Black box circuitry for data processing apparatus

Integrating black box circuitry on chiplets within data processing systems captures event logs to diagnose software attacks, improving safety-critical system reliability and reducing downtime.

WO2025224415A1PCT designated stage Publication Date: 2025-10-30ARM LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/GB2025/050443
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-25
Filing Date
2025-03-05
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

Safety-critical data processing systems are vulnerable to software attacks, making it difficult to diagnose and mitigate such attacks, leading to potential system downtime and loss of critical functionality.

Method used

Integrate black box circuitry onto chiplets within the data processing apparatus to capture an event log of telemetry data before and after anomalous events, providing diagnostic insights and enhancing security through cryptographic attestation and immutability.

Benefits of technology

Facilitates rapid diagnosis of software attacks by capturing detailed telemetry data, reducing system downtime, and ensuring the integrity of the event log, thus enhancing the reliability of safety-critical systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure GB2025050443_30102025_PF_FP_ABST
    Figure GB2025050443_30102025_PF_FP_ABST
Patent Text Reader

Abstract

A data processing apparatus is implemented on one or more chiplets. The data processing apparatus comprises processing circuitry to perform data processing; memory storage circuitry to store data and instructions for processing by the processing circuitry; and black box circuitry responsive to detection of occurrence of an anomalous event indicative of a risk of loss of safety-critical functioning of the data processing apparatus, to capture an event log of telemetry data indicative of behaviour of the data processing apparatus associated with timepoints before or after the occurrence of the anomalous event. The black box circuitry is integrated onto at least one of the one or more chiplets of the data processing apparatus.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] BLACK BOX CIRCUITRY FOR DATA PROCESSING APPARATUS

[0002] The present technique relates to the field of data processing.

[0003] A data processing apparatus may comprise processing circuitry for performing data processing and memory storage circuitry for storing data and instructions for processing by the processing circuitry. Such a data processing apparatus may sometimes be vulnerable to software attacks, where an attacker may attempt to exploit vulnerabilities in software processed by the processing circuitry to cause the software to function incorrectly or to give the attacker access to information stored in the memory that the attacker should not otherwise access.

[0004] At least some examples of the present technique provide a data processing apparatus implemented on one or more chiplets, comprising: processing circuitry to perform data processing; memory storage circuitry to store data and instructions for processing by the processing circuitry; and black box circuitry responsive to detection of occurrence of an anomalous event indicative of a risk of loss of safety-critical functioning of the data processing apparatus, to capture an event log of telemetry data indicative of behaviour of the data processing apparatus associated with timepoints before or after the occurrence of the anomalous event; wherein the black box circuitry is integrated onto at least one of the one or more chiplets of the data processing apparatus.

[0005] At least some examples of the present technique provide a system comprising: the data processing apparatus described above, implemented in at least one packaged chip; at least one system component; and a board, wherein the at least one packaged chip and the at least one system component are assembled on the board.

[0006] At least some examples of the present technique provide a chip-containing product comprising the system described above, wherein the system is assembled on a further board with at least one other product component.

[0007] At least some examples of the present technique provide computer-readable code for fabrication of a data processing apparatus as described above. The computer-readable code may be stored on a computer-readable storage medium. The storage medium may be a non- transitory storage medium.

[0008] At least some examples of the present technique provide a method comprising: performing data processing on a data processing apparatus implemented on one or more chiplets, the data processing apparatus comprising processing circuitry to perform the data processing and memory storage circuitry to store data and instructions for processing by the processing circuitry; and in response to detection of occurrence of an anomalous event indicative of a risk of loss of safety- critical functioning of the data processing apparatus, capturing an event log of telemetry data indicative of behaviour of the data processing apparatus associated with timepoints before or after the occurrence of the anomalous event; wherein the event log is captured using black box circuitry integrated onto at least one of the one or more chiplets of the data processing apparatus. At least some examples of the present technique provide a chiplet for a data processing apparatus, the chiplet comprising: black box circuitry responsive to detection of occurrence of an anomalous event indicative of a risk of loss of safety-critical functioning of a data processing apparatus, to capture an event log of telemetry data indicative of behaviour of the data processing apparatus associated with timepoints before or after the occurrence of the anomalous event; and internal signal paths to communicate between the black box circuitry and other portions of the data processing apparatus, said internal signal paths being separate from input / output interface circuitry used by the data processing apparatus to communicate with external devices external to the data processing apparatus according to an input / output interface protocol.

[0009] Further aspects, features and advantages of the present technique will be apparent from the following description of examples, which is to be read in conjunction with the accompanying drawings, in which:

[0010] Figure 1 illustrates an example of a data processing apparatus comprising black box circuitry;

[0011] Figure 2 illustrates an example where the data processing apparatus is implemented on multiple chiplets;

[0012] Figure 3 illustrates an example of functions of the black box circuitry in a pre-event mode; Figure 4 illustrates an example of functions of the black box circuitry in a post-event mode; Figure 5 illustrates steps for capturing an event log in response to detection of an anomalous event; and

[0013] Figure 6 illustrates a particular example of steps for capturing an event log using the black box circuitry; and

[0014] Figure 7 illustrates a system and a chip-containing product.

[0015] A data processing apparatus is implemented on one or more chiplets, and comprises processing circuitry to perform data processing, and memory storage circuitry to store data and instructions for processing by the processing circuitry. A malicious party may attempt to mount a software attack on the apparatus to cause incorrect functioning of the apparatus. Various kinds of attacks are possible, such as return oriented programming attacks, denial of service attacks, etc. In safety-critical processing systems designed to carry out a safety-critical function, the consequences of such an attack can be severe. For example, for processors designed for use in automotive, medical or public infrastructure applications, if an attack is successful, the safety- critical functioning of the processing apparatus cannot be assured. However, in practice, if an attack occurs and is successful, it can be very difficult for a system operator to determine after the event how and why the attack was carried out. Hence, a successful software attack on a safety-critical system can cause an extended period when the system is out of action, while the operators attempt to detect and eliminate the attack.

[0016] In the examples discussed below, the data processing apparatus comprises black box circuitry responsive to detection of occurrence of an anomalous event indicative of a risk of loss of safety-critical functioning of the data processing apparatus, to capture an event log of telemetry data indicative of behaviour of the data processing apparatus associated with timepoints before or after the occurrence of the anomalous event. The black box circuitry is integrated onto at least one of the one or more chiplets of the data processing apparatus. Hence, the black box circuitry is designed as an integral part of a processor chip product (e.g. a single chiplet serving as a system on chip, or a set of multiple chiplets packaged into a semiconductor package). The black box circuitry can capture an event log which can give system investigators insight into what was happening on the chip / chiplets around the time when an anomalous event occurred. This can provide useful information for identifying the cause of software attacks which disrupt safety-critical functionality. For example, the event log can assist with pinpointing the specific application or portion of an application that was corrupted to enable the attack. Therefore, providing the data processing apparatus with integrated black box circuitry can provide better diagnosis for malicious software attacks, which can help reduce the downtime of a safety-critical system.

