IP Library Granted Patent US 9,984,193
Granted Patent B1
US 9,984,193 · App. 14/589,751 · Granted May 29, 2018

System to combat design-time vulnerability

Inventors: Serge Leef (Portland, OR); Ahmed Badran (Canby, OR); Sudhir Kadkade (Lake Oswego, OR)
Assignee: Mentor Graphics Corporation
G06F17/5081G06F17/5077
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,984,193
App. No.
14/589,751
Granted
May 29, 2018
Kind
B1
Abstract

This application discloses a computing system implementing tools and mechanisms that can incorporate a security co-processor into a circuit design modeling an electronic device. The tools and mechanisms can configure the security co-processor to monitor at least a portion of the electronic device. The tools and mechanisms can generate at least one security action for the security co-processor to initiate when the security co-processor monitors the electronic device failing to conform to rules in a rules database.

Claims (43)

1. A method comprising:

incorporating, by a computing system, a security co-processor into a circuit design modeling an electronic device;

configuring, by the computing system, the security co-processor to monitor messages on an interconnect transmitted by an electronic component in the electronic device; and

loading, by the computing system, one or more rules defining permissibility of the monitored messages on the interconnect in the electronic device, wherein the security co-processor is configured to utilize the rules to identify the monitored messages on the interconnect correspond to an unauthorized operation performed by the electronic component in the electronic device.

2. The method of claim 1 , further comprising defining, by the computing system, at least one security action for the security co-processor to initiate when the security co-processor monitors the electronic device failing to conform to the rules.

3. The method of claim 1 , wherein incorporating the security co-processor into the circuit design includes coupling the security co-processor to the interconnect in the electronic device, and wherein configuring the security co-processor further comprises configuring the security co-processor to monitor activity on the interconnect in the electronic device.

4. The method of claim 3 , further comprising configuring, by the computing system, the security co-processor to determine whether the monitored activity on the interconnect corresponds to the unauthorized operation by the electronic component in the electronic device based on the rules.

5. The method of claim 1 , further comprising configuring, by the computing system, the security co-processor to present interrogation messages on the interconnect of the electronic device, wherein configuring the security co-processor further comprises configuring the security co-processor to monitor the interconnect for responses to the interrogation messages.

6. The method of claim 5 , further comprising configuring, by the computing system, the security co-processor to determine whether the responses to the interrogation messages or lack thereof conform to the rules.

7. The method of claim 1 , further comprising:

configuring, by the computing system, the security co-processor with a location of a rules database; and

configuring, by the computing system, the security co-processor to retrieve the rules from the location associated with the rules database.

8. A system comprising:

a memory system configured to store computer-executable instructions; and

a computing system, in response to execution of the computer-executable instructions, is configured to:

incorporate a security co-processor into a circuit design modeling an electronic device;

configure the security co-processor to monitor messages on an interconnect transmitted by an electronic component in the electronic device; and

load one or more rules defining permissibility of the monitored messages on the interconnect in the electronic device, wherein the security co-processor is configured to utilize the rules to identify the monitored messages on the interconnect correspond to an unauthorized operation performed by the electronic component in the electronic device.

9. The system of claim 8 , wherein the computing system, in response to execution of the computer-executable instructions, is further configured to define at least one security action for the security co-processor to initiate when the security co-processor monitors the electronic device failing to conform to the rules.

10. The system of claim 8 , wherein the computing system, in response to execution of the computer-executable instructions, is further configured to:

couple the security co-processor to the interconnect in the electronic device; and

configure the security co-processor to monitor activity on the interconnect in the electronic device.

11. The system of claim 10 , wherein the computing system, in response to execution of the computer-executable instructions, is further configured to configure the security co-processor to determine whether the monitored activity on the interconnect corresponds to the unauthorized operation by the electronic component in the electronic device based on the rules.

12. The system of claim 8 , wherein the computing system, in response to execution of the computer-executable instructions, is further configured to:

configure the security co-processor to present interrogation messages on the interconnect of the electronic device; and

configure the security co-processor to monitor the interconnect for responses to the interrogation messages.

13. The system of claim 12 , wherein the computing system, in response to execution of the computer-executable instructions, is further configured to configure the security co-processor to determine whether the responses to the interrogation messages or lack thereof conform to the rules.

14. An apparatus comprising at least one computer-readable memory device storing instructions configured to cause one or more processing devices to perform operations comprising:

incorporating a security co-processor into a circuit design modeling an electronic device;

configuring the security co-processor to monitor messages on an interconnect transmitted by an electronic component in the electronic device; and

loading one or more rules defining permissibility of the monitored messages on the interconnect in the electronic device, wherein the security co-processor is configured to utilize the rules to identify the monitored messages on the interconnect correspond to an unauthorized operation performed by the electronic component in the electronic device.

15. The apparatus of claim 14 , wherein the instructions are configured to cause one or more processing devices to perform operations further comprising defining at least one security action for the security co-processor to initiate when the security co-processor monitors the electronic device failing to conform to the rules.

16. The apparatus of claim 14 , wherein the instructions are configured to cause one or more processing devices to perform operations further comprising:

coupling the security co-processor to the interconnect in the electronic device; and

configuring the security co-processor to monitor activity on the interconnect in the electronic device.

17. The apparatus of claim 16 , wherein the instructions are configured to cause one or more processing devices to perform operations further comprising configuring the security co-processor to determine whether the monitored activity on the interconnect corresponds to the unauthorized operation by the electronic component in the electronic device based on the rules.

18. The apparatus of claim 14 , wherein the instructions are configured to cause one or more processing devices to perform operations further comprising:

configuring the security co-processor to present interrogation messages on the interconnect of the electronic device; and

configuring the security co-processor to monitor the interconnect for responses to the interrogation messages.

19. The apparatus of claim 18 , wherein the instructions are configured to cause one or more processing devices to perform operations further comprising configuring the security co-processor to determine whether the responses to the interrogation messages or lack thereof conform to the rules.

20. The apparatus of claim 14 , wherein the instructions are configured to cause one or more processing devices to perform operations further comprising:

configuring the security co-processor with a location of a rules database; and

configuring the security co-processor to retrieve the rules from the location associated with the rules database.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2021
From: LEEF, SERGE; KADKADE, SUDHIR; BADRAN, AHMED
To: MENTOR GRAPHICS CORPORATION
Reel/Frame 057759/0882 →
MERGER AND CHANGE OF NAME Recorded Oct 12, 2021
From: MENTOR GRAPHICS CORPORATION; SIEMENS INDUSTRY SOFTARE INC.
To: SIEMENS INDUSTRY SOFTWARE INC.
Reel/Frame 057759/0946 →
Continuity (1)
Continuation 14168912 · Jan 30, 2014