Security domain prediction
Abstract
A data processing apparatus 2 supports operation in both a secure domain and a less secure domain. The secure domain has access to data that is not accessible when operating the less secure domain. Prediction circuitry 42 generates a domain prediction indicating whether a given processing action (such as a memory access) is to be performed in association with the secure domain or with the less secure domain. In this way, an appropriate set of memory permission data 34, 36 for controlling access by different privilege levels in the domains may be selected and applied by an appropriate memory protection unit. If the domain prediction is incorrect, then the processing is stalled and the given processing action retried.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
21 claims: 3 independent, 18 dependent
- 1A data processing device, the data processing device comprising:processing circuitry configured to perform a data processing operation in response to a program instruction, the processing circuitry having a plurality of operational domains including a security realm And a less secure field, wherein when operating in the security domain, the processing circuitry can access data that is not accessible when operating in the less secure domain;and predictive circuitry that couples Up to the processing circuitry and configured to generate a domain prediction to predict whether a given processing action to be performed by the processing circuitry should operate in association with the security realm or should be associated with the less secure realm Where the processing circuitry performs the given processing action based on the domain prediction. 一種資料處理設備,該資料處理設備包括:處理電路系統,該處理電路系統配置用於回應於程式指令來執行資料處理操作,該處理電路系統具有複數個操作領域,該等操作領域包括一安全領域與一安全性較差領域,其中當在該安全領域中操作時,該處理電路系統可存取當在該安全性較差領域中操作時不可存取的資料;以及預測電路系統,該預測電路系統耦合至該處理電路系統並且配置用於產生一領域預測,以預測將由該處理電路系統執行的一給定處理動作是應該與該安全領域相關聯地操作還是應該與該安全性較差領域相關聯地操作,其中該處理電路系統基於該領域預測來執行該給定處理動作。 一種資料處理設備,該資料處理設備包括:處理電路系統,該處理電路系統配置用於回應於程式指令來執行資料處理操作,該處理電路系統具有複數個操作領域,該等操作領域包括一安全領域與一安全性較差領域,其中當在該安全領域中操作時,該處理電路系統可存取當在該安全性較差領域中操作時不可存取的資料;以及預測電路系統,該預測電路系統耦合至該處理電路系統並且配置用於產生一領域預測,以預測將由該處理電路系統執行的一給定處理動作是應該與該安全領域相關聯地操作還是應該與該安全性較差領域相關聯地操作,其中該處理電路系統基於該領域預測來執行該給定處理動作。
- 18A data processing device, the data processing device comprising:processing means for performing a data processing operation in response to a program instruction, the processing means having a plurality of operation fields including a security field and a security a poor field, wherein when operating in the security realm, the processing means can access data that is not accessible when operating in the less secure domain;and predictive means coupled to the processing means for Generating a domain prediction to predict whether a given processing action to be performed by the processing means should operate in association with the security realm or in association with the less secure domain, wherein the processing means executes the prediction based on the domain prediction Given the processing action. 一種資料處理設備,該資料處理設備包括:處理手段,該處理手段用於回應於程式指令而執行資料處理操作,該處理手段具有複數個操作領域,該等操作領域包括一安全領域與一安全性較差領域,其中當在該安全領域中操作時,該處理手段可存取當在該安全性較差領域中操作時不可存取的資料;以及預測手段,該預測手段耦合至該處理手段,用於產生一領域預測以預測將由該處理手段執行的一給定處理動作應該與該安全領域相關聯地操作還是與該安全性較差的領域相關聯地操作,其中該處理手段基於該領域預測來執行該給定處理動作。 一種資料處理設備,該資料處理設備包括:處理手段,該處理手段用於回應於程式指令而執行資料處理操作,該處理手段具有複數個操作領域,該等操作領域包括一安全領域與一安全性較差領域,其中當在該安全領域中操作時,該處理手段可存取當在該安全性較差領域中操作時不可存取的資料;以及預測手段,該預測手段耦合至該處理手段,用於產生一領域預測以預測將由該處理手段執行的一給定處理動作應該與該安全領域相關聯地操作還是與該安全性較差的領域相關聯地操作,其中該處理手段基於該領域預測來執行該給定處理動作。
- 20A method of processing data, the method comprising the steps of:performing data processing operations using processing circuitry in response to program instructions, the processing circuitry having a plurality of operational domains including a security domain and a less secure domain Wherein, when operating in the security realm, the processing circuitry can access data that is not accessible when operating in the less secure area;Generating a domain prediction to predict whether a given processing action to be performed by the processing means should be performed in association with the security realm or in association with the less secure realm;and executing the given processing based on the domain prediction action. 一種處理資料的方法,該方法包括以下步驟:回應於程式指令而使用處理電路系統執行資料處理操作,該處理電路系統具有複數個操作領域,該等操作領域包括一安全領域與一安全性較差領域,其中當在該安全領域中操作時,該處理電路系統可存取當在該安全性較差領域中操作時不可存取的資料; 產生一領域預測,以預測將由該處理手段執行的一給定處理動作應該與該安全領域相關聯地執行還是與該安全性較差領域相關聯地執行;以及基於該領域預測而執行該給定處理動作。 一種處理資料的方法,該方法包括以下步驟:回應於程式指令而使用處理電路系統執行資料處理操作,該處理電路系統具有複數個操作領域,該等操作領域包括一安全領域與一安全性較差領域,其中當在該安全領域中操作時,該處理電路系統可存取當在該安全性較差領域中操作時不可存取的資料; 產生一領域預測,以預測將由該處理手段執行的一給定處理動作應該與該安全領域相關聯地執行還是與該安全性較差領域相關聯地執行;以及基於該領域預測而執行該給定處理動作。
