Method and apparatus for processing data associated with hardware security module
By determining the identity of the computing device partition and controlling the operation of the hardware security module, the problem of poor access rights management of hardware security modules in the prior art is solved, and secure data access control for multiple partitions of the computing device is realized.
Patent Information
- Application Number
- CN202380070211.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-08-01
- Filing Date
- 2023-07-21
- Publication Date
- 2025-05-09
AI Technical Summary
The prior art is difficult to effectively manage and control the access rights of hardware security modules, resulting in different partitions or programs of computing devices that may manipulate data from other partitions, affecting data security.
By determining the partition identity of the computing device and controlling the operation of the hardware security module based on that identity, it is ensured that different partitions or programs can only access the data they are associated with. The specific method includes determining partition identity using static or temporary communication channel allocations and further protecting data access through storage protection devices and priority configurations.
The fine-grained access control of the hardware security module is realized, which prevents data cross-operation between different partitions or programs, and improves the security of the hardware security module that can be accessed by multiple partitions of the computing device.
Smart Images

Figure CN119968634A_ABST
Abstract
Description
Background Art
[0001] The present disclosure relates to a method for processing data associated with a hardware security module.
[0002] The present disclosure furthermore relates to an apparatus for processing data associated with a hardware security module. Summary of the invention
[0003] Exemplary embodiments relate to a method for processing data associated with a hardware security module, comprising: determining first information, the first information characterizing the identity of at least one partition of a computing device, the partition being configured to access the hardware security module, for example, accessing the hardware security module, and optionally using the first information, for example, for controlling the operation of the hardware security module based at least on the first information. In other exemplary embodiments, this can ensure, for example, that different partitions of the computing device or computer programs associated with different partitions, such as applications, do not manipulate data of other partitions that can be processed by the hardware security module.
[0004] In other exemplary embodiments, the hardware security module is configured to perform cryptographic primitives and / or functions, such as encryption and / or decryption and / or forming hash values and / or forming message authentication codes, and the like.
[0005] In other exemplary embodiments, the hardware security module has a key memory for storing cryptographic keys. For example, based on the first information, it can be controlled which of the multiple partitions that can use the functions of the hardware security module can use a specific cryptographic key. For example, in other exemplary embodiments, it can be specified that some partitions can only use specific cryptographic keys, while other partitions can use, for example, all cryptographic keys, etc.
[0006] In other exemplary embodiments, at least one partition has at least one computing core and optionally a memory assigned to the computing core, for example a working memory, for example a RAM (random access memory).
[0007] In other exemplary embodiments, determining the first information comprises at least one of the following elements: a) determining the first information based on a communication channel, for example statically, for example associated only with at least one partition, b) receiving the first information via a communication channel that can be at least temporarily used by the at least one partition, wherein, for example, the communication channel can be used by multiple partitions, for example in a time division multiplexed manner.
[0008] In other words, in other exemplary embodiments, it can be provided that the first information is provided as if implicitly, for example by a, for example static, allocation of a specific communication channel with a specific partition. That is, in other exemplary embodiments, the hardware security module can derive the identity of a specific partition based on which (for example statically allocated) communication channel (for example of a plurality of communication channels) information, for example data, has been received from the partition.
[0009] In other exemplary embodiments, the first information and / or further information representing the first information may be transmitted, for example, directly from one partition via a communication channel that may be used, for example, with other partitions, for example together with data for operating the hardware security module.
[0010] In other exemplary embodiments it is provided that the method comprises: receiving second information, such as an interrupt request (such as an interrupt request) and / or being associated with an interrupt request from the at least one partition, determining the first information based on a communication channel via which the second information has been received.
[0011] In other exemplary embodiments, it is provided that the method comprises at least one of the following elements: a) using multiple communication channels for communicating with different partitions of the computing device (i.e., for example, for the hardware security module to communicate with different partitions of the computing device), for example, using a first communication channel of the multiple communication channels, for example, only for communicating with the first partition, and using a second communication channel of the multiple communication channels, for example, only for communicating with the second partition, b) using, for example, a common communication channel, for communicating with different partitions of the computing device, for example, based on a time division multiplexing method.
[0012] In other exemplary embodiments, it is provided that the method comprises at least one of the following elements: a) using a first storage area, for example comprising a plurality of storage registers, for implementing a first communication channel, b) using a second storage area, for example comprising a plurality of storage registers, for implementing a second communication channel, c) using a third storage area, for example comprising a plurality of storage registers, for implementing a common communication channel for communicating with different partitions of the computing device.
[0013] In other exemplary embodiments, it is provided that the method comprises at least one of the following elements: a) using a shared memory area, such as a shared memory, such as a working memory, such as a RAM, for example for exchanging information, such as data, with at least one partition, b) virtualizing the shared memory area, for example comprising assigning different sub-areas to another partition of the computing device, respectively, c) using a storage protection device, such as a dynamic storage protection device D-MPU, for example for example for dynamically protecting at least some storage areas from access by at least some partitions of the computing device.
[0014] In other exemplary embodiments, it is provided that the method comprises: configuring a storage protection device or the storage protection device, for example a dynamic storage protection device D-MPU, wherein, for example, the configuration is performed such that the storage protection device protects, for example, at least one storage area associated with a first partition from being manipulated by at least one other partition.
[0015] In other exemplary embodiments, it is provided that the method comprises: assigning a priority to the at least one partition, and performing an operation associated with the at least one partition based at least on the priority of the at least one partition.
[0016] Other exemplary embodiments relate to an apparatus for performing a method according to an embodiment. The apparatus may be implemented, for example, by means of hardware and, at least in some exemplary embodiments, may be integrated or may be integrated into a hardware security module, for example, an otherwise at least substantially conventional hardware security module.
[0017] Further exemplary embodiments relate to a hardware security module having at least one device according to one embodiment.
[0018] Further exemplary embodiments relate to a computing device, such as a microcontroller or a microprocessor or a system on a chip SoC, which comprises at least one of the following elements: a) an apparatus according to an embodiment, b) a hardware security module according to an embodiment, c) at least one partition, which comprises, for example, at least one computing core and a memory, such as a working memory, such as a RAM, optionally assigned to the partition.
[0019] Other exemplary embodiments relate to a method for transmitting data associated with a hardware security module, comprising: providing an identity for at least one partition of a computing device that is configured to access the hardware security module, for example, to access the hardware security module, and transmitting information characterizing the identity to the hardware security module, for example via a communication channel that is common to multiple partitions.
[0020] In other exemplary embodiments, provision is made, for example, for the provision and / or transmission to take place completely on a hardware basis.
[0021] Other exemplary embodiments relate to a method for transmitting data associated with a hardware security module, comprising: providing a first communication channel for exchanging information between a first partition of a computing device, such as exactly one first partition, and the hardware security module, and optionally using the first communication channel for exchanging information between the first partition of the computing device and the hardware security module.
[0022] In other exemplary embodiments, it is provided that the method comprises providing a second communication channel for exchanging information between a second partition of the computing device, for example exactly one second partition, and the hardware security module, and optionally using the second communication channel for exchanging information between the second partition of the computing device and the hardware security module.
[0023] Other exemplary embodiments relate to an apparatus for performing a method according to an embodiment, for example for transmitting data associated with a hardware security module.
