Processor circuit, server, data access method, authentication method and medium

By integrating protection modules and interface modules in the processor package, combined with embedded multiprocessor interconnect bridging technology and security protocols, the existing server firmware protection solutions are solved, and a smaller footprint and more comprehensive security prevention is achieved, reducing the risk of hardware cracking.

CN120387193AActive Publication Date: 2025-07-29INSPUR SUZHOU INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202510875855.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-07-29
Estimated Expiration
2045-06-26

AI Technical Summary

Technical Problem

The firmware protection solutions of existing server platforms have problems such as large size, low integration, insufficient security and incomplete protection scope, especially the lack of security control for key CPU interfaces, which increases the risk of hardware cracking.

Method used

The protection module and the interface module are integrated in the processor package. The protection module is set between the processor and the interface module. The processor is accessed through the interface module through the external access signal of the security authentication. Security authentication is achieved using embedded multi-processor interconnection bridge technology, and permission management and device authentication are performed through the logic submodule and the security protocol submodule.

Benefits of technology

The security circuit design of the server system is simplified, the footprint is reduced, more comprehensive security prevention is achieved, the risk of server being cracked by hardware is reduced, and the security and reliability of the system are enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120387193A_ABST
    Figure CN120387193A_ABST
Patent Text Reader

Abstract

The invention discloses a processor circuit, a server, a data access method, an authentication method and a medium, and relates to the technical field of processor design, the processor circuit comprises a substrate, a processor integrated on the substrate, a protection module and an interface module, the protection module and the interface module are packaged in a packaging piece of the processor, and the protection module is arranged between the processor and the interface module. The external access signal passing the security authentication accesses the processor through the interface module, so that the design of a server system security circuit is simplified, the occupied area is small, and the security protection is more comprehensive; the technical problems of large size, low integration level, insufficient security, incomplete protection range and the like of platform firmware protection schemes in related technologies are solved, and the technical effects of effectively reducing the risk that the server is cracked by hardware, reducing the size of the server and the like are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of processor design, and in particular, to a processor circuit, a server, a data access method, an authentication method, and a medium. Background Art

[0002] Currently, network intrusion has shifted from traditional operating systems and application software carriers to a more concealed firmware level. As the startup code that is first executed after the power-on of server components (such as CPU (Central Processing Unit), network controllers, on-chip RAID (Redundant Array of Inexpensive Disks) solutions, etc.), firmware is usually stored in the SPI (Serial Peripheral Interface) flash memory of the system and is regarded as the starting point of the platform system trust chain. However, once the firmware is infected, malware can launch attacks by tampering with the data in the hard disk or damaging one or more hardware components during the startup process.

[0003] To address such threats, the PFR (Platform Firmware Resilience) mechanism has been proposed. PFR utilizes devices with a trusted root, aiming to provide comprehensive security protection for all firmware in the server and ensure system integrity and reliability. In existing servers, the PFR function is mainly implemented by the PFR FPGA (Field Programmable Gate Array) located in the DC-SCM (Data Center-Security Control Module) module, and together with the SPI Flash (flash memory) used to store the BIOS (Basic Input Output System) and BMC (Baseboard Management Controller) firmware, it constitutes a firmware security protection system. However, this solution has obvious limitations: First, the PFR module consists of multiple discrete devices, occupying a large amount of board space, resulting in limited DC-SCM design and affecting functional integrity and popularity; second, key security devices are exposed on the PCB, and coupled with the DC-SCM being a pluggable module, it increases the risk of physical attacks and hardware cracking; third, the current PFR only protects the BIOS and BMC firmware and does not cover the key debugging interfaces of the CPU, and the security protection scope is not comprehensive, and the overall security still needs to be improved. Summary of the Invention

[0004] The present invention provides a processor circuit, a server, a data access method, an authentication method and a medium, so as to at least solve the technical problems in the related art that the platform firmware protection scheme has a large volume, low integration, insufficient security and incomplete protection scope.

[0005] The present invention provides a processor circuit, including: a substrate and a processor, a protection module and an interface module integrated on the substrate; a package of the processor, in which the protection module and the interface module are encapsulated, and the protection module is arranged between the processor and the interface module for performing security authentication on the external access signals of the processor, and the external access signals passing the security authentication access the processor through the interface module.

[0006] The present invention also provides a server, including the above-mentioned processor circuit.

[0007] The present invention also provides a data access method for a processor circuit. The method performs data access based on the above-mentioned processor circuit. Among them, the method includes: obtaining an external access signal; calling the protection module inside the processor circuit to perform security authentication on the external access signal; and the external access signal passing the security authentication accesses the processor through the interface module.

[0008] The present invention also provides a device authentication method for a processor circuit. The method performs device authentication based on the above-mentioned processor circuit. Among them, the method includes: obtaining an authentication request of a target device to be authenticated; responding to the authentication request and initiating an authentication process to the target device; obtaining a feedback result of the target device, and calling the security protocol sub-module inside the processor circuit. The security protocol sub-module authenticates the target device based on the device data pre-burned in the target device and the feedback result.

