A Security Extension Method, System and Medium for PCIE Protocol

By introducing security information into PCIE protocol messages, the problem of lack of security in data transmission of PCIE protocol is solved, and the security protection of off-chip PCIE device data is achieved, which improves the security of heterogeneous systems.

CN115688089BActive Publication Date: 2025-07-22NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211476721.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-23
Publication Date
2025-07-22
Estimated Expiration
2042-11-23

AI Technical Summary

Technical Problem

The existing PCIE protocol lacks security design during data transmission, resulting in hardware security risks for off-chip data transmission. Especially in heterogeneous computing systems, data offloaded to the acceleration chip cannot be included in a trusted execution environment.

Method used

Security information is introduced into the PCIE protocol message, so that the CPU's access request carries security information, and the target terminal device implements access control based on the security information, so as to realize data security protection offloaded to the off-chip PCIE device.

Benefits of technology

By incorporating the terminal device into the trusted execution environment on the processor side in the PIO direction, security protection of off-chip PCIE device side data is achieved, ensuring that the CPU's security control request is passed to the peripherals, and the security of the system is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115688089B_ABST
    Figure CN115688089B_ABST
Patent Text Reader

Abstract

The present invention discloses a security extension method, system and medium for the PCIE protocol. The security extension method for the PCIE protocol of the present invention includes: S101, generating a PCIE message carrying security information from an access request issued by the CPU and sending it to a target terminal device; S102, after receiving the PCIE message carrying security information, the target terminal device implements security access control of the CPU on the target terminal device according to the security information. The security access control can adopt access allowance and rejection at the resource granularity or device granularity as required. The security extension method, system and medium for the PCIE protocol of the present invention introduce security information into the PCIE protocol message, making the PCIE protocol security-aware, incorporating the terminal device into the trusted execution environment of the processor end in the PIO direction, and realizing the security protection of data unloaded to the off-chip PCIE device end.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer security, and particularly relates to a method, system and medium for secure extension of the PCIE protocol. Background Art

[0002] Currently, more and more attention has been paid to hardware security. Only by enhancing system security from the perspective of underlying hardware security and blocking security vulnerabilities can a more secure information system be constructed. In existing international mainstream CPU architectures, mechanisms related to hardware resource isolation are defined. Based on these mechanisms, an isolated area can be constructed in the system. This area has independent computing, storage, and IO resources, and it is ensured from the hardware level that the data within the isolated area cannot be accessed by resources outside the isolated area, and the software executed in this area cannot be maliciously tampered with, thereby supporting the construction of a secure trusted execution environment.

[0003] However, traditional hardware resource isolation mechanisms are generally built around the inside of the processor. However, with the continuous improvement of the computing power of off-chip accelerators, heterogeneous frameworks with a main processing chip and an off-chip acceleration chip are increasingly used in new application fields. In such a heterogeneous architecture, a large amount of user data needs to be offloaded to the acceleration chip for execution. Generally, the acceleration chip is connected to the main processor through the PCIE bus. In the current mainstream CPU hardware resource isolation architecture, the PCIE bus is not included in the isolated area. Therefore, from the security perspective of the CPU side, the data offloaded to the acceleration chip is not secure, is outside the trusted execution environment, and has relatively large hardware security risks.

[0004] In a typical CPU + accelerator heterogeneous computing system, the RC (Root Complex) device of the PCIE protocol is located between the CPU and the PCIE topology, connected to the CPU through a bus upwards, and managing the nodes in each PCIE tree topology downwards. PCIE nodes include switching devices (switches), EP (Endpoint) devices, etc. The root complex device and the CPU are interconnected through the AXI (Advanced eXtensible Interface) bus. The AXI bus is the fourth-generation on-chip bus protocol developed by ARM Corporation, and is an on-chip bus oriented to high performance, high bandwidth, and low latency. It uses the AxPROT signal to distinguish whether a request is a security request.

