System-on-chip comprising resource isolation and countermeasure means, and corresponding method.
By integrating protection circuits within SoC slave resources to directly generate alert signals for illegal access, the system addresses the limitations of software-dependent alert generation, enhancing reliability and responsiveness in managing SoC anomalies.
Patent Information
- Application Number
- FR2023002838
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-24
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2043-03-24
Smart Images

Figure 00000015_0000 
Figure 00000015_0001 
Figure 00000016_0000
Abstract
Description
Title of the invention: System on chip comprising resource isolation and countermeasure means, and corresponding method.
[0001] Implementations and embodiments of the invention relate to integrated circuits, in particular systems on chip (System on Chip), for example a microcontroller or a microprocessor, and more particularly to techniques for isolating resources belonging to the system on chip.
[0002] To help ensure the reliability of a system-on-chip, resource isolation techniques are used to restrict access by one or more master devices to specific slave resources. "Illegal" access occurs when a transaction issued by a master device to a slave resource does not comply with established access restrictions.
[0003] For example, publication FR 3103586 Al (28 / 05 / 2021) describes a technique for managing these access restrictions that is simple to implement and implement, in particular when this management is dynamic, i.e. it depends on different applications of the system on chip.
[0004] In conventional resource isolation techniques, typically only a "trusted domain" implemented in software, in particular for the management of restrictions and access rights, is informed of illegal access to a resource, by an illegal access management mechanism.
[0005] Furthermore, countermeasure means may conventionally be provided to limit the operation of the system-on-chip against potential anomalies, for example by restricting access to all or some of the resources only to a secure trusted environment. The anomalies may correspond to a violation of the resource isolation rules, which may be caused by an attack aimed at recovering sensitive or secret data, and in the context of reverse engineering.
[0006] However, it is the responsibility of the trusted domain to generate an alert signal controlling the functionality of the countermeasure means if illegal access is identified as an anomaly or as a potential attack.
[0007] During the decision software processing implemented to generate the alert signal, secrets are not blocked for several clock cycles. Furthermore, an accumulation of interruptions of the trusted domain, caused by multiple illegal accesses, could create a denial of services at the trusted domain level, and delay said software processing.
[0008] Thus, there is a need to improve the protection mechanisms against illegal access, particularly from the point of view of the implementation of countermeasure actions and means.
[0009] In this regard, embodiments and implementations provide for directly generating the alert signal controlling the countermeasure means, from the resource which has received illegal access, without going through the decision software processing.
[0010] Further, embodiments and implementations provide for being able to select the behavior for each resource to decide whether illegal access should be silent or cause the generation of the alert signal.
[0011] According to one aspect, a system on a chip is thus proposed comprising at least one slave resource, a resource isolation system, and a countermeasure means capable of and intended to limit the operation of the system against potential anomalies, and, for said at least one slave resource, a protection circuit configured to block or transmit transactions addressed to the resource as a function of access rights of the resource and of the transaction, the protection circuit being configured to generate and directly communicate an alert signal by means of a countermeasure in the event of a transaction being blocked.
[0012] The system on chip may typically comprise at least one master device capable of generating the transactions addressed to the resource, for example via an interconnection bus.
[0013] It will be noted in particular that it is the protection circuit associated with its respective resource (and which is also sometimes called a "firewall") which is at the origin of the generation of the alert signal. The command of the action taken by the countermeasure means is thus directly communicated, which improves the responsiveness and reliability of the countermeasure mechanism.
[0014] According to one embodiment, the system on chip comprises an alert channel directly connecting the protection circuit with the countermeasure means and dedicated to the transmission of said alert signal.
[0015] In other words, the alert signal can be communicated directly and without intermediary via the alert channel, and not being subject to software implementation, reliability is thus improved.
[0016] According to one embodiment, the system on chip comprises a plurality of said at least one resource, and a multiplexer element configured to group all the alert channels connected to said respective protection circuits, on a single outgoing alert channel and directly connected to the countermeasure means.
[0017] For example, the multiplexer element has a function of transmitting alert signals, regardless of their origin, of the “OR gate” type.
[0018] According to one embodiment, the resource isolation system comprises, in a set of configuration registers, for each resource a location for containing alert configuration data, the protection circuit of each resource being configured to generate or not generate said alert signal in the event of blocking of a transaction addressed to the resource, depending on the alert configuration data for this resource.
