Apparatus and method for encoding monotonic counters

The novel encoding scheme for monotonic counters in set-only memory addresses counter failure issues by using unary coding with head, tail, and mid sections, and extension ranges, enhancing secure boot rollback protection efficiency.

WO2025149148A1PCT designated stage expired Publication Date: 2025-07-17HUAWEI TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/050302
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-08
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

Conventional monotonic counter solutions in set-only memory face challenges with counter increment failures due to insufficient space allocation, making it difficult to predict and manage update frequencies reliably.

Method used

A novel encoding scheme that allocates ranges in set-only memory for multiple monotonic counters, utilizing unary coding with head, tail, and optional mid sections, and extension ranges to efficiently use memory and reduce counter failures.

Benefits of technology

Significantly reduces counter increment failures, allowing for more efficient rollback protection in secure boot processes by effectively managing counter updates and extending memory usage when needed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024050302_17072025_PF_FP_ABST
    Figure EP2024050302_17072025_PF_FP_ABST
Patent Text Reader

Abstract

An apparatus and method for encoding monotonic counters stored in set-only memory is described. The disclosed embodiments statically allocate ranges in a set-only memory and dispose multiple unary encoded monotonic counters in each range. The monotonic counter encoding techniques provide an efficient use of the available set-only memory bits and significantly reduce counter increment failures. An extension range is also disclosed that allows counters to be successfully incremented after their statically allocated range has been filled. The disclosed embodiments are ideally suited for supporting rollback protection in secure boot processes and allow significantly more version updates to occur before a version increment failure is experienced.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] APPARATUS AND METHOD FOR ENCODING MONOTONIC COUNTERS

[0002] TECHNICAL FIELD

[0003] The aspects of the disclosed embodiments relate generally to computer security and more particularly to methods and apparatus for providing rollback protection in secure boot processes.

[0004] BACKGROUND

[0005] In computing, secure boot is a boot-time process that prevents unauthorized software and firmware images from loading on a computing device. A trusted vendor cryptographically signs authorized images. During loading, a boot process verifies the signatures prior to loading the image. While signature validation ensures integrity and authenticity, it does not provide protection from rollback attacks. A rollback attack is where an older version of an authorized image that includes a known vulnerability is loaded instead of the updated image that fixes the vulnerability. Rollback protection aims to prevent loading of obsolete images.

[0006] To support rollback protection, software vendors often include a version number in each signed image. Boot loaders can then check this version against a monotonic counter that is maintained within the computing apparatus and used to record the highest known version number of an image being loaded. When the monotonic counter value is greater than the version signed into an image, a rollback protection enabled boot loader will refuse to load the image.

[0007] A monotonic counter is an encoding of an integer variable that can be read and incremented but never decremented. Monotonic counters may be implemented as unary coded counters stored in set-only computer memory, such as an eFuse memory, thereby allowing counters to be incremented and preventing them from being decremented. Multiple counters can be allocated within set-only memory using fixed sizes or using unwritten bits as delimiters.

[0008] Conventional monotonic counter solutions statically allocate space for multiple counters in a set-only memory. When insufficient space is allocated for a counter, the counter may run out of room preventing further increments. Allocating space based on an assumed probability of updates can reduce counter failures, but predicting update frequency is difficult and often unreliable.

[0009] Thus, there is a need for improved apparatus and methods for encoding monotonic counters that can efficiently store rollback protection counters in a set-only type memory while reducing the occurrence of counter increment failure. Accordingly, it would be desirable to provide methods and apparatus that addresses at least some of the problems described above.

[0010] SUMMARY

[0011] The aspects of the disclosed embodiments are directed to apparatus and methods for encoding monotonic counters. The disclosed embodiments are capable of significantly reducing the occurrence of counter increment failures in systems that store monotonic counters in set-only computer memory. The aspects of the disclosed embodiments achieve these benefits through a novel encoding scheme that avoids counter failure by allowing multiple monotonic counters to efficiently use the same preallocated range of set-only memory.

[0012] According to a first aspect, the above and further objectives and advantages are obtained by an apparatus that includes a processor communicatively coupled to a random-access memory, a non-volatile memory, and a set-only memory. The processor is configured to allocate one or more ranges within the set-only memory, where a first range in the one or more ranges includes a unary coded first counter disposed within a head section and a unary coded second counter disposed within a tail section. The first counter is separated from the second counter by one or more unset bits. The processor checks whether there is sufficient space between the first counter and the second counter, and when sufficient space is available, the processor increments one of the first counter and the second counter. Incrementing the first counter includes setting a next unset bit adjacent the first counter, and incrementing the second counter includes setting a prior unset bit adjacent the second counter.

[0013] In a possible implementation form, the first range further includes a third counter disposed within a mid section and separated from each of the first counter and the second counter by one or more unset bits. The processor is further configured to, when sufficient space is available, increment the third counter by setting one of a prior unset bit and a next unset bit, where the prior unset bit and the next unset bit are adjacent the third counter. Including a third counter in a range further reduces the probability of a counter failure when the counters are employed in a rollback protected secure boot process.

[0014] In a possible implementation form, a mid section starting point of the third counter is centered between the first counter and the second counter. Centering the starting point of the third counter provides an easily implemented approach for locating the third counter while still providing a satisfactory reduction in counter failure.

[0015] In a possible implementation form, the mid section starting point is selected to proportionally split a space between the first counter and the second counter based on a current length and a relative sizes of the first counter and the second counter. Selecting a starting point for the third counter based on the current lengths and relative sizes of the first and second counter can further reduce the probability of counter failure by considering the number of counter increments already experienced by the first and second counters during the selection.

