Processing system, processing method, chip, and storage medium

By introducing a mode control unit and a security hardware unit into the processing system, flexible switching of working modes is achieved, and the low performance and security risks of existing systems when switching TEE and REE is solved, and the security and flexibility of the system are improved.

CN120103950APending Publication Date: 2025-06-06BEIJING ESWIN COMPUTING TECH CO LTD +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510252745.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Existing processing systems have poor performance when switching TEE and REE execution environments, and there are risks of context switching, shared resource isolation problems, and log information leakage risks.

Method used

A processing system is provided, including an application subsystem and a hardware device, which includes a mode control unit and a secure hardware unit running in a trusted execution environment. The mode control unit configures the working mode as safe mode and non-safe mode, allowing the application subsystem to directly access the secure hardware unit in the non-safe mode, and not directly access in the safe mode.

Benefits of technology

It realizes flexible configuration of the working mode of the system, expands application scenarios, enhances security, and improves the flexibility of the system to use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120103950A_ABST
    Figure CN120103950A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a processing system, a processing method, a chip and a storage medium. The processing system comprises an application subsystem and a hardware device, the application subsystem is configured to provide a rich execution environment, the hardware device comprises a mode control unit and a secure hardware unit running in a trusted execution environment, the mode control unit is configured to control working modes of the processing system, and the working modes comprise a secure mode and a non-secure mode. In the non-security mode, allowing the application subsystem to directly access the security hardware unit; and in the security mode, the application subsystem is not allowed to directly access the security hardware unit. The working mode of the processing system can be flexibly configured, and the application scene of the processing system is expanded, so that the processing system can determine whether to work in the safe mode or not according to the application scene, the safety of the processing system is enhanced, and the use flexibility of the processing system is also improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to a processing system, a processing method, a chip, and a storage medium. Background Art

[0002] With the development of computer technology, the performance challenges faced by devices such as central processing units, graphics processing units, and artificial intelligence chips are not only data computing capabilities, but also security issues. In some architectures, the execution environment of the processor is divided into a trusted execution environment (TEE) and a rich execution environment (REE). Summary of the invention

[0003] At least one embodiment of the present disclosure provides a processing system, including an application subsystem and a hardware device, wherein the application subsystem is configured to provide a rich execution environment, the hardware device includes a mode control unit and a secure hardware unit running in a trusted execution environment, the mode control unit is configured to control an operating mode of the processing system, the operating modes including a secure mode and a non-secure mode, wherein in the non-secure mode, the application subsystem is allowed to directly access the secure hardware unit; and in the secure mode, the application subsystem is not allowed to directly access the secure hardware unit.

[0004] For example, in a processing system provided in an embodiment of the present disclosure, the hardware device also includes a general hardware unit for use by the application subsystem, and the processing system also includes an access controller, and the access controller is configured to: in response to the working mode of the processing system being the security mode, use part of the general hardware unit as a security subunit; and intercept object access requests provided by the application subsystem, wherein the object access request includes an access request to the security hardware unit and an access request to the security subunit.

[0005] For example, in the processing system provided in one embodiment of the present disclosure, it also includes: a security subsystem configured to provide the trusted execution environment, and the security subsystem is allowed to directly access the security hardware unit and the general hardware unit in both the secure mode and the non-secure mode.

[0006] For example, in the processing system provided by an embodiment of the present disclosure, in the security mode, the application subsystem is allowed to access the security hardware unit and the security subunit through the security subsystem.

[0007] For example, in a processing system provided in an embodiment of the present disclosure, a general hardware unit includes a shared memory, and the application subsystem is configured to: in response to the existence of a security service request, write the data of the security service request to the shared memory, and send an interrupt request to the security subsystem, and the security subsystem is configured to: in response to the interrupt request, obtain the data of the security service request from the shared memory, and process the data of the security service request to obtain a processing result; and write the processing result to the shared memory, and provide an interrupt signal to the application subsystem, and the application subsystem is further configured to: in response to the interrupt signal, obtain the processing result from the shared memory.

[0008] For example, in a processing system provided in an embodiment of the present disclosure, the security hardware unit includes a first memory, wherein the first memory is configured to: store an operating mode identifier of the processing system, and the mode control unit is configured to: obtain the operating mode identifier from the first memory after reset release, and control the operating mode of the processing system based on the operating mode identifier, and the time when the first memory and the mode control unit perform reset release is earlier than the time when the security subsystem and the application subsystem perform reset release.

[0009] For example, in the processing system provided in one embodiment of the present disclosure, it also includes: a reset selection unit, which is coupled to the mode control unit, the security subsystem and the application subsystem, and is configured to control the reset release order of the security subsystem and the application subsystem in response to the working mode identifier provided by the mode control unit. In the security mode, the reset selection unit controls the reset release of the security subsystem earlier than the reset release of the application subsystem.

[0010] For example, in the processing system provided in one embodiment of the present disclosure, the reset selection unit includes: a first reset selector, coupled to the security subsystem, the application subsystem and the mode control unit; a second reset selector, coupled to the application subsystem, the security subsystem and the mode control unit; the first reset selector is configured to: receive a system reset signal and a first reset signal provided by the application subsystem, and provide the system reset signal or the first reset signal to the security subsystem according to the working mode identifier, and the second reset selector is configured to: receive a system reset signal and a second reset signal provided by the security subsystem, and provide the system reset signal or the second reset signal to the application subsystem according to the working mode identifier.

[0011] For example, in the processing system provided in an embodiment of the present disclosure, the first reset selector is further configured to select the system reset signal to be provided to the security subsystem in response to the operating mode identifier indicating that the operating mode of the processing system is the security mode, and the second selector is further configured to select the second reset signal to be provided to the application subsystem in response to the operating mode identifier indicating that the operating mode of the processing system is the security mode.

[0012] For example, in a processing system provided by an embodiment of the present disclosure, the security subsystem includes: a second memory configured to store a trusted program; and a security execution unit configured to execute the trusted program to start the security subsystem in response to a reset release of the security subsystem.