[0005] Figure 1It is a framework diagram of a typical system on chip (SOC) with a main processor externally connected to a PCIE acceleration device. The topology of the PCIE bus system is a tree topology, which mainly includes PCIE devices such as a root complex (RC) device, a switch device, and an endpoint (EP) device. The endpoint device is a device that can support diverse application functions, mainly including a graphics card, a network card, etc. The switch device is a PCIE switch, which can expand the PCIE link when the PCIE link cannot meet the requirements. There are two data transfer methods in PCIE devices: DMA (Direct Memory Access) and PIO (Programmed Input-Output). Among them, in the data transfer method of the DMA mode, data transfer between the memory and the PCIE device can be achieved. For example, the endpoint device sends an access request to the memory, and the memory returns the requested data to the endpoint device; in the data transfer method of the PIO mode, data transfer between the processor and the endpoint device can be achieved. For example, the processor sends an access request to the endpoint device, and the endpoint device returns the requested data to the processor. Currently, the PCIE interface is widely used in the communication between current processors and high-speed peripherals. However, since the PCIE protocol was developed to date, there has never been a targeted design for data security in the message format. Therefore, security vulnerabilities inevitably occur when it comes to data transmission outside the processor chip. Therefore, it has become a key technical problem to be solved urgently to extend the PCIE protocol so that the security control request of the CPU can be passed to the peripheral device. Summary of the Invention

[0006] The technical problem to be solved by the present invention: Aiming at the above problems of the prior art, the present invention provides a security extension method, system and medium for the PCIE protocol. The present invention introduces security information into the PCIE protocol message, making the PCIE protocol security-aware. In the PIO direction, the endpoint device is incorporated into the trusted execution environment of the processor end, so that the security control request of the CPU can be passed to the peripheral device, realizing the security protection of the data unloaded to the off-chip PCIE device end.

[0007] In order to solve the above technical problems, the technical solution adopted by the present invention is as follows:

[0008] A security extension method for the PCIE protocol, including:

[0009] S101, generating a PCIE message carrying security information from the access request issued by the CPU and sending it to the target endpoint device;

[0010] S102. After receiving the PCIE packet carrying security information, the target terminal device implements security access control of the CPU to the target terminal device according to the security information.

[0011] Optionally, implementing security access control of the CPU to the target terminal device in step S102 means allowing the CPU to access all resources of the target terminal device, or only allowing the CPU to access the non-secure part of the resources of the target terminal device, and all resources of the target terminal device are divided into non-secure part of the resources and secure part of the resources.

[0012] Optionally, the value of the security information carried in the PCIE packet in step S102 is one of two options, the first value or the second value. Implementing security access control of the CPU to the target terminal device in step S102 includes: if the security information is the first value, only allowing the CPU to access the non-secure part of the resources of the target terminal device; if the security information is the second value, allowing the CPU to access all resources of the target terminal device.

[0013] Optionally, implementing security access control of the CPU to the target terminal device in step S102 means allowing the CPU to access the target terminal device, or denying the CPU access to the target terminal device.

[0014] Optionally, the value of the security information carried in the PCIE packet in step S102 is one of two options, the first value or the second value. Implementing security access control of the CPU to the target terminal device in step S102 includes: when the security information is the first value, comparing the device information of the target terminal device with a preset list of security terminal device information to determine whether the target terminal device is a security terminal device, and only allowing the CPU to access the target terminal device when the target terminal device is a security terminal device; when the security information is the second value, directly allowing the CPU to access the target terminal device.

[0015] Optionally, step S101 includes:

[0016] S201. The root complex device receives the AXI request sent by the CPU through the AXI bus;

[0017] S202. The root complex device parses and obtains the AxPROT signal in the AXI request, generates security information according to the AxPROT signal, and encodes the security information into the PCIE packet;

[0018] S203. The root complex device determines the connection method with the target terminal device. If it is directly connected to the target terminal device, it directly sends the PCIE packet to the target terminal device; otherwise, it sends the PCIE packet to the switching device connected to the target terminal device.