Independent claims3
41 paragraphs in 1 section, as filed
Security field forecast
SECURITY DOMAIN PREDICTION
The present invention relates to the field of data processing systems. More specifically, this The invention relates to data processing systems that include multiple security domains, such as security domains and poor security.
It is known to provide a data processing system, such as implemented by Cambridge, England. ARM's processor designed for the TrustZone feature structure of those data processing systems. Within such systems, a security realm can be provided for manipulating processing involving sensitive materials (such as cryptographic keys, financial information, etc.), as well as providing less secure areas for routine processing tasks, such as user interfaces. Management, media processing, and more. Different domains can access different sources, where the security realm can access at least some sources that are inaccessible to one or more less secure domains. Multiple privilege levels may be provided within the fields themselves, such as a supervisor privilege level for executing the operating system and a user privilege level for executing the application.
In one aspect, the present invention provides a data processing device, the data processing device comprising: Processing circuitry that is configured to respond to the process The instructions are used to perform a data processing operation, the processing circuitry having a plurality of operational domains, including security domains and areas of poor security, wherein the processing circuitry is accessible when operating in the security domain Data that is inaccessible when operating in a less secure field; and predictive circuitry coupled to the processing circuitry and configured to generate domain predictions to predict a given processing action to be performed by the processing circuitry Whether it should operate in association with the security realm or should be associated with the less secure domain, where the processing circuitry performs the given processing action based on the domain prediction.
The present invention recognizes that when there is a given processing action for an executable Processing bottlenecks can occur when the needs of the operational domain are addressed. The present invention solves this problem by generating a domain prediction for which security domain a given processing action should be performed, and then performing a given processing action based on the domain prediction.
In at least some embodiments, in at least one of the fields A plurality of privilege levels are provided, wherein different privilege levels have different access permissions, for example, one of the fields is used according to the privilege level, using access to different areas of the memory address space depending on the current privilege level Subdivided by permission. This privilege level division can be considered as a division orthogonal to the division between domains.
At least some embodiments include a memory license control circuitry, The system uses the memory license data in the security domain or the less secure memory domain license data as part of the access control action to control the memory. access. In this case, the given processing action that is performed depending on the prediction domain is an access control action based on the prediction domain predicted by the prediction circuitry, using the security domain's memory license data or security. Execution of poorly licensed memory domain data.