[0009] The present invention also provides a computer-readable storage medium, in which a computer program is stored. Among them, when the computer program is executed by a processor, it implements the steps of the above-mentioned data access method of the processor circuit, or the steps of the above-mentioned device authentication method of the processor circuit.

[0010] The present invention also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the above-mentioned data access method of the processor circuit, or the steps of the above-mentioned device authentication method of the processor circuit.

[0011] With the present invention, since a protection module and an interface module are encapsulated within the package of the processor, the protection module is disposed between the processor and the interface module and is used to perform security authentication on the external access signals of the processor. The external access signals that pass the security authentication access the processor through the interface module, simplifying the security circuit design of the server system, having a small board area, providing more comprehensive security prevention, solving the technical problems such as large volume, low integration, insufficient security, and incomplete protection scope existing in the related technology platform firmware protection solutions, and achieving technical effects such as effectively reducing the risk of the server being hacked by hardware and reducing the size of the server. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] To more clearly illustrate the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0013] Figure 1 Schematic diagram of the structure of a processor circuit provided by an embodiment of the present invention; Figure 2 Internal block diagram of a security-enhanced processor provided by an embodiment of the present invention; Figure 3 Schematic diagram of the package of a security-enhanced processor provided by an embodiment of the present invention; Figure 4 Composition diagram of the PFM module provided by an embodiment of the present invention; Figure 5 Device authentication flow chart provided by an embodiment of the present invention; Figure 6 Flow schematic diagram of a data access method for a processor circuit provided by an embodiment of the present invention; Figure 7 Flow schematic diagram of a device authentication method for a processor circuit provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0014] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present invention.

[0015] It should be noted that in the description of the present invention, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present invention are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0016] In the related art, the central processing unit generally does not integrate a secure boot authentication function internally, and the entire boot process lacks an effective monitoring mechanism. Under the traditional architecture, the security encryption and firmware verification operations of the platform are usually completed by external hardware or the platform management controller, such as BMC or PFR FPGA. In the current mainstream server platforms, the key security protection components include: PFR FPGA for implementing the platform firmware elasticity and secure boot function; BIOS Flash for storing the BIOS firmware and supporting the normal boot of the CPU; and SPI Flash for the BMC chip boot and storing the BMC firmware. These key devices are usually integrated in the DC-SCM module.

[0017] During the startup process of the server system, the PFR FPGA, as the core security control unit, can perform three key operations on the BIOS firmware and BMC firmware respectively at different startup stages: Protection, Detection, and Recovery. Through these measures, the PFR FPGA can effectively identify whether the firmware has been tampered with and attempt to restore the original trusted state when an anomaly is detected, thus achieving the security guarantee of the overall operating environment of the service platform. However, this traditional architecture based on an external PFR FPGA has several significant drawbacks. First, the firmware protection unit of the existing server platform is usually composed of a PFR FPGA and multiple logic devices, and the overall circuit occupies a large space, posing a great challenge to the layout of the already space-constrained DC-SCM module. To solve the space problem, the design party often has to trim some functions of the BMC or even delete its peripheral circuits to make room for the PFR-related circuits; or make the PFR function an optional configuration item, resulting in limited product promotion and the inability to form a unified standard solution. Second, since the PFR FPGA and its related key devices are exposed on the motherboard, and the DC-SCM itself is a hot-swappable module, this makes it easier for attackers to physically attack these security devices, greatly increasing the risk of being hacked by hardware, and the overall reliability and security of the system are thus severely affected. In addition, the existing PFR solutions mainly focus on providing security protection for the FLASH memory used for CPU and BMC startup, while lacking necessary security control measures for some key interface pins of the CPU itself (such as the JTAG (Joint Test Action Group) debugging interface, PECI (Platform Environment Control Interface) management interface, etc.). This means that even if the firmware has not been tampered with, attackers may still bypass the security mechanism through these exposed physical interfaces and directly access or modify the content of the CPU internal registers, thus causing serious security risks. In summary, the existing PFR architecture has obvious shortcomings in terms of space utilization, hardware security, and comprehensive CPU protection.

[0018] In view of the deficiencies of the related technologies, there is an urgent need for a new generation of security-enhanced CPU solution that is more integrated, built-in, and has all-round protection capabilities. Embodiments of the present invention propose a processor circuit, a server, a data access method, an authentication method, and a medium to simplify the security circuit design of the server system, reduce the board area, and achieve more comprehensive security prevention, as follows: To enable those skilled in the art of this technology to better understand the solution of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0019] Figure 1 A structural schematic diagram of a processor circuit provided by an embodiment of the present invention is shown as Figure 1 shown. The processor circuit 10 specifically includes: a substrate 101, a processor 102, a package 103, a protection module 104, and an interface module 105.