[0017] In some examples, the black box circuitry may sign the event log to enable attestation of a source of the event log. This allows an operator investigating a possible attack to attest that the event log used for forensic analysis was generated by trusted circuitry, rather than being a fake event log that an attacker may have attempted to substitute for the real event log. Hence, by using signed attestation, trust in the event log can be increased, to support forensic analysis after an anomalous event has occurred.

[0018] For example, the signing may be based on applying a cryptographic signature to the event log. For example, the signing may be based on a public key infrastructure. For example, the black box circuitry may sign the event log using a private key unique to the black box circuitry, and the signature may be verifiable using a corresponding public key which is associated with a digital certificate for attesting to the identity of the black box circuitry.

[0019] In some examples, the black box circuitry may perform an immutability-protecting action to protect the event log against tampering. This can increase trust that an attacker has not been able to substitute fake event log data for the real data in an attempt to evade detection.

[0020] For example, the black box circuitry may generate at least one event log digest associated with the event log, each event log digest derived from at least a portion of the event log and providing a verification value for detection of tampering with the event log. The function used to derive the digest from the portion of the event log may be a cryptographic function, for example. For example, the digest may be generated using a digest generating function for which the probability of an attacker being able to guess the correct digest value for a given set of input data may be negligible, so that it can be assumed that if a digest value generated from a given event log at the point of analysis still matches the corresponding digest value generated by the black box circuitry at the time of generating the event log, then it can be trusted that there has been no tampering with the event log since it was generated. This makes it much harder for attackers to evade detection. In some examples, the black box circuitry may transmit the at least one event log digest to an external device external to the data processing apparatus or to at least one neighbour chiplet of the data processing apparatus other than the at least one chiplet comprising the black box circuitry. This can be helpful to increase robustness against attack, since if an attacker has compromised circuitry on one chiplet, it may be less likely that they have also compromised a neighbour chiplet or an external device, so by transmitting at least the event log digest to a neighbour chiplet or external device, it is less likely that the attacker can also intercept or substitute the event log digest, and so greater defence against tampering is provided.

[0021] In some examples, the black box circuitry may associate timestamps with the event log to enable synchronisation of timepoints associated with different streams of telemetry data captured in the event log. Different sources of telemetry data may be located in parts of the chiplet / multi- chiplet system that operate without any synchronized clock source, so timestamping can be helpful to ensure correlation. For example, the black box circuitry may use its own timekeeping mechanism to determine a timestamp value and communicate this to other sources of telemetry data to allow the current time to be synchronized across multiple sources of telemetry data.

[0022] In some examples, the black box circuitry is configured to include in the event log preevent telemetry data associated with timepoints before the occurrence of the anomalous event. Including pre-event telemetry data can be helpful to allow better diagnosis of the cause of the attack.

[0023] To enable capture of pre-event telemetry data, the black box circuitry may be configured to write captured telemetry data to a first-in-first-out (FIFO) buffer of telemetry data, even in the absence of any detection of occurrence of an anomalous event. Hence, the black box circuitry may continuously record incoming telemetry data into its FIFO buffer, with new data overwriting the oldest data if there is insufficient capacity to write the new data into the FIFO buffer without overwriting any previous data. In response to detection of the occurrence of the anomalous event, the black box circuitry may capture, as pre-event telemetry data to be included in the event log, contents of the first-in-first-out buffer corresponding to a recent window of timepoints before occurrence of the anomalous event, and prevent that pre-event telemetry data being overwritten by subsequently captured telemetry data. Hence, the detection of the anomalous event causes the current contents of the FIFO buffer to be “frozen”, to provide a snapshot of processing activity being performed in the period immediately before the occurrence of the anomalous event.

[0024] In addition to, or instead of, inclusion of pre-event telemetry data in the event log, the black box circuitry could record post-event telemetry data in the event log. Hence, in response to detection of the occurrence of the anomalous event, the black box circuitry is configured to capture, and include in the event log, post-event telemetry data associated with timepoints after the occurrence of the anomalous event. This can provide further useful diagnostic information.

[0025] Although pre-event telemetry data may often be more valuable for diagnostic purposes than post-event telemetry data, post-event telemetry data can still provide some use in diagnosing attack causes, and in practice, restrictions on circuit area and power budgets may limit the amount of storage capacity and telemetry data capture overhead that a system designer may wish to incur in speculatively capturing pre-event telemetry data in the absence of any specific anomalous event being detected. Hence, in some examples providing both pre-event and post-event telemetry data in the event log can provide an improved balance between diagnostic capability and circuit area / power cost associated with the black box circuitry.

[0026] In some examples, in response to detection of the occurrence of the anomalous event, the black box circuitry is configured to trigger capture of at least one type of post-event telemetry data not previously captured prior to detection of the occurrence of the anomalous event, and to include said at least one type of post-event telemetry data in the event log. This recognises that once an anomalous event has been detected, the increased storage capacity and power consumption cost of capturing a higher volume of more detailed telemetry data may be justified, but this cost would not be justified for capturing speculative telemetry data just in case an event occurs which requires pre-event data to be collected. Hence, it can be particularly useful if the black box circuitry increases the volume of telemetry data that is captured after the occurrence of the anomalous event compared to the amount of data captured before the occurrence of the anomalous event, by activating one or more additional sources of post-event telemetry data in response to the occurrence of the anomalous event. This can provide a better balance between security and power and circuit area overheads.

[0027] In some examples, the black box circuitry may capture the event log in black box memory storage circuitry separate from the memory storage circuitry used to store the data and instructions processed by the processing circuitry. By giving the black box circuitry its own dedicated memory storage for capturing event log data, this can improve security and trust in the event log as the event log data may be less vulnerable to tampering by an attacker than if it was stored in the generally accessible system memory. Also, this can be helpful for reducing performance impact of capturing the event log during the pre-event functioning of the black box circuitry, as by capturing the FIFO buffer of pre-event data in dedicated black box memory storage circuitry rather than in the general purpose memory system accessible to software executing on the processing circuitry, the storage of the pre-event data does not consume main memory system bandwidth which could otherwise be used for regular memory accesses triggered by the processing circuitry.

[0028] In some examples, the black box circuitry may operate in a black box power domain separate from at least one power domain associated with the processing circuitry and the memory storage circuitry. For example, the black box power domain may have a dedicated always-on power supply, such as a backup battery separate from the main power supply for other parts of the processing apparatus. This can provide increased reliability for the black box power domain, so that even if supply voltage variation or other power-loss events affect the main processing system functioning, the black box circuitry can continue to operate, e.g. allowing event logging actions such as signing of the event log and / or calculation of the digest to continue even if the main system is not operational.

[0029] The black box circuitry may be tightly integrated into the data processing system at semiconductor level (e.g. silicon level). This is different to classic “black boxes” associated with aircraft or other infrastructure which may record information following a crash or other loss of function, as in those systems the black box is not integrated into the semiconductor chips of a processor system, but rather are standalone devices wired up to a processor system by the end user via external input / output ports.

[0030] In some examples, the black box circuitry is provided within a same semiconductor package as the processing circuitry and the memory storage circuitry. A semiconductor package may provide a casing (e.g. made of metal, plastic, glass or ceramic) which protects individual semiconductor components implemented on one or more chiplets within the package. Integrating the black box circuitry into the same semiconductor package as the processing circuitry and memory storage circuitry which are subject to diagnostic functions by the black box circuitry can be extremely helpful for diagnosing possible causes of software attacks, which would be difficult to achieve with external circuitry as the information available to an external device through input / output mechanisms can be limited.