[0016] In a possible implementation form, allocating the set-only memory further includes allocating an extension range, and the processor is further configured to, when there is insufficient space, associate a first counter extension with a first filled counter, where the first counter extension is disposed adjacent a first end of the extension range and includes a first associated counter indication and a first counter extension value. The processor is configured to increment the first filled counter by setting a next unset bit adjacent the first counter extension value.

[0017] In a possible implementation form, the processor is further configured to, when there is insufficient space, associate a second counter extension with a second filled counter, where the second counter extension is disposed adjacent a second end of the extension range and includes a second associated counter indication and a second counter extension value. The processor is configured to increment the second filled counter by setting a prior unset bit adjacent the second counter extension value.

[0018] In a possible implementation form, the first counter, the second counter and the third counter comprise zero or more contiguous set bits. This ensures a unary encoding of the counters.

[0019] In a possible implementation form, the one or more ranges are statically allocated prior to runtime. Static allocation allows efficient use of the set-only memory.

[0020] In a possible implementation form, the non-volatile memory includes a plurality of images, and each of the first counter, and the second counter correspond to an individual one image in the plurality of images. The monotonic counter encoding techniques performed by the apparatus are ideally suited for tracking versions of software images to support rollback protection within secure boot processes.

[0021] In a possible implementation form of the apparatus, a length of each range in the one or more ranges is based on known priori probabilities of the plurality of images. According to a second aspect, the above and further objectives and advantages are obtained by a method for encoding monotonic counters. The method includes allocating one or more ranges within a set-only memory, where a first range in the one or more ranges includes a unary coded first counter disposed within a head section and a unary coded second counter disposed within a tail section. The first counter is separated from the second counter by one or more unset bits. The method proceeds by checking whether there is sufficient space between the first counter and the second counter, and when sufficient space is available, one of the first counter and the second counter is incremented. Incrementing the first counter includes setting a next unset bit adjacent the first counter, and incrementing the second counter includes setting a prior unset bit adjacent the second counter.

[0022] In a possible implementation form of the method, the first range further includes a third counter disposed within a mid section and separated from each of the first counter and the second counter by one or more unset bits. The method further includes incrementing the third counter by setting one of a prior unset bit and a next unset bit, where the prior unset bit and the next unset bit are adjacent the third counter. Including a third counter further reduces the likelihood of a counter failure.

[0023] In a possible implementation form of the method, where allocating the one or more ranges within the set-only memory further includes allocating an extension range, and the method further includes, when there is insufficient space, associating a first counter extension with a first filled counter. The first counter extension is disposed adjacent a first end of the extension range and includes a first associated counter indication and a first counter extension value. The method increments the first filled counter by setting a next unset bit adjacent the first counter extension value. Associating a first extension counter with the first failed counter further reduces the occurrence of counter failures.

[0024] In a possible implementation form of the method, when there is insufficient space, the method further includes associating a second counter extension with a second filled counter, where the second counter extension is disposed adjacent a second end of the extension range and includes a second associated counter indication and a second counter extension value. The method increments the second filled counter by setting a prior unset bit adjacent the second counter extension value. Associating a second extension counter with the second filled counter further reduces the occurrence of counter failures, while disposing two counter extensions in the same extension range allows efficient use of the allocated set-only memory.

[0025] In a possible implementation form of the method, each of the first counter and the second counter are associated with an individual one image in a plurality of images. The method for encoding monotonic counters is ideally suited for tracking versions of software images to support rollback protection within secure boot processes.

[0026] These and other aspects, implementation forms, and advantages of the exemplary embodiments will become apparent from the embodiments described herein considered in conjunction with the accompanying drawings. It is to be understood, however, that the description and drawings are designed solely for purposes of illustration and not as a definition of the limits of the disclosed invention, for which reference should be made to the appended claims. Additional aspects and advantages of the invention will be set forth in the description that follows, and in part will be obvious from the description, or may be learned by practice of the invention. Moreover, the aspects and advantages of the invention may be realized and obtained by means of the instrumentalities and combinations particularly pointed out in the appended claims.

[0027] BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In the following detailed portion of the present disclosure, the aspects of the disclosed embocdiments will be explained in more detail with reference to the example embodiments shown in the drawings, in which like references indicate like elements and: Figure 1 illustrates a diagram of an exemplary apparatus configured to encode multiple monotonic counters in a set-only memory incorporating aspects of the disclosed embodiments;

[0029] Figure 2 illustrates a pictorial diagram depicting an exemplary technique for encoding three monotonic counters within a single statically allocated range of set-only memory bits incorporating aspects of the disclosed embodiments;

[0030] Figure 3 illustrates a pictorial diagram depicting an exemplary technique for locating a starting point for a monotonic counter incorporating aspects of the disclosed embodiments;

[0031] Figure 4 illustrates an exemplary technique for encoding monotonic counters with an extension range incorporating aspects of the disclosed embodiments;

[0032] Figure 5 illustrates a flow chart of an exemplary method for encoding monotonic counters incorporating aspects of the disclosed embodiments;

[0033] Figure 6 illustrates a diagram showing an exemplary simulation of monotonic counter encoding techniques incorporating aspects of the disclosed embodiments;

[0034] Figure 7 illustrates a graph showing a comparative analysis of failure rates for various monotonic counter encoding techniques incorporating aspects of the disclosed embodiments; and

[0035] Figure 8 illustrates graphs showing a comparative analysis of the number of successful counter increments prior to the first counter failure for various monotonic counter encoding techniques incorporating aspects of the disclosed embodiments.

