Functional security system and method for secure access to non-volatile memory
By using a variety of encryption methods and mode selection circuit systems to control systems for secure access to external flash memory and dynamically switch functional safety mechanisms, the problem of difficult to balance cost and processing efficiency in the prior art is solved, and an efficient secure access strategy is realized.
Patent Information
- Application Number
- CN202411519411.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-07-31
- Filing Date
- 2024-10-29
- Publication Date
- 2025-05-06
AI Technical Summary
When the prior art realizes secure access to external flash memory, it is difficult to achieve a cost-efficient and efficient processing balance between encryption, decryption and secure access.
Various types of encryption and decryption methods are adopted, and the functional security mechanism of dynamic switching of the mode selection circuit system is selected according to the number of pending access requests and incoming responses.
It realizes dynamic adjustment of secure access policies under different system conditions, improves system performance and efficiency, and reduces design costs and throughput losses.
Smart Images

Figure CN119939614A_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims the benefit of priority to U.S. Provisional Patent Application No. 63 / 547,186, filed on November 3, 2023, entitled “METHOD AND SYSTEM FOR FUNCTIONAL SAFETY FOR SECURE ACCESS TOEXTERNAL FLASH,” which is hereby incorporated herein by reference. Technical Field
[0003] The present invention generally relates to controlling cryptographic processes for secure access to non-volatile memory devices. Background Art
[0004] A microcontroller unit (MCU) is designed to run software programs and perform functions enabled by running the software programs. To this end, the MCU may include a processing core configured to execute software and a memory coupled to the processing core, the memory storing instructions and data for the software. For example, an MCU may have one or more central processing units (CPUs), each CPU having any number of processing cores that communicate with volatile memory (e.g., random access memory (RAM)) to execute such software programs. If the software program is too large to be executed from RAM, the MCU may additionally utilize non-volatile memory, such as flash memory, which has a larger capacity to store instructions and data associated with the software. The MCU typically executes software programs from RAM at higher speeds and reduced latency, however, an increase in the complexity and size of the program may require the MCU to execute from volatile memory and / or non-volatile memory to perform the task.
[0005] When utilizing non-volatile memory, the processing core may read from or write to a given non-volatile memory. In many existing solutions, data written to or read from the non-volatile memory may be subjected to encryption and decryption, respectively, for safety and security purposes. In some of these solutions, industry standards, such as automotive functional safety standards (e.g., ISO 26262), require such cryptographic techniques to protect systems, devices, and their users from risks arising from hazards caused by malfunctions of the computing system or malicious intent of an attacker. Summary of the invention
[0006] Improvements to controls regarding security and protection of access to non-volatile memory are disclosed herein. In a computing system, a processing core may attempt to access external non-volatile memory to read data, write data, or execute program instructions directly from the external non-volatile memory. In such a system, data written to the external non-volatile memory may first be encrypted so that data read from the external non-volatile memory may be decrypted for use by the processing core. A system may employ various types of encryption and decryption based on how much capacity is available and based on which elements of the system are more efficient at a given time.
[0007] In an example embodiment, a device is provided. The device includes: a memory security controller configured to operate in a first functional safety mode or a second functional safety mode; a security mode selection controller coupled to the memory security controller; and a memory interface controller coupled to the memory security controller and the security mode selection controller and configured to couple to a non-volatile memory. The security mode selection controller is configured to: determine a number of pending access requests associated with the memory security controller; determine a number of incoming responses from the non-volatile memory to the memory security controller; and select between the first functional safety mode and the second functional safety mode based on at least one of the number of pending access requests or the number of incoming responses.
[0008] This Summary is provided to introduce in simplified form a selection of concepts that are further described below in the Detailed Description. It should be understood that this Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1 An example system for controlling access to a non-volatile memory device according to an embodiment is described.
[0010] Figure 2 A series of steps for controlling cryptographic processes and access to memory devices in an implementation are described.
[0011] Figure 3A and 3B An example sequence diagram illustrating cryptographic control and access between elements of a presentation system according to an embodiment.
[0012] Figure 4 An example block diagram illustrating a system that may be configured to perform memory access and password control in accordance with an embodiment.
[0013] Figure 5 An example flow chart for controlling a cryptographic process in accordance with an embodiment of the present invention is illustrated.
[0014] Figure 6 An example flow chart for performing an error testing process according to an embodiment of the invention is illustrated.
[0015] Figure 7 Computing devices that may be used in accordance with some examples of the present technology are described.
[0016] The drawings are not necessarily drawn to scale. In the drawings, like reference numerals represent corresponding parts throughout the several views. In some instances, components or operations may be divided into different blocks or may be combined into a single block. DETAILED DESCRIPTION
[0017] This article discusses enhanced components, techniques, and systems related to control of security and protection for accessing non-volatile memory and other types of memory. A processing core may be responsible for executing software to implement the functions of an application, device, or system. Although the processing core may copy some code and data to internal memory for execution, copying all code and data to internal memory may not be optimal due to design constraints, cost, and other considerations. Therefore, non-volatile memory may be included in a system external to the processing core. In such a system, some code and data may be copied from non-volatile memory to internal memory (e.g., RAM) at runtime, while other code and data may be retained in external non-volatile memory (e.g., flash memory) at runtime. The processing core may attempt to access both internal and external memory during execution of software.
[0018] In various examples, for security and protection reasons, the system may encrypt information written to the external memory and may decrypt information read from the external memory. The system may employ several cryptographic methods, and a single system may employ multiple cryptographic methods. An example cryptographic solution in the MCU uses encryption and decryption techniques based on message authentication codes (MACs) to provide integrity protection and security support. However, using MAC-based techniques for all incoming and outgoing data to external flash memory may use a large amount of overhead relative to non-volatile memory throughput and firmware size. In addition, some systems may not need to perform integrity protection on all incoming and outgoing data to and from external memory devices. Another example cryptographic solution may use lock-step security techniques to avoid the large overhead constraints introduced by MAC-based solutions, such as in systems that do not require integrity protection provided by MAC-based techniques. However, these solutions compromise between overhead and silicon area and design cost. Therefore, previous solutions for embedded solutions including MCUs cannot provide a cost-effective and processing-efficient balance between encryption, decryption, and secure access to and from external memory.
[0019] The system disclosed herein includes a security and protection subsystem capable of performing multiple types of cryptography and further capable of switching between functional safety mechanisms to ensure that encryption and decryption are performed appropriately. A specific functional safety mechanism may be selected based on system conditions such as whether the security core or external memory is bringing more traffic, and therefore may be a bottleneck with respect to throughput, responsiveness, and processing speed and accuracy. The mode selection circuit system may be configured to identify how many commands for encryption or decryption are presented in various queues (e.g., request queues and / or command queues), and how many responses are waiting for decryption before being provided to one or more processing cores of the system in various queues (e.g., response queues). Based on the numbers in each queue relative to the corresponding threshold, the mode selection circuit system may enable or disable one or more functional safety verification operations (e.g., verification processes applied to the output from the cryptographic process), which may be beneficial for systems that do not require integrity protection. Advantageously, the system may not only enable different types of functional safety verification operations for each access request, which may improve system performance and efficiency, but also reduce design area space, cost, and throughput losses.
[0020] In an example embodiment, a device is provided. The device includes: a memory security controller configured to operate in a first functional safety mode or a second functional safety mode; a security mode selection controller coupled to the memory security controller; and a memory interface controller coupled to the memory security controller and the security mode selection controller and configured to couple to a non-volatile memory. The security mode selection controller is configured to: determine a number of pending access requests associated with the memory security controller; determine a number of incoming responses from the non-volatile memory to the memory security controller; and select between the first functional safety mode and the second functional safety mode based on at least one of the number of pending access requests or the number of incoming responses.
[0021] In another example, a system is provided, the system comprising: one or more processing cores; an interconnect coupled to the one or more processing cores; a memory security controller configured to apply a cryptographic process; a security mode selection controller coupled to the memory security controller; and a memory interface controller coupled to the memory security controller and the security mode selection controller and configured to couple to a non-volatile memory. The security mode selection controller may be configured to: determine a number of pending access requests associated with the memory security controller; determine a number of incoming responses from the non-volatile memory to the memory security controller; and control which cryptographic function security process is applied to at least one of the requests or responses based on at least one of the number of pending access requests or the number of incoming responses.
[0022] In yet another embodiment, a method is provided. The method includes: receiving access requests for data stored in a non-volatile memory device from one or more processing cores; determining a number of pending access requests in the access requests associated with the non-volatile memory device; determining a number of incoming responses from the non-volatile memory device; and selecting which cryptographic functional security process to apply to at least one of the request or the response based on at least one of the number of pending access requests or the number of incoming responses.
[0023] Figure 1 An example system for controlling access to a non-volatile memory device according to an embodiment is described. Figure 1 A system 100 is shown that includes a microcontroller unit (MCU) 105 and a non-volatile memory 135. The MCU 105 includes processing cores 110-1, 110-2, and 110-n (collectively, processing cores 110), a security module 112, an interconnect 115, a memory 120, peripherals 122, a safety and security subsystem 124, and a memory interface controller 134. The safety and security subsystem 124 includes a mode selection controller 126, a functional safety controller 128, a request queue 125, a response queue 127, and a memory security controller 130, which further includes a security core 131 and a message authentication code (MAC) core 132. In various embodiments, the MCU 105 may be configured to execute program instructions stored in the memory 120 and / or the non-volatile memory 135, and perform access control processes, such as Figure 2 process 200.
