Point-to-Point Interconnect Secure Initialization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trusted microprocessor systems face challenges in maintaining privacy and security due to the complexity of operating systems and the inability to use common commercially available software, as well as scalability issues with processor connections.

Innovation Solution

A microprocessor system employing a point-to-point interconnect architecture with secure processors and a Trusted Platform Module (TPM) that uses Secure Virtual Machine Monitor (SVMM) and Secure Initialization Authenticated Code (SINIT-AC) to establish a trusted environment through secure launch and interconnection messaging, allowing simultaneous execution of trusted and untrusted software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a complete closed set of trusted software is used, then security and privacy are improved, but the ability to use common commercially available operating system and application software deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidsoftware compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments software execution into two distinct environments: a trusted execution environment (TEE) for security-critical code and a standard operating system environment for common software. The TEE is isolated from the rest of the system, allowing trusted software to execute with enhanced security while standard software operates independently without compromising either environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A software mediator or gateway is introduced between the trusted execution environment and the standard operating system. This intermediary enables controlled interaction between trusted and untrusted software components, allowing common commercially available software to access secure resources through the mediator while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If processors are connected through a front-side bus, then system implementation is simplified, but scalability deteriorates

Engineering Contradiction:
Improvesystem implementationVSAvoidscalability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system replaces the monolithic front-side bus architecture with multiple independent point-to-point interconnects between processors and memory controllers. Each processor has dedicated interconnect paths to memory and other processors, eliminating the shared bus bottleneck and enabling independent scaling of each component without affecting the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The interconnection architecture transitions from a two-dimensional bus structure to a three-dimensional hierarchical interconnect topology with multiple layers of point-to-point connections. This dimensional expansion allows for increased bandwidth, reduced latency, and better scalability by adding more interconnect layers rather than expanding a single bus width.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8973094B2Execution of a secured environment initialization instruction on a point-to-point interconnect system
Publication Date: 2015.03.03 INTEL CORP
  • US8973094B2 patent drawing
  • US8973094B2 patent drawing
  • US8973094B2 patent drawing

AI summary

Methods and apparatus for initiating secure operations in a microprocessor system are described. In one embodiment, a system includes a processor to execute a secured enter instruction, and a chipset to cause the system to enter a quiescent state during execution of the secured enter instruction.