[0036] DETAILED DESCRIPTION OF THE DISCLOSED EMBODIMENTS

[0037] Referring to Figure 1, a block diagram of an exemplary apparatus 100 configured to encode multiple monotonic counters 154, 156 in a set-only memory 108 incorporating aspects ofthe disclosed embodiments is illustrated. The exemplary apparatus 100 of the disclosed embodiments is directed to a computing apparatus 100 employing improved monotonic counter encoding techniques 174 to store counters in a set-only memory 108. The exemplary apparatus 100 lowers the occurrence of version counter failures resulting from image updates, thereby improving the rollback protection provided by secure boot processes.

[0038] As shown in Figure 1, in one embodiment the exemplary apparatus 100 includes a processor 102 communicatively coupled to a random-access memory (RAM) 104, a non-volatile memory (NVM) 106 and a set-only memory. The processor 102 is generally configured to allocate one or more ranges 150, 152 within the set-only memory 108. A first range 150 in the one or more ranges 150, 152 comprises a unary coded first counter 154 disposed within a head section 162 and a unary coded second counter 156 disposed within a tail section 164. The first counter 154 is separated from the second counter (156) by one or more unset bits 172.

[0039] The processor 102 is also configured to check whether there is sufficient space 172 between the first counter 154 and the second counter 156. When sufficient space is available, the processor 102 is configured to increment one of the first counter 154 and the second counter 156.

[0040] In one embodiment, incrementing the first counter 154 comprises setting a next unset bit 166 adjacent the first counter 154. Incrementing the second counter 134 comprises setting a prior unset bit 168 adjacent the second counter 156.

[0041] The processor 102 generally includes any suitable processing device appropriate for use in a general purpose or specialized purpose processing apparatus. Examples of appropriate processors 102 include a high-performance multi-core computer processing device such as those used in large cloud computing data centers, a multi-core or single core microprocessor such as those used in workstations and laptop computers, a processing device embedded in a system such as a system on a chip (SoC), or any suitable or specialized processing device such as those used in mobile communications devices, telecommunications equipment, and smart devices configured for the internet of things (loT).

[0042] RAM 104 acts as the main memory of the apparatus 100 and provides storage for program instructions and data currently in use by the processor 102. Any suitable type of random-access memory may be advantageously employed in the exemplary apparatus 100 as desired.

[0043] NVM 106 retains data while the apparatus 100 is powered off and may include any suitable type of system storage such as a disk drive, solid state disk, or other non-volatile or read only memory as desired. Software images 110, 112, 114 are stored in NVM 106 where they may be read and loaded into RAM 104 or other desired run-time program storage by a boot loader 120 or other process. Beneficially, the boot loader 120 or other software loader may include secure boot processes to ensure integrity and authenticity of loaded images. Additionally, when desired, the boot loader 120 may include rollback protection to prevent outdated images from being loaded.

[0044] Set-only memory 108 is included in the exemplary apparatus 100 and is configured to store encoded monotonic counters. The monotonic counters are well suited for recording version information which may be used to support rollback protection in a secure boot process.

[0045] As used herein the term set-only memory refers to a class of computer memory where each bit in a set-only memory is initially in an unset state, and may be changed, through software, firmware, or hardware, to a set state. However, once a bit has been set, it can never be unset. A common type of set-only memory is referred to as an eFuse (electronic fuse) memory where each bit is constructed as a microscopic electronic fuse. Initially the fuses are in a conducting or unset state, and during operation, a fuse may be blown, i.e. changed to a non-conducting state. Importantly, once the fuse is blown, i.e. a bit is changed to its set or non-conducting state, it cannot be changed back to an unset or conducting state. EFuse memory is just one example of a set-only memory and is discussed here as an aid to understanding only. Any appropriate type of set-only memory may be advantageously employed as the set-only memory 108 in the herein disclosed embodiments without straying from the spirit and scope of the present disclosure.

[0046] Secure boot refers to a boot-time process that prevents unauthorized software and firmware from loading or executing in a computing apparatus, such as the exemplary apparatus 100. In typical secure boot processes, a trusted software vendor cryptographically signs an image, such as with an asymmetric cryptographic key, and includes the signature in metadata associated with the image. During boot, a secure boot enabled boot loader validates the image signature before allowing the image to be loaded.

[0047] Signature validation authorizes the image and prevents corrupted images from being loaded, however signature validation is not sufficient to prevent rollback attacks. Vulnerabilities or other security defects may be identified after a software image has been released to the field. When this occurs, a new version may be released that corrects known defects found in a prior release. A rollback attack occurs when a malicious actor causes the earlier version, which includes known vulnerabilities along with a valid signature, to be loaded, then exploits the known vulnerabilities.

[0048] Rollback protection refers to a process that aims to prevent loading of obsolete software and firmware images. For rollback protection purposes, an image is deemed as obsolete if a newer version of the same image has been signed by the vendor. To allow rollback protection enabled boot loaders to determine whether an image is obsolete, the vendor may include a version number in the signed image metadata. A monotonic counter may be maintained within a set-only memory 108 and used to record the highest known version number of an image. A monotonic counter is an encoding of an integer variable that can be read and incremented, but never decremented. When the version number included in the signed image, is lower than the monotonic counter value, a rollback protection enabled boot loader will refuse to load the image, thereby preventing a rollback attack.

