Processor circuit, server, data access method, authentication method and medium

By integrating protection and interface modules within the processor package and combining them with embedded multiprocessor interconnect bridging technology, the low integration and insufficient security of existing server firmware protection solutions are resolved, achieving more comprehensive security protection and reducing the risk of hardware cracking.

CN120387193BActive Publication Date: 2025-10-24INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510875855.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-10-24
Estimated Expiration
2045-06-26

AI Technical Summary

Technical Problem

Existing firmware protection solutions for server platforms suffer from problems such as large size, low integration, insufficient security, and incomplete protection scope. In particular, they lack effective protection for critical CPU interfaces, resulting in a high risk of hardware cracking.

Method used

A protection module and an interface module are integrated within the processor package. The protection module is located between the processor and the interface module and achieves security authentication through embedded multiprocessor interconnection bridging technology. The protection module contains a logic submodule and a security protocol submodule, providing rollback protection, filtering rules and device authentication to enhance system security.

Benefits of technology

It simplifies the security circuit design of the server system, reduces the board area, achieves more comprehensive security protection, reduces the risk of the server being hacked by hardware, and improves the security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120387193B_ABST
    Figure CN120387193B_ABST
Patent Text Reader

Abstract

The application discloses a kind of processor circuit, server, data access method, authentication method and medium, it is related to processor design technical field, including substrate and integrated on substrate processor, and in the package of processor Package protection module and interface module, protection module is set between processor and interface module, for the security authentication of external access signal of processor, and the external access signal of security authentication accesses processor through interface module, simplify the server system security circuit design, small, security protection is more comprehensive, solve the technical problems that related technical platform firmware protection scheme exists big, low integration, security is insufficient and protection range is not comprehensive, etc., reaches the technical effect that the risk of effectively reducing server is cracked by hardware, reduce server size etc..
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of processor design, and in particular to a processor circuit, a server, a data access method, an authentication method and a medium. BACKGROUND

[0002] At present, network intrusion has shifted from the traditional operating system and application software carrier to the more covert firmware level. Firmware, as the startup code that is first executed after the power-on of server components such as CPU (Central Processing Unit), network controller, on-chip RAID (Redundant Array of Inexpensive Disks) solution, etc., is usually stored in the SPI (Serial Peripheral Interface) flash of the system and is regarded as the starting point of the platform system trust chain. However, once the firmware is infected, malware can implement attacks by tampering with the data in the hard disk or destroying one or more hardware components during the startup process.

[0003] To cope with such threats, a PFR (Platform Firmware Resilience) mechanism is proposed. PFR uses devices with a trusted root and aims to provide comprehensive security protection for all firmware in the server, ensuring system integrity and reliability. In existing servers, the PFR function is mainly implemented by a PFR FPGA (Field Programmable Gate Array) located in the DC-SCM (Data Center-Security Control Module) module, and cooperates with the SPI Flash used to store the BIOS (Basic Input Output System) and BMC (Baseboard Management Controller) firmware to form a firmware security protection system. However, this scheme has obvious limitations: first, the PFR module is composed of multiple discrete devices, occupying a large amount of board space, which limits the design of the DC-SCM, affecting the functional integrity and promotion; second, the key security devices are exposed on the PCB, and combined with the fact that the DC-SCM is a pluggable module, increasing the risk of physical attacks and hardware cracking; third, the current PFR only protects the BIOS and BMC firmware, and does not cover the key debug interface of the CPU, the security protection range is not comprehensive, and the overall security still needs to be improved. SUMMARY

[0004] The application provides a processor circuit, a server, a data access method, an authentication method and a medium to at least solve the technical problems of large volume, low integration, insufficient security and incomplete protection range of platform firmware protection schemes in the related art.

[0005] The application provides a processor circuit, comprising a substrate and a processor, a protection module and an interface module integrated on the substrate; a package of the processor, the protection module and the interface module are packaged in the package, the protection module is arranged between the processor and the interface module, and the protection module is configured to perform security authentication on an external access signal of the processor; and the external access signal that passes the security authentication accesses the processor through the interface module.

[0006] The application further provides a server comprising the processor circuit.

[0007] The application further provides a data access method of the processor circuit, and the method is based on the processor circuit and comprises the following steps: obtaining an external access signal; calling a protection module in the processor circuit to perform security authentication on the external access signal; and accessing the processor through the interface module by using the external access signal that passes the security authentication.

[0008] The application further provides a device authentication method of the processor circuit, and the method is based on the processor circuit and comprises the following steps: obtaining an authentication request of a target device to be authenticated; initiating an authentication process to the target device in response to the authentication request; obtaining a feedback result of the target device; calling a security protocol sub-module in the processor circuit; and performing device authentication on the target device based on device data pre-burned in the target device and the feedback result.