[0020] Among them, the processor 102 is integrated on the substrate 101, the protection module 104 and the interface module 105 are encapsulated in the package 103 of the processor 102, and the protection module 104 is disposed between the processor 102 and the interface module 105 for performing security authentication on external access signals of the processor 102, and the external access signals passing the security authentication access the processor 102 through the interface module 105.

[0021] Among them, the substrate 101 is a physical infrastructure for carrying electronic components and circuits, providing mechanical support and electrical connection for electronic devices; the protection module 104 is an FPGA module, that is, a field programmable logic array, for performing security protection functions; the protection module 104 is encapsulated in the package 103 of the processor 102, coexists with the original processor 102 and the interface module 105, and is interconnected with the two. Although new functional modules are added, the overall package size, the number and position of pins remain unchanged, and the original interface definition is retained.

[0022] It can be understood that in the embodiment of the present invention, the processor 102 is integrated on the substrate 101, and the protection module 104 and the interface module 105 are encapsulated in the package 103 of the processor 102, and the protection module 104 is located between the processor 102 and the interface module 105 to implement security authentication for all external access signals of the processor 102, achieve security protection, so that only secure signals can access the processor 102 through the interface module 105, enhancing the security of the server processor. Moreover, by integrating the protection module 104 into the package of the processor 102, the protection module 104 shares the package substrate with the original processor 102 and the interface module 105, without changing the pin definition and arrangement method, realizing seamless replacement and upgrade without changing the motherboard wiring, power supply, BIOS firmware, etc., ensuring pin compatibility.

[0023] In the embodiment of the present invention, the protection module 104 and the interface module 105 are interconnected through an embedded multi-processor interconnect bridge.

[0024] Among them, the Embedded Multi-Die Interconnect Bridge (EMIB) is an advanced packaging technology. It is a tiny silicon bridge embedded in the packaging substrate to provide high-speed and low-latency electrical connections between different dies. Different from traditional interposers or the method of directly routing through the substrate, EMIB provides a shorter and more direct path, thus reducing signal delay and loss. It can be used to connect multiple independent silicon chips within a single package, enabling efficient communication between the silicon chips.

[0025] It can be understood that the protection module 104 and the interface module 105 in the embodiment of the present invention are interconnected through the Embedded Multi-Die Interconnect Bridge technology, which means that the protection module 104 can communicate with the interface module 105 efficiently through EMIB. It ensures that after the external access signal passes through the security authentication of the protection module 104 first, it then accesses the processor 102 via the interface module 105. This not only enhances the security of the server processor but also enables the protection module 104 to share the packaging substrate with the original processor 102 and the interface module 105 without changing the pin definition and arrangement method, realizing seamless replacement and upgrade without modifying the motherboard wiring, power supply, BIOS firmware, etc., and ensuring pin compatibility.

[0026] In the embodiment of the present invention, the interface module 105 includes multiple interfaces. Among them, some of the serial bus interfaces among the multiple interfaces are connected to the pins of the processor 102 after passing through the protection module 104.

[0027] Among them, the interface module 105 includes multiple interfaces, such as I2C (Inter-Integrated Circuit, two-wire serial bus), PIROM (Programmable Read-Only Memory), I3C (Improved Inter Integrated Circuit), DEBUG (DEBUG interface), etc., which can allow external devices to communicate with the processor 102.

[0028] It can be understood that the interface module 105 of the embodiment of the present invention includes multiple interfaces. Among them, some serial bus interfaces, such as I2C PIROM and I3C DEBUG, etc., after being processed by the protection module 104, are then connected to the pins of the processor 102. Through these specific serial bus interfaces, it can be realized that the external access signals sent to the processor 102 need to pass through the security authentication of the protection module 104 to ensure security before finally reaching the processor 102, enhancing the security of the system, protecting the processor from unauthorized access, and at the same time maintaining the pin compatibility with the existing processor package.

[0029] In the embodiment of the present invention, the protection module 104 includes a logic sub-module, and among them, anti-rollback protection rules and at least one screening rule are set in the logic sub-module.

[0030] Among them, the logic sub-module is a PFM module, which is used to enhance the security and management of the system firmware; the anti-rollback protection rules refer to a series of measures to prevent the system or firmware version from rolling back to the previous old version, ensuring that the security will not be reduced due to the use of outdated software; the screening rules define which devices or instructions are allowed to access the processor 102, including restricting which addresses can be executed and which commands can be sent. The details will be described in detail below and will not be elaborated here.

[0031] It can be understood that the protection module 104 of the embodiment of the present invention contains a logic sub-module, and anti-rollback protection rules and at least one screening rule are set in the logic sub-module. Specifically, the logic sub-module can perform anti-rollback protection to ensure that the system will not load firmware older than the current version. In addition, screening rules are also set to limit the commands allowed to access the processor 102. In this way, the logic sub-module can effectively control and protect the permission management of external access to the processor 102.

[0032] In the embodiment of the present invention, the header of the logic sub-module contains an open-source version control system for executing anti-rollback protection rules.