The memory admission control circuitry can be used to rank the first privilege A different access license is provided with the second privilege level. The memory admission control circuitry can take the form of, for example, a memory management unit that uses page table data stored in a memory address space. In other embodiments, the memory license control circuitry includes a memory protection unit circuitry for managing memory license data based on memory license data and security in the security domain. The access of the memory, the memory license data in the security domain and the memory license data in the less secure domain each specify a plurality of different memory regions in the memory address space. In some embodiments, each of the regions has at least one associated memory access attribute. The memory protection unit circuitry compares the address of the memory access with the address range of the different regions to determine which associated memory access attribute to apply to the memory access. In some embodiments, the presence or absence of a memory region may include some or all of the attribute data.
In such embodiments, the memory protection unit circuitry needs Depending on whether the address is associated with the security realm or with a less secure domain, use the security license data in the security realm or the memory license data in the less secure realm. Because the system can switch between fine-grained areas in the security realm and less secure areas, it is based on address-related The choice of which license material to use in the field may be a critical path issue. In this case, the use of domain predictions makes it easy to meet critical path needs at the expense of accidental mispredicted recovery.
Some embodiments include a domain attribute circuit system, the domain attribute The road system uses the domain attribute data to perform the domain indication action, thereby generating a domain indicator that indicates whether the memory access operation is associated with the security realm or with a less secure realm. The domain attribute circuitry will take a finite amount of time to execute the decision and generate a domain indicator, and thus using the domain prediction can mitigate timing constraints before the domain indicator becomes available.
In some embodiments, the domain attribute data can specify the memory location A plurality of different areas of memory within the address space. In some exemplary embodiments, each of the different domain memory regions may have at least one related domain attribute. The domain attribute circuitry can compare the address of the memory access with the address of the memory area of the different fields to determine which of the domain attributes to apply. The domain attribute may be, for example, a simple indication of whether the memory address is an address associated with the security realm or an address associated with a less secure realm. In other embodiments, the presence or absence of a domain memory region may itself be used as a related domain property.
In some embodiments, predictive comparison circuitry can be provided for comparison The domain prediction and the domain indicator, and if there is no match between the two, triggers a retry action, in which the processing circuitry again performs a given processing action based on the domain indicator (the action is initially based on The correct field predicts execution).
In some embodiments, the given before the retry action may be revoked The result of the action is processed and the original result is replaced with one or more results from a given process action of the retry action.
The processing circuitry can be stopped at least during the memory access operation during the retry action to provide sufficient time to complete the retry action.
In some embodiments the memory access operation can be an instruction fetch operation. The fetch instruction can be a security sensitive operation because it allows execution of a secure code that will reveal confidential information. Therefore, the control of instruction fetching is a method that is very suitable for systems that use the security domain and the less secure domain. It is expected that such systems should be highly efficient, and this desire can be assisted by the use of domain predictions in at least some example embodiments.
The previously discussed domain attribute circuitry can be configured to perform its domain indication actions in parallel with the access control actions performed by the memory admission control circuitry. Performing these two actions in parallel mitigates timing constraints and can allow for higher performance.
It will be appreciated that the prediction circuitry can be used to generate its predictions in a number of different ways. A simple form of prediction is that the domain prediction should be the same as the current domain in which the system is operating. Another form of prediction that can be used in other embodiments is that the domain prediction is the domain previously associated with a given processing action to be performed.
It will also be appreciated that the security realm and the less secure domain may include different numbers of privilege levels, and in some embodiments, the security realm and the less secure realm each comprise a plurality of privilege levels. This enables flexible control of the processing performed on either side of the domain boundary and also enables Called between different privilege levels on different sides of the supported domain boundary.
Viewed from another aspect, the present invention provides a data processing device. The data processing device includes: processing means for performing a data processing operation in response to the program instruction, the processing means having a plurality of operation fields including a security field and a security-lower field, wherein When operating in the security realm, the processing means can access data that is inaccessible when operating in a less secure field; and predictive means coupled to the processing means for generating domain predictions to predict Whether a given processing action performed by the processing means should operate in association with the security realm or in association with the less secure realm, wherein the processing means performs the given processing action based on the domain prediction.
Viewed from another aspect, the present invention provides a method for processing data. The method includes the steps of: performing a data processing operation using a processing circuit system in response to a program instruction, the processing circuit system having a plurality of operational fields including a security domain and a less secure domain, wherein when in security When operating in the field, the processing circuitry can access data that is not accessible when operating in a less secure field; generating domain predictions to predict that a given processing action to be performed by the processing means should be associated with the security realm Execution is also performed in association with a less secure domain; and the given processing action is performed based on the domain prediction.