[0031] More particularly, in some examples, the black box circuitry may be provided on a same chiplet as at least a portion of at least one of the processing circuitry and the memory storage circuitry. In this case, a single integrated circuit may be implemented on a semiconductor wafer, comprising the processing circuitry, the memory storage circuitry and the black box circuitry.

[0032] In other examples, the black box circuitry may be implemented as its own dedicated chiplet, separate from one or more chiplets providing the processing circuitry and memory storage circuitry whose operation is monitored by the black box circuitry. The chiplets providing the black box circuitry and other parts of the data processing apparatus may be integrated into a single semiconductor package (e.g. using an interposer).

[0033] The data processing apparatus may comprise input / output (I / O) interface circuitry to communicate with external devices external to the data processing apparatus according to an I / O interface protocol. Examples of I / O interface protocols include PCIe and CXL for instance. I / O mechanisms are typically used for communicating with the outside world, e.g. with user input / output devices, external data storage units, networked devices, etc. Communications via an I / O interface tend to be relatively slow and limited in bandwidth compared to internal signal paths (e.g. buses) within the data processing apparatus. Also, I / O mechanisms may be limited in terms of what information is accessible from within the data processing apparatus by an external device.

[0034] In contrast, communications between the black box circuitry and other portions of the data processing apparatus may occur via internal signal paths separate from the input / output interface circuitry. Hence, the black box circuitry is integrated into the data processing apparatus rather than being an external device accessed via I / O mechanisms. This tight integration allows greater access to a variety of sources of telemetry data (some of which may be unpractical to access via I / O mechanisms), and allows a faster response to detection of anomalous events.

[0035] The anomalous event could be any event which is out of the ordinary and could be a possible indicator of loss of safety-critical functioning of the data processing apparatus. Some examples of such an anomalous event can include:

[0036] • a system crash event. If the system has crashed then safety-critical functioning is likely to have been disrupted and so diagnostic information on the cause of the crash could be useful to help identify a response action to be taken. For example, the system crash event could be detected (either by the black box circuitry itself, or by separate monitoring circuitry), based on performance metrics or other monitoring information associated with operation of the processing circuitry. For example, if the system becomes deadlocked then the instruction execution rate may drop and so a performance metric regarding instruction execution rate may be used to detect the system crash event. System crashes could also be detected based on assertion of reset events or other indicators that the system is not functioning correctly.

[0037] • detection of a possible attack on the data processing apparatus by a malicious party. Some systems may have mechanisms to enable attack detection. For example, a cybersecurity processor included in the data processing apparatus may receive telemetry data from a variety of sources (which could be the same telemetry data as used by the black box circuitry, or could be a different subset of telemetry data to the subset used by the black box circuitry), and could process the received telemetry data using a predictive model (e.g. machine learning model) trained to detect signatures of known attacks, to generate an attack detection signal indicative of whether any attack has been detected. The black box circuitry may detect the assertion of the attack detection signal by the cybersecurity processor as an anomalous event which causes capture of the event log.

[0038] • an anomalous pattern of interrupts or faults. If the processing circuitry keeps encountering interrupts or faults, this could be a sign of a denial of service attack or of programming errors which may disrupt proper functioning of the safety-critical system. Hence, a metric tracking the frequency or rate with which faults occur (either faults in general, or one or more specific types of faults) could be used to detect an anomalous event which could trigger the capture of an event log by the black box circuitry.

[0039] • an anomalous pattern of modular redundancy errors. Some safety-critical systems may incorporate modular redundancy, where the same processing is carried out redundantly more than once, to allow for detection of errors when divergence between the two or more redundant instances of the same processing is detected. The redundancy can be provided either at a hardware level (with multiple redundant processor cores operating in lockstep on the same instructions and their outputs compared to detect divergence), or at software level (with the operating system managing the execution of multiple identical threads of processing). Particularly in systems providing modular redundancy at the software level, it may be difficult for a software attack to successfully attack each redundant version of the same processing in the same way, so that divergence between the redundant threads may become likely if an attack is attempted. Hence, information regarding an anomalous pattern of modular redundancy errors could also be a marker of a possible attack and could prompt the black box circuitry to capture the event log.

[0040] • detection of abnormal processing performance associated with the data processing apparatus.

[0041] • a change in configuration and / or integrity of the system that risks compromising safety (e.g. disabling a safeguard or turning off a protection system).

[0042] • removal of a physical protective measure such as a cover or guard housing the data processing apparatus.

[0043] It is not essential for all of these examples to be supported in a given implementation of the black box circuitry. Some examples may support only one, or a subset of, the described types of anomalous events that could trigger event log capture. Other examples may support detection of any of these types of event. It will be appreciated that other event types not described may also be supported.

[0044] The event log could comprise a wide variety of types of telemetry data, and in general may comprise any information which could be useful for diagnosing possible causes of the anomalous event.

[0045] The event log may comprise data from portions of the data processing apparatus that are inaccessible via external pins of said one or more chiplets of the data processing apparatus. This can be helpful to allow more detailed interrogation of the functioning of the data processing apparatus than would be practical without the onboard black box circuitry.

[0046] For example, the event log may comprise at least one of the following types of telemetry data:

[0047] • context information indicative of a processing context active at the time of occurrence of the anomalous event;

[0048] • software version information indicative of a version of software being processed at the time of occurrence of the anomalous event;

[0049] • fingerprint data indicative of a fingerprint of software activity on the data processing apparatus;

[0050] • interrupt data;

[0051] • performance monitoring data;

[0052] • memory access data;

[0053] • memory built-in-self test data;

[0054] • prefetcher data;

[0055] • branch predictor data; • neighbour chiplet data communicated to the black box circuitry from one or more neighbour chiplets other than the one or more chiplets comprising the black box circuitry;

[0056] • power management data associated with power management of the data processing apparatus; and

[0057] • modular redundancy checking information.

[0058] Again, it will be appreciated that not all of these types may be collected in a given system. In practice, the pre-event telemetry data may comprise a smaller subset of types of data than the post-event telemetry data as discussed above.

[0059] Information identifying the specific software version being executed at the time of the event occurring may be particularly useful in helping forensic analysis to identify possible corrupted software that may be a victim of attack. For other diagnostic mechanisms typically supported in data processing systems (e.g. trace capture tools which provide a trace of behaviour of a specific program to assist with software development or performance optimization of that program), it is less likely that the trace data captured would specify the software being executed, since normally such trace capture tools are used to diagnose errors or inefficiencies in the running of a specific piece of software, so the identity of the software being executed would already be known to the diagnostic analyzer and so is not needed to be captured by trace circuitry. Another difference with such trace circuitry is that the diagnostic trace capture may be continual, rather than having an event log captured in response to detection of a safety-critical event which risks loss of safety- critical functioning.