[0024] Other exemplary embodiments relate to a computer-readable storage medium comprising instructions which, when executed by a computer, cause the computer to perform a method according to an embodiment.
[0025] Further exemplary embodiments relate to a computer program comprising instructions which, when the program is executed by a computer, cause the computer to perform a method according to an embodiment.
[0026] Further exemplary embodiments relate to a data carrier signal which transmits and / or represents a computer program according to an embodiment.
[0027] Further exemplary embodiments relate to the use of a method according to an embodiment and / or an apparatus according to an embodiment and / or a hardware security module according to an embodiment and / or a computing device according to an embodiment and / or a computer-readable storage medium according to an embodiment and / or a computer program according to an embodiment and / or a data carrier signal according to an embodiment for at least one of the following elements: a) determining first information characterizing an identity of at least one partition of a computing device that is configured to access the hardware security module, for example, to access the hardware security module, b) virtualizing the hardware security module, c) determining the identity of a partition accessing the hardware security module, d) prioritizing operations associated with different partitions of a computing device based on the identity of at least one of the different partitions, and e) improving the security of a hardware security module accessible to multiple partitions of a computing device. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Further features, application possibilities and advantages of the invention are apparent from the following description of the exemplary embodiments of the invention shown in the figures of the accompanying drawings. All features described or shown here constitute the subject matter of the invention individually or in any combination, regardless of their summary in the claims or their reference and regardless of their description or representation in the description or in the drawings.
[0029] In the attached picture:
[0030] Figure 1 Schematically shows a simplified block diagram according to an exemplary embodiment,
[0031] Figure 2 Schematically illustrates a simplified flow chart according to an exemplary embodiment,
[0032] Figure 3 Schematically illustrates a simplified flow chart according to an exemplary embodiment,
[0033] Figure 4 Schematically shows a simplified block diagram according to an exemplary embodiment,
[0034] Figure 5 Schematically illustrates a simplified flow chart according to an exemplary embodiment,
[0035] Figure 6 Schematically illustrates a simplified flow chart according to an exemplary embodiment,
[0036] Figure 7 Schematically illustrates a simplified flow chart according to an exemplary embodiment,
[0037] Figure 8 Schematically illustrates a simplified flow chart according to an exemplary embodiment,
[0038] Fig. 9 Schematically illustrates a simplified flow chart according to an exemplary embodiment,
[0039] Fig.10 Schematically illustrates a simplified flow chart according to an exemplary embodiment,
[0040] Fig.11 Schematically illustrates a simplified flow chart according to an exemplary embodiment,
[0041] Fig.12 Schematically illustrates a simplified flow chart according to an exemplary embodiment,
[0042] Fig.13 Schematically illustrates a simplified flow chart according to an exemplary embodiment,
[0043] Fig.14 Schematically shows a simplified block diagram according to an exemplary embodiment,
[0044] Fig.15 schematically illustrates a simplified timing diagram according to an exemplary embodiment,
[0045] Fig.16 schematically illustrates a simplified table according to an exemplary embodiment,
[0046] Fig.17 schematically illustrates a simplified table according to an exemplary embodiment,
[0047] Fig.18 Schematically shows a simplified block diagram according to an exemplary embodiment,
[0048] Fig.19 Schematically shows a simplified block diagram according to an exemplary embodiment,
[0049] Fig. 20 schematically illustrates aspects of use according to other exemplary embodiments, and
[0050] Fig.21 A simplified block diagram according to an exemplary embodiment is schematically shown. DETAILED DESCRIPTION
[0051] Exemplary embodiments (see Figure 1 , 2 ) relates to a method for processing data associated with a hardware security module 100, comprising: determining 200 ( Figure 2 ) first information I-1, wherein the first information I-1 represents the computing device 1000 (see also according to Fig.19 The identity 302-1-ID ( Figure 1 ), the partition is configured to access the hardware security module 100, for example, to access the hardware security module 100, and optionally, using 202 ( Figure 2 ) first information I-1, for example, for controlling the hardware security module 100 based at least on the first information I-1 ( Figure 1 ) operation. In other exemplary embodiments, it can be ensured that, for example, different partitions 302-1, 302-2, ... ( Figure 1 ) or computer programs associated with different partitions 302-1, 302-2, . . . such as applications do not manipulate data that can be processed by the hardware security module 100, for example, of other partitions, respectively.
[0052] In other exemplary embodiments, Figure 1In the embodiment, the hardware security module 100 is constructed to execute cryptographic primitives KRYPT-PRIM and / or functions KRYPT-FUNKT, such as encryption and / or decryption and / or formation of hash values HASH and / or formation of message authentication codes MAC, etc.
[0053] In other exemplary embodiments, the hardware security module 100 has a key memory KS for storing cryptographic keys KS-1, KS-2, KS-3, .... For example, based on the first information I-1, it can be controlled which of the multiple partitions 302-1, 302-2, ... of the computing device 1000 can use resources, such as cryptographic primitives KRYPT-PRIM and / or cryptographic functions KRYPT-FUNKT and / or cryptographic keys KS-1, KS-2, KS-3, ... of the hardware security module 100. For example, in other exemplary embodiments, it can be provided that some partitions 302-1 can use only specific cryptographic keys KS-1, while other partitions 302-2 can, for example, use all cryptographic keys KS-1, KS-2, KS-3, etc.
[0054] In other exemplary embodiments, the hardware security module 100 has at least one, for example, secure computing core 102, which can, for example, be structurally and / or functionally separated from components external to the hardware security module 100, such as partitions 302-1, 302-2, ... and which in other exemplary embodiments is, for example, constructed to execute at least some of the cryptographic primitives KRYPT-PRIM or functions KRYPT-FUNKT.
[0055] In other exemplary embodiments, Figure 1 In the embodiment, at least one partition 302 - 1 has at least one computing core 302 - 1 a and optionally a memory, for example a working memory, for example a RAM (random access memory) 302 - 1 b, which is assigned to the computing core 302 - 1 a .
[0056] For example, the first partition 302-1 currently has a computing core 302-1a and a local working memory 302-1b, that is, for example, assigned to the computing core 302-1a, for example, only to the computing core 302-1a. The identity of the first partition 302-1 is Figure 1 In other exemplary embodiments, the identity of the first partition 302-1 may correspond to the CPU-ID (central processing unit identifier) of the computing core 302-1a, or may be based on the CPU-ID of the computing core 302-1a.
[0057] In a comparable manner, for example, second partition 302-2 has a computing core 302-2a and a local working memory 302-2b, ie, for example, assigned to computing core 302-2a, for example, only to computing core 302-2a. The identity of second partition 302-2 is Figure 1 In other exemplary embodiments, the identity of the second partition 302-2 may correspond to the CPU-ID of the computing core 302-2a, or may be based on the CPU-ID of the computing core 302-2a.
[0058] In other exemplary embodiments, Figure 1 In the Figure 1 The current exemplary two partitions 302-1, 302-2 depicted in Figure 1 Through Figure 1 It is symbolically represented by the three vertically arranged dots in the lower left center.
[0059] In other exemplary embodiments, Figure 1 In the embodiment, the hardware security module 100 can be arranged together with the partitions 302-1, 302-2, ... for example on a common semiconductor substrate (in Figure 1 ) and / or, for example, with partitions 302-1, 302-2, ... and / or with other components not depicted for clarity, constitute a system on chip (System on Chip) SoC, 1000.