[0033] Among them, the open-source version control system, namely SVN (Subversion), is used to manage and track changes in the firmware version, enforce anti-rollback protection rules, and ensure that only the firmware that has passed verification can be run. It is a tool for centrally managing the change history of files and directories, widely used in software and firmware development to record every modification, support version backtracking, and enable teamwork. In the embodiments of the present invention, SVN is used for firmware version management and anti-rollback protection. Specifically, through the built-in firmware version tracking mechanism, each verified firmware version is uniquely identified and its version number is stored to ensure that only the firmware newer than the currently running version can be loaded and executed. When attempting to load an older version of the firmware, it is detected that its SVN value is lower than the current version, thereby triggering the anti-rollback protection mechanism to reject the operation and prevent security vulnerabilities or function failures caused by downgrading.

[0034] It can be understood that the header of the logic sub-module in the embodiments of the present invention contains a version control system similar to open source for enforcing anti-rollback protection rules. Specifically, the PFM header contains SVN information to ensure that the system does not load firmware older than the current version, thereby preventing potential security risks caused by using outdated software and effectively preventing any operation that attempts to roll back the firmware to a previous version to ensure the security of the system.

[0035] In the embodiments of the present invention, the logic sub-module includes at least one of a byte signature chain, a hash value of byte-protected content, rules for a serial peripheral interface, and rules for a server message block.

[0036] Among them, the byte signature chain is a key mechanism for ensuring the authenticity and integrity of the firmware. By constructing a verification chain based on digital signatures, starting from the hardware trust root, the signature verification of each level of firmware module is carried out step by step to ensure that the code loaded at each stage comes from a trusted source and has not been tampered with. Related to this is the hash value of the byte-protected content, which is a unique digest value calculated for specific firmware or configuration data using an encryption hash algorithm (such as SHA-256, SHA-384, a set of two standardized cryptographic hash algorithms, etc.). As the "fingerprint" of this content, this hash value is usually embedded in the signature chain and compared by the verifier to confirm whether the firmware content is legal and has been illegally modified; the rules of the Serial Peripheral Interface, namely SPI Rules, define which external debugging devices can access the processor 102 through the SPI bus, as well as the specific commands that can be executed and the address range that can be accessed. These rules, as a fine-grained access control mechanism, prevent unauthorized or insecure operations from being initiated through the SPI interface, thereby protecting the internal resources of the processor from illegal access; the rules of the Server Message Block are similar to the rules of the Serial Peripheral Interface, but specifically for the SMB (System Management Bus) bus, stipulating which hosts can access the processor 102, as well as the types of instructions that these hosts can execute and access permissions, further strengthening the security boundary of the entire system.

[0037] It can be understood that the logic sub-module of the embodiment of the present invention includes at least one of the following components: the signature chain of bytes, used to verify the authenticity and integrity of the firmware; the hash value of the byte-protected content, used to confirm the legality of the firmware content; the defined rules of the Serial Peripheral Interface, restricting which devices can access the processor 102 through the SPI bus and the specific addresses and commands that can be executed; and the Server Message Block rules, further refining which hosts can access the processor 102 and which instructions are allowed to be executed. Through the combined action of the above screening rules, the security of external access and the integrity of the firmware are ensured, preventing unauthorized access and potential security threats.

[0038] In the embodiment of the present invention, the protection module 104 includes a hub sub-module, among which, the hub sub-module provides multiple serial bus outputs.

[0039] Among them, the hub sub-module is an I3C HUB (Improved Inter-Integrated Circuit Hub) module, which is a hardware sub-module based on the I3C protocol. Its main function is to expand a single I3C master controller interface into multiple I3C interfaces, so as to achieve support for multiple slave devices or provide redundant paths to improve system reliability.

[0040] It can be understood that the protection module 104 of the embodiment of the present invention includes a hub sub-module, which implements the I3C HUB function inside the protection module 104, provides at least two I3C outputs, and is connected to the processor 102, which not only supports efficient communication between different devices, but also enhances the security of the system. For example, by performing device authentication on the I3C host, it is ensured that only verified devices can interact with the processor 102, enabling the system to maintain a high level of security protection while ensuring high performance.

[0041] In the embodiment of the present invention, the protection module 104 includes a multiplexer sub-module and a security protocol sub-module. The hub sub-module provides multiple serial bus outputs, which are respectively connected to the multiplexer sub-module and the security protocol sub-module. The security protocol sub-module is used to authenticate the devices accessing the internal registers of the processor 102.

[0042] Among them, the multiplexer sub-module is a MUX (Multiplexer) module, which is a digital or analog circuit module. Its main function is to select the required signal from multiple input signals and forward it to the target output channel. It is widely used in hardware design for resource scheduling, signal switching, and path selection, to select one signal from multiple input signals for output, and determine which input signal will be transmitted to the output end through a control signal; the security protocol sub-module is the SPDM (Secure Protocol for Device Messages Submodule) sub-module, which is a standardized protocol designed to enhance the security of communication between devices, mainly used to ensure the security of data exchange between devices, especially suitable for authentication and encrypted communication between hardware components, and is used here to authenticate and manage the identity of devices accessing the internal registers of the processor.

