SYSTEMS AND METHODS FOR DYNAMIC CONTROL OF A SAFE OPERATING MODE IN A PROCESSOR
The method allows processors to dynamically switch between secure and performance modes using configuration registers, addressing vulnerabilities and optimizing operation without restarts, enhancing security and performance flexibility.
Patent Information
- Application Number
- DE112021005994
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-12-16
- Filing Date
- 2021-12-06
- Publication Date
- 2026-02-12
- Estimated Expiration
- 2041-12-06
AI Technical Summary
Modern computer systems face challenges in dynamically controlling the operating mode of processors between performance and security modes, leading to vulnerabilities such as side-channel attacks, and existing solutions often require system restarts or fixed configurations at startup.
A method and system for dynamically controlling the operating mode of processors using configuration registers with PRVS and ENFB fields to enable secure or performance modes without restarting, allowing software to adjust these modes during operation based on authorization levels.
Enables dynamic switching between secure and performance modes without system restarts, providing enhanced security and performance flexibility based on authorization levels, thereby reducing vulnerabilities and optimizing processor operation.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
BACKGROUND
[0001] The present invention relates generally to information and data processing systems, processors and storage systems, and in particular to the dynamic control of one or more secured operating modes in a processor.
[0002] Recent advances in information technology and the widespread use of the internet for storing and processing information are constantly increasing the demands placed on computer systems for capturing, processing, storing, and distributing information. Computer systems are currently being developed to increase the speed at which they can run increasingly complex applications for professional, personal, and entertainment purposes. The overall performance of a computer system is influenced by each of the key elements in its architecture, including the performance and structure of the processors, any caches, input / output (I / O) subsystems, the efficiency of memory control functions, the performance of memory units and systems and all associated memory interface elements, and the type and structure of memory link interfaces.
[0003] Modern computer systems typically contain several integrated circuits (ICs), including a processor, which is used to process information within the computer system. The information processed by a processor can consist of computer instructions, which are executed by the processor, and data, which is manipulated by the processor using those instructions. The computer instructions (e.g., applications) and data are usually stored in main memory within the computer system. The performance of the processor can affect the performance of the information processing system, also known as the computer system or data processing system.
[0004] Preventing unauthorized users and / or rogue software from accessing information and data processing systems is becoming increasingly important and difficult. In one scenario, a user or software application may be authorized to access an information processing system, a process, register banks, and / or the storage subsystem, but may not have full access to the entire system, all register banks, or the entire storage subsystem. Accordingly, the user or software application may be authorized to access parts of the system, but not the entire system, all register banks, and / or the entire storage subsystem.In other scenarios, a user and / or a software application is not authorized to access a part of the computer system, its register banks, and / or a part of the memory subsystem. It can be difficult to protect systems, register banks, and / or memory subsystems from access by an unauthorized user and / or an unauthorized software application.
[0005] When designing microprocessors, optimizing the performance of the microarchitecture can also introduce certain security vulnerabilities in the processor's side channels, making the processor and / or the computer system more susceptible to attack. For example, certain performance mechanisms and features in a microprocessor can inherently expose it to a Spectre RSB (Return Stack Buffer) side-channel attack. Although these performance features make the processor more vulnerable, in certain trusted execution environments, opting for performance optimization might be advantageous, as the associated side-channel attack may not pose a significant threat. In other circumstances and execution environments, a more secure configuration that does not use or disables performance optimization might be justified.It would be advantageous if the processor configuration providing optimized performance or optimized security could be dynamically controlled or changed, preferably in one embodiment by trusted software, so that the processor can make the best possible use of hardware and features, instead of setting the performance / security mode by firmware at system startup and not changing it afterwards.
[0006] The publication EP 2 619 670 B1 relates to a data processing device comprising the following: processing circuits for processing data, wherein the processing circuits are configurable to operate at a plurality of precedence levels, the processing circuits enforcing different access permissions to a memory and / or a set of registers on program instructions at different precedence levels; wherein the program instructions comprise at least one set of instructions that is used in both a non-debug mode and a debug mode; a debug module for feeding given instructions from the program instructions to serve as debug instructions for execution by the processing circuits; instruction decoding circuits that respond to the program instructions to generate control signals for controlling the processing circuits to perform data processing;wherein the program instructions include a debug precedence switch instruction, the instruction decoding circuits respond to the debug precedence switch instruction to perform the following: (i) if the processing circuits are in a debug mode, to switch the processing circuits from a current precedence level to a target precedence level; and (ii) if the processing circuits are in a non-debug mode, to prevent execution of the debug precedence switch instruction, regardless of the current precedence level, and wherein an instruction encoding of the debug precedence switch instruction is an encoding that belongs to the one or more instruction sets.
[0007] Publication US 2009 / 0204823A1 concerns a processor configured to operate in a variety of modes, including a safe mode that allows secure access to processor resources. The processor includes memory configured to store a message and firmware code; a first register bit configured to indicate one of a variety of states, including a first state and a second state, with the first register bit configured to indicate the first state when private emulation instructions are to be executed and the second state when private emulation instructions are to be ignored; and a second register bit to indicate whether the first register bit should indicate the first or the second state upon subsequent entry into safe mode.and a logic unit configured to execute the firmware code to authenticate the message outside of safe mode, and, if the message is successfully authenticated, sets the first register bit according to the second register bit and switches to safe mode. SUMMARY
[0008] The invention is based on the objective of creating a method and a computer system for improved switching of an operating mode in a processor. This objective has been achieved by the features of the independent claims. Embodiments of the invention are specified in the dependent claims.
[0009] The summary of the disclosure serves to provide a better understanding of a computer system, a computer architecture structure, a processor, their operating procedures, and the execution of software applications, including a technique for controlling the security mode of such systems, processors, and their operating procedures, and is not intended to limit the disclosure or the invention. The present disclosure is addressed to the person skilled in the art. It should be noted that various aspects and features of the disclosure may, in some cases, be advantageously used separately or, in other cases, in combination with other aspects and features of the disclosure. Accordingly, variations and modifications to the computer system, the architecture structure, the processor, register banks, their operating procedures, and the manner of executing software applications may be made to achieve various effects.
[0010] Aspects of the present disclosure provide, in one or more embodiments, a system and / or a method for processing data in a processor, which includes changing an operating mode in a processor without restarting the processor.In one embodiment, the system and / or method comprises: initiating a configuration change in a processor from a performance mode to a privileged mode for a control aspect in a privilege level; determining whether the bit for the control aspect in the privilege level is set to a privileged mode in a privilege entry (PRVS) register field; and if the bit for the control aspect in the privilege level is not set to a privileged mode in the PRVS register field, setting the bit for the control aspect in the privilege level in the PRVS register field to a privileged mode, thereby activating the privileged mode in the processor for the control aspect in the privilege level.Preferably, the system and / or the procedure further includes a determination of whether a secure mode for the tax aspect can be implemented at lower authorization levels; and if it is determined that a secure mode for the tax aspect cannot be implemented at lower authorization levels, the procedure for switching to the secure mode for the tax aspect at that authorization level is terminated.In one embodiment, the system and / or method may further include: when it is determined that a secure mode for the control aspect is to be implemented in the lower authorization levels, determining whether the bit for the control aspect in the lower authorization levels is set to a secure mode in an "Enforce Below" (ENFB) register field; and if it is determined that the bit for the control aspect in the lower authorization levels is set to a secure mode in the ENFB register field, the process for switching to the secure mode for the control aspect in the authorization level is executed.In a further embodiment, the system and / or method: if it is determined that the bit for the control aspect in the lower authorization levels in the ENFB register field is not set to a safe mode, determine whether a policy for the control aspect in the authorization level permits a switch to safe mode for the control aspect in the lower authorization levels; and if the policy for the control aspect in the authorization level does not permit a switch to safe mode for the control aspect in the lower authorization levels, the process of switching to safe mode for the control aspect in the authorization level is completed. In one aspect, the processor's safe mode or performance mode for the control aspect in the authorization level is controlled by a software application.
