SYSTEM AND METHOD FOR DYNAMIC CONTROL OF SECURE OPERATING MODES IN A PROCESSOR - Patent application

The system dynamically controls processor modes using PRVS and ENFB fields to address security and performance challenges, enabling flexible mode switching and enhanced security without reboots.

JP7785082B2Active Publication Date: 2025-12-12INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023535703
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-12-16
Filing Date
2021-12-06
Publication Date
2025-12-12
Estimated Expiration
2041-12-06

AI Technical Summary

Technical Problem

Modern computing systems face challenges in dynamically controlling secure and performance modes of processors, especially in preventing unauthorized access and mitigating side-channel attacks, while maintaining optimal performance without requiring system reboots.

Method used

A system and method for dynamically controlling processor modes by using configuration registers with Privilege Entry (PRVS) and Enforcement Below (ENFB) fields to enable secure or performance modes at different privilege levels, allowing software to change these modes during operation without rebooting.

Benefits of technology

Enables dynamic switching between secure and performance modes at different privilege levels, enhancing security and performance flexibility without system reboots, and allowing granular control based on privilege levels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007785082000001
    Figure 0007785082000001
  • Figure 0007785082000002
    Figure 0007785082000002
  • Figure 0007785082000003
    Figure 0007785082000003
Patent Text Reader

Abstract

A computer system, processor, or method, or combination thereof, for changing a computer's operating mode without rebooting includes a processor including a configuration register, the configuration register including a privilege entry (PRVS) register field for each of one or more privilege levels, each PRVS register field for each privilege level including one or more control aspect entries, and an inferior enforcement (ENFB) register field, each ENFB register field for each privilege level including one or more control aspect entries, the control aspects of the PRVS register fields being equal in number to and corresponding to the control aspects of the ENFB register fields. The PRVS register fields and the ENFB register fields are used to change the processor from a secure mode to a performance mode while executing a software application.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates generally to information and data processing systems, processors, and memory systems, and more particularly to dynamically controlling one or more secure modes of operation in a processor. [Background technology]

[0002] Recent advances in information technology and the widespread use of the Internet to store and process information have placed increasing demands on computing systems to acquire, process, store, and distribute information. Computing systems are being developed to increase the speed at which computers can execute increasingly complex applications for business, personal use, and entertainment. The overall performance of a computer system is affected by each of the major elements of the computer's architecture, including the processor, any memory cache, the performance / structure of the input / output (I / O) subsystem, the efficiency of the memory control functions, the performance of memory devices and memory systems and associated memory interface elements, and the type and structure of the memory interconnection interface.

[0003] Modern computer systems typically contain multiple integrated circuits (ICs), including a processor, which can be used to process information in the computer system. The information processed by the processor can include computer instructions executed by the processor as well as data manipulated by the processor using the computer instructions. The computer instructions (e.g., applications) and data are typically stored in main memory within the computer system. The performance of the processor can affect the performance of the information processing system, also known as a computing system or data processing system.

[0004] Preventing unauthorized users and / or malicious software from accessing information and data processing systems is becoming increasingly important and difficult to achieve. In one situation, a user or software application may be permitted to have access to an information processing system, processor, register file, or memory subsystem, or a combination thereof, but may not be permitted to have complete access to the complete system, all register files, or all of the memory subsystem. Thus, a user or software application may be permitted to access a portion of the system, but the user and / or software application is not permitted to access the entire system, all register files, or all of the memory subsystem, or a combination thereof. In other situations, a user and / or software application is not permitted to access any portion of the computing system, any portion of the register file, or any portion of the memory subsystem, or a combination thereof. Protecting the system, register file, or memory subsystem, or a combination thereof, from being accessed by unauthorized users and / or software applications can be difficult.

[0005] In microprocessor design, microarchitectural performance optimizations may also open certain side-channel security holes in the processor that make the processor, the computing system, or both more vulnerable to attack. For example, certain performance mechanisms and features in a microprocessor may inherently expose the microprocessor to a Spectre-RSB side-channel attack. Although performance features may make the processor more vulnerable to attack, under certain trusted execution environments it may be beneficial to utilize performance optimizations because the associated side-channel attacks may pose less of an actual threat. In other situations and execution environments, a more secure configuration that neither utilizes nor disables performance optimizations may be warranted. It would be beneficial if the processor's configuration could be dynamically controlled or switched to provide optimized performance or optimized security, preferably in an embodiment by trusted software, so that the processor can make the most of its hardware and features, instead of having performance / security modes set and fixed by firmware at boot time. Summary of the Invention

[0006] This summary of the present disclosure is provided to aid in understanding computer systems, computer architecture structures, processors, their methods of operation, and software application execution, including techniques for controlling security modes of such systems, processors, and their methods of operation, but is not intended to limit the present disclosure or the present invention. This disclosure is directed to persons skilled in the art. It should be understood that various aspects and features of the present disclosure may be used to advantage in some instances individually or in combination with other aspects and features of the present disclosure in other instances. Accordingly, variations and modifications may be made to computer systems, architecture structures, processors, register files, their methods of operation, and methods of executing software applications to achieve different effects.

[0007] In one or more embodiments, aspects of the present disclosure provide a system and / or method for processing data in a processor, including changing an operating mode in the processor without rebooting the processor. In an embodiment, the system and / or method includes initiating a configuration change in the processor from a performance mode to a secure mode of a control aspect at a privilege level, determining whether a bit for the control aspect at the privilege level in a privilege entry (PRVS) register field is set to secure mode, and if the bit for the control aspect at the privilege level in the PRVS register field is not set to secure mode, setting the bit for the control aspect at the privilege level in the PRVS register field to secure mode, thereby enabling secure mode of the control aspect at the privilege level in the processor. Preferably, the system and / or method further includes determining whether to enforce secure mode of the control aspect for lower privilege levels, and if it is determined not to enforce secure mode of the control aspect for lower privilege levels, the method for changing to secure mode of the control aspect at the privilege level is completed. In an embodiment, the system and / or method may further include, if it is determined to enforce secure mode of the control aspect for the lower privilege level, determining whether a bit for the control aspect at the lower privilege level in an Enforce Below (ENFB) register field is set to secure mode, and if it is determined that a bit for the control aspect at the lower privilege level in the ENFB register field is set to secure mode, completing the process of changing the control aspect to secure mode at the privilege level.In a further embodiment, the system and / or method includes, if it is determined that the bit of the control aspect at the lower privilege level in the ENFB register field is not set to secure mode, determining whether the policy of the control aspect at the privilege level allows for enforcing secure mode of the control aspect for lower privilege levels, and if the policy of the control aspect at the privilege level does not allow for enforcing secure mode of the control aspect at the lower privilege level, completing the process of changing to secure mode of the control aspect at the privilege level. In one aspect, the secure mode or performance mode of the processor of the control aspect at the privilege level is controlled by a software application.

[0008] In one or more embodiments, the system and / or method further includes, in response to triggering a change of the control aspect at the privilege level from secure mode to performance mode, checking whether a bit in an SRVS register field of the control aspect at the privilege level is set to performance mode; in response to the bit in the SRVS register field of the control aspect at the privilege level being not set to performance mode, setting a bit in a service register field of the control aspect at the privilege level to performance mode; checking whether the control aspect at the privilege level of all higher privilege level ENFB register fields is set to performance mode; and in response to the control aspect at the privilege level of all higher privilege level ENFB register fields being set to performance mode, changing the processor to the performance mode of the control aspect at the privilege level. In one aspect, the system and / or method includes requesting that the higher privilege level allow the performance mode of the control aspect at the privilege level in response to the control aspect of the ENFB register of all higher privilege levels not being set to the performance mode, and the processor not transitioning to the performance mode of the control aspect at the privilege level in response to the higher privilege level not allowing the performance mode of the control aspect at the privilege level. Requesting that the higher privilege level allow the performance mode of the control aspect at the privilege level typically includes looking up a policy of the higher privilege level for the performance mode of the control aspect at the lower privilege level, checking whether the policy allows the performance mode of the control aspect at the privilege level, and in response to the policy allowing the performance mode of the control aspect at the privilege level, setting a bit in the ENFB register field of the control aspect at the privilege level to the performance mode, thereby allowing the processor to transition to the performance mode of the control aspect at the privilege level.

