Secure On-Die Real-Time Clock Isolation in Microprocessors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing microprocessors are inadequate in providing a secure execution environment that isolates secure code from snooping and tampering, as they rely on external chipsets and system buses, which are susceptible to bus snooping and tampering, and cannot execute general-purpose instructions in secure mode.

Innovation Solution

A microprocessor with a secure non-volatile memory accessed via a private bus, a secure real-time clock, and an external crystal, which generates an oscillating output voltage, allowing for the execution of secure and non-secure applications while isolating secure code from system bus resources and providing a persistent time only accessible in secure mode.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If microprocessors use external chipsets and system buses for execution, then device functionality is improved, but security against snooping and tampering deteriorates

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The microprocessor is divided into distinct secure and non-secure execution domains. A secure execution mode is implemented that isolates critical operations from the general-purpose execution environment, preventing snooping and tampering while maintaining overall system functionality through separate execution contexts

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure execution mode acts as an intermediary layer between the processor core and external system resources. This intermediary provides controlled access to system buses and chipsets, enabling functionality while preventing direct exposure to security threats through buffered and monitored interactions

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure code is isolated from system bus resources, then security is improved, but access to system resources deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidresource access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The microprocessor implements dynamic execution modes that can switch between secure and non-secure states. The secure execution mode can dynamically access system resources when needed while maintaining isolation during critical operations, providing both security and resource accessibility through mode-dependent behavior

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The secure execution mode is designed with multi-functional capabilities, enabling it to perform both security-critical isolated operations and system resource access operations. The same secure execution environment can handle cryptographic operations, timer management, and system resource control through unified secure instructions

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a secure real-time clock is isolated within the microprocessor, then security is improved, but functionality limitations deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidfunctionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The secure real-time clock is designed as a self-contained unit within the microprocessor that generates its own timing signals and maintains timekeeping operations independently. This self-service capability provides security through isolation while maintaining full timing functionality through internal oscillator and counter mechanisms

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The secure real-time clock is nested within the microprocessor architecture, with the clock functionality embedded inside the processor core. This nesting provides security through physical isolation while maintaining functionality through integrated access to processor resources and memory

Inventive Principle:
Principle #7Nested doll (Nesting)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables the execution of secure code within a highly isolated environment, resistant to snooping and tampering, with the ability to execute general-purpose instructions and maintain secure operations without compromising system integrity.

Implementation Method 1

An external crystal is coupled to the secure real time clock within the microprocessor and is configured to cause an oscillator within the secure real time clock to generate an oscillating output voltage that is proportional to the frequency of the external crystal

Methodology Applied
Scientific EffectPiezoelectric effect: Piezoelectric Effect

Data Source

PatentUS20090293132A1Microprocessor apparatus for secure on-die real-time clock
Publication Date: 2009.11.26 VIA TECH INC
  • US20090293132A1 patent drawing
  • US20090293132A1 patent drawing
  • US20090293132A1 patent drawing

AI summary

An apparatus providing for a secure execution environment. The apparatus includes a microprocessor and an external crystal. The microprocessor is configured to execute non-secure application programs and a secure application program, where the non-secure application programs are accessed from a system memory via a system bus and the secure application program is accessed from a secure non-volatile memory via a private bus coupled to the microprocessor. The microprocessor has a secure real time clock that is configured to provide a persistent time, where the secure real time clock is only visible and accessible by the secure application program when the microprocessor is executing in a secure mode. The external crystal is coupled to the secure real time clock within the microprocessor and is configured to cause an oscillator within the secure real time clock to generate an oscillating output voltage that is proportional to the frequency of the external crystal.