[0060] In some examples, if other diagnostic tools also providing capture of diagnostic information are provided, the black box circuitry could share some hardware (e.g. memory storage) with those other diagnostic tools. For example, in absence of occurrence of the anomalous event, the black box circuitry may capture safety-critical telemetry data and non-safety-critical telemetry data. In response to occurrence of the anomalous event, the black box circuitry may prioritise retention of the safety-critical telemetry data over retention of the non-safety-critical telemetry data. This allows some hardware to be save din a system also capturing telemetry data for non-safety-critical reasons. For example, the safety-critical telemetry data may include the context information, software version information, interrupt data, operating system provided finger print data, etc. which may be useful for forensic analysis of a possible software attack, whereas the non-safety- critical data may include other information more relevant to diagnosing possible loss of performance of software, such as information on branch misprediction rates, memory address faults, etc.

[0061] The safety-critical functioning at risk of disruption by the anomalous event could comprise a wide variety of safety-critical functions. As a non-exhaustive list of examples, the safety-critical functioning could comprise control of a medical device for which a patient’s health is at risk if the device ceases to function; control of a vehicle such as a car, plane or spacecraft; control of a power station; control of a process within a factory or other industrial facility; control of public infrastructure such as traffic lights, air traffic control, or train signalling systems; etc.

[0062] Some examples may provide a chiplet comprising the black box circuitry as described above. In some examples, that chiplet may also comprise the processing circuitry and memory storage circuitry. In other examples, the chiplet comprising the black box circuitry may be separate from a chiplet comprising the processing circuitry and / or memory storage circuitry.

[0063] Figure 1 illustrates an example of a data processing apparatus 2 implemented on one or more chiplets (integrated circuits) provided within a semiconductor package. The apparatus 2 has processing circuitry 4 for performing data processing. For example, the processing circuitry 4 may include one or more processing elements (PEs). For example, a PE may comprise a central processing unit (CPU), graphics processing unit (GPU) or another more specialized type of processing unit such as a neural processing unit (NPU) providing acceleration for machine learning applications. At least part of the processing circuitry 4 (e.g. one or more CPUs) is capable of executing program instructions defined according to an instruction set architecture, to perform data processing operations represented by those instructions. The instructions executed by the processing circuitry 4 are fetched from memory storage circuitry 6. The memory storage circuitry 6 also stores data values for processing by the processing circuitry 4. Result data generated by the processing circuitry 4 may be written back to the memory storage circuitry 6. While not shown in Figure 1 , it will be appreciated that the processing circuitry 4 may have one or more caches for caching a subset of data from the memory storage circuitry 6 for faster access by the processing circuitry 4.

[0064] The processing circuitry 4 and memory storage circuitry 6 communicate via internal buses and / or signal paths 10, e.g. via a system interconnect communicating according to a memory system bus protocol. The apparatus 2 also has input / output (I / O) interface circuitry 8 for exchanging communications between the internal components of the apparatus 2 and the outside world. For example, the I / O interface circuitry 8 may handle communications with peripheral devices such as user input / output devices, network communication or radio communication devices, external mass data storage, etc.

[0065] Black box circuitry 20 is provided in the apparatus 2, coupled to the internal buses and signal paths 10 of the apparatus 2. The black box circuitry 20 can receive telemetry data from various sources within the apparatus 2 providing information on the functioning of the processing circuitry 4 and / or memory storage circuitry 6 and / or other components of the apparatus 2. For example, the telemetry sources may provide information on which software processes are currently running, which regions of memory are being accessed, the types of operations performed by those processes, etc.

[0066] The black box circuitry 20 provides additional hardware, designed to be integrated into the same semiconductor product as the processing circuitry 4 which is monitored using the black box circuitry 20, to allow the apparatus 2 as a whole to perform secure self-immutable logging of diagnostic data in case of malicious software attacks.

[0067] In response to detection of occurrence of an anomalous event indicating a risk of loss of safety-critical functioning of the data processing apparatus 2, the black box circuitry 20 captures an event log of telemetry data indicative of behaviour of the data processing apparatus associated with timepoints before or after the occurrence of the anomalous event. The event log can be useful for forensic analysis after the event occurs, to help diagnose the cause of the event and help identify possible mitigations. For example, the event log may identify the specific software version that may have been compromised by the attacker to allow developers to patch up any vulnerabilities and reduce risk of such attacks in future.

[0068] As shown in Figure 1 , the black box circuitry 20 may operate in its own dedicated black box power domain 22 separate from one or more power domains used to power other components 4, 6, 10, 8 of the apparatus 2. For example, the black box power domain 22 may have a dedicated backup battery not used for any other portion of the apparatus 2, which can continue to power the black box circuitry 20 even if other portions of the apparatus 2 have become inoperative due to loss of power supply. This can help to ensure that event log data captured by the black box circuitry 20 can still be retained even if there is a power failure.

[0069] As shown in Figure 2, in some implementations the apparatus 2 may comprise multiple chiplets 50, each chiplet 50 comprising a separate integrated circuit on which a subset of components of the apparatus 2 are implemented. Chiplets may communicate via one or more inter-chiplet bridges (e.g. via communication paths provided by an interposer). The group of chiplets 50 may, as a whole, be packaged into a single semiconductor package with the inter- chiplet communications hidden from exposure to the outside world, and any external communications between the chiplets 50 and devices outside the semiconductor package being restricted to a limited set of integrated circuit pins (e.g. a debug port for debug communications) and to I / O communications via the I / O interface circuitry 8, performed according to a given I / O protocol such as PCIe or CXL.

[0070] It will be appreciated that the specific partitioning of circuit components onto particular chiplets of the multi-chiplet system can be varied depending on the design needs of a particular system. Hence, the specific example shown in Figure 2 is merely for illustrative purposes. In some cases, a given chiplet 50 may comprise both a portion of the processing circuitry 4 (e.g. one or more processing elements) and memory storage 6 (e.g. see chiplets 0, 2, 3 in Figure 2). Some chiplets comprising processing circuitry 4 may also include I / O ports 8 (e.g. see chiplet 2). It is also possible for a chiplet 50 to act as an I / O hub chiplet not having any processing elements 4. Other components which could be included on one or more of the chiplets may include:

[0071] • a cybersecurity processor 32 responsible for detection of software attacks or other cybersecurity risks. For example, the cybersecurity processor 32 may run a machine learning model which processes telemetry inputs obtained from various telemetry sources 30 using a trained machine learning model (trained to recognise the telemetry patterns associated with certain known software attacks), to generate an attack likelihood prediction of whether the system is likely to be under attack. For example, the cybersecurity processor 32 may detect risk of attack based on the method for detecting abnormal behaviour of an electronic device described in European patent application 23306870.9 filed on 27 October 2023 by Arm Limited of Cambridge, United Kingdom, the contents of which are incorporated herein entirely by reference.

[0072] • memory built in self test (BIST) circuitry 34 for performing diagnostic operations on associated memory storage circuitry 6. The MBIST circuitry 34 may run self-test operations on the memory to detect occurrence of random hardware faults (such as memory cells becoming stuck at a fixed value regardless of the data written to the memory cell) which may prevent the memory from functioning correctly; and / or

[0073] • power management circuitry 36 for managing power transitions of its own chiplet and / or other neighbouring chiplets.

