Processor Register File Integrity Protection via RoT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security circuitry in electronic devices is inadequate to combat a wide variety of software, physical, and electromagnetic attacks, often designed on a disjointed or ad hoc basis, leading to interoperability issues and increased complexity in design and testing, which can result in overlooked security threats.

Innovation Solution

Implementing a flexible and adaptable framework for programmable security hardware that enables seamless interaction between different security-related components using a common communication protocol, incorporating a hardware root of trust (RoT) and integrity codes to verify and protect information in processor registers, ensuring end-to-end integrity protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security circuitry is designed on a disjointed or ad hoc basis to combat various attacks, then specific security threats can be addressed, but interoperability issues and design complexity increase

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsecurity architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security circuitry into modular components, each designed to address specific security threats independently. These modular segments can be selectively activated based on the type of attack detected, reducing the need for a monolithic complex security system while maintaining comprehensive protection coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security architecture that can handle multiple types of attacks (software malware, physical attacks, electromagnetic attacks) through a unified framework. This multi-functional design allows the same base architecture to adapt to different threat scenarios, reducing overall system complexity while maintaining broad security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive security measures are implemented to protect against all types of attacks, then device security is improved, but design and testing complexity increases

Engineering Contradiction:
Improvedevice securityVSAvoiddesign and testing ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements preliminary security measures by integrating security circuitry directly into the processor architecture at the design stage. Integrity codes and protection mechanisms are built-in beforehand, allowing security verification to occur automatically during normal operation without requiring extensive external testing or validation procedures.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If hardware-based protection is incorporated to counter physical and electromagnetic attacks, then protection against sophisticated attacks is improved, but existing anti-malware strategies become insufficient

Engineering Contradiction:
Improveprotection against physical and electromagnetic attacksVSAvoidcompatibility with existing anti-malware programs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces hardware-based security circuitry as an intermediary layer between the processor and external threats. This intermediary provides a root of trust that verifies the integrity of software and hardware components, enabling cooperation between existing anti-malware programs and new hardware-based protection mechanisms rather than creating conflicts between them.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12189824B2Register file protection
Publication Date: 2025.01.07 GOOGLE LLC
  • US12189824B2 patent drawing
  • US12189824B2 patent drawing
  • US12189824B2 patent drawing

AI summary

An integrated circuit chip can provide protection with registers of a register file. A processor can be part of general or security-oriented (e.g., root-of-trust (RoT)) circuitry. In described implementations, the processor includes multiple register blocks for storing multiple register values. The processor also includes multiple integrity blocks for storing multiple integrity codes. A respective integrity block is associated with a respective register block. The respective integrity block can store a respective integrity code that is derived from a respective register value that is stored in the respective register block. The integrity code can enable detection or correction of one or more corrupted bits in the register value. An integrity controller of the processor can monitor the register value regularly or in response to an access by an execution unit. The controller can take a protective action if corruption is detected. This enables information protection to extend to processor execution units.