IP Library › Granted Patent US 12,572,498
Granted Patent B2
US 12,572,498 · App. 18/553,056 · Granted Mar 10, 2026

Secure serial peripheral interface communication

Inventors: Eunchan Kim (San Jose, CA); Timothy Jay Chen (Pleasanton, CA)
Assignee: Google LLC
G06F13/4282G06F21/85G06F2213/0002
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,572,498
App. No.
18/553,056
Granted
Mar 10, 2026
Kind
B2
Abstract

This document discloses aspects of secure serial peripheral interface (SPI) communication. In some aspects, a secure SPI communication module monitors communications transmitted by a host to a peripheral block that is coupled to the host via a SPI interconnect. The module compares respective commands of the communications sent by the host to information indicating commands that the peripheral block is not authorized to execute. Based on the comparing, the module determines that one of the respective commands is one of the commands that the peripheral block is not authorized to execute. The module then prevents the peripheral block from receiving at least a portion of the respective command of the communication. By so doing, the module can prevent the peripheral block from executing unauthorized commands, which may compromise security of the peripheral block.

Claims (50)

1 . A method implemented by security circuitry associated with a host of a system for secure serial peripheral interface communication, the method comprising:

monitoring communications transmitted by the host to a peripheral block of the system that is coupled to the host via a serial peripheral interface (SPI) interconnect;

comparing respective commands of the communications sent by the host to information indicating which commands the peripheral block is not authorized to execute;

determining, based on the comparing, that one of the respective commands comprises a write-status-register command that the peripheral block is not authorized to execute; and

in response to determining that the peripheral block is not authorized to execute the write-status-register command, altering the write-status-register command to prevent the write-status-register command from altering a status register of the peripheral block.

2 . The method of claim 1 , wherein the respective command comprises a first command of a first communication, and the method further comprises: determining that the peripheral block is not authorized to execute a second command of a second communication sent by the host to the peripheral block; and preventing the peripheral block from receiving at least a portion of the second command that the peripheral block is not authorized to execute.

3 . The method of claim 2 , wherein the preventing comprises altering the state of the chip select line and the clock line of the SPI interconnect to prevent the peripheral block from receiving the at least a portion of the second command of the second communication sent by the host.

4 . The method of claim 3 , wherein:

the second command of the second communication comprises eight bits; and

the altering comprises deasserting the chip select line prior to or on an eighth clock cycle by which an eighth bit of the second command is communicated via the SPI interconnect to prevent at least the eighth bit of the second command from being processed by the peripheral block.

5 . The method of claim 3 , wherein:

the second command of the second communication comprises eight bits; and

the altering comprises gating the clock line prior to or on an eighth clock cycle by which an eighth bit of the second command is communicated via the SPI interconnect to prevent at least the eighth bit of the second command from being processed by the peripheral block.

6 . The method of claim 1 , wherein the altering of the write-status-register command comprises:

setting bit positions of the write-status-register command to predefined bit values to provide an altered write-status-register command; and

passing, to the peripheral block, the altered write-status-register command that comprises the predefined bit values and other bits of the write-status-register command.

7 . The method of claim 1 , wherein the information indicating which commands that the peripheral block is not authorized to execute comprises a table of:

the commands that the peripheral block is not authorized to execute; and

commands that the peripheral block is authorized to execute.

8 . The method of claim 7 , further comprising configuring, prior to the monitoring of the communications, the table of the commands that the peripheral block is not authorized to execute and the commands that the peripheral block is authorized to execute.

9 . The method of claim 7 , wherein the comparing of the respective commands of the communications sent by the host to the information of the table comprises:

indexing, based on the respective commands, into the table to determine whether the respective commands are authorized for execution by the peripheral block.

10 . The method of claim 1 , wherein:

the peripheral block of the system comprises a memory module coupled to the host via the SPI interconnect, the memory module comprising one of non-volatile memory or Flash memory; or

the peripheral block of the system does not include a write protect input node or a write protect input node of the peripheral block is disabled.

11 . The method of claim 10 , further comprising verifying a binary image stored on the memory module of the system before attempting to load the binary image from the memory module to the host via the SPI interconnect.

12 . The method of claim 11 , further comprising:

in response to successful verification of the binary image, allowing the memory module to send the binary image to the host via the SPI interface; or

in response to unsuccessful verification of the binary image, preventing the memory module from sending the binary image to the host via the SPI interface.