[0009] The application further provides a computer readable storage medium, and the computer readable storage medium stores a computer program, wherein the computer program is executed by a processor to implement the steps of the data access method of the processor circuit or the steps of the device authentication method of the processor circuit.

[0010] The application further provides a computer program product, comprising a computer program, and the computer program is executed by a processor to implement the steps of the data access method of the processor circuit or the steps of the device authentication method of the processor circuit.

[0011] By the present application, since the protection module and the interface module are packaged in the package of the processor, the protection module is arranged between the processor and the interface module, and is used for performing security authentication on the external access signal of the processor, the external access signal passing the security authentication accesses the processor through the interface module, the server system security circuit design is simplified, the board area is small, the security protection is more comprehensive, and the technical problems such as large size, low integration, insufficient security and non-comprehensive protection range of the related technology platform firmware protection scheme are solved, and the technical effects of effectively reducing the risk of server hardware cracking and reducing the size of the server are achieved. BRIEF DESCRIPTION OF DRAWINGS

[0012] In order to more clearly illustrate the embodiments of the present application, the drawings needed in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0013] Figure 1 A structural schematic diagram of a processor circuit provided by an embodiment of the present application is shown in the figure.

[0014] Figure 2 An internal block diagram of a security enhanced processor provided by an embodiment of the present application is shown in the figure.

[0015] Figure 3 A packaging schematic diagram of a security enhanced processor provided by an embodiment of the present application is shown in the figure.

[0016] Figure 4 A composition diagram of a PFM module provided by an embodiment of the present application is shown in the figure.

[0017] Figure 5 A device authentication flowchart provided by an embodiment of the present application is shown in the figure.

[0018] Figure 6 A flowchart of a data access method of a processor circuit provided by an embodiment of the present application is shown in the figure.

[0019] Figure 7 A flowchart of a device authentication method of a processor circuit provided by an embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0020] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, but not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the present application.

[0021] It should be noted that in the description of the present application, the term "comprising" or "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or apparatus including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article or apparatus. The terms "first", "second" and the like in the present application are used to distinguish similar objects, not to describe a specific order or sequence.

[0022] In the related art, the central processor is generally not integrated with the security startup authentication function inside, and the whole startup process lacks an effective monitoring mechanism. Under the traditional architecture, the platform security encryption and firmware verification operation is usually completed by external hardware or platform management controller, such as BMC or PFR FPGA. In the current mainstream server platform, the key security protection components include: PFR FPGA for implementing platform firmware resilience and security startup function; BIOS Flash for storing BIOS firmware and supporting CPU normal startup; and SPI Flash for BMC chip startup, storing BMC firmware. These key devices are usually integrated in the DC-SCM module.

[0023] In the server system startup process, the PFR FPGA as the core security control unit can perform three key operations: protection, detection, and recovery on BIOS firmware and BMC firmware in different startup stages. Through these measures, the PFR FPGA can effectively identify whether the firmware has been tampered with and attempt to restore the original trusted state when abnormalities are found, thereby achieving security protection for the overall operating environment of the service platform. However, this traditional architecture based on external PFR FPGA has several significant defects. First, the firmware protection unit of the existing server platform is usually composed of PFR FPGA and multiple logic devices, which occupies a large space in the overall circuit, posing a great challenge to the layout of the DC-SCM module which is already space-constrained. To solve the space problem, the design party often has to cut some functions of the BMC or even delete its peripheral circuits to make room for PFR-related circuits; or make PFR function as an optional configuration item, which limits product promotion and cannot form a unified standard solution. Second, since the PFR FPGA and its related key devices are exposed on the mainboard, and the DC-SCM itself is a module that supports hot plugging, this makes it easier for attackers to conduct physical contact attacks on these security devices, greatly increasing the risk of hardware cracking, and thus seriously affecting the overall reliability and security of the system. In addition, the existing PFR scheme mainly focuses on providing security protection for the FLASH memory used for CPU and BMC startup, but lacks necessary security control measures for some key interface pins of the CPU itself (such as JTAG (Joint Test Action Group) debugging interface, PECI (Platform Environment Control Interface) management interface, etc.). This means that even if the firmware has not been tampered with, attackers can still bypass the security mechanism through these exposed physical interfaces to directly access or modify the CPU internal register content, causing serious security risks. In summary, the existing PFR architecture has obvious shortcomings in space utilization, hardware security, and comprehensive protection of the CPU.