[0019] Thus, the control of the action taken by the countermeasure means can be activated or deactivated depending on each resource. Indeed, a resource can be considered critical or not, depending on the use made of the system on chip. Thus it may or may not be desirable to activate the alert signal in the event of a transaction being blocked for a given resource.
[0020] According to one embodiment, the system on chip further comprises at least one master device capable of generating said transactions addressed to the resource, the transactions comprising a piece of data identifying the master, and the resource isolation system comprises, in a set of configuration registers, for each master device, a location for containing a second piece of data for configuring the alerts, the protection circuit of each resource being configured to generate or not generate said alert signal in the event of blocking of a transaction addressed to the resource by the master device, depending on the second piece of data for configuring the alerts for this master device.
[0021] Thus, the control of the action taken by the countermeasure means can be activated or deactivated depending on each master device. Indeed, it can be considered that a trusted environment, for example the implementation of firmware of a “trusted” master device, cannot generate illegal access. Detection of illegal access from such an environment can therefore systematically be treated as an attack by the countermeasure means.
[0022] According to another aspect, there is also provided a method of managing the isolation of resources of a system on chip, in which: - the system-on-chip comprises at least one slave resource, a resource isolation system, and a countermeasure means suitable and intended to limit the operation of the system against potential anomalies; and - the method comprises, for each resource, an implementation of a protection comprising a blocking or a transmission of transactions addressed to the resource, depending on access rights of the resource and of the transaction, and a generation of an alert signal directly communicated by means of a countermeasure in the event of a transaction being blocked.
[0023] According to one embodiment, the alert signal is transmitted on a dedicated alert channel, directly connecting the protection circuit with the countermeasure means.
[0024] According to one embodiment, the system on chip comprises a plurality of said at least one resource, and all the alert channels connected to said respective protection circuits are grouped on a single outgoing alert channel and directly connected to the countermeasure means.
[0025] According to one embodiment, an alert configuration data item, for each resource, is contained in a set of configuration registers, and said alert signal is generated or not in the event of blocking of a transaction addressed to a resource, depending on the alert configuration data item for this resource.
[0026] According to an embodiment, in which the system on chip further comprises at least one master device generating said transactions addressed to the resource comprising a master identification data item, a second alert configuration data item, for each master device, is contained in a set of configuration registers, and said alert signal is generated or not in the event of blocking of a transaction addressed to a resource by the master device, depending on the second alert configuration data item for this master device.
[0027] Other advantages and characteristics of the invention will appear on examining the detailed description of embodiments and implementations, which are in no way limiting, and the appended drawings, in which the figures:
[0028] [Fig. 1] and
[0029] [Fig.2] and
[0030] [Fig.3] and
[0031] [Fig.4] illustrate embodiments and implementations of the invention.
[0032] [Fig.l] schematically illustrates an exemplary embodiment of a system on chip SOC, such as for example a microcontroller or a microprocessor, comprising at least one master device MSTR, and at least one slave resource RES capable of communicating via an interconnection bus BUS.
[0033] The master devices TDMSTR, MSTR may for example be processors or central processing units “CPU” (for “Central Processing Unit” in English), adapted to implement software functionalities; or other master devices such as direct memory access means “DMA” (for “Direct Memory Access” in English).
[0034] In this example, the system on chip SOC further comprises a master device TDMSTR qualified as “trusted”, typically in charge of the configuration and management of access rights defining the isolation rules, implemented by a RIF resource isolation system described in more detail below.
[0035] The resources may for example comprise a peripheral of the I2C type (for “Inter Integrated Circuit” in English), of the SPI type (for “Serial Peripheral Interface” in English), of the UART type (for “Universal Asynchronous Receiver Transmitter” in English), of the real-time clock type “RTC” (for “Real Time Clock” in English), or of the memory type such as an internal memory to the system on chip or an interface for memory external to the system on chip.
[0036] The interconnection bus BUS is coupled between the master devices and the slave resources and makes it possible to route transactions, for example write or read transactions, and more generally information, on channels which may have dedicated functionalities, between the master devices MSTR and the slave resources RES.