[0011] In one or more embodiments, the system and / or the method further includes: in response to a trigger to switch from a secure mode to a performance mode for the control aspect at the authorization level, checking whether the bit in the SRVS register field for the control aspect at the authorization level is set to performance mode; in response to the fact that the bit in the SRVS register field for the control aspect at the authorization level is not set to performance mode, setting the bit in the service register field for the control aspect at the authorization level to performance mode; checking whether the control aspect in the authorization level of the ENFB register field is set to performance mode for all higher authorization levels;and in response to the fact that the tax aspect in the authorization level of the ENFB register is set to performance mode for all higher authorization levels, switching the processor to performance mode for the tax aspect in the authorization level. The system and / or the procedure, under one aspect in response to the fact that the tax aspect in the authorization level of the ENFB register is not set to performance mode for all higher authorization levels, includes a request that the higher authorization levels allow performance mode for the tax aspect in the authorization level;And in response to the fact that the higher privilege levels do not permit the performance mode for the control aspect at that privilege level, the processor does not enter the performance mode for the control aspect at that privilege level. The request for the higher privilege levels to permit the performance mode for the control aspect at that privilege level typically involves: looking up a policy for the higher privilege levels regarding the performance mode for the control aspect at lower privilege levels; checking whether the policy permits the performance mode for the control aspect at that privilege level;And in response to the policy allowing performance mode for the control aspect at the authorization level, the bit in the ENFB register field for the control aspect at the authorization level is set to performance mode, thereby allowing the processor to enter performance mode for the control aspect at the authorization level.
[0012] In one or more embodiments, a computer system for processing information is disclosed, comprising: at least one processor with one or more register banks, wherein at least one of the registers is a configuration register, the configuration register having a "authorization entry" (PRVS) register field for each of one or more authorization levels, wherein each PRVS register field for each authorization level has one or more control aspect entries containing a bit; and a "translate below" (ENFB) register field for one lower than each of one or more authorization levels, wherein each ENFB register field for each authorization level has one or more control aspect entries containing a bit, wherein the PRVS register field control aspects are numerically equal to and correspond to the ENFB register field control aspects.The processor is configured and designed to initiate a configuration change in a processor from a performance mode to a safe mode for a control aspect in an authorization level, the change comprising: determining whether the bit for the control aspect in the authorization level is set to safe mode in an authorization input (PRVS) register field; and if the bit for the control aspect in the authorization level is not set to safe mode in the PRVS register field, setting the bit for the control aspect in the authorization level in the PRVS register field to safe mode, thereby enabling safe mode in the processor for the control aspect in the authorization level.The processor is preferably configured and designed such that it: can determine whether a safe mode for the control aspect needs to be implemented at lower authorization levels; and if it is determined that a safe mode for the control aspect needs to be implemented at lower authorization levels, it can determine whether the bit for the control aspect at lower authorization levels in a "Implement Below" (ENFB) register field is set to a safe mode; and if it is determined that the bit for the control aspect at lower authorization levels in the ENFB register field is set to a safe mode, the process of switching to safe mode for the control aspect at the authorization level is completed.
[0013] In another embodiment, the system performs the following actions: in response to a trigger to switch from a secure mode to a performance mode for a control aspect at an authorization level, it checks whether a bit in the "Service Entry" (SRVS) register field for the control aspect at that authorization level is set to performance mode; in response to the finding that the bit in the SRVS register field for the control aspect at that authorization level is not set to performance mode, it sets the bit in the "Service" register field for the control aspect at that authorization level to performance mode; and it checks whether the control aspect in the authorization level of an "Implement Below" (ENFB) register field is set to performance mode for all higher authorization levels.and in response to the fact that the control aspect in the authorization level of the ENFB register is set to performance mode for all higher authorization levels, switching the processor to performance mode for the control aspect in the authorization level.
[0014] According to one aspect, a method is provided for changing an operating mode in a processor without restarting the processor, wherein the method comprises: initiating a configuration change in a processor from a performance mode to a privileged mode for a control aspect in a privilege level; determining whether the bit for the control aspect in the privilege level in a privilege entry (PRVS) register field is set to a privileged mode; and if the bit for the control aspect in the privilege level in the PRVS register field is not set to a privileged mode, setting the bit for the control aspect in the privilege level in the PRVS register field to a privileged mode, thereby enabling the privileged mode in the processor for the control aspect in the privilege level.
[0015] According to another aspect, a method is provided for changing a processor's operating mode without restarting the processor, the method comprising: in response to a trigger to switch from a safe mode to a performance operating mode for a control aspect at a privilege level, checking whether a bit in a privilege entry (PRVS) register field for the control aspect at the privilege level is set to performance mode; in response to the finding that the bit in the PRVS register field for the control aspect at the privilege level is not set to performance mode, setting the bit in the service register field for the control aspect at the privilege level to performance mode; checking whether the control aspect in the privilege level of a sub-privilege (ENFB) register field is set to performance mode for all higher privilege levels;and in response to the fact that the control aspect in the authorization level of the ENFB register is set to performance mode for all higher authorization levels, switching the processor to performance mode for the control aspect in the authorization level.
[0016] According to another aspect, a computer system is provided for processing information, wherein the computer system comprises: at least one processor with one or more register banks, wherein at least one of the registers is a configuration register, wherein the configuration register has a "Permission Entry" (PRVS) register field for each of one or more permission levels, wherein each PRVS register field for each permission level has one or more control aspect entries containing a bit;and a "Transfer Below" (ENFB) register field for one lower than any of one or more authorization levels, wherein each ENFB register field for each authorization level has one or more control aspect entries containing a bit, wherein the PRVS register field control aspects are numerically equal to and correspond to the ENRB register field control aspects, wherein the processor is configured and designed to: initiate a change of configuration in a processor from a performance mode to a safe mode for a control aspect in an authorization level; determine whether the bit for the control aspect in the authorization level in the PRVS register field is set to a safe mode;and if the bit for the control aspect in the authorization level in the PRVS register field is not set to a safe mode, the bit for the control aspect in the authorization level in the PRVS register field can be set to a safe mode, thereby enabling safe mode in the processor for the control aspect in the authorization level.
[0017] The foregoing and other features and advantages of the invention will become apparent from the following more specific descriptions of exemplary embodiments of the invention, which are illustrated in the accompanying drawings, wherein identical reference numerals generally represent identical parts of exemplary embodiments of the invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The various aspects, features, and embodiments of the information processing system, the computer system, the computer architecture structure, the processor, the register banks, their operating procedures, and the manner in which software applications are executed are better understood when viewed in conjunction with the provided figures. The embodiments provided in the figures serve to illustrate aspects, features, and / or various embodiments of the information processing system, the computer system, the computer architecture structure, the processor, the register banks, their operating procedures, and the manner in which software applications are executed; however, the claims are not intended to be limited to the precise arrangement, the precise structures, assemblies, subassemblies, functional units, mechanisms, features, aspects, embodiments, units, methods, processes, or techniques as shown.and the arrangements, structures, assemblies, subassemblies, functional units, mechanisms, features, aspects, embodiments, units, methods, processes and techniques shown can be used individually or in combination with other arrangements, structures, assemblies, subassemblies, functional units, mechanisms, features, aspects, embodiments, units, methods, processes and techniques. Fig. Figure 1 shows a general computer or data processing system according to an embodiment of the present disclosure. Fig. Figure 2 shows a processor and memory system according to an embodiment of the present disclosure. Fig. Figure 3 shows a block diagram of a processor according to an embodiment of the present disclosure. Fig. Figure 4 schematically illustrates the organization of a configuration register according to one embodiment of the present disclosure. Fig. Figure 5 illustrates the operation of the configuration register of Fig. 4 according to one embodiment of the present disclosure schematically. Fig. Figure 6 shows a flowchart of a procedure for changing the operating mode of a processor according to one embodiment. Fig. Figure 7 shows a flowchart of a procedure for changing the operating mode of a processor according to a further embodiment. DETAILED DESCRIPTION
[0019] A computer or data processing system 100 suitable for use in a preferred embodiment of the present invention can take many forms, one of which is in Fig. Figure 1 shows the computing or data processing system (information processing system) 100 being configured to store and / or execute program code. In one embodiment, the information processing system 100 may further comprise at least one processor 102, which may be a control unit or part thereof, and which may be directly or indirectly connected via a system bus 106 to storage units and / or input / output units, as shown in Figure 1. Fig. 1 shown. The computer system 100 of Fig. Figure 1 shows a processor 102 (also called a central processing unit (CPU) or microprocessor), random access memory (RAM) 103, non-volatile memory 104, unit-specific circuitry 101, and / or an I / O interface 105. Alternatively or in addition, the RAM 103 and / or the non-volatile memory 104 may be contained within the processor 102, as may the unit-specific circuitry 101 and / or the I / O interface 105. The processor 102 may, for example, be a commercially available microprocessor, a custom processor, a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), separate logic, etc., or generally any instruction-executing unit.RAM 103 is typically used to store variable data, batch data, executable instructions, etc., and may include dynamic random access memory, or DRAM.