[0043] It can be understood that the protection module 104 of the embodiment of the present invention further includes a multiplexer sub-module and a security protocol sub-module. The hub sub-module provides multiple serial bus outputs, which are respectively connected to the multiplexer sub-module and the security protocol sub-module. Specifically, the hub sub-module implements the I3C HUB function and provides at least two I3C outputs. One output is connected to the processor 102 after being selected by the multiplexer sub-module, and the other output is connected to the security protocol sub-module. The security protocol sub-module is used to authenticate the devices attempting to access the internal registers of the processor 102, ensuring that only verified devices can interact with the processor 102. This design not only supports efficient communication between multiple external devices and the processor, but also enhances the security of the system and prevents unauthorized access.

[0044] In an embodiment of the present invention, the protection module 104 identifies application scenarios that do not require authentication and decryption through internal circuit switching, and transmits relevant pins of the interface module 105 from the protection module 104 to the pins of the processor 102 in a pass-through manner.

[0045] Among them, internal circuit switching refers to the ability of the protection module 104 to dynamically change the signal path through its programmable logic structure, thereby determining whether to enable the security mechanism or directly pass through the signal; application scenarios that do not require authentication and decryption include, for example, factory batch testing, the programming phase, etc. In these scenarios, there is no need to perform authentication and data encryption operations to improve efficiency; relevant pins of the interface module 105 can be I2C PIROM and I3C DEBUG, etc.; pass-through means that the signal is directly transmitted from the input end to the output end without any processing or intervention, that is, the protection module 104 does not authenticate or encrypt / decrypt the signal, but directly forwards it to the processor 102.

[0046] It can be understood that the protection module 104 of the embodiment of the present invention has the ability to dynamically switch the internal circuit path according to the application scenario. When it is identified that the current operation scenario does not require authentication and decryption, such as the large-scale testing phase before the processor 102 leaves the factory, the protection module 104 will directly pass through the pin signal originally connected to the external interface module 105 to the corresponding pin of the processor 102, bypassing all security processing procedures, improving the testing efficiency, and ensuring a reasonable balance between flexibility and security at different usage stages.

[0047] In an embodiment of the present invention, the processor 102 is provided with debugging pins, and an external debugging tool accesses the internal registers of the processor 102 through the debugging pins, and the device authentication of the external debugging tool is burned in the protection module 104.

[0048] Among them, the debugging pin is CPU_JTAG, that is, the JTAG interface implemented on the processor 102, which allows an external debugging tool to directly access the internal registers and other hardware resources of the processor 102 through this interface; an external debugging tool is a type of hardware or software device used to access, monitor, and control the internal state of the processor, and is widely used in scenarios such as chip development, firmware debugging, and system verification, such as JTAG debuggers, BDM (Background Debug Mode) debuggers, etc.; device authentication is authentication based on the SPDM protocol. Authentication based on the SPDM protocol is a protocol designed to enhance the security of communication between devices, especially suitable for authentication and encrypted communication between hardware components, used to ensure the security of devices during data exchange and prevent common security threats such as man-in-the-middle attacks and replay attacks.

[0049] It can be understood that the processor 102 in the embodiment of the present invention is provided with debugging pins, and an external debugging tool can access the registers inside the processor 102 through these debugging pins. To ensure the security of this process, the device authentication process of the external debugging tool is burned into the protection module 104. Specifically, the protection module 104 that has burned the device authentication process will verify the external debugging tool that accesses the registers inside the processor 102 through the debugging pins. Only the debugging tool that passes this authentication process can obtain the permission to access the processor 102 and perform debugging operations. This design not only improves the security of the system and prevents unauthorized access, but also ensures the effectiveness and reliability of the debugging process.

[0050] In the embodiment of the present invention, the processor 102 is provided with platform environment control interface pins, and the internal devices of the server access the registers inside the processor 102 through the platform environment control interface pins during the server system startup phase. The device authentication of the internal devices of the server is burned into the protection module 104.

[0051] Among them, the platform environment control interface pins, namely PECI pins, are a single-wire serial interface mainly used to monitor and control environmental parameters such as the temperature and voltage of the system platform, and allow internal devices to access certain registers of the processor during the system startup phase; the internal devices of the server refer to various hardware components inside the server, such as BMC, sensors, etc. These components may need to communicate with the processor 102 during system startup to obtain necessary status information or perform configuration; the device authentication of the internal devices of the server is an authentication based on the SPDM protocol.

[0052] It can be understood that the processor 102 in the embodiment of the present invention is provided with platform environment control interface pins, and the internal devices of the server can access the registers inside the processor 102 through these PECI pins during the server system startup phase. Similarly, to ensure security, the device authentication process of the internal devices of the server is burned into the protection module 104. Specifically, the protection module 104 will perform an authentication based on the SPDM protocol on the internal devices of the server that attempt to access the registers inside the processor 102 through the platform environment control interface pins. Only the devices that pass the authentication can obtain the access permission and perform relevant operations. This design not only supports efficient communication between multiple internal devices and the processor, but also enhances the security of the system and prevents unauthorized access.

