IP Library Granted Patent US 8,117,642
Granted Patent B2
US 8,117,642 · App. 12/053,502 · Granted Feb 14, 2012

Computing device with entry authentication into trusted execution environment and method therefor

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,117,642
App. No.
12/053,502
Granted
Feb 14, 2012
Kind
B2
Abstract

A computing device ( 10 ) includes a trusted execution environment (TEE) manager ( 40 ) that manages a switchover from non-trusted software ( 116 ) to trusted software ( 118 ). The TEE manager ( 40 ) includes memory ( 90 ) configured to store password-bearing, immediate-operand instructions ( 54 ). At the point of switching between the non-trusted software ( 116 ) and the trusted software ( 118 ) the memory ( 90 ) may be accessed as instruction fetches, and its contents fetched into a CPU core ( 24 ) as instructions. Immediate-operand portions ( 60 ) of the immediate-operand instructions ( 54 ) provide passwords, which are written back into guess registers ( 80 ) within the TEE manager ( 40 ). When a predetermined relationship between the instructions ( 54 ) and guesses in guess registers ( 80 ) is identified, actual execution of the immediate-operand instructions ( 54 ) is verified, the TEE mode of operation is signaled, and security-sensitive hardware ( 44 ) is enabled for use by a privileged routine ( 42 ) portion of the trusted software ( 118 ).

Claims (47)

1. A computing device which selectively operates in a non-privileged mode and a privileged mode, said computing device comprising:

a trusted data section configured to store an authentication routine which includes a plurality of immediate-operand instructions wherein each of said plurality of immediate operand instructions has an operand configured to convey a portion of a password;

a first control section configured to grant read access to said immediate-operand instruction in response to an instruction fetch addressed to said trusted data section;

a non-trusted data section configured to store a password guess; and

a second control section, configured as a physical circuit, coupled to said trusted and non-trusted data sections and configured to identify when a predetermined relationship exists between all of said plurality of immediate-operand instructions and said password guess and to signal said privileged mode of operation in response to identifying said predetermined relationship.

2. The computing device as claimed in claim 1 wherein write access is denied for said trusted data section while said computing device operates in said non-privileged mode.

3. The computing device as claimed in claim 1 wherein:

said trusted data section is configured so that said operands of said plurality of immediate-operand instructions are altered from time to time.

4. The computing device as claimed in claim 3 wherein said operands of said plurality of immediate-operand instructions are altered at least as often as said computing device operates in said privileged mode.

5. The computing device as claimed in claim 3 wherein:

said first control section includes a random number generator; and

said is operands of said plurality of immediate-operand instructions are altered in response to data generated by said random number generator.

6. The computing device as claimed in claim 1 wherein said plurality of immediate-operand instructions are prevented from being overwritten when said computing device operates in said non-privileged mode.

7. The computing device as claimed in claim 1 wherein said first control section is configured to deny read access to said plurality of immediate-operand instructions in response to a data fetch.

8. A computing device which selectively operates in a non-privileged mode and a privileged mode, said computing device comprising:

a processor;

a trusted execution environment manager having:

a first trusted data section configured to store an authentication routine which is executable by said processor and includes an immediate-operand instruction;

a first control section configured to grant read access to said immediate-operand instruction in response to an instruction fetch access addressed to said first trusted data section;

a non-trusted data section configured to store a password guess; and

a second control section coupled to said first trusted data section and to said non-trusted data section and configured to identify when a predetermined relationship exists between said immediate-operand instruction and said password guess and to signal said privileged mode of operation in response to identifying said predetermined relationship;

selectively enabled hardware coupled to said trusted execution environment manager, said selectively enabled hardware being enabled when said privileged mode is signaled and being disabled when said non-privileged mode is signaled; and

a second trusted data section configured to store a privileged routine which is executable by said processor, wherein said authentication routine exits to said privileged routine, said privileged routine is configured to access said selectively enabled hardware, and said privileged routine is configured to instruct said trusted execution environment manager to signal said non-privileged mode of operation prior to exiting.