[0024] In various examples, system 100 represents a processing system that includes various hardware, software, and firmware elements configured to execute program instructions and enable functions based on the execution of program instructions. In various examples, the elements of system 100 are on a chip (i.e., a system on a chip (SoC)). In some examples, some elements may be located off-chip relative to other elements on the chip (e.g., non-volatile memory 135). System 100 may be coupled to one or more peripherals 122 to enable the functions of one or more peripherals, which may obtain data from the elements of system 100, such as from the execution of application code. Similar to non-volatile memory 135, one or more peripherals of peripherals 122 may be located off-chip, while one or more other peripherals may be located on-chip.
[0025] The system 100 includes an MCU 105, which may include various processing devices and memory devices from which program instructions and data may be read and to which program instructions and data may be written. More specifically, the MCU 105 may include a plurality of processing cores 110, a security module 112, an interconnect 115 coupled to the processing cores 110 and the security module 112, a memory device coupled to the interconnect 115, a memory 120, a peripheral device 122, a safety and security subsystem 124 coupled to the interconnect, and a memory interface controller 134 coupled to the safety and security subsystem 124 and a non-volatile memory 135.
[0026] Processing core 110 may represent one or more processors, processing cores, or processing circuitry capable of executing software and firmware, such as program instructions (e.g., application code, loadable instructions, read-only data, execute-in-place XIP) code, etc. Such processing cores may include microcontrollers, digital signal processors (DSPs), general-purpose processing units, central processing units (CPUs), special-purpose processors or circuits (e.g., ASICs), and logic devices (e.g., FPGAs), as well as other types of processing devices, combinations or variations thereof. In various examples, processing core 110 may attempt to access memory 120 and / or non-volatile memory 135 via interconnect 115 to read from or write to a given memory device.
[0027] The security module 112 may represent a processing core, a hardware accelerator, or other processing device configured to perform security and protection operations on data read from the memory 120 by one or more of the processing core 110 or the peripheral device 122. In various examples, the security module 112 may identify a read request by the processing core 110 associated with the memory 120, obtain data associated with the read request, and perform security and protection operations (i.e., encryption, decryption) on the data to verify that the data is not suspicious, malicious, or corrupted.
[0028] Memory 120 may represent a computer-readable storage medium located on MCU 105. For example, memory 120 may represent a random access memory (RAM), a tightly coupled memory (TCM), or another type of memory. Although only one block is illustrated in system 100, memory 120 may be implemented as multiple memories that function in an integrated or separate manner. Memory 120 may store program instructions and data. Program instructions may include application code, such as instructions that enable functions when executed by processing core 110. Data may include results and / or other information related to program instructions, loadable instructions, XIP code, etc. Processing core 110 may access memory 120 via interconnect 115 to execute code thereon.
[0029] Some program instructions may initially be stored in non-volatile memory 135 and copied to memory 120 for execution by processing core 110, while XIP code stored on non-volatile memory 135 may be configured to execute directly out of non-volatile memory 135 without first being copied to memory 120. While executing either set of program instructions, processing core 110 may attempt to access memory 120 or a non-volatile memory device. An access request or attempt or command may refer to a read request whereby processing core 110 reads instructions or data from one or more addresses of memory 120 or non-volatile memory 135 to perform processing or calculations using the instructions or data, or an access attempt may refer to a write request whereby processing core 110 writes data to one or more addresses of memory 120 or non-volatile memory 135.
[0030] The non-volatile memory 135 may represent a non-volatile computer-readable storage medium that retains stored information even after power is removed. In some examples, the non-volatile memory 135 may be located externally relative to the MCU 105. In some examples, the non-volatile memory 135 may be located internally relative to the MCU 105. Examples of non-volatile memories 135 and 140 may include FeRAM MRAM, PCM, PRAM, and flash memory. In an example, the non-volatile memory 135 may include one or more memory groups that are included to provide additional capacity to store instructions and data, such as XIP code, read-only data, auxiliary boot loader data, and other loadable instructions. The non-volatile memory 135 may include a first set of addresses dedicated to storing read-only data and / or auxiliary boot loader data, a second set of addresses dedicated to storing data written to the non-volatile memory 135 by the processing core 110 via the memory interface controller 134, and a third set of addresses dedicated to storing program instructions. Other architectures are contemplated for non-volatile memory 135. In some examples, non-volatile memory 135 can include another type of non-volatile memory, or a combination or variation thereof.
[0031] The security and protection subsystem 124 may represent a subsystem or module including one or more components configured to provide the processing core 110 with access to the non-volatile memory 135 via the memory interface controller 134 to execute application code thereon and to encrypt and decrypt information (e.g., data, program instructions) passed to and from the non-volatile memory 135 via the memory interface controller 134. In an example, the security and protection subsystem 124 may include one or more processors, processing cores, processing circuits, or hardware accelerators (HWAs) that include hardware elements coupled to receive access requests (e.g., read, write) from the processing core 110, receive responses based on the access requests from the non-volatile memory 135 via the memory interface controller 134, and perform cryptographic operations on access requests to and access requests returned from the non-volatile memory 135 or responses thereto. The memory interface controller 134 may represent a device configured to route access requests to the physical address space of the non-volatile memory 135 based on the access request and provide access to the non-volatile memory 135 at the physical address. In some examples, the memory interface controller 134 may include a flash interface controller based on the non-volatile memory 135 including flash memory. The elements included in the safety and security subsystem 124 may include a mode selection controller 126, a functional safety controller 128, a memory security controller 130, and a request queue 125 and a response queue 127, which can be accessed by each of the aforementioned elements.
[0032] The mode selection controller 126 may represent one or more processors, circuits, or devices coupled to both the functional safety controller 128 and the memory security controller 130 to control their operations. More specifically, the mode selection controller 126 may be configured to: identify the current state of the functional safety controller 128 and the memory security controller 130 (e.g., enabled, disabled); identify the number of access requests in the request queue 125 being processed by the functional safety controller 128 and / or the memory security controller 130; identify the number of responses in the response queue 127 being processed by the functional safety controller 128 and / or the memory security controller 130; and enable or disable the operation of the functional safety controller 128 and the memory security controller 130 based on system conditions, such as the number of access requests and responses in the respective queues and their current operations.
[0033] For example, in a first mode (e.g., dual pump mode), the functional safety controller 128 may be configured to perform copy, filter, and verify operations to enable functional safety of outgoing requests to the non-volatile memory 135 and incoming responses based on the outgoing requests from the non-volatile memory 135. In the first mode, the security core 131 may be configured to perform cryptographic operations on each copy of the repeated requests and responses, and the functional safety controller 128 may be configured to verify the results of the cryptographic operations performed by the security core 131. In a second mode (e.g., MAC mode), the copy and filter functions of the functional safety controller 128 may be disabled, and in addition to the cryptographic operations performed by the security core 131, the message authentication code (MAC) core 132 may be enabled to perform MAC cryptographic operations on the requests and responses. Therefore, the functional safety controller 128 may be configured to verify the results of both cryptographic operations in the second mode.
[0034] The functional safety controller 128 and the memory security controller 130 may represent security and protection related circuitry capable of enabling and performing cryptographic operations on access requests from the processing core 110 and responses from the non-volatile memory 135 based on the access requests. When enabled, the functional safety controller 128 may be configured to: duplicate access requests; provide the duplicate access requests to the request queue 125 and the memory security controller 130; mutually authenticate each copy of the duplicate access requests based on comparing request related information of the duplicate access requests (e.g., verify that the duplicate requests contain the same information, such as address, size, protocol specific parameters, etc.); filter the duplicate access requests received from the memory security controller 130 based on the authentication; and provide the access requests to the memory interface controller 134 to access the non-volatile memory 135. In addition, the functional safety controller 128 may be configured to: receive a response from the non-volatile memory 135 via the memory interface controller 134 based on the access request; copy the response and add the copied response to the response queue 127; provide the copied response to the memory security controller 130 to decrypt it according to the selected cryptographic mode; verify the decryption of each copy of the copied response based on comparing the response related information (e.g., verify that the copied response contains the same information, such as data, size, etc.); filter the copied decrypted response received from the memory security controller 130 after decryption and verification; and provide the decrypted response to the processing core 110 via the interconnect 115. In some examples, in the second mode, for example, the functional safety controller 128 may not be disabled, but the copying and filtering operations may be bypassed to save power and increase throughput.
[0035] In order to perform encryption and decryption operations, the memory security controller 130 may include a security core 131 and a MAC core 132. The security core 131 may represent one or more processing cores, circuits, or devices capable of encrypting data to be written to the non-volatile memory 135 and decrypting data of responses from the non-volatile memory 135. Similarly, the MAC core 132 may represent one or more processing cores, circuits, or devices capable of performing MAC encryption and decryption when the memory security controller 130 is enabled to operate in the second mode. In various examples, the MAC core 132 may perform MAC encryption on some or all write requests including information to be written to the non-volatile memory 135, regardless of the selected mode. In various examples, the memory security controller 130 or its core may be controlled by the mode selection controller 126 to enable or disable the verification operation applied to the output of the MAC core 132, so that the MAC functional security operation can be enabled or disabled for access requests and responses, respectively.