[0013] For example, in the processing system provided in an embodiment of the present disclosure, the security subsystem is configured as follows: in response to the working mode of the processing system being the security mode, after the security subsystem is started, the system startup image program is verified; in response to the system startup image program passing the verification, the second reset signal is provided to the application subsystem so that the application subsystem is reset and released; in response to the system startup image program failing the verification, the application subsystem is not reset and released.

[0014] For example, in a processing system provided in an embodiment of the present disclosure, the first reset selector and the second reset selector are also respectively coupled to a startup sequence control unit, the startup sequence unit is used to output a startup sequence indication signal, and the first reset selector and the second reset selector are also respectively configured to: in a non-safe working mode, control the reset release sequence of the security subsystem and the application subsystem according to the startup sequence indication signal.

[0015] For example, in the processing system provided in one embodiment of the present disclosure, the first reset selector is configured as follows: in response to the boot sequence indication signal being a first signal, the system reset signal is selected to be provided to the security subsystem; in response to the boot sequence indication signal being a second signal, the first reset signal is selected to be provided to the security subsystem; the second reset selector is configured as follows: in response to the boot sequence indication signal being the first signal, the second reset signal is selected to be provided to the application subsystem; in response to the boot sequence indication signal being the second signal, the system reset signal is selected to be provided to the application subsystem.

[0016] For example, in a processing system provided by an embodiment of the present disclosure, the security hardware unit includes a cryptographic subunit configured to encrypt and decrypt access data through hardware.

[0017] At least one embodiment of the present disclosure provides a processing method, which is applied to a processing system, wherein the processing system includes an application subsystem and a hardware device, wherein the hardware device includes a mode control unit and a secure hardware unit running in a trusted execution environment, and the method includes: in response to a startup signal of the processing system, determining an operating mode of the processing system, wherein the operating mode includes a secure mode and a non-secure mode; in response to the operating mode being the non-secure mode, allowing the application subsystem to directly access the secure hardware unit; and in response to the operating mode being the secure mode, not allowing the application subsystem to directly access the secure hardware unit.

[0018] At least one embodiment of the present disclosure provides a chip, including the processing system provided by any embodiment of the present disclosure.

[0019] At least one embodiment of the present disclosure provides a computer-readable storage medium that non-temporarily stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, the processing method provided by any embodiment of the present disclosure is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings of the embodiments will be briefly introduced below. Obviously, the drawings in the following description only relate to some embodiments of the present disclosure, but are not intended to limit the present disclosure.

[0021] Figure 1 The schematic diagram shows the architecture of the processing system 100 according to the first embodiment of the present disclosure;

[0022] Figure 2 A flow chart of a method for implementing a security service by an application subsystem in a security mode provided by at least one embodiment of the present disclosure is shown;

[0023] Figure 3 A schematic diagram of a reset circuit provided by at least one embodiment of the present disclosure is shown;

[0024] Figure 4 A schematic diagram of a startup method in a safe working mode provided by at least one embodiment of the present disclosure is shown;

[0025] Figure 5 A schematic diagram of a startup method in a non-safe working mode provided by at least one embodiment of the present disclosure is shown;

[0026] Figure 6 A flow chart of a method for controlling a reset release sequence provided by at least one embodiment of the present disclosure is shown;

[0027] Figure 7A flow chart of a method for implementing a security service by an application subsystem in a non-security mode provided by at least one embodiment of the present disclosure is shown;

[0028] Figure 8 A flowchart showing a processing method provided by at least one embodiment of the present disclosure; and

[0029] Fig. 9 A schematic diagram schematically illustrates a computer-readable storage medium according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0030] In order to make the purpose, technical solution and advantages of the embodiments of the present disclosure clearer, the technical solution of the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings of the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the described embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.

[0031] Unless otherwise defined, the technical terms or scientific terms used herein should be understood by people with ordinary skills in the field to which the present disclosure belongs. "First", "second" and similar words used in the present disclosure do not indicate any order, quantity or importance, but are only used to distinguish different components. Similarly, "include" or "comprise" and similar words mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0032] TEE and REE are two execution environments that run in parallel but are isolated from each other in areas such as mobile devices and cloud computing. TEE focuses on protecting the storage and processing of sensitive data (such as payment keys and biometrics) and performing high-security tasks (such as fingerprint verification and cryptographic signatures). REE is usually used to support the operation of daily applications (such as social media and games), providing rich user interaction functions, with a large attack surface and vulnerable to malware and vulnerability attacks.

[0033] Although some system architectures divide the processor's execution environment into TEE and REE, the switching between TEE and REE needs to go through a security monitor, which will lead to poor system performance. In addition, the TEE environment and the REE environment run on the same hardware. There may be risks in building a system security environment by using a time-sharing multiplexing processor core, such as context switching risks. If the software process of REE is attacked, it may cause illegal switching to TEE and there is a risk of information leakage. TEE and REE share storage resources such as cache units. REE may obtain information in the TEE environment, which also brings about risks such as context switching, shared resource isolation problems, log information leakage risks, etc. At present, the solution of built-in hardware security elements in the chip is gradually being adopted. The TEE execution environment runs on a dedicated processor core and is equipped with unique hardware resources such as dedicated storage units. REE runs on different processor cores, so the TEE environment and the REE environment are completely isolated in the hardware environment, which improves system security. Although the solution of using built-in independent hardware security elements enhances the overall security of the system, this implementation method has poor flexibility. The security elements in the TEE environment can only be accessed by the TEE. In some situations where security requirements are relatively low, it is hoped that REE can be allowed to directly access the security elements in the TEE environment.

[0034] At least one embodiment of the present disclosure provides a processing system, the processing system includes an application subsystem and a hardware device, the application subsystem is configured to provide a rich execution environment, the hardware device includes a mode control unit and a secure hardware unit running in a trusted execution environment, the mode control unit is configured to control the working mode of the processing system, the working mode includes a secure mode and a non-secure mode, in which the application subsystem is allowed to directly access the secure hardware unit in the non-secure mode; and in the secure mode, the application subsystem is not allowed to directly access the secure hardware unit. The working mode of the processing system can be flexibly configured, which expands the application scenarios of the processing system, so that the processing system can decide whether to work in the secure mode according to the application scenarios, which not only enhances the security of the processing system, but also improves the flexibility of use of the processing system.