[0060] In other exemplary embodiments, Figure 1 A first communication channel K1 is provided, through which the first partition 302-1, for example only the first partition 302-1 (ie for example not one of the other partitions 302-2, . . . ) can exchange information, for example data, with the hardware security module 100, see block arrow A1.
[0061] In other exemplary embodiments, Figure 1 In the embodiment, a second communication channel K2 is provided, through which the second partition 302-2, for example only the second partition 302-2 (ie, for example, not one of the other partitions 302-1, . . . ) can exchange information, for example data, with the hardware security module 100, see block arrow A2.
[0062] In other exemplary embodiments, Figure 1 In the embodiment, separate communication channels (not shown) comparable to the communication channels K1 , K2 can also be provided for at least some of the other partitions that are optionally present, for example.
[0063] In other exemplary embodiments, Figure 1In the embodiment, it is therefore provided that each partition 302 - 1 , 302 - 2 , . . . exchanges information, such as data, with the hardware security module 100 via its own or separate communication channel K1 , K2 , . . .
[0064] In contrast, Figure 4 A simplified block diagram of a SoC 1000′ according to another exemplary embodiment is shown, wherein instead of a plurality of separate communication channels K1, K2, . . . ( Figure 1 ), a communication channel K is set, for example a single communication channel K, which can be used jointly by multiple partitions 302-1, 302-2, ..., for example in time division multiplexing operation, see block arrows A1', A2'.
[0065] In other exemplary embodiments, according to Figure 1 The exemplary configuration 1000 and according to Figure 4 A hybrid form (not shown) of the exemplary configuration 1000' is also possible, in which, for example, a first number (eg, one or more) of partitions each have a separate communication channel (eg, see Figure 1 Elements K1, K2) are used to exchange information with the hardware security module 100, and wherein, for example, a second number (eg, one or more) of partitions have a common communication channel (eg, see according to Figure 4 Component K) is used to exchange information with the hardware security module 100.
[0066] In other exemplary embodiments (not shown), other hybrid forms are also conceivable, in which at least one partition 302-1 not only has a separate communication channel K1 with the hardware security module 100, but is also constructed to use a common communication channel K with the hardware security module 100, for example together with one or more other partitions 302-2, ...
[0067] In other exemplary embodiments, Figure 3 In, determine 200( Figure 2 ) The first information I-1 includes at least one of the following elements: a) based on the communication channel K1 ( Figure 1 )Determine 200a( Figure 3 ) first information I-1, the communication channel K1 is, for example, statically associated, for example, only with at least one partition 302-1 (see, for example, according to Figure 1 Configuration 1000), b) via a communication channel K ( Figure 4 ) receives 200b the first information I-1, the communication channel K can be used at least temporarily by at least one partition 302-1, wherein for example the communication channel K can be used by a plurality of partitions 302-1, 302-2, ... in a time division multiplexing manner (see for example according to Figure 4 Configuration 1000').
[0068] In other words, in other exemplary embodiments, see Figure 1 , it can be provided that the first information I-1 is provided as if implicitly, for example by a, for example, static allocation of a specific communication channel K1 using a specific partition 302-1. That is, in other exemplary embodiments, the hardware security module 100 can derive the identity 302-1-ID of the specific partition 302-1 based on which (for example, statically allocated) communication channel K1 (for example, among a plurality of communication channels K1, K2, ...) the information, for example, the data A1, has been received from the partition 302-1.
[0069] In other exemplary embodiments, Figure 4 In the embodiment, the first information I-1 and / or other information characterizing the first information I-1 can be transmitted directly from the partition 302-1 via, for example, a communication channel K that can be used in common with other partitions 302-2, ..., for example, together with data for operating the hardware security module, for example, see Figure 4 The reference numeral I-1 at the block arrows A1', A2'.
[0070] In other exemplary embodiments, Figure 1 In the embodiment, the first information I-1 and / or other information characterizing the first information I-1 can be transmitted directly from the partition 302-1 to the hardware security module 100 via, for example, a separate communication channel K1, for example, together with data for operating the hardware security module 100. In other exemplary embodiments, this is due, for example, to Figure 1 An exemplary static, for example one-to-one, assignment of the partitions 302-1, 302-2 to the communication channels K1, K2 is not necessary in order for the hardware security module 100 to obtain the first information I-1, for example to determine or be able to determine the identity of the partition accessing the hardware security module 100. Nevertheless, in other exemplary embodiments, it is not excluded that, for example, the first information I-1 is sent separately, for example via a partition-individual communication channel K1.
[0071] In other exemplary embodiments, Figure 5 The method includes: from at least one partition 302-1, 302-2, ... ( Figure 1 ) receiving 210 second information I-2, such as interrupt requests (such as interrupt request) IRQ1, IRQ2 and / or information associated with the interrupt request, i.e., information associated with the interrupt request; determining 212 ( Figure 5 ) first information I-1. If the hardware security module 100 is for example transmitted according to Figure 1If the hardware security module 100 receives the first interrupt request IRQ1 through the first communication channel K1, for example, the hardware security module 100 can infer that the first interrupt request IRQ1 or the data associated with the first interrupt request IRQ1 originates from the first partition 302-1, because the first communication channel K1 is, for example, statically assigned to the first partition 302-1. In contrast, in other exemplary embodiments, if the hardware security module 100 receives the first interrupt request IRQ1 through the first communication channel K1 according to Figure 1 If the second communication channel K2 receives the second interrupt request IRQ2, the hardware security module 100 can infer that the second interrupt request IRQ2 or the data associated with the second interrupt request IRQ2 originates from the second partition 302-2, because the second communication channel K2 is, for example, statically assigned to the second partition 302-2, and so on.
[0072] In other exemplary embodiments, Figure 6 It is stipulated that the method includes at least one of the following elements: a) using more than 220 communication channels K1, K2, ... ( Figure 1 ) for different partitions 302-1, 302-2, ... ( Figure 1 ) for communication (i.e., for example, for use according to Figure 1 The hardware security module 100 communicates with different partitions 302-1, 302-2, ... of the computing device 1000), for example, using 220a ( Figure 6 ) The first communication channel K1 among the plurality of communication channels K1, K2, ... is, for example, only used for communication A1 with the first partition 302-1, and uses 220b( Figure 6 ) A second communication channel K2 among the plurality of communication channels K1, K2, ... is, for example, only used for communication A2 with the second partition 302-2, b) using 222 ( Figure 6 ) For example, a common communication channel K ( Figure 4 ) is used to communicate A1', A2' with different partitions 301-1, 301-2, ... of the computing device, for example based on a time division multiplexing method.
[0073] In other exemplary embodiments, Figure 7 The method includes at least one of the following elements: a) using 225 a first storage area SB-1 (eg, including a plurality of storage registers (not shown) Figure 1 ), used to implement the first communication channel K1, b) using 227 ( Figure 7 ) For example, a second storage area SB-2 ( Figure 1 ), used to implement the second communication channel K2, c) using 229 ( Figure 7 ) For example, a third storage area SB-3 including a plurality of storage registers for implementing a common communication channel K ( Figure 4) is used to communicate with different partitions 302-1, 302-2, ... of the computing devices 1000, 1000'.
