EP2706478A2

Protecting secure software in a multi-security-CPU system

Abstract

A computing system includes a first central processing unit (CPU) and a second CPU coupled with the first CPU and with a host processor. In response to a request by the host processor to boot the second CPU, the first CPU is configured to execute secure booting of the second CPU by decrypting encrypted code to generate decrypted code executable by the second CPU but that is inaccessible by the host processor.

EP2706478A2, drawing sheet 1
Sheet 1 of 9

Term

6.8 yearsto projected expiry

Projected expiry 26 July 2033, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 4 independent, 11 dependent

  1. 1
    A computing system, comprising:a first central processing unit (CPU);and a second CPU coupled with the first CPU and with a host processor, where, in response to a request by the host processor to boot the second CPU, the first CPU is configured to execute secure booting of the second CPU comprising decrypting encrypted code to generate decrypted code executable by the second CPU but that is inaccessible by the host processor.
  2. 6
    The computing system of any of claims 3 to 5, where in executing the decrypted first stage code, the second CPU is configured to request the first CPU to generate a key usable to decrypt the second stage code, in response to which the first CPU is further configured to:generate the key with specified access rights for use by the second CPU, the access rights including a first region of the DRAM from which to decrypt the second stage code and a second region of the DRAM to which to write the decrypted second stage code;and aid the second CPU in creation of a memory checker configured to ensure decryption occurs only from the first region to the second region of the DRAM.
  3. 11
    A method for securing software in a multi-security central processing unit (CPU) system that includes a first and a second CPU coupled together, comprising:receiving a request from a host processor to boot the second CPU;writing, by the host processor, encrypted code into a dynamic random access memory (DRAM) from flash memory, the encrypted code including a first stage code and a second stage code for executing a two-stage boot process;and decrypting the encrypted first and second stage codes by the first and second CPUs such that the host processor cannot access either the decrypted first stage code or the decrypted second stage code after decryption.
  4. 15
    A computing system, comprising:a first central processing unit (CPU);a dynamic random access memory (DRAM) connected with the first CPU;a flash memory;a second CPU coupled with the first CPU and with the DRAM;a host processor coupled with the first and second CPUs, with the DRAM and with the flash memory, the host processor configured to write encrypted code into the DRAM from the flash memory, the encrypted code including a first stage code and a second stage code for executing a two-stage boot process;where the first CPU is configured to: receive a request form the host processor to boot the second CPU;and decrypt the encrypted first and second stage codes by the first and second CPUs such that the host processor cannot access either the decrypted first stage code or the decrypted second stage code after decryption.