TW200424930A - Secure mode indicator for smart phone or PDA - Google Patents

Secure mode indicator for smart phone or PDA Download PDF

Info

Publication number
TW200424930A
TW200424930A TW092135673A TW92135673A TW200424930A TW 200424930 A TW200424930 A TW 200424930A TW 092135673 A TW092135673 A TW 092135673A TW 92135673 A TW92135673 A TW 92135673A TW 200424930 A TW200424930 A TW 200424930A
Authority
TW
Taiwan
Prior art keywords
security
safe mode
memory
signal
mode
Prior art date
Application number
TW092135673A
Other languages
Chinese (zh)
Other versions
TWI313433B (en
Inventor
Franck B Dahan
Bertrand Nmi Cornillault
Original Assignee
Texas Instruments Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from US10/322,893 external-priority patent/US8479022B2/en
Application filed by Texas Instruments Inc filed Critical Texas Instruments Inc
Publication of TW200424930A publication Critical patent/TW200424930A/en
Application granted granted Critical
Publication of TWI313433B publication Critical patent/TWI313433B/en

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/71Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
    • G06F21/74Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information operating in dual or compartmented mode, i.e. at least one secure mode
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/82Protecting input, output or interconnection devices
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/86Secure or tamper-resistant housings
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/448Execution paradigms, e.g. implementations of programming paradigms
    • G06F9/4482Procedural
    • G06F9/4484Executing subprograms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M1/00Substation equipment, e.g. for use by subscribers
    • H04M1/72Mobile telephones; Cordless telephones, i.e. devices for establishing wireless links to base stations without route selection
    • H04M1/724User interfaces specially adapted for cordless or mobile telephones
    • H04M1/72403User interfaces specially adapted for cordless or mobile telephones with means for local support of applications that increase the functionality
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2141Access rights, e.g. capability lists, access control lists, access tables, access matrices
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2147Locking files
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2149Restricted operating environment

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Software Systems (AREA)
  • Computer Hardware Design (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Mathematical Physics (AREA)
  • Human Computer Interaction (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)

Abstract

A digital system is provided with a secure mode (3rd level of privilege) built in a non-invasive way on a processor system (10) that includes a processor core, instruction and data caches, a write buffer and a memory management unit. A secure execution mode is thus provided on a platform where the only trusted software is the code stored in ROM. In particular the OS is not trusted, all native applications (14a, 14b, 14c) are not trusted. The secure mode is entered through a unique entry point. The secure execution mode can be dynamically entered and exited with full hardware assessment of the entry/exit conditions. A secure mode indicator (30) is provided to tell a user of the digital system that the device is in secure mode. This indicator may be a small LED, for example. The user should not enter any secret information (password) or should not sign anything displayed on the screen if the secure mode indicator is not active.

Description

200424930 A7 ____B7 五、發明說明(1 ) 發明所屬之技術領域 本申請案係為聲稱對2002年1月16曰歐洲專利 申請案序號第02290115.1號,名稱為”支援MMU與 中斷之處理器之安全模式,,(授權備忘號 33762.1 EU )、以及2002年6月30日歐洲專利申 請案序號第02100727.3號,名稱為”支援MMU與中 斷之處理器之安全模式”(授權備忘號33762.2EU) 之優先權。200424930 A7 ____B7 V. Description of the invention (1) The technical field to which the invention belongs This application claims to be the security mode of the processor supporting MMU and interrupts, which is the European Patent Application No. 02290115.1 dated January 16, 2002 ,, (authorization memo number 33762.1 EU), and European Patent Application Serial No. 02100727.3 on June 30, 2002, entitled “Security Mode Supporting MMU and Interrupt Processors” (authorization memo number 33762.2EU) .

ο IX 經濟部智慧財產局員工消費合泎钍印製 20 本發明概與微處理器有關,更特別言之,與用以 支援女全軟體服務之保全機制之改善有關。 先前技術 微處理器係提供高指令運算量以執行其上之軟體之通用 處理器,並視其所含特定軟體應用而具廣泛處理需求。許多. 不同類型之處理器均屬已知,微處理器僅係其一。例如數位 # 5虎處理器(DSP)即泛為使用,並以針對特定應用如行 動處理應用為最。DSP -般魏置錢相關顧之性能最 佳化,為達此目的,其使用更特定化之執行單元與指令集。 欲提供持續攀升之Dsp性能,同時盡料低功率耗=特 別是、但不限於行動電訊之應用中。 為進-步改善數位系統性能,可使兩或多具處理哭互 連。例如可在數位系統中將DSP與通用處理器互連。咖 施行數健化賴處理演算法,而通用處理器綜理所有控制 流程。兩具處理器經由共肢憶體傳遞並轉移資料供作號處 理之用。直接記憶體存取(DMA)控•常與處理° = 本紙張尺度適用中國國豕標準(CNS)A4規格(2丨〇 x 297公爱) 200424930 A7 B7 五、發明說明(2 ) I’以接官記憶體或週邊資源間資料區塊轉移之重擔 ,藉以 改善處理器性能。 、/又均具有作業錢(〇S),俾藉由對資源控制及各種 =核組或任務之執行触—職位魏。在具有數具處 理為之系統中,各處理器均具個別〇s較為便利。概言之, 〇s硫疋其在所有系統資源之控制下。多種均未被設 冲為可與其它os共用記憶體與資源。因此當將兩或更多個 〇s、併在單-系統中時,即可能發生資源分配問題。在記憶ο IX Printed by Employees' Intellectual Property Bureau, Ministry of Economic Affairs, Consumer Consumption 20 The present invention relates to microprocessors, and more specifically, to the improvement of security mechanisms to support women's software services. Prior art microprocessors are general-purpose processors that provide a high amount of instruction to execute the software on them, and have extensive processing requirements depending on the specific software applications they contain. Many different types of processors are known, and microprocessors are just one of them. For example, the Digital # 5 Tiger Processor (DSP) is widely used, and it is most targeted at specific applications such as motion processing applications. DSP-Optimize the performance of the related GPs. To achieve this, they use a more specific execution unit and instruction set. Want to provide continuously rising Dsp performance, while expecting low power consumption = especially, but not limited to mobile telecommunications applications. To further improve the performance of the digital system, two or more processors can be interconnected. For example, a DSP can be interconnected with a general purpose processor in a digital system. The number of algorithms implemented depends on the processing algorithm, and the general-purpose processor takes care of all control processes. The two processors transmit and transfer data via co-limb memory for number processing. Direct memory access (DMA) control • Frequent and processing ° = This paper size applies to China National Standard (CNS) A4 specification (2 丨 〇x 297 public love) 200424930 A7 B7 V. Description of the invention (2) I 'to The burden of transferring data blocks between official memory or peripheral resources to improve processor performance. , / And have operating money (0S), through the control of resources and various = audit team or task execution touch-position Wei. In a system with several processing behaviors, it is more convenient for each processor to have an individual 0s. In a nutshell, 0s sulfur is under the control of all system resources. Many are not designed to share memory and resources with other OSs. So when two or more 0s are combined in a single-system, resource allocation problems may occur. In memory