[0053] The processor circuit proposed according to an embodiment of the present invention encapsulates a protection module and an interface module within the package of the processor. The protection module is disposed between the processor and the interface module and is used to perform security authentication on the external access signals of the processor. The external access signals that pass the security authentication access the processor through the interface module, simplifying the security circuit design of the server system, having a small board area, and providing more comprehensive security prevention, achieving technical effects such as effectively reducing the risk of the server being hacked by hardware and reducing the size of the server.

[0054] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.

[0055] The processor circuit will be further described below through a specific embodiment.

[0056] Figure 2 For the block diagram of the security-enhanced processor designed in this article, taking the existing mainstream processor as an example, the processor acts as the receiving end. Its interface module can externally provide interfaces such as I2C PIROM, I3C DEBUG, I3C MNG (Improved Inter-Integrated Circuit Management Interface), CPU_JTAG, and PECI. External debug root tools can perform read and write access to the processor through these buses. The current platform security management policy does not protect these interfaces, and these interfaces are exposed on the motherboard side, greatly increasing the risk of abnormal tampering with processor information. In this embodiment, a protection module (field programmable gate array chip) is encapsulated in the CPU Package (processor package) to effectively protect the processor from being abnormally tampered with. As Figure 3 shown, the protection module is located near the interface module and shares the same substrate. Through the EMIB packaging technology, the interface module and the protection module are interconnected. The protection module can authenticate the relevant signals accessing the processor first and perform encryption and decryption; through the internal circuit switching of the protection module, for some application scenarios that do not require authentication and decryption, such as batch processor testing, the relevant pins of the processor interface module can be directly connected to the processor pins through transparent transmission inside the protection module to improve the testing efficiency. At the same time, after performing security authentication on the processor self-boot firmware, the normal operation of the processor system can be effectively protected.

[0057] The main functions of the protection module are as follows: 1. The I2C_PIROM and I3C_DBG interfaces of the processor interface module are connected to the processor PIN pins after passing through the protection module. The protection module integrates the Platform Firmware Manifest Logic Module (PFM) internally. The PFM header contains SVN to enforce anti-rollback protection. SMB and I3C filtering rules are set inside the PFM, including allowable HOST (host) filtering and allowable HOST instruction filtering. Figure 4 This is the component diagram of the PFM module, which mainly consists of three parts: Block1 - an 896 - byte signature chain, Block0 - a hash value of 128 - byte protected content, and defined SPI Rules and SMB Rules. The Rules are used to restrict which devices can access the processor and the address commands that can be executed during the access process.

[0058] Specifically, first, Block 0 (data block 0) contains a 128 - byte hash value used to verify the integrity of the protected content; then comes Block 1 (data block 1), which contains an 896 - byte signature chain to ensure the authenticity and non - tampering of the data source; subsequently, the PFM part details SPI rules, SMBus rules, and signed FVM (Firmware Verification Module) capsules and other information, which are used to define and manage the configuration and update policies of the platform firmware; finally, by padding the PC (Padding Count, the number of padding bytes) to align to the 64 - byte boundary, the standardization and efficiency of the entire data structure are guaranteed, ensuring the security, integrity, and seamless update of the platform firmware.

[0059] 2. The protection module integrates the I3C HUB function internally, providing two I3C outputs. One can be connected to the processor after being gated by the multiplexer sub - module MUX, and the other is connected to the SPDM sub - module inside the protection module. The SPDM sub - module authenticates the I3C HOST device. At the same time, the SPDM sub - module is connected to the processor through I3C for the PFR protection module to interact with the processor about PFR - related information.

[0060] 3. CPU_JTAG, as the debug pin of the processor, external debug tools can access most of the internal registers of the processor through this pin. Therefore, device authentication based on the SPDM protocol is added to restrict the access of debug tools to the internal registers of the processor. The CPU_JTAG device authentication is enabled after burning the PFR protection module. By default, the CPU_JTAG pin is passed through from the protection module to the processor interface module before the chip leaves the factory. Similarly, the PECI pin of the processor can also be used to access the internal register information of the processor during the system startup phase, so the same device authentication measures are also adopted. Figure 5 This is the schematic diagram of the device authentication process, asFigure 5 As shown, the protection module, as the requesting end device, initiates an authentication process to the debugging end such as BMC. The process sequence is to obtain the firmware version of the debugging end, and the debugging end feeds back the version information; obtain the debugging ability from the debugging end, and the debugging end feeds back the debugging command; request to negotiate the algorithm with the debugging end; initiate to obtain DIGESTS (digest information) from the debugging end, obtain the certificate request, and the debugging end returns the certificate information; initiate an authentication request to the debugging end, and the debugging end returns the identity information; initiate a request to obtain the debugging content to the debugging end, and the debugging end starts the debugging work process.