[0009] In one or more embodiments, a computer system for processing information is disclosed that includes at least one processor including one or more register files, at least one of the registers being a configuration register, the configuration register including a privilege entry (PRVS) register field for each of one or more privilege levels, each PRVS register field for each privilege level including one or more control aspect entries for holding bits, and an inferior enforcement (ENFB) register field for each lower privilege level than the one or more privilege levels, each ENFB register field for each privilege level including one or more control aspect entries for holding bits, the control aspects of the PRVS register fields being equal in number to and corresponding to the control aspects of the ENFB register field. The processor is adapted and configured to initiate a configuration change in the processor from a performance mode of a control aspect at a privilege level to a secure mode, the change including determining whether a bit of the control aspect at a privilege level in a privilege entry (PRVS) register field is set to secure mode, and if the bit of the control aspect at a privilege level in the PRVS register field is not set to secure mode, setting the bit of the control aspect at a privilege level in the PRVS register field to secure mode, thereby enabling secure mode of the control aspect at a privilege level in the processor.Preferably, the processor is further configured and adapted to determine whether to force a secure mode of the control aspect for a lower privilege level, and if it is determined to force a secure mode of the control aspect for a lower privilege level, determine whether a bit for the control aspect at the lower privilege level in an Enforcement Below (ENFB) register field is set to secure mode, and if it is determined that a bit for the control aspect at the lower privilege level in the ENFB register field is set to secure mode, complete the process of changing the control aspect to secure mode at the privilege level.

[0010] In a further embodiment, the system includes, in response to triggering a change of the control aspect at the privilege level from a secure mode of operation to a performance mode of operation, checking whether a bit in a service entry (SRVS) register field of the control aspect at the privilege level is set to performance mode; in response to the bit in the SRVS register field of the control aspect at the privilege level being not set to performance mode, setting a bit in a service register field of the control aspect at the privilege level to performance mode; checking whether all higher privilege level subordinate forcing (ENFB) register fields of the control aspect at the privilege level are set to performance mode; and in response to all higher privilege level ENFB register fields of the control aspect at the privilege level being set to performance mode, changing the processor to the performance mode of the control aspect at the privilege level.

[0011] According to one aspect, a method for changing an operating mode in a processor without rebooting the processor is provided, the method including initiating a configuration change in the processor from a performance mode to a secure mode of a control aspect at a privilege level; determining whether a bit for the control aspect at the privilege level in a privilege entry (PRVS) register field is set to the secure mode; and if the bit for the control aspect at the privilege level in the PRVS register field is not set to the secure mode, setting the bit for the control aspect at the privilege level in the PRVS register field to the secure mode, thereby enabling the secure mode of the control aspect at the privilege level in the processor.

[0012] According to another aspect, a method for changing an operating mode of a processor without rebooting the processor is provided, the method including: in response to triggering a change of a control aspect at a privilege level from a secure mode of operation to a performance mode of operation, checking whether a bit in a Privilege Entry (PRVS) register field of the control aspect at the privilege level is set to the performance mode; in response to the bit in the PRVS register field of the control aspect at the privilege level being not set to the performance mode, setting a bit in a Service register field of the control aspect at the privilege level to the performance mode; checking whether an Enforcement Downstream (ENFB) register field of the control aspect at the privilege level of all higher privilege levels is set to the performance mode; and in response to the control aspect at the privilege level of the ENFB register field of all higher privilege levels being set to the performance mode, changing the processor to the performance mode of the control aspect at the privilege level.

[0013] According to another aspect, a computer system for processing information is provided, the computer system comprising at least one processor including one or more register files, at least one of the registers being a configuration register, the configuration register including: a privilege entry (PRVS) register field for each of one or more privilege levels, each PRVS register field for each privilege level including one or more control aspect entries for holding bits; and an inferior enforcement (ENFB) register field for each lower privilege level below the one or more privilege levels, each ENFB register field for each privilege level including one or more control aspect entries for holding bits. the control aspect of the PRVS register field is equal in number to and corresponds to the control aspect of the ENFB register field, and the processor is configured and adapted to: initiate a configuration change in the processor from a performance mode of the control aspect at a privilege level to a secure mode; determine whether a bit of the control aspect at a privilege level in the PRVS register field is set to the secure mode; and, if the bit of the control aspect at a privilege level in the PRVS register field is not set to the secure mode, set the bit of the control aspect at a privilege level in the PRVS register field to the secure mode, thereby enabling the secure mode of the control aspect at a privilege level in the processor.

[0014] The foregoing and other features and advantages of the present invention will become apparent from the following more particular description of exemplary embodiments of the invention, as illustrated in the accompanying drawings, in which like reference numerals generally represent like parts of the exemplary embodiments of the invention.

[0015] Various aspects, features, and embodiments of information processing systems, computer systems, computer architectural structures, processors, register files, their methods of operation, and methods of executing software applications will be best understood when read in conjunction with the provided figures. Although the figures provide embodiments for the purpose of illustrating various aspects, features, or various embodiments, or combinations, of computer systems, computer architectural structures, processors, register files, and their methods of operation, including methods of executing software applications, the claims should not be limited to the exact arrangements, structures, assemblies, subassemblies, functional units, mechanisms, features, aspects, embodiments, devices, methods, processes, or techniques shown, and the illustrated arrangements, structures, assemblies, subassemblies, functional units, mechanisms, features, aspects, embodiments, devices, methods, processes, and techniques may be used alone or in combination with other arrangements, structures, assemblies, subassemblies, functional units, mechanisms, features, aspects, embodiments, devices, methods, processes, and techniques. [Brief explanation of the drawings]

[0016] [Figure 1] 1 illustrates a typical computing system or data processing system according to an embodiment of the present disclosure. [Figure 2] FIG. 1 illustrates a processor and memory system according to an embodiment of the present disclosure. [Figure 3] FIG. 2 illustrates a block diagram of a processor in accordance with an embodiment of the present disclosure. [Figure 4] FIG. 2 illustrates a schematic diagram of an organization of configuration registers in accordance with an embodiment of the present disclosure. [Figure 5] FIG. 5 illustrates a schematic diagram of the operation of the configuration register of FIG. 4 in accordance with an embodiment of the present disclosure. [Figure 6] 1 illustrates a flow chart of a method for changing an operating mode of a processor, according to an embodiment. [Figure 7] FIG. 10 illustrates a flow chart of a method for changing an operating mode of a processor according to another embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0017] The following description is provided for the purpose of explaining the general principles of the present invention and is not intended to limit the inventive concepts claimed herein. Although the following detailed description sets forth numerous details to provide an understanding of information processing systems, computer systems, computer architecture structures, processors, memories, functional units, register files, memory subsystems, and their methods of operation, including methods of executing software applications, it will be understood by those skilled in the art that many different embodiments of computer systems, computer architecture structures, processors, functional units, register files, memory subsystems, and their methods of operation, including methods of executing software applications, may be practiced without these specific details, and that the claims and the present invention should not be limited to the embodiments, assemblies, subassemblies, structures, arrangements, mechanisms, functional units, features, aspects, processes, methods, techniques, or details specifically described and illustrated herein. Furthermore, particular features, functional units, mechanisms, structures, arrangements, embodiments, and aspects described herein may be used in combination with other described features, functional units, mechanisms, structures, arrangements, embodiments, and aspects, in each of a variety of possible combinations and permutations.

