IP Library Granted Patent US 11,089,016
Granted Patent B2
US 11,089,016 · App. 16/076,449 · Granted Aug 10, 2021

Secure system on chip

Inventors: Dong Kyue Kim (Seoul, KR); Ji-Hoon Kim (Gyeonggi-do, KR)
Assignee: INDUSTRY-UNIVERSITY COOPERATION FOUNDATION HANYANG UNIVERSITY
H04L63/0869G06F15/7807G06F15/7842G06F15/7853G06F21/55G06F21/556G06F21/57G06F21/60G06F21/602G06F21/74G06F21/85G06K19/07372G06Q20/341H04L9/321H04L9/3263H04L9/3278G06F2221/2149H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,089,016
App. No.
16/076,449
Granted
Aug 10, 2021
Kind
B2
Abstract

Disclosed is a secure semiconductor chip. The semiconductor chip is, for example, a system-on-chip. The system-on-chip is operated by connecting normal IPs to a processor core included therein via a system bus. A secure bus, which is a hidden bus physically separated from the system bus, is separately provided. Security IPs for performing a security function or handling security data are connected to the secure bus. The secure semiconductor chip can perform required authentication while shifting between a normal mode and a secure mode.

Claims (36)

1. A semiconductor chip comprising:

a processor core;

a first group comprising elements connected to the processor core by a first bus; and

a second group comprising elements connected to the processor core by a second bus and configured to operate in a secure mode,

wherein the second group processes data by using a memory address different from that of the first group, and

wherein the processor core partitions a memory area into a code area and a data area and comprises a memory protection unit, the memory protection unit configured to prohibit writing in the code area and prohibit execution in the data area,

wherein the processor core comprises a RISC (reduced instruction set computing)-V processor, the RISC-V processor being a 32-bit RISC type embedded processor,

wherein the second bus comprises a hidden bus implemented by using an ASR (application specific register) of the RISC-V processor as an address space for controlling elements included in the second group.

2. The semiconductor chip of claim 1 , wherein the second bus is physically separate from the first bus so that the second group is physically isolated from the first group.

3. The semiconductor chip of claim 1 , wherein the second group uses an MTA (move to ASR) command and an MFA (move from ASR) command in the secure mode for processing secure instructions, the MTA command and the MFA command being commands for processing data in relation to the ASR.

4. The semiconductor chip of claim 1 , wherein the code area and the data area are configured by secure instructions processed using commands associated with an ASR of the RISC-V processor.

5. The semiconductor chip of claim 1 , wherein the processor core comprises a shadow stack configured to backup a return address included in a code sequence.

6. The semiconductor chip of claim 5 , wherein the shadow stack does not use a bus, is not accessed by an OS or software, is automatically executed to backup the return address when a command related to a memory stack is executed,

and a security attack is detected by a sameness check with an original return address using the backed up return address.

7. The semiconductor chip of claim 1 , further comprising:

an authentication part configured to perform mutual authentication with an outside trusted authority when the semiconductor chip is powered on,

wherein the second group is usable only when the authentication is successful.

8. The semiconductor chip of claim 1 , wherein the secure mode is activated and at least a portion of the second group is operated if there is a security violation event or a call for processing at an increased security level while the second group is usable and the first group is operating.

9. The semiconductor chip of claim 1 , wherein the second group includes at least one of a cryptographic IP, a secure SRAM, a secure DMA, and a boot ROM.

10. The semiconductor chip of claim 1 , further comprising:

a PUF configured to provide a root key used by the authentication part for the mutual authentication with the outside trusted authority.

11. An operation method for a semiconductor system-on-chip, the operation method comprising:

performing mutual authentication with an outside trusted authority, the mutual authentication performed by an authentication part; and

activating a first group comprising elements connected to the processor core by a first bus and deactivating elements connected to the processor core by a second bus and configured to operate in a secure mode, if the authentication is not successful,

wherein the second group processes data by using a memory address different from that of the first group, and

wherein the processor core partitions a memory area into a code area and a data area and comprises a memory protection unit, the memory protection unit configured to prohibit writing in the code area and prohibit execution in the data area,

wherein the processor core comprises a RISC (reduced instruction set computing)-V processor, the RISC-V processor being a 32-bit RISC type embedded processor, and

wherein the second bus comprises a hidden bus implemented by using an ASR (application specific register) of the RISC-V processor as an address space for controlling elements included in the second group.

12. The operation method of claim 11 , wherein the second group includes at least one of a cryptographic IP, a secure SRAM, a secure DMA, and a boot ROM.

13. The operation method of claim 11 , wherein a root key used by the authentication part in the mutual authentication with the outside trusted authority is provided by a PUF included within the semiconductor system-on-chip.

14. The operation method of claim 11 , further comprising:

activating the secure mode to operate at least a portion of the second group if there is a security violation event or a call for processing at an increased security level during an operation of the first group while the second group is in a usable state due to the authentication being successful.

15. The operation method of claim 11 , wherein the processor core comprises a hardware-based shadow stack, and wherein the shadow stack does not use a bus, is not accessed by an OS or software, and is configured to back up a return address included in a code sequence.

16. The operation method of claim 15 , further comprising:

backing up the return address when the processor core executes a command related to a memory stack; and

detecting an attack by comparing the return address with an original to check for sameness.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2018
From: KIM, DONG KYUE; KIM, JI-HOON
To: INDUSTRY-UNIVERSITY COOPERATION FOUNDATION HANYANG UNIVERSITY
Reel/Frame 046748/0712 →
Priority Claims (2)
KR 10-2016-0016587 · Feb 12, 2016 · national
KR 10-2017-0019341 · Feb 13, 2017 · national
Continuity (1)
Related Publication 20190114428A1 · Apr 18, 2019
Cited By (1)
US 12,511,398