[0035] The following will be combined Figure 1 The processing system provided by the present disclosure and its working principle are described in detail.

[0036] Figure 1 The schematic diagram shows the architecture of the processing system 100 according to the first embodiment of the present disclosure.

[0037] like Figure 1As shown, the processing system 100 includes an application subsystem 101 and a hardware device 102. The application subsystem 101 is configured to provide a rich execution environment, and the hardware device 102 includes a mode control unit 112 and a secure hardware unit 122 running in a trusted execution environment. The mode control unit 112 is configured to control the working mode of the processing system, which includes a secure mode and a non-secure mode. In the non-secure mode, the application subsystem 101 is allowed to directly access the secure hardware unit 122. In the secure mode, the application subsystem 101 is not allowed to directly access the secure hardware unit 122.

[0038] The working mode of the processing system 100 can be flexibly configured, which expands the application scenarios of the processing system 100, so that the processing system 100 can decide whether to work in a safe mode according to the application scenarios, which not only enhances the security of the processing system, but also improves the flexibility of the processing system. The processing system 100 can be, for example, a chip.

[0039] In some embodiments of the present disclosure, the application subsystem 101 may be used to run user applications and an operating system that enriches the execution environment. The application subsystem 101 may include software and hardware required to run programs. For example, the application subsystem 101 includes some conventional operating systems, such as Linux, iOS, and other operating systems, and may also include some client applications. Figure 1 As shown, for example, the application subsystem 101 includes an application execution unit, which may be a processor, for example, to perform operations such as calculations. The application subsystem 101 may also include other hardware besides the processor, such as a communication interface, a storage unit, and the like.

[0040] In some embodiments of the present disclosure, the security hardware unit 122 may be a security element in a trusted execution environment, accessed by the trusted execution environment. For example, the security hardware unit 122 may include a cryptographic subunit configured to encrypt and decrypt access data through hardware. For example, the cryptographic subunit may include a security service cryptographic engine, such as a symmetric encryption and decryption cryptographic engine, an asymmetric cryptographic engine, and a random number generator. For example, tasks such as symmetric encryption and decryption cryptographic engines, asymmetric cryptographic engines, and random number generators are directly executed by dedicated hardware such as security service cryptographic engines, thereby hardware-accelerating security service requests and improving the work efficiency of the processing system.

[0041] In some embodiments of the present disclosure, the security hardware unit 122 may further include a first memory. Figure 1The read-only memory 2 in the example is an example of the first memory. The first memory is configured to: store the working mode identifier of the processing system. The mode control unit 112, for example, reads the working mode identifier in the read-only memory 2, and controls the working mode of the processing system based on the working mode identifier. The mode control unit 112 can be, for example, a controller of the read-only memory 2. For example, if the working mode identifier is 1, the working mode of the processing system is a safe mode; if the working mode identifier is 0, the working mode of the processing system is a non-safe mode.

[0042] For example, in the non-secure mode, the application subsystem 101 can directly access the secure hardware unit 122 configured for the trusted execution environment; in the secure mode, the application subsystem 101 cannot directly access the secure hardware unit 122 .

[0043] Therefore, in situations where security requirements are high, the processing system 100 operates in a secure mode, so that the application subsystem 101 cannot directly access secure hardware units such as the cryptographic unit and the read-only memory 2; in situations where security requirements are not high, the processing system 100 operates in a non-secure mode, so that the application subsystem 101 can directly access secure hardware units such as the cryptographic unit and the read-only memory 2. Therefore, the embodiments of the present disclosure not only enhance the security of the processing system such as a chip, but also improve the flexibility of chip use.

[0044] In some embodiments of the present disclosure, the first memory is a one-time programmable memory. For example, Figure 1 The read-only memory 2 in the chip is a one-time programmable memory (OTP). For example, the read-only memory 2 stores the chip's working mode identification, and the information is programmed and written after the chip is produced. A one-time modification is performed according to the application requirements, and the chip's working mode identification is burned to make the chip work in a secure mode or a non-secure mode. In this way, whether it is a chip working in a secure mode or a chip working in a non-secure mode, the same set of tape-out templates can be used without using two sets of tape-out templates. After the chip is produced, the working mode identification is written according to the chip's application requirements to control the chip's working mode, thereby saving the chip's production cost.

[0045] like Figure 1As shown, in some embodiments of the present disclosure, the processing system 100 may further include a security subsystem 103. The security subsystem 103 is configured to provide a trusted execution environment, and the security subsystem is allowed to directly access the security hardware unit in both secure mode and non-secure mode. The security subsystem 103 can run security services and TEE operating systems. For example, the operating system run by the security subsystem 103 is a lightweight trusted operating system independent of REE, and only runs security-related code, such as OP-TEE and Trustonic's trusted kernel. The security subsystem 103 runs security-sensitive programs, such as biometric matching, encryption key management and other programs. The security hardware unit 122 is specially configured for the security subsystem 103, so the security subsystem 103 is not restricted from accessing the security hardware unit 122, and the security subsystem 103 can access the security hardware unit 122 regardless of secure mode or non-secure mode.

[0046] In some embodiments of the present disclosure, the application subsystem 101 and the security subsystem 103 each have a unique execution unit, the application subsystem includes the above application execution unit, the security subsystem includes the security execution unit 113, and the application execution unit and the security execution unit can be the same processor or a heterogeneous processor. Compared with the implementation of time-sharing multiplexing processors, the use of an independent security execution unit in the security subsystem improves the chip security characteristics and prevents security risks that may arise due to shared hardware resources.

[0047] In some embodiments of the present disclosure, the security subsystem 103 includes, in addition to the security execution unit 113, a second memory configured to store a trusted program. Figure 1 As shown, the security subsystem 103 includes a security execution unit 113 and a read-only memory 1, which is an example of a second memory. The security execution unit 113 is configured to execute a trusted program to start the security subsystem in response to the security subsystem 103 being released from reset.

