IP Library Granted Patent US 7,130,951
Granted Patent B1
US 7,130,951 · App. 10/419,091 · Granted Oct 31, 2006

Method for selectively disabling interrupts on a secure execution mode-capable processor

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,130,951
App. No.
10/419,091
Granted
Oct 31, 2006
Kind
B1
Abstract

A method of controlling a secure execution mode-capable processor includes allowing a plurality of interrupts to interrupt the secure execution mode-capable processor when the secure execution mode-capable processor is operating in a non-secure execution mode. The method also includes disabling the plurality of interrupts from interrupting the secure execution mode-capable processor when the secure execution mode-capable processor is operating in a secure execution mode.

Claims (38)

1. A method of controlling a secure execution mode-capable processor, said method comprising:

operating in a non-secure execution mode;

entering a secure execution mode by initializing, from the non-secure execution mode, and executing a trusted secure operating system code segment that has been verified external to said secure execution mode-capable processor;

allowing a plurality of interrupts to interrupt said secure execution mode-capable processor when said secure execution mode-capable processor is operating in a non-secure execution mode; and

disabling said plurality of interrupts, including software interrupts, from interrupting said secure execution mode-capable processor and ensuring that said plurality of interrupts cannot be re-enabled, except by said trusted secure operating system code segment when said secure execution mode-capable processor is operating in said secure execution mode.

2. The method as recited in claim 1 , wherein disabling said plurality of interrupts includes holding said plurality of interrupts in a pending state until said plurality of interrupts is re-enabled.

3. The method as recited in claim 1 further comprising disabling said plurality of interrupts from interrupting said secure execution mode-capable processor in response to a system context switch upon entry into said trusted secure operating system code segment.

4. The method as recited in claim 1 further comprising disabling said plurality of interrupts by executing a clear global interrupt flag instruction.

5. The method as recited in claim 4 further comprising disabling debug traps in response to execution of said clear global interrupt flag instruction.

6. The method as recited in claim 4 further comprising enabling said plurality of interrupts in response to executing a set global interrupt flag instruction.

7. The method as recited in claim 6 further comprising executing said set global interrupt flag instruction and said clear global flag instruction during execution of said trusted secure operating system code segment.

8. The method as recited in claim 6 further comprising executing said clear global flag instruction in response to execution of a security initialization instruction.

9. The method as recited in claim 6 further comprising generating an invalid opcode fault in response to executing said set global interrupt flag instruction when said secure execution mode-capable processor is operating in said non-secure execution mode.

10. The method as recited in claim 6 further comprising generating an invalid opcode fault in response to executing said clear global interrupt flag instruction when said secure execution mode-capable processor is operating in said non-secure execution mode.

11. A secure execution mode-capable processor comprising:

execution logic configured to execute program instructions in a non-secure execution mode;

wherein the execution logic is further configured to execute program instructions in a secure execution mode in response to a secure execution mode initialization sequence initiated from the non-secure execution mode, wherein said program instructions include a trusted secure operating system code segment that has been verified external to said secure execution mode-capable processor; and

interrupt control logic coupled to said execution logic and configured to allow a plurality of interrupts to interrupt said execution logic during operation in a non-secure execution mode;

wherein said interrupt control logic is further configured to disable said plurality of interrupts, including software interrupts, from interrupting said execution logic and to ensure that said plurality of interrupts cannot be re-enabled, except by said trusted secure operating system code segment, during operation in said secure execution mode.

12. The secure execution mode-capable processor as recited in claim 11 , wherein said interrupt control logic is further configured to hold said plurality of interrupts in a pending state until said plurality of interrupts is re-enabled.

13. The secure execution mode-capable processor as recited in claim 11 , wherein said interrupt control logic is further configured to disable said plurality of interrupts from interrupting said execution logic in response to a system context switch upon entry into said trusted secure operating system code segment.

14. The secure execution mode-capable processor as recited in claim 11 further comprising a global interrupt disable storage configured to disable said plurality of interrupts from interrupting said execution logic during operation in said secure execution mode.