ο 1X 5 11 經濟部智慧財產局員工消費合泎ii印製 20 體或週邊裝置使用上之衝突,均可能對系統操作造成不良後 果。 大#刀處理态之建構均具2特權等級:其一供〇s使 用’另-則供用戶任務之用。曾有人提出第三特權等級,但 在現行CPU中從未付諸實現。 一針對特定財務或安全關鍵應用,-些作業系統已被確認 為安全無虞。部分通用作獅統聲稱有喊保全,但其不堪 一擊係眾所週知。 可利用硬體機制改善保全。例如美國專利第4590552 號’名稱為”心標示齡於轉發性記憶體巾之資訊保全 狀怨之保全位兀”,揭示一種藉由提供可永久設定為禁止晶 片外(off-chip)資源進入晶片上(〇r>chjp)記憶體之一或 多個保全位元,因而保護資料儲存之機制,藉以保護儲存於 晶片上記憶體中之碼或資料。但作業系統之誤判操作可破解 此類保全方法。 在能施行安全類別之應用如商務(行動商務)或^銀行 -4- 本紙張尺度適用中國國家標準(CNS)A4規格(2丨〇 χ 297公釐) 200424930 A7 五、發明說明 10 15 經濟部智慧豺產局員工消費合阼钍印製 20 (,子銀行)之智縣置上,要求用戶以鍵盤輪人私密資气 如搶碼,或於螢幕上顯示之訊,⑭署。在執行此動 戶除完全仰賴其裝置之健全性外,別無其它選擇。但用: 法檢測·駭客或病毒是否已入侵其裝置之保全架構。 - 發明内容 因/匕,確需改善純保全。概言之,在本發明之—型式 中,提供-具有以非侵入性方式建於處理器系統之安全模 (特權等級第三級)之數位⑽。安全執行模胡而位於— 平台上,該平台之唯一信賴軟體係儲存於晶片上R〇M中之 碼。並提供數位系統用戶可見之指示器手段,其中該指示哭 手段僅可於安全模式之操作下,以信賴程式碼啟動之。 在一實施例中,經由一獨特進入點進入安全模式。可以 進/出條件之充分硬體評估,動態出入安全執行模式。 實施方式 Ί 與用戶交換如密碼或螢幕上顯示之訊息之機密資訊,須 僅於處理裝置處於安全模式下時才施行。—種提供安全模式 ,裝置與方法述如20G2年6Θ 3G日提n料請案序 號第02100727.3號相關專利申請案”供支援MM(j及中斷之 處理器用之安全模式"。在此納入安全模式之充分描述,俾 使熟悉此技藝者瞭解其操作。 在女全模式中,實體用戶介面(如鍵盤或顯示器)之進 入受限於經由受信賴驅動器之安全應用。以安全模式為進入 鍵盤及顯示器把關,並不足以充分保障與用戶間之訊息交 換。現本發明人已發現需以一手段指示用戶,〇s呼叫適當 訂 本紙張尺度適用中國國家標準(Cns)A4規格(210 X 297公釐) 200424930 發明說明(〇 受信賴之鍵盤或顯示器驅動器,亦即儲存於安全記憶體中之 驅動器,並進入安全模式執行。否則若病毒/骇客欲;載〇 慧裝置上之偽驅動H ’則用戶無從得知其無法仰賴其裝置。 依本發明之-態樣’執行安全應用之智慧裝置除具顯示 器與袖珍鍵盤外’尚具-安全模式指示器。此指示器將告知 用戶該裝置處於安全模式。此指示器可為例如小型13 若安全模式指示器未啟動,則用戶不應輸入任何私穷資1 (密碼)或不應於營幕上之顯示之任何東西簽署。若在指示 器未啟動時欲輸入其個人識別碼,則用戶將得知其裝置^遭 破解,而裝置無法提供安全操作。 4 為達此目的’於® 1之數位系統上提供-僅可於安全模 式下進入之輸人/輸出(GP丨0) _位元154。以此安 全GPK) Γ4鎖驅動保全指示器LED 155。刻正於來自安全 ROM/SRAM (唯言賣記憶體/靜態隨機存取記憶體)之安全模 式下執订之受信賴鍵盤與顯示H驅動器負責管理安全即丨〇 閃鎖。 安全模式指示器須獨立於鍵盤及顯示器之外,因為非安 全應用軟體會於非安全模式下進入這些裝置。特別言之,螢 泰上顯示之訊息如,,現在輸入密碼,,-般並不可靠。此外,由 ;骇客馬可進人螢幕’故營幕上顯示之用以指示安全操作之 符號或訊息(如鎖狀符號)並不可靠。安全模式指示器須可 靠指示何日«Μ於安域灯運作,且僅當裝置處於安全 U寺才有“不。除非安全模式指示器已啟動,否則應通 用戶不要輪入任何如密碼之私密資訊或不要在勞幕上簽署 200424930 Α7 Β7 五、發明說明(5) 10 15 經濟部智慧財產局員工消費合作钍印製 20 任何東西。 圖1係在具有複數個處理器102、104之兆位單元 (mega cell) 100中之包含本發明之一實施例之數位系統 之方塊圖。為利明晰之故,圖1僅顯示兆位單元1QQ中與 本發明之一實施例之瞭解有關之部分。數位信號處理器 (DSP)之一般架構細節係眾所週知,且易於在它處得 見。例如Frederick Boutaud等人在美國專利第5,072,418 號中詳述一種DSP。Gary Swoboda等人在美國專利第 5,329,471號中詳述如何測試與模擬DSP。以下將對兆位單 元100中與本發明之一實施例有關之部分作充分描述,俾 使熟悉微處理器技術者施行與利用本發明。 雖然本發明發現對施行例如在特殊應用積體電路 (ASIC)上之數位糸統之特殊應用,亦發現對其它形式系 統之應用。ASIC可包含一或多個兆位單元,其各自包含針 對客戶设計之功能性電路以及出自設計庫中之預先設計之功 能性電路。 在兆位單元100中具有一種分佈保全系統,其採用選擇 硬體方塊與叉保護軟體執行環境之組合。該分佈保全系統係 用以解決行動電話環境内之電子商務(e,務)與行動商務 (m-商務)保全議題之方法。保全議題包含以下所列: 機密度:確保僅有通信者可理解傳輸資訊之内容; -疋整性:確保資訊在傳送期間不變; '驗證性:確保另-通信者係即為其所宣稱者; -無否定性:確保傳送者不能否認傳送訊息;ο 1X 5 11 Conflicts in the consumption of employees of the Intellectual Property Bureau of the Ministry of Economic Affairs ii Printed 20 conflicts in the use of external devices or peripheral devices may cause adverse consequences to system operation. The construction of the big #knife processing state has 2 privilege levels: one is for 0s use, and the other is for user tasks. A third privilege level has been proposed, but it has never been implemented in current CPUs. For specific financial or safety-critical applications, some operating systems have been identified as safe. Some are commonly used as Lions's claim to yell security, but its unbeatable system is well known. Hardware mechanisms can be used to improve security. For example, U.S. Patent No. 4,905,552, with the name "Heart-marked Security Preservation Status of Information Memory in Retransmitting Memory Towels", discloses a method of providing off-chip resources that can be permanently set to prevent access to the chip. One or more security bits in the memory (0r > chjp), thus protecting the data storage mechanism, thereby protecting the code or data stored in the memory on the chip. However, the misjudgment of the operating system can crack such a security method. For applications that can implement security categories such as commerce (mobile commerce) or ^ bank-4- This paper size applies the Chinese National Standard (CNS) A4 specification (2 丨 〇χ 297 mm) 200424930 A7 V. Description of invention 10 15 Ministry of Economy The Consumer Affairs Bureau of the Intellectual Property Industry Bureau printed a 20 (, sub-bank) Zhixian County and asked users to use the keyboard to rotate private information such as code grabbing, or the information displayed on the screen. There is no other option but to rely on the soundness of their device in performing this campaign. But use: to detect whether a hacker or virus has invaded the security structure of its device. -Summary of the Invention Due to the need to improve pure security. In summary, in a form of the present invention, a digital frame having a security module (privileged level 3) built in a processor system in a non-intrusive manner is provided. The security execution module is located on the platform, the only trusted software system of the platform is stored in the ROM code on the chip. It also provides the indicator means visible to the users of the digital system. The instruction crying method can only be activated by the trusted code under the operation of the safe mode. In one embodiment, the safe mode is entered via a unique entry point. Full hardware evaluation of entry / exit conditions and dynamic entry and exit of safe execution mode. Implementation Ί Exchanging confidential information with the user, such as passwords or messages displayed on the screen, should only be performed when the processing device is in secure mode. —A kind of security mode, device and method are described in 6G, 20G2, 6Θ, 3G date, and filed with the relevant patent application No. 02100727.3. "Security mode for supporting MM (j and interrupted processors)." Include security here A full description of the mode, so that those skilled in the art understand its operation. In the women's full mode, access to the physical user interface (such as a keyboard or display) is limited to secure applications via a trusted driver. The safe mode is used to enter the keyboard and The display control is not enough to fully guarantee the exchange of information with the user. Now the inventor has found that it is necessary to instruct the user by one means, and the 0s call should be appropriately adjusted. (%) 200424930 Description of the invention (〇 Trusted keyboard or display driver, that is, the driver stored in secure memory, and enter safe mode for execution. Otherwise, if a virus / hacker desires; a fake driver on a smart device H ′ Then the user cannot know that he cannot rely on his device. According to the aspect of the present invention, the smart device for performing security applications has a display and a pocket. Outside the keyboard-there is a safe mode indicator. This indicator will inform the user that the device is in safe mode. This indicator can be, for example, small 13 If the safe mode indicator is not activated, the user should not enter any private money 1 ( Password) or should not be signed on anything displayed on the camp screen. If you want to enter your PIN when the indicator is not activated, the user will know that their device ^ has been cracked and the device cannot provide secure operation. 4 is To achieve this' is provided on the digital system of ® 1-input / output (GP 丨 0) _ bit 154 that can only be entered in safe mode. This is a safe GPK) Γ4 lock drive security indicator LED 155. engraved The trusted keyboard and display H driver, which are subscribed to the security mode from the secure ROM / SRAM (Weiyin memory / static random access memory), are responsible for managing the security, ie flash lock. The security mode indicator must be independent Outside the keyboard and display, non-secure application software will enter these devices in non-secure mode. In particular, the messages displayed on Firefly such as, now enter the password, are generally not reliable. In addition, The symbol or message (such as a lock symbol) displayed on the camp screen to indicate safe operation is unreliable. The safe mode indicator must reliably indicate the date «M on Anyu Light Operation, and only "No" when the device is in the safe U temple. Unless the safe mode indicator is activated, the user should not pass any private information such as passwords or sign on the labor curtain 200424930 Α7 Β7 V. Description of the invention (5) 10 15 Consumer cooperation of the Intellectual Property Bureau of the Ministry of Economic Affairs prints anything 20. Figure 1 shows an embodiment of the present invention in a mega cell 100 having a plurality of processors 102 and 104. Block diagram of the digital system. For the sake of clarity, Fig. 1 only shows the part of the megabit unit 1QQ related to the understanding of one embodiment of the present invention. The general architectural details of digital signal processors (DSPs) are well known and readily available elsewhere. For example, Frederick Boutaud et al. Detail a DSP in US Patent No. 5,072,418. Gary Swoboda et al., In US Patent No. 5,329,471, detail how to test and simulate a DSP. The following will fully describe the part of the megabit unit 100 related to one embodiment of the present invention, so that those skilled in the microprocessor technology can implement and utilize the present invention. Although the present invention finds special applications for implementing digital systems such as those on special application integrated circuits (ASICs), it also finds applications for other forms of systems. The ASIC may include one or more megabit units, each of which includes a functional circuit designed for a customer and a pre-designed functional circuit from a design library. There is a distributed security system in the megabit unit 100, which uses a combination of selected hardware blocks and fork protection software execution environments. The distributed security system is a method to solve e-commerce (e, business) and mobile commerce (m-commerce) security issues in the mobile phone environment. The security issues include the following: Density: ensure that only the communicator understands the content of the transmitted information;-integrity: ensure that the information does not change during transmission; 'verification: ensure that the other-the correspondent is what he claims -No negativity: ensure that the sender cannot deny sending the message;

200424930 五、發明說明200424930 V. Description of Invention

A7 B7 -用戶保護性:假名與匿名; -無法複製之保護。 現行作業系統(〇s)無法被視為安全。部分〇s聲稱 安全’但其複雜性導致不易達成或保證安全。對電子商務及 其它安全交易而言’亟f安全軟體層。此須易於在既有os 施行,但又支援記憶體管理單元(MMU)與快速緩衝儲存 區使用,同時支援及時中斷與QS支援。 在許多應用中已證實僅具軟體之解決方式不夠健全,且 僅能透過軟硬齡構之妥善個解決這些議題。在此實施例 中採用之安全模式之發展’係為將硬體健全性導入整體保全 機制中,其係根據以下前提為之: -作業系統(〇s)不可信賴; -在平台上執行之所有本質軟體均不可信; _唯一可信之軟體為儲存於安全程式R0M/SRAM中之碼; -可因性能之故啟動快速緩衝儲存區; -為即時之故可啟動中斷; -為彈性之故可啟動MMU。 上述丽提驅動下列結果。首先,〇S記憶體管理並不可 信。換言之,MMU操作與0S定義之轉譯表並不可靠。安 全模式應可抗拒MMU之任何誤用以及〇s定義之轉譯表可 能錯誤百出的事實。其次,Qs定義之情向量表以及中斷 服務例行程序並不可信。需於安全模式下施行中斷之特定管 理,致使安全模式得以抗拒中斷之任何誤用以及中斷向量表 及丨SR可能錯誤百出的事實。第三,〇s基本操作之完整性 本紙張尺度適用1f7國國家標準(CNS)A4規格(2丨Οχ 297公髮)A7 B7-user protection: pseudonymity and anonymity;-protection against copying. The current operating system (0s) cannot be considered safe. Some 〇s claim security, but its complexity makes it difficult to achieve or guarantee security. For e-commerce and other secure transactions, there is a need for a secure software layer. This must be easy to implement on existing os, but also support the use of memory management unit (MMU) and cache memory, while supporting timely interruption and QS support. In many applications, it has been proven that software-only solutions are not sound enough, and these issues can only be properly addressed through the hard and soft age structure. The development of the security model used in this embodiment is to introduce hardware integrity into the overall security mechanism, which is based on the following premise:-the operating system (0s) is unreliable;-all executed on the platform The essential software is not trusted; _ The only trusted software is the code stored in the security program ROM / SRAM;-the fast buffer storage area can be started for performance reasons;-the interrupt can be started for real-time reasons;-the flexibility can be Start the MMU. The above mentioned Liti drives the following results. First, OSS memory management is untrustworthy. In other words, the translation table defined by MMU operation and OS is not reliable. The security model should be able to resist any misuse of the MMU and the fact that the translation table defined by 0s may be erroneous. Secondly, the Qs definition vector table and interrupt service routines are not credible. The specific management of interrupts needs to be performed in safe mode, so that safe mode can resist any misuse of interrupts and the fact that the interrupt vector table and SR may be erroneous. Third, the completeness of the basic operation of 0s This paper standard is applicable to 1f7 national standard (CNS) A4 specification (2 丨 〇χ 297)