[0048] For example, the program in the read-only memory 1 is burned into the chip during the chip tape-out process and cannot be changed after burning. Therefore, the read-only memory 1 is also the trusted root of the chip. The read-only memory 1 can be a boot read-only memory (Bootrom). When the chip is deployed in secure mode, the secure execution unit 113 in the security subsystem 103 starts executing from the program in the read-only memory 1.

[0049] For example, after the security subsystem 103 is reset and released, the security execution unit 113 starts executing the program in the read-only memory 1. Reset release refers to releasing the reset state, that is, restoring the subsystem from the reset state to the working state. For example, if the reset signal is at a high level, the security subsystem 103 is in a reset state, and if the reset signal is at a low level, the security subsystem 103 is in a working state. Reset release refers to the reset signal switching from a high level to a low level. In some embodiments of the present disclosure, in a safe mode, the security subsystem 103 controls the release of the reset of the application execution unit in the application subsystem 101, and the application subsystem enters a working state.

[0050] The application execution unit in the application subsystem 101 cannot access the read-only memory 1 in either the secure mode or the non-secure mode, thereby preventing malicious applications in the application subsystem 101 from analyzing the design vulnerabilities of the startup program in the read-only memory 1 .

[0051] In some embodiments of the present disclosure, the hardware device 102 may include a general hardware unit 132 for use by the application subsystem in addition to the security hardware unit 122. The general hardware unit 132 is common to the application subsystem and the security subsystem. The general hardware unit 132 includes, for example, hardware such as an IO device 1322 and a memory 1321.

[0052] like Figure 1 As shown, in some embodiments of the present disclosure, the processing system 100 may further include at least one access controller 104. Each access controller 104 is used to intercept illegal access requests of the application subsystem 101. The illegal access request includes, for example, an access request of the application subsystem 101 to the security hardware unit 122 in the security mode.

[0053] In some embodiments of the present disclosure, the access controller 104 is configured to: in response to the operating mode of the processing system being a security mode, use a portion of the general hardware unit 132 as a security sub-unit; and intercept object access requests provided by the application subsystem 101, the object access requests including access requests to the security hardware unit 122 and access requests to the security sub-unit.

[0054] For example, for memory 1321, if the working mode of the processing system 100 is the security mode, the access controller 104 uses part of the memory space as the secure memory (an example of the security subunit) and the other part as the normal memory. In the security mode, the access controller 104 intercepts the access request to the secure memory provided by the application subsystem 101, so that the application subsystem 101 can only access the normal memory and cannot access the secure memory. The access controller 104 does not intercept the access request of the security subsystem 103, so the security subsystem 103 can access the entire memory space.

[0055] For another example, in the security mode, the access controller 104 divides the IO device 1322 into a secure IO device and a common IO device, and the application subsystem 101 can only access the common IO device but cannot access the secure IO device.

[0056] The embodiment of the present disclosure does not limit the number of access controllers 104, and the access controllers 104 and the hardware components may have a one-to-one correspondence. Figure 1 As shown, each of the IO device 1322, the memory 1321, the cryptographic subunit and the read-only memory 2 corresponds to an access controller 104. In some other embodiments of the present disclosure, one access controller 104 may correspond to multiple hardware elements, or multiple access controllers 104 may correspond to one hardware element.

[0057] In some embodiments of the present disclosure, Figure 1 As shown, the processing system 100 may further include a system bus 105. The system bus 105 is mounted with a read-only memory 2, a cryptographic subunit, an IO device 1322, and a memory 1321. An access controller 104 exists between the system bus 105 and the mounted devices, and the access controller 104 is used to intercept illegal access requests on the system bus 105. The illegal access request includes, for example, an access request from the application subsystem 101 to the security hardware unit 122 and an access request from the application subsystem 101 to the security subunit in a secure mode.

[0058] In some embodiments of the present disclosure, if the processing system 100 operates in non-secure mode, the access controller 104 does not divide the general hardware units, that is, the application subsystem 101 can access all general hardware units. For example, if the processing system 100 operates in non-secure mode, the application subsystem 101 can access all IO devices and all memory spaces. In non-secure mode, the security subsystem 103 can also access all general hardware units.

[0059] When the processing system 100 operates in a secure mode, the secure execution unit 113 configures the access controller 104 to operate in a secure mode after startup, and configures other operating parameters (for example, hardware initialization parameters, memory resource allocation parameters, etc.). At this time, the access controller 104 will intercept illegal access requests from the application subsystem 101.

[0060] In some embodiments of the present disclosure, in the secure mode, the application subsystem 101 is allowed to access the secure hardware unit 122 and the secure subunit through the secure subsystem 103. This can ensure the security of the processing system and expand the services of the application subsystem 101. For example, in the secure mode, the application subsystem 101 requests security services from the secure subsystem 103 through interrupts and shared memory.

[0061] In some embodiments of the present disclosure, the application subsystem 101 is configured to: in response to the presence of a security service request, write the security service request to the shared memory, and send an interrupt request to the security subsystem 103. The security subsystem 103 is configured to: in response to the interrupt request, obtain the security service request from the shared memory, and process the security service request to obtain a processing result; and write the processing result to the shared memory, and provide an interrupt signal to the application subsystem 101. The application subsystem 101 is also configured to: in response to the interrupt signal, obtain the processing result from the shared memory.

[0062] Shared memory can be Figure 1 The ordinary memory in the memory 1321 may also be another memory independent of the memory 1321.

[0063] Figure 2 A flow chart of a method for implementing a security service by an application subsystem in a security mode provided by at least one embodiment of the present disclosure is shown.

[0064] like Figure 2 As shown, the method includes steps S201 to S203.

[0065] Step S201: When the application subsystem has a security service request to be processed, it sends an interrupt request to the security subsystem and writes the security service request into the shared memory.

[0066] Step S202: After receiving the interrupt request, the security subsystem retrieves the security service request from the shared memory and calls the corresponding security service to process the security service request to obtain a processing result.

[0067] Step S203: the security subsystem writes the processing result into the shared memory and provides an interrupt signal to the application subsystem.

[0068] Step S204: the application subsystem obtains the processing result from the shared memory in response to the interrupt signal.