[0036] In order to determine whether to enable the first mode or the second mode to ensure the functional safety of the cryptography, the mode selection controller 126 may be configured to determine the number of pending access requests associated with the memory security controller 130 or its corresponding core in the request queue 125 and determine the number of incoming responses from the non-volatile memory 135 to the memory security controller 130 in the response queue 127 during a given mode. Each incoming response may correspond to an access request in the pending access requests. Based on the number of pending access requests and incoming responses in the request queue 125 and the response queue 127, respectively, the mode selection controller 126 may determine whether the non-volatile memory 135 may be slowing down the overall operation of the MCU 105 (i.e., being a bottleneck), or whether the memory security controller 130 or the functional safety controller 128 may be slowing down the operation of the MCU 105 (i.e., being a bottleneck). For example, if the number of pending access requests exceeds a threshold number, the mode selection controller 126 may determine that the non-volatile memory 135 and the memory interface controller 134 may not be processing the access requests and providing responses to the access requests quickly enough, such that the non-volatile memory 135 and the memory interface controller 134 are reducing the processing efficiency, responsiveness, throughput, etc. of the MCU 105. Therefore, the mode selection controller 126 may disable the second mode (MAC mode) and may enable the first mode (double pump mode). Conversely, if the number of incoming responses exceeds a threshold number, the mode selection controller 126 may determine that the memory security controller 130 and the functional safety controller 128 may not be processing (e.g., copying, filtering) and decrypting the access responses quickly enough, such that the memory security controller 130 and the functional safety controller 128 are reducing the processing efficiency, responsiveness, throughput, etc. of the MCU 105. Therefore, the mode selection controller 126 may disable the first mode of the security and protection subsystem 124 and enable the second mode. In the first mode, the security and protection subsystem 124 may take longer to perform functional safety operations (e.g., copying, verifying, and filtering access requests, and copying, decrypting, verifying, and filtering corresponding responses) than in the second mode. In this way, by controlling the cryptographic mode and its verification via the functional safety controller 128 and the memory security controller 130, the mode selection controller 126 can dynamically balance the load of the components of the security and protection subsystem 124 and the MCU 105 to improve performance and reduce latency due to bottleneck effects.
[0037] In some examples, the mode selection controller 126 may be configured to control which mode is enabled or disabled based on a selection signal 123 indicating a cryptographic functional security mode provided by the processing core 110-1 to the mode selection controller 126. In some such examples, the processing core 110-1 may provide the selection signal 123 to the mode selection controller 126 during a boot or start-up sequence. In some such examples, the processing core 110-1 may provide the selection signal 123 to the mode selection controller 126 before or at the beginning of a runtime sequence after booting the MCU 105 and its components. In some such examples, the processing core 110-1 may provide the selection signal 123 to the mode selection controller 126 based on the execution of program instructions. In some such examples, the processing core 110-1 may provide the selection signal 123 to the mode selection controller 126 after a plurality of processing cycles.
[0038] In some examples, the mode selection controller 126 can be configured to enable the first mode by default. In some examples, the mode selection controller 126 can be configured to enable the second mode by default. In some examples, the mode selection controller 126 can override the mode based on receiving the selection signal 123. Regardless of the implementation method, the mode selection controller 126 can be configured to use a mode for a given access request and for a corresponding response to the given access request.
[0039] By way of a first example, in operation, the processing core 110-1 provides an access request corresponding to a write request to the non-volatile memory 135 indicating a first data set to the security and protection subsystem 124 via the interconnect 115. In this first example, the security and protection subsystem 124 may be configured to operate in a first mode. In some examples, based on the access request including the write request, the functional safety controller 128 may not be configured to perform a copy operation on the write request, but instead provide the write request to the security core 131 to encrypt it, and forward the encrypted write request to the memory interface controller 134 to write the first data set to the non-volatile memory 135. In some examples, the functional safety controller 128 may be configured to perform copy, verification, and filtering operations on the write request. In some such examples, the functional safety controller 128 may be configured to copy the write request and add the two write requests to the request queue 125, which in turn may provide the write request to the security core 131 of the memory security controller 130 based on the first mode being enabled. The security core 131 may be configured to encrypt the two write requests and provide the encrypted write requests to the functional safety controller 128 for verification and filtering thereof. The functional safety controller 128 may verify the encryption of the write requests, filter out (e.g., discard, not provide) one of the write requests based on successful verification, and provide one of the write requests to the memory interface controller 134 to write the first data set to the non-volatile memory 135.
[0040] After the first instance, the processing core 110-1 may then provide an access request corresponding to the read request indicating the first data set to the safety and protection subsystem 124 via the interconnect 115. Based on being enabled to operate in the first mode, the functional safety controller 128 may be configured to receive a response corresponding to the read request for the first data set from the non-volatile memory 135 via the memory interface controller 134, copy the response, and add both responses to the response queue 127. The memory security controller 130 may be configured to obtain the responses, decrypt the two responses via the security core 131, and provide the decrypted responses to the functional safety controller 128. The functional safety controller 128 may be configured to verify the decryption based on comparing the decrypted responses to each other. In some instances, this may require comparing the data contained in the responses, the size of the data in each response, etc. Based on its successful decryption and verification, the functional safety controller 128 may filter out one of the responses and provide the other to the processing core 110-1. Based on unsuccessful decryption and verification, such as when the information of one response does not match the information of another response, the functional safety controller 128 may provide an indication thereof to the processing core 110 - 1 .
[0041] In a second example, the processing core 110-1 provides an access request corresponding to a write request to the non-volatile memory 135 indicating a second data set to the security and protection subsystem 124 via the interconnect 115. In this second example, the security and protection subsystem 124 may be configured to operate in a second mode. Based on the second mode, the functional safety controller 128 may be configured to add the write request to the request queue 125 without duplicating the write request. The memory security controller 130 may obtain the write request from the request queue 125 and perform encryption on it via the security core 131. In addition, based on the second mode, the memory security controller 130 may be configured to perform MAC encryption on the write request via the MAC core 132. In this way, the security core 131 may encrypt the second data set, and the MAC core 132 may add the MAC information to the encrypted second data set. In some examples, the encryption request may include 32 bytes of data, and the MAC information may include 16 bytes of data, so the encryption request may include a total of 48 bytes of data. The memory security controller 130 may provide the encryption request to the functional safety controller 128 to verify the encryption. The functional safety controller 128 may provide an encrypted request to the memory interface controller 134 to write the second data set to the non-volatile memory 135 .
[0042] After the second instance, the processing core 110-1 may then provide an access request corresponding to the read request indicating the second data set to the safety and security subsystem 124 via the interconnect 115. Based on being enabled to operate in the second mode, the functional safety controller 128 may be configured to receive a response corresponding to the read request for the second data set and the response to the response queue 127 from the non-volatile memory 135 via the memory interface controller 134 without copying the response. The memory security controller 130 may be configured to obtain the response, decrypt the response via the security core 131, perform MAC verification on the MAC information of the decrypted response via the MAC core 132, and provide the decrypted response to the functional safety controller 128. The functional safety controller 128 may be configured to verify the decryption based on comparing the decrypted data with the second data set, and verify the MAC information (e.g., MAC value) based on comparing the MAC information received from the non-volatile memory 135 with the MAC information of the outgoing request added to the non-volatile memory 135. Based on its successful decryption and verification, the functional safety controller 128 may provide the second data set to the processing core 110-1. Based on unsuccessful decryption and verification, such as when the incoming MAC information does not match the outgoing MAC information, the functional safety controller 128 may provide an indication thereof to the processing core 110 - 1 .
[0043] Between the time when the processing core 110-1 provides a read request and a corresponding write request both associated with the first data set in the first example, the security and protection subsystem 124 may perform cryptographic processes on other access requests associated with different data (e.g., access requests associated with the second data set in the second example). Before processing these other access requests, the mode selection controller 126 may be configured to: determine the number of pending access requests in the request queue 125; determine the number of pending responses in the response queue 127; and control the modes of the functional safety controller 128 and the memory security controller 130 based on the determined number relative to the corresponding threshold. Thus, the mode of the security and protection subsystem 124 may be changed one or more times to process other access requests that occur between the read request and the write request of the first example. Other combinations or variations of access requests, responses, and mode switching are contemplated to implement different cryptographic operations.
[0044] In various examples, regardless of the operating mode, the memory security controller 130 may be configured to encrypt data to be written to the non-volatile memory 135 using both the security core 131 and the MAC core 132 such that each encrypted data set written to the non-volatile memory 135 includes MAC information associated with the encrypted data.
[0045] In various examples, non-volatile memory 135 may further provide error check indications to MCU 105 via memory interface controller 134, which may be provided to processing core 110 via interconnect 115. Upon receiving an indication, such as an interrupt indication, processing core 110-1 may provide selection signal 123 to mode selection controller 126 to enable or disable modes of functional safety controller 128 and memory security controller 130.