[0074] In other exemplary embodiments, at least one of the storage areas SB-1, SB-2, SB-3 can be set in a shared memory (i.e., usable by one or more partitions and the hardware security module 100), such as a working memory, RAM, SH-RAM.
[0075] In other exemplary embodiments, Figure 8 The method comprises at least one of the following elements: a) using 230 a shared memory area SH-MEM, such as a working memory, such as a RAM, a SH-RAM, such as a shared memory, for example for exchanging information, such as data, with at least one partition 302-1, 302-2, ..., b) virtualizing 232 the shared memory area SH-MEM, for example including assigning different sub-areas of the shared memory area SH-MEM, such as memory areas SB-1, SB-2, respectively, to another partition 302-1, 302-2 of the computing device, c) using 234 ( Figure 8 )Optional storage protection device MPU( Figure 1 , 4 ), such as a dynamic storage protection device D-MPU, for example, for dynamically protecting at least some storage areas SB-1 from access by at least some partitions 302-2 of the computing device.
[0076] In other exemplary embodiments, Fig. 9 The method comprises: configuring 240 a storage protection device MPU or the storage protection device MPU, for example a dynamic storage protection device D-MPU, wherein for example the configuration 240 is performed so that the storage protection device MPU protects, for example, at least one storage area SB-1 ( Figure 1 , 4 ) is protected from manipulation by at least one other partition 302-2, .... Fig. 9 The optional block 242 symbolically represents the use of at least one storage area SB- 1 for data exchange between the first partition 302 - 1 and the hardware security module 100 .
[0077] In other exemplary embodiments, Fig.10The method includes: assigning 245 a priority PR-1 to at least one partition 302-1, and performing 247 an operation OP-302-1 (e.g., encrypting data) associated with at least one partition 302-1 based at least on the priority PR-1 of the at least one partition 302-1. In other exemplary embodiments, for example, the priority PR-1 may be assigned based on the first information I-1. Fig.15 Other exemplary aspects and implementations related to priorities are described.
[0078] Other exemplary embodiments (see Fig.21 ) relates to an apparatus 400 for performing a method according to an embodiment. The apparatus 400 can be implemented, for example, by means of hardware, for example only by means of hardware, and can be integrated into or integrated into a hardware security module 100 at least in some exemplary embodiments, for example see Figure 1 , 4 .
[0079] Other exemplary embodiments, Figure 1 , 4 The invention relates to a hardware security module 100 having at least one device 400 according to one embodiment.
[0080] In other exemplary embodiments, Fig.21 It is stipulated that the apparatus 400 includes: a computing device ("computer") 402, which has, for example, at least one computing core 402a; a storage device 404 assigned to the computing device 402, for at least temporarily storing at least one of the following elements: a) data DAT (for example, representing at least one of the following elements: first information I-1, second information I-2, information representing the identity 302-1-ID of at least one partition 302-1, information representing the allocation of communication channels K1, K2 to partitions 302-1, 302-2, information representing the priority PR-1 associated with at least one partition 302-1, for example, virtualization 232 for a shared storage area SH-MEM and / or configuration information for a storage protection device MPU or the storage protection device MPU); b) a computer program PRG, in particular for executing a method according to an embodiment (for example, in the case of a non-pure hardware-based implementation of the apparatus 400).
[0081] In other exemplary embodiments, the storage device 404 includes a volatile memory 404a (eg, a working memory (RAM)) and / or a non-volatile memory 404b (eg, a flash EEPROM) or a combination thereof or a combination with other memory types not explicitly mentioned.
[0082] Further exemplary embodiments relate to a computer-readable storage medium SM, such as a semiconductor memory and / or an optical data carrier and / or a magnetic storage medium, which comprises instructions PRG which, when executed by a computer 402 , cause the computer to perform a method according to an embodiment.
[0083] Other exemplary embodiments relate to a computer program PRG comprising instructions which, when the program PRG is executed by a computer 402 , cause the computer to carry out a method according to an embodiment.
[0084] Further exemplary embodiments relate to a data carrier signal DCS which transmits and / or represents a computer program PRG according to an embodiment. The data carrier signal DCS can be transmitted, for example like other optional data D, for example via the optional data interface 406 .
[0085] In other exemplary embodiments, for example, when the device 400 or the functionality of the device 400 is integrated into the hardware security module 100, the implementation or execution according to the method can be realized, for example, by using corresponding and possibly already existing components of the hardware security module 100. Fig.21 At least some of the components 402, 402a, 404, 404a, 404b, ... of the apparatus 400 (e.g., according to Fig.21 , computing core 402a is implemented or implemented by HSM computing core 102, etc.).
[0086] Other exemplary embodiments, Figure 1 , 4 It relates to a computing device, such as a microcontroller or a microprocessor or a system on chip SoC 1000, 1000', which includes at least one of the following elements: a) an apparatus 400 according to an embodiment, b) a hardware security module 100, such as a hardware security module 100 according to an embodiment, c) at least one partition 302-1, 302-2, ..., such as having at least one computing core 302-1a, 302-2a, ... and optionally having a memory allocated to the partition, such as a working memory, such as a RAM 302-1b, 302-2b, ...
[0087] Other exemplary embodiments, Fig.11 A method for transmitting and hardware security module 100 ( Figure 1 , 4 ) associated data, comprising: providing 250 an identity 302-1-ID for a computing device configured to access A1 hardware security module 100, for example, access at least one partition 302-1 of the hardware security module 100; for example, via a communication channel K( Figure 4 ), transmits 252 the information I-ID representing the identity 302-1-ID to the hardware security module 100 (eg in the form of the second information I-2 and / or the first information I-1 and / or the identity 302-1-ID itself).
[0088] In other exemplary embodiments, Fig.11 It is provided that, for example, providing 250 and / or transmitting 252 is performed entirely based on hardware.
[0089] Other exemplary embodiments, Fig.12 A method for transmitting and hardware security module 100 ( Figure 1 , 4 ) associated data, comprising: providing 260( Fig.12 )First communication channel K1( Figure 1 ) is used to exchange information A1 between the first partition 302-1 of the computing device, for example, exactly one first partition 302-1 and the hardware security module 100, and optionally, a first communication channel K1 is used to exchange information A1 between the first partition 302-1 of the computing device and the hardware security module 100.
[0090] In other exemplary embodiments, Fig.13 It is provided that the method comprises: providing 264 a second communication channel K2 ( Figure 1 ), for exchanging information A2 between a second partition 302-2 of the computing device, for example, exactly one second partition 302-2, and the hardware security module 100, and optionally, using 266 a second communication channel K2 for exchanging information A2 between the second partition 302-2 of the computing device and the hardware security module 100.
[0091] Other exemplary embodiments, Figure 1 It is related to a method for performing the following steps, for example, according to Fig.11 and / or Fig.12 and / or Fig.13 An apparatus 301 of a method, for example, for transmitting data associated with a hardware security module.
[0092] In other exemplary embodiments, the device 301 ( Figure 1 ) For example, according to Fig.21 A comparable or at least similar configuration of the apparatus 400 , wherein an implementation, for example a purely hardware-based implementation, is possible.