13 . The method of claim 12 , wherein the binary image is a first binary image stored in a first partition of the memory module, and the method further comprises:

manipulating an address of a read command for the first binary image to cause the memory module to send a second binary image to the host from a second partition of the memory module.

14 . An integrated circuit including circuitry for secure serial peripheral interface communication, the circuitry comprising:

a host with a functional core;

at least one peripheral block;

a serial peripheral interface (SPI) interconnect coupling the host and the at least one peripheral block; and

a secure SPI communication module operably coupled with the SPI interconnect and configured to:

monitor communications transmitted by the host to a peripheral block of the at least one peripheral block of the integrated circuit that is coupled to the host via the serial peripheral interface (SPI) interconnect;

compare respective commands of the communications sent by the host to information indicating which commands the peripheral block is not authorized to execute;

determine, based on the comparing, that one of the respective commands comprises a write-status-register command that the peripheral block is not authorized to execute; and

in response to the determination that the peripheral block is not authorized to execute the write-status-register command, alter the write-status-register command to prevent the write-status-register command from altering a status register of the peripheral block.

15 . The integrated circuit of claim 14 , wherein: the respective command comprises a first command of a first communication; and the secure SPI communication module is further configured to: determine that the peripheral block is not authorized to execute a second command of a second communication sent by the host to the peripheral block; and prevent the peripheral block from receiving at least a portion of the second command that the peripheral block is not authorized to execute.

16 . The integrated circuit of claim 15 , wherein the secure SPI communication module is further configured to alter the state of the chip select line and the clock line of the SPI interconnect to prevent the peripheral block from receiving the at least a portion of the respective second command of the second communication sent by the host.

17 . The integrated circuit of claim 16 , wherein:

the second command of the second communication comprises eight bits; and

the secure SPI communication module is further configured to deassert the chip select line prior to or on an eighth clock cycle by which an eighth bit of the second command is communicated via the SPI interconnect to prevent at least the eighth bit of the second command from being processed by the peripheral block.

18 . The integrated circuit of claim 16 , wherein:

the second command of the second communication comprises eight bits; and

the secure SPI communication module is further configured to gate the clock line prior to or on an eighth clock cycle by which an eighth bit of the second command is communicated via the SPI interconnect to prevent at least the eighth bit of the second command from being processed by the peripheral block.

19 . The method of claim 2 , wherein the preventing comprises altering a state of a chip select line or a clock line of the SPI interconnect to prevent the peripheral block from receiving the at least a portion of the second command of the second communication sent by the host.