[0049] When a newer version of an image is released, associated version counters need to be incremented to reflect the new version number. Any suitable approach for updating the counters may be advantageously employed. For example, a computing apparatus, such as the apparatus 100, may update the associated monotonic counter when a newer version of an image is received. Alternatively, a boot process may choose to update the version counter whenever a newer version is encountered during loading of an image. In certain embodiments is may be desirable to allow a vendor to control counter increments using any suitably secure mechanism.

[0050] A unary code is an integer encoding method that encodes a non-negative integer value as a sequence of set bits, where the number of set bits corresponds to the integer value. When storing a unary coded monotonic counter in memory, it may be desirable to follow the sequence of set bits by one or more unset bits to act as a terminator or delimiter allowing monotonic counter values to be separated when stored in the memory. In a unary code, each set bit in the code has an equivalent contribution to the encoded value. In contrast, other binary codes, such as binary integer codes, assign a different value to each set bit depending on the bit’s position in the codeword. A benefit of unary codes is that incrementing an encoded value is achieved by setting an additional bit. It is never necessary to unset a bit when incrementing a unary coded value. This property of unary codes allows them to be stored and incremented in set-only memory, and once incremented they can never be decremented.

[0051] For illustrative purposes, an unset bit is represented herein as a logic zero (0) and a set bit is represented herein as a logic one (1). Those skilled in the art will readily recognize that these logic states may be inverted, i.e. a logic one (1) may be used to represent an unset bit and a logic zero (0) to represent a set bit, without straying from the spirit and scope of the present disclosure.

[0052] Referring once again to Figure 1, there can be seen a depiction of an exemplary technique 174 for encoding monotonic counters in a set-only memory 108. The exemplary technique 174 statically allocates ranges 150, 152 in a set-only memory 108, and increments each counter in a fashion that makes efficient use of memory space while also reducing the risk of counter failure. When desired, each monotonic counter 154, 156 may be associated 126 with a software image 110, 112, 114, and used to support rollback protection. Counter failure, as used herein, refers to a condition where a counter increment fails due to insufficient memory space.

[0053] As used herein a range is an array of consecutive bits in a set-only memory. For illustrative purposes, ranges, such as the ranges 150, 152, allocated in the set-only memory 108 are depicted in the accompanying figures as an array of memory bits, such as the array of sixteen memory bits used to depict the range 150. An array of memory bits 150 is described as beginning at a first or left-hand end 160 and ending at a second or right-hand end 170. Following this convention, relative directional language is used to refer to various bits and locations within the set-only memory. The first unset bit 166 adjacent and to the right of the head section 162 is referred to as the “next” unset bit 166 adjacent the first counter 154, and the first unset bit 168 adjacent and to the left of the tail section 164 is referred to as the “prior” unset bit 168 adjacent the second counter 156.

[0054] Before any counters are incremented, the processor 102 is configured to statically allocate 124, or pre-partition, one or more ranges 150, 152 within the set only memory 108. Once a range has been allocated 124, its size remains fixed and does not change. The time during which the processor 102 is incrementing counters is referred to herein as “runtime”. As used herein ranges are statically allocated prior to runtime and counters are incremented during runtime. Each statically allocated range 150, 152 may have the same size or may be of different sizes as desired. In one embodiment, available set-only memory bits are evenly distributed among the allocated ranges 152, 154. Alternatively, ranges may be of different sizes. Some types of images may be known to receive more frequent updates, or be more likely to require fixes. It may be beneficial in certain embodiments to use known priori probabilities of image updates to help determine the lengths of each range.

[0055] In one embodiment, the set-only memory may be partitioned into fixed width ranges based on the number of images for which version information is to be tracked. With the illustrated monotonic counter encoding technique 174, two counters are stored in each range, one adjacent a first end 160 of the range 150, and the other adjacent a second end 170. When there are N images, N / 2 fixed width ranges are created, where the number of bits in each range is the total number of bits in the set-only memory divided by half the number of images. When the division is not even, remainder bits may all be included in the last range or distributed among the ranges in any suitable fashion. For example, the remainder bits may be included in ranges where the assigned version numbers are most likely to be incremented. The exemplary technique 174 is illustrated using two ranges 150, 152 of sixteen bits each, however any number of one or more ranges having any desired number of bits each may be advantageously employed.

[0056] Two monotonic counters 154, 156 are disposed in a range 150 with a unary encoded first counter 154 disposed within a head section 162 of the range 150, and a unary encoded second counter 156 disposed within a tail section 164 of the range 150. The first counter 154 is separated from the second counter 156 by one or more unset bits 172.

[0057] As used herein the term “head section” 162 refers to a string of contiguous set bits adjacent a first end 160 of a range 150, and the term “tail section” 164 refers to a string of contiguous set bits adjacent a second end 170 of the range 150. Each string of set bits 162, 164 represents the integer value of a unary coded counter. When desired, the string of contiguous set bits may include zero set bits to represent an integer value of zero.

[0058] When employing unary encoded counters to support rollback protection, each counter 154, 156 is associated 126 with a software image, and the integer value of the associated counter represents the highest known version number of the corresponding image. A rollback protected boot process will not load an image when the version number embedded in the image is less than the corresponding monotonic counter.