[0046] These examples discuss only a few cases and a few types of access requests, however, combinations and variations of requests that access different types of memory and use different types of encryption and decryption techniques can be envisioned. Regardless of the type of memory, the address attempted to access, the type of password, etc., the mode selection controller 126 can switch between two or more types of cryptographic functional security methods to ensure that requests and responses thereto are executed in an order that at least improves the processing efficiency and throughput of the processing core 110 and the MCU 105, while also reducing the delay caused by the bottleneck effect.
[0047] Figure 2 A series of steps for controlling cryptographic processes and access to memory devices in an implementation are described. Figure 2 Display reference Figure 1 Process 200 of an element of a processing system. Process 200 may be performed by one or more components of a processing system, such as Figure 1Thus, process 200 may be implemented in hardware, firmware, and / or software, or a combination or variation thereof.
[0048] In operation 205, the safety and protection subsystem 124 may be configured to receive access requests for data stored in the non-volatile memory 135 from one or more of the processing cores 110. The access request may refer to a read request, whereby the processing core 110 reads instructions or data from one or more addresses of the memory 120 or the non-volatile memory 135 to perform processing or calculations using the instructions or data, or the access attempt may refer to a write request, whereby the processing core 110 writes data to one or more addresses of the memory 120 or the non-volatile memory 135. The safety and protection subsystem 124 may include various components, such as a mode selection controller 126, a functional safety controller 128, and a memory security controller 130, which are coupled to receive access requests from one or more processing cores, apply cryptographic techniques to the access requests, and provide the access requests to the memory interface controller 134 to access the non-volatile memory 135. Specifically, functional safety controller 128 may be coupled to receive access requests from one or more of processing cores 110 via interconnect 115 .
[0049] Next, in operation 210, the security and protection subsystem 124, or its mode selection controller 126, may be configured to determine the number of pending access requests associated with the non-volatile memory 135 in the request queue 125. The pending access request may refer to the access request in the access request queue waiting to be encrypted or decrypted by the memory security controller 130. In operation 215, the security and protection subsystem 124, or its mode selection controller 126, may be configured to determine the number of incoming responses from the non-volatile memory 135 in the response queue 127. The incoming response may refer to the response provided to the security and protection module 124 from the non-volatile memory 135 via the memory interface controller 134 based on the access request. More specifically, the incoming response may include data or program instructions requested in the access request after accessing the non-volatile memory 135 via the memory interface controller 134. Each incoming response may be associated with a given access request. Each incoming response may be indicated in the response queue 127. Therefore, the mode selection controller 126 may identify the number of incoming responses in the response queue 127 during this step.
[0050] In various examples, the memory security controller 130 may perform encryption or decryption operations on the contents of pending access requests in the request queue 125 and pending responses in the response queue 127 on a first-in-first-out (FIFO) basis. The memory security controller 130 may include a security core 131 and a MAC core 132, which may perform cryptographic operations on requests and responses thereto. For example, the security core 131 may be configured to perform encryption of access requests and decryption of corresponding responses in both a first mode and a second mode configured by the mode selection controller 126. The MAC core 132 may be configured to perform MAC encryption on access requests encrypted by the security core 131 and MAC decryption on responses decrypted by the security core 131 in the second mode configured by the mode selection controller 126. In some examples, the MAC core 132 may also perform MAC encryption on access requests in the first mode. In some examples, the functional safety controller 128 may perform different functional safety verification operations on encrypted and / or decrypted requests and responses based on the selected mode.
[0051] In operation 220, the security and protection subsystem 124, or its mode selection controller 126, may be configured to select which cryptographic functional safety process to apply to verify cryptographic operations applied to at least one of the pending access requests or the corresponding incoming responses based on at least one of the number of pending access requests in the request queue 125 or the number of incoming responses in the response queue 127. In various examples, this may require determining whether the non-volatile memory 135 may be slowing down the overall operation of the MCU 105 (i.e., is a bottleneck), or whether the memory security controller 130 or the functional safety controller 128 may be slowing down the operation of the MCU 105 (i.e., is a bottleneck) based on the number of pending access requests and incoming responses. For example, the mode selection controller 126 may compare the number with a corresponding threshold number. If the number of pending access requests exceeds a threshold number, the mode selection controller 126 may determine that the non-volatile memory 135 and the memory interface controller 134 may not be processing the access requests and providing responses to the access requests quickly enough, such that the non-volatile memory 135 and the memory interface controller 134 are reducing the processing efficiency, responsiveness, throughput, etc. of the MCU 105. Therefore, the mode selection controller 126 may disable the second mode operation (MAC cryptographic functional security) and enable the first mode operation (double pump cryptographic functional security). Conversely, if the number of incoming responses exceeds a threshold number, the mode selection controller 126 may determine that the memory security controller 130 and the functional safety controller 128 may not be processing (e.g., copying, filtering) and decrypting the responses quickly enough, such that the memory security controller 130 and the functional safety controller 128 are reducing the processing efficiency, responsiveness, throughput, etc. of the MCU 105. Therefore, the mode selection controller 126 may disable the first mode operation of the functional safety controller 128 and the memory security controller 130 and enable its second mode operation.
[0052] In the first mode, the copy and filter functional safety operations of the functional safety controller 128 may be enabled. In this way, the security core 131 of the memory security controller 130 may be used to encrypt and / or decrypt a plurality of access requests and responses, respectively, and the functional safety controller 128 may verify the encryption and / or decryption thereof based on comparing the results of the cryptographic operations performed on the plurality of requests and responses. In the second mode, the copy and filter functional safety operations of the functional safety controller 128 may be disabled. Thus, the security core 131 may be used to encrypt and / or decrypt a separate access request and response, and the MAC core 132 may be used to add MAC information to the encrypted request and verify the MAC information of the decrypted response. In the first mode, based on performing the double pumping technique, the security and protection subsystem 124 may take longer to perform cryptographic functional safety operations on the access request and the corresponding response than in the second mode, because twice the number of requests and responses may be encrypted and decrypted, respectively. In this way, by controlling the cryptographic mode via the functional safety controller 128 and the memory security controller 130 , the mode selection controller 126 can dynamically balance the load of the components of the safety and security subsystem 124 and the MCU 105 to improve performance and reduce latency due to bottleneck effects.
[0053] Figure 3A and 3B An example sequence diagram illustrating cryptographic control and access between elements of a presentation system according to an embodiment. Figure 3A Display sequence 301, and Figure 3B Sequence 302 is shown, both referencing elements of system 100 .
[0054] Sequences 301 and 302 may include operations performed by elements of system 100 with respect to read requests from one or more of processing cores 110 (e.g., processing core 110-1). In some sequences related to write requests, elements of system 100 may perform cryptographic security operations to encrypt data being written to non-volatile memory and verify its encryption based on a selected mode enabled by mode selection controller 126.
[0055] In sequence 301, the processing core 110-1 provides an access request corresponding to a read request indicating a first data set stored in the non-volatile memory 135 to the safety and security subsystem 124, or its functional safety controller 128, via the interconnect 115. Before the read request is executed by the memory interface controller 134, the mode selection controller 126 of the safety and security subsystem 124 may be configured to determine the number of pending access requests associated with the non-volatile memory 135 in the request queue 125 and the number of incoming responses from the non-volatile memory 135 in the response queue 127 to determine to enable a cryptographic functional security mode of the components of the safety and security subsystem. Based on the request queue 125 and the response queue 127, the mode selection controller 126 may be configured to enable a first mode of cryptographic operation (double pumping cryptographic functional security) and provide an indication of the first mode to the functional safety controller 128 and the memory security controller 130.
[0056] Based on the indication of the first pattern, the functional safety controller 128 may be configured to duplicate the read request and provide the duplicated read request to the request queue 125. The memory security controller 130 may be configured to obtain the read request from the request queue 125. The memory security controller 130 may be configured to recognize the indication of the first pattern. The functional safety controller 128 may then be configured to verify the duplication of the read request based on comparing the information of each of the read requests. If the functional safety controller 128 confirms that the information of each read request matches, the functional safety controller 128 may filter out one of the read requests and provide the read request to the memory interface controller 134 to access the non-volatile memory 135 based on the read request.
[0057] Next, the functional safety controller 128 may be configured to obtain a response including a first encrypted data set from the non-volatile memory 135 via the memory interface controller 134. The functional safety controller 128 may copy the response and add the response to the response queue 127. The security core 131 of the memory security controller 130 may be configured to receive the copied response from the response queue 127. The security core 131 may decrypt the two responses based on the first mode being enabled and provide the decrypted data set to the functional safety controller 128. The functional safety controller 128 may then verify whether the decryption of the response is successful. In various instances, this may require comparing information of each decrypted response, such as the size of the response, the data of the response, etc. Based on successful decryption, the functional safety controller 128 may filter the copied decrypted response and provide the first decrypted data set to the processing core 110-1 via the interconnect 115. Based on unsuccessful decryption, the functional safety controller 128 may be configured to output an indication thereof to the processing core 110.