20 . The integrated circuit of claim 15 , wherein the secure SPI communication module is further configured to alter a state of a chip select line or a clock line of the SPI interconnect to prevent the peripheral block from receiving the at least a portion of the second command of the second communication sent by the host.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2023
From: KIM, EUNCHAN; CHEN, TIMOTHY JAY
To: GOOGLE LLC
Reel/Frame 065074/0509 →
Continuity (2)
Provisional Application 63179043 · Apr 23, 2021
Related Publication 20240184735A1 · Jun 6, 2024
References Cited (56)
US 6286066B1 · Hayes et al. · 2001 [cited by applicant]
US 7924048B2 · Oh et al. · 2011 [cited by applicant]
US 8123133B2 · Dubois et al. · 2012 [cited by applicant]
US 8769172B2 · Soffer · 2014 [cited by examiner]
US 9304579B2 · Ware et al. · 2016 [cited by applicant]
US 9728275B2 · Tsuji et al. · 2017 [cited by applicant]
US 9792446B2 · Chan et al. · 2017 [cited by applicant]
US 9946899B1 · Wesson et al. · 2018 [cited by applicant]
US 9953166B2 · Newell · 2018 [cited by applicant]
US 11087610B2 · Anderholm et al. · 2021 [cited by applicant]
US 11477219B2 · Jenkinson et al. · 2022 [cited by applicant]
US 12153720B2 · Johnson et al. · 2024 [cited by applicant]
US 20030115503A1 · Lehman et al. · 2003 [cited by applicant]
US 20090037747A1 · Xie · 2009 [cited by applicant]
US 20090327429A1 · Hughes et al. · 2009 [cited by applicant]
US 20140229644A1 · Thanigasalam et al. · 2014 [cited by applicant]
US 20160180095A1 · Sarangdhar · 2016 [cited by applicant]
US 20160378996A1 · Smith et al. · 2016 [cited by applicant]
US 20170126472A1 · Margalit et al. · 2017 [cited by applicant]
US 20170249099A1 · Jun et al. · 2017 [cited by applicant]
US 20180034793A1 · Kibalo et al. · 2018 [cited by applicant]
US 20190026478A1 · Wu et al. · 2019 [cited by applicant]
US 20190088096A1 · King et al. · 2019 [cited by applicant]
US 20190172047A1 · Tan et al. · 2019 [cited by applicant]
US 20190180041A1 · Bhunia et al. · 2019 [cited by applicant]
US 20190187922A1 · Marley et al. · 2019 [cited by applicant]
US 20190327486A1 · Liao et al. · 2019 [cited by applicant]
US 20200004994A1 · Hershman · 2020 [cited by examiner]
US 20200310662A1 · Staab et al. · 2020 [cited by applicant]
US 20210124711A1 · Ansari et al. · 2021 [cited by applicant]
US 20210312092A1 · Belgarric et al. · 2021 [cited by applicant]
US 20220292226A1 · Johnson et al. · 2022 [cited by applicant]
US 20220292228A1 · Johnson et al. · 2022 [cited by applicant]
US 20240184735A1 · Kim et al. · 2024 [cited by applicant]
JP 2019121410A · 2019 [cited by applicant]
JP 2019212293A · 2019 [cited by applicant]
JP 2021507369A · 2021 [cited by applicant]
WO 2021087417 · 2021 [cited by applicant]
WO 2021087418 · 2021 [cited by applicant]
WO 2022226520 · 2022 [cited by applicant]
“Foreign Office Action”, JP Application No. 2023-557156, Oct. 1, 2024, 12 pages. [cited by applicant]
“Notice of Allowance”, U.S. Appl. No. 17/633,541, Aug. 28, 2024, 9 pages. [cited by applicant]
“Final Office Action”, U.S. Appl. No. 17/633,530, Aug. 31, 2023, 15 pages. [cited by applicant]
“Foreign Office Action”, CN Application No. 202080020058.6, Sep. 29, 2023, 25 pages. [cited by applicant]
“Intel Atom Processor C2000 Product Family for Microserver”, Datasheet, Jan. 2016, 745 pages. [cited by applicant]
“International Preliminary Report on Patentability”, Application No. PCT/US2020/058444, May 3, 2022, 7 pages. [cited by applicant]
“International Preliminary Report on Patentability”, Application No. PCT/US2020/058445, May 3, 2022, 7 pages. [cited by applicant]
“International Preliminary Report on Patentability”, Application No. PCT/US2022/071842, Oct. 24, 2023, 8 pages. [cited by applicant]
“International Search Report and Written Opinion”, Application No. PCT/US2020/058445, Feb. 16, 2021, 10 pages. [cited by applicant]
“International Search Report and Written Opinion”, Application No. PCT/US2020/058444, Feb. 16, 2021, 11 pages. [cited by applicant]
“Non-Final Office Action”, U.S. Appl. No. 17/633,530, Mar. 2, 2023, 14 pages. [cited by applicant]
Sukhomlinov, et al., “Mitigating Malicious Firmware by Detecting the Removal of a Storage Device”, Technical Disclosure Commons; Retrieved from https://www.tdcommons.org/dpubs_series/2378, Aug. 2, 2019, 10 pages. [cited by applicant]
“Enhanced Serial Peripheral Interface (eSPI)”, Accessed online at: https://www.intel.com/content/dam/support/us/en/documents/software/chipset-software/327432-004_espi_base_specification_rev1.0_cb.pdf on Mar. 30, 2021, 0… [cited by applicant]
“International Search Report and Written Opinion”, Application No. PCT/US2022/071842, Jul. 13, 2022, 12 pages. [cited by applicant]
“Non-Final Office Action”, U.S. Appl. No. 17/633,541, Mar. 1, 2024, 22 pages. [cited by applicant]
“Foreign Office Action”, IN Application No. 202347059884, Apr. 4, 2025, 6 pages. [cited by applicant]