TDISP support in a FPGA-embedded device
Embodiments herein describe a circuit including a user domain configured to execute user functions and a hardened domain configured to communicate with the user domain. The hardened domain includes peripheral component interconnect express (PCIe) function decoding logic having a plurality of register bits and a Trusted Execution Environment (TEE) Device Interface Security Protocol (TDISP) core communicating with the PCIe function decoding logic. The TDISP core supports a plurality of PCIe functions. Each register bit of the plurality of register bits is assigned to a respective PCIe function of the plurality of PCIe functions.
1 . A circuit comprising:
a user domain configured to execute user functions; and
a hardened domain configured to communicate with the user domain, the hardened domain including:
peripheral component interconnect express (PCIe) function decoding logic having a plurality of register bits, each register bit assigned to a respective PCIe function of a plurality of PCIe functions; and
a Trusted Execution Environment (TEE) Device Interface Security Protocol (TDISP) core communicating with the PCIe function decoding logic, wherein the TDISP core supports the plurality of PCIe functions.
2 . The circuit of claim 1 , wherein each register bit of the plurality of register bits is configured to indicate whether a corresponding PCIe function is enabled as a Trusted Device Interface (TDI) for secure communication under the TDISP.
3 . The circuit of claim 2 , wherein the TDISP core is configured to enable or disable TDISP support for each PCIe function based on the corresponding register bit in the PCIe function decoding logic.
4 . The circuit of claim 1 , wherein each register bit of the plurality of register bits is a TDI Valid bit indicating TDISP enablement.
5 . The circuit of claim 1 , wherein the TDISP core supports a number of TDIs up to a maximum number of PCIe functions.
6 . The circuit of claim 5 , wherein a one-to-one mapping is created between the number of TDIs and the number of PCIe functions without using mapping tables.
7 . The circuit of claim 1 , wherein the TDISP core includes a TDI state machine.
8 . The circuit of claim 7 , wherein the TDI state machine includes four states for each TDI or for each PCIe function.
9 . The circuit of claim 8 , wherein most state transition logic of the four states is implemented by firmware.
10 . The circuit of claim 8 , wherein error state transition logic of the four states is implemented by using hardware.
11 . The circuit of claim 1 , wherein the user domain is a field programmable gate array (FPGA)-embedded device and the hardened domain is a PCIe domain.
12 . The circuit of claim 1 , wherein the PCIe function decoding logic is Single-Root input/output (I/O) Virtualization (SR-IOV) logic.
13 . A method comprising:
executing user functions in a user domain; and
permitting a hardened domain to communicate with the user domain, the hardened domain including:
peripheral component interconnect express (PCIe) function decoding logic having a plurality of register bits, each register bit assigned to a respective PCIe function of a plurality of PCIe functions; and
a Trusted Execution Environment (TEE) Device Interface Security Protocol (TDISP) core communicating with the PCIe function decoding logic, wherein the TDISP core supports the plurality of PCIe functions.
14 . The method of claim 13 , wherein each register bit of the plurality of register bits is configured to indicate whether a corresponding PCIe function is enabled as a Trusted Device Interface (TDI) for secure communication under the TDISP.
15 . The method of claim 14 , wherein the TDISP core is configured to enable or disable TDISP support for each PCIe function based on the corresponding register bit in the PCIe function decoding logic.
16 . The method of claim 13 , wherein the TDISP core supports a number of TDIs up to a maximum number of PCIe functions and wherein a one-to-one mapping is created between the number of TDIs and the number of PCIe functions without using mapping tables.
17 . The method of claim 13 , wherein the TDISP core includes a TDI state machine, the TDI state machine including four states for each TDI or for each PCIe function and wherein most state transition logic of the four states is implemented by firmware.
18 . The method of claim 13 , wherein the user domain is a field programmable gate array (FPGA)-embedded device and the hardened domain is a PCIe domain.
19 . The circuit of claim 1 , wherein the TDISP core is configured to maintain, for each PCIe function, a TDI state comprising a plurality of states stored in hardened-domain hardware, while transition logic for the TDI state is executed by firmware to reduce hardware area.
20 . The method of claim 13 , wherein the TDISP core is configured to maintain, for each PCIe function, a TDI state comprising a plurality of states stored in hardened-domain hardware, while transition logic for the TDI state is executed by firmware to reduce hardware area.