[0058] In sequence 302, the processing core 110-1 provides an access request corresponding to a read request indicating a second data set stored in the non-volatile memory 135 to the safety and security subsystem 124 or its functional safety controller 128 via the interconnect 115. Before the read request is executed by the memory interface controller 134, the mode selection controller 126 of the safety and security subsystem 124 may be configured to determine the number of pending access requests associated with the non-volatile memory 135 in the request queue 125 and the number of incoming responses from the non-volatile memory 135 in the response queue 127 to determine to enable a cryptographic functional security mode of the components of the safety and security subsystem. Based on the request queue 125 and the response queue 127, the mode selection controller 126 may be configured to enable a second mode of cryptographic operation (MAC cryptographic functional security) and provide an indication of the second mode to the functional safety controller 128 and the memory security controller 130.
[0059] In the second mode, the copy and filter operations of the functional safety controller 128 may be disabled. In fact, the functional safety controller 128 may be configured to add the read request to the request queue 125 without copying the request. The memory security controller 130 may obtain the read request from the request queue 125 and provide the read request to the memory interface controller 134 to access the non-volatile memory 135 based on the read request.
[0060] Next, the functional safety controller 128 may be configured to obtain a response including the second encrypted data set from the non-volatile memory 135 via the memory interface controller 134. The functional safety controller 128 may add the response to the response queue 127 without copying the response. The memory security controller 130 may be configured to obtain the response from the response queue 127. The security core of the memory security controller 130 may be configured to decrypt the response and provide the decrypted response to the MAC core 132 of the memory security controller 130 based on the second mode being enabled. The MAC core 132 may verify the MAC information of the decrypted response based on comparing the MAC information received from the non-volatile memory 135 with the MAC information used to encrypt the second data set. Based on the successful verification of the MAC information and the information of the response, the memory security controller 130 may be configured to provide the response to the processing core 110-1 via the interconnect 115. Based on the unsuccessful verification, for example, if the MAC information of the response does not match the MAC information used to encrypt the second data set, the memory security controller 130 may output an indication thereof to the processing core 110.
[0061] Figure 4 An example block diagram illustrating a system that may be configured to perform memory access and password control in accordance with an embodiment. Figure 4System 400 is shown that includes and references elements of system 100, such as processing core 110-1, mode selection controller 126, memory security controller 130, memory interface controller 134, and non-volatile memory 135. System 400 also includes command copier 405, response error injection 406, response checker 407, request queue 125, command filter 411, command error injection 412, command checker 413, in-line security interface controller 415, response copier 416, response queue 127, response filter 418, error interface 419, and status register 421. In various examples, command copier 405, command filter 411, command error injection 412, command checker 413, in-line security interface controller 415, response copier 416, response filter 418, and error interface 419 may be included in a functional safety element of the system, such as functional safety controller 128 of system 100.
[0062] In various examples, system 400 represents a processing system that includes various hardware, software, and firmware elements configured to execute program instructions and enable functionality based on the execution of program instructions. In various examples, the elements of system 400 are on a chip (i.e., a system on a chip (SoC)). In some examples, some elements may be located off-chip relative to other elements on the chip (e.g., non-volatile memory 135).
[0063] The processing core 110-1 of the system 400 may represent a processor, processing core, or processing circuitry capable of executing software and firmware, such as program instructions (e.g., application code, loadable instructions, read-only data, execute-in-place XIP) code, etc. Examples of the processing core 110-1 may include a microcontroller, a digital signal processor (DSP), a general-purpose processing unit, a central processing unit (CPU), a special-purpose processor or circuit (e.g., an ASIC), and one or more logic devices (e.g., an FPGA), as well as other types of processing devices, combinations or variations thereof. In various examples, the processing core 110-1 may attempt to access the non-volatile memory 135 to read from or write to the non-volatile memory 135. Non-volatile memory 135. The non-volatile memory may include one or more flash memory groups, which are included to provide additional capacity to store instructions and data, such as XIP code, read-only data, auxiliary boot loader data, and other loadable instructions, which can be accessed by processing core 110-1 via memory interface controller 134 and various security and protection components.
[0064] Mode selection controller 126, memory security controller 130, command copier 405, response error injection 406, response checker 407, request queue 125, command filter 411, command error injection 412, command checker 413, inline security interface controller 415, response copier 416, response queue 127, response filter 418, error interface 419, and status register 421 may be collectively referred to as security and protection components of system 400. These components may represent a subsystem (e.g., security and protection subsystem 124) configured to provide processing core 110-1 with access to non-volatile memory 135 via memory interface controller 134 to execute application code thereon and to encrypt and decrypt information (e.g., data, program instructions) passed to and from non-volatile memory 135 via memory interface controller 134. In an example, these components may be coupled to receive access requests (e.g., read, write) from processing core 110-1, receive responses based on the access requests from non-volatile memory 135 via memory interface controller 134, and perform cryptographic operations and cryptographic functional security operations on access requests to non-volatile memory 135 and access requests (responses) returned from non-volatile memory 135. Memory interface controller 134 may be configured to route access requests to a physical address space of non-volatile memory 135 based on the access requests and provide access to non-volatile memory 135 at the physical address.
[0065] The mode selection controller 126 may represent one or more processors, circuits, or devices coupled to the command copier 405, the command filter 411, and the memory security controller 130 to control their operation. The mode selection controller 126 may also be coupled to the request queue 125 and the response queue 127. Specifically, in operation, the mode selection controller 126 may be configured to: identify the current state (i.e., enabled, disabled) (i.e., mode) of the dual pump functional safety circuit system (e.g., command copier 405, response copier 416) and the memory security controller 130; identify the number of access requests in the request queue 125; identify the number of responses in the response queue 127; and enable or disable the operation of the dual pump functional safety circuit system and the memory security controller 130 based on the number and its current operation. In various examples, the mode selection controller 126 may identify the current operating state of the components based on the indication of the status register 421. For example, the status registers 421 may include memory mapped registers (MMRs) that include an indication of the status of the double pump functional safety circuitry and the memory security controller 130 at a given time and with respect to a given access request and corresponding response.
[0066] When enabled to operate in the first mode based on the control of the mode selection controller 126, the command copier 405, the command filter 411, the response copier 416, the response filter 418, and the memory security controller 130 may be configured to operate using a first cryptographic functional security method (double pumping functional security) to copy, encrypt or decrypt (i.e., via a first set of security cores (e.g., security core 131) of the memory security controller 130), verify, and filter access requests and responses. When enabled to operate in the second mode, the copying and filtering functions of the command copier 405, the command filter 411, the response copier 416, and the response filter 418 may be disabled, and the memory security controller 130 may use a first set of security cores and a second set of security cores (e.g., MAC core 132) capable of performing message authentication code (MAC) encryption and decryption to encrypt and decrypt access requests and corresponding responses, respectively.
[0067] To determine whether to use the first mode or the second mode to enable cryptographic functional safety, the mode selection controller 126 may be configured to determine the number of pending access requests associated with the memory security controller 130 or its corresponding core in the request queue 125 and determine the number of incoming responses from the non-volatile memory 135 to the memory security controller 130 in the response queue 127 during a given mode. Each incoming response may correspond to an access request in the pending access requests. Based on the number of pending access requests and incoming responses in the corresponding queues, the mode selection controller 126 may determine whether the non-volatile memory 135 may be slowing down the overall operation of the system 400 (i.e., is a bottleneck), or whether the memory security controller 130 or the dual pump functional safety circuit system may be slowing down the operation of the system 400 (i.e., is a bottleneck).
[0068] For example, if the number of pending access requests exceeds a threshold number, the mode selection controller 126 may determine that the non-volatile memory 135 and the memory interface controller 134 may not be processing the access requests and providing responses to the access requests quickly enough, such that the non-volatile memory 135 and the memory interface controller 134 are reducing the processing efficiency, responsiveness, throughput, etc. of the MCU 105. Therefore, the mode selection controller 126 may disable the second mode (MAC functional safety) and may enable the first mode (dual pump functional safety). Conversely, if the number of incoming responses exceeds a threshold number, the mode selection controller 126 may determine that the memory security controller 130, the command copier 405, the command filter 411, the response copier 416, and the response filter 418 may not be processing (e.g., copying, verifying, filtering) and decrypting the access requests and responses quickly enough, such that the memory security controller 130 and the dual pump circuit system are reducing the processing efficiency, responsiveness, throughput, etc. of the MCU 105. Therefore, the mode selection controller 126 may disable the first mode and enable the second mode, and update the status register 421 accordingly.
[0069] By way of a first example, in operation, the processing core 110-1 provides an access request to the safety and security components of the system 400 to access the non-volatile memory 135 based on the access request and the decryption of the information specified in the access request. More specifically, the processing core 110-1 may provide the access request to the command copier 405. The access request may correspond to a read request indicating a first data set to be read from the non-volatile memory 135. In this first example, the safety and security components of the system 400 may be configured to operate in a first mode (e.g., a dual pump function safety mode). In some examples, the mode selection controller 126 may control some components of the system 400 to operate in the first mode. In some examples, the processing core 110-1 may direct the mode selection controller 126 to control the components to operate in the first mode.