[0020] According to various approaches, the non-volatile memory 104 can be any type of non-volatile memory, such as electrically erasable programmable read-only memory (EEPROM), programmable flash read-only memory (PROM), backup battery RAM, hard disks, etc., but is not limited to these. The non-volatile memory 104 is typically used to store the executable firmware and non-volatile data containing programming instructions that can be executed to cause the processor 102 to perform certain functions.
[0021] In some embodiments, the I / O interface 105 may include a data transmission interface through which the processor 102 can exchange data with units located outside the control unit. Examples of the data transmission interface may include serial interfaces such as RS-232 USB (Universal Serial Bus), Small Computer Systems Interface (SCSI), RS-422, or a wireless data transmission interface such as WLAN, Bluetooth, Near Field Communication (NFC), or other wireless interfaces, but are not limited to these. The computer system 100 can exchange data with an external unit via the data transmission interface 105 using any data transmission protocol, such as Automation Drive Interface (ADI).
[0022] Fig. Figure 2 shows an exemplary processing system 180 in which a preferred embodiment of the present invention can be implemented and which can be part of a larger computer system architecture or a larger computer network. The processing system 180 comprises a control processor system or a control processor 102, which is a processing subsystem comprising at least one processor unit (CPU) 125 that can be configured to communicate with a memory control unit (MCU) 140. The CPU 125, also referred to as a microprocessor, can be a module that handles read, write, and configuration requests from a system control unit (not shown). The CPU 125 can be a multi-core processor.The MCU 140 can have a Memory Controller Synchronous (MCS) 142, also called a memory control unit, which enables data transfer with one or more memory units, e.g. DRAMs (in . Fig. (2 not shown) controls a memory subsystem 103. The MCU 140 and the MCS 142 can have one or more processing circuits, or the processing can be performed by the processor 125 or in conjunction with it. The control processor system 102 exchanges data with the memory subsystem 103 via a data transmission bus 106.
[0023] Fig. Figure 3 shows a block diagram of a processor 102 according to an embodiment in which the present disclosure can be exercised. The processor 102 can be a piped processor configured to execute one or more instruction streams or threads. A thread (also called an instruction stream) comprises a sequence or collection of instructions that collectively perform a specific task. The threads can be instruction streams from different parts of the same program running on the processor, from different programs running on the processor, or combinations thereof. In one embodiment, the processor can be a multi-threaded processor and can process threads concurrently.
[0024] According to one embodiment, the processor 102 can include a memory 202, an instruction cache 204, an instruction retrieval unit 206, a branch prediction unit 208, a processing pipeline 210, and a destination resource 220. The processor 102 can be contained within a computer processor or can be otherwise distributed within a computer system. Instructions and data can be stored in the memory 202, and the instruction cache 204 can access instructions in the memory 202 and store the instructions to be retrieved from the cache 204, e.g., the instructions of the various threads. The memory 202 can include any type of volatile or non-volatile memory, such as a cache. The memory 202 and the instruction cache 204 can have multiple cache levels. A data cache (not shown) can also be included in the processor 102.The processor 102 preferably enables multiple threads to share the functional units of the processor 102 (e.g. instruction retrieval and decoding units, caches, branch prediction units and execution units), preferably simultaneously.
[0025] In Fig. Figure 3 shows a simplified example of the instruction retrieval unit 206 and the processing pipeline 210. In various embodiments, the processor 102 can have one or more processing pipelines 210 and instruction retrieval units 206. In one embodiment, the processing pipeline 210 includes a decoding unit 20, an output unit 22, an execution unit 24, a write-back logic 26, a unit 28 for assigning logical registers, a protocol buffer, e.g., a Save & Restore Buffer (SRB), 30, and a physical register bank 32. The instruction retrieval unit 206 and / or the branch prediction unit 208 can also be part of the processing pipeline 210. The processing pipeline 210 may also have other features such as error checking and error handling logic, one or more parallel paths through the processing pipeline 210, and other features that are currently or subsequently known in the field.The pipeline can also be broken down and illustrated in different ways. Although in . Fig. Figure 3 shows a forward path through processor 102, but other feedback and signaling paths between elements of processor 102 may be included. Processor 102 may also include other circuits, functional units, and components.
[0026] The instruction retrieval unit 206 retrieves instructions from the instruction cache 204 for further processing by the decoding unit 20. The decoding unit 20 decodes instructions and forwards the decoded instructions, instruction segments, or other decoded data to the output unit 22. The decoding unit 20 can also detect branch instructions that were not predicted by the branch prediction unit 208. The decoding unit 20 can have one or more configuration registers 250, which are discussed in more detail below. The output unit 22 analyzes the instructions or other data and, based on the analysis, transmits the decoded instructions, instruction segments, or other data to the execution unit 24 in the pipeline 210. The execution unit 24 performs and executes operations as determined by the instructions issued to the execution unit 24.The execution unit 24 can contain multiple execution units, such as fixed-point execution units, floating-point execution units, load / store execution units, vector scalar execution units, and / or other execution units. The physical register bank 32 stores data for the execution units 24. The logical register mapping unit 28 contains entries that provide a mapping between a logical register entry (Leg) and an entry in the physical register bank 32. When an instruction requests to read a logical register entry (Leg), the logical register mapping unit 28 informs the output unit 22, which then informs the execution unit 24 where the data can be positioned in the physical register bank 32.
[0027] When a mispredicted branch or other exception is detected, instructions and data following the mispredicted branch or exception are discarded, for example, deleted from the various units of processor 110. A protocol buffer, such as the Save & Restore Buffer (SRB) 30, contains both speculative and architecture-defined state and backups of the logical register file data when a new instruction is allocated. In this context, protocol buffer 30 stores information from logical register allocation unit 28 when a new instruction is issued and cleans up data from logical register allocation unit 28 when the new instruction is deleted and the old data needs to be restored. Protocol buffer (SRB) 30 retains the stored information until the new instruction has completed.Protocol buffer (SRB) 30 connects to logical register mapping unit 28 to restore the contents of the local register entries from protocol buffer (SRB) 30 to logical register mapping unit 28, updating the pointers in logical register mapping unit 28 so that instructions know where the correct data is located; for example, the processor is reset to the state it was in before the interrupting instruction, such as before the branch instruction was incorrectly predicted.
[0028] The write-back logic 26 writes the results of executed instructions back to a target resource or destination 220. The target resource 220 can be any type of resource, including registers, cache memory, other memory, I / O circuitry for exchanging data with other units, other processing circuitry, or any other type of destination for executed instructions or data. One or more of the processor pipeline units can also provide information about the execution of conditional branch instructions to the branch prediction unit 208.
[0029] Instructions can be processed in the processor 102 in a sequence of logical stages placed in a pipeline. However, it should be noted that the functions of these stages can be combined, so this particular division of stages should not be understood as a limitation unless such a limitation is explicitly stated in the claims herein. Indeed, some of the stages in Fig. 3 is presented as a single logic unit for ease of understanding, and further details are provided below as needed.
[0030] Under certain aspects, a processor 102 can have multiple execution / processing sectors, with each sector containing one or more of the functions specified in Fig. The 3 units shown. For example, each processing sector can have its own processing pipeline 210 with function / execution units 24. A processor 102 with multiple processing sectors can be capable of executing multiple instructions simultaneously, e.g., one instruction in each processing sector at the same time in a processing cycle. Such a processor with multiple processing sectors can be called a multi-sector processor or a parallel-sector processor. By processing simultaneously in multiple sectors, the processing speed can be considerably increased. In single-threaded mode (ST mode), a single thread is processed, and in SMT mode, multiple threads are processed; in one or more embodiments, for example, two threads (SMT2) or four threads (SMT4) are processed simultaneously.