The above and other objects, features and advantages of the present invention are as follows A detailed description of the illustrative embodiments will be apparent from the following description.
<p>2Data processing equipment</p><p>4 Processor Core</p><p>6 memory</p><p>8Information</p><p>10Program Instructions</p><p>12Load storage unit</p><p>14Command Capture Unit</p><p>16Domain Attribute Unit</p><p>18Memory License Control Circuitry</p><p>20Processing pipeline</p><p>22Decoder</p><p>24Control signal</p><p>26storage group</p><p>28Multiplier</p><p>30Shifter</p><p>32Adder</p><p>34Safe memory protection data</p><p>36Memory license information in areas with poor security</p><p>38Multiplexer</p><p>40 comparator</p><p>42 Prediction Circuit System</p><p>44Field comparator</p><p>46Field attribute data</p><p>48Predictive Comparison Circuit System</p><p>50 steps</p><p>52Steps</p><p>54Steps</p><p>56Steps</p><p>58Steps</p><p>60 steps</p><p>62Steps</p><p>64Steps</p><p>66Steps</p><p>68Steps</p><p>70Steps</p><p>72Steps</p><p>74Steps</p><p>76Steps</p><p>78Steps</p><p>80 steps</p><p>90BLX Directive</p><p>92 Login Point Program Instructions</p><p>94 function</p><p>96BX program instructions</p><p>98 Remaining program instructions</p><p>100Insecure security</p>
Figure 1 schematically illustrates a data processing device, the data processing device Supporting both the security realm and the poor security of the execution of program instructions; Figure 2 schematically illustrates the relationship between the less secure domain, the security realm, and the different privilege levels in the two domains; Figure 3 is a flow diagram schematically illustrating control of memory access to a system comprising multiple domains and multiple privilege levels within their fields.
Figure 4 is a diagram illustrating a function call from the less secure area to the security realm; Figure 5 is a diagram schematically illustrating the use of domain prediction to select which memory license data to use to determine Whether to allow memory access to a given memory address; and Fig. 6 is a flow chart schematically illustrating the operation of the circuit of Fig. 3.
FIG. 1 schematically illustrates a data processing device 2 comprising a processor core 4 and a memory 6. The memory 6 stores both the data to be manipulated 8 and the program instructions 10 to be executed as a sequence of program instructions (both in a secure form and in a less secure form). The processor core 4 uses the load storage unit 12 and the instruction fetch unit 14 to read and write the data 8 and retrieve the program instructions 10 to be executed. The data processing device 2 supports two fields of operation, that is, a field of security and security. It will be appreciated that more than two fields may be supported in other embodiments.
The domain attribute unit 16 is configured to store domain attribute data, and the domain belongs to Sex data specifies which memory address is associated with which field. This security realm has access to at least some of the material that is inaccessible when operating in a less secure area. Such information may be, for example, cryptographic keys, cryptographic algorithms, financial information, and other sensitive materials. These areas provide different execution environments for the execution of secure/sensitive programs that use secure data as compared to more conventional processing that can occur in less secure areas. The data processing device 2 has a state in which it is placed in a security field or a poor security field. Each of the fields may include one or more privilege levels that are orthogonal to the fields, such as supervisor level and user level. Different privilege levels may have different memory attributes associated with different areas of the memory address space.
The data processing device 2 includes two memory protection units, the two The memory protection unit responds to the security data in the security field and the location data in the less secure field, respectively, and together form a device that can be considered as the system's memory admission control circuitry 18. The two memory protection units are used to govern memory attributes that will be applied at different privilege levels within the domain. The realm attribute unit 16 is used to govern which field the data processing device 2 must be in order to access a particular memory address, regardless of or regardless of the privilege level.
