AC-ROT Root Leaf Identity Generation for CPU Sub-Socket Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In systems on chip (SoCs) with partitioned CPU sockets, establishing independent identities for each sub-socket is challenging due to the single physical device identity associated with the CPU.
Innovation Solution
The implementation of an active component root of trust (AC-ROT) mechanism, where a single AC-ROT Root is used to generate unique AC-ROT Leaf identities for each sub-socket, allowing each sub-socket to operate as an independent cluster with its own identity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single physical CPU is partitioned into multiple sub-sockets to improve resource utilization and flexibility, then adaptability and productivity are improved, but device complexity and security verification difficulty increase due to the single physical device identity
Solution Approach 1:
The patent segments the single physical CPU identity into multiple virtual identities (AC-ROT Leaves) corresponding to each sub-socket. The control circuitry partitions the CPU socket into multiple sub-sockets and generates a unique AC-ROT Leaf for each sub-socket, enabling each partition to have its own identity while sharing the physical hardware resource.
Solution Approach 2:
The patent introduces an AC-ROT Leaf as an intermediary identity layer between the physical CPU and the platform root of trust. This intermediary enables security verification for each sub-socket without requiring separate physical identities, resolving the conflict between partitioning flexibility and identity management complexity.
2Reliability
If multiple unique identities are generated for each sub-socket to improve security verification, then platform integrity is maintained, but manufacturing complexity increases
Solution Approach 1:
The patent performs preliminary action by generating all AC-ROT Leaf identities before the CPU begins operation. The control circuitry generates the AC-ROT Leaves during initialization, establishing the identity structure in advance so that security verification can proceed without adding operational complexity.
Solution Approach 2:
The patent creates copies of the root of trust (AC-ROT Leaves) for each sub-socket. Each AC-ROT Leaf is a derived identity that copies the security properties of the parent AC-ROT Root while maintaining uniqueness for its specific sub-socket, enabling standardized manufacturing processes.
3Productivity
If dynamic partitioning is implemented to improve resource allocation efficiency, then productivity increases, but security verification difficulty increases due to changing configurations
Solution Approach 1:
The patent implements dynamic partitioning where the control circuitry can modify the partitioning configuration of the CPU socket during operation. When partitioning changes occur, the system dynamically generates or updates the corresponding AC-ROT Leaves, allowing the identity structure to adapt to changing configurations while maintaining verification capability.
Solution Approach 2:
The patent establishes a feedback mechanism where the platform root of trust verifies the AC-ROT Leaf identities and communicates verification results back to the control circuitry. This feedback loop ensures that even with dynamic partitioning changes, security verification is maintained through continuous validation of the generated identities.
Data Source
AI summary
A computer platform is disclosed. The computer platform comprises a central processing unit (CPU) including at least one socket having a plurality of tiles and control circuitry to partition the socket into a plurality of sub-sockets and assign a unique identity to each of the plurality of sub-sockets for security verification, wherein each sub-socket comprises at least one of the plurality of tiles to operate as a cluster of resources.