[0018] In this specification, unless otherwise specifically defined, all terms are to be given their broadest possible interpretation, including the meaning implied from the specification and the meaning understood by a person of ordinary skill in the art and / or as defined in dictionaries, treatises, etc. It should also be noted that as used in this specification and the appended claims, the singular forms "a," "an," and "the" include plural referents unless otherwise specified.

[0019] The following description omits or only briefly describes conventional features of information handling systems, including processors, microprocessor systems, memory systems, and system architectures that will be apparent to those skilled in the art. It is assumed that those skilled in the art are familiar with computer systems, memory systems, the general architecture of processors, and register files, including configuration register files. Note that numbered elements are numbered according to the figure in which they are introduced and are typically referenced by that number throughout subsequent figures.

[0020] A computing system or data processing system 100 suitable for use in a preferred embodiment of the present invention may take a variety of forms, one of which is shown in FIG. 1, in which the computing system or data processing (information processing) system 100 is configured to store and / or execute program code. In one embodiment, the information processing system 100 may take a variety of forms and may include at least one processor 102, which may be or be part of a controller coupled directly or indirectly to memory devices and input / output devices via a system bus 106, as shown in FIG. 1. The computing system 100 of FIG. 1 is shown with the processor 102 (also called a central processing unit (CPU) or microprocessor), random access memory (RAM) 103, non-volatile memory 104, device-specific circuitry 101, and I / O interface 105. Alternatively or additionally, RAM 103 and / or non-volatile memory 104 may be included in processor 102, and device-specific circuitry 101 and I / O interface 105 may also be included in processor 102. Processor 102 may comprise, for example, an off-the-shelf microprocessor, a custom processor, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), discrete logic, etc., or generally any device for executing instructions. RAM 103 is typically used to hold variable data, stack data, executable instructions, etc., and may include dynamic random access memory (DRAM).

[0021] According to various approaches, non-volatile memory 104 may include any type of non-volatile memory, such as, but not limited to, Electrically Erasable Programmable Read Only Memory (EEPROM), flash Programmable Read Only Memory (PROM), battery-backed RAM, hard disk drive, etc. Non-volatile memory 104 is typically used to hold executable firmware and any non-volatile data, including programming instructions that can be executed to cause processor 102 to perform certain functions.

[0022] In some embodiments, I / O interface 105 may include a communication interface that allows processor 102 to communicate with devices external to the controller. Examples of communication interfaces may include, but are not limited to, serial interfaces such as RS-232, Universal Serial Bus (USB), Small Computer Systems Interface (SCSI), RS-422, or wireless communication interfaces such as Wi-Fi, Bluetooth, near-field communication (NFC), or other wireless interfaces. Computing system 100 may communicate with external devices via communication interface 105 in any communication protocol, such as Automation Drive Interface (ADI).

[0023] FIG. 2 illustrates an exemplary processing system 180 in which a preferred embodiment of the present invention may be practiced, which may be part of a larger computer system architecture or network. The processing system 180 includes a control processor system or processor 102, which is a processing subsystem including at least one processor unit (CPU) 125 that may be configured to interface with a memory control unit (MCU) 140. The CPU 125, also referred to as a microprocessor, may be a module that processes read, write, and configuration requests from a system controller (not shown). The CPU 125 may be a multi-core processor. The MCU 140 may include a memory controller synchronous synchronous (MCS) 142 (also referred to as a memory controller) that controls communication with one or more memory devices (e.g., DRAM) (not shown in FIG. 2) in the memory subsystem 103. MCU 140 and MCS 142 may include one or more processing circuits, or processing may be performed by or in conjunction with processor 125. Control processor system 102 communicates with memory subsystem 103 via communication bus 106.

[0024] 3 illustrates a block diagram of a processor 102 according to an embodiment in which the present disclosure may be practiced. The processor 102 may be a pipelined processor configured to execute one or more streams of instructions or threads. A thread (also called an instruction stream) comprises a sequence or collection of instructions that together perform a particular task. Threads may be instruction streams from different parts of the same program running on the processor, or from different programs running on the processor, or a combination thereof. In one embodiment, the processor may be a multithreaded processor and may process threads simultaneously.

[0025] According to one embodiment, the processor 102 may include a memory 202, an instruction cache 204, an instruction fetch unit 206, a branch predictor 208, a processing pipeline 210, and destination resources 220. The processor 102 may be contained within a computer processor or otherwise distributed within a computer system. Instructions and data may be stored in the memory 202, and the instruction cache 204 may access instructions in the memory 202 and store fetched instructions (e.g., instructions for various threads) in the cache memory 204. The memory 202 may include any type of volatile or non-volatile memory, such as a cache memory. The memory 202 and the instruction cache 204 may include multiple cache levels. A data cache (not shown) may be included in the processor 102. The processor 102 preferably allows multiple threads to share the processor's 102 functional units (e.g., instruction fetch and decode units, caches, branch prediction units, and execution units), preferably in a concurrent manner.

[0026] 3 illustrates a simplified example of an instruction fetch unit 206 and a processing pipeline 210. In various embodiments, the processor 102 may include one or more processing pipelines 210 and an instruction fetch unit 206. In an embodiment, the processing pipeline 210 includes a decode unit 20, an issue unit 22, an execution unit 24, writeback logic 26, a logical register mapper 28, a history buffer (e.g., a Save & Restore Buffer (SRB) 30), and a physical register file 32. The instruction fetch unit 206 and / or a branch predictor 208 may be part of the processing pipeline 210. The processing pipeline 210 may include other features, such as error checking and processing logic, one or more parallel paths through the processing pipeline 210, and other features now or hereafter known in the art. The pipeline may be decomposed and illustrated differently. 3 shows a forward path through processor 102, other feedback and signaling paths may be included between elements of processor 102. Processor 102 may include other circuits, functional units, and components.

[0027] The instruction fetch unit 206 fetches instructions from the instruction cache 204 for further processing by the decode unit 20. The decode unit 20 decodes the instructions and passes the decoded instructions, portions of instructions, or other decoded data to the issue unit 22. The decode unit 20 may detect branch instructions not predicted by the branch predictor 208. The decode unit 20 may include one or more configuration registers 250, which are described in further detail below. The issue unit 22 analyzes the instructions or other data and, based on this analysis, sends the decoded instructions, portions of instructions, or other data to one or more execution units 24 in the pipeline 210. The execution units 24 perform the operations specified by the instructions issued to them. The execution units 24 may include multiple execution units, such as fixed-point execution units, floating-point execution units, load / store execution units, vector / scalar execution units, or other execution units, or a combination thereof. The physical register file 32 maintains data for the execution units 24. Logic register mapper 28 contains entries that provide a mapping between logic register entries (Leg) and entries in physical register file 32. When an instruction needs to read a logic register entry (Leg), logic register mapper 28 provides information to issue unit 22 about where the data can be located in physical register file 32, and issue unit 22 provides this information to execution unit 24.

[0028] When a mispredicted branch instruction or other exception is detected, the instructions and data following the mispredicted branch or exception are discarded (e.g., flushed from various units of processor 110). A history buffer (e.g., save and restore buffer (SRB) 30) contains the state of both speculative and architected registers and backs up logic register file data when a new instruction is dispatched. In this regard, the history buffer 30 stores information from logic register mapper 28 when the new instruction is flushed and the old data needs to be restored. The history buffer (SRB) 30 maintains the stored information until the new instruction is completed. The history buffer (SRB) 30 interfaces with the logic register mapper 28 to update pointers in the logic register mapper 28 so that the instruction knows where to get the correct data and to restore the contents of the logic register entries from the history buffer (SRB) 30 to the logic register mapper 28, e.g., returning the processor to the state it was in before the interruptible instruction (e.g., before the branch instruction was mispredicted).

[0029] Writeback logic 26 writes the results of the executed instructions back to destination resources 220. Destination resources 220 may be any type of resource, including registers, cache memory, other memory, I / O circuitry for communicating with other devices, other processing circuitry, or any other type of destination, for the instructions or data being executed. One or more of the processor pipeline units may provide information regarding the execution of conditional branch instructions to branch predictor 208.

