Microprocessor, method of protection and method of revoking first password
Abstract
The invention provides a microprocessor, which includes a key, a special module register, a plurality of fuses, and a microcode. The key is manufactured inside the microprocessor. The special module register has an address specified by instructions executed by the microprocessor. The microcode is used to receive commands that require access to the special module register, where the commands are used to specify the address of the special module register; execute the address and read of the specified special module register A functional operation of the value of the fuse to generate a first result; encrypt the first result with a key to generate a second result; compare the second result with the password specified by the command; and only have the second result Only when the result matches the password, the command is allowed to access the special module register.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
16 claims: 16 independent, 0 dependent
- 1A microprocessor includes:a secret key manufactured inside the above-mentioned microprocessor;a special module register with an address designated by an instruction that can be executed by the above-mentioned microprocessor;a plurality of fuses;and a Microcode for: receiving the above command requesting access to the above special module register, wherein the above command is used to specify the address of the above special module register;using the designated special module for temporary storage The address of the device and a value read from the fuse perform a function operation to generate a first result;use the key to encrypt the first result to generate a second result;compare the second result The result matches one of the passwords specified by the above command;and if the second result matches the above password, the above command is allowed to access the above special module register, otherwise the above command is rejected to store the above special module register Pick. 一種微處理器,包括:一密鑰,製造於上述微處理器的內部;一特別模組暫存器,具有可由上述微處理器執行之一指令所指定之一位址;複數保險絲;以及一微碼,用以:接收要求對上述特別模組暫存器進行存取之上述指令,其中上述指令用以指定上述特別模組暫存器之位址;利用所指定之上述特別模組暫存器之位址與讀取自上述保險絲之一數值執行一函數運算,用以產生一第一結果;使用上述密鑰對上述第一結果進行加密,用以產生一第二結果;比較上述第二結果與上述指令所指定之一密碼;以及若上述第二結果與上述密碼匹配,允許上述指令對上述特別模組暫存器進行存取,否則拒絕上述指令對上述特別模組暫存器進行存取。
- 2The microprocessor as described in item 1 of the scope of patent application, in which the specified address of the above-mentioned special module register and the function calculation of the value read from the above-mentioned fuse, including the designated above-mentioned special module register The address of the device and the Boolean operation of the value read from the fuse mentioned above are mutually exclusive. 如申請專利範圍第1項所述之微處理器,其中所指定之上述特別模組暫存器之位址與讀取自上述保險絲之數值的函數運算,包括所指定之上述特別模組暫存器之位址與讀取自上述保險絲之數值的布林互斥或運算。
- 3The microprocessor described in item 1 of the scope of patent application, wherein Function calculation between the address of the specified special module register and the value read from the fuse, including the sequence of the address of the specified special module register and the value read from the fuse Concatenation. 如申請專利範圍第1項所述之微處理器,其中所 指定之上述特別模組暫存器之位址與讀取自上述保險絲之數值的函數運算,包括所指定之上述特別模組暫存器之位址與讀取自上述保險絲之上述數值的一序連串接(concatenation)。
- 4In the microprocessor described in item 1 of the scope of the patent application, the above-mentioned key cannot be observed by the outside of the above-mentioned microprocessor. 如申請專利範圍第1項所述之微處理器,其中上述密鑰係無法由上述微處理器的外部所觀視的。
- 5The microprocessor described in item 1 of the scope of patent application, wherein the microprocessor uses the key to encrypt the first result according to an Advanced Encryption Standard (AES) to generate the second result. 如申請專利範圍第1項所述之微處理器,其中上述微處理器根據一先進加密標準(AES),使用上述密鑰對上述第一結果進行加密,用以產生上述第二結果。
- 6A security method suitable for a microprocessor to provide selective access to a special module register of the microprocessor. The method includes:receiving a request to store the special module register Take an instruction, where the instruction is used to specify the address of the special module register;use the address of the special module register specified by the microprocessor and read the plural fuses from the processor Perform a function operation on a value to generate a first result;encrypt the first result with a key made in the microprocessor to generate a second result;compare the second result A password specified by the above command;and if the second result matches the password, the command is allowed to access the special module register, otherwise the command is denied to access the special module register . 一種保密方法,適用於一微處理器,用以提供具選擇性之存取至上述微處理器之一特別模組暫存器,上述方法包括:接收要求對上述特別模組暫存器進行存取之一指令,其中上述指令用以指定上述特別模組暫存器之位址;利用上述微處理器所指定之上述特別模組暫存器之位址以及讀取自上述處理器之複數保險絲之一數值執行一函數運算,用以產生一第一結果;使用製造於上述微處理器的內部之一密鑰對上述第一結果進行加密,用以產生一第二結果;比較上述第二結果與上述指令所指定之一密碼;以及若上述第二結果與上述密碼匹配,允許上述指令對上述特別模組暫存器進行存取,否則拒絕上述指令對上述特別模組暫存器進行存取。
- 7As the security method described in item 6 of the scope of patent application, the specified address of the above-mentioned special module register is the same as the one read from the above-mentioned fuse Numerical function operations include the Bollinger mutual exclusive OR operation of the specified address of the special module register and the value read from the fuse. 如申請專利範圍第6項所述之保密方法,其中所指定之上述特別模組暫存器之位址與讀取自上述保險絲之 數值的函數運算,包括所指定之上述特別模組暫存器之位址與讀取自上述保險絲之數值的布林互斥或運算。