[0024] In view of the defects of the related art, a new generation of security-enhanced CPU solution that is more integrated, built-in, and has comprehensive protection capability is urgently needed. The embodiments of the present application propose a processor circuit, a server, a data access method, an authentication method, and a medium to simplify the security circuit design of the server system, reduce the board area, and achieve more comprehensive security protection, as follows:

[0025] In order for those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0026] Figure 1 A structural schematic diagram of a processor circuit provided by an embodiment of the present application is shown in the figure, which specifically comprises a substrate 101, a processor 102, a package 103, a protection module 104 and an interface module 105. Figure 1

[0027] The processor 102 is integrated on the substrate 101, and the protection module 104 and the interface module 105 are packaged in the package 103 of the processor 102, and the protection module 104 is arranged between the processor 102 and the interface module 105, for performing security authentication on external access signals of the processor 102, and the external access signals passing the security authentication access the processor 102 through the interface module 105.

[0028] The substrate 101 is a physical basic structure for bearing electronic components and circuits, and provides mechanical support and electrical connection for electronic devices; the protection module 104 is an FPGA module, i.e. a field programmable logic array, for performing security protection function; the protection module 104 is packaged in the package 103 of the processor 102, coexists with the original processor 102 and the interface module 105, and is interconnected with the two, and although a new functional module is added, the overall package size, pin number and position remain unchanged, and the original interface definition is reserved.

[0029] It can be understood that the embodiment of the present application integrates the processor 102 on the substrate 101, and packages the protection module 104 and the interface module 105 in the package 103 of the processor 102, and the protection module 104 is located between the processor 102 and the interface module 105, to perform security authentication on all external access signals of the processor 102, to realize security protection, so that only the security signals can access the processor 102 through the interface module 105, to enhance the security of the server processor, and by integrating the protection module 104 into the package of the processor 102, the protection module 104 shares the package substrate with the original processor 102 and the interface module 105, without changing the pin definition and arrangement mode, to realize seamless replacement and upgrading without changing the motherboard wiring, power supply, BIOS firmware and the like, to ensure the compatibility of the pins.

[0030] In the embodiment of the present application, the protection module 104 and the interface module 105 are interconnected through an embedded multi-processor interconnection bridge.

[0031] ​Among them, the embedded multi-processor interconnection bridge, namely EMIB (Embedded Multi-Die Interconnect Bridge), is an advanced packaging technology, which is a tiny silicon bridge embedded in the packaging substrate to provide high-speed and low-delay electrical connection between different dies. Unlike the traditional method of interposer or direct wiring through the substrate, EMIB provides a shorter and more direct path, thereby reducing signal delay and loss. It can be used to connect multiple independent silicon chips in a single package, enabling efficient communication between the silicon chips.

[0032] It can be understood that the protection module 104 and the interface module 105 of the embodiment of the application are interconnected through the embedded multi-processor interconnection bridge technology, which means that the protection module 104 can efficiently communicate with the interface module 105 through the EMIB, ensuring that the external access signal first passes through the security authentication of the protection module 104 and then accesses the processor 102 through the interface module 105. This not only enhances the security of the server processor, but also enables the protection module 104 to share the packaging substrate with the original processor 102 and the interface module 105, without changing the pin definition and arrangement, thereby realizing seamless replacement and upgrading without changing the motherboard wiring, power supply, BIOS firmware, etc., and ensuring the compatibility of the pins.

[0033] In the embodiment of the application, the interface module 105 includes a plurality of interfaces, and part of the serial bus interfaces in the plurality of interfaces are connected to the pins of the processor 102 through the protection module 104.

[0034] Among them, the interface module 105 includes a plurality of interfaces, such as I2C (Inter-Integrated Circuit, two-wire serial bus) PIROM (Programmable Read-Only Memory, programmable read-only memory), I3C (Improved Inter Integrated Circuit, improved two-wire serial bus) DEBUG (DEBUG interface, debugging interface), etc., which can allow external devices to communicate with the processor 102.

[0035] It can be understood that the interface module 105 of the embodiment of the present application comprises a plurality of interfaces, part of which are serial bus interfaces such as I2C PIROM and I3C DEBUG, which are connected to the pins of the processor 102 after being processed by the protection module 104. Through these specific serial bus interfaces, the external access signals sent to the processor 102 need to pass through the security authentication of the protection module 104, and can finally reach the processor 102 after ensuring safety, thereby enhancing the security of the system, protecting the processor from unauthorized access, and maintaining compatibility with the pins of the existing processor package.

[0036] In the embodiment of the present application, the protection module 104 comprises a logic submodule, wherein the logic submodule is provided with a rollback prevention protection rule and at least one screening rule.

[0037] The logic submodule is a PFM module for enhancing the security and management of the system firmware. The rollback prevention protection rule refers to a series of measures to prevent the system or firmware version from rolling back to the previous old version, thereby ensuring that the security will not be reduced due to the use of outdated software. The screening rule defines which devices or instructions are allowed to access the processor 102, including limiting which addresses can be executed and which commands can be sent. Details will be described below, and will not be repeated here.