[0093] Fig.14A simplified block diagram according to an exemplary embodiment is schematically shown, which illustrates the information flow between a partition 302-1' and a hardware security module 100' of a computing device according to other exemplary embodiments. The element e1 symbolically represents an application or application program, which can be executed on the partition 302-1' and, for example, performs security-related functions and uses the hardware security module 100' at least temporarily for this purpose. The element e2 symbolically represents the preparation of data for processing with the help of the hardware security module 100', such as a "security job". The arrow a1 symbolically represents the writing of the prepared data into a memory e5 shared with the hardware security module 100', such as a memory area e5a of a shared RAM. The element e3 symbolically represents the signaling to the hardware security module 100': for example, the security job is ready for processing by the hardware security module 100', see also the arrow a2. The signaling e3 can be performed, for example, using an interrupt request, which the partition 302-1' sends to the hardware security module 100'. In addition to the interrupt request, for example, together with the interrupt request, information characterizing the memory area e5a, for example in the form of a pointer to a corresponding address of the shared memory e5 and / or information characterizing the cryptographic key KS-1 ( Figure 1 ) is transmitted to the hardware security module 100', for example, in the form of a pointer to a corresponding address of the key memory KS.
[0094] Element e6 symbolically represents receiving or reading information or data signaled by partition 302-1', see also arrow a3. Element e7 symbolically represents processing data by hardware security module 100'. Element e8 symbolically represents outputting the result of data processing by hardware security module 100', for example, outputting to storage area e5b of shared memory e5, see also arrow a4. Element e4 symbolically represents reading the result of data processing by hardware security module 100' through partition 302-1', see also arrow a5.
[0095] In other exemplary embodiments, for example in the case where the partition 302-1' sends at least one, some or all interrupt requests a2 to the hardware security module 100', in addition to the interrupt request or interrupt number characterizing the interrupt request, information about the identity 302-1'-ID of the sending partition 302-1' may additionally be transmitted to the hardware security module 100'.
[0096] In other exemplary embodiments, the identity 302 - 1 ′-ID is provided, for example, via a hardware-based, for example purely hardware-based mechanism, so that manipulation, for example by software, for example application e1 , is not possible.
[0097] In other exemplary embodiments, it is provided that the identity 302-1'-ID of the partition 302-1' is transmitted, for example together (i.e., for example, if necessary in addition to other information or data) when the partition 302-1' interacts, for example, with at least some, for example, multiple, for example, each, for example, any of the memory e5 and / or the hardware security module 100'.
[0098] In other exemplary embodiments, the hardware security module 100' and the at least one partition 302-1' are configured such that the hardware security module 100' and the at least one partition 302-1' can exchange information or data, for example, via at least one corresponding address area e5a, e5b, for example, in a shared memory, such as a shared RAM, e5.
[0099] In other exemplary embodiments, for example, information characterizing which operation(s) should be performed in the hardware security module 100' and, if necessary, a pointer (e.g., a Pointer) to data that can be used for (one or more) operations (e.g., a pointer to data that should be encrypted by the hardware security module 100' and, if necessary, other information (e.g., parameters) about (one or more) operations to be performed) are located in the address area.
[0100] In other exemplary embodiments, the device 400 according to the embodiment may be provided in the hardware security module 100 ′, and the device may also be referred to as a “Partition Detector”, ie, a partition detector, in other exemplary embodiments.
[0101] In other exemplary embodiments, the apparatus 400 associates and / or manages, for example, a unique identity, such as a "partition ID", for some, such as all operations executed or called in the hardware security module 100'. In other exemplary embodiments, all operations executed or called in the hardware security module 100' can be traced back to a specific partition, which can be called a "source partition", for example.
[0102] In other exemplary embodiments, for example, based on a plurality of physical partitions 302-1, 302-2, . . . ( Figure 1 )Configure the number of partitions and / or the partition IDs to which they belong.
[0103] In other exemplary embodiments, Figure 1For example, when performing operations on the partition 302-1 in the hardware security module 100, it is ensured, for example, by the device 400 and / or under the control of the device 400 that, for example, only data associated with the partition 302-1 is accessed or can be accessed. For this purpose, in other exemplary embodiments, at least one function of the hardware security module 100, for example an application, such as a key memory KS or a secure data storage (Datenhaltung) (for example a secure log (Secure Log), not shown) can be virtualized accordingly.
[0104] In other exemplary embodiments, Figure 1 In the embodiment, the hardware security module 100, 100' is configured to perform process planning of operations, such as scheduling, such as preemptive scheduling ( Scheduling).
[0105] In other exemplary embodiments, Figure 1 In the example, the scheduling can be implemented, for example, by a software-based or firmware-based mechanism SCHED-MECH in the hardware security module 100, 100'. In this case, in other exemplary embodiments, for example, respective priorities are assigned to the respective operations, and the respective operations are executed on the hardware security module 100 according to the assigned priorities. Figure 1 An optional, for example firmware-based mechanism SCHED-MECH may also be optionally provided in accordance with Figure 4 The HSM 100 is, however, not currently depicted there for the sake of clarity.
[0106] If, for example, an operation with a lower priority is executed during which an operation with a higher priority arrives at the hardware security module 100 (e.g., by being signaled by a partition), in other exemplary embodiments, the new operation is prioritized and the operation with the lower priority is suspended. In other exemplary embodiments, information describing the status of the operation, such as all information, is stored in a memory before the suspension, so that, for example, the operation with the lower priority can be completed after the operation with the higher priority is executed.
[0107] In the case of, for example, using the device 400 as a "partition detector", for example, using a plurality of partitions 302-1, 302-2, ... ( Figure 1) When using the principle according to the embodiment, in other exemplary embodiments, the preemptive scheduling can be designed so that, for example, the device 400 and / or the scheduling mechanism SCHED-MECH in the hardware security module 100 are configured so that each partition also has its own priority, which, for example, invalidates the priority of a specific operation from a specific threshold. Thus, in other exemplary embodiments, it is prevented that each operation of each partition may be "starved", that is, not (or, for example, not) executed for a relatively long period of time.
[0108] In other exemplary embodiments, the previously mentioned threshold values may be defined, for example, by means of more complex rules, but in still other exemplary embodiments, simpler rules are also possible.
[0109] In other exemplary embodiments, the threshold value may be configured, for example, so that the operation of a specific partition with a specific priority level (priority value) may be interrupted only n times, n>=0. Fig.15 A simplified example according to another exemplary embodiment is shown in a diagram of , wherein the horizontal axis t represents time and the vertical axis P represents priority. For the sake of clarity, four different priority values 1, 2, 3, 4 are currently set exemplarily, and by way of example and without limiting generality, it is assumed that there are four partitions that can access the hardware security module 100 ( Figure 1 ). In other exemplary embodiments, there may be fewer or more than four different priority values and / or fewer or more than four partitions.
[0110] In other exemplary embodiments, for example, by a software-based or firmware-based mechanism SCHED-MECH( Figure 1 ) sets the schedule so that the operation of the first partition 302-1 can be interrupted, for example, at most twice. Currently, the operation e10 of the first partition, which exemplarily has a priority value of 1 (lowest priority), is interrupted by the operation e15 of the third partition (priority value 3), and then by the operation e14 of the second partition (priority value 2). Before the execution e17 of the fourth operation (priority value 4) occurs, the first operation is, for example, continued, for example, completely executed, see element e12. Element e11 symbolically represents the interruption of the first operation e10, e12, element e13 symbolically represents the operation of the second partition waiting for the end of operation e15, and element e16 symbolically represents the operation e17 of the fourth partition waiting for the end of operation e12.