- 8The security method described in item 6 of the scope of patent application, in which the specified above-mentioned special module register address and the above-mentioned function calculation of the value read from the above-mentioned fuse include the specified above-mentioned special module temporary storage The address of the device is connected in series with the above-mentioned value read from the above-mentioned fuse. 如申請專利範圍第6項所述之保密方法,其中所指定之上述特別模組暫存器之位址與讀取自上述保險絲之數值的上述函數運算,包括所指定之上述特別模組暫存器之位址與讀取自上述保險絲之上述數值的一序連串接。
- 9The security method described in item 6 of the scope of patent application, wherein the above-mentioned key cannot be observed by the outside of the above-mentioned microprocessor. 如申請專利範圍第6項所述之保密方法,其中上述密鑰係無法由上述微處理器的外部所觀視的。
- 10The security method described in item 6 of the scope of patent application, wherein the encryption step includes the use of advanced encryption standards for encryption. 如申請專利範圍第6項所述之保密方法,其中上述加密步驟包括使用先進加密標準進行加密。
- 11A security method comprising:manufacturing a first version of a microprocessor, the plurality of fuses of the first version of the microprocessor have a first value, and the first version of the microprocessor is used to prohibit an instruction To access a special module register, unless the instruction provides a first password, and the first password uses a key manufactured in the first version of the microprocessor to pair the first value with The address of the special module register is generated by a function operation;the key is used to perform a function operation on the first value and the address of the special module register to generate the first password And provide the above-mentioned first password to users of the above-mentioned first version of the above-mentioned microprocessor;and manufacture a second version of the above-mentioned microprocessor, and the fuse in the second version of the above-mentioned microprocessor has a second value , Wherein the above second version of the above microprocessor is used to prohibit (prohibit) the above instruction to the above special The module register is accessed unless the command provides a second password, and the second password uses the key to pair the second value and the address of the special module register to perform a function operation. produced. 一種保密方法,包括:製造一微處理器之一第一版本,上述微處理器之上述第一版本之複數保險絲具有一第一數值,其中上述微處理器之上述第一版本用以禁止一指令對一特別模組暫存器進行存取,除非上述指令提供一第一密碼,而上述第一密碼係使用製造於上述微處理器之上述第一版本內部的一密鑰對上述第一數值與上述特別模組暫存器之位址進行一函數運算所產生的;使用上述密鑰對上述第一數值與上述特別模組暫存器之位址以執行函數運算,用以產生上述第一密碼,並且提供上述第一密碼給上述微處理器之上述第一版本的使用者;以及製造上述微處理器之一第二版本,上述微處理器之第二版本中之上述保險絲具有一第二數值,其中上述微處理器之上述第二版本用以禁止(prohibit)上述指令對上述特別 模組暫存器進行存取,除非上述指令提供一第二密碼,而上述第二密碼係使用上述密鑰對上述第二數值與上述特別模組暫存器之位址以執行一函數運算所產生的。
- 12According to the security method described in item 11 of the scope of patent application, the above-mentioned function operation includes performing a Bollinger exclusive OR (XOR) operation between the above-mentioned first/second value and the address of the above-mentioned special module register. 如申請專利範圍第11項所述之保密方法,其中上述函數運算包括執行在上述第一/第二數值與上述特別模組暫存器之位址的一布林互斥或(XOR)運算。
- 13According to the security method described in item 11 of the scope of patent application, the above-mentioned function operation includes performing a sequential concatenation of the above-mentioned first/second value and the address of the above-mentioned special module register. 如申請專利範圍第11項所述之保密方法,其中上述函數運算包括執行在上述第一/第二數值與上述特別模組暫存器之位址的一序連串接(concatenation)。
- 14As for the security method described in item 11 of the scope of patent application, the above-mentioned key cannot be observed by the outside of the above-mentioned microprocessor. 如申請專利範圍第11項所述之保密方法,其中上述密鑰係無法由上述微處理器的外部所觀視的。
- 15The security method described in item 11 of the scope of patent application, wherein the above-mentioned encryption step uses an advanced encryption standard (AES). 如申請專利範圍第11項所述之保密方法,其中上述加密步驟係使用一先進加密標準(AES)。
- 16A security method, suitable for a microprocessor, provides a method for selectively accessing a special module register of the microprocessor. The method includes:receiving a request for access to the special module register A command, wherein the special module register has an address designated by the command, and the command is used to designate a password;the address of the designated special module register is read from the above A value of the plural fuses of the microprocessor performs a function operation to generate a first result;the password is decrypted using a key made in the microprocessor to generate a second result;compare The above-mentioned first result and the above-mentioned second result;and When the first result matches the second result, the command is allowed to access the special module register, otherwise the command is denied to the special module register. 一種保密方法,適用於一微處理器,提供具有選擇性存取上述微處理器之一特別模組暫存器之方法,上述方法包括:接收要求對上述特別模組暫存器進行存取之一指令,其中上述特別模組暫存器具有被上述指令所指定之一位址,並且上述指令用以指定一密碼;對所指定之上述特別模組暫存器之位址與讀取自上述微處理器之複數保險絲之一數值執行一函數運算,用以產生一第一結果;使用製造於上述微處理器的內部之一密鑰對上述密碼進行解密,用以產生一第二結果;比較上述第一結果以及上述第二結果;以及 當上述第一結果與上述第二結果匹配,允許上述指令對上述特別模組暫存器進行存取,否則拒絕上述指令對上述特別模組暫存器進行。
Independent claims16
54 paragraphs, as filed
Microprocessor, security method and method for revoking first password
Microprocessor, Method of Protection and Method of Revoking first Password
The present invention relates to restricting access to a special module register (MSR) of a microprocessor, and particularly restricts access to the special module register through a password.