[0059] During operation, the processor executes 140 a boot loader 120 or other appropriate software component, and begins loading images 110, 112, 114 into memory 104 where they may be subsequently executed by the processor 102. The bootloader 120 reads 142 the next image 112 to be loaded from the NVM 106, and decodes 118 the corresponding monotonic counter from set-only memory 108. The value G of the corresponding counter represents the maximum version of the image 112 known to the apparatus 100. A rollback protection enabled boot loader validates the image 112, such as with a digital signature validation, and reads a version number X embedded in the signed image 112. The counter value G is then compared with the image version number X, and when the image version number is less than the counter value X < Ci, the image is deemed out of date and the boot loader 120 refuses to load the image. When the image version number X is greater than or equal to the counter value X > Ci, the boot loader loads the image and passes control to the next boot loader stage, which may be an entry point in the loaded image. When desired, the image version number X may be updated by encoding 116 the new version number and writing it 146 to the set-only memory 108.

[0060] When a software image is updated, the associated monotonic counter needs to be incremented accordingly. The processor 102 identifies 128 the counter associated with the image being updated and locates the range 150 in which the counter is located. The located range 150 is checked 130 to determine whether there is enough space available, i.e. enough unset bits between the counters 172, to increment the identified counter 154. Incrementing a unary encoded monotonic counter entails setting an unset bit adjacent the current monotonic counter value. For example, when incrementing the first counter 154, the adjacent unset bit 166 is set. At least two adjacent unset bits 172 are required to increment a counter 154, one unset bit 166 to be set during the increment and a second to act as a delimiter to demarcate the boundary between the first counter 154 and the second counter 156. When sufficient space is not available 130N a counter failure occurs 136 and the filled counter can no longer be incremented. As used herein the term “filled counter” refers to a counter that has only one adjacent unset bit.

[0061] When sufficient space is available 130Y, i.e. when there are two or more unset bits 172 between the first 154 and second 156 counters, the processor increments 134 the identified counter. Either counter 154, 156 in a range 150 having available space may be incremented 134. Incrementing the first counter entails setting the next unset bit 166 adjacent the first counter 154, and incrementing the second counter 156 entails setting the prior unset bit 168 adjacent the second counter 156.

[0062] Figure 2 illustrates a pictorial diagram depicting an exemplary technique 200 for encoding three monotonic counters 154, 156, 202 within a single statically allocated range 150 of set-only memory bits incorporating aspects of the disclosed embodiments. The exemplary technique 200 is appropriate for encoding monotonic counters in any suitable computing apparatus, such as the exemplary apparatus 100 described above. The exemplary technique 200 allows three monotonic counters 154, 156, 202 to be stored within a single statically allocated range 150 of set-only memory in a fashion that makes efficient use to the allocated space and significantly reduces the occurrence of counter failure.

[0063] The exemplary encoding technique 200 is similar to the encoding technique 172 described above where a unary encoded first counter 154 is disposed in a head section 162 adjacent a first end 160 of the range 150, and a unary encoded second counter 156 is disposed in a tail section 164 adjacent a second end 170 of the range 150. In the exemplary technique 200 a third counter 202 is disposed in a mid section 204 located between the head section 162 and the tail section 164 and is separated from each of the first counter 154 and the second counter by one or more unset bits 210, 212.

[0064] While being incremented, the first counter 154 begins at a first end 160 of the range 150 and grows toward the second end 170, and the second counter begins at the second end 170 of the range 150 and grows toward the first end 160. The third counter 202 begins at a mid section starting point in the unset space between the first counter 154 and the second counter 156, and grows in either direction, toward the first end 160 or toward the second end 170, as desired. As used herein the term “mid section starting point” refers to the first bit that is set on the initial increment of the third counter.

[0065] When disposing the third counter 202 within the mid section 204, a mid section starting point 214 is selected. The mid section starting point 214 becomes the first bit to be set upon incrementing the third counter. In one embodiment the mid section starting point may be centrally located at an unset bit located half way between the head section 162 and the tail section 164. Alternatively, the mid section starting point may be located half way between the first end 160 and the second end 170 of the range 150.

[0066] Figure 3 illustrates a pictorial diagram depicting an exemplary technique 300 for locating a mid section starting point 308 for a monotonic counter 310 incorporating aspects of the disclosed embodiments. Consider an embodiment where a first counter 304 is disposed in a head section 162, a second counter 306 is disposed in the tail section, and a third counter needs to be disposed in the unset bits between the first counter 304 and the second counter 306. It may be beneficial to select a mid section starting point 308 so that the number of unset bits left for the head section 162 and tail section 164 to grow are proportional to the amount of space the set bits in the head section 162 and tail section 164 are currently occupying. It is likely advantageous to leave more unset bits adjacent the counter that has already received more increments. As an example of a proportional selection, the number f unset bits allowed for the head section 304 may be computed as shown in equation 1 : h > x h+t i- h+ty’ where x represents the number of unset bits allowed for expansion of the head section, h represents the current length of the first counter 304, t represents the current length of the second counter 306, and / represents the total length of the range 302. Solving equation 1 forx gives the number of bits as shown in equation 2:

[0067] Since the index of the mid section starting point equals the current head section length h 6 plus the number of unset bits left for the head section to grow, the starting point of the mid section (assuming a zero based index) is given by equation 3: index = x + h = — =(6)(21)14 h+t 6+3 (3)

[0068] As illustrated in Figure 3, the mid section starting point 308 allows a proportional number of unset bits for each of the first 304 and second 306 counters to grow.

[0069] Figure 4 illustrates an exemplary technique 400 for extending encoded monotonic counters incorporating aspects of the disclosed embodiments. Over time, monotonic counters can grow to consume all available space, leading to counter failures. An extension range 450 is a mechanism that helps avoid counter failures by associating additional space with a filled counter at runtime. The exemplary technique 400 illustrates two statically allocated ranges 150, 152 with three counters 402, 404, 406 in the first range 150 and three counters 408, 410, 412 in the second range.