[0069] For example, the shared memory above can refer to Figure 1 The ordinary memory in the memory 1321 is described above in detail. In the security mode, the application subsystem 101 interacts with the security subsystem 103 through the ordinary memory in the memory 1321, for example.

[0070] The security service request is, for example, a service request for biometric feature comparison. For example, the application subsystem 101 writes the data of the biometric feature comparison to the general memory described above. The data of the biometric feature comparison includes, for example, the fingerprint feature of the user. In response to the interrupt request, the security subsystem 101 obtains the fingerprint feature of the user from the shared memory, and compares the fingerprint feature of the user with the stored fingerprint feature to obtain a processing result, then writes the processing result to the general memory, and provides an interrupt signal to the application subsystem 101. After receiving the interrupt signal, the application subsystem 101 obtains the processing result from the general memory.

[0071] In some embodiments of the present disclosure, the mode control unit 112 is configured to: after reset release, obtain the working mode identifier from the first memory, and control the working mode of the processing system based on the working mode identifier, and the time when the first memory and the mode control unit 112 perform reset release is earlier than the time when the security subsystem 103 and the application subsystem 101 perform reset release.

[0072] For example, by controlling the reset release timing of the processing system 100, the read-only memory 2 and the mode control unit 112 are reset and released before the security subsystem 103 and the application subsystem 101. For example, the reset signal is delayed by a delay circuit and then provided to the security subsystem 103 and the application subsystem 101 to reset and release the security subsystem 103 and the application subsystem 101, so that the time when the read-only memory 2 and the mode control unit 112 are reset and released is earlier than the time when the security subsystem 103 and the application subsystem 101 are reset and released. For example, the delay time can be controlled by a counter.

[0073] In some embodiments of the present disclosure, the processing system further includes a reset selection unit 106. The reset selection unit 106 is coupled to the mode control unit 112, the security subsystem 103, and the application subsystem 101, and is configured to control the reset release order of the security subsystem 103 and the application subsystem 101 in response to the working mode identifier provided by the mode control unit 112. In the security mode, the reset selection unit 106 controls the reset release of the security subsystem 103 earlier than the reset release of the application subsystem 101. The reset of the security subsystem 103 is released first, and execution starts from the program in the read-only memory 1. The program in the read-only memory 1 is burned and completed when the chip is taped out. Because it is the trusted root of the chip, the burned program is considered to be trusted, thereby ensuring the security of the execution environment.

[0074] For example, the reset selection unit 106 preferentially controls the security subsystem to perform reset release, and after the security subsystem is reset and released, the reset selection unit 106 controls the application subsystem to perform reset release.

[0075] For another example, the reset selection unit 106 preferentially controls the security subsystem to perform reset release, and after the security subsystem is reset and released, the security subsystem controls the application subsystem to perform reset and release.

[0076] In some embodiments of the present disclosure, the reset selection unit 106 may be a multiplexer that provides different reset release signals to the security subsystem or the application subsystem according to the working mode identifier, so that the security subsystem or the application subsystem performs reset release.

[0077] In some embodiments of the present disclosure, the reset selection unit 106 includes a first reset selector and a second reset selector. The first reset selector is coupled to the security subsystem, the application subsystem, and the mode control unit; the second reset selector is coupled to the application subsystem, the security subsystem, and the mode control unit; the first reset selector is configured to receive a system reset signal and a first reset signal provided by the application subsystem, and provide a system reset signal or a first reset signal to the security subsystem according to a working mode identifier, and the second reset selector is configured to receive a system reset signal and a second reset signal provided by the security subsystem, and provide a system reset signal or a second reset signal to the application subsystem according to a working mode identifier.

[0078] Combine the following Figure 3 An example is used to illustrate an embodiment in which the reset selection unit controls the reset release timing.

[0079] Figure 3 A schematic diagram of a reset circuit provided by at least one embodiment of the present disclosure is shown.

[0080] like Figure 3 As shown, the reset selection unit 106 includes a reset selector F1 and a reset selector F2. The reset selector F1 is an example of a first reset selector, and the reset selector F2 is an example of a second reset selector. In this example, the mode control unit 112 is a read-only memory 2 controller.

[0081] like Figure 3 As shown, the reset selector F1 is coupled to the security subsystem, the application subsystem and the mode control unit. The reset selector F2 is coupled to the application subsystem, the security subsystem and the mode control unit.

[0082] The two input ends of the reset selector F1 are used to receive the system reset signal and the reset signal provided by the application subsystem respectively. The control end of the reset selector F1 is coupled to the read-only memory 2 controller for receiving the working mode identification. The output end of the reset selector is coupled to the security subsystem.

[0083] The reset selector F1 receives a system reset signal and a reset signal A (an example of a first reset signal) through two input terminals, and provides the system reset signal or the reset signal A to the safety subsystem according to the operation mode identification.

[0084] The two input ends of the reset selector F2 are used to receive the system reset signal and the reset signal provided by the security subsystem respectively. The control end of the reset selector F2 is coupled to the read-only memory 2 controller for receiving the working mode identification. The output end of the reset selector is coupled to the application subsystem.

[0085] The reset selector F2 receives a system reset signal and a reset signal B (an example of a second reset signal) through two input terminals, and provides the system reset signal or the reset signal B to the application subsystem according to the working mode identifier.

[0086] In some embodiments of the present disclosure, the first reset selector is further configured to select a system reset signal to be provided to the security subsystem in response to the operating mode identifier indicating that the operating mode of the processing system is a security mode, and the second selector is further configured to select a second reset signal to be provided to the application subsystem in response to the operating mode identifier indicating that the operating mode of the processing system is a security mode.

[0087] For example, if the working mode is the security mode, the ROM 2 controller outputs a high level. In response to the ROM 2 controller outputting a high level, the reset selector F1 selects to provide a system reset signal to the security subsystem, and the security subsystem performs a reset release according to the signal change of the system reset signal. The reset selector F2 selects to provide a reset signal B to the application subsystem, and the application subsystem performs a reset release according to the signal change of the reset signal B.