The processor has many internal control registers, which can usually only be accessed by microcode. Taking the bus control register as an example, it can control, for example, the timing on the processor bus, the precise bus protocol to be used, and other detailed actions. When testing and debugging a system with a processor in use, the tester/debugger usually wants to be able to execute an external program to set (or read) the control register inside the processor. For example, a tester/debugger may want to try different timings on the processor bus. In addition, testers/debuggers often want to access the internal registers of these processors as part of the manufacturing test procedure.
For example, the instruction set of the x86 structure includes the read from MSR (RDMSR) instruction and the write to MSR (WRMSR) instruction to temporarily store the special module The device (MSR) reads or writes. Testers/debuggers can access the internal control register of the x86 processor through RDMSR and WRMSR commands. However, if it is used incorrectly, accessing certain internal control registers will cause the processor to work incorrectly, work slowly, or not work completely. Furthermore, the actions of accessing certain internal control registers will cause users to not be protected by security mechanisms, such as allowing access to the core state (ring 0) in the user mode (ring 3). In addition, these control registers may leak information that the processor designer wants to retain ownership of. Therefore, the manufacturers of different x86 processors will not publicly provide any documents describing the addresses or functions of the registers of certain control special modules.
However, the address or existence of the undisclosed control special module register can be easily discovered by programmers, and then programmers traditionally disclose their findings to others for use. Furthermore, the processor manufacturer may need to disclose the address and related description of the register of the special module to the customer for testing and debugging procedures. However, the information disclosed to the customer may cause the secrets of the control special module registers to become well known, so anyone or any processor can use these control special module registers.
Before executing the RDMSR/WRMSR command to access the protected special module register, a stricter method is to place a confidential access key in the register. If the value of the access key is incorrect, the RDMSR/WRMSR command will fail, and the processor cannot read/write the specified special module register. Theoretically, the value of the access key is obtained from the manufacturer of the processor. Unfortunately, after the manufacturer provides the value of the access key to the customer, the value of the access key will soon be disclosed, and other persons who are not authorized can use the disclosed access key to temporarily control the control. The memory is accessed.
The invention provides a microprocessor, which includes a key, a special module register, a plurality of fuses, and a microcode. The key is manufactured inside the microprocessor. The special module register has an address designated by an instruction executed by the microprocessor. The microcode is used to receive commands that require access to the special module register, where the commands are used to specify the address of the special module register; the address and read of the specified special module register Perform a function operation on the value of the fuse to generate a first result; encrypt the first result with a key to generate a second result; compare the second result with a password specified by the command; and if the first result is The second result matches the password, allowing the instruction to access the special module register, otherwise the instruction is denied to access the special module register.
The present invention also provides a security method suitable for a microprocessor to provide selective access to a special module register of the microprocessor. The method includes receiving a request for access to the special module register An instruction, where the instruction is used to specify the address of the special module register; perform a function operation on the address of the special module register designated by the microprocessor and a value read from the processor's complex fuse To generate a first result; encrypt the first result with an internal key manufactured in the microprocessor to generate a second result; compare the second result with a password specified by the instruction; and if The second result matches the password, allowing the instruction to access the special module register; otherwise, the instruction is denied to access the special module register.
The present invention also provides a microprocessor including a special module register, a plurality of fuses, and a control register. The special module register has a single address. The plural fuses are manufactured using a first predetermined value. The microprocessor is used to initially load the first predetermined value from the fuse to the control register, and after the first predetermined value is loaded into the control register, to load a second predetermined value from the system software of a computer system Write to the control register, the computer system includes a microprocessor. Wherein, when an instruction provides a first predetermined value of a key pair in a first version of the microprocessor and the address of a special module register for performing an encryption function operation and a first password is generated , The microprocessor prohibits the instruction to access the special module register. When the instruction provides the second predetermined value of the key pair and the address of the special module register to perform the encryption function operation, a first In the second password, the microprocessor enables the instruction to access the special module register.
The present invention also provides a method for revoking a first password, wherein the first password is used to access a special module register of a microprocessor. The method includes using the microprocessor to remove a plurality of fuses from the microprocessor. A first predetermined value is loaded into a control register of the microprocessor; a second predetermined value is written to the control register, wherein the second predetermined value is loaded into the control register at the first predetermined value After the device, the system software of a computer system is written into the control register, and the computer system includes a microprocessor; when a command is provided by a key pair the first predetermined value and the address of the special module register are used When a first password is generated after the operation of the encryption function, the microprocessor prohibits the instruction from accessing the special module register; and when the instruction is provided by the key pair the second predetermined value and the special module register When the address is used to execute a second password generated after the operation of the encryption function, the microprocessor enables the instruction to access the special module register.
