Microprocessor Secure Execution Mode Logic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current microprocessors are inadequate in executing general purpose instructions within a secure execution environment due to limitations in existing security features, such as reliance on external chipsets and susceptibility to bus snooping and tampering, which compromises security and performance.

Innovation Solution

A microprocessor with a secure non-volatile memory and watchdog manager that isolates secure execution mode logic from system resources, using asymmetric and symmetric cryptographic algorithms to encrypt and decrypt secure applications, and monitors environmental and physical attributes to prevent tampering, ensuring secure execution without external dependencies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure execution is implemented using external chipsets and system bus, then security isolation is provided, but the system becomes susceptible to bus snooping and tampering

Engineering Contradiction:
Improvesecurity isolationVSAvoidbus snooping and tampering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges the secure execution environment and secure application storage directly into the microprocessor by integrating a secure execution mode logic unit and secure non-volatile memory onto the same chip. This eliminates the need for external chipsets and system bus communication for secure operations, thereby preventing bus snooping and tampering while maintaining security isolation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a private bus as an intermediary communication path between the secure execution mode logic unit and secure non-volatile memory. This private bus is isolated from the system bus and other non-secure resources, providing a dedicated communication channel that prevents snooping and tampering while enabling data transfer between secure components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If secure execution mode logic is integrated within the microprocessor, then performance is improved by eliminating external dependencies, but device complexity increases

Engineering Contradiction:
Improveexecution performanceVSAvoidprocessor architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The microprocessor is designed with multi-functionality to handle both secure and non-secure execution modes within a single processor unit. The secure execution mode logic unit can execute secure application programs while the same processor can also execute non-secure applications, eliminating the need for separate secure processors and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The microprocessor architecture is segmented into distinct functional units: a secure execution mode logic unit for executing secure code, a secure non-volatile memory for storing secure applications, and a watchdog manager for monitoring security. This segmentation allows each component to be optimized for its specific function while working together within the integrated processor, managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

3Reliability

If secure applications are stored in external non-volatile memory, then security is maintained through isolation, but access speed is reduced due to bus communication overhead

Engineering Contradiction:
Improvesecurity isolationVSAvoidapplication access speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent combines secure non-volatile memory with the microprocessor on the same chip, eliminating the need for external memory components and system bus communication. This integration dramatically reduces access latency and communication overhead while maintaining security isolation through the private bus and isolated architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The private bus serves as a dedicated intermediary communication path between the secure execution mode logic unit and secure non-volatile memory. This private communication channel eliminates the need to use the slower system bus, providing high-speed access to secure applications while maintaining security isolation from other system resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If watchdog manager monitors environmental and physical attributes, then tampering detection is improved, but power consumption increases

Engineering Contradiction:
Improvetampering detectionVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The watchdog manager implements selective monitoring of environmental and physical attributes rather than continuous monitoring of all parameters. It monitors critical security-relevant attributes such as temperature thresholds and physical tampering indicators, while avoiding unnecessary monitoring of non-critical parameters, thereby reducing power consumption while maintaining effective tampering detection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2667322B1Microprocessor having a secure execution mode with provisions for monitoring, indicating, and managing security levels
Publication Date: 2016.09.14 VIA TECH INC
  • EP2667322B1 patent drawingFigure 1
  • EP2667322B1 patent drawingFigure 2
  • EP2667322B1 patent drawingFigure 3

AI summary

An apparatus providing for a secure execution environment including a microprocessor and a secure non-volatile memory. The microprocessor executes non-secure application programs and a secure application program. The non-secure application programs are accessed from a system memory via a system bus, and the secure application program is executed in a secure execution mode. The microprocessor has a watchdog manager that monitors environments of the microprocessor by noting and evaluating data communicated by a plurality of monitors, and that classifies the data to indicate a security level associated with execution of the secure application program, and that directs secure execution mode logic to perform responsive actions in accordance with the security level. The secure non-volatile memory is coupled to the microprocessor via a private bus, and stores the secure application program. Transactions over the private bus are isolated from the system bus and corresponding system bus resources within the microprocessor.