On-Die Cryptographic Unit for Secure Microprocessor Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current microprocessors are inadequate in executing general purpose instructions within a secure execution environment due to limitations in existing security features, which can be compromised and are susceptible to snooping and tampering, especially when using external chipsets and system buses.
Innovation Solution
A microprocessor with a secure non-volatile memory and cryptographic unit, isolated from system bus resources, enables execution of secure applications by encrypting and decrypting code using asymmetric key algorithms, ensuring secure execution within a private bus environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If external chipsets and system buses are used for microprocessor execution, then device complexity is reduced and ease of manufacture is improved, but security is compromised due to susceptibility to snooping and tampering
Solution Approach 1:
The microprocessor is segmented into distinct secure and non-secure execution environments. The secure execution environment includes dedicated secure registers, secure instruction streams, and isolated execution units that are physically separated from the non-secure system bus interfaces. This segmentation allows the processor to manufacture using standard external chipsets while maintaining isolated secure paths that prevent snooping and tampering.
Solution Approach 2:
An intermediary secure execution environment is introduced between the external system bus and the critical processing functions. This intermediary layer includes secure memory interfaces and encrypted data paths that mediate all communications between the external bus and internal secure resources, preventing direct access and potential tampering while still allowing external connectivity.
2Reliability
If a secure execution environment is implemented within the microprocessor, then security is improved, but device complexity increases
Solution Approach 1:
The secure execution environment is merged with the existing microprocessor architecture rather than being implemented as a separate external device. Secure registers, encryption units, and isolated execution paths are integrated into the processor core, combining security functions with general-purpose computing resources. This merging reduces overall system complexity by eliminating the need for separate secure coprocessors or external security chips.
Solution Approach 2:
The microprocessor is designed with universal resources that can operate in both secure and non-secure modes. Execution units, memory interfaces, and I/O controllers are configured to handle both encrypted secure instructions and standard non-secure instructions, allowing a single device to perform multiple functions without requiring separate dedicated hardware for each mode.
3Reliability
If secure code is isolated from system bus resources, then security is improved by preventing snooping, but access speed may be reduced
Solution Approach 1:
The secure execution environment is nested within the microprocessor core, with secure registers and instruction streams embedded within the broader processor architecture. This nesting allows secure code to access critical processing resources through direct internal pathways that are hierarchically organized, maintaining high-speed access while preventing exposure to external system bus resources. The nested structure enables secure data to flow through multiple layers of protection without requiring external memory accesses.
Data Source
AI summary
An apparatus providing for a secure execution environment, including a secure non-volatile memory and a microprocessor. The secure non-volatile memory stores a secure application program. The secure application program is encrypted according to a cryptographic algorithm. The microprocessor is coupled to the secure non-volatile memory via a private bus and to a system memory via a system bus. The microprocessor executes non-secure application programs and the secure application program. The non-secure application programs are accessed from the system memory via the system bus. Transactions over the private bus are isolated from the system bus and corresponding system bus resources within the microprocessor. The microprocessor has a cryptographic unit, disposed within execution logic. The cryptographic unit is configured to encrypt the secure application program for storage in the secure non-volatile memory, and is configured to decrypt the secure application program for execution by the microprocessor.