200424930 A7200424930 A7

(如背景保存、快速緩衝儲存區快取、丁LB快取、寫入緩 衝;及取等)並不確定,故安全模式不應仰仗之。最後但非最 不重要處在於,在安全模式下,需將所有的測試、錯誤移除 與核擬能力去除。 5 ο 1·—* 經濟部智慧財產局員工消賣合作社印製 20 在此實施例中,針對處理器102產生分割”安全模式”, 使之可如個別虛擬保全處理器”般操作,並同時執行保全操 作。可將安全模式視為處理器102之第三特權等級。其啟 動端視特定目的硬體之存在於否而定,該硬體可藉由不受信 賴之軟體產生一環境,以保護機密資訊不被存取。安全模式 係由宣告一專屬之保全信號152設定之,保全信號彳52傳 播過系統,並於受信賴軟體可進入之資源與任何軟體皆可進 入之資源間建立邊界。 安全模式啟動亦視保全軟體之適當控制而定。保全軟體 係儲存於安全程式ROM/SRAM中,並於該處執行。該處不 可能存在藉由欺瞒硬體而得以進安全模式,或取得受信賴 碼而施行其不應施行之任務之流動。若適當建立邊界,則除 經由受控制之操作外,應無利用處理器之正常操將資訊作自 邊界内向外移之管道。注意處理器之正常操作包含執行有潛 在瑕疵之”用戶碼”。 安全軟體層受安全記憶體之信賴並儲存於其中。其係藉 由通過單一安全閘道至安全模式,同時保護免於MMU修 改,而進入一軟體序列,向硬體保全狀態引擎(SSM) 150 展不其確賞在執行女全碼。當女全軟體正在在執行安全模式 時,將中斷向量重新定向,致使保全控制軟體得以視需要開 本紙張尺度適用中國國家標準(CNS)A4規格(2丨0x297公釐) 200424930 A7 B7 五、發明說明(8 ) 始適當離開安全模式。重新定向過程對〇S為透明的,並可 在過渡後避免顯現安全資料。 5 15 經 濟 部 智 慧 財 產 局 合 作 社 印 製 20 GPIO閂鎖154係以ΐ知方式操作之記憶體映對問鎖, 例外處在於其僅可為安全軟體存取與啟動。指示器155輕 合至GPIO 154,並響應於GPIO而發亮。藉由寫入一如邏 輯1之邏輯值於閂鎖154而打開指示器155 ;並藉由寫入 一如邏輯0之互補邏輯值於閂鎖154而將其關閉之。核心 103經週邊匯流排信號156存取閂鎖154。但係以受控於 SSM 150之安全信號152限定GPI◦閂鎖154之操作。如 此一來,僅可於安全信號152處於指示處理器1〇2正執行 安全軟體例行程序之啟動狀態時對GPIO 154寫入。在本實 施例中,指示器155係發光二極體(LED),但在其他實施 例中,可採用得以顯現兩相異錢:開與關之任何類型之指 示器。例如可採用各類燈,諸如氖、錢等。可制各種機 械裝置,諸如轉動顯示不同色而指示開/關狀態之碟,或移 動柁示器以代表開/關狀態之致動器。在其他實施例中, 可以結構、高度、溫度等之表面變化表示兩狀態,使得視力 有缺陷或其他肢體受損人顿讀測兩錄態。例如可將接 觸f指示器置於捲動式顯·示器裝置中。在另-實施财,指 不可提供音頻指示,例如可播放音調以指示安全模式開 啟’但由於可轉安全音親模仿該音調,故需有_定程度 之注意。 復參關1,驗單元彻包含具32位元核心之 微處理器(MPU) 1〇2,l、m a ncD 以及具DSP核心105之數位信號 -10- 本紙張尺度顧令國國家標準(CNS)A4規格(21〇— 297公釐) 200424930 A7 B7 五、發明說明(9 )(Such as background save, fast buffer storage area cache, DLB cache, write buffer; and fetch, etc.) are not sure, so the security mode should not be relied on. Last but not least, in safe mode, all testing, error removal, and verification capabilities need to be removed. 5 ο 1 · — * Printed by the staff of the Intellectual Property Bureau of the Ministry of Economic Affairs, printed by the cooperative. 20 In this embodiment, a split “security mode” is generated for the processor 102, so that it can operate as an individual virtual security processor, and simultaneously Perform security operations. The security mode can be regarded as the third privilege level of the processor 102. Its activation end depends on the existence of specific purpose hardware, which can generate an environment through untrusted software to Protect confidential information from being accessed. The security mode is set by announcing an exclusive security signal 152, and the security signal 彳 52 is transmitted through the system and establishes a boundary between resources accessible by trusted software and resources accessible by any software. The activation of the security mode also depends on the proper control of the security software. The security software system is stored in the security program ROM / SRAM and executed there. There can be no access to the security mode or deception by deceiving the hardware. Trust the flow of tasks that it should not perform. If the boundary is properly established, there should be no use of the processor's normal operations, except through controlled operations. It is used as a pipeline that moves outward from the boundary. Note that the normal operation of the processor includes the execution of "user code" with potential flaws. The security software layer is trusted and stored in the secure memory. It is accessed through a single security gateway to Safe mode, while protecting from MMU modification, and enters a software sequence to the hardware security state engine (SSM) 150 does not really reward the execution of the female full code. When the female full software is executing the safe mode, it will be interrupted Vector reorientation, so that the security control software can use the Chinese paper standard (CNS) A4 specification (2 丨 0x297 mm) as required. 200424930 A7 B7 V. Description of the invention (8) Leave the security mode appropriately. Reorientation process It is transparent to 0S and can prevent the emergence of security information after the transition. 5 15 Printed by the Intellectual Property Bureau of the Ministry of Economic Affairs. 20 GPIO latch 154 is a memory mapped interlock that operates in a known manner. The exception is its Can only be accessed and activated by security software. The indicator 155 is lightly closed to GPIO 154 and lights up in response to the GPIO. By writing logic like logic 1 The indicator 155 is turned on by the latch 154; and the latch 154 is turned off by writing a complementary logic value such as logic 0 to the latch 154. The core 103 accesses the latch 154 via the peripheral bus signal 156. The GPI is limited by the security signal 152 controlled by the SSM 150. The operation of the latch 154 is limited to the GPIO 154 only when the security signal 152 is in the startup state indicating that the processor 102 is executing a security software routine. Write. In this embodiment, the indicator 155 is a light-emitting diode (LED), but in other embodiments, any type of indicator that can show two different kinds of money: on and off. For example, it can be used Various lights, such as neon, money, etc. Various mechanical devices can be made, such as turning a disc that displays different colors to indicate the on / off state, or an actuator that moves the indicator to represent the on / off state. In other embodiments, the two states can be represented by surface changes in structure, height, temperature, etc., so that a person with visual impairment or other limb impairment can read and test the two states. For example, the contact f indicator can be placed in a scroll display device. In another implementation, it means that no audio instructions can be provided, for example, a tone can be played to indicate that the safe mode is on ', but since the turnable safety tone can imitate the tone, a certain degree of attention is required. Repeat reference level 1. The test unit contains a 32-bit core microprocessor (MPU) 102, 1, ncD, and a digital signal with DSP core 105. -10- This paper is based on the national standard (CNS) A4. Specifications (21—297 mm) 200424930 A7 B7 V. Description of the invention (9)

處理器(DSP) 104,兩者共用一稱之為第二等級(L2)記 憶體子系統之記憶體方塊113。流量控制方塊11〇接收來自 連結至主介面120b之主處理裔之轉移要求、來自控制處理 态102之要求,以及來自DSP104中之記憶體存取節點之 5 轉移要求。流量控制方塊插入這些要求,並將之呈現於共用 之記憶體與快速緩衝記憶區。亦經流量控制方塊存取共用週 邊116。直接記憶體存取控制器1〇6可於外部來源如晶片外 3己憶體132或晶片上記憶體134與共用記憶體間轉移資 料。亦可視各應用需要將各種特定應用處理器或硬體加速器 10 108納入兆位單元中,並經由流量控制方塊與DSP及MPU 交互作用。 .訂· 在兆位單元之外,第三等級(L3)控制方塊130響應 於來自DSP或MPU之明確要求,連結接收來自内部流量 控制方塊110之§己憶體要求。晶片外之外部記憶體132及/ 15 或晶片上記憶體134連結至系統流量控制器130 ;這些稱 經濟部智慧財產局員工消費合作钍印製 之為L3記憶體子系統。時框緩衝器136及顯示裝置138均 連結至系統流量控制器,以接收用以顯示圖像之資料。主處 理β 120a與外部資源經由系統流量控制器13〇交互作用。 連結至流量控制器130之主介面可為主處理器i2〇a存取至 20 外部記憶體及其他連結至流量控制器130之裝置。因此, 在各實施例中,可於第三等級或第二等級下連結主處理器。 —組私人週邊140連結至DSP ,同時另一組私人週邊142 連結至MPU。 圖2係在圖1之系統中之MPU 102之方塊圖,其闡釋 -11- 本·.氏張尺度迥用中國國家標準(CNS)A4規格(210 x297公釐) 200424930 A7 五、發明說明(10 10 15 經濟部智慧財產局員工消費合作钍印製 20 採用選擇硬體方塊與由保全狀態弓丨擎執行之受保護軟 體執行環境之組合之分散保全。在數位系統之另一實施例 中,、舉例來說,處理器1(32可為單—處理器,或可搞合至 一或更多個處理器供協同操作之用。 安全模式係處理器102.之,,第三特權等級,,。安全模式提 供硬體手段,嫌制對於在適當執行環境下設定之處理器子 系統(CPU) 20Ό之安全資社存取。安全模式係建於 CPU 2Q0周圍,CPU 200包含處理器核心、資料及指令快 速緩衝健存區204、206與MMU 210。優點在於本實施例 之保全特性對CPU 200不具侵入性,故在另一實施例中, 可採用另一處理器取代本處理器處。 保全硬體有兩類:控制保全信號之邏輯,以及受限於安 全模式之硬體資源。前者主要由保全狀態引擎(SSM) 3〇〇 組成。SSM 300負責監視進入安全模式之條件;宣告/取消 保全彳§號302 ;以及彳貞側安全模式違反。藉由宣告連結至重 置電路系統306之違反信號304而指示違反,其在檢測到 保全違反時即使系統重置。保全狀態引擎監視來自處理器 200外部介面之各信號330,尤其是在指令匯流排上為處理 裔取得之位址。保全狀態引擎緊密麵合至來自進入序列之低 階組合碼。其對由所監視信號上之進入序列產生之事件作出 反應。 當宣告保全信號302時即進入安全模式。當宣告保全信 號時,其傳遍整個系統,俾開放對安全資源之存取。在安全 模式下,僅有處理器200可存取安全資源。在本實施例 計 -12- 本紙張尺度適用中國國家標準(CNS)A4規格(210 X 297公釐) 200424930 A7The processor (DSP) 104 shares a memory block 113 called a second-level (L2) memory subsystem. The flow control block 11 receives a transfer request from the main processing node connected to the main interface 120b, a request from the control processing state 102, and a 5 transfer request from a memory access node in the DSP 104. The flow control block inserts these requests and presents them in shared memory and fast buffer memory. The shared periphery 116 is also accessed via a flow control block. The direct memory access controller 106 can transfer data from external sources such as off-chip memory 132 or on-chip memory 134 and shared memory. It can also be seen that each application needs to include various application-specific processors or hardware accelerators 10 108 into the megabit unit, and interact with the DSP and MPU through the flow control block. · In addition to the megabit unit, the third level (L3) control block 130 responds to the explicit request from the DSP or MPU, and links to receive the §memory request from the internal flow control block 110. The external memory 132 and / 15 outside the chip or the on-chip memory 134 are connected to the system flow controller 130; these are called the L3 memory subsystem printed by the consumer cooperation of the Intellectual Property Bureau of the Ministry of Economic Affairs. Both the time frame buffer 136 and the display device 138 are connected to the system flow controller to receive data for displaying images. The main processing β 120a interacts with external resources via the system flow controller 130. The main interface connected to the flow controller 130 can access the main processor i20a to 20 external memories and other devices connected to the flow controller 130. Therefore, in each embodiment, the main processor may be connected at the third level or the second level. — A group of private peripherals 140 is connected to the DSP, while another group of private peripherals 142 is connected to the MPU. Fig. 2 is a block diagram of the MPU 102 in the system of Fig. 1 and its explanation. The eleven-square scale uses the Chinese National Standard (CNS) A4 specification (210 x 297 mm) 200424930 A7. 5. Description of the invention ( 10 10 15 Printed by the Intellectual Property Bureau of the Ministry of Economic Affairs for consumer cooperation. 20 Decentralized security using a combination of selected hardware blocks and a protected software execution environment executed by a security state bow engine. In another embodiment of the digital system, For example, the processor 1 (32 may be a single-processor, or may be combined with one or more processors for cooperative operation. The security mode is the processor 102. Among them, the third privilege level, The security mode provides hardware means to prevent access to the security subsystem of the processor subsystem (CPU) 20Ό set under the appropriate execution environment. The security mode is built around the CPU 2Q0. The CPU 200 contains the processor core, The data and instruction cache areas 204, 206 and MMU 210 are fast. The advantage is that the security features of this embodiment are not invasive to the CPU 200. Therefore, in another embodiment, another processor may be used instead of the processor. Security Hardware Yes Category: logic to control the security signal, and hardware resources restricted by the security mode. The former is mainly composed of the security state engine (SSM) 300. SSM 300 is responsible for monitoring the conditions for entering the security mode; declare / cancel security 302; and the security mode violation on the side. Indication of a violation by declaring a violation signal 304 connected to the reset circuit system 306, even if the system is reset when a security violation is detected. The security status engine monitors from the external interface of the processor 200 Each of the signals 330, especially the address obtained for the processing source on the instruction bus. The state-preserving engine is tightly coupled to the low-order combination code from the incoming sequence. It makes events on the events generated by the incoming sequence on the monitored signal Response. The security mode is entered when the security signal is announced 302. When the security signal is announced, it passes through the entire system and opens access to secure resources. In secure mode, only the processor 200 can access secure resources. In this example -12- This paper size applies to China National Standard (CNS) A4 (210 X 297 mm) 200424930 A7

