EP3192003B1

Providing a trusted execution environment using a processor

Abstract

This record has no abstract on file.

EP3192003B1, drawing sheet 1
Sheet 1 of 6

Term

8.8 yearsleft in the term

Expires 28 July 2035.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

13 claims: 7 independent, 6 dependent

  1. 1
    A system on a chip (SoC) comprising:a single core, wherein the single core comprises the only core of the SoC, and wherein the single core is configured to enter a system management mode (SMM) to provide a trusted execution environment (TEE) to perform at least one secure operation, wherein in the TEE, the single core is to emulate at least one security instruction of an instruction set unsupported by the single core;and a memory controller coupled to the single core, the memory controller to interface with a system memory, wherein, to set up the TEE, the single core is to authenticate a pre-boot firmware, execute the pre-boot firmware, create a trusted portion of the system memory for the SMM, and transfer execution to a trusted agent associated with the trusted portion to obtain a key pair from a protected storage and store the key pair in the trusted portion of the system memory.
  2. 3
    The SoC of any one of claims 1 or 2, wherein in the TEE, the single core is to receive encrypted content, decrypt the encrypted content using one or more derived keys stored in an unprotected storage coupled to the SoC, and output the decrypted content to an output device via a trusted channel.
  3. 4
    The SoC of any one of claims 1 or 2, wherein in the TEE, the single core is to encrypt a page of information stored in the secure memory and store the encrypted page in an unprotected portion of the system memory.
  4. 5
    The SoC of any one of claims 1 or 2, wherein the SoC further comprising a boot read only memory (ROM) to store the key pair in a protected portion of the boot ROM.
  5. 8
    A method for setting up a trusted execution environment on a system on a chip (SoC) comprising a single core of a processor and a memory controller, wherein the single core comprises the only core of the SoC, wherein the memory controller is coupled to the single core, and wherein the memory controller is to interface with a system memory, the method comprising executing at least a portion of a firmware of a pre-boot environment in the single core of the processor to create a trusted portion of the system memory for a system management mode (SMM) to provide a trusted execution environment (TEE) to perform at least one secure operation, wherein in the TEE, the single core is to emulate at least one security instruction of an instruction set unsupported by the single core;and transferring execution to a trusted agent associated with the trusted portion, requesting a key pair from a protected portion of a non-volatile storage, storing the key pair in the trusted portion of the system memory.
  6. 12
    An apparatus comprising means to perform a method as claimed in any one of claims 8 to 11.
  7. 13
    A machine-readable storage medium including machine-readable instructions, which when executed by a processor, causing said processor to implement a method as claimed in any one of claims 8 to 11.