[0038] It can be understood that the protection module 104 of the embodiment of the present application comprises a logic submodule, and the logic submodule is provided with a rollback prevention protection rule and at least one screening rule. Specifically, the logic submodule can perform rollback prevention protection to ensure that the system will not load firmware older than the current version. In addition, the screening rule is also set to limit the commands that can access the processor 102. In this way, the logic submodule can effectively control and protect the authority management of accessing the processor 102 from the outside.

[0039] In the embodiment of the present application, the header of the logic submodule comprises an open source version control system for executing the rollback prevention protection rule.

[0040] The open source version control system, i.e., SVN (Subversion), is used to manage and track changes of the firmware version, execute the anti-rollback protection rule, and ensure that only the firmware that has passed the verification can be run. The SVN is a tool for centrally managing the change history of files and directories, is widely used in software and firmware development, is used to record each modification, support version backtracking, and realize team collaboration. In the embodiment of the present application, the SVN is used for firmware version management and anti-rollback protection. Specifically, through the built-in firmware version tracking mechanism, each verified firmware version is uniquely identified and its version number is stored, so that only the firmware newer than the current running version can be loaded and executed. When an old version firmware is attempted to be loaded, it is detected that the SVN value is lower than the current version, so that the anti-rollback protection mechanism is triggered, the operation is refused, and the security risk or function failure caused by degradation is prevented.

[0041] It can be understood that the header of the logical sub-module of the embodiment of the present application contains a version control system similar to an open source code, which is used to execute the anti-rollback protection rule. Specifically, the PFM header contains SVN information to ensure that the system will not load the firmware older than the current version, thereby preventing the security risk that may be caused by using outdated software, and effectively preventing any operation that attempts to roll back the firmware to a previous version, thereby ensuring the security of the system.

[0042] In the embodiment of the present application, the logical sub-module includes at least one of a byte signature chain, a hash value of byte-protected content, a rule of a serial peripheral interface, and a rule of a server message block.

[0043] The byte signature chain is a key mechanism for guaranteeing firmware authenticity and integrity. By constructing a verification chain based on digital signatures, starting from the hardware root of trust, each firmware module is verified level by level, ensuring that the code loaded at each stage comes from a trusted source and has not been tampered with. Related to this is the hash value of the byte-protected content, which is a unique digest value calculated using a cryptographic hash algorithm (such as SHA-256, SHA-384, and other standardized cryptographic hash algorithms) for specific firmware or configuration data. This hash value serves as a "fingerprint" for the content and is usually embedded in the signature chain for comparison by the verifier to confirm whether the firmware content is legitimate and has not been illegally modified. The SPI rules define which external debugging devices can access the processor 102 through the SPI bus and the specific commands and address ranges they can execute. These rules serve as a fine-grained access control mechanism to prevent unauthorized or unsafe operations from being initiated through the SPI interface, thereby protecting the internal resources of the processor from illegal access. The SMB rules are similar to the SPI rules but are specific to the SMB (System Management Bus) bus, specifying which hosts can access the processor 102 and the types of instructions and access permissions they can execute, further strengthening the security boundary of the entire system.

[0044] It can be understood that the logical sub-module of the embodiment of the present application includes at least one of the following components: a byte signature chain for verifying the authenticity and integrity of firmware; a hash value of byte-protected content for confirming the legitimacy of firmware content; defined serial peripheral interface rules limiting which devices can access the processor 102 through the SPI bus and the specific addresses and commands they can execute; and server message block rules further refining which hosts can access the processor 102 and which instructions are allowed to execute. Through the combined action of the above screening rules, the security of external access and the integrity of firmware are ensured, preventing unauthorized access and potential security threats.

[0045] In the embodiment of the present application, the protection module 104 includes a hub sub-module, wherein the hub sub-module provides multiple serial bus outputs.

[0046] The hub sub-module is an I3C HUB (Improved Inter-Integrated Circuit Hub) module, which is a hardware sub-module based on the I3C protocol. Its main function is to expand a single I3C master controller interface into multiple I3C interfaces, thereby supporting multiple slave devices or providing redundant paths to improve system reliability.

[0047] It can be understood that the protection module 104 of the embodiment of the application includes a hub submodule, which implements an I3C HUB function inside the protection module 104, provides at least two I3C outputs, and is connected to the processor 102, thereby not only supporting efficient communication between different devices but also enhancing the security of the system, for example, by performing device authentication on the I3C host to ensure that only verified devices can interact with the processor 102, so that the system can maintain high-level security protection while ensuring high performance.

[0048] In the embodiment of the application, the protection module 104 includes a multiplexer submodule and a security protocol submodule, and the hub submodule provides a plurality of serial bus outputs and is connected to the multiplexer submodule and the security protocol submodule, respectively. The security protocol submodule is used to authenticate devices accessing internal registers of the processor 102.