Order

I I 4I I 4

、發明說明(12) 安全模式下具有少許可被重置之變數,因而具有已知且僅可 於安全模式下改變之初使值係屬有利。例如此特性可用以: 在安全模式下檢測第一入口;設定適當離開.模式值(正常、 例外、違反);檢測電源開啟等。在另一實施例中,可以其 它方式施行這些可重置值,諸如藉由將暫存器置於未與 SRAM重疊之位址空間中;藉由連結重置信號至SRam内 之所選記憶體單元等。 並無可用以宣告保全信號302或改良狀態引擎行為之軟 體方式。SSM緊練合至將參關5詳述之啟動序列。 SSM監視來自處理器2〇〇之實體指令位址匯流排33〇以及 自各資源接收之各進入條件信號321-327 α出自處理器2〇〇 之指令介面信號331與資料介面信號333亦被監視,並分 別界定在指令匯流排330與資料匯流排332上施行何種匯 流排處置。 安全杈式係藉由分支為公用R〇M中之一特定位址而進 入’其稱之為單一進入點,此係SSM中之硬編碼位址。進 入點係’’啟動序列”之開始位址。啟動序列係餘存於耦合至保 全狀態引擎之公用ROM之-組瑪,並確保符合安全模紅 部为進入條件。其他進人條件係由監縣定進人條件信號而 直接評估。 啟動序列於保全狀態引擎所監視之部分錢上產生界定 之事件.序列。這些事件確保進入安全模式所需之條件已符 合。保全狀態引擎認知此模式並宣告保全信號。在安全模式 下’保全狀態弓|擎持續監視-些信號,俾檢測安全模式違反 200424930 五、發明說明(13 ) 105 0 112 經濟部智慧財產局員工消費合泎钍印製 A7 B7 及確保符合安全模式離開程序。不論何時發生違反情事, SSM均會釋出保全信號並宣告保全違反信號304。典型違 反係I试取出r〇M/sram位址範圍外之指令。 啟動序列係儲存於公用R〇M中。其確保安全模式進入 條件已符合。環境設定序列係儲存於安全ROM中。其針對 用於可致動快速緩衝儲存區'中斷與MMU處之安全模式設 定適當執行環境。離開序列係儲存於安全R〇M中。其強制 執行符合安全模式離開程序。其藉由一 BRANCH或在中斷 .下提供一女全離開安全模式之方式。其亦於離開時保護安全 ROM與RAM之”私密”内容。 仍參閱圖2,保全控制暫存器319僅在安全模式下可充 作δ己憶體映對暫·存器而可以存取,並用以致動/關閉可被駭 客用,以破壞保全,但對系統硬體與軟體之認證及除錯仍屬需 要而使用之測試、除錯與模擬設施。例如以信號32彳表示 之一位元致動/關閉供程式發展用之嵌入追縱巨集單元 (ΕΤΜ) 350之運作。信號322致動/關閉在處理器2〇〇上 之JTAG介面之運作。信號323致動/關閉在處理器2〇〇上 之除錯介面(dbg I/F)之運作。 在非安全模式下,保全條件暫存器32〇可充作記憶體映 對暫存器而被存取,並藉由控制可為駭客用以破壞保全之各 資源之操作模式而設定在安全模式下之部分進入條件。自保 全條件暫存器提出之信號亦受狀態引擎監視。例如直接記憶 體存取(DMA)致動信號324係用以致動可以存取安全記 憶體312之DMA控制器(未圖示)。 -15- 本紙張尺度適用中國國家標準(CNS)A4規格(2丨0 x297公爱)Explanation of the invention (12) There are a few variables that can be reset in the safe mode, so it is advantageous to have the initial value that is known and can only be changed in the safe mode. For example, this feature can be used to: detect the first entry in safe mode; set the proper leave. Mode values (normal, exception, violation); detect power on, etc. In another embodiment, these resettable values can be implemented in other ways, such as by placing a register in an address space that does not overlap the SRAM; by linking the reset signal to the selected memory in the SRam Unit, etc. There is no software way to declare the security signal 302 or improve the behavior of the state engine. SSM is tightly integrated into the startup sequence detailed in Part 5. The SSM monitors the physical instruction address bus 330 from the processor 200 and the entry condition signals 321-327 received from each resource. The instruction interface signal 331 and the data interface signal 333 from the processor 200 are also monitored. It also defines what kind of bus processing is performed on the instruction bus 330 and the data bus 332. A secure fork is an entry by branching to a specific address in a common ROM. It is called a single entry point and is a hard-coded address in the SSM. The entry point is the start address of the "startup sequence". The startup sequence is stored in the -ROM of the public ROM coupled to the security status engine, and it is ensured that the red part of the security model is the entry condition. Other entry conditions are monitored by the supervisor The county determines the condition signal and directly evaluates it. The startup sequence generates defined events on a portion of the money monitored by the security status engine. The sequences ensure that the conditions required to enter the security mode have been met. The security status engine recognizes this model and declares Security signal. In the safe mode, the “preservation status bow | engine continuously monitors some signals to detect violations of the security mode. 200424930 V. Description of invention (13) 105 0 112 Employees of the Intellectual Property Bureau of the Ministry of Economic Affairs printed A7 B7 and Ensure that the safe mode exit procedure is met. Whenever a violation occurs, SSM will release a security signal and declare a security violation signal 304. A typical violation is to try to take out instructions outside the range of rOM / sram. The startup sequence is stored in Public ROM. It ensures that the safe mode entry conditions have been met. The environment setting sequence is stored in the secure ROM. Set the appropriate execution environment in the safe mode that can activate the fast buffer storage area 'interrupt and MMU. The exit sequence is stored in the secure ROM. It enforces the safe mode exit procedure. It is executed by a branch or interrupt. The following provides a way for a woman to leave the security mode. It also protects the "private" content of the security ROM and RAM when leaving. Still referring to Figure 2, the security control register 319 can act as a delta memory only in the security mode. The mapping memory can be accessed and used to actuate / shut down. It can be used by hackers to break the security, but the system hardware and software certification and debugging are still needed for testing, debugging and simulation. Facility. For example, signal 32 indicates that one bit activates / deactivates the operation of embedded tracking macro unit (ETM) 350 for program development. Signal 322 activates / deactivates the JTAG interface on the processor 2000. The signal 323 activates / deactivates the operation of the debug interface (dbg I / F) on the processor 200. In the non-secure mode, the security condition register 32 can be used as a memory mapping temporarily. Registers and are accessed by control Partial entry conditions set in safe mode for hackers to destroy the operation mode of the resources protected. The signals provided by the self-protection condition register are also monitored by the state engine. For example, direct memory access (DMA) actuation Signal 324 is used to actuate a DMA controller (not shown) that can access the secure memory 312. -15- This paper size applies to China National Standard (CNS) A4 specification (2 丨 0 x297 public love)