[0031] Information and data processing systems, computer systems, processors, and / or digital logic systems may exhibit processor features and / or performance enhancements that, while optimizing processor performance, may reduce processor security by making it more vulnerable, for example, via a side-channel attack. In some circumstances, it may be preferable for the processor to operate at a higher performance level, such as in performance mode, and in other circumstances, it may be preferable for the processor to operate at a higher security level, such as in a secure mode, rather than in performance mode.It would be preferable and advantageous if the mode in which the processor operates could be dynamically controlled, so that the processor can switch between various performance or security modes during processor operation, instead of setting the performance or security mode via firmware at system startup and not changing it afterwards.
[0032] Furthermore, it would be advantageous if different performance / security operating modes could be defined and configured for various control aspects of different privilege levels within a single processor. It would also be beneficial if the different secure / performance operating modes could be dynamically defined and changed for various control aspects of different privilege levels or statuses during processor operation, thus eliminating the need for a restart. Additionally, it would be advantageous if different security configurations could be implemented with high granularity, allowing, for example, a hypervisor to specify a particular secure configuration or secure mode for an entire logical partition.It would be convenient and advantageous if the system or mechanism for dynamic control would allow the implementation of a secure configuration or a secure mode of processor operation independently of the dynamic control desired at a lower authorization level.
[0033] In one embodiment, dynamic control of the security / performance mode is provided for each control aspect of a processor. In one or more embodiments, different security / performance modes of processor operation can be created for each authorization level (also referred to as authorization state) of a processor. In one embodiment, dynamic control of the secure / performance mode for each control aspect and / or authorization level is achieved by software. In another embodiment, higher authorization levels / states can implement and / or block favorable or desirable security / performance mode settings for lower authorization levels. For example, the secure mode of a higher authorization level in the processor can be implemented against all lower authorization levels or states.The system and the technology for dynamically controlling the security / performance mode of various authorization statuses also allow, in one embodiment, that each authorization status or authorization level is aware of the performance / security mode for each control aspect within that authorization level, and has the ability to control the performance / security mode for each control aspect of each underlying authorization level, provided that no security mode is implemented by a higher authorization level or authorization status.
[0034] In one or more embodiments, configuration registers can be used to provide dynamic control of a processor, and more specifically, dynamic control of a processor's power or safe operating mode. Computer systems, processors, and digital logic systems often have registers that are read from or written to by software programs. Modern integrated circuit-based registers are usually implemented using multi-pin static random-access memory (SRAM). Registers generally have dedicated read and write connections. Registers can be user-accessible, such as data registers, address registers, general-purpose registers, status registers, and configuration registers.From one perspective, a register is a physical or virtual data storage location that, in one embodiment, has an address in the memory map. For example, a register bank might be an array of processor registers within a processor (CPU). Some of these registers, or sections of the registers, such as register entries, are configuration registers. The configuration registers, used to provide dynamic control of the processor's operating mode, such as a safe or power mode, are typically located within the processor and, in one or more embodiments, are situated in the processor's decoding unit, although the configuration registers may be located elsewhere.
[0035] In one or more embodiments, the performance / security mode setting for each aspect of a processor, for each privilege level, can be dynamically controlled and changed during processor operation, preferably by software. For each processor aspect of each privilege level or privilege state—except the lowest privilege level—one embodiment provides two entry fields in a configuration register (or two configuration registers) used to define and control the security / performance mode of that aspect. One of the configuration register fields (or registers) is called the Privilege State Register (PRVS Register) and corresponds to and controls the privilege mode for each aspect of that privilege level.The other configuration register field (or configuration register) is called the Sub-Implement Register (ENFB Register) and provides, for each control aspect, the security / performance mode that a given authorization level in a given implementation intends to implement against lower authorization levels than that given authorization level. The fields or entries in the ENFB configuration register are writable only in that authorization state or level, or in a higher authorization state or level, in one or more implementations, whereas the fields or entries in the ENFG configuration register are readable at all authorization levels.In one embodiment, the final control of the performance / security mode for each control aspect of each authorization level is the OR value of the bit for that control aspect in the PRVS entry for that authorization level and the ENFB bit for the corresponding control aspect in all authorization levels above the authorization level currently being controlled.
[0036] The following describes a dynamic control of the operating mode of a processor, e.g., security mode or performance mode, for an embodiment with reference to Fig. Figure 4 describes a block diagram of configuration register 250. Although configuration register 250 is illustrated as a single configuration register, it should be noted that the configuration register may consist of a series of separate configuration registers and that Fig. 4 is only an exemplary embodiment for illustrative purposes. The configuration register 250 is configured to have a number of authorization levels or authorization states 455, corresponding to the number of authorization levels used by the processor. If the processor has "n" authorization levels or authorization states, the configuration register 250 typically has a corresponding number of "n" authorization levels or authorization states 455. In the example of Fig. 4 The configuration register “n” has authorization levels 455, illustrated as authorization level 0 to “n - 1”, where authorization level 0 is the highest authorization level and authorization level “n - 1” is the lowest authorization level, and the configuration file 260 can vary. In one or more embodiments, each authorization level 455 of the processor and / or each configuration file 250 “m” has aspects 480 of a performance / security mode that can be controlled. In Fig. 4 has configuration register 250 “m” control aspects 480, which are illustrated as control aspects 0 to “m - 1”.
[0037] In one embodiment, each authorization level 455, except for the lowest authorization level 455[n - 1], has two entry fields: a sub-translate field 460 (also called ENFB, ENFB field, or ENFB register) and an authorization entry field 470 (also called PRVS, PRVS field, or PRVS register). Each PRVS field 470 provides control information for the security / performance mode for that particular authorization level 455[k], where [k] represents the authorization level 455. Each PRVS field 470 has one or more entries 472 that may contain control bits for each control aspect 480[j] of the processor that can be controlled or modified, where [j] represents the particular control aspect 480.In one or more embodiments, each ENFB field 460 has one or more entries 462 containing control bits for each control aspect 480[j] that provides the security / performance mode that the current authorization level 455[k] wants to implement in all authorization levels 455 below the current level (e.g., authorization level 455[k - 1], etc.). For each authorization level 455, each ENFB field 460 and each PRVS field 740 in the configuration register 250 in one embodiment has a one-bit entry 462 or 472 for each control aspect 480[0] to 480[m - 1] of the processor, and the number of aspects 480 and thus the number of ENFB entries 462 and PRVS entries 272 in each respective ENFB field 460 and PRVS field 470 are the same.A "1" in each entry 462 and 472 in each ENFB 460 and PRVS 470 for each control aspect 480 indicates that a security mode is set or configured for that aspect 480, while a "0" indicates that the performance mode is set or configured for that aspect 480. Control aspects 480[0] to 480[n - 1] in the ENFB field 460 correspond to the same aspects 480[0] to 480[n - 1] in the PRVS field 470.
[0038] The lowest authorization level 455, e.g., authorization level (n - 1), in one embodiment only has the PRVS field 470 for each control aspect 480 and in another embodiment may have neither the ENFB field 460 nor the PRVS field 470. If "n" authorization levels or authorization statuses 455 and "m" safety / performance control aspects 480 are present in a processor, then in one embodiment the configuration register contains a total of at most 2(n - 1)m + m or m(2n - 1) field entries and at least 2m(n - 1) field entries. Fig. Figure 4 shows the setup of configuration register 250 in one embodiment, where "n" authorization levels 0 to n - 1 and "m" security / performance control aspects 0 to m - 1 are present. A plurality of configuration registers could exist, which could be used and formatted in a variety of ways. For example, there could be a separate ENFB register and / or a separate PSRV configuration register for each authorization level, or alternatively, each authorization level could have one register, each register having two fields: an ENFB register bank and a PSRV register bank.