[0061] An embodiment of the present invention also provides a server, including the above-mentioned processor circuit.

[0062] An embodiment of the present invention also provides a data access method for a processor circuit. The method performs data access based on the above-mentioned processor circuit. Figure 6 It is a flowchart of the data access method for the processor circuit provided by the embodiment of the present invention. As Figure 6 shown, the method includes the following steps: In step S201, an external access signal is obtained.

[0063] Among them, the external access signal is an access request signal from an external device, usually passed in through a physical interface (such as I2C PIROM, I3C DEBUG, JTAG, PECI, etc.).

[0064] It can be understood that the embodiment of the present invention first needs to obtain an external access signal passed in through a physical interface, such as I2C PIROM, I3C DEBUG, JTAG, PECI, etc.

[0065] In step S202, the protection module inside the processor circuit is called to perform a security authentication on the external access signal.

[0066] Among them, the security authentication is a security authentication based on the SPDM protocol.

[0067] It can be understood that when the processor in the embodiment of the present invention detects an access request from an external device, it will call the integrated protection module inside it to perform a security authentication on the external access signal based on the SPDM protocol to ensure that only authorized access behaviors can be executed, thereby guaranteeing the security and integrity of the system.

[0068] In step S203, the external access signal that passes the security authentication accesses the processor through the interface module.

[0069] It is understandable that in the embodiments of the present invention, only after the SPDM authentication process in the protection module in the previous step, the access request signal of the external device can be regarded as passing the security authentication. The authenticated access signal will then enter the processor through the interface module to perform access operations on internal registers, firmware, or configuration information, thereby ensuring that only authenticated devices can truly access the internal resources of the processor, effectively preventing illegal access and potential security risks.

[0070] According to the data access method of the processor circuit provided by the embodiments of the present invention, the protection module inside the processor circuit performs security authentication on external access signals, enabling external access signals that pass the security authentication to access the processor. The security prevention is more comprehensive, achieving the technical effect of effectively reducing the risk of the server being cracked by hardware.

[0071] For the description of the features in the corresponding embodiments of the data access method of the processor circuit, reference can be made to the relevant descriptions of the corresponding embodiments of the processor circuit, which will not be elaborated here one by one.

[0072] The embodiments of the present invention also provide a device authentication method for a processor circuit. The method performs device authentication based on the above-mentioned processor circuit. Figure 7 It is a schematic flowchart of the device authentication method for the processor circuit provided by the embodiments of the present invention, as Figure 7 shown. The method includes the following steps: In step S301, obtain the authentication request of the target device to be authenticated.

[0073] Among them, the target device to be authenticated is the external debugging device waiting for authentication; the authentication request is a set of identity verification information sent by the target device, which may include the device firmware version, identity information, operations to be executed, etc.

[0074] It is understandable that in the embodiments of the present invention, when the external debugging device attempts to access the processor through interfaces such as JTAG, PECI, or I3C, the protection module will first obtain the authentication request of the target device. This request contains the identity information of the device, supported algorithms, and firmware version, etc., which is the basis for subsequent identity verification.

[0075] In step S302, in response to the authentication request, initiate an authentication process to the target device.

[0076] Among them, responding to the authentication request means that after the protection module receives the identity verification information sent by the external device, it makes a response and prepares to start the security authentication process.

[0077] It can be understood that after the protection module in the embodiment of the present invention detects an authentication request from an external debugging device, it will respond to it and actively initiate an authentication process. This process includes multiple stages such as algorithm negotiation, certificate acquisition, and identity verification, which are used to determine whether the target device has legitimate access rights. Only the device that passes the complete authentication process is allowed to continue accessing the internal resources of the processor, thereby effectively preventing unauthorized operations and potential security threats.

[0078] In step S303, obtain the feedback result of the target device, and call the security protocol sub-module inside the processor circuit. The security protocol sub-module performs device authentication on the target device based on the device data pre-burned in the target device and the feedback result.

[0079] Among them, the security protocol sub-module is the SPDM sub-module. This sub-module can, for example, compare and verify by combining the identity information pre-burned when the target device leaves the factory with the currently obtained feedback result to complete the identity authentication process of the device.

[0080] It can be understood that after the protection module in the embodiment of the present invention receives the feedback result of the target device in the authentication process, it will call the security protocol sub-module encapsulated inside the processor circuit, and compare and verify by combining the identity information pre-burned when the target device leaves the factory with the currently obtained feedback result, thereby completing the identity authentication process of the device. Only the device that passes this authentication is allowed to continue accessing the internal registers or other key resources of the processor, ensuring that the access control of the system has high security.

[0081] According to the device authentication method of the processor circuit provided by the present invention, the feedback result of the target device in the authentication process can be received, and the security protocol sub-module encapsulated inside the processor circuit can be called to complete the identity authentication process of the device. Only the device that passes this authentication is allowed to continue accessing the internal registers or other key resources of the processor, ensuring that the access control of the system has high security.