[0070] Based on being enabled to operate in the first mode, the command copier 405 may be configured to copy the read request and add the read request to the request queue 125. The memory security controller 130 may obtain the read request from the request queue 125, record an indication of the first mode corresponding to the read request, and provide the read request to the command checker 413 to verify the copying performed by the command copier 405. The command checker 413 may be configured to perform a comparison between the two read requests to verify the copying. In some examples, the command checker 413 may be configured to compare information such as the address of the read request, the number of bytes (e.g., size) of the read request, and the protocol specific information of each read request. Based on unsuccessful verification, the command checker 413 may output an indication thereof (e.g., an interrupt signal) to the processing core 110-1, indicating a failure in the dual pump functional safety operation. Based on successful verification, the command checker 413 may provide the read request to the command filter 411 to filter one of the read requests (e.g., discard).
[0071] The command filter 411 may filter the read request so that the command filter 411 provides one read request to the inline security interface controller 415. Next, the inline security interface controller 415 may perform additional security operations on the read request and provide the read request to the memory interface controller 134. Then, the memory interface controller 134 may access the nonvolatile memory 135 to obtain a first data set indicated by the read request at a set of addresses of the nonvolatile memory 135 based on the read request.
[0072] After obtaining the first data set, the memory interface controller 134 may provide a response from the non-volatile memory 135 including the first data set to the in-line security interface controller 415. The in-line security interface controller 415 may provide a security operation (e.g., malware detection) on the response and provide the response to the response copier 416. Based on operating in the first mode, the response copier 416 may copy the response and add the response to the response queue 127. The memory security controller 130 may obtain the response from the response queue 127. The memory security controller 130 may then utilize the first set of security cores (e.g., security core 131) to decrypt each copy of the copied response. After decryption, the memory security controller 130 may provide the decrypted response to the response 408 to verify the decryption. The response checker 408 may be configured to verify the decryption based on performing a comparison between the two decrypted responses to determine whether the decrypted information (e.g., the size of the response, the data or text of the response) is the same in the response. Based on unsuccessful verification, the response checker 408 may be configured to output an indication thereof to the processing core 110-1. Based on successful verification, response inspector 408 may provide the decrypted response to response filter 418 for filtering.
[0073] Response filter 418 may filter the decrypted response so that response filter 418 provides an encrypted read request to error interface 419. Error interface 419 may determine whether an error occurred during decryption or through the response, and if not, provide a response containing the first decrypted data set to processing core 110-1. If error interface 419 detects an error, error interface 419 may provide an indication thereof to processing core 110-1 if another element of system 400 has not already output an indication thereof.
[0074] By way of a second example, in operation, processing core 110-1 provides an access request to a security and protection component of system 400 to access non-volatile memory 135 based on the access request and the decryption of information specified in the access request. More specifically, processing core 110-1 may provide the access request to command copier 405. The access request may correspond to a read request indicating a second data set to be read from non-volatile memory 135. In this second example, the security and protection component of system 400 may be configured to operate in a second mode (e.g., a MAC functional safety mode). In some examples, mode selection controller 126 may control the component to operate in the second mode. In some examples, processing core 110-1 may direct mode selection controller 126 to control the component to operate in the second mode.
[0075] Based on being enabled to operate in the second mode, the command copier 405 may be configured to add the read request to the request queue 125 without duplicating the read request. The memory security controller 130 may obtain the read request from the request queue 125 and provide the read request to the command checker 413. The command checker 413 may provide the read request to the command filter 411, which may not perform filtering in view of the lack of duplication of the read request by the command copier 405 based on operating in the second mode. The command filter 411 may provide the read request to the inline security interface controller 415. Next, the inline security interface controller 415 may perform additional security operations on the read request and provide the read request to the memory interface controller 134. Then, the memory interface controller 134 may access the non-volatile memory 135 to obtain the second data set indicated by the read request at a set of addresses of the non-volatile memory 135 based on the read request.
[0076] After obtaining the second data set, the memory interface controller 134 may provide a response including the second data set from the non-volatile memory 135 to the in-line security interface controller 415. The in-line security interface controller 415 may provide security operations (e.g., malware detection) on the response and provide the response to the response copier 416. Based on operating in the second mode, the response copier 416 may add the response to the response queue 127 without copying. The memory security controller 130 may obtain the response from the response queue 127. The memory security controller 130 may utilize a first set of security cores (e.g., security core 131) and a second set of security cores (e.g., MAC core 132) to decrypt the response and perform functional safety verification thereof. More specifically, the first set of security cores may be configured to decrypt the second encrypted data set of the response and provide the decrypted data to the second set of security cores. The second set of security cores may be configured to verify the MAC information associated with the decrypted data based on comparing the MAC information received in the response with the MAC information used to encrypt the second data set.
[0077] Based on unsuccessful verification of the MAC information or other information of the response (e.g., the size of the response, the data or text of the response), the memory security controller 130 may be configured to output an indication thereof to the processing core 110-1. Based on successful verification of the MAC information and other information of the response, the memory security controller 130 may output the decrypted data to the error interface 419 and bypass other elements of the system 400 (e.g., the response checker 408) based on being enabled to operate in the second mode. In some examples, the memory security controller 130 may still provide the decrypted response to the response checker 408, despite being enabled to operate in the second mode. However, based on being enabled to operate in the second mode, the response checker 408 may provide the decrypted response to the response filter 418, which may not provide filtering based on the lack of replication of the response by the response copier 416. The response filter 418 may then provide the encrypted response to the error interface 419. The error interface 419 may determine whether an error occurred during decryption or through the response, and if not, provide a response including a second decrypted data set to the processing core 110-1. If error interface 419 detects an error, error interface 419 may provide an indication thereof to processing core 110 - 1 .
[0078] Between the time when the processing core 110-1 provides a read request as in the first example and a read request as in the second example, the security and protection component may perform cryptographic processes on other access requests associated with different data. Before processing these other access requests, the mode selection controller 126 may be configured to: determine the number of pending access requests in the request queue 125; determine the number of pending responses in the response queue 127; and control the modes of the command copier 405, the command filter 411, the response copier 416, the response filter 418, and the memory security controller 130 based on the determined number relative to the corresponding threshold. Therefore, the mode of the security and protection component may be changed one or more times to process other access requests that occur between the access requests of the above examples. For example, the processing core 110-1 may provide a first read request indicating a first data set at a first time and provide a second read request indicating a second data set at a second time later than the first time. Therefore, the mode selection controller 126 may switch modes between subsequent access requests based on this example. Other combinations or variations of access requests, responses, and mode switching can be envisioned to implement different cryptographic operations.
[0079] In various examples, non-volatile memory 135 may further provide an error check indication to memory security controller 130 via memory interface controller 134, which may be provided to processing core 110-1 via interconnect 115. Example indications may include a MAC error, which may indicate an error in encryption or decryption of an access request when components of system 400 are operating in the second mode (MAC mode). Upon determining a MAC error, memory interface controller 134 may provide an indication to inline security interface controller 415, which may provide a MAC error indication to memory security controller 130 and / or processing core 110-1. Based on receiving the MAC error indication, processing core 110-1 may be configured to retry the access request or interrupt the operation.
[0080] Figure 5 An example flow chart for controlling a cryptographic process in accordance with an embodiment of the present invention is illustrated. Figure 5 Include reference Figure 1 and Figure 4 Method 500 of an element of a processing system. Method 500 may be performed by one or more components of a processing system, such as Figure 1 MCU 105 and Figure 4 Thus, the method 500 may be implemented in hardware, firmware, and / or software, or a combination or variation thereof.
[0081] In operation 505, mode selection controller 126 may determine whether to enable adaptive switching. Adaptive switching may refer to a mode of mode selection controller 126 that, when enabled, enables mode selection controller 126 to control a cryptographic mode of a safety and security component of the system (e.g., functional safety controller 128, memory security controller 130). To enable adaptive switching, one of processing cores 110, such as processing core 110-1, may provide an enable signal (e.g., select signal 123) to mode selection controller 126. In some examples, the enable signal may include an indication of which cryptographic mode the mode selection controller 126 should also enable.
[0082] Based on the adaptive switching of mode selection controller 126 being disabled, in operation 510, mode selection controller 126 may enable a cryptographic mode (e.g., MAC cryptographic, double pump cryptographic) based on an indication provided by processing core 110-1 via selection signal 123. In some examples, the mode indicated and enabled by selection signal 123 may be determined based on processing core 110-1 executing program instructions (i.e., enabled software). In some examples, the value of selection signal 123 may be user selected or predetermined.
[0083] Based on the adaptive switching of the mode selection controller 126 being enabled, in operation 515, the mode selection controller 126 may be configured to determine the number of pending access requests associated with the non-volatile memory 135. The pending access request may refer to an access request in an access request queue waiting to be encrypted by the memory security controller 130. The memory security controller 130 may compare the number of pending access requests with a threshold number. In some examples, the threshold number may be a predetermined number based on the capacity of the access request queue (e.g., the request queue 125). In response to determining that the number of pending access requests exceeds the threshold number, in operation 525, the mode selection controller 126 may control the security and protection components to operate in a dual pumping function security mode to apply a dual pumping cryptographic function security operation to the access request and the corresponding response. In response to determining that the number of pending access requests does not exceed the threshold number, in operation 530, the mode selection controller 126 may control the security and protection components to operate in a MAC function security mode to apply a MAC function security operation to the access request and the corresponding response.