The present invention also provides a security method that includes manufacturing a first version of a microprocessor, the plurality of fuses of the first version of the microprocessor have a first value, and the first version of the microprocessor is used to prohibit one instruction to one The special module register is accessed unless the command provides a first password, and the first password uses a key pair manufactured in the first version of the microprocessor to compare the first value and the special module register The address is generated by performing an encryption function operation; using the key to perform an encryption function operation on the first value and the address of the special module register to generate the first password, and provide the first password to the microprocessor The user of the first version of the microprocessor; and the second version of a microprocessor, the fuse in the second version of the microprocessor has a second value, and the second version of the microprocessor is used to prohibit commands to special The module register is accessed unless the command provides a second password, and the second password is generated by using a key to perform an encryption function operation on the second value and the address of the special module register.
The present invention also provides a security method suitable for a microprocessor, and provides a method for selectively accessing a special module register of the microprocessor. The method includes receiving a request to access one of the special module register Instructions, where the special module register has an address designated by the instruction, and the instruction is used to specify a password; execute the designated special module register address and read the plural fuses from the microprocessor A function operation of a value to generate a first result; use a key made in the microprocessor to decrypt the password to generate a second result; compare the first result with the second result; And when the first result matches the second result, the instruction is allowed to access the special module register, otherwise the instruction is denied to the special module register.
The methods of manufacturing and using various embodiments of the present invention will be discussed in detail below. However, it is worth noting that many feasible inventive concepts provided by the present invention can be implemented in various specific ranges. These specific embodiments are only used to illustrate the manufacturing and use methods of the present invention, but are not used to limit the scope of the present invention.
The US Patent Case No. 12/781,087 (CNTR.2293) describes a method by which a microprocessor manufacturer can restrict access to a special module register. The above method of restricting access is by requiring the user to After the manufacturer obtains a password, it uses the password to access the specific mode register (MSR). The microprocessor includes a manufacturing ID, which uniquely defines the processor part. In addition, the microprocessor has a secret key manufactured inside the microprocessor, where the secret key cannot be viewed from the outside of the microprocessor and is only known by the manufacturer of the microprocessor. The manufacturer uses the key to encrypt the manufacturing identifier to generate the password. Therefore, the password is unique to a particular processor. Before executing the RDMSR/WRMSR command to access the special module register, a user program writes the password received from the manufacturer into a register of the microprocessor. When the processor receives (encounter) RDMSR/WRMSR instructions, one of the encryption engines accompanying the processor uses the key to decode the password to generate a plaintext result (plaintext result). If the plain text includes the manufacturing identifier, the processor completes the RDMSR/WRMSR instruction, that is, allows the RDMSR/WRMSR instruction to access the specific module register; otherwise, the processor aborts the RDMSR/WRMSR instruction, that is, rejects the RDMSR The /WRMSR command accesses the register of a specific module.
The U.S. Patent Case No. 12/781,087 (CNTR.2293) describes a more rigorous method to restrict access to special module registers. The method in the U.S. Patent Case No. 12/781,087 is for manufacturing Both the identifier and the address of the special module register are encrypted to restrict the access of the special module register, so that the password is not only unique to the specific processor, but also for the special module that is accessed. The group register is also unique. The microprocessor is based on the RDMSR/WRMSR instruction and whether the plaintext includes both the manufacturing identifier and the special module register address, and selectively allows the access operation to proceed.
The inventor of this case discloses a security method provided to microprocessor manufacturers. The security method is to provide a different global password for each special module register to restrict access to the special module register . Therefore, in the embodiment of the present invention, the address of the special module register is encrypted by the manufacturer, so that the special module register to be accessed has a unique password. Because the unique manufacturing identifier is not encrypted with the address of the special module register, its password is not unique to the microprocessor. Therefore, a special module register is unique, but for manufacturing A password established by the manufacturer's microprocessor system one (global) of the same type.
Furthermore, the global MSR-specific register password (the global MSR-specific password) can be known to the public. Therefore, the present invention provides a method for revoking the password of the overall specific special module register. In more detail, the microprocessor includes one or more fuses, which can be selectively blown during the manufacturing process of the microprocessor. The manufacturer performs an encryption function (for example, mutual exclusion or XOR) operation on the value of the fuse and the number of the special module register to generate an overall specific special module register password for the user. When the user attempts to use a password to access the special module register, the microprocessor reads the value of the fuse, and then performs an encryption function operation on the fuse value and the user-defined special module register address, and After comparing the password provided by the user and the encrypted result, the special module register is selectively allowed to access according to the comparison result. In this way, the manufacturer burns different values into the fuses of the subsequent microprocessors to revoke the overall specific special module register passwords in the subsequent microprocessors. Due to the use of rigorous encryption methods (for example, 128-bit advanced encryption standard AES), although malicious attackers have the old password and the old fuse value, as long as the fuse value is changed by a single bit, the malicious attacker cannot Get the key. Therefore, a malicious attacker cannot predict a new password. For example, the contemporary factory (Original equipment manufacturer, OEM) hope that the specific special module register password of the new version of the microprocessor is not known to the public, that is, when the contemporary factory wants to revoke the password for its own microprocessor version, the special module The group register has the ability to revoke the password of the overall specific special module register.
In one embodiment, when the microprocessor is reset, the microprocessor reloads the value of the fuse into a characteristic control register, and then when the microprocessor performs a function of the fuse value and the address of the special module register When performing encryption operation, the microprocessor reads the value of the fuse from the characteristic control register. It is worth noting that the characteristic control register can also be written by software executed by the microprocessor. This embodiment provides an alternative method of revoking the overall specific special module register password, that is, by the system software ( For example, the basic output input system (BIOS)) to revoke the overall specific special module register password.