[0082] For the description of the features in the corresponding embodiments of the device authentication method of the processor circuit, reference can be made to the relevant description of the corresponding embodiments of the processor circuit, which will not be elaborated here one by one.

[0083] The embodiment of the present invention also provides a computer-readable storage medium, in which a computer program is stored. Among them, the computer program is set to execute the steps in any of the above-mentioned embodiments of the data access method of the processor circuit or the device authentication method of the processor circuit when running.

[0084] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media capable of storing computer programs, such as USB flash drives, read-only memory (ROM for short), random access memory (RAM for short), mobile hard disks, magnetic disks, or optical discs.

[0085] Embodiments of the present invention also provide a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above embodiments of the data access method for a processor circuit or the device authentication method for a processor circuit.

[0086] Embodiments of the present invention also provide another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above embodiments of the data access method for a processor circuit or the device authentication method for a processor circuit.

[0087] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0088] The above has introduced in detail a processor circuit, a server, a data access method, an authentication method, and a medium provided by the present invention. Specific examples are used herein to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present invention, several improvements and modifications can still be made to the present invention, and these improvements and modifications also fall within the protection scope of the claims of the present invention.

Claims

1. A processor circuit, characterized in that, Comprising: A substrate, and a processor, a protection module, and an interface module integrated on the substrate; A package of the processor, wherein the protection module and the interface module are encapsulated in the package, and the protection module is disposed between the processor and the interface module for performing security authentication on external access signals of the processor, and the external access signals passing the security authentication access the processor through the interface module.

2. The processor circuit according to claim 1, wherein The protection module and the interface module are interconnected by an embedded multi-processor bridge.

3. The processor circuit according to claim 1, wherein The interface module includes a plurality of interfaces, wherein some of the plurality of interfaces, i.e., serial bus interfaces, are connected to pins of the processor after passing through the protection module.

4. The processor circuit according to claim 1, wherein The protection module includes a logic sub-module, wherein an anti-rollback protection rule and at least one screening rule are set in the logic sub-module.

5. The processor circuit according to claim 4, characterized in that, The header of the logic sub-module includes an open-source version control system for executing the anti-rollback protection rule.

6. The processor circuit according to claim 4, wherein The logic sub-module includes at least one of a byte signature chain, a hash value of byte-protected content, a rule of a serial peripheral interface, and a rule of a server message block.

7. The processor circuit according to claim 1, wherein The protection module includes a hub sub-module, wherein the hub sub-module provides multiplexed serial bus outputs.

8. The processor circuit according to claim 7, wherein The protection module includes a multiplexer sub-module and a security protocol sub-module. The hub sub-module provides multiplexed serial bus outputs, which are respectively connected to the multiplexer sub-module and the security protocol sub-module. The security protocol sub-module is used for authenticating a device accessing internal registers of the processor.

9. The processor circuit according to claim 8, wherein The processor is provided with debug pins, and an external debug tool accesses internal registers of the processor through the debug pins. The device authentication of the external debug tool is burned in the protection module.

10. The processor circuit according to claim 8, wherein, The processor is provided with platform environment control interface pins, and internal devices of a server access internal registers of the processor through the platform environment control interface pins during the startup phase of the server system. The device authentication of the internal devices of the server is burned in the protection module.

11. A server, characterized in that, Including the processor circuit according to any one of claims 1-10.

12. A data access method for a processor circuit, characterized in that, The method performs data access based on the processor circuit according to any one of claims 1-10, wherein the method includes: Obtaining an external access signal; Invoking the protection module inside the processor circuit to perform security authentication on the external access signal; The external access signal passing the security authentication accesses the processor through the interface module.

13. A device authentication method for a processor circuit, characterized in that, The method performs device authentication based on the processor circuit according to any one of claims 1-10, wherein the method includes: Obtaining an authentication request of a target device to be authenticated; Responding to the authentication request and initiating an authentication process to the target device; Obtaining a feedback result of the target device, and invoking the security protocol sub-module inside the processor circuit. The security protocol sub-module authenticates the target device based on device data pre-burned in the target device and the feedback result.

14. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein when the computer program is executed by a processor, the steps of the data access method of the processor circuit as described in claim 12 or the steps of the device authentication method of the processor circuit as described in claim 13 are implemented.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the data access method of the processor circuit as described in claim 12 or the steps of the device authentication method of the processor circuit as described in claim 13 are implemented.

Citation Information

Patent Citations

  • Device for supporting high-performance safety protocol

    CN101997834A

  • Trusted server security control device and method and trusted server

    CN113918953A

  • JTAG interface security protection method, device and system, equipment and storage medium

    CN114861173A

  • Security chip protection device and method based on active shielding layer

    CN117251890A

  • Secure starting method of server mainboard based on eSPI (enhanced serial peripheral interface) and related equipment

    CN118427147A

Cited By

  • Optical module conflict-free security access method and device and storage medium

    CN121643930A