[0030] Instructions may be processed within processor 102 in a series of logical, pipelined stages. However, it should be understood that the functionality of these stages may be merged together, such that this particular division of stages is not considered limiting unless a limitation is expressly set forth in the claims herein. Indeed, in Figure 3, some of the stages are shown as a single logical unit for ease of understanding, and related further details are provided below.

[0031] In certain aspects, processor 102 may include multiple execution / processing slices, each slice including one or more of the units shown in FIG. 3 . For example, each processing slice may include its own processing pipeline 210, including functional / execution unit 24. A processor 102 including multiple processing slices may be capable of executing multiple instructions simultaneously (e.g., one instruction in each processing slice simultaneously in one processing cycle). Such a processor including multiple processing slices may be referred to as a multi-slice processor or a parallel slice processor. Simultaneous processing on multiple slices can significantly increase processing speed. In single-thread (ST) mode, a single thread is processed, and in SMT mode, multiple threads are processed, e.g., two threads (SMT2) or four threads (SMT4) are processed simultaneously in one or more embodiments.

[0032] Information and data processing systems, computer systems, processors, or digital logic systems, or combinations thereof, may include processor features and / or performance improvements that optimize the processor's performance but may also reduce the processor's security, for example, by making it more vulnerable to side-channel attacks. In some environments, it may be desirable for the processor to operate at a higher performance level (e.g., a performance mode), while in other environments, it may be desirable for the processor to operate at a higher security level (e.g., a secure mode) rather than a performance mode. It would be desirable and beneficial if the mode in which the processor operates could be dynamically controlled, such that the processor could switch between different performance or security modes while the processor is running, rather than the processor's performance or security mode being fixed and set by firmware at startup.

[0033] Additionally, it would be beneficial if different performance / security operating modes could be set and configured for different control aspects at different privilege levels set within a processor. For example, it would be advantageous if different secure / performance operating modes could be dynamically set and changed for different control aspects at different privilege levels or states while the processor is running, so that a reboot is not required. It would be even more advantageous if different security configurations could be enforced with a large granularity, for example, a hypervisor could require a particular secure configuration or mode for an entire logical partition. It would be beneficial and advantageous if a system or mechanism for dynamic control allowed for the enforcement of a secure configuration or mode of processor operation regardless of desired dynamic control at lower privilege levels.

[0034] In embodiments, dynamic control of security / performance modes per control aspect of a processor is provided. In one or more embodiments, different security / performance operating modes of a processor may be established for each privilege level (also referred to as a privilege state) of the processor. In embodiments, dynamic control of secure / performance modes per control aspect, per privilege level, or both is achieved by software. In further embodiments, higher privilege levels / states may enforce or suppress preferred or desired security / performance mode settings for lower privilege levels. For example, a secure mode of a higher privilege level in a processor may be enforced for all lower privilege levels or states. In embodiments, systems and techniques for dynamic control of security / performance modes of various privilege states also enable each privilege state or level to know the performance / security mode for each control aspect at that privilege level and also enable the ability to control the performance / security mode for each control aspect of each privilege level below that privilege level, unless a security mode is enforced by a higher privilege level or state.

[0035] In one or more embodiments, configuration registers may be used to provide dynamic control of a processor, and more particularly, to provide dynamic control of a processor's performance or secure operating modes. Computing systems, processors, and digital logic systems often include registers that may be read from or written to by software programs. Registers based on modern integrated circuits are typically implemented using static random access memory (SRAM) that includes multiple ports. Registers typically include dedicated read and write ports. Registers can be user-accessible registers, such as data registers, address registers, general-purpose registers, status registers, and configuration registers. In one aspect, registers are real or virtual data storage locations that, in embodiments, have addresses in a memory map. In one example, a register file can be an array of processor registers within a processor (CPU). Some of these registers, or portions of registers (e.g., register entries), are configuration registers. Configuration registers utilized to provide dynamic control of the processor's operating mode (e.g., secure mode or performance mode) are typically located within the processor, and in one or more embodiments, within the processor's decode unit, although the configuration registers can be located in other locations.

[0036] In one or more embodiments, in a processor, performance mode / security mode settings can be dynamically controlled and changed, preferably by software, during processor operation on a per-privilege-level, per-aspect basis. For each processor aspect for each privilege level or state, except for the lowest privilege level, in embodiments, two fields of entries in a configuration register (or two configuration registers) are provided that are used to define and control the security mode / performance mode for that aspect. One of the configuration register fields (or configuration registers) is called the Privilege State Register (PRVS) and corresponds to and controls the privilege mode for each aspect of that privilege level. The other configuration register field (or configuration register) is called the Lower Enforcement Register (ENFB) and, in embodiments, provides, for each control aspect, the security mode / performance mode that a particular privilege level wants to enforce for privilege levels below the particular privilege level. In one or more embodiments, a field or entry in the ENFB configuration register is writable only from that privilege state or level or higher, while a field or entry in the ENFB configuration register is readable from all privilege levels. In an embodiment, the final control of performance mode / security mode for each control aspect at each privilege level is the OR value of that control aspect's bit in the PRVS entry for that privilege level and the ENFB bits of the corresponding control aspects at all privilege levels above the privilege level being controlled.

[0037] Dynamic control of a processor's operating mode (e.g., security mode or performance mode) will now be described with reference to an embodiment shown in FIG. 4, which is a block diagram of a configuration register 250. While configuration register 250 is shown as a single configuration register, it will be understood that the configuration register can be a series of individual configuration registers, and that FIG. 4 is merely an example embodiment for illustrative purposes. Configuration register 250 is configured to include multiple privilege levels or states 455 corresponding to the number of privilege levels utilized by the processor. If a processor has "n" privilege levels or states, then configuration register 250 typically includes a corresponding number of "n" privilege levels or states 455. In the example of FIG. 4, the configuration register includes "n" privilege levels 455, shown as privilege levels 0 through "n-1," with privilege level 0 being the highest privilege level and privilege level "n-1" being the lowest privilege, and the configuration register 250 can be changed. In one or more embodiments, each privilege level 455 of the processor and / or configuration file 250 includes "m" aspects 480 of performance / security modes that can be controlled. In Figure 4, the configuration register 250 includes "m" control aspects 480, shown as control aspects 0 through "m-1."

[0038] In an embodiment, each privilege level 455 except the lowest privilege level 455[n-1] includes two fields of entry: a lower enforcement field 460 (also referred to as an ENFB, ENFB field, or ENFB register) and a privilege entry field 470 (also referred to as a PRVS, PRVS field, or PRVS register). Each PRVS field 470 provides control information regarding the security / performance modes of that particular privilege level 455[k], where [k] represents the privilege level 455. Each PRVS field 470 includes one or more entries 472 for holding control bits for each control aspect 480[j] of the processor that can be controlled or changed, where [j] represents the particular control aspect 480. In one or more embodiments, each ENFB field 460 includes one or more entries 462 to hold control bits for each control aspect 480[j] that provide the security / performance modes that the current privilege level 455[k] wants to enforce for all privilege levels 455 below the current level (e.g., privilege level 455[k-1], etc.). In an embodiment, for each privilege level 455, each ENFB field 460 and PRVS field 470 in configuration register 250 includes a one-bit entry 462 or 472 for each processor control aspect 480[0] through 480[m-1], and an aspect number 480. Thus, the number of ENFB entries 462 and PRVS entries 472 in each ENFB field 460 and PRVS field 470 is the same. A "1" in each entry 462 and 472 in each of the ENFB 460 and PRVS 470 for a control aspect 480 indicates that the security mode of that aspect 480 is set or configured, while a "0" indicates that the performance mode of that aspect 480 is set or configured. Control aspects 480[0] through 480[n-1] in the ENFB field 460 correspond to the same aspects 480[0] through 480[n-1] in the PRVS field 470.