9. A method of authenticating entry into a trusted environment of a computing device which has a processor and a hardware trusted execution environment manager and which selectively operates in a non-privileged mode and a privileged mode, said method comprising:

storing an authentication routine in a first trusted data section of said hardware trusted execution environment manager, said authentication routine being executable by said processor, said authentication routine including an immediate-operand instruction, and said authentication routine being configured to exit to a privileged routine;

granting, in a first control section of said hardware trusted execution environment manager, read access to said immediate-operand instruction in response to an instruction fetch access addressed by said processor to said first trusted data section;

storing a password guess in a non-trusted data section of said hardware trusted execution environment manager;

identifying, in a second control section of said hardware trusted execution environment manager, when a predetermined relationship exists between said immediate-operand instruction and said password guess;

signaling said privileged mode of operation in response to said identifying step;

enabling selectively enabled hardware coupled to said trusted execution environment manager when said privileged mode is signaled in response to said identifying step;

disabling said selectively enabled hardware when said non-privileged mode is signaled in response to said identifying step; and

storing said privileged routine in a second trusted data section, said privileged routine being executable by said processor, said privileged routine being configured to access said selectively enabled hardware, and said privileged routine being configured to instruct said trusted execution environment manager to signal said non-privileged mode of operation prior to exiting.

10. The method claimed in claim 9 wherein said computing device is formed using one or more semiconductor devices which have pins through which signals are routed into and out from said semiconductor devices and said method additionally comprises:

refraining from transferring said immediate-operand instruction through one or more of said pins of a semiconductor device of said one or more semiconductor devices.

11. The method claimed in claim 9 wherein said authentication routine includes an instruction which is executed by said processor to implement said step of storing said password guess in said non-trusted data section.

12. The method claimed in claim 11 wherein:

said authentication routine includes a plurality of immediate-operand instructions wherein each of said plurality of immediate operand instructions has an operand configured to convey a portion of a password;

said step of storing said password guess in said non-trusted data section is implemented by said processor executing all of said plurality of immediate operand instructions.

13. The method claimed in claim 9 wherein:

said immediate-operand instruction includes an operation code portion and an operand portion; and

said method additionally comprises altering said operand portion of said immediate-operand instruction from time to time.

14. The method claimed in claim 13 wherein said operand portion of said immediate-operand instruction is altered at least as often as said privileged routine is executed.

15. The method claimed in claim 13 wherein said operand portion of said immediate-operand instruction is altered in response to data provided by a random number generator.

16. The method claimed in claim 9 wherein:

said immediate-operand instruction includes an operation code portion and an operand portion; and

said privileged routine is configured to alter said operand portion of said immediate-operand instruction.

17. The method claimed in claim 9 wherein: said processor is prevented from overwriting said immediate-operand instruction when said selectively enabled hardware is disabled.

Assignments (26)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040925 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Feb 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V. F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 052917/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040928 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Jan 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 052915/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 037486 FRAME 0517. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Dec 10, 2019
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 053547/0421 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042985 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0387 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051030/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042762 FRAME 0145. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051145/0184 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050745/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050744/0097 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT THE APPLICATION NO. FROM 13,883,290 TO 13,833,290 PREVIOUSLY RECORDED ON REEL 041703 FRAME 0536. ASSIGNOR(S) HEREBY CONFIRMS THE THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS.. Recorded Feb 20, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SHENZHEN XINGUODU TECHNOLOGY CO., LTD.
Reel/Frame 048734/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 040632 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER AND CHANGE OF NAME. Recorded Sep 21, 2017
From: FREESCALE SEMICONDUCTOR INC.
To: NXP USA, INC.
Reel/Frame 044209/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042762/0145 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042985/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENTS 8108266 AND 8062324 AND REPLACE THEM WITH 6108266 AND 8060324 PREVIOUSLY RECORDED ON REEL 037518 FRAME 0292. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Feb 1, 2017
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 041703/0536 →
CHANGE OF NAME Recorded Nov 8, 2016
From: FREESCALE SEMICONDUCTOR, INC.
To: NXP USA, INC.
Reel/Frame 040632/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 040928/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 21, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V., F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 040925/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12092129 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Jul 14, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039361/0212 →
SUPPLEMENT TO THE SECURITY AGREEMENT Recorded Jun 16, 2016
From: FREESCALE SEMICONDUCTOR, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039138/0001 →
SECURITY AGREEMENT SUPPLEMENT Recorded Mar 7, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 038017/0058 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 13, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037518/0292 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 12, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037486/0517 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037354/0688 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037356/0553 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037356/0143 →
SECURITY AGREEMENT Recorded Nov 6, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 031591/0266 →