[0074] As shown in Figure 2, at least one of the chiplets (in this example, chiplet 0 and chiplet 3) comprises digital black box (DBB) circuitry 20 for capturing the event log as discussed above in response to detection of an anomalous event. The event log comprises telemetry data captured by at least some of the telemetry sources 30 associated with time points around (before and / or after) the time when the event was detected. A wide variety of event types could be detected as the anomalous event triggering capture of an event log. For example, such an event may include a system crash event; a suspicious pattern of interrupts being detected; a detection of divergence between outputs of redundant software components executed on the processing circuitry; and / or detection of a software attack pattern by the cybersecurity processor 32. Examples of telemetry data which could be captured in the event log are described below with reference to Figures 3 and 4.

[0075] While Figure 2 shows an example where the black box circuitry 20 is on a same chiplet 50 as processing circuitry 4 and memory storage circuitry 6 of the apparatus 2 being monitored, it is also possible to provide the black box circuitry 20 as a separate chiplet from the chiplet(s) comprising processing circuitry 4 and memory storage circuitry 6.

[0076] The black box circuitry 20 provides a secure way (e.g. an immutable way) to store silicon die level context and telemetry data in case of attacks or misbehaviour of a safety critical system. This is usually done at the system, or system-of-systems level (e.g. black box in an aeroplane), where the black box communicates with the system it is monitoring via I / O mechanisms. In contrast, the black box circuitry 20 is integrated into the processing system it monitors at silicon level, being an integral part of the semiconductor product (e.g. system-on-chip or multi-chiplet processor system) that it is monitoring.

[0077] Telemetry data, e.g. die "context" information defining the application(s) running at a given time and operational telemetry regarding the activity of the application(s), can be streamed to an embedded memory within the black box circuitry 20 that always stores the past X seconds (X being a design parameter to be selected by the system designer) of on chip telemetry data. Once an event is detected by internal / external chip security or safety monitoring systems, or by the operating system executing on the processing circuitry 4, the chipset turns into Digital Black Box (DBB) mode, freezing the capture of the pre-event telemetry data to keep the storage of the past X seconds before the event, as well as beginning to record new data. The black box circuitry 20 creates an event block which can be used for forensic analysis, which can be trusted because of the process and the use of CCA or TEE signed attestation. This allows such forensic analysis of the causes of loss of safety-critical functioning to access data from those blocks of an integrated circuit (chiplet 50) which have no direct connection with external pins accessible via I / O interfaces 8.

[0078] Figure 3 illustrates an example of components of the black box circuitry 20 operating in a pre-event mode, prior to occurrence of any anomalous event. As shown in Figure 3, the black box circuitry 20 includes an entry bus 62 for receiving telemetry data 60 from various telemetry sources, compression / encryption circuitry 64 for performing compression and / or encryption on the telemetry data 60, a switch 66 for selecting telemetry data and directing the telemetry data to other components of the black box circuitry 20, a black box controller (DBB controller) 68 for controlling operation of the black box circuitry 20, an event detector 70 for detecting occurrences of the anomalous event, and dedicated black box memory storage 72, 74 separate from the main memory storage circuitry 6 used by the processing circuitry 4. The black box memory storage includes an always-on portion of memory storage 72 used for recording telemetry data in preevent mode, and an on-event portion of memory storage 74 that is in a power saving state during the pre-event mode but is powered up in response to occurrence of the anomalous event to provide additional storage for storing a greater volume of telemetry data than would fit in the always on memory storage 72.

[0079] The telemetry data 60 can be obtained from various sources. For example, Figure 3 shows examples of any of the following types of telemetry data 60:

[0080] - operational telemetry from system components such as a power manager 36;

[0081] - dedicated telemetry specific to black box operation (e.g. telemetry from a delay monitor, process detector, voltage droop detector and / or hot spot profiler);

[0082] - secure trace information giving a trace of activity of one or more applications executed on the processing apparatus 2;

[0083] - interrupt data providing information about the pattern of interrupts (e.g. type of interrupts and frequency of occurrence of interrupts) occurring during processing performed by the processing apparatus 2;

[0084] - operating system (OS) fingerprinting information providing a snapshot of OS activity;

[0085] - hardware / software fingerprinting providing a snapshot of other hardware or software activity. For example, the fingerprinting data may comprise a digest of instruction addresses of executed instructions or data addresses of data accessed in memory 6 by the processing circuitry 4; identifiers of applications running on the processing circuitry 4, including specific version information identifying the specific software version being executed;

[0086] BIST data provided by the memory built in self test circuitry 34; information sent from telemetry sources on neighbouring chiplets 50 other than the chiplet 50 comprising the black box circuitry 20;

[0087] It will be appreciated that this list is not exhaustive and that not all of these types of telemetry data need to be considered in a given implementation. Also, in pre-event mode, it may be that only a subset of these telemetry sources are active (some sources may only provide telemetry in postevent mode).

[0088] One or more streams of such telemetry data are received at the entry bus 62 and may be subject to lossless compression and / or encryption by the compression / encryption circuitry 64. The switch 66 selects telemetry data from one or more streams for routing to the black box controller 68 and / or other components.

[0089] The black box controller 68 supports an attestation service 76 for digitally signing the received telemetry data to provide a signature enabling third parties to attest to the identity of the source of the telemetry data. Hence, the attestation service 76 generates a digital signature corresponding to the pre-event log data generated based on the received telemetry data. Also, the black box controller 68 supports a time stamping service 78 which periodically inserts timestamps (defined according to a local clock scheme used by the black box circuitry 20) into the stream of pre-event telemetry data, to assist with synchronizing information from different sources of telemetry.

[0090] The signed and time stamped telemetry data is written to the always on memory 72, to provide a buffer of pre-event telemetry data. The always on memory 72 is managed as a first-in first-out (FIFO) buffer, so that once the capacity of the always on memory 72 is fully used, the oldest items of telemetry data are overwritten with newer items of telemetry data. Hence, the black box controller 68 controls the always on memory 72 to capture a record of telemetry data for a most recent window of time (e.g. the last X seconds - the capacity of the always on memory may be chosen based on the length of time for which the pre-event log data is to be captured).

[0091] The event detector 70 detects whether any occurrence of an anomalous event has occurred. In the example shown in Figure 3, the event detector 70 may read telemetry data from the always on memory 72 and detect occurrences of anomalous events based on the telemetry data (e.g. based on the interrupt data provided as a source of telemetry, which may indicate a suspicious pattern of interrupts). In other examples, the event detector 70 may receive event signals from other portions of the system, rather than detecting anomalous events internally based on analysis of the received telemetry data. For example, the event detector 70 may receive a signal from the cyber security processor 32 indicating whether any risk of a software attack has been detected, or a system crash signal from a system crash monitor which monitors system activity to detect scenarios where the system has crashed.

[0092] When an anomalous event occurs, the black box controller 68 switches the operation of the black box circuitry to a post-event mode. Figure 4 illustrates functions of the black box circuitry 20 in the post-event mode.

[0093] In the post-event mode, the black box controller 68 communicates with telemetry sources 30 to activate one or more additional sources of telemetry 30 which were not previously sending telemetry to the black box circuitry 20 during the pre-event mode.

[0094] Also, the black box controller 68 freezes the contents of the always on memory 72, to capture as the pre-event log the telemetry data 60 which was recorded in the FIFO buffer in the period immediately before occurrence of the anomalous event. The always on memory 72 becomes read-only.