[0039] The terminology used to identify the different bit values in the ENFB field 460 and the PRVS field 470 for the control / configuration register 250 can be described as ENFB[k][j] PRVS[k][j], where [k] denotes the authorization level and [j] denotes the security / performance control aspect. A logic provides one or more access and control rules that define the behavior of the control / configuration register 250 and the processor. In one or more embodiments, control aspect bits [j] can be written for ENFB 460 and PRVS 470 at any time during processor operation, typically without requiring a system restart. For example, the control aspect bits j for both ENFB 460 and PRVS 470 can be written as soon as an application begins executing.The control aspect bits [j] for ENFB 460 and PRVS 470 can also be written at other times, for example at system restart, at periodic intervals, at predefined times or at any other time.
[0040] Although the control aspect bits [j] for ENFB 460 and PRVS 470 can be programmable under one or more aspects and configured to be written at various times (without requiring a system restart), writing the control aspect bits [j] for ENFB 460 and ENFB 470 can be performed according to one or more rules. Thus, in one or more embodiments, setting the performance / safety mode for the control aspect bits [j] in ENFB 460 and PRVS 470 is governed by one or more control rules. In one embodiment, all control aspect bits [j] for ENFB[k] 460 in an authorization level [k] are writable by the authorization level [k] and a higher authorization level, and control aspect bits [j] of PRVS[k][j] are writable for PRVS 470 in an authorization level [k] by the authorization level [k] and a higher authorization level.In one embodiment, a lower authorization level [k] cannot write the control aspect bits [j] for ENFB 460 for a higher authorization level [k - 1], and a lower authorization level [k] can write the control aspect bits [j] for PRVS 470 for a higher authorization level [k - 1].
[0041] During operation of the processor 102 or the computer system 100, the control aspect bits [j] for ENFB 460 and PRVS 470 can be read at various times, programmable times, or predefined times during processor operation in one or more embodiments, and no restart is required to read the configuration register 250. In one or more embodiments, the configuration register is read multiple times during processing, and in one embodiment, it is read when an application is started. Although the control aspect bits [j] can be read at several different times, the ability to read different authorization levels of ENFB 460 and PRVS 470 is controlled by a set of access rules in one or more embodiments.In one or more embodiments, all control aspect bits [j] of ENFB[k] 460 are readable for each authorization level 455[0] to 455[n - 1], and in an alternative embodiment, all control aspect bits of EFNB 460 are readable for all lower authorization levels. All control aspect bits [j] of PRVS 470 are readable only for the current authorization level [k] and each higher authorization level.
[0042] In one or more embodiments, the processor writes ENFB[k][j] to ENFB 460 for each authorization level [k] when it attempts to control the processor's behavior, e.g., the safety / power mode, with respect to a control aspect [j] at each lower authorization level. If a "1" or high bit is written to ENFB[k][j], the processor implements (operates in) the secure behavior mode for aspect [j] for all authorization levels lower than authorization level k (e.g., authorization levels 455[k - 1], 455[k - 2], etc.). If a "0" or low bit is written to ENFB[k][j], the processor refrains from controlling the behavior of authorization level k, e.g., the safety / power mode, of control aspect 480[j] at each authorization level lower than level [k].In one or more embodiments, the processor writes PRSV[k][j] to PRVS 470 for each privilege level k when attempting to control the behavior (safety / performance mode) of its own level, e.g., privilege level k. If a "1" or high bit is written to PRVS[k][j], the processor implements a safe mode of operation at its own privilege level, e.g., privilege level k; and if a "0" or low bit is written to PRVS[k][j], the processor implements its own performance mode for its privilege level k unless a higher privilege level [k] implements the safe mode.
[0043] The control value for the authorization level [k] and aspect [j] can be expressed as PRVS[k][j] or ENFB[k - 1][j] or ENFB[k - 2][j] or ... or ENFB[0][j]. Each authorization level higher than k can implement a value of 1 = secure mode via ENFB[k - 1][j] up to ENFB[0][j]. If the operating mode, e.g., secure mode, is not implemented by an authorization level higher than authorization level [k], the safety / performance mode can be set / selected either by authorization level k or a higher authorization level by setting the PRVS[k][j] bit for aspect [j].
[0044] Fig. Figure 5 illustrates an example of a tax register according to one embodiment, using an example of applying the tax rules to determine the secure mode or performance mode for tax aspect [j] for authorization level [k]. In the example of Fig. 5. The control of aspect [j] for authorization level [k] is determined based on the value in PRVS [k][j] (the black box 575 in PRVS 470) or ENFB[k - 1][j] (not shown) or ... or ENFB[1][j] (striped box 565 in ENRB 460) or ENB[0][j] (striped box 566 in ENRB 460). Accordingly, the control of a performance or secured mode for control aspect [j] for authorization level [k] can be represented as PRVS[k][j] or ENRB[(k - 1)[[j] to ENRB[0][j].
[0045] Fig. Figure 6 is an exemplary flowchart according to an embodiment, illustrating and describing a method executed by a computer, and more specifically, a method for dynamically controlling the operating mode of a processor, and in particular for dynamically controlling whether a processor operates in a more secure mode or in a more performance-oriented mode and executes instructions therein. Although the method 600 is described for convenience and the disclosure is not intended to limit it to a series and / or a number of steps, it is pointed out that the process 600 need not be carried out as a series of steps and / or that the steps need not be in the manner described with respect to Fig. The steps must be carried out in the sequence shown and described in 6, but the process can be integrated and / or one or more steps can be carried out together or simultaneously, or the steps can be carried out in the disclosed sequence or in an alternative sequence.
[0046] In one or more embodiments, when an application is invoked, typically all bits in all entries of both the ENFB and SRVS registers everywhere start in a performance mode. For example, the bits in the ENFB and SRVS fields / registers for each control aspect (control aspect 480[0] to 480[m]) in each authorization level (authorization level 450[0] to 450[n]) are set to "0". At some point, a secure mode or secure configuration for an authorization level [k] or a control aspect [j] in an authorization level [k] is justified, desired, required, or necessary during operations in the processor, for example, during application execution. Fig. Figure 6 illustrates an embodiment of a method 600 for switching, preferably dynamically without an application or system restart, the performance configuration of an authorization level [k] in a processor to a safe mode, and in a further embodiment, the performance configuration of a control aspect [j] in an authorization level [k] in a processor to a safe mode. It should be noted that the method 600 for switching to a safe mode can be performed entirely on the basis of an authorization level, e.g., authorization level by authorization level, or more granularly on the basis of a single control aspect in an authorization level, e.g., control aspect by control aspect within a certain authorization level.The following describes procedure 600 for switching from a performance mode to a secure mode based on a tax aspect within an authorization level. It should be noted that the process can also be performed based on an authorization level.
[0047] At 605, an authorization level [k] initiates a change to its safe operating mode. At 610, it is determined whether a safe mode for control aspect [j] should be implemented for this authorization level [k]. If control aspect [j] should be implemented in authorization level [k] (610: Yes), the process continues with 615, checking whether the bit field for control aspect [j] in authorization [k] is set to "1". In other words, whether PRVS[k][j] is 1. If control aspect [j] in authorization level [k] is not set to "1" (615: No; PRVS[k][j] = 0), the control aspect entry [j] in authorization level [k] is set (written) to "1" in the PRVS register at 620, e.g., setting PRVS[k][j] = 1, and the process continues with 625. If the tax aspect [j] in authorization level [k] is set to “1” (615: Yes; PRVS[k][j] = 1), the process skips 620 and proceeds to 625.
[0048] Process 625 determines whether a secure mode for tax aspect [j] should be implemented for all authorization levels lower than authorization level [k]. Specifically, it determines whether a secure mode for tax aspect [j] should be implemented for all lower authorization levels [k + 1] to [n], where "n" is the lowest authorization level. If a secure mode for tax aspect [j] should not be implemented for all lower authorization levels (625: No), process 600 is executed as illustrated in 630. However, if it is determined that a secure mode for tax aspect [j] should be implemented at lower authorization levels (625: Yes), the process continues with 635, which determines whether the tax aspect [j] is "1" at authorization level [k] of the ENFB register.In other words, if 625 is Yes and a secure mode for lower authorization levels needs to be implemented, process 635 determines whether ENFB[k][j] is set to "1" or equals "1". If the control aspect [j] for lower authorization levels is set to "1" in the ENFB register field (635: Yes), i.e., ENFB[k][j] = 1), process 600 is executed as illustrated in 640. If it is determined that the control aspect [j] is not set to "1" in the lower authorization level (635: No), e.g., ENFB[k][j] = 0), process 600 continues with 645.