200424930 Α7200424930 Α7

5 ο 1Χ 5 1Χ 經濟部智慧財產局員工消賣合作社印製 20 在本實施例中,為測試而提供掃瞄串介面(掃插|/f), 並可提供保全破壞點。但處㈣未提供_掃描串輸 出之手段。為避免修改處理H 之内部信號,自外部= 供掃描閘342,俾於遮蓋處理器2〇〇之掃睇輪出,其時鐘 長度等於處理器200内最長掃描串之數目。於重置時初私 化此遮蔽機制(計數器重置),且每次均以在外部測試設備 (未圖示)之控制下之掃描致動將裝置自功能模式切換為測 試模式。 提供外部中斷操作器360以接收一組中斷信號,並將之 夕重發Λ為接著為處理器2〇〇接收之兩中斷信號362、 363·。中斷處理器360具有可由軟體設定之整體遮蔽位元 364,並致使軟體得以對處理器整體關閉所有中斷。不論何 時設定整體遮蔽位元,中斷控制器均宣告遮蔽信號325,並 將中斷信號362、363關閉。在宣告遮蔽信號325後,直到 由軟體清除整體遮蔽位元前,均無法再宣告中斷控制器所輸 出之中斷信號362、363。SSM 300監視遮蔽信號325以決 定是否致動或遮蔽中斷。 自外部記憶體開機係駭客破壞系統保全之常見手段。在 本實施例中,避免外部開機。此外,SSM 300監視於嘗試 外部開機時會被宣告之開機信號327。但在程式發展期間, 較佳允許外部開機以利軟體除錯。提供熔絲電路328以區 分發展裝置與生產裝置。裝置型信號326為SSM 300所監 視,故得以於發展裝置上提供釋放之保全模式。對發展裝置 而言,SSM 300會忽略開機信號327。 -16- 本紙張尺度適用中國國家標準(CNS)A4規格(210x297公爱) 200424930 A7 五、發明說明( 5 10 15 20 圖3係闡釋圖2之R〇M内容及用以將R〇M分割為公 用部與安全部之電路系統之方塊圖。在本實施例中之公用 ROM 311與安全ROM 310係以單一 ROM實施之。在另一 貫施例中’則可於不影響此處之發明性態樣下分割之。位址 解碼态電路370a係用以對r〇m之存取解瑪之解碑電路 370的一部份。對SRAM與其他指令或資料匯流排連結之 裝置提供類似電路。 不論何時,響應於分別和公用ROM位址或安全ROM 位址對應之位址解碼信號406或407,因而宣告在指令位 址匯流排330a上對應於r〇m 310、311之位址,均致動驅 動裔電路400以於指令匯流排33〇b上提供要求指令資料。 “如上揭,若非於安全模式下存取安全資源,則提供假資 料。閘電路404監視保全信號3〇2與安全R〇M解媽信號 407,並且若存取安全R〇M但未宣告保全信號,則使驅動 器電路400通過無效資料。 安全模式 圖4係_賴2纽上安全模式操狀存取流程圖, 現將更加詳述之。步驟_、5Q2、5Q4代表在—正常非特 權等級執行t ’在處理器2(χ)上執行之應用程^有時為 在特權等級操作中之服務,如步驟510、512、514及516 所示對作業系統(os)產生—呼叫5Q2。只要_呼叫,郎 2驟⑽中儲存狀態並切換至特權模式;在步驟514中 知订待權操作’·在步驟516中恢復狀態;並在咖中返回 非特權應用。這兩鱗級之卿絲關知。 ° 4 訂 -17- 本紙張尺度適財@ ϋ家標準(cns)A4規格⑽ X 297公釐) 200424930 A7 五、發明說明(l6 在步驟512中,以測試決定所要求之服務是否為安全操 作;若是,則系統將進入稱之為安全模式之第三等級保全。 在步驟520 + ’ OS驅動器施行管家工作,.將系統置於適當 狀態以進入安全模式。此包含遮蔽中斷;設定保全條件暫存 器320以關閉存在保全風險之各種資源;以及確認是否致 動記憶體官理單元210,其係使對應於啟動序列之頁表入口 標示為非可快速儲存緩衝’’。此將於稍後進一步詳述。 在步驟522中,復參閱圖3,跳至一位於公用r〇m 311中之進入序列412中之進入點410。進入序列係一組 10 碼,其每次在於平台上執行任何類型之保全碼之前,在”安 全服務’’為應用所呼喚時執行。此序列亦於自已中斷保全碼 訂 執行之例外處恢復時執行。進入序列始於R〇M中界定之位 址,其係為硬編瑪並稱之為”進入點”。進入序列係由兩部分 組成··保全信號啟動序列413及安全模式環境設定序列 414。 啟動序狀目的係為取代處理H 之執行流動,並確 保任何其他非受铺碼無賴先占有4進人糊之此部份 期間之某些點處’宣告保全信號302以進入安全模式,並 解除對安全資源(ROM ' SRAM '周邊裝置等)之存取。 序列414之目的係為設定全媽執行之環境。優點在 於藉由設定安全魏,即可安全致雜式與資憾速緩衝儲 存區,並操作中斷例外。 保全信號啟動序列413位於公用R〇M中,而安全模式 環境設定序列414則位於安全R〇M巾。進入序列之總碼大 -18- 本紙張尺度適用令國國家標準(CNS)A4規格(2|〇 χ 297公釐) 200424930 A7 B7 五、發明說明(Γ 5 10 15 經濟部智慧財產局員工消費合作钍印製 20 小(部份1+部份2)需小於1千位元組,使之得以映對於 1千位元組頁,對此實施例而言為MMU轉譯表中最小記憶 體段落。以此方式為之,則進入序列虛擬位址無法映對於兩 段落上,以在進入序列執行期間,於部分明斷點處優先佔有 處理器。於進入序列之記憶體頁為非可快速緩衝儲存,或於 執行進入序列時將指令快速緩衝儲存區關閉亦屬重要。 隨後將描述安全轉譯表(STT) 420與安全中斷向量表 (SIVT) 430 〇 若所見1千位元組碼大小對給定之實施例而言被視為限 制過大,則MMU可於啟動序列413關閉,並於環境序列 414末處再致動。在此情況下,1千位元組限制將僅對啟動 序列作用。· 復參閱圖4,在步驟524中,為修正之故,以SSM 300檢查啟動序.如下將參關5所詳述。若未正確施行 啟動序列’則於步驟54Q中以SSM 宣告違反信號並將 系統重置。在步驟526中,藉由執行環境設定序列414而 設定安全環境,如後將詳細描述。 要建立女全環境,即從安全碼416於步驟中 執订要求之安全操作,如同以非娜制於開始時要求一 般。依本發明之一態樣,安全碼416 &含在步驟汹」中 寫入GPIO _ 318之—指令,其僅於安全模式下開啟安 全模式指示器319。安全碼接著可於步驟528 2中要求 用戶提供機密資訊,隨後於步驟528.3巾藉由再度寫入 GPIO閂鎖而關閉安全模 又”·, 明女全拉式才曰不裔。在步驟5284中執行附 本紙張尺度適用中國國家標準 訂 200424930 A75 ο 1 × 5 1 × Printed by the staff of the Intellectual Property Bureau of the Ministry of Economic Affairs, sold by the cooperative. 20 In this embodiment, a scan string interface (scanning | / f) is provided for testing, and a security damage point can be provided. However, the office did not provide a means for outputting the scan string. In order to avoid modifying and processing the internal signal of H, from the outside = for scan gate 342, it is out of the scan wheel that covers processor 200, and its clock length is equal to the number of the longest scan string in processor 200. This masking mechanism (counter reset) is personalized at the time of reset, and the device is switched from the function mode to the test mode each time by a scan actuation under the control of an external test device (not shown). An external interrupt operator 360 is provided to receive a set of interrupt signals, and retransmit them as two interrupt signals 362, 363, which are then received by the processor 2000. The interrupt processor 360 has an overall masking bit 364 that can be set by software and enables the software to turn off all interrupts to the processor as a whole. Whenever the overall mask bit is set, the interrupt controller announces the mask signal 325 and turns off the interrupt signals 362, 363. After announcing the masking signal 325, until the overall masking bit is cleared by the software, the interruption signals 362 and 363 output by the interrupt controller can no longer be announced. The SSM 300 monitors the masking signal 325 to decide whether to activate or mask the interrupt. Booting from external memory is a common way for hackers to compromise system security. In this embodiment, external booting is avoided. In addition, the SSM 300 monitors a power-on signal 327 that is announced when an external power-on is attempted. However, during program development, it is better to allow external boot to facilitate software debugging. A fuse circuit 328 is provided to distinguish a development device from a production device. The device-type signal 326 is monitored by the SSM 300, so it can provide a release security mode on the development device. For development devices, the SSM 300 ignores the power-on signal 327. -16- This paper size is in accordance with the Chinese National Standard (CNS) A4 specification (210x297 public love) 200424930 A7 V. Description of the invention (5 10 15 20 Figure 3 illustrates the ROM content of Figure 2 and is used to divide the ROM It is a block diagram of the circuit system of the public ministry and the security ministry. In this embodiment, the common ROM 311 and the secure ROM 310 are implemented by a single ROM. In another embodiment, 'can not affect the inventiveness here. It is divided in an aspect. The address decoding state circuit 370a is a part of the inversion circuit 370 for accessing the ROM of the ROM. Similar circuits are provided for devices connected to the SRAM and other instructions or data buses. At any time, in response to the address decoding signal 406 or 407 corresponding to the public ROM address or the secure ROM address, respectively, the declaration of the address corresponding to the ROM 310 and 311 on the instruction address bus 330a results in The driver circuit 400 is driven to provide the required instruction data on the instruction bus 33ob. "As disclosed above, if the secure resource is not accessed in the safe mode, false data is provided. The gate circuit 404 monitors the security signal 302 and the safety R 〇M solution signal 407, and if access If the safety ROM is not announced, the driver circuit 400 will pass the invalid data. The safety mode is shown in Figure 4_Lai 2 on the safe mode operation flow chart, which will now be described in more detail. Steps_5Q2 5Q4 stands for-normal unprivileged execution of t 'applications executed on processor 2 (χ) ^ sometimes services in privileged operation, as shown in steps 510, 512, 514 and 516 to the operating system ( os) generation—call 5Q2. As long as _call, Lang 2 saves the state and switches to privileged mode; knows the subscription operation in step 514; restores the state in step 516; and returns the non-privileged application in the coffee 。 These two scales are important. ° 4 Order -17- This paper size is suitable for wealth @ ϋ 家 标准 (cns) A4⑽⑽ X 297mm) 200424930 A7 V. Description of the invention (l6 In step 512, Test to determine whether the required service is safe operation; if so, the system will enter a third level of security called a security mode. At step 520 + 'OS driver performs housekeeping work, puts the system in an appropriate state to enter security Mode. This includes masking Set the security condition register 320 to shut down various resources with security risks; and confirm whether to activate the memory management unit 210, which causes the page table entry corresponding to the startup sequence to be marked as a non-quick storage buffer ''. This will be further detailed later. In step 522, referring back to FIG. 3, skip to an entry point 410 in an entry sequence 412 located in the public ROM 311. The entry sequence is a set of 10 yards, each time Before any type of security code is executed on the platform, it is executed when the "security service" is called by the application. This sequence is also executed when the exception is resumed from the execution of the interrupted security code. The entry sequence starts at the address defined in ROM, which is hard-coded and is called the "entry point". The entry sequence is composed of two parts: a security signal activation sequence 413 and a safe mode environment setting sequence 414. The purpose of starting the sequence is to replace the execution flow of processing H, and to ensure that any other non-random code rogue first occupies some point during this part of the gangster's announcement of the security signal 302 to enter the safe mode and release Access to secure resources (ROM 'SRAM' peripherals, etc.). The purpose of the sequence 414 is to set the environment in which the whole mother executes. The advantage is that by setting the safety switch, you can safely store miscellaneous and miscellaneous caches, and make exceptions to operation interruptions. The security signal activation sequence 413 is located in the public ROM, and the safe mode environment setting sequence 414 is located in the safe ROM. The total code of the entering sequence is large-18- This paper size is applicable to the national standard (CNS) A4 specification (2 | 〇χ 297mm) 200424930 A7 B7 V. Description of the invention (Γ 5 10 15 Employees ’consumption of Intellectual Property Bureau of the Ministry of Economic Affairs Cooperate to print 20 small (Part 1 + Part 2) less than 1 kilobyte, so that it can be mapped to a 1-byte page. For this embodiment, it is the smallest memory paragraph in the MMU translation table. In this way, the virtual address of the entry sequence cannot be mapped to two paragraphs, so that during the execution of the entry sequence, the processor is preferentially occupied at some breakpoints. The memory page of the entry sequence is non-fast bufferable storage It is also important to close the instruction fast buffer when executing the entry sequence. The security translation table (STT) 420 and the security interrupt vector table (SIVT) 430 will be described later. If you see that the size of the 1-byte code is given to Considered as too restrictive in the embodiment, the MMU can be turned off at the startup sequence 413 and re-activated at the end of the environmental sequence 414. In this case, the 1-kbyte limit will only affect the startup sequence. See FIG. 4 at step 524 For the sake of correction, check the startup sequence with SSM 300. As described in detail in Part 5. If the startup sequence is not implemented properly, then the violation signal is announced by SSM in step 54Q and the system is reset. The security environment is set by executing the environment setting sequence 414, which will be described in detail later. To create a female-wide environment, that is, to perform the required security operation in steps from the security code 416, as if it was requested at the beginning with a Fina system. According to one aspect of the present invention, the security code 416 & includes a command to write GPIO_318 in the step ”, which only turns on the security mode indicator 319 in the security mode. The security code can then be requested in step 5282 The user provides confidential information, and then in step 528.3, the security mode is closed again by writing to the GPIO latch again. ", The full-length pull-down style is not forbidden. In step 5284, the attached paper is executed in accordance with Chinese national standards. 200424930 A7

Order

AA

200424930200424930

經濟部智慧財產局員工消費合作社印製Printed by the Consumer Cooperative of the Intellectual Property Bureau of the Ministry of Economic Affairs

,’需於觀安纽元錢行非安全顺清除之。為於安全 模式下允許中斷,需提供安全。 &圖5係更詳述保全狀態引-擎·操作之狀態圖。保全狀 態引擎在於ROM中執行啟動相_,於某些點處宣告保 全信號,以進人安全模式。此部分進人序狀目的係為在保 全狀態㈣所侧之信號上產生界定之事件相。這些事件 確保設定保全信號所需之條件為符合,並可以SSM搜尋 2。於整個啟動序列中監視”條件”信號。若在啟動序列結束 則有任何進人條件不符雜止有效,保全狀態引擎將過渡至 違反狀態630並宣告保全違反信號3〇4。在以SSM監裸進 入條件之背後有兩關鍵目的:(彳)處理器200正在汲取且 凌駕執行啟動序列碼;(2)受信賴碼已完全取代cpu執行 流程,除非經過受控操作,不論在設定保全信號之前後,無 任何者可優先占有而不被檢測到。 啟動程序之建構方式係於指令位址匯流排上產生獨特原 型。該原型係由啟動序列碼之(實際)位址值以及在時間中 之相對時機製成,這些位址應出現在匯流排上。但原型之製 成與記憶體系統存取潛伏期無關。確切啟動序列匯流排原型 k自SSM中之模擬及硬編瑪而得。SSM因而確保與啟動 序列匯流排原型完全符合。典型上,啟動序列之最終指令係 分支指令,且異於快速緩衝儲存區清除指令或快速緩衝儲存 區關閉指令,在啟動序列中之所有其他指令均為NOP指 令0 在進入安全模式並已宣告保全信號後,進入條件無需有 -21- 本紙張尺度適用中國國家標準(CNS)A4規格(210 x297公釐), ’Need to be cleared in Guan'an New Yuan money line. To allow interrupts in safe mode, security is required. & FIG. 5 is a detailed state diagram of the security state operation. The security status engine executes the startup phase in ROM and announces a security signal at some points to enter the safe mode. The purpose of this part of the sequence is to generate a defined event phase on the signal on the side of the preservation state. These events ensure that the conditions required to set the security signal are met and can be searched by SSM2. "Condition" signals are monitored throughout the startup sequence. If at the end of the start sequence, any entry conditions are not valid, the protection state engine will transition to the violation state 630 and declare a security violation signal 304. There are two key purposes behind monitoring the entry conditions with SSM: (i) the processor 200 is drawing and executing the boot sequence code; (2) the trusted code has completely replaced the cpu execution process, except after controlled operations, regardless of whether Before and after the security signal is set, no one can take priority without being detected. The startup process is constructed in such a way that a unique prototype is generated on the instruction address bus. The prototype is made up of the (actual) address values of the boot sequence and the relative timing in time. These addresses should appear on the bus. However, the prototype is not related to the memory system access latency. The exact startup sequence bus prototype k is derived from simulation and hard coding in SSM. SSM thus ensures full compliance with the start-up sequence bus prototype. Typically, the final instruction of the startup sequence is a branch instruction, and is different from the fast cache clear instruction or fast cache close instruction. All other instructions in the startup sequence are NOP instructions. 0 In safe mode and have been declared safe After the signal, the entry conditions do not need to be -21- This paper size applies to China National Standard (CNS) A4 (210 x 297 mm)

200424930 經濟部智慧財產局員工消費合作社印製 A7 B7 五、發明說明(20 ) 效,且SSM不對其持續測試。但SSM持續偵測各信號以 檢測女全模式运反,以下將描述之。直到有效進入安全記憶 體後’始測試安全模式離開條件。 復參閱圖5,狀態600係一閒置狀態,在該段期間 5 SSM監視位址匯流排330,尋找進入序列之進入點位址 (ESA[EP])。只要一檢測到進入點位址,若符合所有進入 條件’ SSM即過渡至狀態601 ;若非如此,則過渡至宣告 違反信號304之違反狀態630處。 須藉由檢測正確進入序列位址及對應之進入條件信號而 10 依序經過各狀態601-615,否則SSM即過渡至違反狀態 630。若這些序列無誤地經過,則進入安全模式狀態620並 宣告保全信號302。 例如為自狀態600過渡至狀態601,進入點指令之位址 須與所有的正確條件信號一併出現。次一出現位址須為次一 15 序列指令之位址,以過渡至狀態602,否則SSM即過渡至 違反狀態630。在一顓似方法中,啟動序列之各位址均須出 現,以過渡至狀態602-615,且最終至安全模式狀態620。 在一條件信號中之錯誤位址'位址計時或錯誤變化,均將造 成過渡至运反狀態630 ’諸如呢線601a所示。類似地,若 2〇 狀態信號指示任一啟動序列存取均為可快速緩衝儲存,則啟 動序列會失敗。 在安全模式狀態620中,以及在有效檢測用以指示已進 入安全記憶體之安全例行程序(ESA[SR])之位址後,若以 位於公用R〇M内之SSM檢測出一位址,則SSM過渡回 -22- 本紙張尺度適用+國國家標準(CNS)A4規格(210 x 297公釐)200424930 Printed by the Consumer Cooperatives of the Intellectual Property Bureau of the Ministry of Economic Affairs A7 B7 V. Invention Description (20), and SSM does not continuously test it. However, the SSM continuously detects each signal to detect the reversal of the female full mode, which will be described below. The test of the safe mode exit condition is not performed until after the safe memory is effectively entered. Referring again to FIG. 5, state 600 is an idle state. During this period, 5 SSM monitors address bus 330 to find the entry point address (ESA [EP]) of the incoming sequence. As soon as an entry point address is detected, SSM transitions to state 601 if all entry conditions are met; otherwise, transitions to state 630 where the violation signal 304 is declared. 10 must pass through the states 601-615 in sequence by detecting the correct entry sequence address and the corresponding entry condition signal, otherwise the SSM transitions to the violation state 630. If these sequences pass without error, the safe mode state 620 is entered and a security signal 302 is announced. For example, to transition from state 600 to state 601, the address of the entry point instruction must appear with all the correct condition signals. The next occurrence address must be the address of the next 15 sequence instruction to transition to state 602, otherwise SSM transitions to violation state 630. In a similar approach, all addresses in the startup sequence must appear to transition to states 602-615, and finally to safe mode state 620. The error address 'address timing or error change in a condition signal will cause a transition to the reverse state 630', such as shown by the line 601a. Similarly, if the 20 status signal indicates that any boot sequence access is cacheable, the boot sequence will fail. In safe mode state 620, and after effectively detecting the address of the security routine (ESA [SR]) that indicates that it has entered secure memory, if an address is detected by the SSM located in the public ROM , Then SSM transitions back to -22- This paper size applies + National National Standard (CNS) A4 specification (210 x 297 mm)