[0039] In an embodiment, the lowest privilege level 455 (e.g., privilege level (n-1)) includes only the PRVS field 470 per control aspect 480 and, in an embodiment, precedes both the ENFB field 460 and the PRVS field 470. If a processor has "n" privilege levels or states 455 and "m" security / performance control aspects 480, in an embodiment, there are a total of 2(n-1)m+m or m(2n-1) maximum field entries and 2m(n-1) minimum field entries in the configuration register. FIG. 4 illustrates the configuration register 250 setup in an embodiment, where there are "n" privilege levels 0 through n-1 and "m" security / performance control aspects 0 through m-1. There can be multiple configuration registers that are used and formatted in various ways. For example, there can be a separate ENFB register and / or a separate configuration PRVS register for each privilege level, or alternatively, each privilege level can include one register, each register including two fields (an ENFB register field and a PRVS register field).

[0040] The terminology for identifying different bit values ​​within the ENFB field 460 and PRVS field 470 of the control / configuration register 250 may be represented by ENFB[k][j] PRVS[k][j], where the privilege level is identified by [k] and the security / performance control aspect is identified by [j]. Logic provides one or more access and control rules that define the behavior of the control / configuration register 250 and the processor. In one or more embodiments, the control aspect bit [j] of ENFB 460 and PRVS 470 may be written at any time during processor operation, typically without requiring a system reboot. For example, the control aspect bit j of each of ENFB 460 and PRVS 470 may be written when an application begins execution. The control aspect bits of ENFB 460 and PRVS 470 may also be written at other times, including upon system reboot, periodic intervals, predetermined times, or any other time.

[0041] While the control aspect bits[j] of ENFB 460 and PRVS 470 in one or more aspects may be programmable and may be configured to be written at various times (and not require a system reboot), the control aspect bits[j] of ENFB 460 and PRVS 470 may be written according to one or more rules. That is, in one or more embodiments, setting the performance / security mode of the control aspect bits[j] in ENFB 460 and PRVS 470 is controlled by one or more control rules. In an embodiment, for ENFB[k] 460 at privilege level k, all control aspect bits[j] of ENFB[k][j] are writable by privilege level[k] and any higher privilege levels, and for PRVS 470 at privilege level[k], all control aspect bits[j] of PRVS[k][j] are writable by privilege level[k] and any higher privilege levels. That is, in an embodiment, a lower privilege level [k] cannot write the control aspect bit [j] of the ENFB 460 of a higher privilege level [k-1], and a lower privilege level [k] cannot write the control aspect bit [j] of the PRVS 470 of a higher privilege level [k-1].

[0042] During operation of the processor 102 or computing system 100, the control aspect bits [j] of the ENFB 460 and PRVS 470 may be read at various, programmable, or predetermined times during processor operation, in one or more embodiments, and reading the configuration register 250 does not require a reboot. In one or more embodiments, the configuration register is read multiple times during processing, in embodiments, at the start of an application. While the control aspect bits [j] may be read at multiple different times, the ability to read different privilege levels of the ENFB 460 and PRVS 470 is controlled, in one or more embodiments, by a set of access rules. In one or more embodiments, all control aspect bits [j] of the ENFB[k] 460 are readable by any privilege level 455[0] through 455[n-1], and in alternative embodiments, all control aspect bits of the ENFB 460 are readable by any lower privilege level. All control aspect bits [j] of the PRVS470 are readable only by the current privilege level [k] and any higher privilege level.

[0043] In one or more embodiments, the processor writes ENFB[k][j] in ENFB 460 for any privilege level[k] when it attempts to control the processor's behavior (e.g., security / performance operating modes) with respect to control aspect[j] for any privilege level below privilege level[k]. If a "1" or high bit is written to ENFB[k][j], the processor forces secure mode (operates in secure mode) of aspect[j] behavior for all privilege levels below privilege level k (e.g., privilege levels 455[k-1], 455[k-2], etc.), and if a "0" or low bit is written to ENFB[k][j], the processor relinquishes privilege level k's control over the behavior (e.g., secure mode / performance mode) of control aspect 480[j] at any privilege level below level[k]. In one or more embodiments, a processor writes PRVS[k][j] in PRVS 470 for any privilege level k when it attempts to control the behavior (security mode of operation / performance mode of operation) of its own level (e.g., privilege level k) with respect to control aspect[j] for any privilege level below privilege level[k]. If a "1" or high bit is written to PRVS[k][j], the processor forces a secure mode of operation for its own privilege level (e.g., privilege level k), and if a "0" or low bit is written to PRVS[k][j], the processor forces a performance mode for privilege level k, provided that a higher privilege level[k] does not force a secure mode.

[0044] The control values ​​for privilege level[k] and aspect[j] may be represented in embodiments as PRVS[k][j] or ENFB[k-1][j] or ENFB[k-2][j] or ... or ENFB[0][j]. Any privilege level above k can force a value of 1 = secure mode via ENFB[k-1][j] through ENFB[0][j]. If an operational mode (e.g., secure mode) is not forced by any privilege level above privilege level[k], either privilege level k or a higher privilege level can set / select secure mode / performance mode by setting the PRVS[k][j] bit for aspect[j].

[0045] 5 illustrates an example of a control register according to an embodiment in which an example of applying a control rule is utilized to determine the secure or performance mode of a control aspect [j] of privilege level [k]. In the example of FIG. 5, the value of PRVS[k][j] (black box 575 in PRVS 470) or ENFB[k-1][j] (not shown) or... or ENFB[1][j] (striped box 565 in ENFB 460) or ENFB[0][j] (striped box 566 in ENFB 460) determines the control of aspect [j] of privilege level [k]. Thus, the control of the performance or secure mode of control aspect [j] of privilege level [k] may be represented as PRVS[k][j] or ENFB[k-1][j] through ENFB[0][j].

[0046] 6 is an exemplary flowchart illustrating and describing a computer-implemented method, and more particularly, a method for dynamically controlling the operating mode of a processor, and specifically, a method for dynamically controlling whether a processor operates to execute instructions in a more secure mode or a more performance-oriented mode, according to an embodiment. While method 600 is described for convenience and is not intended to limit the disclosure as including a series of steps and / or multiple steps, it should be understood that process 600 need not be performed as a series of steps and / or the steps need not be performed in the order shown and described with respect to FIG. 6; the process may be integrated and / or one or more steps may be performed concurrently or the steps may be performed in the order disclosed or in another order.

[0047] In one or more embodiments, when an application is invoked, typically, all bits in all entries of both the ENFB and SRVS registers are initialized to performance mode at every position, e.g., the bits in the ENFB and PRVS fields / registers for all control aspects (control aspects 480'0'-480'm') at all privilege levels (privilege levels 455[0]-455[n]) are set to '0'. At some point during operation on the processor (e.g., while an application is running), a secure mode or secure configuration is warranted, desired, required, or needed for privilege level[k] or control aspect[j] at privilege level[k]. FIG. 6 illustrates an embodiment of a method 600 for changing (preferably dynamically, without restarting the application or the system) the performance configuration of privilege level[k] on a processor to secure mode, and in further embodiments, changing the performance configuration of control aspect[j] at privilege level[k] on a processor to secure mode. It should be understood that method 600 for changing to secure mode can be performed based on an entire privilege level (e.g., per privilege level), or at a finer granularity, based on a single control aspect at a privilege level (e.g., per control aspect within a particular privilege level). Method 600 is described with respect to changing from performance mode to secure mode based on a control aspect within a privilege level. It can also be understood that this process can be performed based on privilege level.