Referring to Figure 1, Figure 1 shows a block diagram of a microprocessor 100 of the present invention. The microprocessor 100 is similar to the microprocessor 100 shown in Figure 1 in the U.S. Patent No. 12/781,087 (CNTR.2293), and the first in the U.S. Patent No. 12/781,087 (CNTR.2293) The microprocessor 100 shown in the figure is also similar to the microprocessor 600 shown in figure 6 of the US Patent No. 7,321,910 (CNTR.2224). The full text of the aforementioned patent application is hereby incorporated by reference. The method is incorporated into this text and constitutes a part of the specification. Therefore, please refer to the above-mentioned patent application for a part of the description of the microprocessor 100, and will not be repeated for a brief description. The microprocessor 100 shown in FIG. 1 of the present invention also includes a Feature control register (FCR) 142 coupled to the execution unit 632. The microprocessor 100 also includes a fuses 144 coupled to the characteristic control register 142. In one embodiment, the fuse 144 is coupled to the execution unit 632, and when reset, the microprocessor 100 populates the characteristic control temporary with default values corrected with the value of the fuse 144 In the memory 142. In one embodiment, the initial value (default values) is the result of the Bollinger Exclusive OR (XOR) operation on the value of the fuse 144. In one embodiment, the microcode read-only memory 604 reads the value of the fuse 144, and fills the characteristic control register 142 with an initial value corrected with the value of the fuse 144. The method of controlling the register 142 by filling the characteristics of the fuse 144 in the embodiment of the present invention is similar to the US Patent No. 5,889,679 (CNTR.1328) and the US Patent Application No. 12/609,207 (CNTR.2490) The above is a brief description, so I won't repeat it here. The manufacturer of the microprocessor 100 can selectively blow the fuse 144 during the manufacturing stage.
Part of the special module register 132 is protected by a password, while another part of the special module register 132 is not protected by a password. In one embodiment, the microcode read only memory (ROM) 604 is used to store a list of the special module register 132 protected by a password. In order to determine whether to restrict access, it is required to be valid ( valid), the microcode will measure when to execute RDMSR/WRMSR commands. In one embodiment, each special module register 132 has one of several different password protection types. The following describes a type of protecting a specific special module register 132 based on a general specific special module register password. The overall specific special module register password is determined by the special module register 132 The number and the value of the fuse 144 are generated, and the number of the special module register 132 and the value of the fuse 144 are related to the specific version of the microprocessor 100. The above type is to protect a specific special module register (MSR-specific), but not a specific component (part-specific), or at least not a set of components with the same fuse value (a set of parts (part-specific). As described in the present invention, the specific special module register password of the first group (or the first version) microprocessor that blows according to the value of the first group of fuses 144 will be different from that according to the second group. The value of the fuse 144 burns the specific special module register password of the second group (or the second version) microprocessor. In addition to the type described in the US Patent Application (CNTR.2293) with the case number 12/781,087, the special module register 132 is protected by a specific partial password, and this specific partial password It is generated using the manufacturing identifier of the microprocessor 100, or generated using the manufacturing identifier and the special module register address 206 at the same time. In addition, each special module register 132 can be based on whether it is protected for read (Protected for Read, for example, the special module register 132 is used to read the microcode of the microprocessor 100), write protection ( Protected for Write, such as controlling the timing or protocol of the bus, or the internal control register that controls the different characteristics or power saving features of the microprocessor 100) or the simultaneous protection of read and write (Protected for both Read and Write) Use the above type classification.
The manufacturing identifier 134 is a serial number manufactured in the hardware of the microprocessor 100, and is a unique serial number for each microprocessor 100. Since the manufacturing identifier 134 is a serial number, the manufacturing identifier 134 is a predictable number. In one embodiment, the manufacturing identifier 134 is burned into the 50-digit number of the fuse 144 of the microprocessor 100 and is visible to the user. In one embodiment, the user can read the manufacturing identifier 134 through the RDMSR command.
The key 136 is a secret value (secret value) manufactured in the hardware of the microprocessor, which cannot be observed from the outside. The key 136 is only known by a small number of authorized employees of the manufacturer. The key 136 can be read internally by the microcode of the microprocessor 100, but cannot be read from outside the microprocessor 100. Therefore, the key 136 cannot be obtained by any external program running on the microprocessor 100. However, only someone who knows the secret key 136 leaks it, or someone analyzes the physical silicon and/or metal layer of the microprocessor 100 and discovers that the secret key 136 is manufactured in the hardware of the microprocessor 100. Only by location and arrangement can the key 136 be known. In one embodiment, the key 136 is the same for all instances of the microprocessor of the same manufacturer. In one embodiment, the key 136 is 128 bits.
Referring to Fig. 4, Fig. 4 is a flowchart according to an embodiment of the present invention. Fig. 4 includes Fig. 4A and Fig. 4B. FIG. 4A includes steps 401 to 406 and step 492, and FIG. 4B includes steps 408 to step 432. The steps shown in step 402 to step 406 in FIG. 4A are also described in the block diagram of FIG. 2, and many steps shown in step 408 to step 432 in FIG. 4B are also described in the block diagram of FIG. 3. Therefore, the description of Fig. 2 and Fig. 3 also accompanies the description of Fig. 4. The process starts at step 401.
In step 401, the manufacturer of the microprocessor 100 manufactures a set of first versions of the microprocessor 100. The first version includes a first fuse value 204, and the first fuse value 204 is used (as shown in FIG. 2) to selectively blow the fuse 144 shown in FIG. Then, the process proceeds to step 402.