[0070] An extension range 450 may be statically allocated along with the one or more ranges 150, 152 and like the one or more allocated ranges, an extension range 450 does not change size at runtime. An extension range 450 provides space for two counter extensions, a first counter extension 414 disposed adjacent a first end 426 of the extension range 450, and a second counter extension 416 disposed adjacent a second end 428 of the extension range 450. Each counter extension 414, 416 includes a counter indication 418, 422 used to identify the associated counter, and a counter extension value 420, 422 used to provide additional space for counter increments.

[0071] As discussed above, before incrementing a counter, the exemplary apparatus 100 checks 130 whether there is sufficient space available to perform the increment, and when space is not available 130N, a counter failure occurs. When a counter extension is available, the counter failure may be avoided by associated the available counter extension with the filled counter at runtime.

[0072] For example, as illustrated in Figure 4, there is only one unset bit 418 between the first counter 402 and the second counter 404, thus, there is insufficient space to increment the first counter 402 and the first counter may be referred to as a filled counter. To increment the first filled counter 402 a first counter extension 414 is associated with the first filled counter 402 and the next unset bit 430 adjacent the first counter extension value 420 is set. Similarly, a second filled counter 410 may be incremented by associating a second counter extension 416 with the second filled counter 410 and setting the prior unset bit 432 adjacent the second counter extension value 424. Note, the extension range 450 illustrated in Figure 4 depicts the state of the extension range 450 after the above first filled counter and second filled counter increments have been completed.

[0073] Figure 5 illustrates a flow chart of an exemplary method 500 for encoding monotonic counters incorporating aspects of the disclosed embodiments. The exemplary method 500 is appropriate for encoding monotonic counters stored in a set-only memory in a computing apparatus such as the exemplary apparatus 100 described above. The exemplary method 500 significantly reduces the occurrence of counter failure in applications where the monotonic counters are employed as version counters to support rollback protection within a secure boot process.

[0074] In one embodiment the exemplary method 500 is employed in a computing apparatus having a set-only memory configured to store a plurality of monotonic counters. One or more ranges are allocated 502 within the set-only memory. Once allocated, the size of the allocated ranges does not change. The ranges may all be the same size or they may be of varying sizes as desired. Each statically allocated range includes a unary encoded first counter disposed within a head section of the range and a unary encoded second counter disposed within a tail section of the range. The first counter is adjacent a first end of the range and the second counter is adjacent a second end of the range. The first counter is separated from the second counter by one of more unset bits.

[0075] When either one of the first counter and the second counter needs to be incremented, the range is checked 504 to determine if there is sufficient space between the first counter and the second counter to allow the counter to be incremented. In order to increment a counter, there needs to be two or more unset bits between the first counter and the second counter, one unset bit for a delimiter and a second unset bit to be set when incrementing the counter, thus sufficient space as used herein refers to two or more unset bits between the counters.

[0076] When sufficient space is available 506, one of the first counter and the second counter may be incremented 510. The first counter, which is adjacent a first end of the range, is incremented by setting the next unset bit adjacent the first counter. Setting the next adjacent bit increases the number of consecutive set bits in the unary coded counter by one thereby incrementing the value of the counter by one. Similarly, the second counter, which is adjacent a second end of the range, is incremented by setting the prior unset bit adjacent the second counter.

[0077] In one embodiment it may be beneficial to include a third counter disposed within a mid section of the range, where the third counter is separated from each of the first counter and the second counter by one or more unset bits. At least one unset bit is required between any two counters in the same range to allow the set bits belonging to one counter to be distinguished from the set bits belonging to the other counter. When space is available 504, i.e. there are two or more bits separating the third counter from another counter in the same range, the third counter may be incremented. The third counter, being disposed between the other two counters may grow in either direction, thus incrementing 510 the third counter may be achieved by setting either one of a next unset bit adjacent one side of the third counter or a prior unset bit adjacent the other side of third counter.

[0078] It may be advantageous in certain embodiments to include additional protection against counter failure by incorporating an extension range. When allocating 502 the one or more ranges, an extension range may be allocated 502 as well. The extension range is statically allocated along with the one or more ranges and like the one or more ranges does not change size once it has been allocated.

[0079] An extension range may be configured to support two counter extensions. A first counter extension may be disposed adjacent a first end of the extension range, and a second counter extension may be disposed adjacent a second end of the extension range. A counter extension includes a counter indication, also referred to as a filled counter indication, indicating the counter that is associated with this counter extension. Along with the filled counter indication, each extension counter includes a counter extension value. The counter extension value provides additional space to be used when incrementing a filled counter.

[0080] When it is determined 508 that there is insufficient space available to increment a counter, a first counter extension is associated 516 with the first filled counter. The first counter extension is adjacent a first end of the extension range and includes a first filled counter indication and a first counter extension value. Associating 516 the first counter extension with the first filled counter is achieved by setting the first filled counter indication to a value corresponding with the first filled counter. The first filled counter may then be incremented 518 by logically extending the first filled counter into the first counter extension value and setting the next unset bit adjacent the first counter extension value.

[0081] Similarly, when it is determined 508 that a second counter has insufficient space avail for an increment, a second counter extension is associated 520 with the second filled counter. The second filled counter may then be incremented 522 by logically extending the second filled counter into the second counter extension value and setting the prior unset bit adjacent the second counter extension value.