[0049] At 645, the policy regarding control of the security / performance mode for authorization level [k] for control aspect [j] is looked up at authorization levels lower than authorization level [k]. At 650, it is determined whether the policy for control aspect [j] at authorization level [k] allows the implementation of the secure configuration for aspect [j] at lower authorization levels. If at 650 it is determined that the policy does not allow the implementation of the secure configuration at lower authorization levels, e.g., authorization levels lower than authorization level [k], for control aspect [j] (650: No), the process is executed as illustrated in 655. If the policy allows the implementation of the secure mode or secure configuration at lower authorization levels for control aspect [j] (650: Yes), the process continues at 660, where control aspect [j] at authorization [k] is set to "1" in the EFNB register.In other words, at 660 ENFB[k][j] is set to "1", ENFB[k][j] = 1. The process to change the tax aspect [j] to authorization level [k] is then completed, as illustrated in 665.
[0050] At a certain point, a performance mode (a performance configuration) in the processor for a privilege level [k] or a control aspect [j] at a privilege level [k], e.g., during the execution of a software application, is justified, desired, required, or necessary. For example, a processor for one or more privilege levels [k] and / or one or more control aspects [j] at a privilege level [k] might operate in a safe mode and execute a software application, and the software application might require and / or trigger the processor to operate in a performance mode because the environment might justify a safe operating mode and it might be convenient or advantageous to operate in a safe mode. Fig.Figure 7 illustrates an embodiment of a method 700 for performing a process to switch, preferably dynamically without an application or system restart, from a secure mode in a process at authorization level [k] to a performance mode, and in a further embodiment, a process to switch from a secure operating mode in a processor for a control aspect [j] at authorization level [k] to a performance mode. It should be noted that the method 700 for switching to a performance mode can be performed entirely on the basis of an authorization level, e.g., authorization level by authorization level, or more granularly on the basis of a single control aspect within an authorization level, e.g., control aspect by control aspect within a certain authorization level.The following describes Method 700, which attempts to switch from a safe mode to a performance mode based on a control aspect within a permission level. In one or more embodiments, the processor cannot switch to a safe mode if a higher permission level implements a safe operating mode for the control aspect in the lower permission levels.
[0051] At process 705, authorization level [k] wants to switch to a performance operating mode for aspect [j]. At process 710, it is determined whether the PRVS register field for tax aspect [j] at authorization level [k] is set to "0" in the PRVS register. In other words, whether PRVS[k][j] is 0. If tax aspect [j] at authorization level [k] is set to "0" (710: Yes; PRVS[k][j] = 0), then process 700 continues with process 720. If at process 710 the tax aspect entry [j] at authorization level [k] in the PRVS register is not set (written) to "0" (710: No), e.g., PRVS[k][j] = 1), then process 700 continues with process 715. If the control aspect [j] in authorization level [k] is set to "1" (710: No; PRVS[k][j] not 0), then process 700 continues with 715, where the bit in the PRVS register field for control aspect [j] in authorization level [k] is set (written) to "1". After 715, process 700 continues with 720.
[0052] At 720, it is determined whether the ENFB register field for tax aspect [j] is set to "0" in all authorization levels higher than authorization level [k], i.e., all authorization levels [k - 1] down to authorization level 0. If it is determined that the ENFB register field for tax aspect [j] is set to zero in every authorization level higher than authorization level [k] (720: Yes; ENFB[p][j] = 0, where p = authorization levels (k - 1) down to 0), a performance mode for tax aspect [j] can be initiated (activated) at authorization level [k].If the ENFB register field for tax aspect [j] is not set to "0" for all authorization levels higher than authorization level [k] (720: No; ENFB[p][j] = 1, where p = authorization levels (k - 1) to 0), the process proceeds to 730, where a system call requests to allow, or checks, a performance mode for tax aspect [j] for each higher authorization level p (where p = authorization levels [k - 1] to authorization level 0). In this context, the process executes 700, 720, 730, 735, 740, 745, and 750, authorization level by authorization level, for each authorization level higher than authorization level [k].
[0053] More specifically, a system call at 730 for authorization level [k - 1], the authorization level directly above authorization level [k], requests that a performance mode for control aspect [j] be allowed for authorization level [k - 1], or checks whether this is permissible. Process 700 continues with 735, where a policy for authorization level [k - 1] is looked up to determine whether the secure or performance mode for control aspect [j] is controlled at lower authorization levels. At 740, it is determined whether the policy for authorization level [k - 1] allows the performance mode for control aspect [j] for lower authorization levels. If, at 740, the policy for authorization level [k - 1] does not allow the performance mode for tax aspect [j] to be used for lower authorization levels (740: No), then a performance mode at 745 for tax aspect [j] in authorization level [k] is not permitted.The processor remains in a safe operating mode for aspect [j] in authorization level [k].
[0054] If at 740 it is determined that the policy for authorization level [k - 1] for tax aspect [j] allows the activation of the performance mode for lower authorization levels (740: Yes), e.g. for authorization level [k], ENFB[k -1][j] at 750 is set to “0”. After 750, the process returns to 720, determining whether the ENFB register field for tax aspect [j] is set to “0” for the next higher authorization level [k - 2], and if the ENFB field register for tax aspect [j] is not set to zero (“0”) in authorization level [k - 2], process 700 repeats steps 730, 735, 740, 745 and 750 for authorization level [k - 2], returning to step 720 for the next higher authorization level, until process steps 730 to 750 have been performed for all authorization levels [k - 1] down to authorization level 0 (the highest authorization level).After checking the highest authorization level (authorization level 0), the ENFB register field for tax aspect [j] in authorization level 0 is set to "0" at 750 (ENFB[0][j] = 0) and the process returns to 720, where in step 720 it is determined that ENFB[k][j] = 0, and the process continues to 725, where the performance mode for aspect [j] in authorization [k] has been enabled.
[0055] Although the system and procedure have been described with respect to a configuration and operation where the safe mode is set with a high bit, e.g., a "1", it should be noted that a performance mode can be set with a HIGH bit (bit = 1) and that a safe mode can be set with a LOW bit (bit = 0). It should also be noted that the processor or the invocation of a software application can initiate a safe mode by changing the values in the ENFB register field and the PRVS register field.
[0056] The present invention may be a system, a method, and / or a computer program product. The computer program product may comprise a computer-readable storage medium (or media) containing computer-readable program instructions to induce a processor to execute aspects of the present invention.
[0057] A computer-readable storage medium can be a physical unit capable of retaining and storing instructions for use by a system to execute instructions. For example, a computer-readable storage medium can be an electronic storage unit, a magnetic storage unit, an optical storage unit, an electromagnetic storage unit, a semiconductor storage unit, or any suitable combination of the foregoing, but not limited to these. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: a removable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), and erasable programmable read-only memory (EPROM).Flash memory), static random-access memory (SRAM), removable compact storage disk read-only memory (CD-ROM), DVD (Digital Versatile Disc), USB flash drive, floppy disk, a mechanically coded unit such as punched cards or raised structures in a groove on which instructions are stored, and any suitable combination of the foregoing. For the purposes of this usage, a computer-readable storage medium shall not be understood as volatile signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses traveling through an optical fiber cable), or electrical signals transmitted by a wire.
[0058] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to individual data processing units or, via a network such as the internet, a local area network, a wide area network, and / or a wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission lines, wireless transmission, routers, firewalls, switching units, gateway computers, and / or edge servers. A network adapter card or network interface in each data processing unit receives computer-readable program instructions from the network and forwards them for storage on a computer-readable storage medium within the respective data processing unit.
[0059] Computer-readable program instructions for executing the steps of the present invention can be assembly instructions, ISA (Instruction Set Architecture) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state data, or either source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., as well as conventional procedural programming languages such as C or similar languages. The computer-readable program instructions can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server.In the latter case, the remotely located computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be established with an external computer (for example, via the internet using an internet service provider). In some embodiments, electronic circuits, including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), can execute computer-readable program instructions by using state information from the computer-readable program instructions to personalize the electronic circuits to perform aspects of the present invention.