[0049] The multiplexer submodule is a MUX (Multiplexer) module, which is a digital or analog circuit module. Its main function is to select the required signal from multiple input signals and forward it to the target output channel. It is widely used in resource scheduling, signal switching, and path selection in hardware design. It is used to select a signal from multiple input signals for output, and the control signal determines which input signal will be transmitted to the output end. The security protocol submodule is an SPDM (Secure Protocol for Device Messages Submodule) submodule, which is a standardized protocol designed to enhance the security of communication between devices. It is mainly used to ensure the security of devices during data exchange, and is particularly suitable for authentication and encrypted communication between hardware components. Here, it is used to authenticate and securely manage devices accessing internal registers of the processor.

[0050] It can be understood that the protection module 104 of the embodiment of the application also includes a multiplexer submodule and a security protocol submodule, and the hub submodule provides a plurality of serial bus outputs and is connected to the multiplexer submodule and the security protocol submodule, respectively. Specifically, the hub submodule implements an I3C HUB function and provides at least two I3C outputs. One is connected to the processor 102 through the multiplexer submodule, and the other is connected to the security protocol submodule. The security protocol submodule is used to authenticate devices attempting to access internal registers of the processor 102, ensuring that only verified devices can interact with the processor 102. This design not only supports efficient communication between multiple external devices and the processor but also enhances the security of the system, preventing unauthorized access.

[0051] In the embodiment of the present application, the protection module 104 switches through internal circuits, identifies application scenarios that do not require authentication and decryption, and transmits the relevant pins of the interface module 105 to the pins of the processor 102 through the protection module 104.

[0052] Among them, the internal circuit switching refers to the ability of the protection module 104 to dynamically change the signal path through its programmable logic structure, thereby determining whether to enable the security mechanism or directly transmit the signal; the application scenarios that do not require authentication and decryption, such as factory batch testing, burning stage, etc., do not need to perform identity verification and data encryption operations in these scenarios to improve efficiency; the relevant pins of the interface module 105 can be I2C PIROM and I3C DEBUG, etc.; the transparent transmission refers to the signal being directly transmitted from the input end to the output end without any processing or intervention, that is, the protection module 104 does not authenticate or encrypt and decrypt the signal, but directly forwards it to the processor 102.

[0053] It can be understood that the protection module 104 of the embodiment of the present application has the ability to dynamically switch the internal circuit path according to the application scenario, and when it is identified that the current is an operation scenario that does not require authentication and decryption, for example, the large-scale testing stage before the processor 102 is shipped, the protection module 104 will directly transmit the pin signal originally connected to the external interface module 105 to the corresponding pin of the processor 102, bypassing all security processing procedures, improving the testing efficiency, and ensuring a reasonable balance between flexibility and security in different use stages.

[0054] In the embodiment of the present application, the processor 102 is provided with a debugging pin, and an external debugging tool accesses the internal registers of the processor 102 through the debugging pin. The device authentication of the external debugging tool is burned in the protection module 104.

[0055] Among them, the debugging pin is CPU_JTAG, that is, the JTAG interface implemented on the processor 102, which allows the external debugging tool to directly access the internal registers and other hardware resources of the processor 102 through the interface; the external debugging tool is a kind of hardware or software device used to access, monitor and control the internal state of the processor, which is widely used in chip development, firmware debugging, system verification and other scenarios, such as JTAG debugger, BDM (Background Debug Mode, background debugging mode) debugger, etc.; the device authentication is an identity verification based on the SPDM protocol, which is a protocol designed to enhance the security of communication between devices, especially suitable for authentication and encrypted communication between hardware components, used to ensure the security of devices when exchanging data, prevent common security threats such as man-in-the-middle attacks, replay attacks, etc.

[0056] It can be understood that the processor 102 of the embodiment of the application is provided with debugging pins, and an external debugging tool can access the internal registers of the processor 102 through the debugging pins. In order to ensure the security of the process, a device authentication process of the external debugging tool is burned in the protection module 104. Specifically, the protection module 104 in which the device authentication process is burned will verify the external debugging tool that accesses the internal registers of the processor 102 through the debugging pins. Only the debugging tool that passes the authentication process can obtain the access right of the processor 102 and perform the debugging operation. This design not only improves the security of the system and prevents unauthorized access, but also ensures the effectiveness and reliability of the debugging process.

[0057] In the embodiment of the application, the processor 102 is provided with platform environment control interface pins, and the internal devices of the server access the internal registers of the processor 102 through the platform environment control interface pins in the server system startup stage. The device authentication of the internal devices of the server is burned in the protection module 104.

[0058] The platform environment control interface pins, i.e. PECI pins, are a kind of single-wire serial interface, which is mainly used for monitoring and controlling the environmental parameters such as temperature and voltage of the system platform, and allowing the internal devices to access certain registers of the processor in the system startup stage. The internal devices of the server refer to various hardware components inside the server, such as BMC, sensors, etc. These components may need to communicate with the processor 102 in the system startup to obtain necessary state information or perform configuration. The device authentication of the internal devices of the server is an identity verification based on the SPDM protocol.