[0019] S204, forward the PCIE packet to the target terminal device through the switching device connected to the target terminal device, and at the same time transparently transmit the security information encoded in the PCIE packet, and finally send the PCIE packet to the target terminal device.

[0020] Optionally, when generating the security information according to the AxPROT signal in step S202, the generated security information is the identification bit indicating whether the access is secure or insecure in the AxPROT signal in the AXI request. If the identification bit indicating whether the access is secure or insecure in the AxPROT signal indicates secure, the value of the security information is the first value, otherwise the value of the security information is the second value, where the first value is used to only allow the CPU to access the non-secure partial resources of the target terminal device, the second value is used to allow the CPU to access all resources of the target terminal device, or the first value is used to allow the CPU to access the target terminal device only when the target terminal device is a secure terminal device, and the second value is used to directly allow the CPU to access the target terminal device.

[0021] Optionally, encoding the security information into the PCIE packet in step S202 specifically refers to encoding the security information into the reserved field of the PCIE packet to achieve compatibility with the standard PCIE packet protocol.

[0022] In addition, the present invention also provides a security extension system for the PCIE protocol, including a microprocessor and a memory connected to each other, and the microprocessor is programmed or configured to execute the security extension method of the PCIE protocol.

[0023] In addition, the present invention also provides a computer-readable storage medium, in which a computer program is stored, and the computer program is used to be programmed or configured by a microprocessor to execute the security extension method of the PCIE protocol.

[0024] Compared with the prior art, the present invention mainly has the following advantages: The security extension method of the PCIE protocol of the present invention includes: carrying security information in the PCIE packet sent by the CPU to the target terminal device; after receiving the PCIE packet carrying the security information, the target terminal device selects to allow the CPU to access all resources of the target terminal device or the partial resources set as non-secure according to the security information. The present invention introduces security information into the PCIE protocol packet, making the PCIE protocol security-aware, incorporating the terminal device into the trusted execution environment of the processor side in the PIO direction (the read / write direction of the CPU to the terminal device), so that the security control request of the CPU is transmitted to the peripheral device, realizing the security protection of the data unloaded to the off-chip PCIE device side. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 It is a schematic diagram of the architecture of an existing PCIE application system.

[0026] Figure 2 This is a schematic diagram of the basic process flow of the method according to the first embodiment of the present invention.

[0027] Figure 3 This is a schematic diagram of the specific implementation process of secure access control in the first embodiment of the present invention.

[0028] Figure 4 This is a schematic diagram of the process of step S101 in the first embodiment of the present invention.

[0029] Figure 5 This is the format definition of the header of the third-generation standard PCIE message protocol (PCIe Gen3).

[0030] Figure 6 This is a schematic diagram of the specific implementation process of secure access control in the second embodiment of the present invention. Detailed implementation manners

[0031] Embodiment 1:

[0032] As Figure 2 shown, the method for secure extension of the PCIE protocol in this embodiment includes:

[0033] S101, generating a PCIE message carrying security information for the access request sent by the CPU and sending it to the target terminal device;

[0034] S102, after receiving the PCIE message carrying security information, the target terminal device implements secure access control of the CPU to the target terminal device according to the security information.

[0035] Implementing secure access control of the CPU to the target terminal device according to the security information can select a feasible implementation manner of secure access control as needed. For example, as an optional implementation manner, implementing secure access control of the CPU to the target terminal device in step S102 of this embodiment means allowing the CPU to access all resources of the target terminal device, or only allowing the CPU to access the non-secure part of the resources of the target terminal device, and all resources of the target terminal device are divided into non-secure part of the resources and secure part of the resources. In this embodiment, by dividing the security levels of the resources of the target terminal device (non-secure part of the resources and secure part of the resources), the fine-grainedness of the security control of the target terminal device is richer, so that the implementation of the target terminal device is more flexible.