[0082] Figure 6 illustrates a diagram showing an exemplary simulation of monotonic counter encoding techniques incorporating aspects of the disclosed embodiments. The exemplary simulation combines two of the above-described encoding techniques. The encoding technique 174 illustrated in Figure 1, where two unary encoded monotonic counters are disposed within the head and tail sections of a statically allocated range, is combined with the extension range technique 400 illustrated in Figure 4, where a counter extension is associated with each of a first and second filled counter.

[0083] The simulation 600 is based on twelve (12) counters and assumes a 256-bit set-only memory. Thirty -two (32) bits are statically allocated for an extension range 604 and the remaining 224 bits are split into six ranges 602 to hold the twelve counters. With first technique 174, each range includes two counters so six ranges 602 are required to support twelve counters, and each range will have 224 / 6 = 37 bits with the two remainder bits being added to the last range 602. To improve readability, each of the seven ranges (six counter ranges 602 and an extension range 604) is shown on a different line in the diagram.

[0084] As images are updated the associated counters are incremented and the state of the set-only memory is updated. Three memory states at various point in the simulation are shown in the illustrated diagram 600. The memory state after one version update 606 shows a single bit 612 set in the eleventh counter. A second memory state 608 is illustrative of an interim state 608 where numerous counter increments have been performed but no counter failures have yet occurred. In the simulation counter increments occur randomly resulting in some counters receiving a large number of increments and others receiving only a few increments.

[0085] The final state 610 shown in the diagram, depicts a set-only memory state occurring after two counters have filled their range 622 and overflowed into the counter extensions disposed in the extension range 604. As discussed above, each counter extension includes a version indication 618, 620 along with a counter extension value. In the illustrated embodiment a low short semi-fixed length code 614 is used to indicate which counter is associated with each counter extension 604. The first counter extension 618 is associated with counter index 8 and the second counter extension 620 is associated with counter index 9. For reference, the final counter values for each image represented by the final set-only memory state 610 are listed 624 below the final set-only memory state 602.

[0086] Comparative analysis of the presently disclosed monotonic counter encoding techniques shows significant improvement over conventional approaches. Experimental results comparing conventional techniques with a few of the presently disclosed embodiments are discussed below. The conventional technique used for comparison pre-partitions the set-only memory into ranges and implements a single monotonic counter in each range.

[0087] The comparative analysis was performed by running simulations of each technique based on a two hundred fifty-six (256) bit set-only memory. In the following experimental results, an upper-case letter \ represents the number of counters, and a lowercase n represents the number of counter updates in the experiment (in total). The probability of counter increments was based on Zipfs distribution and were assigned to each counter randomly. The counter update probabilities are: P±= =

[0088] = y / F,v ' ■■■ , where HNis the .hharmonic number. The simulations computed the number of counter failures. Where the number of counter failures represents the number of times the counter being updated ran out of bits resulting in a failure to increment the counter. The simulation was repeated 512 times with 128 image updates, n=128, and a varying number of images, N=8, 12, 16, and 18.

[0089] Figure 7 illustrates a graph 700 showing a comparative analysis of failure rates for various monotonic counter encoding techniques incorporating aspects of the disclosed embodiments. The results illustrated in the graph 700 include three presently disclosed embodiments. Technique 1 (Tech.1 ) corresponds to the technique 174 described above and with respect to Figure 1 and incorporates two counter per range disposed in the head and tail section (head+tail). Technique 2 (Tech.2) corresponds to the technique 200 described above and with respect to Figure 2 and incorporates three counters per range disposed in the head, tail, and mid sections (head+mid+tail). Technique 3 (Tech.3) combines Technique 2 with the technique 400 described above and with respect to Figure 4 which incorporates an extension range (32 runtime assigned bits).

[0090] The Graph 700 depicts the average number of version increment failures encountered during the 512 simulation runs along a vertical axis increasing upwards, and shows results for each simulated technique along the horizontal axis grouped by the number of counters used in each simulation run. As can be seen in the Graph 700, the techniques for encoding monotonic counters disclosed herein significantly reduce the average number of version increment failures encountered when incrementing counters stored in set-only memory.

[0091] Figure 8 illustrates graphs 800 showing a comparative analysis of the number of successful counter increments prior to the first counter failure for various monotonic counter encoding techniques incorporating aspects of the disclosed embodiments. The average number of successful counter increments before the first failed increment occurs is depicted along the vertical axis increasing upwards. The simulated techniques and horizontal axis depictions used in Figure 8 are the same as described above and with respect to Figure 7. As can be seen in the graph 800, the disclosed embodiments provide significantly more successful counter increments before encountering a counter failure than do the conventional solutions.

[0092] Improvements provided by the disclosed embodiments can be summarized as follows:

[0093] • The presently disclosed embodiments significantly decrease the average number of failed version counter increments as compared to prior art. With sixteen images (A=16) the presently disclosed embodiments encounter an average of three (3) failures as compared with twenty-nine (29) for the prior art. With eight images (A=8) the presently disclosed embodiments encounter no (zero) failures while the prior art encounters and average of sixteen (16) failures. • The presently disclosed embodiments are significantly less likely to run out of bits in the set-only memory for skewed (non-uniform) version update probabilities. With sixteen images (JV=16) the prior art solution failed on the fifty fourth (54) update, while the presently disclosed embodiments did not encounter any failures until the one hundred sixteenth (116) update.