[0059] It can be understood that the processor 102 of the embodiment of the application is provided with platform environment control interface pins, and the internal devices of the server can access the internal registers of the processor 102 through the PECI pins in the server system startup stage. Similarly, in order to ensure the security, the device authentication process of the internal devices of the server is burned in the protection module 104. Specifically, the protection module 104 will perform identity verification based on the SPDM protocol on the internal devices of the server that try to access the internal registers of the processor 102 through the platform environment control interface pins. Only the devices that pass the authentication can obtain the access right and perform the related operation. This design not only supports efficient communication between multiple internal devices and the processor, but also enhances the security of the system and prevents unauthorized access.

[0060] The processor circuit provided by the embodiment of the present application encapsulates the protection module and the interface module in the package of the processor, the protection module is arranged between the processor and the interface module, and the protection module is configured to perform security authentication on an external access signal of the processor. The external access signal that passes the security authentication accesses the processor through the interface module. The processor circuit simplifies the design of the security circuit of the server system, occupies a small area on a board, and provides more comprehensive security protection, thereby achieving the technical effects of effectively reducing the risk of hardware cracking of the server and reducing the size of the server.

[0061] From the above description of the embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software on a general hardware platform, and of course, can also be implemented by hardware, but in many cases, the former is a better embodiment.

[0062] The processor circuit is further described below through a specific embodiment.

[0063] Figure 2 For the safety-enhanced processor diagram designed in this paper, taking a mainstream existing processor as an example, the processor serves as a receiving end, and the interface module thereof can provide I2C PIROM, I3C DEBUG, I3C MNG (Improved Inter-Integrated Circuit Management Interface), CPU_JTAG, PECI and other interfaces to the outside. An external debugging root tool can perform read-write access to the processor through these buses. The current platform security management strategy does not protect these interfaces, and these interfaces are exposed to the motherboard end, which greatly increases the risk of abnormal tampering of processor information. The embodiment effectively protects the processor from abnormal tampering by encapsulating a protection module (a field programmable gate array chip) in the CPU Package (processor package). Figure 3 As shown in the figure, the protection module is located near the interface module and shares the same substrate. The interface module and the protection module are interconnected through EMIB packaging technology. The protection module can authenticate, encrypt and decrypt related signals for accessing the processor before the interface module. For some application scenarios that do not require authentication and decryption, such as batch processor testing, the related pins of the processor interface module can be directly connected to the processor pins through the protection module inside the protection module, thereby improving the testing efficiency. At the same time, after the security authentication of the processor self-starting firmware, the normal operation of the processor system can be effectively protected.

[0064] The main functions of the protection module are as follows:

[0065] I2C PIROM, I3C_DBG interface of processor interface module is connected to processor PIN pin after protection module, protection module integrates platform firmware list logic module PFM internally, PFM header contains SVN to enforce anti-rollback protection, PFM internally sets SMB, I3C screening rules, contains allowable HOST screening and allowable HOST instruction screening. Figure 4 PFM module composition diagram is mainly composed of three parts, Block1-896 bytes of signature chain, Block0-128 bytes of hash value of protected content and defined SPI Rules and SMB Rules, which limit which devices can access the processor and the address command executable in the access process through Rules.

[0066] Specifically, first, Block 0 (data block 0) contains 128 bytes of hash value, which is used to verify the integrity of the protected content; then Block 1 (data block 1) contains 896 bytes of signature chain, which ensures the authenticity and non-tampering of the data source; then the PFM part lists the SPI rules, SMBus rules and signed FVM (Firmware Verification Module) capsules and other information in detail, which are used to define and manage the configuration and update strategy of platform firmware; finally, by filling PC (Padding Count, the number of padding bytes) to align to the 64-byte boundary, the specification and efficiency of the entire data structure are guaranteed, ensuring the safety, integrity and seamless update of the platform firmware.

[0067] Two, the protection module internally integrates I3C HUB function, provides two-way I3C output, one way through the multiplexer submodule MUX gating can be connected to the processor, the other way is connected to the SPDM submodule in the protection module, the SPDM submodule performs device authentication on the I3C HOST, at the same time the SPDM submodule is connected to the processor through I3C, used for PFR protection module to interact with the processor PFR related information.