[0036] As Figure 3As shown, in step S102 of this embodiment, the value of the security information carried in the PCIE message is one of two options, the first value or the second value. Implementing the CPU's security access control for the target terminal device in step S102 includes: if the security information is the first value, only allowing the CPU to access the non-secure partial resources of the target terminal device; if the security information is the second value, allowing the CPU to access all resources of the target terminal device. Among them, the first value or the second value is only used to distinguish between the two security access control methods and can be defined as needed. For example, as an optional implementation, in this embodiment, the first value is defined as 1 and the second value is defined as 0.

[0037] The access requests issued by the CPU in step S101 can be configuration requests, IO requests, MEM requests, etc., and the method of this embodiment does not depend on the specific request type. The topology corresponding to the PCIE protocol of the computer includes a root complex device and a target terminal device. The root complex device and the target terminal device can be directly connected or connected through a switching device (specifically, a PCIE switching device). The root complex device is used to receive the access requests issued by the CPU. Without a doubt, a bus supporting security control can be adopted between the root complex device and the CPU as needed. For example, a common bus supporting security control between the root complex device and the CPU is the AXI bus. Below, taking the AXI bus being adopted between the root complex device and the CPU as an example, the implementation method of step S101 in this embodiment will be further described in detail.

[0038] As Figure 4 shown, step S101 of this embodiment includes:

[0039] S201, the root complex device receives the AXI request issued by the CPU through the AXI bus;

[0040] S202, the root complex device parses and obtains the AxPROT signal in the AXI request, generates security information according to the AxPROT signal, and encodes the security information into the PCIE message;

[0041] S203, the root complex device determines the connection method with the target terminal device. If it is directly connected to the target terminal device, it directly sends the PCIE message to the target terminal device; otherwise, it sends the PCIE message to the switching device connected to the target terminal device;

[0042] S204, the switching device connected to the target terminal device forwards the PCIE message to the target terminal device and at the same time transparently transmits the security information encoded in the PCIE message, and finally sends the PCIE message to the target terminal device.

[0043] In this embodiment, when generating security information according to the AxPROT signal in step S202, the generated security information is the identification bit indicating whether the access is secure or insecure in the AxPROT signal in the AXI request (the AxPROT signal has a width of 3 bits. AxPROT[0] identifies the access as non-privileged or privileged. AxPROT[1] identifies the access as secure or insecure. AxPROT[2] indicates whether it is a data or instruction access. However, it is not accurate in all cases. For example, the transaction contains a mixture of instructions and data items). If the identification bit indicating whether the access is secure or insecure in the AxPROT signal indicates secure, the value of this security information is the first value, otherwise the value of this security information is the second value, where the first value is used to only allow the CPU to access the non-secure partial resources of the target terminal device, and the second value is used to allow the CPU to access all resources of the target terminal device.

[0044] As an alternative implementation, encoding the security information into the PCIe message in step S202 in this embodiment specifically refers to encoding the security information into the reserved field of the PCIe message to achieve compatibility with the standard PCIe message protocol. Figure 5 The following shows the format definition of the header of the third-generation standard PCIe message protocol (PCIe Gen3). The header is four bytes in total, 32 bits in size. Among them, there is a 1-bit reserved field R between the type Type and the transmission class TC, between the transmission class TC and the message attribute Attr, and between the message attribute Attr and the message processing hint information flag TH. Since the first value is defined as 1 and the second value is defined as 0 in this embodiment, one of the 1-bit reserved fields R can be occupied. The security extension of the protocol can be achieved by using any one of the 1-bit reserved fields R. The internal security information AxPROT of the processor is passed and encoded into the reserved field R in the PCIe message and then passed to the external device. After receiving these messages, the external terminal device also needs to decode the reserved field R in the TLP message, convert the reserved field R decoding into the internal security information of the terminal device, and then the CPU can implement the security access control of the target terminal device according to the security information.