[0111] In other exemplary embodiments, the partitions 302-1, 302-2, . . . ( Figure 1 ) and virtualization of the communication channel between the hardware security module 100, 100'.
[0112] In other exemplary embodiments, different methods can be used to signal: which partition of the plurality of partitions 302-1, 302-2, ... currently wants to trigger communication with the hardware security module 100, 100'. In other exemplary embodiments, for example, a multiplication of the communication channels is set, for example, see Figure 1 Configuration 1000. In other exemplary embodiments, for example, a (eg, single) communication channel K is shared, for example, Sharing, for example, see Figure 4 Configuration 1000'.
[0113] In other exemplary embodiments, in the case of the multiplication of the communication channels mentioned above, for example, each individual partition 302-1, 302-2, ... is provided with, for example, a complete register set (e.g., a storage register set), see channel K1 for the first partition 302-1, channel K2 for the second partition 302-2, etc., which is used for communication with the hardware security module 100, 100'. This means that, in other exemplary embodiments, each partition 302-1, 302-2, ... is physically and explicitly provided with a complete register set.
[0114] In other exemplary embodiments, the register sets are numbered consecutively, for example, in sequence, so that the device 400, for example a "partition detector", in the hardware security module 100, 100' can clearly determine, for example confirm: from which partition the corresponding communication comes. In other exemplary embodiments, the advantage of this variant is that no conflicts can occur between the individual partitions 302-1, 302-2, ... in the communication channel (or multiple channels K1, K2, ...).
[0115] In other exemplary embodiments, in the case of the above-mentioned Sharing, a (eg, common) communication channel K is shared between the partitions 302-1, 302-2, ... Figure 4 ), in which case for example all partitions are provided with a unique identity (eg a "partition ID"), in other exemplary embodiments the unique identity is derived, for example, from the CPU-ID of its respective computing core.
[0116] In other exemplary embodiments, it can be provided that the partition ID is represented, for example, by a byte value (i.e., with an amount of information of 8 bits), which byte value is, for example, unique. In other exemplary embodiments, for example, in addition to other information or data to be transmitted in the communication channel K, if necessary, its unique partition ID is transmitted to the hardware security module, for example, when the respective partition is interrupted. If the communication channel K is currently occupied, for example, by another partition, it can be provided that the partition waits until the communication channel K is available again for terminating (absconding) further communication (such as interruption). In other exemplary embodiments, in the case of this method, it may be advantageous that there is a single communication channel K, which, for example, does not have to be increased.
[0117] In other exemplary embodiments, Figure 1 In the embodiment, virtualization of the shared memory SH-MEM can be provided. In other exemplary embodiments, the shared memory SH-MEM can be used, for example, to exchange data between partitions and hardware security modules 100, 100'. In particular, it can be provided that multiple, for example all partitions access the shared memory SH-MEM. In this case, in some exemplary embodiments, the following situation may occur: the second partition manipulates the data of the first partition in the shared memory SH-MEM, and thereby may affect the execution of operations in the hardware security modules 100, 100'. In other exemplary embodiments, this is prevented, for example, by at least one of the following elements: a) virtualizing the shared memory SH-MEM, for example by means of sharing (Sharing), b) using a storage protection device MPU, for example a dynamic MPU.
[0118] In other exemplary embodiments, virtualization of the shared memory SH-MEM is performed by means of sharing, wherein the shared memory is configured, for example, so that, for example, a dedicated area SB-1, SB-2 is predefined for each partition 302-1, 302-2, wherein, for example, only one partition can be written to, and, for example, the other partitions can be operated in a read-only manner (or, for example, not at all). In other exemplary embodiments, the hardware security module 100, 100' can be constructed, for example, configured, so that it can operate both in a read mode and in a write mode on, for example, all storage areas configured accordingly, which in other exemplary embodiments provides a relatively high reliability.
[0119] In other exemplary embodiments, for example, a dynamic memory protection unit (D-MPU) MPU ( Figure 1) is used to virtualize individual memory areas, such as memory blocks. In other exemplary embodiments, the D-MPU protects memory areas and address areas, for example, similarly to an MPU. In other exemplary embodiments, the D-MPU, for example, unlike a conventional MPU or MMU (memory management unit), can be dynamically, for example, on demand (i.e., for example, when needed and therefore flexibly), for example, by the hardware security module 100, 100', for example, depending on the software application e1( Fig.14 ), for example, so that a predeterminable address area of the storage device is protected accordingly. After, for example, the storage area is protected accordingly by the D-MPU, in other exemplary embodiments, only the hardware security module 100, 100' can make changes to the storage area. In other exemplary embodiments, it is achieved, for example, that a potential attacker who has taken over the software system (for example, except for the hardware security module 100, 100') does not transfer manipulated information to the hardware security module 100, 100' and / or makes corresponding changes to the content in the storage area during data processing by the hardware security module 100, 100'.
[0120] In other exemplary embodiments, for example, in addition to using the D-MPU, information is also provided: which partition owns the respective memory area. In other exemplary embodiments, the use of the D-MPU also prevents, for example, manipulation by one partition in the memory area of another partition.
[0121] However, in other exemplary embodiments, for example in contrast to memory sharing, it is additionally prevented that the owning partition manipulates its memory areas after it has transferred data to the hardware security module 100 , 100 ′, for example for the purpose of operating on the memory areas.
[0122] In other exemplary embodiments, the D-MPU is configured dynamically, for example at runtime, for example only by the hardware security module 100, 100' or the hardware security module 100, 100'. To this end, the D-MPU can, for example, protect individual and / or multiple address areas in the memory from being changed by individual partitions.
[0123] exist Fig.16 In FIG. 1 , a storage area of a storage device according to an exemplary embodiment is depicted in a simplified manner. The first column SP-1 represents a storage address, the second column SP-2 represents a data content, the third column SP-3 represents at least one protection flag, such as a Protection Flag (which may be represented by one or more bits, such as a bitmap, such as a linear bitmap), and the fourth column SP-4 represents an owner (e.g., an owner), i.e., a partition that owns the corresponding storage area. As shown in FIG. Fig.16As can be seen, the first row Z-1 describes the storage address 0x00, which has a data content of 0x1245, a protection flag of "W", and the storage address is assigned to the first partition Par#1. Another row Zk describes the storage address 0xA0, which has a data content of 0x156A, a protection flag of "R", "W", and the storage address is assigned to the third partition Par#3. Another row Zm describes the storage address 0xBA, which has a data content of 0xA352, a protection flag of "W", and the storage address is assigned to all partitions. Another row Zo describes the storage address 0xD3, which has a data content of 0x425D, no protection flag, and the storage address is assigned to the second partition Par#2.
[0124] In other exemplary embodiments, the protection flag or Protection Flag is defined as follows:
[0125] "W" = write protection, changes in the address area are not possible, read access is possible;
[0126] "R", "W" = read / write protection, i.e. neither read nor write access is possible;
[0127] "" = no protection or no flag set, the address area can be accessed not only in read mode but also in write mode;
[0128] "Part#n", n>=1, describes the partition to which the memory area belongs. For example, only this partition can access the memory in principle (for example according to "R", "W"), unless, for example, a protection flag overwrites the access authorization;
[0129] "ALL" = Access to this memory area is possible arbitrarily via all partitions.