[0060] Aspects of the present invention are described herein with reference to flowcharts and / or block diagrams or charts of methods, devices (systems), and computer program products according to embodiments of the invention. It is pointed out that each block of the flowcharts and / or block diagrams or charts, as well as combinations of blocks in the flowcharts and / or block diagrams or charts, can be executed by means of computer-readable program instructions.
[0061] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a specialized computer, or another programmable data processing device to create a machine, such that the instructions executed via the processor of the computer or other programmable data processing device generate a means of implementing the functions / steps specified in the block(s) of the flowcharts and / or block diagrams or charts.These computer-readable program instructions may also be stored on a computer-readable storage medium capable of controlling a computer, programmable data processing device and / or other units to function in a determined manner, such that the computer-readable storage medium on which instructions are stored has a manufactured product, including instructions that implement aspects of the function / step specified in the block(s) of the flowchart and / or block diagrams or charts.
[0062] The computer-readable program instructions can also be loaded onto a computer, other programmable data processing device, or other unit to cause the execution of a series of process steps on the computer or other programmable device or other unit in order to generate a process executed on a computer, such that the instructions executed on the computer, other programmable device, or other unit implement the functions / steps specified in the block(s) of the flowcharts and / or block diagrams or charts.
[0063] The flowcharts and block diagrams or charts in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, processes, and computer program products according to various embodiments of the present invention. In this context, each block in the flowcharts or block diagrams or charts can represent a module, segment, or part of instructions that includes one or more executable instructions for performing the specified logical function(s). In some alternative embodiments, the functions specified in the block can occur in a different order than shown in the figures. For example, two blocks shown consecutively can be executed essentially simultaneously, or the blocks can sometimes be executed in reverse order depending on the corresponding functionality.It should also be noted that each block of the block diagrams or charts and / or flowcharts, as well as combinations of blocks in the block diagrams or charts and / or flowcharts, can be implemented by special hardware-based systems that perform the specified functions or steps, or execute combinations of special hardware and computer instructions.
[0064] Furthermore, according to various embodiments, a system may include a processor and logic that is integrated into and / or executable by the processor, the logic being configured to perform one or more of the process steps mentioned herein. "Integrated into" means logic embedded in the processor as hardware logic, such as an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), etc. "Executable by the processor" means logic that is hardware logic; software logic, such as firmware, part of an operating system, part of an application program; etc.; or a combination of hardware and software logic that is accessible to and configured by the processor to cause the processor to execute a function when executed by the processor.Software logic can be stored on local and / or remote memory of any type known in the field. Any processor known in the field can be used, such as a software processor module and / or a hardware processor such as an ASIC, an FPGA, a central processing unit (CPU), an integrated circuit (IC), a graphics processing unit (GPU), etc.
Claims
[1] Method for changing an operating mode in a processor (102, 125) without restarting the processor, which has authorization status registers, PRVS registers, (470) for respective authorization levels (455), wherein each PRVS register has entries containing a bit for each control aspect (480) of the processor for the corresponding authorization level, in order to specify either a performance mode or a secure mode for each control aspect, the method comprising: Initiating (605) a change of configuration in the processor from a performance mode to a safe mode for a control aspect (480) in an authorization level (455); Determine (615) whether the bit for the control aspect in the authorization level in a PRVS register (470) is set to a secure mode; If the control aspect bit in the authorization level in the PRVS register has not been set to a safe mode, setting (620) the control aspect bit in the authorization level in the PRVS register to a safe mode, thereby enabling safe mode in the processor for the control aspect in the authorization level; Determine (625) whether a secure mode for the tax aspect can be implemented at lower authorization levels; and If it is determined that a safe mode for the tax aspect cannot be implemented at lower authorization levels, the procedure for switching to safe mode for the tax aspect at the authorization level is completed (630). [2] Method according to claim 1, wherein the processor has a sub-translate register, ENFB register, (460) for each of the authorization levels (455) except the lowest authorization level, wherein each ENFB register has entries containing a bit for each control aspect (480) of the processor for all lower authorization levels to specify either the performance mode or the secure mode for each control aspect, further comprising: If it is determined that a secure mode for the control aspect is to be implemented in the lower authorization levels, determine (635) whether the bit for the control aspect in the lower authorization levels in an ENFB register (460) is set to a secure mode; and If it is determined that the bit for the control aspect in the lower authorization levels in the ENFB register is set to a safe mode, the process to switch to safe mode for the control aspect in the authorization level is completed (640). [3] The method of claim 2, further comprising: If it is determined that the bit for the tax aspect in the lower privilege levels in the ENFB register is not set to a safe mode, determine (650) whether a policy for the tax aspect in the privilege level allows a change to safe mode for the tax aspect in the lower privilege levels; and If the policy for the tax aspect at the authorization level does not permit the implementation of the safe mode for the tax aspect at the lower authorization levels, the procedure for switching to a safe mode for the tax aspect at the authorization level is completed (655). [4] Method according to claim 3, wherein determining whether a guideline for the tax aspect at the authorization level allows the implementation of the secure mode for the tax aspect at lower authorization levels comprises looking up (645) the guideline for the tax aspect at the authorization level with regard to the implementation of the secure mode for the tax aspect at the lower authorization levels. [5] The method of claim 3, further comprising: If the policy for the tax aspect at the authorization level allows the implementation of the safe mode of the tax aspect at the lower authorization levels, set (660) the bit in the ENFB register for the tax aspect at the authorization level to a safe mode. [6] Method according to claim 2, wherein the bits in the ENFB register and the bits in the PRVS register for the control aspect in the authorization level are initially set to the performance mode during an application call. [7] Method according to claim 2, wherein the ENFB register and the PRVS register are arranged in the processor in a decoding unit (20), the decoding unit decoding the instructions for execution by the processor. [8] Method according to claim 2, wherein the bits in the ENFB register and the PRVS register are set to 1 for a safe mode and are set to 0 for a power mode. [9] Method according to claim 1, wherein the secure mode or performance mode of the processor for the control aspect in the authorization level is controlled by a software application. [10] The method of claim 2, further comprising: In response to a trigger (705) to switch from a safe mode to a performance mode for the control aspect in the authorization level, check (710) whether the bit in the PRVS register for the control aspect in the authorization level is set to performance mode; In response to the fact that the bit in the PRVS register for the control aspect in the authorization level is not set to performance mode, set (715) the bit in the PRVS register for the control aspect in the authorization level to performance mode; Check (720) whether the tax aspect in the authorization level of the ENFB register is set to a performance mode for all higher authorization levels; and In response to the fact that the control aspect in the authorization level of the ENFB register is set to performance mode for all higher authorization levels, switching (725) the processor to performance mode for the control aspect in the authorization level. [11] The method of claim 10, further comprising: in response to the fact that the tax aspect in the authorization level of the ENFB register is not fixed to the performance mode for all higher authorization levels, Request (730) that the higher authorization levels allow the performance mode for the tax aspect in the authorization level; In response to the fact that the higher authorization levels do not allow performance mode for the control aspect at the authorization level, the processor does not enter performance mode for the control aspect at the authorization level (745). [12] Method according to claim 11, wherein the requirement that the higher authorization levels permit the performance mode for the tax aspect in the authorization level further comprises: Referring to (735) a guideline for the higher entitlement levels regarding the performance mode for the tax aspect in lower entitlement levels; Check (740) whether the directive permits the performance mode for the tax aspect at the entitlement level; and In response to the policy allowing performance mode for the control aspect at the authorization level, the bit in the ENFB register for the control aspect at the authorization level is set to performance mode (750), thereby allowing the processor to enter performance mode for the control aspect at the authorization level. [13] The method of claim 12, wherein the lookup of a policy for the higher authorization levels regarding the performance mode for the control aspect in lower authorization levels and the checking whether the policy allows the performance mode for the control aspect in the authorization level is performed on a level-by-level basis; and for each higher authorization level in which the policy allows the performance mode for the control aspect in that authorization level, the bit in the ENFB register for the control aspect in that authorization level is set to the performance mode; and the processor then checks whether the bit in the ENFB register for the control aspect is set to the performance mode for all higher authorization levels. [14] Method for changing