[0045] In summary, in this embodiment, security information is introduced into the PCIE protocol packet, making the PCIE protocol security-aware. In the PIO direction (the read / write direction from the CPU to the EP device), the EP device (terminal device) is incorporated into the trusted execution environment of the processor side, achieving security protection for the data unloaded to the off-chip PCIE device side. In particular, to achieve compatibility with the existing PCIE protocol, in this embodiment, a security attribute field segment for introducing security information is added to the standard PCIe protocol packet, so that the security control request of the CPU can be transmitted to the peripheral device, realizing the security extension of the PCIE standard protocol under the premise of compatibility with the existing PCIE protocol.

[0046] In addition, this embodiment also provides a security extension system for the PCIE protocol, including a microprocessor and a memory connected to each other. The microprocessor is programmed or configured to execute the aforementioned security extension method for the PCIE protocol. The security extension system for the PCIE protocol can be a heterogeneous system composed of a CPU + accelerator, or a system without an accelerator. In addition, this embodiment also provides a computer-readable storage medium, in which a computer program is stored. The computer program is used to be programmed or configured by the microprocessor to execute the aforementioned security extension method for the PCIE protocol.

[0047] Embodiment 2:

[0048] This embodiment is basically the same as Embodiment 1, and the main difference is that: in step S102 of this embodiment, the implementation of the CPU's secure access control to the target terminal device means allowing the CPU to access the target terminal device or denying the CPU's access to the target terminal device, that is, realizing secure access control at the granularity of the terminal device.

[0049] Similarly, in step S102 of this embodiment, the value of the security information carried in the PCIE packet is one of two options, the first value or the second value. However, different from Embodiment 1, as Figure 6 shown, the implementation of the CPU's secure access control to the target terminal device in step S102 of this embodiment includes: when the security information is the first value, comparing the device information of the target terminal device with a preset list of secure terminal device information to determine whether the target terminal device is a secure terminal device, and only allowing the CPU to access the target terminal device when the target terminal device is a secure terminal device (that is, if the CPU accesses the target terminal device of a non-secure terminal device, it will be denied); when the security information is the second value, directly allowing the CPU to access the target terminal device.

[0050] Correspondingly, when generating security information based on the AxPROT signal in step S202 of this embodiment, the generated security information is the identification bit indicating whether the access is secure or insecure in the AxPROT signal in the AXI request. If the identification bit indicating whether the access is secure or insecure in the AxPROT signal indicates secure, the value of this security information is the first value; otherwise, the value of this security information is the second value. Different from Embodiment 1, in this embodiment, the first value is used to allow the CPU to access the target terminal device only when the target terminal device is a secure terminal device, and the second value is used to directly allow the CPU to access the target terminal device. Similarly, the first value or the second value is only used to distinguish between the two security access control methods and can be defined as needed. For example, as an alternative embodiment, in this embodiment, the first value is defined as 1 and the second value is defined as 0.

[0051] In addition, this embodiment also provides a security extension system for the PCIE protocol, including a microprocessor and a memory connected to each other. The microprocessor is programmed or configured to execute the aforementioned security extension method for the PCIE protocol. The security extension system for the PCIE protocol can be a heterogeneous system composed of a CPU + accelerator or a system without an accelerator. In addition, this embodiment also provides a computer-readable storage medium, in which a computer program is stored. The computer program is used to be programmed or configured by the microprocessor to execute the aforementioned security extension method for the PCIE protocol.

[0052] Embodiment 3:

[0053] This embodiment is basically the same as Embodiment 1, and the main difference is that: in step S202 of this embodiment, when the root complex device parses and obtains the AxPROT signal in the AXI request, generates security information based on the AxPROT signal, and encodes the security information into the PCIE message, the security information is not encoded in the message header of the PCIE protocol, but encoded into the data of the PCIE message. The target terminal device can also extract the security information by decoding the data of the PCIE message. In addition, not only can the security information be encoded into the data of the PCIE message, but other feasible valid information fields can also be selected to write the security information according to the format definition of the PCIE message, which will not be listed one by one here.

