IP Library › Granted Patent US 10,482,258
Granted Patent B2
US 10,482,258 · App. 15/719,637 · Granted Nov 19, 2019

Method for securing runtime execution flow

Inventors: Lawrence Loren Case (Austin, TX); Aditi Dinesh Shah (Austin, TX)
Assignee: NXP USA, INC.
G06F21/575G06F9/4406H04L9/14H04L9/3226G06F1/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,482,258
App. No.
15/719,637
Granted
Nov 19, 2019
Kind
B2
Abstract

A runtime security system, including: a shared core configured to execute processes having varying levels of trustworthiness configured to receive security services requests; an execution monitor configured to monitor the execution of the shared core further comprising a timer, a policy table, and an execution monitor state machine; secure assets including cryptographic keys; and immutable security service functions configured to enable access to the secure assets in response to secure services requests; wherein the execution monitor is configured to: detect that the shared core has received a secure boot request; verify that the secure boot request is valid; allow the shared core to securely boot when the secure boot request valid.

Claims (44)

1. A runtime security system, comprising:

a shared core configured to execute processes having varying levels of trustworthiness configured to receive security services requests;

an execution monitor configured to monitor the execution of the shared core further comprising a timer, a policy table, and an execution monitor state machine; secure assets including cryptographic keys; and immutable security service functions configured to enable access to the secure assets in response to secure services requests, wherein the execution monitor is configured to:

detect that the shared core has received a secure boot request;

verify that the secure boot request is valid during a temporary window of access based upon a state of the execution monitor, a received command, and a requestor ID: and

allow the shared core to securely boot when the secure boot request is valid;

wherein the execution monitor is further configured to set the timer related to an expected reaction time of the shared core to the secure boot request.

2. The runtime security system of claim 1 , wherein the execution monitor is further configured to monitor an entry point of an instruction sequence of the secure boot request.

3. The runtime security system of claim 1 , wherein the execution monitor is further configured to:

detect that the shared core has received a non-maskable secure services request;

verify that an instruction related to the non-maskable secure services request is valid; and

set a privilege level of the instruction based upon a policy evaluation using the policy table.

4. The runtime security system of claim 3 , wherein the execution monitor is further configured to revert the privilege level to a different trust level once the non-maskable secure services request has been completed.

5. The runtime security system of claim 3 , wherein the execution monitor is further configured to set the timer related to an expected reaction time of the shared core to the non-maskable secure services request.

6. The runtime security system of claim 3 , wherein the shared core receives security assets based upon the set privilege level.

7. A runtime security system, comprising:

a shared core configured to execute processes having varying levels of trustworthiness configured to receive non-maskable security services requests;

an execution monitor configured to monitor the execution of the shared core further comprising a timer, a policy table, and an execution monitor state machine; secure assets including cryptographic keys; and immutable security service functions configured to enable access to the secure assets in response to non-maskable secure services requests, wherein the execution monitor is configured to:

detect that the shared core has received a non-maskable secure services request;

verify that an instruction related to the non-maskable secure services request is valid during a temporary window of access based upon a state of the execution monitor, a received command, and a requestor ID: and

set a privilege level of the instruction based upon a policy evaluation using the policy table;

wherein the execution monitor is further configured to set the timer related to an expected reaction time of the shared core to the non-maskable secure services request.

8. The runtime security system of claim 7 , wherein the execution monitor is further configured to monitor an entry point of an instruction sequence of the non-maskable secure services request.

9. The runtime security system of claim 7 , wherein the execution monitor is further configured to revert the privilege level to a different trust level once the non-maskable secure services request has been completed.

10. The runtime security system of claim 7 , further comprising:

a handshake queue configured to perform a handshake protocol with a system sending secure services requests to the shared core.

11. The runtime security system of claim 7 , further comprising:

a queue with ID configured to receive security services requests and the requestor ID from a system and provide the security services requests to the shared core based upon the requestor ID.

12. The runtime security system of claim 7 , further comprising:

a system security monitor configured to provide an integrity indicator to the execution monitor based upon a tamper or integrity issued indication.

13. A method of monitoring a shared core configured to perform functions having varying levels of trustworthiness by an execution monitor, wherein the execution monitor includes a timer, a policy table, and an execution monitor state machine, the method comprising:

receiving a secure boot request by a shared core;

detecting, by the execution monitor, that the shared core has received the secure boot request;

verifying that the secure boot request is valid during a temporary window of access based upon a state of the execution monitor, a received command, and a requestor ID: and

allowing the shared core to securely boot when the secure boot request is valid;

setting, by the execution monitor, the timer related to an expected reaction time of the shared core to the non-maskable secure services request.

14. The method of claim 13 , further comprising:

receiving a non-maskable secure services request by the shared core;

detecting, by the execution monitor, that the shared core has received a non-maskable secure services request;

verifying, by the execution monitor, that an instruction related to the non-maskable secure services request is valid; and

setting, by the execution monitor, a privilege level of the instruction based upon a policy evaluation using the policy table.

15. The method of claim 14 , wherein the shared core receives security assets based upon the set privilege level.

16. The method of claim 14 , further comprising;

reverting, by the execution monitor, the privilege level to an un-trusted level once the non-maskable secure services request has been completed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2017
From: CASE, LAWRENCE LOREN; SHAH, ADITI DINESH
To: NXP USA, INC.
Reel/Frame 043736/0470 →
Continuity (1)
Related Publication 20190102556A1 · Apr 4, 2019
Cited By (1)
US 12,393,704