五、發明說明(Μ) 200424930 Α7 ___ Β7V. Description of Invention (Μ) 200424930 Α7 ___ Β7

到閒置模式600,如弧線621所示。若以r〇m或SRAM 外之SSM檢測出一位址,或者若以受監視信號中之錯誤變 化指示保全違反,則SSM過渡至違反狀態63〇 ,如弧線 622所示。 在啟動序列期間無需關閉指令快速緩衝儲存區;指令之 不可快速緩衝儲存性即足以確保進入序列之健全。但使快速 緩衝儲存區關閉將消弭根據快速緩衝儲存區清除機制之不當 使用所為之侵入嘗試。 安全模式環境設定序列Go to idle mode 600, as shown by arc 621. If an address is detected with Sm outside of rom or SRAM, or if a security violation is indicated by an error change in the monitored signal, the SSM transitions to a violation state of 63, as shown by arc 622. There is no need to close the instruction cache during the startup sequence; the non-cacheable nature of instructions is sufficient to ensure the soundness of the incoming sequence. However, turning the cache off will eliminate attempts to invade it by improper use of the cache clearing mechanism. Safe Mode Environment Setting Sequence

復參閱圖4,在步驟526中,藉由執行來自安全R〇M 之環境設定序列414而設定安全環境。此序列之目的在設 定供安全碼執行狀適當觀。安全魏允許·程式與資 料快速緩衝儲存區、即時中斷及潛在之MMU。這些步驟中 之某一些特定針對安全模式操作,某些則係在呼叫啟動序列 則正常應已為QS施行之操作。如前述,安全模式不能仰賴 基本〇s操作。因此,環境設定序列需施行部分背景切換操 作如快速緩衝儲存區清除、TLB清除等對安全模式完整性 為基本者。 系統實施例 圖6闡釋在—行動電信裝置巾實現本發明之積體電路之 示例性施行,諸如行動個人數位助理(PDA) 1〇,其具有 顯示器14以及位於顯示器14 之整合輸入感測器 12a、12b。數位系統1〇包含如圖,之驗單元彻,其經 接合器(未圖示)連結至輸入感測器12a、12b,作為Mpu -23-Referring again to FIG. 4, in step 526, a secure environment is set by executing an environment setting sequence 414 from the secure ROM. The purpose of this sequence is to set a proper view of the execution status of the security code. Security Wei allows programs and data to quickly buffer storage areas, immediate interruptions, and potential MMUs. Some of these steps are specific to safe mode operation, and some are normal operations that should have been performed for QS during the call start sequence. As mentioned before, the safe mode cannot rely on basic 0s operation. Therefore, the environment setting sequence needs to perform some background switching operations, such as clearing the cache area and clearing the TLB, which are essential to the security mode integrity. System Embodiment FIG. 6 illustrates an exemplary implementation of an integrated circuit implemented in a mobile telecommunication device, such as a mobile personal digital assistant (PDA) 10, having a display 14 and an integrated input sensor 12a located on the display 14. , 12b. The digital system 10 includes a test unit as shown in the figure, which is connected to the input sensors 12a and 12b via an adapter (not shown) as an Mpu -23-

1520 經濟部智慧財產局員工消費合作钍印製 五、發明說明(22) 周邊142用。可利用炎筆或手指經輸入感測器他、 伽輸入資訊至PDA。顯示器14經由類似於時框緩衝器 136之局部_缓衝器連結至驗單元彻^顯示器^提 供在疊置視窗如MPEG影像視窗l4a、共 5 10 15 他及三維遊戲視窗14c中之圖像與影像輸出。 卿⑽;電路系統、補不」運結至天線18,盆為 驗單元鶴驅動作為DSP私人周邊⑽並提供無線網路 鏈。接頭20連結至電境接合器姻機(未圖示),並自該 處連結至尬料彻作為Dsp私人周邊,提供有線 網路鍵供例如辦公室環射靜態烟。純餘鏈23亦,,連 結至耳機22,並為賴至纽單元·作為咖私人周 邊140之低功率發射機(未圖示)所驅動。麥克風μ亦以 類似方式連結至兆位單元彻,因而得以利用麥克風%及 無線耳機22與無線或有線麟上之其侧戶交換雙向聲音 資訊。 Λ 兆位早π 1⑷對經由無線網路鍵及/或以有線為基之網 路鍵傳送熱收之聲音與影像/圖«訊提供所有的編碼與 解碼。優點在於驗^勘亦提供安全操作模式。如此 處所述’安全模式指示器燈3〇受控於一問鎖,其在兆位單 2〇 70彻正於安全模式下執行時,僅可由執行碼開啟之。安 全模式指示器燈30藉以於安全時指示ρ〇Α 1〇之用戶以1520 Consumption co-operation by employees of the Intellectual Property Bureau of the Ministry of Economic Affairs V. Description of invention (22) 142 for peripheral use. You can use Yan Pen or your finger to input information to the PDA via the sensor. The display 14 is connected to the inspection unit via a local buffer similar to the time frame buffer 136. The display ^ provides the images in the superimposed windows such as the MPEG image window 14a, a total of 5 10 15 and the 3D game window 14c. Image output. ⑽ 电路; circuit system, make up "is carried to antenna 18, the driver for the inspection unit crane is used as a DSP private peripheral, and provides a wireless network chain. The connector 20 is connected to an electrical coupler (not shown), and from there it is connected to the device as a Dsp private perimeter, providing a wired network key for, for example, the office to emit static smoke. The pure surplus chain 23 is also connected to the earphone 22 and is driven by a low-power transmitter (not shown) as a private peripheral 140 of the coffee unit. The microphone μ is also connected to the megabit unit in a similar manner, so that the microphone% and the wireless headset 22 can be used to exchange two-way sound information with its side users on the wireless or wired link. Λ Megabit π 1⑷ provides all encoding and decoding for the sound and video / pictures that are transmitted via wireless network keys and / or wired-based network keys. The advantage is that the survey also provides a safe operating mode. As described herein, the 'safe mode indicator light 30' is controlled by a question lock, which can only be turned on by the execution code when the megabit 270 is executed in the safe mode. The safety mode indicator lamp 30 indicates to the user of ρ〇Α〇 at

提供在PDA上執行之應帛之機密資料。在此方法t,PDA Γ玫對在行動電輯翻㈣之電子聽(e·雜)及行動 商務(m-商務)保全議題提供解決方法。 -24- 200424930 A7Provide confidential information for execution on the PDA. In this method t, PDA Γ provides solutions to the issues of electronic listening (e.com.) And mobile commerce (m-commerce) preservation in mobile electronic series. -24- 200424930 A7

I I I 200424930 A7 B7 24 五、發明說明 玄、、心令與資料快速緩衝儲存區、寫入緩衝器及記憶體管 理單7C。安全執行模式位於-平台上,其中唯_信賴軟體為 儲存於ROM中之竭。特別言之,0S不受信賴,所有本質 應用亦不受信賴。安全模式指示器係為告知用戶裝置處於安 全模式用。 105 ο 1 1 2 經濟部智慧財產局員工消費合作社印製 雖已參閱圖解實施例描述本發明,此描述並無因而限制 之意。熟悉本技藝者,參閱此描述即可了解本發明之各種其 他實施例。例如此處所述安全模式態樣均可用以改善所有處 理裔類型如精間指令集運算(RISC )、複雜指令隼運算 (CISC)、寬字組、DSP等。 在另一實施例中,可擴充安全環境以於數個起始器資源 如DSP間共享安全資源。在此一實施例中,可以保全狀態 引擎監視各指示器資源,以強制實施上述保全原理。 在各實施例中,可具有安全硬體之不同補充物,包含各 周邊如監視計時器、加密/解密硬體加速器、隨機數產生器 (RNG)等;以及各種|/〇裝置如鍵盤、[CD、觸控螢幕 等。 復參閱圖1,在另一實施例中,第二SSM可位於DSP 104中’俾以處理益1〇2上類似方式產生保全信號,供在 DSP 104上執行之安全軟體層用。在此實施例中,可將匯 流排版本之保全信號納入流量控制匯流排110中,俾使處 理器102或DSP 104啟動之各項處置得以存取安全資源, 諸如在依各SSM產生之保全信號之特定共享周邊116。 復參閱圖1,在另一實施例中,保全信號可能延伸超出 -26- 本紙張尺度適用中國國家標準(CNS)A4規格(210 X 297公釐) 200424930 A7 B7 五、發明說明(25 5 ο 11I I I 200424930 A7 B7 24 V. INTRODUCTION OF THE INVENTION Xuan, Xing and data fast buffer storage area, write buffer and memory management sheet 7C. The safe execution mode is located on the platform, where the only trusted software is the exhaustion stored in ROM. In particular, 0S is unreliable and all essential applications are unreliable. The safe mode indicator is used to inform the user that the device is in safe mode. 105 ο 1 1 2 Printed by the Consumer Cooperatives of the Intellectual Property Bureau of the Ministry of Economic Affairs Although the present invention has been described with reference to the illustrated embodiments, this description is not intended to be limiting thereby. Those skilled in the art can refer to this description to understand various other embodiments of the present invention. For example, the security mode patterns described here can be used to improve all types of processing, such as precision instruction set operations (RISC), complex instruction / operations (CISC), wide blocks, DSP, and so on. In another embodiment, the security environment may be extended to share security resources among several initiator resources such as DSPs. In this embodiment, the preservation status engine can monitor each indicator resource to enforce the above-mentioned preservation principle. In various embodiments, there may be different supplements of security hardware, including various peripherals such as watchdog timers, encryption / decryption hardware accelerators, random number generators (RNG), etc .; and various | / 〇 devices such as keyboards, [ CD, touch screen, etc. Referring again to FIG. 1, in another embodiment, the second SSM may be located in the DSP 104 ′ to generate a security signal in a similar manner to the processing 102 for the security software layer executing on the DSP 104. In this embodiment, the security signal of the bus version can be incorporated into the flow control bus 110, so that the processing initiated by the processor 102 or the DSP 104 can access the security resources, such as the security signal generated by each SSM Of specific shared perimeter 116. Referring again to FIG. 1, in another embodiment, the security signal may extend beyond -26- This paper size applies the Chinese National Standard (CNS) A4 specification (210 X 297 mm) 200424930 A7 B7 V. Description of the invention (25 5 ο 11