[0048] At 605, privilege level [k] initiates a change to a secure mode of operation. At 610, it is determined whether secure mode should be enforced for control aspect [j] at privilege level [k]. If control aspect [j] at privilege level [k] should be enforced (YES at 610), the process proceeds to 615, where it is checked whether the bit field for control aspect [j] at privilege level [k] is set to "1" (in other words, whether PRVS[k][j]=1). If control aspect [j] at privilege level [k] is not set to "1" (NO at 615, PRVS[k][j]=0), at 620, the control aspect entry [j] at privilege level [k] in the PRVS register is set (written) to "1" (e.g., by setting PRVS[k][j]=1), and the process proceeds to 625. If the control aspect [j] at privilege level [k] is set to “1” (“Yes” in 615, PRVS[k][j]=1), the process skips 620 and proceeds to 625.

[0049] At 625, it is determined whether secure mode is enforced for control aspect[j] at all privilege levels lower than privilege level[k]. That is, it is determined whether secure mode is enforced for control aspect[j] at all lower privilege levels [k+1] through [n], where "n" is the lowest privilege level. If secure mode is not enforced for control aspect[j] at any lower privilege level ("No" at 625), process 600 is completed as shown at 630. On the other hand, if it is determined that secure mode is enforced for control aspect[j] at a lower privilege level ("Yes" at 625), the process proceeds to 635, where it is determined whether control aspect[j] at privilege level[k] in the ENFB register is "1". In other words, if 625 is "yes" and secure mode needs to be forced for lower privilege levels, then at 635 it is determined whether ENFB[k][j] is set to or equal to 1. If the lower privilege level control aspect[j] in the ENFB register field is set to 1 ("yes" at 635) (i.e., ENFB[k][j]=1), then process 600 is complete, as shown at 640. If it is determined ("no" at 635) that the lower privilege level control aspect[j] is not set to 1 (i.e., ENFB[k][j]=0), then process 600 proceeds to 645.

[0050] At 645, for control aspect[j] at a privilege level lower than privilege level[k], a policy is searched for control of security mode / performance mode at privilege level[k]. At 650, it is determined whether the policy for control aspect[j] at privilege level[k] allows aspect[j] at the lower privilege level to enforce a secure configuration. If it is determined at 650 that the policy does not allow control aspect[j] at a lower privilege level (e.g., a privilege level lower than privilege level[k]) to enforce a secure configuration ("No" at 650), process 600 is completed, as shown at 655. If the policy allows control aspect[j] at a lower privilege level to enforce a secure mode or secure configuration ("Yes" at 650), the process continues to 660, where control aspect[j] at privilege[k] in the ENFB register is set to "1" at 660. In other words, ENFB[k][j] is set to 1 (ENFB[k][j]=1) at 660. The process for changing control aspect[j] at privilege level[k] is then completed, as shown at 665.

[0051] At some point, for example, during the execution of a software application, a performance mode (performance configuration) may be warranted, desired, requested, or required in the processor for privilege level [k] or for control aspect [j] at privilege level [k]. For example, the environment may warrant a secure mode of operation, and it may be beneficial and advantageous to operate in a secure mode, so the processor may operate in a secure mode at one or more privilege levels [k], or one or more control aspects [j] at privilege level [k], or both, and execute a software application, which may desire or trigger the processor to operate in performance mode. Figure 7 illustrates an embodiment of a method 700 for causing a process of changing (preferably dynamically, without restarting the application or the system) the secure mode of operation in a processor to a performance mode, and in a further embodiment, a process of changing the secure mode of operation of control aspect [j] at privilege level [k] in a processor to a performance mode. It should be understood that method 700 for changing to performance mode can be performed based on an entire privilege level (e.g., per privilege level) or, at a finer granularity, based on a single control aspect at a privilege level (e.g., per control aspect within a particular privilege level). Method 700 is described with respect to a process for attempting to change from secure mode to performance mode based on a control aspect within a privilege level. In one or more embodiments, for example, if a higher privilege level forces a secure mode of operation for a control aspect at a lower privilege level, the processor cannot change to performance mode.

[0052] At 705, privilege level[k] needs to be changed to the performance operating mode of aspect[j]. At 710, it is determined whether the PRVS register field for control aspect[j] at privilege level[k] in the PRVS register is set to "0" (in other words, whether PRVS[k][j]=0). If control aspect[j] at privilege level[k] is set to "0" ("Yes" at 710, PRVS[k][j]=0), process 700 continues to 720. If control aspect entry[j] at privilege level[k] in the PRVS register is not set (written) to "0" ("No" at 710) (e.g., PRVS[k][j]=1), process 700 proceeds to 715. That is, if the control aspect[j] at privilege level[k] is set to "1" ("No" in 710, PRVS[k][j] is not 0), process 700 proceeds to 715, where the bit in the PRVS register field of the control aspect entry[j] at privilege level[k] is set (written) to "1." After 715, process 700 proceeds to 720.

[0053] In 720, it is determined whether the ENFB register field of control aspect[j] at all privilege levels above privilege level[k] (i.e., all of privilege levels [k-1] through privilege level 0) is set to "0." If it is determined that the ENFB register field of control aspect[j] at all privilege levels above privilege level[k] is set to zero (YES in 720, ENFB[p][j]=0, p=privilege level(k-1) through privilege level 0), then a performance mode may be implemented (enabled) for control aspect[j] at privilege level[k]. If the ENFB register field of control aspect[j] for all privilege levels higher than privilege level[k] is not set to 0 ("No" in 720, ENFB[p][j] = 1, p = privilege level(k-1) to privilege level 0), the process proceeds to 730, where it checks whether a system call requests or allows the performance mode of control aspect[j] for each higher privilege level p (p = privilege level[k-1] to privilege level 0). In this regard, process 700 executes steps 720, 730, 735, 740, 745, and 750 for each privilege level higher than privilege level[k].

[0054] More specifically, at 730, for privilege level [k-1], the privilege level immediately above privilege level [k], the system call checks whether privilege level [k-1] requests or allows the performance mode of control aspect [j]. Process 700 proceeds to 735, where a policy is searched for privilege level [k-1] to determine control over the secure or performance mode of operation of control aspect [j] at a lower privilege level. At 740, it is determined whether the policy at privilege level [k-1] allows the performance mode of control aspect [j] at the lower privilege level. If the policy at privilege level [k-1] does not allow the performance mode to be used for control aspect [j] at the lower privilege level (No at 740), then at 745, the performance mode of control aspect [j] at privilege level [k] is not allowed. The processor remains in the secure mode of operation of control aspect [j] at privilege level [k].

[0055] If it is determined in 740 that the policy for privilege level [k-1] of control aspect [j] allows performance mode to be enabled for a lower privilege level (e.g., privilege level [k]) ("Yes" in 740), then ENFB[k-1][j] is set to "0" in 750. After 750, the process returns to 720, where it is determined whether the ENFB register field for control aspect [j] at the next highest privilege level [k-2] is set to "0." If the ENFB field register for control aspect [j] at privilege level [k-2] is not set to zero ("0"), then process 700 returns to step 720 for the next highest privilege level and repeats steps 730, 735, 740, 745, and 750 for privilege level [k-2] until steps 730 through 750 of the process have been performed for all of privilege levels [k-1] through 0 (the highest privilege level). After the highest privilege level (privilege level 0) is checked, at 750 the ENFB register field for control aspect[j] at privilege level 0 is set to "0" (ENFB[0][j]=0) and the process returns to 720, at 720 it is determined that ENFB[k][j]=0 and the process proceeds to 725, at 725 the performance mode for control aspect[j] at privilege[k] is enabled.

[0056] Although the system and process have been described in terms of the configuration and operation of a design in which a high bit (i.e., "1") is used to set the secure mode, it can be understood that a high bit (bit = 1) can be used to set the performance mode and a low bit (bit = 0) can be used to set the secure mode. It can also be understood that a processor or software application call can initialize the values ​​in the ENFB and PRVS register fields to the secure mode.

[0057] The present invention may be a system, a method, and / or a computer program product, which may include a computer-readable storage medium containing computer-readable program instructions for causing a processor to perform aspects of the present invention.