[0095] Also, the black box controller 68 activates the on event memory 74, powering up the on event memory 74 so that the on event memory 74 can start recording the telemetry data 60 received in post-event mode. In the post-event mode, the attestation service 76 and time stamping service 78 of the black box controller 68 continue to sign and timestamp the incoming telemetry data, and the signed / timestamped data is written to the on event memory 74.

[0096] The black box controller 68 also supports a hash service 80 which generates a digest of a given portion of event log data according to a given cryptographic function (e.g. a variant of SHA, QARMA, etc.) based on secret keys, the cryptographic function being a function which makes it statistically improbable that an attacker not knowing the secret keys could guess the correct digest value for a given block of event log data. Such a digest can be generated based on the pre-event log data stored in the always on memory 72, and also based on post-event telemetry data stored in the on event memory 74 subsequent to detection of the event.

[0097] The black box controller 68 also supports a broadcasting service 82 by which the digest(s) and / or the captured event log data (either pre-event or post-event logged data) can be transmitted to neighbour chiplets 50 of the processing system and / or to external devices via the I / O circuitry 8. For example, to guard against the risk of an attacker intercepting the event log data at read out and substituting it for other data, at least the digests could be broadcast to other chiplets 50 and / or external devices promptly upon generation of the event log, to provide an anti-tampering protection mechanism.

[0098] The black box circuitry 20 may continue to capture post-event telemetry data until the system is reset or until the black box circuitry 20 is otherwise instructed (e.g. by trusted system software or by hardware) to stop capture of event log data.

[0099] Captured event log data may be read out from the on event memory 74 by various mechanisms. In some cases, the only mechanism for extracting the event memory 74 may be via the broadcasting service 82, which may write out the captured event log data to memory storage on another chiplet 50 or to an external device via I / O mechanisms 8. Other examples may support the black box memory 72, 74 to be mapped into the physical address space of the apparatus 2 so that the event log can be read out by software, and / or could provide a dedicated hardware path (e.g. certain black box readout pins) by which external devices could read out captured event log data from the black box memory 72, 74.

[0100] One specific example of a process for capturing the event log is as follows, to obtain signed and time-stamped telemetry data stored in an immutable way by the black box circuitry 20.

[0101] 1. Triggering DBB initiation: the DBB controller detects an anomaly (e.g. SoC crash, suspicious pattern of interrupts / faults) or receive a signal from cybersecurity processor, a firewall etc. The DBB controller triggers generation of a timestamp event request. a. The embedded memory of the DBB, which stored the streamed data from all telemetry of the SoC for the past X seconds at runtime, is frozen (prevented from being overwritten by further telemetry data) and timestamped, to generate the "pre-event log". b. the DBB Controller sends a signal to DBB receivers (e.g. on chip telemetry sensors, BIST, memory controller, neighbouring chiplets, the operating system, etc.) with a timestamp of the time when the anomaly occurred. This timestamp can be inserted into the streams generated by each source of telemetry data to ensure time alignment between telemetries (since system clocks may not be fully aligned between different portions of the system). d. Hence, time stamped and event ID stamped streams of telemetry are obtained for a given set of components or sub-components of the system. e. The DBB circuitry 20 can request that certain sub-components not previously in continuous monitoring mode now start monitoring and generating telemetry streams.

[0102] 2. Gathering event data: Full systems switch to black-box recorder mode, with data attestation and secure mode.

[0103] The DBB Controller signs all SOC transaction / input / output and other data / metadata that can be collected. The DBB controller generates a hash digest of the event data to prevent future malicious data tampering. The device subcomponent telemetry sources keep storing and streaming the past X seconds of historical data and new data to the black box controller.

[0104] 3. Verifying and creating new event: a. Upon the occurrence of an DBB Event, the DBB controller starts broadcasting the hash of the sub-component telemetry event and global event hash to a DBB proxy (e.g. on a different chiplet or at an external device). This will enable future verification and provides resistance against potential attacks on the system like spoofing event data.

[0105] 4. Trusted Proof of Event: The DBB Controller records the submitters’ digitally signed input, as well as the digitally signed transaction responses from each of the subcomponents in a protected memory.

[0106] 5. Reviewing event for forensic investigation: Later, people or artificial intelligence (Al) tools can review the Event log to identify causes for the incident. Figure 5 illustrates steps for capturing an event log using the black box circuitry 20. At step 100, data processing is performed on the data processing apparatus 2. At step 102, the black box circuitry 20 detects whether an anomalous event has occurred. When an anomalous event occurs, at step 104 the black box circuitry 20 (integrated onto at least one chiplet 50 of the apparatus 2) captures an event log of telemetry data 30 indicating behaviour of the apparatus associated with timepoints before or after occurrence of the anomalous event.

[0107] Figure 6 illustrates steps for capturing the event log in more detail. At step 150 the black box circuitry 20 captures pre-event telemetry data in a FIFO buffer structure stored in its dedicated black box memory storage (e.g. in the always on memory 72). Capture of pre-event telemetry data continues (overwriting older data with newer data when required) until an anomalous event is detected at step 152.

[0108] In response to detection of the anomalous safety critical event, at step 154 the black box circuitry 20 freezes contents of the pre-event log FIFO structure (to prevent further updates), timestamps the captured pre-event log data, and generates a digest of the pre-event telemetry data. At step 156, the black box circuitry 20 activates one or more additional streams of postevent telemetry data which were not active prior to occurrence of the event detected at step 152 (one or more of the streams of telemetry data used pre-event may also continue to generate telemetry data post-event). At step 158, the black box circuitry 20 timestamps and captures postevent telemetry data in the on-event portion 74 of the black box memory storage. At step 160, a digest is generated of the post-event telemetry data.

[0109] If further post-event telemetry data is to be captured (Y at step 162), the method continues to loop through steps 158 to 162 until it is determined at step 162 that capture of post-event telemetry data can be halted, at which point capture ends at step 164. For example, capture of telemetry data may stop when the processing system is reset or when a command is sent to the black box circuitry 20 to halt capture of telemetry data.

[0110] Meanwhile, at step 164, from time to time a given portion of event log data captured at step 158 and / or the digest generated at step 160 is cryptographically signed (to provide an attestable root of trust for the event log data and digest). This enables both attestation and tamper-protection for the event log data. The timing at which event log data is signed / hashed may vary from one implementation to another. For example, this could be done at regular intervals of time, or could be done as and when required e.g. based on capacity constraints in the on event memory 74. At step 166 at least the digest (and optionally also the event log data itself) can be transmitted to a neighbour chiplet and / or to an external device for external storage. Transmitting at least the digest can be helpful to provide a value stored by a “witness” which can be compared with a hash of the event log data read out from the black box memory 72, 74, to provide tamper detection. While the flow chart shown in Figure 6 shows steps performed in a particular order, it will be appreciated that the same functions could be performed in a different order from the order shown, or some steps shown sequentially could be performed at least partially in parallel.