The instruction fetched by the instruction fetch unit 14 is supplied to the processing pipeline 20. The instructions are decoded from the processing pipeline 20 by the decoder 22 to generate a control signal 24, thereby controlling the processing circuitry, the processing circuitry including the load storage unit 12 and the data processing path, the data processing path including the register group 26. Multiplier 28, shifter 30 and adder 32. It will be appreciated that in practice processor core 4 will typically include many additional processing components (for clarity, Omitted here).
FIG. 2 schematically illustrates different states that the data processing device 2 can employ. First, both the security domain and the less secure areas are illustrated. The conversion between the fields is controlled by the domain attribute unit 16 and the login point instruction 92. At least in this exemplary embodiment, there are both user mode privilege levels and supervisor mode privilege levels in various fields. When the data processing device 2 is in a less secure field, memory access to data access is controlled by a less secure memory protection unit. When operating in the security realm, memory access to data access is controlled by a secure memory protection unit. The switching between privilege levels is controlled by the SVC (Supervisor Call) exception command. It will be appreciated that different memory protection units may actually share circuitry, such as when accessing only one of the memory protection units at a given time, then the different memory protection units are available The comparators are shared in a way that reduces the extra burden of power consumption and the extra burden of circuit area.
Figure 3 is a flow diagram that schematically illustrates the entire set of decisions to be performed for instruction fetching. At step 70, the process waits until there is an instruction fetch to be executed. Data access is handled by different mechanisms. Step 72 then decides which field to apply to the instruction, that is, the less secure field or the security field. If a security realm is selected, then step 74 determines and checks the secure memory attributes of the memory access to determine whether to allow access to the memory. If the memory access is allowed, then step 76 performs the memory access. If the memory access is not allowed, then step 78 triggers an exception.
If the decision at step 72 is to select a less secure area, then the step 80 determines and checks the memory attributes of the memory that are less secure. If the memory access is not allowed, then step 78 triggers an exception. If the memory access is allowed, then step 76 performs the memory access.
Figure 4 is a diagram showing the security from this poor area to the security A function call of the realm; the program flow in the less secure domain 100 encounters a BLX instruction 90 that invokes a function 94 in the memory associated with the security realm. This causes the program stream to change and resume execution at the logon point program instruction 92. Execution of this program instruction causes the processing circuitry to switch the processing of the remaining program instructions 98 in the function to the security realm. Since the login point program instruction 92 causes a domain switch, the execution of the login point program instruction itself is an area of poor security. However, since the instruction is part of a security function in the memory associated with the security realm, the secure memory protection material 34 is used by the MPU 18 when verifying the memory access to the login point program instruction 92. of. Once the remaining program instructions 98 in the security function 94 have been executed, the BX program instructions 96 return the program stream to a less secure field.
Figure 5 schematically illustrates the domain attribute circuitry 16 in more detail with Memory license control circuitry 18. The memory license control circuitry 18 uses the memory license data 34 in the security realm or the memory license data 36 in the less secure domain, which is selected by the multiplexer 38 and supplied to the memory grant control circuitry comparator 40. . The predictive circuitry 42 generates a domain prediction that predicts to switch the multiplexer 38 to one of the set of select memory grant profiles 34, 36 for use by the comparator 40. The comparator 40 uses the memory grant associated with the address of the memory to be checked. Material, and the current privilege level.
The memory license data specifies the difference in the memory address space Areas and memory attributes associated with their different areas. The comparators 40 determine from which memory location the memory address is located from the memory address to be checked. When the area has been identified, the appropriate memory attributes can be read and a decision is made as to whether the memory in question is allowed to be accessed, and a signal allowed by the MPU is generated to indicate this result. If the memory access does not pass its MPU check, an exception will be triggered, as will be familiar to those skilled in the art.
In parallel with the operation of the memory admission control circuitry 18, The domain attribute circuitry 16 uses the memory address accessed by the candidate memory to perform a domain comparison operation using the domain comparator 44 configured by the domain attribute data 46 to determine that the memory address candidate falls within the memory address space. Which of the plurality of regions is in the region. In some exemplary embodiments, if the address matches any of the domain memory regions programmed in the domain attribute circuitry 16, the address is in a less secure area, otherwise the address is in a security realm. In other exemplary embodiments, different domain memory regions may have at least one related domain attribute specified within the domain attribute material 46. This domain attribute may include an indication of whether the memory address in question is associated with a security realm or a less secure realm. Thus, the domain comparator 44 generates a domain indicator signal based on a lookup of the appropriate domain based on the domain memory region and the domain attribute data.