[0058] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. A non-exhaustive list of more specific examples of computer-readable storage media includes portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanically encoded devices such as punch cards or ridge-in-groove structures on which instructions are recorded, and any suitable combination thereof. As used herein, computer-readable storage media should not be construed as being ephemeral signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses passing through fiber optic cable), or electrical signals transmitted over wires.

[0059] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing / processing device or to an external computer or storage device over a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network). This network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface within each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage on a computer-readable storage medium within each computing / processing device.

[0060] Computer-readable program instructions for carrying out the operations of the present invention may be source or object code written in any combination of one or more programming languages, including assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or object code written in one or more programming languages, including object-oriented programming languages ​​such as Smalltalk®, C++, and conventional procedural programming languages ​​such as the “C” programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer as a standalone software package, partially on the user's computer and on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be to an external computer (e.g., via the Internet using an Internet Service Provider). In some embodiments, to carry out aspects of the present invention, electronic circuitry including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), may execute computer-readable program instructions to customize the electronic circuitry by utilizing state information of the computer-readable program instructions.

[0061] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0062] These computer-readable program instructions may be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to create a machine, where the instructions, executed by the processor of the computer or other programmable data processing apparatus, create means for performing the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams. These computer-readable program instructions may be stored on a computer-readable storage medium and capable of directing a computer, programmable data processing apparatus, or other device, or combination thereof, to function in a particular manner, such that the computer-readable storage medium on which the instructions are stored comprises an article of manufacture containing instructions for performing aspects of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.

[0063] The computer-readable program instructions may be loaded into a computer, other programmable data processing apparatus, or other device to cause a series of operable steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, such that the instructions, which execute on the computer, other programmable apparatus, or other device, perform the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.

[0064] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions, comprising one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions shown in the blocks may occur out of the order shown in the figures. For example, two blocks shown in succession may be executed substantially concurrently or may be executed in the reverse order, depending on the functionality involved. It is also noted that each block in the block diagrams and / or flowchart diagrams, and combinations of blocks included in the block diagrams and / or flowchart diagrams, may be implemented by a special-purpose hardware-based system that performs the specified functions or operations or executes a combination of special-purpose hardware and computer instructions.

[0065] Additionally, systems according to various embodiments may include a processor and logic integrated with and / or executable by the processor, configured to perform one or more of the processing steps enumerated herein. By integrated, we mean that the logic is embedded in the processor as hardware logic, such as an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), etc. By executable by the processor, we mean that the logic is hardware logic accessible by the processor, software logic (such as firmware, part of an operating system, part of an application program), etc., or some combination of hardware and software logic, which, when executed by the processor, is configured to cause the processor to perform a function. The software logic may be stored in any memory type known in the art, local and / or remote memory. Any processor known in the art may be used, such as a software processor module and / or hardware processor, such as an ASIC, FPGA, central processing unit (CPU), integrated circuit (IC), or graphics processing unit (GPU).

[0066] It will be apparent from the description provided above that multiple combinations may be created such that the various features of the systems and / or methods described above may be combined in any manner.

[0067] It will further be appreciated that embodiments of the present invention may be provided in the form of a service that is deployed for customers to provide the service on demand.

[0068] The description of various embodiments of the present invention is presented for illustrative purposes, but is not intended to be exhaustive and is not limited to the disclosed embodiments. Many changes and modifications that do not depart from the scope and spirit of the described embodiments will be apparent to those skilled in the art. The terms used in this specification are selected to best explain the principles of the embodiments, practical applications, or technical improvements beyond those found in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.

Claims

1. 1. A method for changing an operating mode of a processor without rebooting the processor, the method comprising: Initiating a configuration change in the processor from a performance mode to a secure mode of a control aspect at a privilege level; determining whether a bit for the control aspect at the privilege level in a privilege entry (PRVS) register field is set to secure mode; if the bit for the control aspect at the privilege level in the PRVS register field is not set to secure mode, setting the bit for the control aspect at the privilege level in the PRVS register field to secure mode, thereby enabling the secure mode for the control aspect at the privilege level in the processor; A method comprising:

2. The method further comprising: determining whether the processor enforces a secure mode of the control aspect for a lower privilege level; 2. The method of claim 1, wherein if it is determined not to enforce a secure mode of the control aspect for the lower privilege level, the method of changing to the secure mode of the control aspect at the privilege level is complete.

3. The processor: if it is determined that a secure mode of the control aspect is to be forced for the lower privilege level, determining whether the bit for the control aspect at the lower privilege level in a lower enforcement (ENFB) register field is set to secure mode; If it is determined that the bit in the ENFB register field of the control aspect at the lower privilege level is set to secure mode, the process of changing the control aspect at the privilege level to secure mode is completed. The method of claim 2 further comprising:

4. The processor: if it is determined that the bit in the ENFB register field for the control aspect at the lower privilege level is not set to secure mode, determining whether a policy for the control aspect at the privilege level allows the secure mode of the control aspect to be enforced for the lower privilege level; If the policy of the control aspect at the privilege level does not allow the secure mode of the control aspect at the lower privilege level to be enforced, the process of changing to the secure mode of the control aspect at the privilege level is completed. The method of claim 3 further comprising:

5. 5. The method of claim 4, wherein determining whether a policy of the control aspect at the privilege level allows for enforcement of the secure mode of the control aspect for the lower privilege level comprises searching, by the processor, the policy of the control aspect at the privilege level for enforcement of the secure mode of the control aspect for the lower privilege level.

6. The processor:

5. The method of claim 4, further comprising: setting the bit for the control aspect at the privilege level to secure mode in the ENFB register field if the policy for the control aspect at the privilege level allows for enforcing the secure mode for the control aspect at the lower privilege level.

7. 4. The method of claim 3, wherein upon invocation of an application, the bit in the ENFB register field and the bit in the PRVS register field of the control aspect at the privilege level are initially set to the performance mode.

8. 4. The method of claim 3, wherein the ENFB register field and the PRVS register field are in a decode unit within the processor, the decode unit decodes instructions for execution by the processor.

9. 4. The method of claim 3, wherein the bits in the ENFB register field and the PRVS register field are set to 1 for secure mode and set to 0 for performance mode.

10. 2. The method of claim 1, wherein the secure mode or performance mode of the processor of the control aspect at the privilege level is controlled by a software application.

11. The processor, in response to triggering a change from secure mode to performance mode of the control aspect at the privilege level, checking whether the bit in the PRVS register field of the control aspect at the privilege level is set to performance mode; responsive to the bit in the PRVS register field of the control aspect at the privilege level not being set to the performance mode, setting a bit in a service register field of the control aspect at the privilege level to the performance mode; checking whether the control aspect at the privilege level in the ENFB register field of all higher privilege levels is set to performance mode; in response to the control aspect at the privilege level in the ENFB register fields of all of the higher privilege levels being set to the performance mode, changing the processor to the performance mode of the control aspect at the privilege level; The method of claim 3 further comprising:

12. The processor: in response to the control aspects at the privilege level of the ENFB registers of all the higher privilege levels not being set to the performance mode; and requesting that the higher privilege level permit the performance mode of the control aspect at the higher privilege level; 12. The method of claim 11, wherein in response to the higher privilege level not allowing the performance mode of the control aspect at the privilege level, the processor does not transition to the performance mode of the control aspect at the privilege level.

13. requesting that the higher privilege level allow the performance mode of the control aspect at the higher privilege level, by the processor; retrieving a policy at the higher privilege level for the performance mode of the control aspect at the lower privilege level; checking whether the policy allows the performance mode of the control aspect at the privilege level; 13. The method of claim 12, further comprising: in response to the policy permitting the performance mode of the control aspect at the privilege level, the bit in the ENFB register field of the control aspect at the privilege level is set to the performance mode, thereby permitting the processor to transition to the performance mode of the control aspect at the privilege level.