[0037] The interconnection bus may for example be a bus of the “AXI” type for “Advanced extensible Interface” in English, or of the “AHB” type for “Advanced High-performance Bus” in English, which are types of “AMBA” microcontroller bus for “Advanced Microcontroller Bus Architecture”.
[0038] In a particular case, the interconnection bus BUS may comprise an error notification channel RREP, for example provided to communicate response information to a transaction by the slave resources.
[0039] The system on chip SOC further comprises a RIF resource isolation system configured to restrict access of one or more master devices to specific slave resources, in particular based on access rights defined in this regard.
[0040] For example, among the access rights that can define the resource isolation rules, it is possible to provide for defining privileged and non-privileged environments, and possibly cumulatively secure and non-secure environments, as well as possibly in addition a compartmentalization identifier.
[0041] The concepts of secure / non-secure and privileged / non-privileged environments and access rights are well known to those skilled in the art, and the concept of compartmentalization identifier is notably taught in publication FR 3103586 Al (05 / 28 / 2021).
[0042] We speak of “illegal” access when the access rights of a transaction do not comply with those of the recipient resource.
[0043] For example, the RIF resource isolation system of the system on chip may be part of the resource isolation technique described in publication FR 3103586 Al (05 / 28 / 2021).
[0044] The RIF resource isolation system comprises in particular for each RES resource, a RISUP protection circuit (sometimes called a “firewall”), configured to block or transmit transactions addressed to the RES resource by the bus. BUS interconnection, depending on the said access rights of the resource and the transaction.
[0045] Furthermore, the system on chip SOC comprises a TAMP countermeasure means capable of and intended to limit the operation of the system on chip SOC against potential anomalies.
[0046] Anomalies may correspond to a violation of resource isolation rules, which may be caused by an attack aimed at recovering sensitive or secret data, for example in the context of reverse engineering or hacking.
[0047] For example, such a TAMP countermeasure means can be implemented in the form of a hardware circuit which can in one clock cycle disconnect the critical resources (and which benefit from the protection) from the rest of the system, permanently or temporarily.
[0048] For example, the TAMP countermeasure means may be capable of "freezing" the resource in the system, i.e. restricting all (or some) access to the protected resources only to a secure trusted environment, i.e. for example only to the trusted master device TDMSTR, or even strictly preventing all access to said resources. The TAMP countermeasure means may also erase the contents of certain sensitive registers, and is capable in this regard of resetting the registers.
[0049] The practical applications vary depending on the resource to be protected, and may, for example, include generation of a “reset” type signal; or isolation of the resource by disconnecting it from the interconnection bus.
[0050] On the other hand, for example depending on a decision taken by the trusted master device TDMSTR, the countermeasure means TAMP can be configured to possibly release the restriction, or carry out other actions to prevent the anomaly from persisting, for example a deactivation of an identified functionality, a complete restart of the system on chip, an erasure of data in memories, or even a destruction of the system on chip SOC.
[0051] Furthermore, according to a general characteristic of the present description, the RISUP protection circuit is configured to generate and directly communicate a TAMP_SGNL alert signal by means of TAMP countermeasure in the event of a transaction being blocked. The TAMP_SGNL alert signal may for example be adapted to command an action of the TAMP countermeasure means, for example as presented above to freeze the system on chip SOC or to prevent the anomaly from persisting.
[0052] In this regard, reference is made to [Fig.2].
[0053] [Fig.2] illustrates the method 200 implemented by the RISUP protection circuit, in the management of the RIF resource isolation of the SOC system on chip described in relation to [Fig. 1].
[0054] Thus, the implementation of the protection 200 of each resource comprises, upon reception 210 of a transaction from the interconnection bus BUS, a verification 220 of the access rights of this transaction with respect to the access rights of the resource.
[0055] Depending on the verification 220, the transaction 210 can be transmitted 230 to the downstream RES resource, or blocked 240 by the upstream RISUP protection circuit.
[0056] And, if the transaction is blocked 240, the alert signal TAMP_SNGL is generated 250 by the protection circuit RISUP, and directly transmitted to the countermeasure means TAMP.
[0057] Reference is again made to [Fig. 1].
[0058] The alert signal TAMP_SGNL is advantageously communicated via a CNLa alert channel connected directly to the RISUP protection circuit by means of TAMP countermeasure and dedicated to the transmission of said alert signal TAMP_SGNL.