[0084] In addition, based on the adaptive switching of the mode selection controller 126 being enabled, in operation 520, the mode selection controller 126 may be configured to determine the number of incoming pending responses associated with the non-volatile memory 135. A response may refer to information returned from the non-volatile memory 135 to the memory interface controller 134 based on an access request. Each response may be provided based on an access request and thus may be associated with a specific access request. The memory security controller 130 may compare the number of incoming responses to a threshold number. In some examples, the threshold number may be a predetermined number based on the capacity of a response queue (e.g., response queue 127). In some examples, this threshold number may be the same as or different from a threshold number associated with an access request queue. In response to determining that the number of incoming responses exceeds the threshold number, in operation 530, the mode selection controller 126 may control the security and protection components to operate in a MAC functional safety mode. In response to determining that the number of pending access requests exceeds the threshold number, in operation 525, the mode selection controller 126 may control the security and protection components to operate in a dual pump functional safety mode.
[0085] Figure 6 An example flow chart for controlling a cryptographic process in accordance with an embodiment of the present invention is illustrated. Figure 6 Include reference Figure 1 and Figure 4 Method 600 of an element of a processing system. Method 600 may be performed by one or more components of a processing system, such as Figure 1 MCU 105 and Figure 4 Thus, the method 600 may be implemented in hardware, firmware, and / or software, or a combination or variation thereof.
[0086] In various examples, the method 600 may include a series of steps related to functional testing of components of the system. Thus, the steps of the method 600 may not refer to runtime operation of the system or be used during runtime operation of the system. However, in some examples, the testing steps may be intermittently employed during runtime operation to ensure correct and adequate operation of the safety and security components of the system (e.g., the safety and security subsystem 124 and its components).
[0087] In operation 605, the processing core 110-1 starts testing of the safety and security components of the system. In this step, the processing core 110-1 may provide an access request to the safety and security components, and may further enable the mode selection controller 126 to control the safety and security components to operate in a dual pump function safety mode. In this mode, the command copier 405 may replicate the access request and provide the replicated request to the command checker 413 and other components.
[0088] In operation 610, processing core 110-1 utilizes command error injection 412 to randomly corrupt data and provides the corrupted data to command checker 413. During this step, command checker 413 may be configured to receive the replicated access request from command copier 405 and perform a verification operation using the corrupted data and the replicated access request. This may require determining whether command checker 413 identifies the corrupted data and whether the corrupted data affects each copy of the replicated access request. Therefore, in operation 620, command checker 413 may confirm the error based on the verification indicating that command checker 413 received the corrupted data. Based on confirming the error, in operation 625, command checker 413 may provide an indication of confirmation to processing core 110-1. Therefore, processing core 110-1 may determine that command checker 413 has successfully passed the test and the double pump functional safety mode is operating correctly.
[0089] Similarly, in operation 615, processing core 110-1 utilizes response error injection 406 to randomly corrupt data associated with a response from non-volatile memory 135 based on an access request, and provides the corrupted data to response checker 408. During this step, response checker 408 may be configured to receive a replicated response from response copier 416, and perform a verification operation using the corrupted data and the replicated response. This may require determining whether response checker 408 identifies the corrupted data and whether the corrupted data affects each copy of the replicated response. In operation 620, response checker 408 may confirm the error based on a verification indicating that response checker 408 received the corrupted data. Based on confirming the error, in operation 625, response checker 408 may provide an indication of confirmation to processing core 110-1. Therefore, processing core 110-1 may determine that response checker 408 has successfully passed the test and that the double pump functional safety mode is operating correctly.
[0090] However, if command checker 413 or response checker 408 does not acknowledge an error, or in other words, does not identify the received corrupted data, command checker 413 and / or response checker 408 may not provide an acknowledgement to processing core 110-1 in operation 620. As a result, processing core 110-1 may determine that the dual pump circuitry (e.g., functional safety controller 128) has failed the test and may interrupt operation.
[0091] Figure 7A computing system 701 for performing cryptographic processes related to memory access according to an embodiment of the present technology is illustrated. The computing system 701 represents any system or collection of systems that can employ the various operational architectures, processes, scenarios, and sequences for memory access control disclosed herein. The computing system 701 can be implemented as a single device, system, or apparatus, or can be implemented in a distributed manner as multiple devices, systems, or apparatuses. The computing system 701 includes, but is not limited to, a processing system 702, a storage system 703, software 705, a communication interface system 707, and a user interface system 709 (optional). The processing system 702 is coupled to the storage system 703, the communication interface system 707, and the user interface system 709 in an operational manner. The computing system 701 can represent a cloud computing device, a distributed computing device, etc.
[0092] Processing system 702 loads and executes software 705 from storage system 703. Software 705 includes and implements a security mode control process 706, which represents any of the access request and response replication, filtering, encryption, decryption, and statistical data collection processes discussed with respect to the aforementioned figures. When executed by processing system 702 to provide access functions, software 705 directs processing system 702 to operate as described herein to perform at least the various processes, operating scenarios, and sequences discussed in the aforementioned embodiments. Computing system 701 may optionally include additional devices, features, or functions that are not discussed for the sake of brevity.
[0093] Still refer to Figure 7 , processing system 702 may include a microprocessor and other circuitry that retrieves and executes software 705 from a storage system 703. Processing system 702 may be implemented within a single processing device, but may also be distributed across multiple processing devices or subsystems that cooperate to execute program instructions. Examples of processing system 702 include general-purpose central processing units, graphics processing units, special-purpose processors and logic devices, and any other type of processing device, combination, or variation thereof.
[0094] The storage system 703 may include any computer-readable storage media that can be read by the processing system 702 and that is capable of storing the software 705. The storage system 703 may include volatile and nonvolatile media, removable and non-removable media implemented in any method or technology to store information such as computer-readable instructions, data structures, program modules, or other data. Examples of storage media include random access memory, read-only memory, magnetic disks, optical disks, optical media, flash memory, virtual and non-virtual memory, cassettes, magnetic tape, magnetic disk storage or other magnetic storage, or any other suitable storage media. In any case, a computer-readable storage medium is not a propagated signal.
[0095] In addition to computer-readable storage media, in some embodiments, storage system 703 may also include computer-readable communication media through which at least some of software 705 may be transferred internally or externally. Storage system 703 may be implemented as a single storage device, but may also be implemented across multiple storage devices or subsystems that are co-located or distributed relative to each other. Storage system 703 may include additional elements, such as a controller, that can communicate with processing system 702 or possibly other systems.
[0096] The software 705 (including the security mode control process 706) may be implemented in program instructions and, among other functions, may direct the processing system 702 to operate as described with respect to the various operating scenarios, sequences, and processes described herein when executed by the processing system 702. For example, the software 705 may include program instructions for selecting a cryptographic mode as described herein.
[0097] Specifically, program instructions may include various components or modules that collaborate or otherwise interact to implement the various processes and operating scenarios described herein. Various components or modules may be embodied in compiled or interpreted instructions, or in some other variant or combination of instructions. Various components or modules may be executed in a synchronous or asynchronous manner, serially or in parallel, in a single-threaded environment or in multithreading, or according to any other suitable execution paradigm, its variant or combination. Software 705 may include additional processes, programs or components, such as operating system software, virtualization software or other application software. Software 705 may also include firmware or some other form of machine-readable processing instructions that can be executed by processing system 702.
[0098] In general, software 705, when loaded into processing system 702 and executed, may transform a suitable device, system, or apparatus as a whole (represented by computing system 701) from a general purpose computing system to a special purpose computing system customized to provide memory access as described herein. In practice, encoding software 705 on storage system 703 may transform the physical structure of storage system 703. In different implementations of the specification, the specific transformation of the physical structure may depend on various factors. Examples of such factors may include, but are not limited to, the technology of the storage media used to implement storage system 703 and whether the computer storage media is characterized as a primary storage device or a secondary storage device, as well as other factors.
[0099] For example, if the computer-readable storage medium is implemented as a semiconductor-based memory, the software 705 may transform the physical state of the semiconductor memory when the program instructions are encoded therein, such as by transforming the states of transistors, capacitors, or other discrete circuit elements that make up the semiconductor memory. Similar transformations may occur with respect to magnetic or optical media. Other transformations of the physical media are possible without departing from the scope of this specification, with the foregoing examples provided merely to facilitate this discussion.
[0100] The communication interface system 707 may include communication connections and devices that allow communication with other computing systems (not shown) over a communication network (not shown). Examples of connections and devices that together allow inter-system communication may include network interface cards, antennas, power amplifiers, radio frequency circuitry, transceivers, and other communication circuitry. The connections and devices may communicate over a communication medium such as metal, glass, air, or any other suitable communication medium used to exchange communications with other computing systems or systems networks. The foregoing media, connections, and devices are well known and need not be discussed in detail herein.
[0101] Communications between computing system 701 and other computing systems (not shown) may occur over a communications network and according to various communications protocols, combinations of protocols, or variations thereof. Examples include an intranet, interconnect, the Internet, a local area network, a wide area network, a wireless network, a wired network, a virtual network, a software-defined network, a data center bus and backplane, or any other type of network, combination of networks, or variations thereof. The aforementioned communications networks and protocols are well known and need not be discussed in detail here.