14. The processor:

14. The method of claim 13, wherein looking up a policy of the higher privilege level for the performance mode of the control aspect at the lower privilege level and checking whether the policy allows the performance mode of the control aspect at the privilege level is performed for each privilege level and for each higher privilege level, and if the policy allows the performance mode of the control aspect at that privilege level, the bit in the ENFB register field of the control aspect at that privilege level is set to the performance mode, and then the processor checks whether the bit in the ENFB register field of the control aspect is set to the performance mode for all of the higher privilege levels.

15. 1. A method for changing an operating mode of a processor without rebooting the processor, comprising: In response to triggering a change from secure mode to performance mode of a control aspect at a privilege level, checking whether a bit in a privilege entry (PRVS) register field of said control aspect at said privilege level is set to performance mode; responsive to the bit in the PRVS register field of the control aspect at the privilege level not being set to the performance mode, setting a bit in a service register field of the control aspect at the privilege level to the performance mode; checking whether the control aspect at the privilege level of all higher privilege level subordinate forcing (ENFB) register fields is set to performance mode; in response to the control aspect at the privilege level in the ENFB register fields of all the higher privilege levels being set to the performance mode, changing the processor to the performance mode of the control aspect at the privilege level; A method comprising:

16. The processor, in response to the control aspects at the privilege level of the ENFB registers of all the higher privilege levels not being set to the performance mode; and requesting that the higher privilege level permit the performance mode of the control aspect at the higher privilege level; 16. The method of claim 15, wherein in response to the higher privilege level not allowing the performance mode of the control aspect at the privilege level, the processor does not transition to the performance mode of the control aspect at the privilege level.

17. requesting that the higher privilege level allow the performance mode of the control aspect at the higher privilege level, by the processor; retrieving a policy at the higher privilege level for the performance mode of the control aspect at the lower privilege level; checking whether the policy allows the performance mode of the control aspect at the privilege level; in response to the policy permitting the performance mode of the control aspect at the privilege level, the bit in the ENFB register field of the control aspect at the privilege level is set to the performance mode, thereby permitting the processor to transition to the performance mode of the control aspect at the privilege level; 17. The method of claim 16, further comprising:

18. The processor, 18. The method of claim 17, wherein looking up a policy of the higher privilege level for the performance mode of the control aspect at the lower privilege level and checking whether the policy allows the performance mode of the control aspect at the privilege level is performed for each privilege level and for each higher privilege level, and if the policy allows the performance mode of the control aspect at that privilege level, the bit in the ENFB register field of the control aspect at that privilege level is set to the performance mode, and then the processor checks whether the bit in the ENFB register field of the control aspect is set to the performance mode for all higher privilege levels.

19. The processor, Initiating a configuration change in the processor from a performance mode to a secure mode of a control aspect at a privilege level; determining whether the bit for the control aspect at the privilege level in the PRVS register field is set to secure mode; if the bit for the control aspect at the privilege level in the PRVS register field is not set to secure mode, setting the bit for the control aspect at the privilege level in the PRVS register field to secure mode, thereby enabling the secure mode for the control aspect at the privilege level in the processor; determining whether to enforce a secure mode of the control aspect for the lower privilege level; if it is determined that a secure mode of the control aspect is to be forced for the lower privilege level, determining whether the bit for the control aspect at the lower privilege level in a lower enforcement (ENFB) register field is set to secure mode; If it is determined that the bit in the ENFB register field of the control aspect at the lower privilege level is set to secure mode, the process of changing the control aspect at the privilege level to secure mode is completed.

16. The method of claim 15, further comprising:

20. 1. A computer system for processing information, said computer system comprising: at least one processor including one or more register files, at least one of said registers being a configuration register; the configuration register includes a privilege entry (PRVS) register field for each of one or more privilege levels, each PRVS register field for each privilege level including one or more control aspect entries for holding bits, and a lower force (ENFB) register field for a privilege level lower than each of the one or more privilege levels, each ENFB register field for each privilege level including one or more control aspect entries for holding bits, the control aspects of the PRVS register fields being equal in number to and corresponding to the control aspects of the ENFB register fields; the processor: Initiating a configuration change in the processor from a performance mode to a secure mode of a control aspect at a privilege level; determining whether the bit for the control aspect at the privilege level in the PRVS register field is set to secure mode; 1. A computer system configured and adapted to: if the bit for the control aspect at the privilege level in the PRVS register field is not set to secure mode, set the bit for the control aspect at the privilege level in the PRVS register field to secure mode, thereby enabling the secure mode for the control aspect at the privilege level in the processor.

21. the processor: determining whether to enforce a secure mode of the control aspect for the lower privilege level; if it is determined not to force the secure mode of the control aspect for the lower privilege level, the method for changing to the secure mode of the control aspect at the privilege level is completed; and if it is determined that a secure mode of the control aspect is to be forced for the lower privilege level, determining whether the bit for the control aspect at the lower privilege level in a lower enforcement (ENFB) register field is set to secure mode; 21. The computer system of claim 20, further configured and adapted to: if it is determined that the bit in the ENFB register field for the control aspect at the lower privilege level is set to secure mode, then completing the process of changing the control aspect at the privilege level to the secure mode.

22. the processor: if it is determined that the bit in the ENFB register field for the control aspect at the lower privilege level is not set to secure mode, determining whether a policy for the control aspect at the privilege level allows the secure mode of the control aspect to be enforced for the lower privilege level; If the policy of the control aspect at the privilege level does not allow the secure mode of the control aspect at the lower privilege level to be enforced, the process of changing to the secure mode of the control aspect at the privilege level is completed. further configured to perform 22. The computer system of claim 21, wherein determining whether a policy of the control aspect at the privilege level allows for enforcement of the secure mode of the control aspect for the lower privilege level comprises searching the policy of the control aspect at the privilege level for enforcement of the secure mode of the control aspect for the lower privilege level.

23. the processor:

23. The computer system of claim 22, further configured to set the bit for the control aspect at the privilege level to secure mode in the ENFB register field if the policy for the control aspect at the privilege level allows the secure mode for the control aspect at the lower privilege level to be enforced.

24. the processor: in response to triggering a change from secure mode to performance mode of the control aspect at the privilege level, checking whether the bit in the PRVS register field of the control aspect at the privilege level is set to performance mode; responsive to the bit in the PRVS register field of the control aspect at the privilege level not being set to the performance mode, setting a bit in a service register field of the control aspect at the privilege level to the performance mode; checking whether the control aspect at the privilege level in the ENFB register field of all the higher privilege levels is set to performance mode; in response to the control aspect at the privilege level in the ENFB register fields of all the higher privilege levels being set to the performance mode, changing the processor to the performance mode of the control aspect at the privilege level; 24. The computer system of claim 23, further configured to execute:

25. the processor: in response to the control aspects at the privilege level of the ENFB registers of all the higher privilege levels not being set to the performance mode; requesting that the higher privilege level permit the performance mode of the control aspect at the privilege level; in response to the higher privilege level not allowing the performance mode of the control aspect at the privilege level, the processor is further configured to not transition to the performance mode of the control aspect at the privilege level; requiring the higher privilege level to allow the performance mode of the control aspect at the privilege level; retrieving a policy at the higher privilege level for the performance mode of the control aspect at the lower privilege level; checking whether the policy allows the performance mode of the control aspect at the privilege level; in response to the policy permitting the performance mode of the control aspect at the privilege level, the bit in the ENFB register field of the control aspect at the privilege level is set to the performance mode, thereby permitting the processor to transition to the performance mode of the control aspect at the privilege level; 25. The computer system of claim 24, further comprising:

26. A computer program comprising program code means adapted to perform the method according to any of claims 1 to 19 when the computer program is run on a computer.

Citation Information

Patent Citations

  • Apparatus and method for controlling the execution of instructions

    JP2020525934A

  • Dynamic Configuration of a Computer Processor based on the Presence of a Hypervisor

    US20200073693A1