[0068] Three, CPU_JTAG is the debugging pin of the processor, external debugging tools can access most of the registers in the processor through this pin, so the device authentication based on SPDM protocol is added to limit the access of debugging tools to the internal registers of the processor. CPU_JTAG device authentication is enabled after burning PFR protection module, the chip transmits CPU_JTAG pin from protection module to processor interface module by default before shipment. Similarly, the PECI pin of the processor can also be used to access the internal register information of the processor during system startup, so the same device authentication measures are adopted. Figure 5 The flowchart of device authentication is as follows,Figure 5 As shown, the protection module initiates an authentication process as a request end device to a debugging end such as a BMC, and the process sequence is to obtain a debugging end firmware version, the debugging end feeds back version information; obtain debugging capability from the debugging end, the debugging end feeds back debugging commands; request the debugging end to negotiate an algorithm; initiate DIGESTS (digest information) acquisition from the debugging end, acquire certificate request, and the debugging end returns certificate information; initiate an identity authentication request to the debugging end, and the debugging end returns identity information; initiate a debugging content acquisition request to the debugging end, and the debugging end starts a debugging work process.

[0069] Embodiments of the application also provide a server comprising the processor circuit described above.

[0070] Embodiments of the application also provide a data access method of a processor circuit, which is based on the processor circuit described above to access data. Figure 6 A flowchart of the data access method of the processor circuit provided by the embodiments of the application is shown in FIG. 6. Figure 6 As shown, the method comprises the following steps:

[0071] In step S201, an external access signal is acquired.

[0072] The external access signal is an access request signal from an external device, which is usually transmitted through a physical interface (such as I2C PIROM, I3C DEBUG, JTAG, PECI, etc.).

[0073] It can be understood that the embodiments of the application first need to acquire an external access signal transmitted through a physical interface, such as I2C PIROM, I3C DEBUG, JTAG, PECI, etc.

[0074] In step S202, a protection module inside the processor circuit is called to perform security authentication on the external access signal.

[0075] The security authentication is a security authentication based on the SPDM protocol.

[0076] It can be understood that when the processor detects an access request from an external device, the embodiments of the application will call the integrated protection module inside to perform security authentication on the external access signal based on the SPDM protocol, so as to ensure that only authorized access behavior can be executed, thereby guaranteeing the security and integrity of the system.

[0077] In step S203, the external access signal that passes the security authentication accesses the processor through an interface module.

[0078] It can be understood that, only after the SPDM authentication process in the protection module in the above step, the access request signal of the external device can be regarded as passing the security authentication, and the authenticated access signal will then enter the processor through the interface module to perform the access operation on the internal register, the firmware or the configuration information, so that only the authenticated device can really access the internal resources of the processor, thereby effectively preventing illegal access and potential security risks.

[0079] According to the data access method of the processor circuit provided by the embodiment of the application, the external access signal is subjected to security authentication by the protection module in the processor circuit, so that only the external access signal passing the security authentication can access the processor, the security protection is more comprehensive, and the technical effect of effectively reducing the risk of hardware cracking of the server is achieved.

[0080] The features of the embodiments corresponding to the data access method of the processor circuit can be referred to the related description of the embodiments corresponding to the processor circuit, which will not be repeated here.

[0081] The embodiment of the application further provides a device authentication method of a processor circuit, which is based on the processor circuit described above to authenticate a device, Figure 7 The flowchart of the device authentication method of the processor circuit provided by the embodiment of the application is shown in Figure 7 The method comprises the following steps:

[0082] In step S301, an authentication request of a target device to be authenticated is obtained.

[0083] The target device to be authenticated is an external debugging device waiting for authentication, and the authentication request is a set of identity verification information sent by the target device, which can include the device firmware version, identity information, and operation to be executed.

[0084] It can be understood that, when the external debugging device tries to access the processor through the JTAG, PECI or I3C interface, the protection module will first obtain the authentication request of the target device, which contains the identity information, supported algorithm and firmware version of the device, and is the basis for subsequent identity verification.

[0085] In step S302, in response to the authentication request, an authentication process is initiated to the target device.

[0086] The response to the authentication request means that, after receiving the identity verification information sent by the external device, the protection module responds and prepares to start the security authentication process.

[0087] It can be understood that, after the protection module detects the authentication request from the external debugging device, the protection module responds to the authentication request and initiates an authentication process, including algorithm negotiation, certificate acquisition, identity verification and the like, to determine whether the target device has a legal access right. Only the device that passes the complete authentication process is allowed to continue to access the internal resources of the processor, thereby effectively preventing unauthorized operations and potential security threats.

[0088] In step S303, a feedback result of the target device is acquired, and a security protocol submodule inside the processor circuit is called to perform device authentication on the target device based on the device data pre-burned in the target device and the feedback result.

[0089] The security protocol submodule, namely, the SPDM submodule, can perform, for example, comparison and verification of the identity information pre-burned in the target device at the time of factory shipment and the feedback result currently acquired, to complete the identity authentication process of the device.