In step 402, the user wants to read/write the special module register 132 of the microprocessor 100, so the user provides the number or address of the special module register 132 to the microprocessor 100 The manufacturer, and requires a special module register password 138. The user also provides the version of the microprocessor 100 to the manufacturer, so that the manufacturer can find out the fuse value 204 that was originally burned into the version of the user's microprocessor 100. Then, the process proceeds to step 404.
In step 404, the manufacturer uses the key 136 and the function operation 208 to compare the number of the special module register 132 received in step 402 and the first fuse value 204 (where the first fuse value 204 is related to the first version (ie The user's version) is encrypted to generate the first special module register password 138 by an encryption function 202, as shown in Figure 2. In one embodiment, the function operation 208 is a Bollinger mutual exclusion Or (XOR) function operation, although this embodiment is disclosed as above, the present invention can also include the design of other functions. For example, in other embodiments, concatenation is adopted. In one implementation In the example, the encryption function 202 used by the manufacturer is advanced encryption standard (AES) encryption, but other embodiments can also be considered, such as Data Encryption Standard (DES). It is worth noting that the advanced encryption standard encryption Plain text input and cypher text in text) The output has the same number of bits. Therefore, when the special module register address 206 and the first fuse value 204 in the embodiment of the present invention have fewer bits compared to the special module register password 138, the manufacturer is checking the special module The register address 206 and the first fuse value 204 function operation 208 before the advanced encryption standard encryption is executed, the special module register address 206 and the first fuse value 204 are filled to the special module register The password 138 has the same number of bits and is used to generate the special module register password 138. Use the key 136 to encrypt the special module register address 206 and the first fuse value 204 using a rigorous encryption algorithm, such as Advanced Encryption Standard (AES), which provides a password-protected special module register 132 pole High high) security, because for anyone who does not know the key 136, even if he knows the encryption algorithm, or knows the special module register address 206 and the first fuse value 204, it is statistically impossible. Use the correct calculation method to calculate the special module register password 138. In one embodiment, the key 136 is 128 bits and the generated special module register password 138 is also 128 bits. However, embodiments with keys with other bits can also be considered. Furthermore, even if someone knows the special module register address 206, the first fuse value 204, and the generated special module register password 138 provided by the manufacturer, it is impossible to use the correct calculation method statistically. To find out the key 136. In one embodiment, the manufacturer uses the written program to encrypt the special module register address 206 and the first fuse value 204 through the function operation 208 to generate the special module register. The device password is 138. The program can be executed in any system, which includes a processor capable of executing the aforementioned encryption algorithm. Although not necessary, the system may also include the microprocessor 100 according to the present invention, which includes a cryptographic unit 617 for executing the above-mentioned encryption algorithm. Then, the process proceeds to step 406.
In step 406, the manufacturer provides the special module register password 138 generated in step 404 to the user, for example, via telephone, email, website, file transfer protocol (FTP), paper mail, etc. It is worth noting that although the special module register password 138 is for a specific special module register (MSR-specific), not for a specific component (part-specific). Therefore, if the special module register password 138 becomes publicly known information, the manufacturer has someone other than the user who provides the special module register password 138, and it can also be the first of a group of microprocessors 100. On the version, the special module register password 138 is used to access the special module register 132. When this method is adopted by general users and manufacturers, as discussed above, it may happen that users and manufacturers wish to revoke access to the specific special module register 132 through the special module register password 138. Users and manufacturers can incorporate (incorporating) the value of the fuse 144 to cancel the subsequent version of the microprocessor 100 to access the specific special module register 132 through the first special module register password 138, such as According to the present invention. Then, the process proceeds to step 408.
In step 408, the user program loads the special module register password 138 received in step 406 from the manufacturer into the register of the microprocessor 100. In one embodiment, the register is an XMM7 register in the x86 Streaming SIMD extensions (SSE) programming environment. In another embodiment, the user program loads the special module register password 138 into the system memory, and loads an index into the general register of the microprocessor 100, where the index is used Indicate the memory location for storing the special module register password 138. Then, the process proceeds to step 412.
In step 412, the user program executes the RDMSR command or the WRMSR command, which designates the specific special module register 132 to be read or written. Then, the process proceeds to step 414.
In step 414, the processor decodes the RDMSR instruction or the WRMSR instruction, and transfers control to the microcode routine of the microcode read-only memory 604 in Figure 1. The microcode will determine whether the specific special module register 132 exists in the list of password-protected special module registers. In one embodiment, the architected special module register is not included in the list of password-protected special module registers. In one embodiment, the list of special module registers protected by passwords can be changed by blowing the fuse in the microprocessor, such as the United States filed on February 24, 2009 and the case number is 12/391,781 Described in the patent application. In addition, the microcode also determines the type of password protection related to the special module register 132, that is, whether the accessed special module register 132 already has a specific special module register password, a specific Part of the password or the password specific to the special module register and part of the password at the same time. Then, the flow proceeds to step 416.
In step 416, if the special module register 132 specified by the RDMSR command or the WRMSR command does not appear in the list of password-protected special module registers, the flow proceeds to step 432. Otherwise, then, the flow proceeds to step 423.
In step 423, if the special module register 132 requires an MSR-specific password, then the flow proceeds to step 425. Otherwise, the process proceeds to step 424.