[0094] Thus, while there have been shown, described, and pointed out, fundamental novel features of the invention as applied to the exemplary embodiments thereof, it will be understood that various omissions, substitutions and changes in the form and details of devices and methods illustrated, and in their operation, may be made by those skilled in the art without departing from the spirit and scope of the presently disclosed invention. Further, it is expressly intended that all combinations of those elements, which perform substantially the same function in substantially the same way to achieve the same results, are within the scope of the invention. Moreover, it should be recognized that structures and / or elements shown and / or described in connection with any disclosed form or embodiment of the invention may be incorporated in any other disclosed or described or suggested form or embodiment as a general matter of design choice. It is the intention, therefore, to be limited only as indicated by the scope of the claims appended hereto.

Claims

CLAIMSWhat is claimed is:

1. An apparatus (100) comprising: a processor (102) communicatively coupled to a random-access memory (104), a non-volatile memory (106), and a set-only memory (108), wherein the processor (102) is configured to: allocate one or more ranges (150, 152) within the set-only memory (108), wherein a first range (150) in the one or more ranges (150, 152) comprises a unary coded first counter (154) disposed within a head section (162) and a unary coded second counter (156) disposed within a tail section (164), wherein the first counter (154) is separated from the second counter (156) by one or more unset bits (172); check whether there is sufficient space (172) between the first counter (154) and the second counter (156); and when sufficient space is available, increment one of the first counter (154) and the second counter (156), wherein incrementing the first counter (154) comprises setting a next unset bit (166) adjacent the first counter (154), and incrementing the second counter (134) comprises setting a prior unset bit (168) adjacent the second counter (156).

2. The apparatus (100) according to claim 1, wherein the first range (150) further comprises a third counter (202) disposed within a mid section (204) and separated from each of the first counter (154) and the second counter (156) by one or more unset bits (210, 212), and wherein the processor (102) is further configured to: when sufficient space is available, increment the third counter (202) by setting one of a prior unset bit (206) and a next unset bit (208), wherein the prior unset bit (206) and the next unset bit (208) are adjacent the third counter (202).

3. The apparatus (100) according to any one of the preceding claims wherein a mid section starting point (214) of the third counter (202) is centered between the first counter (154) and the second counter (156).

4. The apparatus (100) according to any one of the preceding claims wherein the mid section starting point (308) is selected to proportionally split a space (312) between the first counter (304) and the second counter (306) based on a current lengths and a relative sizes of the first counter (304) and the second counter (306).

5. The apparatus (100) according to any one of the preceding claims wherein, allocating the set-only memory (108) further comprises allocating an extension range (450), and the processor (102) is further configured to, when there is insufficient space: associate a first counter extension (414) with a first filled counter (402), wherein the first counter extension (414) is disposed adjacent a first end (426) of the extension range (450) and comprises a first associated counter indication (418) and a first counter extension value (420); and increment the first filled counter (402) by setting a next unset bit (430) adjacent the first counter extension value (420).

6. The apparatus (100) according to any one of the preceding claims wherein the processor (102) is further configured to, when there is insufficient space (130N):associate a second counter extension (416) with a second filled counter (410), wherein the second counter extension (416) is disposed adjacent a second end (428) of the extension range (450) and comprises a second associated counter indication (422) and a second counter extension value (424); and increment the second filled counter (410) by setting a prior unset bit (432) adjacent the second counter extension value (424).

7. The apparatus (100) according to any one of the preceding claims wherein the first counter (154), the second counter (156) and the third counter (202) comprise zero or more contiguous set bits.

8. The apparatus (100) according to any one of the preceding claims wherein the one or more ranges (150, 152) are statically allocated prior to runtime.

9. The apparatus (100) according to any one of the preceding claims wherein the non-volatile memory (106) comprises a plurality of images (110, 112, ... 114), and wherein each of the first counter (154), and the second counter (156) correspond to an individual one image (110, 114) in the plurality of images.

10. A method (500) for encoding monotonic counters, the method (500) comprising: allocating (502) one or more ranges within a set-only memory, wherein a first range in the one or more ranges comprises a unary coded first counter disposed within a head section and a unary coded second counter disposed within a tail section, wherein the first counter is separated from the second counter by one or more unset bits; checking (504) whether there is sufficient space between the first counter and the second counter; and when sufficient space is available (506), incrementing (510) one of the first counter and the second counter, wherein incrementing the first counter comprises setting a next unset bit adjacent the first counter, and incrementing the second counter comprises setting a prior unset bit adjacent the second counter.

11. The method (500) according to claim 10 wherein the first range further comprises a third counter disposed within a mid section and separated from each of the first counter and the second counter by one or more unset bits, the method (500) further comprises: incrementing (510) the third counter by setting one of a prior unset bit and a next unset bit, wherein the prior unset bit and the next unset bit are adjacent the third counter.

12. The method (500) according to any one of claims 10 and 11 wherein allocating (502) the one or more ranges within the set- only memory further comprises allocating an extension range, and the method (500) further comprises, when there is insufficient space (508): associating (516) a first counter extension with a first filled counter, wherein the first counter extension is disposed adjacent a first end of the extension range and comprises a first associated counter indication and a first counter extension value; and incrementing (518) the first filled counter by setting a next unset bit adjacent the first counter extension value.

13. The method (500) according to claim 12 further comprising, when there is insufficient space (508): associating (520) a second counter extension with a second filled counter, wherein the second counter extension is disposed adjacent a second end of the extension range and comprises a second associated counter indication and a second counter extension value; and incrementing (522) the second filled counter by setting a prior unset bit adjacent the second counter extension value.

14. The method (500) according to any one of claims 10 through 13 wherein each of the first counter and the second counter are associated with an individual one image in a plurality of images.

Citation Information

Patent Citations

  • Memory system

    US20210124529A1

  • Logic circuitry

    WO2022186812A1