[0088] In the safety working mode, the reset selector F1 selects the system reset as the output, and the reset selector F2 selects the reset signal issued by the safety subsystem as the output, so the reset of the safety subsystem is released first.

[0089] In some embodiments of the present disclosure, the security subsystem is configured as follows: in response to the operating mode of the processing system being the security mode, after the security subsystem is started, the system startup image program is verified; in response to the system startup image program passing the verification, a second reset signal is provided to the application subsystem so that the application subsystem is reset and released; in response to the system startup image program failing the verification, the application subsystem is not reset and released.

[0090] The system boot image program is a complete snapshot of the operating system of the application subsystem, including all elements required for operation, such as a kernel, a boot program, and user data. The system boot image program is stored in a storage chip, for example.

[0091] Before releasing the reset of the application subsystem, the security subsystem first verifies the signature of the system boot image program to be loaded. Only after the signature verification is passed, the system boot image program loaded by the application subsystem is considered to be credible. Then the security subsystem releases, for example, reset signal B, so that the application subsystem is reset and released. The application subsystem starts execution from the system boot image program. If the signature verification of the application subsystem system boot image fails, it means that the system boot image program may have been tampered with. At this time, the security subsystem will not release the reset of the application subsystem, and the system boot image program will not be executed, thereby protecting the security of the chip execution environment.

[0092] Figure 4 A schematic diagram of a startup method in a safe working mode provided by at least one embodiment of the present disclosure is shown.

[0093] like Figure 4 As shown, the method includes steps S401 to S407. In this example, the processing system is described as a chip.

[0094] Step S401: Determine whether the chip is operating in a safe mode.

[0095] Step S402: The security subsystem starts executing from the read-only memory 1.

[0096] Step S403: The security subsystem uses the cryptographic subunit to verify the system startup image signature of the application subsystem.

[0097] Step S404: Determine whether the signature verification is passed. If the signature verification is passed (ie, successful), then execute step S405 and step S406. If the signature verification is not passed (ie, failed), then execute step S407.

[0098] Step S405: The security subsystem releases the application subsystem reset.

[0099] Step S406: the application subsystem starts executing from the system startup image.

[0100] Step S407: Chip security startup fails.

[0101] In some embodiments of the present disclosure, the first reset selector and the second reset selector are also respectively coupled to a startup sequence control unit, and the startup sequence unit is used to output a startup sequence indication signal. The first reset selector and the second reset selector are also respectively configured to: in a non-safe working mode, control the reset release sequence of the security subsystem and the application subsystem according to the startup sequence indication signal.

[0102] like Figure 3As shown, the reset selector F1 and the reset selector F2 each further include another control terminal, which is coupled to the startup sequence control unit, for example, the startup sequence control unit is a register or a gate circuit, etc. For example, the control terminal can be coupled to the startup sequence pin of the startup sequence control unit. In the non-safety working mode, the reset selector F1 and the reset selector F2 control the reset release sequence of the safety subsystem and the application subsystem according to the signal provided by the startup sequence pin.

[0103] For example, if the working mode is a non-secure working mode, the ROM 2 controller inputs a low level. If the ROM 2 controller provides a low level to the reset selector F1 and the reset selector F2, the reset selector F1 and the reset selector F2 control the reset release sequence of the security subsystem and the application subsystem according to the signal provided by the boot sequence pin.

[0104] In some embodiments of the present disclosure, the first reset selector is configured to select the system reset signal to be provided to the security subsystem in response to the boot sequence indication signal being the first signal, and to select the first reset signal to be provided to the security subsystem in response to the boot sequence indication signal being the second signal. The second reset selector is configured to select the second reset signal to be provided to the application subsystem in response to the boot sequence indication signal being the first signal, and to select the system reset signal to be provided to the security subsystem in response to the boot sequence indication signal being the second signal.

[0105] The first signal is, for example, a high-level signal, and the second signal is, for example, a low-level signal. Alternatively, the first signal is a low-level signal, and the second signal is a high-level signal. The embodiments of the present disclosure do not limit the first signal and the second signal.

[0106] For example, if the signal provided by the startup sequence pin to the reset selector F1 and the reset selector F2 is a high level signal, the reset selector F1 and the reset selector F2 control the security subsystem to reset and release earlier than the application subsystem. For example, if the signal provided by the startup sequence pin to the reset selector F1 and the reset selector F2 is a high level signal, the reset selector F1 chooses to provide the system reset signal to the security subsystem, and the security subsystem performs reset release according to the signal change of the system reset signal, and the reset selector F2 chooses to provide the reset signal B to the application subsystem, and the application subsystem performs reset release according to the signal change of the reset signal B.

[0107] For example, if the signal provided by the startup sequence pin to the reset selector F1 and the reset selector F2 is a low level signal, the reset selector F1 and the reset selector F2 control the security subsystem to reset and release later than the application subsystem. For example, if the signal provided by the startup sequence pin to the reset selector F1 and the reset selector F2 is a low level signal, the reset selector F1 chooses to provide the reset signal A to the security subsystem, and the security subsystem performs reset release according to the signal change of the reset signal A, and the reset selector F2 chooses to provide the system reset signal to the application subsystem, and the application subsystem performs reset release according to the signal change of the system reset signal.

[0108] Figure 5 A schematic diagram of a startup method in a non-safe working mode provided by at least one embodiment of the present disclosure is shown.

[0109] exist Figure 5 In the example, the startup process is explained by taking the reset release of the application subsystem earlier than the security subsystem as an example.

[0110] like Figure 5 As shown, the method includes steps S501 to S504.

[0111] Step S501: The chip operates in a non-secure mode and determines to start execution from the application subsystem.

[0112] Step S502: the application subsystem loads the system startup image to execute.

[0113] Step S503: the application subsystem releases the security subsystem reset.

[0114] Step S504: The security subsystem starts executing the trusted program in the read-only memory 1.

[0115] Figure 6 A flow chart of a method for controlling a reset release sequence provided by at least one embodiment of the present disclosure is shown.

[0116] like Figure 6 As shown, the method includes steps S601-S611.

[0117] Step S601: Power on the chip and start it.

[0118] Step S602: The ROM 2 controller is reset and released.