[0059] In other words, the alert signal can be communicated directly and without intermediary via the alert channel, and not being subject to software implementation the reliability of the communication is improved.
[0060] The system on chip SOC usually comprises a large plurality of RES resources, for example several dozen, and several of these RES resources (in absolute terms, all the resources) can benefit from the direct communication of the alert signal TAMP_SGNL by the respective protection circuits RISUP.
[0061] Thus, an OR multiplexer element is configured to group all the alert channels CNLa respectively connected to said respective protection circuits RISUP, towards a single outgoing alert channel CNLo and directly connected to the countermeasure means TAMP. For example, the multiplexer element has a function of transmitting the alert signals, indistinctly from their origins CNLa, of the “OR gate” type.
[0062] Furthermore, advantageously, the alert channel CNLa is materially distinct from the interconnection bus BUS on which the transactions addressed to the resource RES are communicated. Here again, this makes it possible to communicate the alert signal directly and without an intermediary, in particular without using the protocol of the interconnection bus BUS, nor addressing, etc., improving the responsiveness and reliability of the communication of the alert signal.
[0063] In parallel with the communication of the TAMP_SGNL alert signal described above, the RIF resource isolation system can also be configured to generate an ILAC_INTRPT interrupt signal addressed to the trusted master device TDMSTR, for example via the interconnect bus routing mechanism BUS, in the event of a transaction being blocked by any of the RISUP protection circuits of the peripherals (at least one) of the system on chip SOC.
[0064] The RIF resource isolation system may in this respect comprise a central management unit for illegal access IAC, for example within a control device of the RIFSC resource isolation system.
[0065] In this case, the RISUP protection circuits of the RES resources are configured to generate a signal for detecting illegal access ILAC (and / or blocking of the corresponding transaction) and communicate it to the central management unit for illegal access IAC.
[0066] The central illegal access management unit IAC is configured to generate the ILAC_INTRPT interrupt addressed to the trusted master device TDMSTR, in the event of receipt of an ILAC illegal access detection signal communicated by any of the RISUP protection circuits.
[0067] Furthermore, the RISUP protection circuit may be capable of generating an ILAC_BUS notification signal addressed to the master device MSTR at the origin of said blocked transaction, by the bus routing mechanisms, and advantageously on an RREP error notification channel of the interconnection bus BUS.
[0068] It will be noted that the RREP error notification channel of the bus can normally be provided to be used by the RES resource, and not by the RISUP protection circuit itself, for example to communicate response information from the slave resources, following reception of a read or write transaction, such as an error notification in the event of a transaction received successfully but which is not understood by the slave resource.
[0069] Thus, the error notification channel of the RREP bus is potentially “overloaded” since it is connected and usable independently by two separate circuits, both by the RISUP protection circuit and by the RES resource.
[0070] Furthermore, the ILAC_BUS notification signal can be provided to generate a reaction, advantageously immediate, from the master device MSTR at the origin of the blocked transaction.
[0071] The reaction of the master device MSTR to the reception of the ILAC_BUS notification signal may include an interruption of the current data transfer, and / or a termination of the current process (at the origin of the illegal access) by forcing a generation of a data abort exception making it possible to identify the address which generated the illegal access.
[0072] Finally, the RIF resource isolation system can advantageously include CFGREG configuration registers, for example within the control device of the RIFSC resource isolation system, capable of containing CONFIG configuration information of the elements of the RIF resource isolation system (in particular the RISUP protection circuits of the RES resources and also of the master devices MSTR, TDMSTR).
[0073] In this regard, reference is made to [Fig.3]
[0074] [Fig.3] illustrates an example of a configuration register CFGREG, for example dedicated to a resource RES of the system on chip SOC.
[0075] The configuration register CFGREG contains 32 locations "0" to "31" to contain setting data relating to resource isolation, for the respective RES resource.
[0076] For example and arbitrarily, location "0" can be used to define the secure or non-secure SEC access right of the resource, while location "1" can be used to define the privileged or non-privileged PRIV access right of the resource.
[0077] For example also, locations “4” to “6” can be used to contain the CID compartmentalization identifier of the resource.