In step 425, if the special module register 132 requires a part-specific password, then the flow proceeds to step 427. Otherwise, the process proceeds to step 429.
In step 424, the microcode read-only memory 604 causes the cryptographic unit 617 to encrypt the manufacturing identifier 134 using the key 136. Then, the process proceeds to step 431.
In step 427, the microcode read-only memory 604 causes the cryptographic unit 617 to encrypt the manufacturing identifier 134 and the special module register address 206 using the key 136. Then, the process proceeds to step 431.
In step 429, the microcode read-only memory 604 causes the cryptographic unit 617 to use the secret key 136 to perform the function operation 208 of the special module register address 206 and the fuse value read from the characteristic control register 142 Encrypt, as shown in Figure 3. Then, the process proceeds to step 431.
In step 431, the integer unit 610 appropriately compares the special module register password 138 provided by the user with the encryption result generated in step 429, step 424, or step 427 (as shown in FIG. 3). As shown in Figure 3, the integer unit 610 will generate a valid indicator 302, which will indicate the number of the encrypted special module register 132 and the value of the fuse read from the characteristic control register 142 The function operation 208 (that is, indicates whether the encryption result of the function operation 208) matches the special module register password 138. Then, the flow proceeds to step 426.
In step 426, if in the comparison of step 431, the encrypted function operation 208 of the special module register address 206 and the fuse value read from the characteristic control register 142 (that is, the encrypted result of the function operation 208) ) Does match the special module register password 138, and then the process goes to step 432. Otherwise, the process proceeds to step 428.
In step 428, the microprocessor 100 aborts the RDMSR/WRMSR instruction. In one embodiment, the microprocessor 100 may generate a general protection fault. Then, the process proceeds to step 492.
In step 432, the processor executes the RDMSR command or WRMSR command required by the user program. Then, the process proceeds to step 492.
In step 492, the manufacturer of the microprocessor 100 manufactures a set of second versions of the microprocessor 100. The second version of the microprocessor 100 includes a second fuse value. The second fuse value is used to selectively burn the fuse 144 shown in Figure 1, which is different from the set of microprocessors generated and burned in step 401 The first fuse value of the first version of the device 100. Therefore, the user cannot use the first password to access the special module register 132 on the second version of the microprocessor 100. Therefore, for the second version of the microprocessor 100, the first password has been revoked. The rigorous encryption method described in the present invention (for example, encryption using advanced encryption standards), for those who do not know the key 136, even if they know the first special module register password 138 generated in step 404 , The special module register address 206, the first fuse value and the encryption algorithm, it is statistically impossible to use the correct calculation method to calculate the second special module register password 138, because at present it is necessary to use micro Only the second version of the processor 100 can access the special module register 132. In addition, even if someone knows the special module register 132 password, the first fuse value, the first special module register password 138, the second fuse value, and the second special module register password 138 , It is statistically impossible to use the correct calculation method to calculate the key 136. The process ends in step 492.
In another embodiment, in order to determine whether the special module register password 138 provided by the user is valid, the microprocessor 100 does not check the special module register address 206 and the read self-characteristic control register 142. The value of the fuse is encrypted after the function arithmetic processing, and then the generated encryption result is compared with the special module register password 138 provided by the user, and the special module register password 138 provided by the user is compared. Perform decryption, and compare the decrypted result with the special module register address 206 and the value of the fuse value read from the characteristic control register 142 after the function operation 208 is processed. This embodiment is shown in Figure 6.
Please refer to FIG. 5. FIG. 5 is a flowchart illustrating the operation of another embodiment disclosed in the present invention. Figure 5 describes a second method in addition to the first method shown in step 492 in Figure 4. The second method can cancel the temporary storage of a specific special module without burning a new value to the fuse 144 in Figure 1 Device password. The process starts at step 592.
In step 592, the manufacturer of the microprocessor 100 provides a newly released basic input output system (BIOS). The newly released basic input output system (BIOS) includes program code. The program code includes running at system boot time and writing a value to the characteristic control register 142 in Figure 1. The above value includes The second fuse value burned into the fuse 144 in Figure 1 is different from the first fuse value used in step 401 in Figure 4. Although the fuse 144 itself will not be physically altered, since the microprocessor 100 encrypts the value of the fuse read from the characteristic control register 142 according to step 429 in FIG. 4, the basic input and output system can By programming the characteristic control register 142, the microprocessor 100 is effectively reconfigured to the second version, so that the user can no longer use the first special module register password generated in step 404 of Figure 4 to save Take a specific special module register. In other words, in the microprocessor 100 in the system with the newly released basic output input system, the basic output input system (BIOS) can effectively revoke the first specific special module register password. It is worth noting that the feature control register 142 can also be password protected according to any of the special module register password types described in the present invention. The process ends in step 592.
Although the present invention and the objects, features, and advantages of the present invention have been described in detail above, other embodiments that do not violate the spirit and scope of the present invention are also included in the present invention. For example, the value of the fuse 144 can also use the value of the specific component code of steps 424 and 427 in Figure 4. Although the parts that need to revoke the specific component password are not similar, it can simplify the design of the microprocessor 100 to achieve the purpose, that is, the design of the microcode. In addition, although the embodiments of the present invention have been described in detail above, in which 128-bit encryption keys are used, other embodiments of the present invention also include keys of other sizes. And although the embodiments of the present invention have been described in detail above, in which the Advanced Encryption Standard (AES) is used for encryption, other embodiments of the present invention may also include other encryption standards.