the operating mode of a processor (102, 125) without restarting the processor, which has authorization status registers, PRVS registers, (470) for each authorization level (455), wherein each PRVS register has entries containing a bit for each control aspect (480) of the processor for the corresponding authorization level to specify either a performance mode or a secure mode for each control aspect, wherein the processor has a downgrade register, ENFB register, (460) for each of the authorization levels (455) except the lowest authorization level, wherein each ENFB register has entries containing a bit for each control aspect (480) of the processor for all lower authorization levels to specify either the performance mode or the secure mode for each control aspect, the method comprising: In response to a trigger (705) to switch from a secure operating mode to a performance operating mode for a control aspect (480) in an authorization level (455), check if a bit in a PRVS register (470) for the control aspect in the authorization level is set to performance mode; In response to the fact that the bit in the PRVS register for the control aspect in the authorization level is not set to performance mode, set (715) the bit in the PRVS register for the control aspect in the authorization level to performance mode; Check (720) whether the tax aspect in the authorization level of an ENFB register (460) is set to a performance mode for all higher authorization levels; and In response to the fact that the control aspect in the authorization level of the ENFB register is set to performance mode for all higher authorization levels, switching (725) the processor to performance mode for the control aspect in the authorization level. [15] The method of claim 14, further comprising: in response to the fact that the tax aspect in the authorization level of the ENFB register is not fixed to the performance mode for all higher authorization levels, Request (730) that the higher authorization levels allow the performance mode for the tax aspect in the authorization level; In response to the fact that the higher authorization levels do not allow performance mode for the control aspect at the authorization level, the processor does not enter performance mode for the control aspect at the authorization level (745). [16] Method according to claim 15, wherein the requirement that the higher authorization levels permit the performance mode for the tax aspect in the authorization level further comprises: Referring to (735) a guideline for the higher entitlement levels regarding the performance mode for the tax aspect in lower entitlement levels; Check (740) whether the directive permits the performance mode for the tax aspect at the entitlement level; and In response to the policy allowing performance mode for the control aspect at the authorization level, the bit in the ENFB register for the control aspect at the authorization level is set to performance mode (750), thereby allowing the processor to enter performance mode for the control aspect at the authorization level. [17] The method of claim 16, wherein the lookup of a policy for the higher authorization levels regarding the performance mode for the control aspect in lower authorization levels and the checking whether the policy allows the performance mode for the control aspect in the authorization level is performed on a level-by-level basis; and for each higher authorization level in which the policy allows the performance mode for the control aspect in that authorization level, the bit in the ENFB register for the control aspect in that authorization level is set to the performance mode; and the processor then checks whether the bit in the ENFB register for the control aspect is set to the performance mode for all higher authorization levels. [18] The method of claim 14, further comprising: Initiating (605) a change of configuration in the processor from a performance mode to a safe mode for a control aspect at a permission level; Determine (615) whether the bit for the control aspect in the authorization level in the PRVS register field is set to a secure mode; If the control aspect bit in the authorization level in the PRVS register has not been set to a safe mode, setting (620) the control aspect bit in the authorization level in the PRVS register to a safe mode, thereby enabling safe mode in the processor for the control aspect in the authorization level; Determine (625) whether a secure mode for the tax aspect can be implemented at lower authorization levels; If it is determined that a secure mode for the control aspect is to be implemented in the lower authorization levels, determine (635) whether the bit for the control aspect in the lower authorization level in an ENFB register is set to a secure mode; and If it is determined that the bit for the control aspect in the lower authorization levels in the ENFB register is set to a safe mode, the process to switch to safe mode for the control aspect in the authorization level is completed (640). [19] Computer system for processing information, wherein the computer system comprises: at least one processor with one or more register banks, where at least one of the registers is a configuration register, wherein the configuration register includes an authorization status register, PRVS register, (470) for each of authorization levels (455), each PRVS register containing entries that include a bit for each control aspect (480) of the processor for the corresponding authorization level to specify either a performance mode or a secure mode for each control aspect; and a sub-translate register, ENFB register, (460) for each of the authorization levels except the lowest authorization level, each ENFB register containing entries that include a bit for each control aspect (480) of the processor for all lower authorization levels to specify either the performance mode or the secure mode for each control aspect, the PRVS register control aspects being numerically equal to and corresponding with the ENFB register control aspects (480). the processor is configured and designed to: initiates a change in a processor's configuration from a performance mode to a safe mode for a control aspect at a permission level; determines whether the bit for the control aspect in the authorization level in the PRVS register is set to a secure mode; and If the bit for the control aspect in the authorization level in the PRVS register has not been set to a safe mode, set the bit for the control aspect in the authorization level in the PRVS register to a safe mode, thereby enabling safe mode in the processor for the control aspect in the authorization level. [20] Computer system according to claim 19, wherein the processor is further configured and designed such that it: determines whether a secure mode for the tax aspect can be implemented at lower authorization levels; If it is determined that a secure mode for the tax aspect cannot be implemented at lower authorization levels, the procedure for switching to the secure mode for the tax aspect at that authorization level is completed; If it is determined that a secure mode for the control aspect needs to be implemented in the lower authorization levels, it determines whether the bit for the control aspect in the lower authorization level in an ENFB register field is set to a secure mode; and If it is determined that the bit for the control aspect in the lower authorization levels in the ENFB register is set to a safe mode, the process to switch to safe mode for the control aspect in the authorization level is completed. [21] Computer system according to claim 20, wherein the processor is further configured such that it: If it is determined that the bit for the control aspect in the lower authorization levels in the ENFB register is not set to a secure mode, determine whether a policy for the control aspect in the authorization level allows a change to secure mode for the control aspect in the lower authorization levels; If the policy for the tax aspect at the authorization level does not allow the implementation of the safe mode of the tax aspect at the lower authorization levels, the procedure for switching to a safe mode for the tax aspect at the authorization level is executed; Determining whether a policy for the tax aspect at the authorization level allows the implementation of the safe mode for the tax aspect at lower authorization levels includes looking up the policy for the tax aspect at the authorization level with regard to the implementation of the safe mode for the tax aspect at lower authorization levels. [22] Computer system according to claim 21, wherein the processor is further configured such that it: If the policy for the tax aspect at the authorization level allows the implementation of the safe mode of the tax aspect at the lower authorization levels, the bit in the ENFB register for the tax aspect at the authorization level is set to a safe mode. [23] Computer system according to claim 22, wherein the processor is further configured such that it: In response to a trigger to switch from a safe mode to a performance mode, the control aspect in the authorization level checks whether the bit in the PRVS register for the control aspect in the authorization level is set to performance mode; in response to the fact that the bit in the PRVS register field for the control aspect in the authorization level is not set to performance mode, sets the bit in the service register field for the control aspect in the authorization level to performance mode; checks whether the tax aspect in the authorization level of the ENFB register is set to a performance mode for all higher authorization levels; and In response to the fact that the tax aspect in the authorization level of the ENFB register is set to performance mode for all higher authorization levels, the processor switches to performance mode for the tax aspect in the authorization level. [24] Computer system according to claim 23, wherein the processor is further configured such that it: in response to the fact that the tax aspect in the authorization level of the ENFB register is not fixed to the performance mode for all higher authorization levels, requires that the higher authorization levels allow the performance mode for the tax aspect in the authorization level; In response to the fact that higher authorization levels do not allow performance mode for the control aspect at the authorization level, the processor does not switch to performance mode for the control aspect at the authorization level. the requirement that the higher authorization levels allow the performance mode for the tax aspect in the authorization level further includes: Refer to a guideline for the higher entitlement levels regarding the performance mode for the tax aspect in lower entitlement levels; Check whether the directive permits the performance mode for the tax aspect at the entitlement level; and In response to the policy allowing performance mode for the control aspect at the authorization level, the bit in the ENFB register for the control aspect at the authorization level is set to performance mode, thereby allowing the processor to enter performance mode for the control aspect at the authorization level.
Citation Information
Patent Citations
Debugging of a data processing apparatus
EP2619670B1
Method and apparatus for controlling system access during protected modes of operation
US20090204823A1