[0078] In an advantageous embodiment of the RIF resource isolation system, the configuration register CFGREG of each RES resource includes a location “7” intended to contain a parameter data item for the TAMP_EN alerts.
[0079] The TAMP_EN alert configuration data makes it possible to activate or deactivate (for example when it is recorded at the value “1”, or respectively “0”) the functionality of generation and direct communication of the TAMP_SGNL alert signal by means of the TAMP countermeasure, by the RISUP protection circuit which blocks a transaction.
[0080] The value of the TAMP_EN alert configuration data can, for example, be recorded by a user, in order to choose the degree of protection against illegal access that he wishes to benefit from for each RES resource of the SOC system on chip.
[0081] The value of the alert parameter data TAMP_EN can also, for example, be recorded by an access rights establishment procedure, usually carried out by the trusted master device TDMSTR when starting the system on chip SOC.
[0082] Thus, the operation of the RISUP protection circuit of each RES resource is configured according to the TAMP_EN alert configuration data contained in a location (for example location “7”) of the CFGREG configuration register dedicated to this RES resource.
[0083] Alternatively, the configuration register CFGREG may be dedicated to a master device MSTR of the system-on-chip SOC.
[0084] In this case, the respective location, for example location “7”, contains a second alert setting data TAMP_CID.
[0085] The second data item for setting the TAMP_CID alerts allows the activation or deactivation (for example when recorded at "1" or respectively "0") of the functionality for generating and directly communicating the TAMP_SGNL alert signal by means of the TAMP countermeasure, by the RISUP protection circuit which blocks the transaction sent by the MSTR master device associated with this CFGREG configuration register.
[0086] In other words, the RISUP protection circuit of each RES resource is configured to generate or not generate said alert signal TAMP_SGNL in the event of blocking of a transaction addressed to the resource by the master device MSTR, depending on the second data item for configuring the alerts TAMP_CID for this master device.
[0087] For example in practice, the RISUP protection circuit of each RES resource can know which master device issued the transaction by means of a master identification data item incorporated in the transaction, for example the compartmentalization identifier CID.
[0088] Thus, according to two possibilities which are compatible and can be combined, a user can choose to generate the alert signal TAMP_SGNL if illegal access is detected on a given resource (with the alert configuration data TAMP_EN), and / or if illegal access is detected by a given master (with the second alert configuration data TAMP_CID).
[0089] In this regard, reference is made to [Fig.4].
[0090] [Fig.4] illustrates an example of implementation of a decision 400 by a RISUP protection circuit, in the event of a transaction 240 being blocked (as described in relation to [Fig.2]), to generate or not the alert signal 250 (as described in relation to [Fig.2]) as a function of said alert parameterization data TAMP_EN, TAMP_CID contained in the set of configuration registers CFGREG.
[0091] In a step 242, it is verified whether the resource RES a to which the blocked transaction is addressed benefits from the protection of the TAMP countermeasure means, by the alert configuration data associated with this resource TAMP_EN[RES]. The protection circuit RISUP can access this data contained in the configuration register
[0092] If yes, “y”, then the alert signal is generated 250.
[0093] If no, “n”, then we check, in a step 244, if the master device MSTR which issued the blocked transaction benefits from the protection of countermeasures TAMP, by the second alert configuration data associated with this master device TAMP_CID[MSTR],
[0094] If yes, “y”, then the alert signal is generated 250.
[0095] If no, “n”, then the alert signal is not generated, and the implementation of the TAMP countermeasure means activation mechanism may end in a step 260.
[0096] Optionally, after step 260, the resource isolation system can notify the master device MSTR that issued the illegal transaction, for example by means of the notification signal ILAC_BUS, or notify the trusted master device TDMSTR for example by means of the interrupt signal ILAC_INTRPT.
[0097] We refer again to [Fig.3].
[0098] In this regard, on the one hand, in the case where the RIF resource isolation system is capable of generating the ILAC_BUS notification signal as mentioned previously, the configuration register CFGREG dedicated to each RES resource can contain a location “8” intended to contain a data item for setting the ILAC_BUS_CFG notifications. The data item for setting the ILAC_BUS_CFG notifications makes it possible to activate or deactivate the ILAC_BUS illegal access notification functionality via the RREP error notification channel of the BUS interconnection bus.