[0090] It can be understood that, after the protection module receives the feedback result of the target device in the authentication process, the protection module calls the security protocol submodule encapsulated inside the processor circuit to perform comparison and verification of the identity information pre-burned in the target device at the time of factory shipment and the feedback result currently acquired, to complete the identity authentication process of the device. Only the device that passes the authentication is allowed to continue to access the internal registers or other critical resources of the processor, to ensure that the access control of the system has high security.

[0091] According to the device authentication method of the processor circuit provided in the application, the feedback result of the target device in the authentication process can be received, and the security protocol submodule encapsulated inside the processor circuit is called to complete the identity authentication process of the device. Only the device that passes the authentication is allowed to continue to access the internal registers or other critical resources of the processor, to ensure that the access control of the system has high security.

[0092] The features of the embodiments of the device authentication method of the processor circuit can be referred to the related descriptions of the embodiments of the processor circuit, which will not be repeated here.

[0093] The embodiments of the application further provide a computer readable storage medium, which stores a computer program, and the computer program is configured to execute the steps in the above-mentioned any one of the data access method of the processor circuit or the device authentication method of the processor circuit.

[0094] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.

[0095] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of any of the above-mentioned data access method for a processor circuit or device authentication method for a processor circuit.

[0096] An embodiment of the present invention also provides another computer program product, including a non-volatile computer-readable storage medium, the non-volatile computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, implementing the steps in any of the above-mentioned data access method for a processor circuit or device authentication method embodiments for a processor circuit.

[0097] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0098] The above is a detailed introduction to a processor circuit, server, data access method, authentication method and medium provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the scope of protection of the claims of the present invention.

Claims

1. A processor circuit, characterized by, The processor circuit comprises: a substrate and a processor, a protection module and an interface module integrated on the substrate, the protection module and the interface module are connected through an embedded multi-processor interconnection bridge; a package of the processor, the protection module and the interface module are packaged in the package, the protection module is arranged between the processor and the interface module, and the protection module is used for security authentication of an external access signal of the processor, and the security authenticated external access signal accesses the processor through the interface module; the protection module comprises a hub submodule, wherein the hub submodule provides a plurality of serial bus outputs; the protection module comprises a multiplexer submodule and a security protocol submodule, the hub submodule provides a plurality of serial bus outputs, and is connected with the multiplexer submodule and the security protocol submodule respectively, and the security protocol submodule is used for authenticating a device accessing an internal register of the processor.

2. The processor circuit of claim 1, wherein, The interface module comprises a plurality of interfaces, wherein part of the serial bus interfaces in the plurality of interfaces are connected to pins of the processor through the protection module.

3. The processor circuit of claim 1, wherein, The protection module comprises a logic submodule, wherein the logic submodule is provided with an anti-rollback protection rule and at least one screening rule.

4. The processor circuit of claim 3, wherein, The header of the logic submodule contains an open source version control system, which is used to execute the anti-rollback protection rule.

5. The processor circuit of claim 3, wherein, The logic submodule comprises at least one of a byte signature chain, a hash value of byte protected content, a rule of serial peripheral interface and a rule of server message block.

6. The processor circuit of claim 1, wherein, The processor is provided with a debugging pin, an external debugging tool accesses the internal register of the processor through the debugging pin, and device authentication of the external debugging tool is burned in the protection module.

7. The processor circuit of claim 1, wherein, The processor is provided with a platform environment control interface pin, and an internal device of a server accesses the internal register of the processor through the platform environment control interface pin in a server system startup stage, and device authentication of the internal device of the server is burned in the protection module.

8. A server, characterized by The processor circuit comprises the processor circuit according to any one of claims 1-7.

9. A data access method of a processor circuit, characterized by, The method performs data access based on the processor circuit according to any one of claims 1-7, and the method comprises: obtaining an external access signal; calling a protection module in the processor circuit to perform security authentication on the external access signal; accessing the processor through the interface module through the security authenticated external access signal.

10. A device authentication method of a processor circuit, characterized by, The method performs device authentication based on the processor circuit according to any one of claims 1-7, and the method comprises: obtaining an authentication request of a target device to be authenticated; in response to the authentication request, initiating an authentication process to the target device; obtaining a feedback result of the target device, calling a security protocol submodule in the processor circuit, and performing device authentication on the target device based on device data pre-burned in the target device and the feedback result.

11. A computer readable storage medium, characterized in that, The computer program is stored in the computer readable storage medium and is executed by the processor to implement the steps of the data access method of the processor circuit according to claim 9 or the steps of the device authentication method of the processor circuit according to claim 10.

12. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the data access method of the processor circuit according to claim 9 or the steps of the device authentication method of the processor circuit according to claim 10.

Citation Information

Patent Citations

  • JTAG interface security protection method, device and system, equipment and storage medium

    CN114861173A

  • RSIC-V CPU security chip based on authority management

    CN119808083A

  • BMC intrusion protection method and device, BMC and computer equipment

    CN120017290A