterized in that, The trusted general operating system in the trusted open execution environment of the first device is implemented by a second secure boot after the first secure boot in the trusted execution environment is successfully completed, wherein the trusted general operating system is authenticated by a digital signature generated by a trusted authority and is trusted by the trusted specific operating system in the trusted execution environment.
17. The calculation method according to claim 15, characterized in that, The data transmitted between the Trusted Open Execution Environment and the Trusted Execution Environment via the Trusted Execution Environment Communication Agent of the first device is protected by confidentiality, integrity and authentication services.
18. The calculation method according to claim 15, characterized in that, Also includes: After the trusted execution environment of the first processing resource group in the first device is successfully established, a trusted association is established between the first device and the second device by executing a mutual authentication procedure between the first encryption processor in the first processing resource group of the first device and the second encryption processor in the fourth processing resource group of the second device.
19. The calculation method according to claim 15, characterized in that, Also includes: After successful mutual authentication between the first device and the second device, a secure communication with confidentiality, integrity and authentication protection is established between the first encryption processor in the first device and the second encryption processor in the second device.
20. The calculation method according to claim 15, characterized in that, Also includes: A secure transmission of programs and data with confidentiality, integrity, and authentication protection is established between the second dedicated processor in the second processing resource group of the first device and the third dedicated processor in the fourth processing resource group of the second device.
21. The calculation method according to claim 15, characterized in that, in, The state of the program executed by the third dedicated processor in the fourth processing resource group of the second device is verified by using a signed hash value of the dedicated memory content generated by the second encryption processor, and the signed hash value is transferred from the third dedicated processor in the second device to the second dedicated processor in the second processing resource group of the first device, wherein the trusted open execution environment is implemented in the second processing resource group.
22. The calculation method according to claim 15, characterized in that, in, The first encryption processor in the first device is used to perform the first secure boot of the trusted specific operating system in the trusted execution environment, and to perform mutual authentication between the first device and the second device, and to provide confidentiality and integrity protection for data stored in the first memory protected area and the second memory protected area, and to provide confidentiality, integrity and authentication protection for data transmitted through the shared bus and open connector. as well as The second encryption processor is used to perform mutual authentication between the first device and the second device, and to provide confidentiality, integrity and authentication protection for data transmitted through the open connector.
23. The calculation method according to claim 15, characterized in that, The first secure boot and the second secure boot verify the authenticity and integrity of the system firmware and software by using an electronic signature that verifies the hash value of the target code sent by a trusted authority, which is different from the provider or user of the target code.
Citation Information
Patent Citations
Computing system for securely executing secure application in rich execution environment
CN108062242A
Virtual machine memory compartmentalization in multi-core architectures
US20110293097A1
Method and Apparatus for Maintaining Secure Time
US20140095918A1