15. The secure execution mode-capable processor as recited in claim 14 , wherein said global interrupt disable storage is a global interrupt flag.

16. The secure execution mode-capable processor as recited in claim 14 , wherein said plurality of interrupts includes non-maskable interrupts.

17. The secure execution mode-capable processor as recited in claim 11 further comprising an interrupt disable storage configured to disable a portion of said plurality of interrupts from interrupting said execution logic during operation in said non-secure execution mode.

18. The secure execution mode-capable processor as recited in claim 17 , wherein said portion of said plurality of interrupts includes maskable interrupts.

19. The secure execution mode-capable processor as recited in claim 11 , wherein said interrupt control logic is further configured to disable said plurality of interrupts in response to said execution logic executing a clear global interrupt flag instruction.

20. The secure execution mode-capable processor as recited in claim 19 , wherein said interrupt control logic is further configured disable debug traps in response to execution of said clear global interrupt flag instruction.

21. The secure execution mode-capable processor as recited in claim 19 , wherein said interrupt control logic is further configured re-enable said plurality of interrupts in response to said execution logic executing a set global interrupt flag instruction during operation in said secure execution mode.

22. The secure execution mode-capable processor as recited in claim 21 , wherein said execution logic is further configured to execute said set global interrupt flag instruction and said clear global flag instruction during execution of said trusted secure operating system code segment.

23. The secure execution mode-capable processor as recited in claim 21 , wherein said execution logic is further configured to execute said clear global flag instruction in response to executing a security initialization instruction.

24. The secure execution mode-capable processor as recited in claim 21 , wherein said execution logic is further configured to generate a fault in response to executing said clear global interrupt flag instruction during operation in said non-secure execution mode.

25. The secure execution mode-capable processor as recited in claim 21 , wherein said execution logic is further configured to generate a fault in response to executing said set global interrupt flag instruction during operation in said non-secure execution mode.

26. A secure execution mode-capable processor comprising:

execution logic configured to execute program instructions in a non-secure execution mode;

wherein the execution logic is further configured to execute program instructions in a secure execution mode in response to a secure execution mode initialization sequence initiated from the non-secure execution mode, wherein said program instructions include a trusted secure operating system code segment that has been verified external to said secure execution mode-capable processor;

means for allowing a plurality of interrupts to interrupt said secure execution mode-capable processor when said secure execution mode-capable processor is operating in a non-secure execution mode; and

means for disabling said plurality of interrupts, including software interrupts, from interrupting said secure execution mode-capable processor and to ensure that said plurality of interrupts cannot be re-enabled, except by said trusted secure operating system code segment, when said secure execution mode-capable processor is operating in said secure execution mode.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded May 12, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: GLOBALFOUNDRIES U.S. INC.
Reel/Frame 056987/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2021
From: GLOBALFOUNDRIES US INC.
To: MEDIATEK INC.
Reel/Frame 055173/0781 →
RELEASE OF SECURITY INTEREST Recorded Nov 20, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: GLOBALFOUNDRIES INC.
Reel/Frame 054636/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2020
From: GLOBALFOUNDRIES INC.
To: GLOBALFOUNDRIES U.S. INC.
Reel/Frame 054633/0001 →
SECURITY AGREEMENT Recorded Nov 29, 2018
From: GLOBALFOUNDRIES INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 049490/0001 →
AFFIRMATION OF PATENT ASSIGNMENT Recorded Aug 18, 2009
From: ADVANCED MICRO DEVICES, INC.
To: GLOBALFOUNDRIES INC.
Reel/Frame 023119/0083 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2003
From: MCGRATH, KEVIN J.
To: ADVANCED MICRO DEVICES, INC.
Reel/Frame 014346/0847 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2003
From: CHRISTIE, DAVID S.; STRONGIN, GEOFFREY S.; MCGRATH, KEVIN J.
To: ADVANCED MICRO DEVICES, INC.
Reel/Frame 013987/0617 →