[0119] Step S603: the read-only memory 2 controller reads out the working mode identifier.

[0120] Step S604: Determine whether the chip is working in the safe mode according to the working mode identifier. If the chip is working in the safe mode, execute steps S605 and S606. If the chip is working in the non-safe mode, jump to step S607.

[0121] Step S605: The reset selector F1 selects the system reset signal to be output to the security subsystem.

[0122] Step S606: the reset selector F2 selects the reset signal provided by the security subsystem and inputs it into the application subsystem.

[0123] Step S607: Determine the startup sequence according to the signal of the startup sequence pin. If the security subsystem is started first, execute steps S608 and S609. If the application subsystem is started first, execute steps S610 and S611.

[0124] Step S608: The reset selector F1 selects the system reset signal to be output to the security subsystem.

[0125] Step S609: the reset selector F2 selects the reset signal provided by the security subsystem and inputs it into the application subsystem.

[0126] Step S610: The reset selector F2 selects a system reset signal to be input to the application subsystem.

[0127] Step S611: the reset selector F1 selects the reset signal provided by the application subsystem and inputs it into the security subsystem.

[0128] In some embodiments of the present disclosure, when the chip works in non-secure mode, the access control unit will not restrict the application subsystem's access to the secure device, and the application subsystem can access the cryptographic subunit, the read-only memory 2, the secure memory space, and the secure IO device, etc. Therefore, the application subsystem can directly access these secure devices to process security services without going through the secure subsystem, thereby improving work efficiency.

[0129] Figure 7 A flow chart of a method for implementing a security service by an application subsystem in a non-security mode provided by at least one embodiment of the present disclosure is shown.

[0130] like Figure 7 As shown, the method includes steps S701-S702.

[0131] Step S701: The application subsystem has a security service request to be processed.

[0132] Step S702: the application subsystem calls a corresponding security service (eg, a cryptographic subunit) to process the security service request and obtain a processing result.

[0133] At least one embodiment of the present disclosure provides a processing method, which is applied to the processing system provided by any of the above embodiments. The processing system includes an application subsystem and a hardware device, and the hardware device includes a mode control unit and a secure hardware unit running in a trusted execution environment. For details about the processing system, please refer to the above description. For details about the processing method, please refer to Figure 8 .

[0134] Figure 8 A flowchart of a processing method provided by at least one embodiment of the present disclosure is shown.

[0135] like Figure 8 As shown, the method includes steps S801 to S803.

[0136] Step S801: In response to the processing system being started, determining the working mode of the processing system, where the working mode includes a secure mode and a non-secure mode.

[0137] Step S802: In response to the working mode being a non-secure mode, allowing the application subsystem to directly access the secure hardware unit.

[0138] Step S803: In response to the working mode being the security mode, the application subsystem is not allowed to directly access the security hardware unit.

[0139] The processing method can flexibly configure the working mode of the processing system, expand the application scenarios of the processing system, and enable the processing system to decide whether to work in a safe mode according to the application scenarios, which not only enhances the security of the processing system, but also improves the flexibility of use of the processing system.

[0140] For step S801, for example, the processing system is powered on to start. Figure 1 In the example, in response to the processing system 100 being powered on, the read-only memory 2 controller performs a reset release, and reads the operating mode identifier from the read-only memory 2 to determine the operating mode of the processing system.

[0141] For steps S802 and S803, if the working mode is non-secure mode, the application subsystem can directly access the secure hardware unit; if the working mode is secure mode, the application subsystem cannot directly access the secure hardware unit. For example, if the working mode is secure mode, the application subsystem can request security services from the security subsystem through interrupts and shared memory.

[0142] In some embodiments of the present disclosure, the method further includes starting the security subsystem in response to the working mode being the security mode; verifying the system startup image program through the security subsystem; and starting the application subsystem in response to the system startup image program passing the verification. Figure 4 Embodiment of the invention.

[0143] The processing method provided in the embodiment of the present disclosure corresponds to the processing system described above. For details about the processing method, please refer to the description of the processing system above.

[0144] Some embodiments of the present disclosure provide a chip, which includes a processing system provided by any embodiment of the present disclosure. The working mode of the chip can be flexibly configured, which expands the application scenarios of the chip, so that the chip can decide whether to work in a safe mode according to the application scenarios, which not only enhances the security of the chip, but also improves the flexibility of the processing system.

[0145] At least some embodiments of the present disclosure also provide a non-transitory storage medium. Fig. 9 A schematic diagram of a computer-readable storage medium provided by an embodiment of the present disclosure is schematically shown. Fig. 9 As shown, the storage medium 900 stores non-transitory computer-readable instructions 901. When the non-transitory computer-readable instructions 901 are executed by a computer (including a processor), the processing method provided by any embodiment of the present disclosure can be executed. The method can flexibly configure the working mode of the processing system, expand the application scenarios of the processing system, and enable the processing system to decide whether to work in a safe mode according to the application scenarios, which not only enhances the security of the processing system, but also improves the flexibility of use of the processing system.

[0146] For example, one or more computer instructions may be stored on the storage medium 900. Some of the computer instructions stored on the storage medium 900 may be, for example, instructions for implementing one or more steps in the above-mentioned processing method.

[0147] For example, the storage medium may include a storage component of a tablet computer, a hard disk of a personal computer, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a compact disk read-only memory (CD-ROM), a flash memory, or any combination of the above storage media, or other applicable storage media.

[0148] The technical effects of the storage medium provided by the embodiments of the present disclosure can be referred to the corresponding description of the processing method in the above embodiments, which will not be repeated here.

[0149] There are a few points to note about this disclosure:

[0150] (1) In the drawings of the embodiments of the present disclosure, only the structures related to the embodiments of the present disclosure are involved, and other structures can refer to the general design.

[0151] (2) Unless there is a conflict, the features of the same embodiment or different embodiments of the present disclosure may be combined with each other.

[0152] The above are only specific embodiments of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present disclosure, which should be included in the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be based on the protection scope of the claims.

