IP Library › Granted Patent US 11,983,260
Granted Patent B2
US 11,983,260 · App. 18/296,679 · Granted May 14, 2024

Partitioned platform security mechanism

Inventors: Bharat Pillilli (El Dorado Hills, CA); David W. Palmer (Beaverton, OR); Nikola Radovanovic (Los Altos, CA)
Assignee: Intel Corporation
G06F21/33G06F21/44G06F21/572G06F21/73
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,983,260
App. No.
18/296,679
Granted
May 14, 2024
Kind
B2
Abstract

A computer platform is disclosed. The computer platform comprises a central processing unit (CPU) including at least one socket having a plurality of tiles and control circuitry to partition the socket into a plurality of sub-sockets and assign a unique identity to each of the plurality of sub-sockets for security verification, wherein each sub-socket comprises at least one of the plurality of tiles to operate as a cluster of resources.

Claims (28)

1. A system comprising:

an integrated circuit (IC), including:

a processor; and

control circuitry to generate a first active component root of trust (AC-ROT) Leaf associated with a first virtual component and generate a second active component AC-ROT Leaf associated with a second virtual component.

2. The system of claim 1 , wherein the first AC-ROT Leaf and the second AC-ROT Leaf are generated using an AC-ROT Root.

3. The system of claim 2 , wherein the AC-ROT Root comprises an AC-ROT associated with the processor.

4. The system of claim 3 , wherein the AC-ROT Root operates as a certificate of authority to generate a first certificate chain associated with the first AC-ROT Leaf and a second certificate chain associated with the second AC-ROT Leaf.

5. The system of claim 4 , wherein the certificate chain comprises a leaf identity, an indication that an identified Leaf has been cryptographically signed by the AC-ROT Root and an on-device device signature authority associated with a manufacturer of the processor.

6. The system of claim 5 , wherein the AC-ROT Leaf receives a device identifier public key signed by the AC-ROT Root.

7. The system of claim 6 , wherein the IC further comprises a security engine to operate is a root of trust for the system.

8. The system of claim 7 , wherein the security engine verifies the identity of a first sub-socket via the first AC-ROT Leaf and verifies the identity of a second sub-socket via the second AC-ROT Leaf.

9. A method comprising:

generating a first active component root of trust (AC-ROT) Leaf associated with a first virtual component of a processor; and

generating a second active component AC-ROT Leaf associated with a second virtual component of the processor.

10. The method of claim 9 , wherein the first AC-ROT Leaf and the second AC-ROT Leaf are generated using an AC-ROT Root.

11. The method of claim 10 , wherein the AC-ROT Root comprises a processor AC-ROT associated with the processor.

12. The method of claim 11 , wherein the AC-ROT Root operates as a certificate of authority to generate a first certificate chain associated with the first AC-ROT Leaf and a second certificate chain associated with the second AC-ROT Leaf.

13. The method of claim 11 , further comprising:

verifying an identity of the first sub-socket via a first AC-ROT Leaf at a platform root of trust; and

verifying an identity of the second sub-socket via a second AC-ROT Leaf at the platform root of trust.

14. At least one computer readable medium having instructions stored thereon, which when executed by one or more processors, cause the processors to:

generate a first active component root of trust (AC-ROT) Leaf associated with a first virtual component of a processor; and

generate a second active component AC-ROT Leaf associated with a second virtual component of the processor.

15. The computer readable medium of claim 14 , wherein the first AC-ROT Leaf and the second AC-ROT Leaf are generated using an AC-ROT Root associated with the processor.

16. The computer readable medium of claim 15 , wherein the AC-ROT Root operates as a certificate of authority to generate a first certificate chain associated with the first AC-ROT Leaf and a second certificate chain associated with the second AC-ROT Leaf.

17. The computer readable medium of claim 16 , having instructions stored thereon, which when executed by one or more processors, further cause the one or more processors to:

verify an identity of the first sub-socket via a first AC-ROT Leaf at a platform root of trust; and

verify an identity of the second sub-socket via a second AC-ROT Leaf at the platform root of trust.

Continuity (2)
Continuation 17355378 · Jun 23, 2021
Related Publication 20230244772A1 · Aug 3, 2023