[0130] In other exemplary embodiments, the protection flag of the memory area may change during operation, for example, due to a corresponding configuration of the D-MPU by the hardware security module 100, 100'. In other exemplary embodiments, it is provided that, for example, after the data of the partition have been transferred to the hardware security module 100, 100', the hardware security module 100, 100' protects at least one memory area, for example, from further access, for example, manipulation, for example, by an owner (e.g., "partition owner"), whereby, in other exemplary embodiments, for example, time-of-check / time-of-use attacks can be prevented.
[0131] The key storage KS( Figure 1), for example, relating to the virtualization of the key memory KS. In the following, for example, aspects of the device 400 are also explained using the example of the key memory KS in the sense of a "partition detector", wherein the aspects mentioned in other exemplary embodiments can also be transferred to other, for example, all other application scenarios of the hardware security module 100, 100', in which, for example, sensitive data belong to a specific partition, such as applications related to the aspect of "security log".
[0132] In other exemplary embodiments, for example, all cryptographic keys are securely stored in a key memory KS. The key memory KS is stored in an encrypted manner, for example in a flash memory, and is loaded into the hardware security module 100, 100', for example, during initial booting. In order to prevent one partition from being able to access the cryptographic material of another partition, in other exemplary embodiments, for example, corresponding access rights are configured for each individual entry in the key memory KS.
[0133] In other exemplary embodiments, in the key memory KS, for example, in addition to access rights such as "Read", "Write", "Executable", for example, corresponding additional protection flags can be provided, for example, set, for example, as described above for the storage device, for example, the shared memory SH-MEM. If these protection flags are set accordingly, this will mean, for example, that one partition can, for example, overwrite the key, but another partition can only use the key (but, for example, cannot overwrite the key). In other exemplary embodiments, it can also be provided, for example, that a read flag is set for the key memory KS.
[0134] Fig.17 A simplified table according to an exemplary embodiment is schematically shown, which contains information of an exemplary key storage. The key identification (e.g., key ID (Key-ID)) is contained in column SP-1, column SP-2 contains the cryptographic key, column SP-3 contains information about the key type or the algorithm for which the relevant key can be used, column SP-4 contains other characteristics of the relevant key (e.g., "Verify-only", "For verification only", "Signing Key", "Key for signing"), and column SP-5 specifies the partition as the owner of the relevant key if necessary. In other exemplary embodiments, for example, only the owner of the key according to column SP-5 can use the relevant cryptographic key for the operation. In other exemplary embodiments, other permission granularities are also possible, but in accordance with Fig.17 Not shown in the exemplary drawing.
[0135] Fig.18 A simplified block diagram according to other exemplary embodiments is schematically shown. A hardware security module 100", is depicted, which is, for example, arranged on the same semiconductor substrate 1002 as multiple partitions e32-1, ..., e32-n of the computing device. Information or data exchange between components e32-1, ..., e32-n, 100", is performed, for example, via a bus system a6, for example a chip-internal ("on-chip") bus system a6. Units e32-1', e32-n' are allocated to some, for example all, partitions e32-1, ..., e32-n, respectively, for providing identifications ID#1, ..., ID#n of the partitions e32-1, ..., e32-n assigned thereto, for example when the respective partitions transmit data to the hardware security module 100", the units transmit, for example, the identifications of the respective partitions to the hardware security module 100", see arrows a7, a8. In this way, the hardware security module 100 ″ obtains first information I- 1 characterizing the identity of at least one partition e32 - 1 , . . . , e32 - n accessing the hardware security module 100 ″.
[0136] Element e21 symbolically represents an optional device for supporting the debugging process. Element e22 symbolically represents, for example, a secure computing core. Element e23 symbolically represents at least one entropy source, such as a pseudo-random number generator (PRNG) or a random number generator (TRNG). Element e24 symbolically represents, for example, a secure memory (e.g., protected from access outside the hardware security module 100"), such as a volatile memory, such as a working memory, such as a secure local RAM. Element e25 symbolically represents a device for forming a hash value. Element e26 symbolically represents an interface with the bus system a6. Element e27 symbolically represents an apparatus 400 according to an embodiment. Element e28 symbolically represents a device for executing cryptographic primitives and / or functions, for example, based on ECC (elliptic curve cryptography). Element e29 symbolically represents a device for executing cryptographic primitives and / or functions, for example, based on the RSA algorithm. Element e30 symbolically represents a device for executing cryptographic primitives and / or functions, for example, based on the AES algorithm.
[0137] The element e31 symbolically represents a memory device, which is connected, for example, via a bus system a6, for example of the RAM type, said memory device being divided, for example, into a shared memory area e31a, a system RAM e31b and a protected area e31c.
[0138] The device e27, 400 can determine the identities of the individual partitions e32-1, . . . and provide the identities, for example, for controlling the operation of the hardware security module 100" based on the determined identities.
[0139] Fig.19 Schematically shows a simplified block diagram of a SoC 1000" according to an exemplary embodiment, wherein the SoC has a computing device 300 with multiple partitions e32-1, e32-2, ..., e32-n, a hardware security module 100", a storage device e31, for example, according to Fig.18 The configurations are similar or identical. Element e33 symbolically represents a D-MPU having a configuration e33a, which can be predetermined and / or changed, for example, by a hardware security module 100", for example via a bus system a6. Element e34 symbolically represents a non-volatile memory, such as a flash memory, such as a host flash memory, which has, for example, a storage area e34a for data and a storage area e34b for program code. Element e35a symbolically represents a chip or SoC internal diagnostic interface, element e35b symbolically represents a register associated with the diagnostic interface e35a, and element e35c symbolically represents an external (arranged outside the SoC 1000") diagnostic device, such as a debug access port (Debug Access Port), i.e., a terminal for diagnostic access, for example for debugging.
[0140] The element e36 symbolically represents a device for processing data associated with, for example, AES, which is connected to the interface e26, for example via the secure bus system a9, and is, for example, the same or similar to the flash memory e20 assigned to the hardware security module 100", see the secure bus system a10. The flash memory e20 has, for example, a data area e20a and an area e20b for program code.
[0141] Other exemplary embodiments, Fig. 20 The invention relates to a method according to an embodiment and / or an apparatus 301, 400 according to an embodiment and / or a hardware security module 100, 100', 100" according to an embodiment and / or a computing device 300, 1000, 1000' according to an embodiment and / or a computer-readable storage medium SM according to an embodiment and / or a computer program PRG according to an embodiment and / or a use 500 of a data carrier signal DCS according to an embodiment for at least one of the following elements: a) determining 501 first information I-1, which characterizes the identity of at least one partition of the computing device that is configured to access a hardware security module, for example, accessing the hardware security module, b) virtualizing 502 the hardware security module, c) determining 503 the identity of the partition accessing the hardware security module, d) prioritizing 504 operations associated with different partitions of the computing device based on the identity of at least one of the different partitions, e) improving 505 the security of a hardware security module that can be accessed by multiple partitions of the computing device.
[0142] The principles according to the embodiments may be used, for example, for a microprocessor and / or a microcontroller or for SoC 1000, 1000', 1000", for example, for a control device for a vehicle, for example a motor vehicle (e.g., a control device for an internal combustion engine and / or an airbag and / or a braking system, etc.), and / or may be used for a domain control device, but is not limited thereto.