Claims

1. A processing system comprising: an application subsystem, configured to provide a rich execution environment; A hardware device, comprising a mode control unit and a secure hardware unit running in a trusted execution environment, wherein the mode control unit is configured to control an operating mode of the processing system, the operating mode comprising a secure mode and a non-secure mode, Wherein, in the non-secure mode, the application subsystem is allowed to directly access the secure hardware unit; in the secure mode, the application subsystem is not allowed to directly access the secure hardware unit.

2. The processing system according to claim 1, wherein: The hardware device also includes a general hardware unit used by the application subsystem, and the processing system also includes an access controller. Wherein, the access controller is configured as follows: In response to the operating mode of the processing system being the security mode, using part of the general hardware unit as a security sub-unit; and Intercepting an object access request provided by the application subsystem, wherein the object access request includes an access request to the security hardware unit and an access request to the security subunit.

3. The processing system according to claim 2, further comprising: A security subsystem configured to provide the trusted execution environment, Wherein, in both the secure mode and the non-secure mode, the secure subsystem is allowed to directly access the secure hardware unit and the general hardware unit.

4. The processing system according to claim 3, wherein: In the security mode, the application subsystem is allowed to access the security hardware unit and the security subunit through the security subsystem.

5. The processing system according to claim 1, wherein: The common hardware unit includes a shared memory, The application subsystem is configured as follows: In response to the presence of a security service request, writing data of the security service request into the shared memory, and sending an interrupt request to the security subsystem, The security subsystem is configured as follows: In response to the interrupt request, acquiring data of the security service request from the shared memory, and processing the data of the security service request to obtain a processing result; as well as writing the processing result into the shared memory and providing an interrupt signal to the application subsystem, The application subsystem is further configured as: In response to the interrupt signal, the processing result is obtained from the shared memory.

6. The processing system according to claim 1, wherein: The security hardware unit includes a first memory, wherein the first memory is configured to: store an operating mode identifier of the processing system, The mode control unit is configured to: after reset is released, obtain the working mode identifier from the first memory, and control the working mode of the processing system based on the working mode identifier, The time when the first memory and the mode control unit are reset and released is earlier than the time when the security subsystem and the application subsystem are reset and released.

7. The processing system of claim 6, further comprising: a reset selection unit coupled to the mode control unit, the security subsystem and the application subsystem, and configured to control a reset release sequence of the security subsystem and the application subsystem in response to the working mode identifier provided by the mode control unit, Wherein, in the safety mode, the reset selection unit controls the reset release of the safety subsystem to be earlier than the reset release of the application subsystem.

8. The processing system according to claim 7, wherein: The reset selection unit comprises: a first reset selector coupled to the security subsystem, the application subsystem and the mode control unit; a second reset selector coupled to the application subsystem, the security subsystem and the mode control unit; The first reset selector is configured to: receive a system reset signal and a first reset signal provided by the application subsystem, and provide the system reset signal or the first reset signal to the security subsystem according to the working mode identifier, The second reset selector is configured to receive a system reset signal and a second reset signal provided by the security subsystem, and provide the system reset signal or the second reset signal to the application subsystem according to the working mode identifier.

9. The processing system according to claim 8, wherein: The first reset selector is further configured to, in response to the operating mode identifier indicating that the operating mode of the processing system is the security mode, select the system reset signal to be provided to the security subsystem, The second selector is further configured to, in response to the operating mode identifier indicating that the operating mode of the processing system is the secure mode, select the second reset signal to provide to the application subsystem.

10. The processing system according to claim 8 or 9, wherein: The safety subsystem includes: a second memory configured to store a trusted program; and The secure execution unit is configured to execute the trusted program to start the secure subsystem in response to the secure subsystem being released from reset.

11. The processing system according to claim 10, wherein: The security subsystem is configured as follows: In response to the working mode of the processing system being the security mode, after the security subsystem is started, verifying the system startup image program; In response to the system boot image program passing the verification, providing the second reset signal to the application subsystem so that the application subsystem performs reset release, In response to the system boot image program failing to pass verification, the application subsystem is not reset and released.

12. The processing system of claim 8, wherein: The first reset selector and the second reset selector are also coupled to a startup sequence control unit, respectively, wherein the startup sequence unit is used to output a startup sequence indication signal. The first reset selector and the second reset selector are further respectively configured to: in a non-safety working mode, control a reset release sequence of the safety subsystem and the application subsystem according to the startup sequence indication signal.

13. The processing system of claim 12, wherein: The first reset selector is configured to: in response to the boot sequence indication signal being a first signal, select the system reset signal to provide to the security subsystem; in response to the boot sequence indication signal being a second signal, select the first reset signal to provide to the security subsystem; The second reset selector is configured to: in response to the boot sequence indication signal being the first signal, select the second reset signal to provide to the application subsystem; in response to the boot sequence indication signal being the second signal, select the system reset signal to provide to the application subsystem.

14. The processing system of claim 6, wherein: The first memory is a one-time programmable memory.

15. The processing system of claim 1, wherein: The security hardware unit includes a cryptographic subunit configured to encrypt and decrypt access data through hardware.

16. A processing method, applied to a processing system, the processing system comprising an application subsystem and a hardware device, the hardware device comprising a mode control unit and a secure hardware unit running in a trusted execution environment, the method comprising: In response to the processing system being started, determining an operating mode of the processing system, the operating mode comprising a secure mode and a non-secure mode; In response to the operating mode being the non-secure mode, allowing the application subsystem to directly access the secure hardware unit; as well as In response to the operating mode being the security mode, the application subsystem is not allowed to directly access the security hardware unit.

17. The method according to claim 16, wherein: The processing system further includes a security subsystem, and the method further includes: In response to the working mode being a safety mode, starting the safety subsystem; The system starts the mirroring program through the security subsystem verification system; In response to the system boot image program passing the verification, the application subsystem is started.

18. A chip, comprising: A processing system according to any one of claims 1 to 15.

19. A computer-readable storage medium non-transitorily storing computer-readable instructions, wherein: When the computer-readable instructions are executed by a processor, the method according to any one of claims 16 to 17 is implemented.

Citation Information

Cited By

  • Processing system, processing method, chip, and storage medium

    WO2026184012A1