Selective Read-Only Protection for System Control Registers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for protecting system control registers in data processing apparatuses lack flexibility, as they often enforce a fixed set of registers to be read-only, restricting usage models and not providing adequate security against compromised trusted software.
Innovation Solution
A data processing apparatus with a write control register and disable control logic that allows selective marking of system control registers as read-only, enabling programmable write restriction data to manage access rights dynamically, even for trusted software routines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a fixed predetermined list of system control registers is enforced to become read only, then security of system control register contents is improved, but flexibility in usage models deteriorates
Solution Approach 1:
The patent segments the system control registers into two categories: those that become read-only when the disable signal is set, and those that remain writable. This is achieved through the write control logic that checks the disable signal status and the specific control register being accessed, allowing selective enforcement of read-only protection rather than a blanket restriction on all system control registers.
Solution Approach 2:
The patent introduces a dynamic mechanism where the read-only enforcement is not fixed but can be changed by clearing the disable signal. When the disable signal is cleared, previously read-only control registers become writable again, allowing the system to dynamically switch between protected and configurable states based on operational needs.
2Ease of operation
If trusted software is used to update system control registers, then ease of operation is improved, but security against compromised trusted software deteriorates
Solution Approach 1:
The patent applies preliminary action by setting the disable signal before trusted software updates the system control registers. This ensures that once the registers are configured, they are immediately protected from further modification, preventing compromised trusted software from altering critical system control settings after initialization.
Solution Approach 2:
The patent implements preliminary anti-action by establishing the disable signal mechanism that preemptively blocks write access to system control registers after they have been configured. This creates a protective barrier against potential compromises of trusted software that might attempt to maliciously modify system control settings.
Data Source
AI summary
A data processing apparatus and method for protecting system control registers is provided. Processing logic is providing for executing software routines and a plurality of system control registers are used to store access control information for a plurality of system resources available to the processing logic when executing at least some of those software routines. Additionally, at least one write control register is provided, with each field of that register being associated with one or more of the system control registers. Disable control logic is used to generate a disable signal, and when that disable signal is clear access control information can be written into the system control registers, and write restriction data can be written into each of the fields of the at least one write control register. Then, when the disable control logic sets the disable signal, the at least one write control register becomes read only, and for each field that has write restriction data therein those associated system control registers indicated by the write restriction data also become read only. This mechanism provides a very flexible approach for programming which system control registers are to be treated as read only registers.