5 IX 經濟部智慧財產局員工消費合作钍印製 20 兆位草元100 ,使得第三等級之資源得以在安全方式下操 作。 Μ 啟動序列、環境設定序列及離開序列均可視各實施例之 需求而變。例如不同的指令管線長度及不同的快速緩衝儲存 區線長均需於啟動序列中變動。在另一實施例中,可將步驟 520中施行之管家工作納入啟動序列中。 在另一實施例中,進入安全模式之手段可與此處所述 SSM相異。只要一以任何手段獲得安全模式操作,即可存 取僅當處於安全模式時可得之安全模式指示器,用以指示用 戶系統係於安全模式下操作。 在另一實施例中,可提供GPI◦閂鎖以外之手段,俾啟 動安全模式指示器。例如可採用來自保全控制暫存器319 之位元。類似地,可採用來自安全裝置316a或316b之一 之位元。主要需求在於僅當在安全模式下可對手段進行存 取。 在另一實施例中,安全模式指示器可直接響應於安全信 號,使得安全模式指示器在處理器處於安全模式時全時啟 動。但在此一實施例中,用戶可察知指示器處於開啟模式, 因而欲略之,故此並非較佳實施例。 復參閱圖2,安全裝置316a可為輸入裝置,用以接收 來自用戶之機密資訊。如此一來,即可僅於系統在安全模下 操作時,致動此輸入裝置以接收機密資訊。圖2欲顯示安 全裝置係在晶片上。此並非對所有實施例均為必要之情況。 亦可為晶片外裝置如獨立指印辨識裝置。對外部裝置之存取 -27-5 IX Consumption cooperation with employees of the Intellectual Property Bureau of the Ministry of Economic Affairs printed 20 trillion yuan of 100 yuan, allowing third-level resources to operate in a secure manner. The M startup sequence, the environment setting sequence, and the leaving sequence may be changed according to the requirements of the embodiments. For example, different instruction pipeline lengths and different cache line lengths need to be changed during the startup sequence. In another embodiment, the housekeeping work performed in step 520 can be included in the startup sequence. In another embodiment, the means of entering the safe mode may be different from the SSM described herein. As long as the safe mode operation is obtained by any means, a safe mode indicator, which is available only when in the safe mode, can be used to indicate that the user system is operating in the safe mode. In another embodiment, a means other than GPI may be provided to activate the safe mode indicator. For example, bits from the security control register 319 can be used. Similarly, bits from one of the security devices 316a or 316b may be used. The main requirement is that the means can be accessed only in safe mode. In another embodiment, the safe mode indicator may be directly responsive to the safe signal such that the safe mode indicator is activated full time when the processor is in the safe mode. However, in this embodiment, the user can know that the indicator is in the on mode, and therefore wants to omit it, so this is not a preferred embodiment. Referring again to FIG. 2, the security device 316a may be an input device for receiving confidential information from the user. In this way, the input device can be activated to receive the confidential information only when the system is operating in the safe mode. Figure 2 shows the security device attached to the wafer. This is not necessary for all embodiments. It can also be an off-chip device such as an independent fingerprint identification device. Access to external devices -27-

200424930 A7 五、發明說明 26 5 10 15 20 在女全核式下可受限。典伽言,與安全外部裝置交換之資 料,除加密者外,無需為機密資料。當操作裝置時,用戶可 看到外部安全裝置。若賴置無法於安全模式外之狀況下操 作,則對駭客而言,更不易欺瞒用戶。 復參閱® 2,可選擇性地提供竄改檢測裝置38〇。來自 竄改檢測裝置380之輸出380.1提供指示在包含CRJ 2〇〇 之封套上之存取封蓋已被竄改。接著以SSM 3GQ監視信號 _·1 ’俾當檢測到竄改時,將不進入安全模式。類钱’ 右在發生竄改時處於安全模式下,則SSM 檢測此經過 信號38Q_1,並離開安全模式指示違反,如前述。竄改檢測 裝置亦可為外部晶片外裝置。可以SSM監視纽檢測裝置 之輸出或登人安全GPI0。由於Gp|〇之存取受限於安全模 式’使㈣客無法清除之。以此方式為之,安全軟體將於下 次進入安全模式時看到。 因而將隨附之申請專利範圍視為涵蓋在本發明之真實範 _與精神下之實施例之任何此類改良。圖式簡單說明 以上參閱隨附圖式,僅藉由實例描述依本發明之特殊實 施例,其中所用類似代號係表類似部分,且除非另有描述, 其中圖式均與圖1之數位系統有關,其中·· 圖1係在具有多重處理器核心之兆位單元中之包含本發 明之一實施例之數位系統之方塊圖; 圖2係在圖1之系統方塊之方塊圖,其闡釋以 選擇硬體方塊併同由安全狀態引擎(SSM)強化之受保護 i tt -28- 本紙張尺度適用中國國家標準(CNS)A4規格(2丨〇 χ 297公爱 200424930200424930 A7 V. Description of invention 26 5 10 15 20 May be restricted in women's full-core model. The code exchanged with security external devices does not need to be confidential except for the encryptor. When operating the device, the user can see the external safety device. If Lai Zhi is unable to operate outside the safe mode, it is more difficult for hackers to deceive users. Refer to ® 2 for optional tamper detection device 38. Output 380.1 from the tamper detection device 380 provides an indication that the access cover on the sleeve containing CRJ 2000 has been tampered with. Then use SSM 3GQ monitoring signal _ · 1 ′ 俾 When tampering is detected, it will not enter safe mode. The money-like right is in safe mode when tampering occurs, then the SSM detects this passing signal 38Q_1 and leaves the safe mode to indicate violation, as mentioned above. The tamper detection device may also be an external off-chip device. The output of the button detection device can be monitored by SSM or the safety GPI0 can be registered. Since Gp | 〇's access is restricted by the security mode, the client cannot clear it. In this way, the security software will see the next time it enters safe mode. The scope of the accompanying patent application is therefore to be regarded as any such improvement of the embodiments encompassed within the true spirit and spirit of the invention. Brief Description of the Drawings With reference to the accompanying drawings, the special embodiments according to the present invention are described by way of example only. Similar codes used are similar parts of the table, and unless otherwise described, the drawings are related to the digital system of Figure 1. Among them, FIG. 1 is a block diagram of a digital system including an embodiment of the present invention in a megabit unit with multiple processor cores; FIG. 2 is a block diagram of the system block of FIG. 1, which is explained by selecting The hardware block is also protected by the Security State Engine (SSM). Tt -28- This paper size is applicable to the Chinese National Standard (CNS) A4 specification (2 丨 〇χ 297 公 爱 200424930)

55

ο 1X 軟體執行環境之組合之分散安全; 圖3係闡視圖2之ROM内容以及將該R〇M分隔為公用部 與安全部之電路之方塊圖; 圖4係閣釋進入圖2之系統之安全模式之操作之流程圖; 圖5係闡釋在圖2之系統中之安全狀態引擎之操作狀態 圖;及 圖6闡釋包含本發明之一實施例之無線個人數位助理。 除另作指陳者外,不同圖表中對應之數字與符號係指對 應部分。 10144h 經濟部智慧財產局員工消費合作钍印製 8 2 4 0 3 5 8333 1222410101010112030343850 U1* HI T— 1. 圖式之代號說明 個人數位助理 12a, 12b 整合輸入感測器 顯示器 14a 影像視窗 共用文字文件視 窗 14c 三維遊戲視窗 天線 20 接頭 耳機 23 無線鏈結 麥克風 30 安全模式指示器燈 兆位單元 102 微處理器 核心 104 數位信號處理器 (DSP) 數位信號處理器 106 直接記憶體存取控 核心 制器 硬體加速器 110 流量控制方塊 記憶體方塊 116 共享週邊 主處理器 120b 主介面 流量控制器 132 晶片外記憶體 晶片上記憶體 136 時框緩衝器 顯示裝置 140,142 私人週邊 保全狀態引擎 (SSM) 152 保全信號 -29- 本紙張尺度適用中國國家標準(CNS)A4規格(210x297公釐) 200424930 A7 B7 五、發明說明(28 ) 經濟部智慧財產局員工消費合作钍印製 154 通用輸入/輸出 (GPIO)閂鎖 位元 155 保全指示器LED 156 週邊匯流排信號 200 中央處理單元 (CPU)/處理器子系 統 204 資料快速緩衝儲 .存器 206 指令快速緩衝儲存 器 210 記憶體管理單元 300 保全狀態引擎 (MMU) (SSM) 302 保全信號 304 違反信號 306 重置電路系統 310 安全唯讀記憶體 (ROM) 311 公用唯讀記憶體 (ROM) 312 安全靜態隨機存取 記憶體(SRAM) 316a,316b 安全週邊裝置 318 通用輸入/輸出 (GPIO)閂鎖 319 保全控制暫存器 /安全模式指示 器 熔絲電路 321〜327 進入條件信號 328 330 指令匯流排 330a 指令位址匯流排 330b 指令匯流排 324 致動信號 326 裝置型信號 327 開機信號 331 指令介面信號 332 資料匯流排 333 資料介面信號 342 掃描閘 350 嵌入追蹤巨集單元 360 中斷操作器 362,363 中斷信號 364 整體遮蔽位元 370 解碼電路 370a 位址解碼器電路 380 竄改檢測裝置 380.1 信號 400 驅動器電路 404 閘電路 406 公用唯讀記憶體 (ROM)編碼信號 407 安全唯讀記憶體 (ROM)解碼信號 410 進入點 -30- 本紙張尺度適用中國國家標準(CNS)A4規格(210 x297公釐) 200424930 A7 五、發明說明(29) 413 416 420 閒置狀態 安全模式狀態 (一)、本案指定代表圖:第4圖 保全信號啟動序 列 安全媽 安全轉譯表 (STT) 500,502,504,步驟 510,512,514, 516,520,522, 524,526,528, 528.1,528.2, 528.3,528.4, 530,540 600 620 414 安全模式環境設定 序列 418 安全唯讀記憶體 (ROM)離開序列 430 安全中斷向量表 (SIVT) 542,601 a,旅線 621,622 601〜605狀態 630 違反狀態 代表圖之元件代表符號簡箪說明:ο The decentralized security of the 1X software execution environment combination; Figure 3 is a block diagram illustrating the ROM contents of View 2 and the circuit that separates the ROM into the Ministry of Public Security and the Ministry of Security; Figure 4 illustrates the system entering Figure 2 Flow chart of the operation of the security mode; FIG. 5 is an operation state diagram illustrating the security state engine in the system of FIG. 2; and FIG. 6 illustrates a wireless personal digital assistant including an embodiment of the present invention. Unless otherwise indicated, the corresponding numbers and symbols in different diagrams refer to the corresponding parts. 10144h Consumption cooperation by employees of the Intellectual Property Bureau of the Ministry of Economic Affairs 8 2 4 0 3 5 8333 1222410101010112030343850 U1 * HI T— 1. Schematic code description Personal digital assistant 12a, 12b Integrated input sensor display 14a Image window shared text file Windows 14c 3D gaming window antenna 20 connector headset 23 wireless link microphone 30 safety mode indicator light megabit unit 102 microprocessor core 104 digital signal processor (DSP) digital signal processor 106 direct memory access control core controller Hardware accelerator 110 Flow control block Memory block 116 Shared peripheral main processor 120b Main interface flow controller 132 Off-chip memory On-chip memory 136 Frame buffer display device 140, 142 Private peripheral security status engine (SSM) 152 Security signal -29- This paper size is in accordance with Chinese National Standard (CNS) A4 (210x297 mm) 200424930 A7 B7 V. Description of Invention (28) Consumer Co-operation of Intellectual Property Bureau of the Ministry of Economic Affairs 钍 Printed 154 Universal Input / Output (GPIO) latch Lock bit 155 security indicator around LED 156 Bus signal 200 Central Processing Unit (CPU) / Processor Subsystem 204 Data cache. Memory 206 Instruction cache memory 210 Memory management unit 300 Security state engine (MMU) (SSM) 302 Security signal 304 Violation signal 306 Reset circuit system 310 Secure read-only memory (ROM) 311 Public read-only memory (ROM) 312 Secure static random access memory (SRAM) 316a, 316b Safety peripherals 318 General-purpose input / output (GPIO) latch 319 Security control register / safe mode indicator fuse circuit 321 ~ 327 Entry condition signal 328 330 Command bus 330a Command address bus 330b Command bus 324 Actuation signal 326 Device type signal 327 Start-up signal 331 Command interface signal 332 data bus 333 data interface signal 342 scanning gate 350 embedded tracking macro unit 360 interrupt operator 362, 363 interrupt signal 364 overall mask bit 370 decoding circuit 370a address decoder circuit 380 tamper detection device 380.1 signal 400 driver circuit 404 gate circuit 406 public read-only memory (ROM) encoding signal 407 Security read-only memory (ROM) decoded signal 410 Entry point -30- This paper size applies Chinese National Standard (CNS) A4 (210 x 297 mm) 200424930 A7 V. Description of the invention (29) 413 416 420 Idle state security mode State (I), the designated representative of this case: Figure 4: The sequence of the security signal activation sequence Safety Translator Table (STT) 500,502,504, steps 510,512,514, 516,520,522, 524,526,528, 528.1,528.2, 528.3,528.4, 530,540 600 620 414 Safety mode environment settings Sequence 418 Safety read-only memory (ROM) leaving sequence 430 Safety interrupt vector table (SIVT) 542,601 a, trip line 621,622 601 ~ 605 status 630 Violation of the state representative diagram of the component representative symbol Brief description:

經濟部智慧財產局員工消費合作社印製 本紙張尺度適用中國國家標準(CNS)A4規格(2l〇x297公釐)Printed by the Consumer Cooperatives of the Intellectual Property Bureau of the Ministry of Economic Affairs This paper is sized for China National Standard (CNS) A4 (210x297 mm)

Claims (1)

200424930 申請專利範圍 1. 一種操作一數位系統之方法,包括步驟: 提供僅可執行信賴程式碼之安全模式操作;及 ^提供一該數位系統之用彳可見之安全模式指示器手 &,其中僅可於該安全模式操作下以該_程式碼啟動該指 示器手段。 2.如申請專利範圍第1之方法,進一步包括步驟: .執行一應用程式; 進入該安全模式操作以執行該應用程式之安全部分; 10 15 20 響應於該應用程式之該安全部分,啟動該安全模式指 示器手段;及 •在啟動該^曰示裔手段之同時,要求一用戶提供機密資 訊予該應用程式之該安全部分。 、 =如申%專利範圍第2項之方法,進一步包括在接收 該機密資訊後,在該應用程式之該安全部分持續於安全模式 下執行時,關閉該安全模式指示器手段之步驟。 今如申請專利範圍第2項或第3項之方法,其中啟動該 安全模式指示H手段之步驟包括執行—寫人_記憶體映對閃 鎖之^令’其中僅當在該安全模式操作下執行該指令時,可 寫入該記憶體映對閂鎖。 5.如申請專利範圍第彳項至第4項中任一項之方法,其 中提供一安全模式操作之步驟進一步包括步驟: 跳至位於一指令記憶體中之特定位址處之進入位址; 自該進入位址開始執行一啟動序列指令;及 僅當由中央處理單元(CPU)於一預定順序充分執行 32 - 本紙張尺度適用巾國國家標準(CNS)A4規格(7^ 297公爱) 200424930 AS B8 C8 六、申請專利範ΐ ~ ----- 之該啟動序列指令處時,進入該安全模式操作。 6·如申請專利範圍第j項至第5項_任一項之方法,進 -步包括提供竄改檢測手段之步驟,以檢測該數位系統是否 遭竄改;及 5 其中’若該纽檢測手段指示該數位系統已遭竄改, 則禁止提供一安全模式操作之步驟。 7. —種數位系統,包括: 一用以執行指令之中央處理單元(CPU); 一連結至一該CPU之指令匯流排之用以保存非安全指 々之公用5己憶體,該cpu隨時可進入該公用記惊體· 一連結至該CPU之該指令匯流排之用以保存安全指令 之安全記憶體,僅當宣告一保全信號時,始可存取該安全記 憶體; 保全電路,其具有一輸出,俾於建立一安全模式操作 15 時,用以宣告該保全信號;及 一響應於該保全信號之安全模式指示器,一該數位系 統之用戶可看到該安全模式指示器,其中僅可在宣告該保全 經濟部智慧財產局員工消費合作钍印製 k號時,藉由執行一指令使該安全模式指示器處於一啟動模 式下。 、 2〇 8.如申請專利範圍第7項之數位系統,其中該安全模 式指示器包括: 、 一連結之記憶體映對閂鎖,以響應於一寫入指令而自 該CPU接收一資料位元信號,該記憶體映對閂鎖之操作受 控於該保全信號,使得僅當宣告該保全信號時,始寫入該記 -33 - 本紙張尺度適用中國國家標準(CNS)aT^格⑵0?(297公») '— - 200424930 六、申請專利範圍 憶體映對㈣,該記㈣映對_具有-輸出健,以指示 該閂鎖之狀態;及 -安全模式指示器裝置,其連結至該記,映對問鎖 之該輸出信號,該安全模式指示器裝置係響應於該問鎖之狀 5態’,其中該安全模式指示器裝置係、-燈,或-可指示開啟狀 態或關閉裝置之機械裝置’或—可指示開啟狀態棚閉裝置 之聲音裝置。 9·如申請專利範圍第7項或第8項之數位系統 ,進一步 包括用以檢測之纽手段,其可操作以指示是否錄位系統 1〇已遭纽,其巾聰全電路監視顧以檢喊改之手段,並 可操作以避免響應於刻以檢測纽之手段而建立一安全操 作模式。 10·如申請專利範圍第7-9項中任一項之數位系統係一 無線裝置,進一步包括·· 15 一經一鍵盤轉接器連結至該CPU之整合鍵盤; 一經一顯示器轉接器連結至該CPU之顯示器; 經濟部智慧財產局員工消費合作杜印製 連結至該CPU之射頻(rf)電路系統;及 一連結至該RF電路系統之天線;及 其中该安全模式指示器包括一與該顯示器安排在視距 範圍内之發光二極體(LED)。 -34 - 本纸張尺度適財國國家標準(CNS)A4規格(χ撕公200424930 Patent Application Scope 1. A method for operating a digital system, comprising the steps of: providing a safe mode operation that can only execute trusted code; and ^ providing a visible safe mode indicator hand & for the digital system, where The indicator means can only be activated with the _ code in the safe mode operation. 2. The method according to the first patent application scope, further comprising the steps of: executing an application program; entering the safe mode operation to execute a secure portion of the application program; 10 15 20 in response to the secure portion of the application program, activating the Means of safe mode indicator; and • while activating the means of displaying the information, a user is required to provide confidential information to the secure part of the application. , = The method of item 2 of the patent scope, further comprising the step of turning off the safe mode indicator means after receiving the confidential information and when the safe part of the application is continuously executed in the safe mode. If the method of the second or third item of the patent scope is applied, the step of activating the safe mode indication H means includes the execution of the “write_memory mapping to flash lock order” where only when operating in the safe mode When this instruction is executed, the memory map latch can be written. 5. The method as claimed in any one of items 彳 to 4 of the scope of patent application, wherein the step of providing a safe mode operation further comprises the steps of: jumping to an entry address located at a specific address in an instruction memory; A start-up sequence instruction is executed from the entry address; and only when fully executed by the central processing unit (CPU) in a predetermined sequence 32-This paper size is applicable to National Standard (CNS) A4 (7 ^ 297 public love) 200424930 AS B8 C8 VI. When applying for the start-up sequence instruction of the patent application range ~ -----, enter the safe mode operation. 6. If the method of any of the items j to 5_ in the scope of the patent application, further comprising the step of providing tamper detection means to detect whether the digital system has been tampered with; and 5 of which, if the new detection means indicates The digital system has been tampered with, and it is forbidden to provide a step of safe mode operation. 7. — A digital system, including: a central processing unit (CPU) for executing instructions; a public 5th memory for storing non-secure instructions connected to an instruction bus of the CPU, the CPU at any time Access to the public memory body · A secure memory for storing safety instructions connected to the instruction bus of the CPU, the safety memory can only be accessed when a security signal is announced; the security circuit, which Has an output for declaring the security signal when a security mode operation is established 15; and a security mode indicator in response to the security signal, a user of the digital system can see the security mode indicator, where The safe mode indicator can only be placed in a start-up mode by executing an instruction when announcing the consumer cooperation of the employee of the Intellectual Property Bureau of the Ministry of Economic Affairs to print the k number. 2. The digital system according to item 7 of the patent application scope, wherein the safe mode indicator includes: A linked memory mapping latch to receive a data bit from the CPU in response to a write instruction Meta signal, the operation of the memory mapping latch is controlled by the security signal, so that only when the security signal is announced, the record -33-This paper size applies the Chinese National Standard (CNS) aT ^ 格 ⑵0 ? (297 公 ») '—-200424930 VI. Patent application scope Memory map pair, which has a-output key to indicate the status of the latch; and-safe mode indicator device, its connection To the record, the output signal of the interlock is reflected, and the safe mode indicator device is in response to the state of the interlock 5 ', wherein the safe mode indicator device is -light, or -can indicate the open state or The mechanical device of the closing device 'or-a sound device which can indicate the opening state of the shed closing device. 9. If the digital system of the 7th or 8th in the scope of patent application, further includes a button to detect, it is operable to indicate whether the recording system 10 has been buttoned, and its full circuit monitoring and inspection The method of calling for change is operable to avoid establishing a safe operation mode in response to the method of detecting the button. 10 · If the digital system of any one of claims 7-9 is a wireless device, further comprising: · 15 an integrated keyboard connected to the CPU via a keyboard adapter; and a display adapter connected to A display of the CPU; consumer cooperation of the Intellectual Property Bureau of the Ministry of Economic Affairs; printed radio frequency (rf) circuit system connected to the CPU; and an antenna connected to the RF circuit system; and the safe mode indicator includes a The display is a light emitting diode (LED) arranged in the line of sight. -34-This paper is suitable for National Standards (CNS) A4 specifications
TW092135673A 2002-12-18 2003-12-17 Method for operating digital system including graphics display and digital system thereof TWI313433B (en)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
US10/322,893 US8479022B2 (en) 2002-01-16 2002-12-18 Secure mode indicator for smart phone or PDA

Publications (2)

Publication Number Publication Date
TW200424930A true TW200424930A (en) 2004-11-16
TWI313433B TWI313433B (en) 2009-08-11

Family

ID=34272233

Family Applications (1)

Application Number Title Priority Date Filing Date
TW092135673A TWI313433B (en) 2002-12-18 2003-12-17 Method for operating digital system including graphics display and digital system thereof

Country Status (3)

Country Link
KR (1) KR20040054493A (en)
CN (1) CN100363854C (en)
TW (1) TWI313433B (en)

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100420323C (en) * 2005-03-11 2008-09-17 佛山市顺德区顺达电脑厂有限公司 Method for protecting private files in smart mobile phones
GB0615015D0 (en) * 2006-07-28 2006-09-06 Hewlett Packard Development Co Secure use of user secrets on a computing platform
US8793786B2 (en) * 2008-02-08 2014-07-29 Microsoft Corporation User indicator signifying a secure mode
US9805196B2 (en) 2009-02-27 2017-10-31 Microsoft Technology Licensing, Llc Trusted entity based anti-cheating mechanism
US9705964B2 (en) 2012-05-31 2017-07-11 Intel Corporation Rendering multiple remote graphics applications
CN104272285B (en) * 2012-05-31 2017-06-20 英特尔公司 Method and apparatus for rendering graphics applications
CN104463028B (en) * 2013-09-25 2018-06-22 中国银联股份有限公司 Safe mode reminding method and the mobile equipment for realizing this method
CN107608700A (en) * 2017-10-16 2018-01-19 浪潮(北京)电子信息产业有限公司 A kind of update method, device and the medium of FPGA firmwares

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5388156A (en) * 1992-02-26 1995-02-07 International Business Machines Corp. Personal computer system with security features and method
US5596718A (en) * 1992-07-10 1997-01-21 Secure Computing Corporation Secure computer network using trusted path subsystem which encrypts/decrypts and communicates with user through local workstation user I/O devices without utilizing workstation processor
US6938163B1 (en) * 1999-06-17 2005-08-30 Telefonaktiebolaget Lm Ericsson (Publ) Technique for securely storing data within a memory

Also Published As

Publication number Publication date
CN100363854C (en) 2008-01-23
TWI313433B (en) 2009-08-11
CN1510540A (en) 2004-07-07
KR20040054493A (en) 2004-06-25

Similar Documents

Publication Publication Date Title
US8479022B2 (en) Secure mode indicator for smart phone or PDA
US12086293B2 (en) Method and system for preventing unauthorized processor mode switches
US7890753B2 (en) Secure mode for processors supporting MMU and interrupts
Costan et al. Intel SGX explained
US7073059B2 (en) Secure machine platform that interfaces to operating systems and customized control programs
CN101533446B (en) Microprocessor providing a secure execution environment and method for executing secure coding
US8843769B2 (en) Microcontroller with embedded secure feature
US20070226795A1 (en) Virtual cores and hardware-supported hypervisor integrated circuits, systems, methods and processes of manufacture
Costan et al. Secure processors part I: background, taxonomy for secure enclaves and Intel SGX architecture
TW200412105A (en) Virtual to physical memory address mapping within a system having a secure domain and a non-secure domain
TWI313433B (en) Method for operating digital system including graphics display and digital system thereof
Tiemann et al. IOTLB-SC: An accelerator-independent leakage source in modern cloud systems
JP2010134572A (en) Device and method for achieving security
Quisquater Enhancing security in the memory management unit
JP2013114367A (en) File communication method and external device

Legal Events

Date Code Title Description
MM4A Annulment or lapse of patent due to non-payment of fees