[0111] Concepts described herein may be embodied in a system comprising at least one packaged chip. The data processing apparatus 2 described earlier is implemented in the at least one packaged chip (either being implemented in one specific chip of the system, or distributed over more than one packaged chip). The at least one packaged chip is assembled on a board with at least one system component. A chip-containing product may comprise the system assembled on a further board with at least one other product component. The system or the chipcontaining product may be assembled into a housing or onto a structural support (such as a frame or blade).

[0112] As shown in Figure 7, one or more packaged chips 400, with the apparatus 2 described above implemented on one chip or distributed over two or more of the chips, are manufactured by a semiconductor chip manufacturer. In some examples, the chip product 400 made by the semiconductor chip manufacturer may be provided as a semiconductor package which comprises a protective casing (e.g. made of metal, plastic, glass or ceramic) containing the semiconductor devices implementing the apparatus described above and connectors, such as lands, balls or pins, for connecting the semiconductor devices to an external environment. Where more than one chip 400 is provided, these could be provided as separate integrated circuits (provided as separate packages), or could be packaged by the semiconductor provider into a multi-chip semiconductor package (e.g. using an interposer, or by using three-dimensional integration to provide a multi-layer chip product comprising two or more vertically stacked integrated circuit layers).

[0113] In some examples, a collection of chiplets (i.e. small modular chips with particular functionality) may itself be referred to as a chip. A chiplet may be packaged individually in a semiconductor package and / or together with other chiplets into a multi-chiplet semiconductor package (e.g. using an interposer, or by using three-dimensional integration to provide a multilayer chiplet product comprising two or more vertically stacked integrated circuit layers).

[0114] The one or more packaged chips 400 are assembled on a board 402 together with at least one system component 404 to provide a system 406. For example, the board may comprise a printed circuit board. The board substrate may be made of any of a variety of materials, e.g. plastic, glass, ceramic, or a flexible substrate material such as paper, plastic or textile material. The at least one system component 404 comprise one or more external components which are not part of the one or more packaged chip(s) 400. For example, the at least one system component 404 could include, for example, any one or more of the following: another packaged chip (e.g. provided by a different manufacturer or produced on a different process node), an interface module, a resistor, a capacitor, an inductor, a transformer, a diode, a transistor and / or a sensor. A chip-containing product 416 is manufactured comprising the system 406 (including the board 402, the one or more chips 400 and the at least one system component 404) and one or more product components 412. The product components 412 comprise one or more further components which are not part of the system 406. As a non-exhaustive list of examples, the one or more product components 412 could include a user input / output device such as a keypad, touch screen, microphone, loudspeaker, display screen, haptic device, etc.; a wireless communication transmitter / receiver; a sensor; an actuator for actuating mechanical motion; a thermal control device; a further packaged chip; an interface module; a resistor; a capacitor; an inductor; a transformer; a diode; and / or a transistor. The system 406 and one or more product components 412 may be assembled on to a further board 414.

[0115] The board 402 or the further board 414 may be provided on or within a device housing or other structural support (e.g. a frame or blade) to provide a product which can be handled by a user and / or is intended for operational use by a person or company.

[0116] The system 406 or the chip-containing product 416 may be at least one of: an end-user product, a machine, a medical device, a computing or telecommunications infrastructure product, or an automation control system. For example, as a non-exhaustive list of examples, the chipcontaining product could be any of the following: a telecommunications device, a mobile phone, a tablet, a laptop, a computer, a server (e.g. a rack server or blade server), an infrastructure device, networking equipment, a vehicle or other automotive product, industrial machinery, consumer device, smart card, credit card, smart glasses, avionics device, robotics device, camera, television, smart television, DVD players, set top box, wearable device, domestic appliance, smart meter, medical device, heating / lighting control device, sensor, and / or a control system for controlling public infrastructure equipment such as smart motorway or traffic lights.

[0117] Concepts described herein may be embodied in computer-readable code for fabrication of an apparatus that embodies the described concepts. For example, the computer-readable code can be used at one or more stages of a semiconductor design and fabrication process, including an electronic design automation (EDA) stage, to fabricate an integrated circuit comprising the apparatus embodying the concepts. The above computer-readable code may additionally or alternatively enable the definition, modelling, simulation, verification and / or testing of an apparatus embodying the concepts described herein.

[0118] For example, the computer-readable code for fabrication of an apparatus embodying the concepts described herein can be embodied in code defining a hardware description language (HDL) representation of the concepts. For example, the code may define a register-transfer-level (RTL) abstraction of one or more logic circuits for defining an apparatus embodying the concepts. The code may define a HDL representation of the one or more logic circuits embodying the apparatus in Verilog, SystemVerilog, Chisel, or VHDL (Very High-Speed Integrated Circuit Hardware Description Language) as well as intermediate representations such as FIRRTL. Computer-readable code may provide definitions embodying the concept using system-level modelling languages such as SystemC and SystemVerilog or other behavioural representations of the concepts that can be interpreted by a computer to enable simulation, functional and / or formal verification, and testing of the concepts.

[0119] Additionally or alternatively, the computer-readable code may define a low-level description of integrated circuit components that embody concepts described herein, such as one or more netlists or integrated circuit layout definitions, including representations such as GDSIL The one or more netlists or other computer-readable representation of integrated circuit components may be generated by applying one or more logic synthesis processes to an RTL representation to generate definitions for use in fabrication of an apparatus embodying the invention. Alternatively or additionally, the one or more logic synthesis processes can generate from the computer-readable code a bitstream to be loaded into a field programmable gate array (FPGA) to configure the FPGA to embody the described concepts. The FPGA may be deployed for the purposes of verification and test of the concepts prior to fabrication in an integrated circuit or the FPGA may be deployed in a product directly.

[0120] The computer-readable code may comprise a mix of code representations for fabrication of an apparatus, for example including a mix of one or more of an RTL representation, a netlist representation, or another computer-readable definition to be used in a semiconductor design and fabrication process to fabricate an apparatus embodying the invention. Alternatively or additionally, the concept may be defined in a combination of a computer-readable definition to be used in a semiconductor design and fabrication process to fabricate an apparatus and computer- readable code defining instructions which are to be executed by the defined apparatus once fabricated.

[0121] Such computer-readable code can be disposed in any known transitory computer- readable medium (such as wired or wireless transmission of code over a network) or non- transitory computer-readable medium such as semiconductor, magnetic disk, or optical disc. An integrated circuit fabricated using the computer-readable code may comprise components such as one or more of a central processing unit, graphics processing unit, neural processing unit, digital signal processor or other components that individually or collectively embody the concept.

[0122] In the present application, the words “configured to...” are used to mean that an element of an apparatus has a configuration able to carry out the defined operation. In this context, a “configuration” means an arrangement or manner of interconnection of hardware or software. For example, the apparatus may have dedicated hardware which provides the defined operation, or a processor or other processing device may be programmed to perform the function. “Configured to” does not imply that the apparatus element needs to be changed in any way in order to provide the defined operation.

[0123] In the present application, lists of features preceded with the phrase “at least one of” mean that any one or more of those features can be provided either individually or in combination. For example, “at least one of: [A], [B] and [C]” encompasses any of the following options: A alone (without B or C), B alone (without A or C), C alone (without A or B), A and B in combination (without C), A and C in combination (without B), B and C in combination (without A), or A, B and C in combination.

