IP Library › Granted Patent US 11,461,146
Granted Patent B2
US 11,461,146 · App. 17/126,873 · Granted Oct 4, 2022

Scheduling sub-thread on a core running a trusted execution environment

Inventors: Dongdong Yao (Beijing, CN); Yu Li (Beijing, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
G06F9/505G06F21/53G06N3/063G06F2209/5018
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,461,146
App. No.
17/126,873
Granted
Oct 4, 2022
Kind
B2
Abstract

A method, implemented by a computer system comprising a trusted execution environment (TEE) and a rich execution environment (REE) includes creating, by the TEE, a plurality of sub-threads preparing to implement sub-functions of a trusted application (TA), for each sub-thread, triggering, by the TEE, the REE to generate a shadow thread, where running of the shadow thread will cause a core on which the shadow thread runs to enter the TEE, and scheduling the created sub-thread to the entered core for execution.

Claims (48)

1. A multiprocessing method, implemented by a computer system comprising a trusted execution environment (TEE) and a rich execution environment (REE), wherein the multiprocessing method comprises:

creating, by the TEE, a sub-thread, wherein the sub-thread implements a sub-function of a trusted application (TA) on the TEE;

triggering, by the TEE, the REE to generate a shadow thread;

running, by the REE, the shadow thread on a core of the computer system to cause the core to enter the TEE; and

scheduling, by the TEE, the sub-thread for execution by the core.

2. The multiprocessing method of claim 1 , further comprising:

generating, by the TEE, a notification in response to creating the sub-thread;

sending, by the TEE, the notification to the REE; and

creating, by the REE, the shadow thread based on the notification.

3. The multiprocessing method of claim 2 , wherein the notification is a software interrupt.

4. The multiprocessing method of claim 1 , further comprising recording, by the TEE, a correspondence between the shadow thread and the sub-thread.

5. The multiprocessing method of claim 4 , further comprising recording, by the TEE, an identifier of the shadow thread in a first thread identifier in a thread control block (TCB) of the sub-thread, wherein the first thread identifier indicates a thread that accesses the sub-thread.

6. The multiprocessing method of claim 4 , further comprising scheduling, by the TEE based on the correspondence, the sub-thread to a current core that the shadow thread uses to run when the shadow thread re-enters the TEE.

7. The multiprocessing method of claim 1 , further comprising recording, by the TEE, a correspondence between the shadow thread and the core.

8. The multiprocessing method of claim 7 , further comprising:

recording, by the TEE, an identifier of the shadow thread in an element corresponding to the core in a global status array in response to the core entering the TEE, wherein the global status array comprises a plurality of elements that each correspond to one core of the computer system; and

clearing, by the TEE, a value of the element in response to the core leaving the TEE.

9. The multiprocessing method of claim 1 , further comprising calling, by the TEE, a neural processing unit (NPU) driver in the TEE to call an NPU of the computer system.

10. The multiprocessing method of claim 1 , further comprising:

accessing, by the TEE, corresponding hardware through a hardware driver unit on the TEE; and

storing, by the TEE, data from the hardware in a security storage unit on the TEE.

11. The multiprocessing method of claim 1 , wherein the TA is for implementing either a facial recognition function or a fingerprint recognition function.

12. A computer system comprising:

a plurality of processing cores configured to run a trusted execution environment (TEE) and in a rich execution environment (REE); and

a memory coupled to the processing cores and configured to store instructions that, when executed by the processing cores, cause the computer system to be configured to:

create, by the TEE, a sub-thread, wherein the sub-thread implements a sub-function of a trusted application (TA) on the TEE;

trigger, by the TEE, the REE to generate a shadow thread;

run, by the REE, the shadow thread on a core of the processing cores to cause the core to enter the TEE; and

schedule, by the TEE, the sub-thread for execution by the core.

13. The computer system of claim 12 , wherein the instructions further cause the computer system to be configured to:

generate, by the TEE, a notification in response to creating the sub-thread;

send, by the TEE, the notification to the REE; and

create, by the REE, the shadow thread based on the notification.

14. The computer system of claim 12 , wherein the instructions further cause the computer system to be configured to record, by the TEE, a correspondence between the shadow thread and the sub-thread.

15. The computer system of claim 14 , wherein the instructions further cause the computer system to be configured to record, by the TEE, an identifier of the shadow thread in a first thread identifier in a thread control block (TCB) of the sub-thread, and wherein the first thread identifier indicates a thread that accesses the sub-thread.

16. The computer system of claim 14 , wherein the instructions further cause the computer system to be configured to schedule, by the TEE based on the correspondence, the sub-thread to a current core that the shadow thread uses to run when the shadow thread re-enters the TEE.

17. The computer system of claim 12 , wherein the instructions further cause the computer system to be configured to record, by the TEE, a correspondence between the shadow thread and the core.

18. The computer system of claim 17 , wherein the instructions further cause the computer system to be configured to:

record, by the TEE, an identifier of the shadow thread in an element corresponding to the core in a global status array in response to the core entering the TEE, wherein the global status array comprises a plurality of elements that each correspond to one core of the REE; and

clear, by the TEE, a value of the element in response to the core leaving the TEE.

19. The computer system of claim 12 , wherein the instructions further cause the computer system to be configured to:

access, by the TEE, corresponding hardware through a hardware driver unit on the TEE; and

store, by the TEE, data from the hardware in a security storage unit on the TEE.

20. A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause a computer system to:

create, by a trusted execution environment (TEE), a sub-thread, wherein the sub-thread implements a sub-function of a trusted application (TA) on the TEE;

trigger, by the TEE, a processing core running in a rich execution environment (REE) to generate a shadow thread;

run, by the REE, the shadow thread on a core of the computer system to cause the core to enter the TEE; and

schedule, by the TEE, the sub-thread to the core for execution.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2021
From: YAO, DONGDONG; LI, YU
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 055067/0914 →
Priority Claims (1)
CN 201810632168.2 · Jun 19, 2018 · national
Continuity (2)
Continuation PCTCN2019086133 · May 9, 2019
Related Publication 20210103470A1 · Apr 8, 2021
Cited By (1)
US 12,423,431