Different embodiments of the present invention have been described herein, but those with ordinary knowledge in the art should understand that these embodiments are only examples, and are not limited thereto. Those skilled in the art can make various changes in the form and details without departing from the spirit of the present invention. For example, the software can enable the functions, fabrication, modeling, simulation, description, and/or testing of the devices and methods described in the embodiments of the present invention, and can also be implemented through general programming languages (C, C++), Hardware Description Languages (HDL) (including Verilog HDL, VHDL, etc.), or other available programming languages. This software can be deployed on any known computer-usable media, such as tape, semiconductor, magnetic disk, or optical disc (such as CD-ROM, DVD-ROM, etc.), the Internet, wired, wireless, or other communication media Among the transmission methods. The device and method embodiments of the present invention can be included in a semiconductor intellectual property core, such as a microprocessor core (implemented in HDL), and converted into the hardware of an integrated circuit product. In addition, the device and method of the present invention are realized through the combination of hardware and software. Therefore, the present invention should not be limited to the disclosed embodiments, but is defined by the appended patent application scope and equivalent implementation. In particular, the present invention can be implemented in a microprocessor device used in a general-purpose computer. Finally, although the present invention is disclosed as above in a preferred embodiment, it is not intended to limit the scope of the present invention. Anyone with ordinary knowledge in the relevant technical field should do something without departing from the spirit and scope of the present invention. Modifications and modifications, therefore, the scope of protection of the present invention shall be subject to those defined by the attached patent application scope.
<p>100. . . microprocessor</p><p>132. . . Special module register</p><p>134. . . Manufacturing identifier</p><p>136. . . Key</p><p>138. . . Special module register password</p><p>142. . . Characteristic control register</p><p>144. . . fuse</p><p>601. . . Extract logical unit</p><p>602. . . Translation logic unit</p><p>603. . . Translator</p><p>604. . . Microcode read-only memory</p><p>605. . . Register</p><p>606. . . Address</p><p>607. . . Loading</p><p>608. . . implement</p><p>609, 611, 613, 615. . . Microinstruction queue</p><p>610. . . Integer unit</p><p>612. . . Floating point unit</p><p>614. . . Multimedia eXensions (MMX) unit</p><p>616. . . SSE unit</p><p>617. . . Cryptographic unit</p><p>618. . . store</p><p>619. . . Write back</p><p>620. . . Load bus</p><p>621. . . Idle signal</p><p>622. . . Storage bus</p><p>623. . . Busbar</p><p>624. . . EFLAGS register</p><p>625. . . X bit</p><p>626. . . Interrupt logic unit</p><p>627. . . Microinstruction</p><p>628. . . MSR register</p><p>629. . . E bit</p><p>630. . . FCR register</p><p>631. . . D bit</p><p>632. . . Execution unit</p><p>202. . . Encryption function</p><p>204. . . Fuse value</p><p>206. . . Special module register address</p><p>208. . . Function operation</p><p>302. . . Effective indicators</p>
Figure 1 is a block diagram of the microprocessor disclosed according to the present invention;
Figure 2 is a block diagram describing the operation of step 402 in Figure 4 of the present invention;
Figure 3 is a block diagram describing the operation of step 432 in Figure 4 of the present invention;
Figure 4 is an operation flowchart according to an embodiment of the present invention;
Figure 5 is an operation flowchart according to another embodiment of the present invention; and
FIG. 6 is a block diagram of the operation of another embodiment similar to FIG. 3 of the present invention.
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2009119748A1 | Cites | United States of America | Examiner |
| TW200949687A | Cites | Taiwan Province of China | Examiner |
| US2010064117A1 | Cites | United States of America | Examiner |
| TW201011643A | Cites | Taiwan Province of China | Examiner |
| US6154818A | Cites | United States of America | Examiner |
| US7043616B1 | Cites | United States of America | Examiner |
| US6154818 | Cites | United States of America | – |
| US20090119748A1 | Cites | United States of America | – |
| US20100064117A1 | Cites | United States of America | – |
10 members in 3 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 37525010 | United States of America | P | |
| 61375250 | United States of America | – | |
| 13034062 | United States of America | – | |
| 201113034062 | United States of America | A | |
| 13034062 | – | – | – |
| 61375250 | – | – | – |
| US20100375250P | – | – | – |
| US201113034062 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| CN102306253A | China | A | |
| US2012047369A1 | United States of America | A1 | |
| TW201209710A | Taiwan Province of China | A | |
| US8590038B2 | United States of America | B2 | |
| US2014059358A1 | United States of America | A1 | |
| US8793785B2 | United States of America | B2 | |
| TW201502979A | Taiwan Province of China | A | |
| TWI474257BThis record | Taiwan Province of China | B | |
| CN102306253B | China | B | |
| TWI522914B | Taiwan Province of China | B |
Numbers
- Publication
- I474257
- Publication, DOCDB
- I474257
- Publication, EPODOC
- TWI474257B
- Application
- 100129500
- Application, DOCDB
- 100129500
- Application, EPODOC
- TW20110129500
Titles2
- English
- Microprocessor, method of protection and method of revoking first password
- Chinese
- 微處理器、保密方法以及撤銷第一密碼之方法
Classification
- CPC, 7
- G06F12/1408
- G06F9/30076
- G06F9/30101
- G06F21/71
- G06F21/31
- G06F21/79
- G06F21/78
- IPC, 1
- G06F9 30