Prediction comparison circuitry 48 is used to compare prediction circuitry 42 domain predictions with actual domain indicators, where the domain predictions are supplied For selecting memory license data 34, 36, the field indicator is determined in parallel with the memory admission control circuitry activity. If the domain prediction does not match the domain indicator, then this indicates a misprediction and a retry signal is generated. At the same time, the predictive comparison circuit system generates a stop signal for stopping the processor core 4, at which time the memory access check by the circuitry of FIG. 3 is re-executed based on the actual field indication carried by the replacement signal, so that The memory license control circuitry 18 will apply the correct data from the memory license profiles 34,36. The result of the memory permission check operation based on the misprediction (the result of the given processing action before the retry operation) is abolished and the result of the memory permission check (given processing action) originating from the retry action is used. Alternative. Therefore, when a misprediction occurs, the processor 14 is stopped for a short period of time.
The prediction circuitry 42 is based on the data processing device 2 being The current realm of operations to make its predictions. This prediction can be made in different ways in other embodiments, such as by using the field used by the given processing action for the last time it was executed. Those skilled in the art will appreciate that other predictive techniques/algorithms can also be used to generate domain predictions associated with different types of processing actions that will depend on the domain involved (or at least associated with the domain) ) was executed.
Figure 6 is a flow chart schematically illustrating the circuit system of Figure 3 Operation. At step 50, processing waits until a memory address is received. When the memory address is received, then steps 52 and 54 are performed in parallel before the process passes to step 56. in step 52, the memory protection unit permission check is performed using the memory protection unit of the prediction domain (current domain). The memory protection unit of the prediction domain is actually made by the memory The shared comparator within controllable circuitry 40 is constructed of appropriately selected data from a collection of memory grant profiles 34,36. Step 54 performs the decision as to which of the security realms or areas of poor security should be applied to the received memory address. This decision is performed by the domain attribute circuitry 16 and results in the generation of an actual domain indicator.
At step 56, an actual determination is made as indicated by the field indicator Whether the field is equal to the decision in the forecasting field. If there is a mismatch, then step 58 causes the data processing device 2 to stop, step 60 replaces the prediction signal generated by the prediction circuitry 42 with the actual domain indication, and then step 62 returns the processing to parallel steps 52, 54. At the beginning, a retry of the memory access permission check is triggered.
If the decision at step 56 is that there is a mismatch, then step 64 determines Whether the access is actually indicated is as permitted by the memory admission control circuitry 18. If the access is allowed, then step 66 performs the access. If the access is not allowed, then step 68 triggers an exception, such as a memory failure.
Although the illustrative embodiments of the present invention have been described in detail herein with reference to the accompanying drawings, it is understood that the invention Various changes and modifications can be made therein without departing from the scope and spirit of the invention.
8 members in 4 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 14310332 | United States of America | – | |
| 201414310332 | United States of America | A | |
| 201414310332 | – | – | – |
| US201414310332 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| US2015371017A1 | United States of America | A1 | |
| GB2527643A | United Kingdom | A | |
| TW201601002AThis record | Taiwan Province of China | A | |
| CN105279451A | China | A | |
| GB2527643B | United Kingdom | B | |
| US9501667B2 | United States of America | B2 | |
| TWI664554B | Taiwan Province of China | B | |
| CN105279451B | China | B |
Numbers
- Publication
- 201601002
- Publication, DOCDB
- 201601002
- Publication, EPODOC
- TW201601002
- Application
- 104112736
- Application, DOCDB
- 104112736
- Application, EPODOC
- TW20154112736
Titles2
- English
- Security domain prediction
- Chinese
- ??????
Classification
- CPC, 12
- G06F21/79
- G06F21/6209
- G06F21/74
- G06F9/3806
- G06F21/78
- G06F21/554
- G06F2221/2141
- G06F2221/2149
- G06F9/3842
- G06F9/3844
- G06F12/14
- G06F2221/2105
- IPC, 2
- G06F21 78
- G06F21 60