[0054] In addition, this embodiment also provides a security extension system for the PCIE protocol, including a microprocessor and a memory connected to each other. The microprocessor is programmed or configured to execute the aforementioned security extension method for the PCIE protocol. The security extension system for the PCIE protocol can be a heterogeneous system composed of a CPU + accelerator or a system without an accelerator. In addition, this embodiment also provides a computer-readable storage medium, in which a computer program is stored. The computer program is used to be programmed or configured by the microprocessor to execute the aforementioned security extension method for the PCIE protocol.

[0055] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code. The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the processes and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device realizes the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Therefore, the instructions executed on the computer or other programmable device provide steps for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0056] The above are only the preferred embodiments of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the concept of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art, several improvements and refinements made without departing from the principle of the present invention should also be regarded as within the protection scope of the present invention.

Claims

1. A security extension method for the PCIE protocol, characterized in that, Including: S101, generating a PCIE message carrying security information from the access request sent by the CPU and sending it to the target terminal device; S102, after receiving the PCIE message carrying security information, the target terminal device implements security access control of the CPU to the target terminal device according to the security information; Step S101 includes: S201, the root complex device receives the AXI request sent by the CPU through the AXI bus; S202, the root complex device parses and obtains the AxPROT signal in the AXI request, generates security information according to the AxPROT signal, and encodes the security information into the PCIE message; S203, the root complex device determines the connection method with the target terminal device. If it is directly connected to the target terminal device, it directly sends the PCIE message to the target terminal device. Otherwise, it sends the PCIE message to the switching device connected to the target terminal device; S204, forwarding the PCIE message to the target terminal device through the switching device connected to the target terminal device and simultaneously transparently transmitting the security information encoded in the PCIE message, and finally sending the PCIE message to the target terminal device; When generating security information according to the AxPROT signal in step S202, the generated security information is the identification bit indicating whether the access is secure or insecure in the AxPROT signal from the AXI request. If the identification bit indicating whether the access is secure or insecure in the AxPROT signal indicates secure, the value of the security information is the first value. Otherwise, the value of the security information is the second value, where the first value is used to only allow the CPU to access the non-secure partial resources of the target terminal device, the second value is used to allow the CPU to access all resources of the target terminal device, or the first value is used to allow the CPU to access the target terminal device only when the target terminal device is a secure terminal device, and the second value is used to directly allow the CPU to access the target terminal device; Encoding the security information into the PCIE message in step S202 specifically means encoding the security information into the reserved field of the PCIE message to achieve compatibility with the standard PCIE message protocol.

2. The security extension method of the PCIE protocol according to claim 1, wherein, The value of the security information carried in the PCIE message in step S102 is one of the two options of the first value or the second value. Implementing the security access control of the CPU to the target terminal device in step S102 includes: when the security information is the first value, comparing the device information of the target terminal device with the preset list of secure terminal device information to determine whether the target terminal device is a secure terminal device, and only allowing the CPU to access the target terminal device when the target terminal device is a secure terminal device; when the security information is the second value, directly allowing the CPU to access the target terminal device.

3. A security extension system for the PCIE protocol, comprising a microprocessor and a memory connected to each other, characterized in that, The microprocessor is programmed or configured to execute the security extension method of the PCIE protocol according to claim 1 or 2.

4. A computer-readable storage medium storing a computer program therein, characterized in that, The computer program is used to be programmed or configured by the microprocessor to execute the security extension method of the PCIE protocol according to claim 1 or 2.

Citation Information

Patent Citations

  • Access management method, related device, system and computer readable storage medium

    CN114912107A

  • URL filtering method based on HTTPS protocol, safety equipment and storage medium

    CN115277060A