[0124] Although illustrative embodiments of the invention have been described in detail herein with reference to the accompanying drawings, it is to be understood that the invention is not limited to those precise embodiments, and that various changes and modifications can be effected therein by one skilled in the art without departing from the scope of the invention as defined by the appended claims.

Claims

CLAIMS1 . A data processing apparatus implemented on one or more chiplets, comprising: processing circuitry to perform data processing; memory storage circuitry to store data and instructions for processing by the processing circuitry; and black box circuitry responsive to detection of occurrence of an anomalous event indicative of a risk of loss of safety-critical functioning of the data processing apparatus, to capture an event log of telemetry data indicative of behaviour of the data processing apparatus associated with timepoints before or after the occurrence of the anomalous event; wherein the black box circuitry is integrated onto at least one of the one or more chiplets of the data processing apparatus.

2. The data processing apparatus according to claim 1 , in which the black box circuitry is configured to sign the event log to enable attestation of a source of the event log.

3. The data processing apparatus according to any of claims 1 and 2, in which the black box circuitry is configured to perform an immutability-protecting action to protect the event log against tampering.

4. The data processing apparatus according to any preceding claim, in which the black box circuitry is configured to generate at least one event log digest associated with the event log, each event log digest derived from at least a portion of the event log and providing a verification value for detection of tampering with the event log.

5. The data processing apparatus according to claim 4, in which the black box circuitry is configured to transmit the at least one event log digest to an external device external to the data processing apparatus or to at least one neighbour chiplet of the data processing apparatus other than the at least one chiplet comprising the black box circuitry.

6. The data processing apparatus according to any preceding claim, in which the black box circuitry is configured to associate timestamps with the event log to enable synchronisation of timepoints associated with different streams of telemetry data captured in the event log.

7. The data processing apparatus according to any preceding claim, in which the black box circuitry is configured to include in the event log pre-event telemetry data associated with timepoints before the occurrence of the anomalous event.

8. The data processing apparatus according to any preceding claim, in which, in absence of occurrence of the anomalous event, the black box circuitry is configured to write captured telemetry data to a first-in-first-out buffer of telemetry data; and in response to detection of the occurrence of the anomalous event, the black box circuitry is configured to capture, as pre-event telemetry data to be included in the event log, contents of the first-in-first-out buffer corresponding to a recent window of timepoints before occurrence of the anomalous event, and prevent said pre-event telemetry data being overwritten by subsequently captured telemetry data.

9. The data processing apparatus according to any preceding claim, in which, in response to detection of the occurrence of the anomalous event, the black box circuitry is configured to capture, and include in the event log, post-event telemetry data associated with timepoints after the occurrence of the anomalous event.

10. The data processing apparatus according to any preceding claim, in which in response to detection of the occurrence of the anomalous event, the black box circuitry is configured to trigger capture of at least one type of post-event telemetry data not previously captured prior to detection of the occurrence of the anomalous event, and to include said at least one type of post-event telemetry data in the event log.11 . The data processing apparatus according to any preceding claim, in which the black box circuitry is configured to capture the event log in black box memory storage circuitry separate from the memory storage circuitry.

12. The data processing apparatus according to any preceding claim, in which the black box circuitry is configured to operate in a black box power domain separate from at least one power domain associated with the processing circuitry and the memory storage circuitry.

13. The data processing apparatus according to any preceding claim, in which the black box circuitry is provided within a same semiconductor package as the processing circuitry and the memory storage circuitry.

14. The data processing apparatus according to any preceding claim, in which the black box circuitry is provided on a same chiplet as at least a portion of at least one of the processing circuitry and the memory storage circuitry.

15. The data processing apparatus according to any preceding claim, comprising input / output interface circuitry to communicate with external devices external to the data processing apparatus according to an input / output interface protocol; wherein communications between the black box circuitry and other portions of the data processing apparatus are via internal signal paths separate from the input / output interface circuitry.

16. The data processing apparatus according to any preceding claim, in which the anomalous event comprises at least one of: a system crash event; detection of a possible attack on the data processing apparatus by a malicious party; an anomalous pattern of interrupts or faults; an anomalous pattern of modular redundancy errors; detection of abnormal processing performance associated with the data processing apparatus; a change in configuration or integrity of the system that risks compromising safety; removal of a physical protective measure.

17. The data processing apparatus according to any preceding claim, in which the event log comprises data from portions of the data processing apparatus that are inaccessible via external pins of said one or more chiplets of the data processing apparatus.

18. The data processing apparatus according to any preceding claim, in which the event log comprises at least one of: context information indicative of a processing context active at the time of occurrence of the anomalous event; software version information indicative of a version of software being processed at the time of occurrence of the anomalous event; fingerprint data indicative of a fingerprint of software activity on the data processing apparatus; interrupt data; performance monitoring data; memory access data; memory built-in-self test data; prefetcher data; branch predictor data; neighbour chiplet data communicated to the black box circuitry from one or more neighbour chiplets other than the one or more chiplets comprising the black box circuitry;power management data associated with power management of the data processing apparatus; and modular redundancy checking information.

19. The data processing apparatus according to any preceding claim, in which, in absence of occurrence of the anomalous event, the black box circuitry is configured to capture safety-critical telemetry data and non-safety-critical telemetry data; and; in response to occurrence of the anomalous event, the black box circuitry is configured to prioritise retention of the safety-critical telemetry data over retention of the non-safety-critical telemetry data.

20. A system comprising: the data processing apparatus of any preceding claim, implemented in at least one packaged chip; at least one system component; and a board, wherein the at least one packaged chip and the at least one system component are assembled on the board.

21. A chip-containing product comprising the system of claim 20, wherein the system is assembled on a further board with at least one other product component.

22. Computer-readable code for fabrication of a data processing apparatus according to any preceding claim.

23. A method comprising: performing data processing on a data processing apparatus implemented on one or more chiplets, the data processing apparatus comprising processing circuitry to perform the data processing and memory storage circuitry to store data and instructions for processing by the processing circuitry; and in response to detection of occurrence of an anomalous event indicative of a risk of loss of safety-critical functioning of the data processing apparatus, capturing an event log of telemetry data indicative of behaviour of the data processing apparatus associated with timepoints before or after the occurrence of the anomalous event; wherein the event log is captured using black box circuitry integrated onto at least one of the one or more chiplets of the data processing apparatus.

24. A chiplet for a data processing apparatus, the chiplet comprising:black box circuitry responsive to detection of occurrence of an anomalous event indicative of a risk of loss of safety-critical functioning of a data processing apparatus, to capture an event log of telemetry data indicative of behaviour of the data processing apparatus associated with timepoints before or after the occurrence of the anomalous event; and internal signal paths to communicate between the black box circuitry and other portions of the data processing apparatus, said internal signal paths being separate from input / output interface circuitry used by the data processing apparatus to communicate with external devices external to the data processing apparatus according to an input / output interface protocol.

Citation Information

Patent Citations

  • Safety protection method for Chiplet chip system

    CN117290898A

  • Verifiable redactable audit log

    US20150188715A1

  • Method, apparatus, and electronic device for blockchain-based recordkeeping

    US20210081551A1

  • Redundant data log retrieval in multi-processor device

    US20230161599A1

  • EP23306870A