[0099] On the other hand, in the case where the RIF resource isolation system comprises the central illegal access management unit IAC, as mentioned previously, the configuration register CFGREG dedicated to each RES resource can advantageously contain a location “9” intended to contain an ILAC_INTRPT_CFG interrupt configuration data item. The ILAC_INTRPT_CFG interrupt configuration data item makes it possible to activate or deactivate the functionality of the central illegal access management unit IAC generating ILAC_INTRPT interrupts to the trusted master device TDMSTR, in the event of detection of illegal access, and respectively for each of the RES resources.
Claims
Claims
1. System on chip (SOC) comprising at least one slave resource (RES), a resource isolation system (RIF), and a countermeasure means (TAMP) capable and intended to limit the operation of the system (SOC) against potential anomalies, and, for said at least one slave resource (RES), a protection circuit (RISUP) configured to block or transmit transactions addressed to the resource (RES) according to access rights of the resource and the transaction, the protection circuit (RISUP) being configured to generate and directly communicate an alert signal (TAMP_SGNL) to the countermeasure means (TAMP) in the event of a transaction being blocked, in which the resource isolation system (RIF) comprises, in a set of configuration registers (CFGREG), for each resource a location for containing alert configuration data (TAMP_EN),the protection circuit (RISUP) of each resource being configured to generate or not generate said alert signal (TAMP_SGNL) in the event of blocking of a transaction addressed to the resource, depending on the alert configuration data (TAMP_EN) for this resource.,
2. System on chip (SOC) according to claim 1, comprising an alert channel (CNLa) directly connecting the protection circuit (RISUP) with the countermeasure means (TAMP) and dedicated to the transmission of said alert signal (TAMP_SGNL).
3. System on chip according to claim 2, comprising a plurality of said at least one resource (RES), and a multiplexer element (OR) configured to group all the alert channels respectively connected to said respective protection circuits (RISUP), on a single outgoing alert channel and directly connected to the countermeasure means (TAMP).
4. System on chip according to one of claims 1 to 3, further comprising at least one master device (MSTR) capable of generating said transactions addressed to the resource (RES) comprising a master identification data item (CID), in which the resource isolation system (RIF) comprises, in a set of configuration registers (CFGREG), for each master device, a location for containing a second parameter data item alerts (TAMP_CID), the protection circuit (RISUP) of each resource being configured to generate or not generate said alert signal (TAMP_SGNL) in the event of blocking of a transaction addressed to the resource by the master device (MSTR), depending on the second alert configuration data (TAMP_CID) for this master device.
5. Method for managing the isolation of resources of a system on chip (SOC), in which: - the system on chip (SOC) comprises at least one slave resource (RES), a resource isolation system (RIF), and a countermeasure means (TAMP) capable and intended to limit the operation of the system (SOC) against potential anomalies;and - the method comprises, for each resource, an implementation of a protection (RISUP) comprising a blocking or a transmission of transactions addressed to the resource (RES), depending on access rights of the resource and the transaction, and a generation of an alert signal (TAMP_SGNL) directly communicated by means of countermeasure (TAMP) in the event of a transaction being blocked, in which an alert configuration data item (TAMP_EN), for each resource, is contained in a set of configuration registers (CFGREG), and said alert signal (TAMP_SGNL) is generated or not in the event of a transaction being blocked addressed to a resource, depending on the alert configuration data item (TAMP_EN) for this resource.;
6. Method according to claim 5, wherein the alert signal (TAMP_SGNL) is transmitted on a dedicated alert channel (CNLa), directly connecting the protection circuit (RISUP) with the countermeasure means (TAMP).
7. Method according to claim 6, wherein the system on chip comprises a plurality of said at least one resource (RES), and all the alert channels respectively connected to said respective protection circuits (RISUP) are grouped (OR) on a single outgoing alert channel and directly connected to the countermeasure means (TAMP).
8. Method according to one of claims 5 to 7, the system on chip further comprising at least one master device (MSTR) generating said transactions addressed to the resource (RES) comprising a master identification data (CID), in which a second alert configuration data (TAMP_CID), for each master device, is contained in a set of configuration registers (CFGREG), and said alert signal (TAMP_SGNL) is generated or not in the event of blocking of a transaction addressed to a resource by the master device (MSTR), depending on the second alert configuration data (TAMP_CID) for this master device.