Claims
1. A method for processing and hardware security module (100; 100'; 100”) associated data, comprising: Determining (200) first information (I-1), the first information characterizing an identity (302-1-ID) of at least one partition (302-1) of a computing device (300), the partition being configured to access (A1) the hardware security module (100; 100'; 100"), for example accessing the hardware security module (100; 100'; 100"), and optionally using (202) the first information (I-1), for example for controlling the operation of the hardware security module (100; 100'; 100") based at least on the first information (I-1).
2. A method according to claim 1, wherein determining (200) the first information (I-1) comprises at least one of the following elements: a) determining (200a) the first information (I-1) based on a communication channel (K1) which is, for example, statically, for example, associated only with at least one partition (302-1), b) receiving (200b) the first information (I-1) via a communication channel (K) which can be used at least temporarily by the at least one partition (302-1), wherein, for example, the communication channel (K) can be used by multiple partitions (302-1, 302-2, ...) in a time division multiplexed manner.
3. The method according to at least one of the preceding claims, comprising: Second information (I-2), such as an interruption request and / or associated with an interruption request, is received (210) from at least one partition (302-1), and the first information (I-1) is determined (212) based on the communication channel (K1) via which the second information (I-2) has been received.
4. The method according to at least one of the preceding claims, comprising at least one of the following elements: a) using (220) multiple communication channels (K1, K2, ...) for communicating with different partitions (302-1, 302-2, ...) of the computing device (300), for example, using (220a) a first communication channel (K1) of the multiple communication channels (K1, K2, ...), for example, only for communicating with the first partition (302-1), and using (220b) a second communication channel (K2) of the multiple communication channels (K1, K2, ...), for example, only for communicating with the second partition (302-2), b) using (222) for example a common communication channel (K), for example, based on a time division multiplexing method, for communicating with different partitions (302-1, 302-2, ...) of the computing device (300).
5. The method according to at least one of the preceding claims, comprising at least one of the following elements: a) using (225) a first storage area (SB-1), for example comprising a plurality of storage registers, for implementing a first communication channel (K1), b) using (227) a second storage area (SB-2), for example comprising a plurality of storage registers, for implementing a second communication channel (K2), c) using (229) a third storage area (SB-3), for example comprising a plurality of storage registers, for implementing a common communication channel (K) for communicating with different partitions (302-1, 302-2, ...) of the computing device (300).
6. The method according to at least one of the preceding claims, comprising at least one of the following elements: a) using (230) a shared memory area (SH-MEM), such as a shared memory, such as a working memory, such as a RAM, for example for exchanging information, such as data, with the at least one partition (302-1, 302-2, ...), b) virtualizing (232) the shared memory area (SH-MEM), for example comprising assigning different sub-areas (SH-MEM-1, SH-MEM-2, ...) to another partition (302-1, 302-2, ...) of the computing device (300), respectively, c) using (234) a storage protection device (MPU), such as a dynamic storage protection device D-MPU, for example for example for dynamically protecting at least some storage areas from access by at least some partitions (302-1, 302-2, ...) of the computing device (300).
7. The method according to at least one of the preceding claims, comprising: A storage protection device (MPU) or the storage protection device (MPU), for example a dynamic storage protection device D-MPU, is configured (240), wherein the configuration (240) is performed, for example, so that the storage protection device protects at least one storage area, for example associated with a first partition (302-1), from being manipulated by at least one other partition (302-2, ...).
8. The method according to at least one of the preceding claims, comprising: A priority level (PR-1) is assigned (245) to the at least one partition (302-1), and an operation (OP-302-1) associated with the at least one partition (302-1) is performed (247) based at least on the priority level (PR-1) of the at least one partition (302-1).
9. An apparatus (400) for performing the method according to at least one of the preceding claims.
10. A hardware security module (100; 100'; 100") comprising at least one device (400) according to claim 9.
11. A computing device (300), such as a system on chip SoC (1000; 1000'; 1000"), comprising at least one of the following elements: a) an apparatus (400) according to claim 9, b) a hardware security module (100; 100'; 100") according to claim 10, c) at least one partition (302-1, 302-2, ...).
12. A method for transmitting and hardware security module (100; 100'; 100”) associated data, comprising: A computing device (300) configured to access (A1) the hardware security module (100; 100'; 100″), for example, at least one partition (302-1) accessing the hardware security module (100; 100'; 100″) provides (250) an identity (302-1-ID), for example, by transmitting (252) information (I-ID) characterizing the identity (302-1-ID) to the hardware security module (100; 100'; 100″) via a communication channel (K) that is common to a plurality of partitions (302-1, 302-2, ...).
13. The method according to claim 12, wherein the providing (250) and / or the transmitting (252) is performed, for example, entirely on a hardware basis.
14. A method for transmitting and hardware security module (100; 100'; 100”), comprising: providing (260) a first communication channel (K1) for exchanging information between a first partition (302-1) of a computing device (300), for example exactly one first partition (302-1) and the hardware security module (100; 100'; 100”), and optionally using (262) the first communication channel (K1) for exchanging information between the first partition (302-1) of the computing device (300) and the hardware security module (100; 100'; 100”).
15. The method according to claim 14, comprising: A second communication channel (K2) is provided (264) for communication between a second partition (302-2), for example exactly one second partition (302-2), of the computing device (300) and the hardware security module (100; 100'; 100″), and optionally using (266) the second communication channel (K2) for communication between a second partition (302-2) of the computing device (300) and the hardware security module (100; 100′; 100”) to exchange information.
16. An apparatus (301) for performing the method according to at least one of claims 12 to 15.
17. A computer-readable storage medium (SM) comprising instructions (PRG) which, when executed by a computer (202), cause the computer (202) to perform the method according to at least one of claims 1 to 8 and / or 12 to 15.
18. A computer program (PRG) comprising instructions which, when said program (PRG) is executed by a computer (202), cause said computer (202) to perform the method according to at least one of claims 1 to 8 and / or 12 to 15.
19. A data carrier signal (DCS) transmitting and / or representing a computer program according to claim 18.
20. A method according to at least one of claims 1 to 8 and / or 12 to 15 and / or an apparatus (400) according to claim 9 and / or a hardware security module (100; 100'; 100") according to claim 10 and / or a computing device (300) according to claim 11 and / or an apparatus (301) according to claim 16 and / or a computer-readable storage medium (SM) according to claim 17 and / or a computer program (PRG) according to claim 18 and / or a data carrier signal (DCS) according to claim 19 for at least one of the following: a) determining (501) first information (I-1) characterizing an identity (302-1-ID) of at least one partition (302-1) of the computing device (300), the partition being structured a) creating a hardware security module (100; 100'; 100") for accessing (A1) the hardware security module (100; 100'; 100"), for example, accessing the hardware security module (100; 100'; 100"), b) virtualizing (502) the hardware security module (100; 100'; 100"), c) determining (503) the identity of the partition (302-1, 302-2, ...) accessing the hardware security module (100; 100'; 100"), d) prioritizing (504) operations associated with different partitions (302-1, 302-2, ...) of a computing device (300) based on the identity of at least one of the different partitions (302-1, 302-2, ...), and e) improving (505) the security of the hardware security module (100; 100'; 100") accessible to multiple partitions (302-1, 302-2, ...) of the computing device (300).