[0102] Although some of the examples provided herein are described in the context of systems on a chip, processors, processing cores, microcontroller units, circuit systems, environments, etc., the memory access methods, techniques, and systems described herein are not limited to such examples and can be applied to various other processes, systems, applications, devices, etc. Aspects of the present invention may be embodied as systems, methods, computer program products, and other configurable systems. Therefore, aspects of the present invention may take the form of a complete hardware embodiment, a complete software embodiment (including firmware, resident software, microcode, etc.), or a combination of hardware and software embodiments (generally referred to herein as "circuits," "modules," or "systems"). In addition, aspects of the present invention may take the form of a computer program product implemented in one or more computer-readable media, the computer-readable media having computer-readable program code implemented thereon.
[0103] Unless the context clearly requires otherwise, throughout the description and claims, the words "comprise", "comprising", etc. should be interpreted as inclusive, rather than exclusive or exhaustive; that is, in the sense of "including but not limited to". As used herein, the terms "connect", "couple" or any variation thereof mean any connection or coupling, direct or indirect, between two or more elements; the coupling or connection between elements may be physical, logical, or a combination thereof. In addition, the words "herein", "above", "below" and words of similar meaning, when used in this application, shall refer to the application as a whole, rather than to any particular part of the application. Where the context permits, words used in the singular or plural in the above specific embodiments may also include the plural or singular, respectively. The word "or", when referring to a list of two or more items, covers all the following interpretations of the word: any item in the list, all items in the list, and any combination of items in the list.
[0104] The phrases "in some examples," "according to some examples," "in the examples shown," "in other examples," and the like generally mean that the particular feature, structure, or characteristic following the phrase is included in at least one embodiment of the present technology, and may be included in more than one embodiment. Additionally, such phrases do not necessarily refer to the same example or different examples.
[0105] The above specific implementation of the example of technology is not intended to be exhaustive or to limit the technology to the exact form disclosed above. Although the above describes the specific example of technology for illustrative purposes, as those skilled in the relevant art will recognize, various equivalent modifications can be made within the scope of technology. For example, although the process or block is presented in a given order, the alternative embodiment can perform a routine with steps in a different order or adopt a system with blocks, and some processes or blocks can be deleted, moved, added, subdivided, combined and / or modified to provide an alternative or sub-combination. Each of these processes or frames can be implemented in various different ways. In addition, although sometimes the process or block is shown as being performed serially, these processes or blocks can be performed or implemented in parallel alternatively, or can be performed at different times. In addition, any specific number mentioned herein is only an example; alternative embodiments can adopt different values or ranges.
[0106] The teachings of the technology provided herein may be applicable to other systems, not necessarily the systems described above. The elements and actions of the various examples described above may be combined to provide further implementations of the technology. Some alternative implementations of the technology may include not only the additional elements of those implementations described above, but also fewer elements.
[0107] In view of the above detailed description, these and other changes may be made to the technology. Although the above description describes certain examples of the technology and describes the best mode contemplated, no matter how detailed the above content appears in this article, the technology can be practiced in many ways. The details of the system can vary considerably in its specific implementation while still being covered by the technology disclosed herein. As described above, the specific terms used when describing certain features or aspects of the technology should not be understood to imply that the terms are redefined herein as being limited to any specific characteristics, features or aspects of the technology associated with the terms. In general, unless such terms are explicitly defined in the above specific implementation section, the terms used in the attached claims should not be interpreted as limiting the technology to the specific examples disclosed in the specification. Therefore, the actual scope of the present technology not only covers the disclosed examples, but also includes all equivalent ways of practicing or realizing the present technology under the claims.
[0108] In order to reduce the number of claims, certain aspects of the technology are presented below in certain claim forms, but applicants consider various aspects of the technology in any number of claim forms. For example, although only one aspect of the technology is described as a computer-readable media claim, other aspects may also be embodied as a computer-readable media claim, or in other forms, such as means plus function claims. It is expected that any claim processed under 35 U.S.C. §112(f) will begin with the words "device for", but the use of the term "for" in any other context is not intended to invoke processing under 35 U.S.C. §112(f). Therefore, applicants reserve the right to seek additional claims after filing this application to seek such additional claim forms in this application or a continuation application.
Claims
1. A device comprising: a memory security controller configured to operate in a first functional safety mode or a second functional safety mode; a security mode selection controller coupled to the memory security controller; and a memory interface controller coupled to the memory security controller and the security mode selection controller and configured to couple to a nonvolatile memory; The safety mode selection controller is configured to: determining a number of pending access requests associated with the memory security controller; determining a number of incoming responses from the nonvolatile memory to the memory security controller; and A selection is made between the first functional safety mode and the second functional safety mode based on at least one of the number of pending access requests or the number of incoming responses.
2. The device of claim 1, wherein the security mode selection controller is configured to: directing the memory security controller to operate in the first functional safety mode based on the number of incoming responses exceeding a first threshold number; and The memory security controller is directed to operate in the second functional security mode based on the number of pending access requests exceeding a second threshold number.
3. The device of claim 2, wherein the memory security controller is configured to copy at least one of a request or a response in the first functional safety mode and compare the copies of the at least one of the request or the response. 4 . The device of claim 3 , wherein the memory security controller is configured to compare at least a portion of a decrypted response with a message authentication code (MAC) value in the second functional security mode.
5. The device of claim 3, wherein the memory security controller is configured to, in the first functional safety mode: copying said request; encrypting information associated with each copy of the request; and A subset of the copies of the request is provided to the memory interface controller.
6. The device of claim 5, wherein the memory security controller is configured to, in the first functional safety mode: copying said response; decrypting information associated with each copy of the response; and A subset of the copies of the responses is provided to one or more processing cores.
7. The device of claim 1, wherein the pending access requests include read requests and write requests, and wherein the incoming responses include data or instructions corresponding to the pending access requests.
8. A system comprising: one or more processing cores; an interconnect coupled to the one or more processing cores; a memory security controller; a security mode selection controller coupled to the memory security controller; and a memory interface controller coupled to the memory security controller and the security mode selection controller and configured to couple to a nonvolatile memory; The safety mode selection controller is configured to: determining a number of pending access requests associated with the memory security controller; determining a number of incoming responses from the nonvolatile memory to the memory security controller; and Which cryptographically functional security process is applied to at least one of the requests or the responses is controlled based on at least one of the number of pending access requests or the number of incoming responses.
9. The system of claim 8, wherein to control which cryptographic function security process is applied by the memory security controller, the security mode selection controller is configured to: directing the memory security controller to perform a first cryptographic function security process on the at least one of the request or the response based on the number of incoming responses exceeding a first threshold number; and The memory security controller is directed to perform a second cryptographic function security process on the at least one of the request or the response based on the number of pending access requests exceeding a second threshold number.
10. The system of claim 9, wherein the first cryptographically secure process includes replicating the at least one of the request or the response.
11. The system of claim 10, wherein the second cryptographic function security process comprises comparing at least a portion of the decrypted response to a message authentication code (MAC) value.
12. The system of claim 10, wherein to perform the first cryptographic function security process, the memory security controller is configured to: duplicating the request to produce a copy of the request; encrypting information associated with each of the copies of the request; and A subset of the copies of the request is provided to the memory interface controller.
13. The system of claim 12, wherein to perform the first cryptographic function security process, the memory security controller is configured to: copying the response to produce a copy of the response; decrypting information associated with each of the copies of the response; and A subset of the copies of the responses is provided to the one or more processing cores.
14. The system of claim 8, wherein the pending access requests include read requests and write requests, and wherein the incoming responses include data or instructions corresponding to the pending access requests.
15. A method comprising: receiving, from one or more processing cores, a request to access data stored in a non-volatile memory device; determining a number of pending ones of the access requests associated with the non-volatile memory device; determining a number of incoming responses from the non-volatile memory device; and Which cryptographic security process to apply to at least one of the requests or the responses is selected based on at least one of the number of pending access requests or the number of incoming responses.
16. The method of claim 15, wherein controlling which cryptographic function security process is to be applied comprises: selecting to apply a first cryptographic function security process to said at least one of said request or said response based on said number of incoming responses exceeding a first threshold number; and Applying a second cryptographic security process to the at least one of the request or the response is selected based on the number of pending access requests exceeding a second threshold number.
17. A method according to claim 16, wherein applying the first cryptographic function security process includes copying at least one of the request or the response and comparing the copies of the at least one of the request or the response, and wherein applying the second cryptographic function security process includes comparing at least a portion of the decrypted response with a message authentication code (MAC) value.
18. The method of claim 17, wherein applying the first cryptographic function security process comprises: copying said request; encrypting information associated with each copy of the request; and A subset of the copies of the request is provided to a memory interface controller.
19. The method of claim 18, wherein applying the first cryptographic function security process further comprises: copying said response; decrypting information associated with each copy of the response; and A subset of the copies of the responses is provided to the one or more processing cores.
20. The method of claim 15, wherein the pending access requests include read requests and write requests, and wherein the incoming responses include data or instructions corresponding to the pending access requests.