Security isolation apparatus and method
A system includes a first subsystem and a second subsystem that are used in a same chip. A security level of a first physical resource included in the first subsystem is higher than a security level of a second physical resource included in the second subsystem. The first subsystem includes an interrupt controller, and the interrupt controller is configured to manage an interrupt of a peripheral of the second subsystem. Embodiments of this application are for isolation between subsystems of different security levels in a chip.
1 . A security isolation apparatus, comprising:
a chip comprising:
a second subsystem comprising a second processor core, a first peripheral, and a second physical resource, wherein the second physical resource has a second security level; and
a first subsystem comprising:
a first processor core;
a first physical resource, wherein the first physical resource has a first security level, and wherein the first security level is higher than the second security level; and
an interrupt controller configured to:
receive an interrupt signal from the first peripheral of the second subsystem; and
control, when receiving the interrupt signal, the first processor core or the second processor core to suspend a running program and to execute a program from the interrupt signal.
2 . The security isolation apparatus of claim 1 , wherein the first peripheral comprises a second peripheral, and wherein the second peripheral is configured to send the interrupt signal to the interrupt controller.
3 . The security isolation apparatus of claim 2 , wherein the second physical resource comprises:
an interrupt configuration register; and
a third processor core configured to write interrupt information into the interrupt configuration register, wherein the interrupt information comprises an interrupt attribute of the interrupt signal, and
wherein the first physical resource comprises a fourth processor core configured to:
read the interrupt information from the interrupt configuration register; and
configure the interrupt information in the interrupt controller to enable the interrupt controller to control the first processor core or the second processor core to execute the program.
4 . The security isolation apparatus of claim 3 , wherein the fourth processor core is further configured to obtain an interrupt configuration request from the interrupt configuration register to trigger the fourth processor core to read the interrupt information.
5 . The security isolation apparatus of claim 1 , wherein the first physical resource is configured as a first security level identifier, and wherein the second physical resource is configured as a second security level identifier.
6 . The security isolation apparatus of claim 5 , wherein the first physical resource comprises a first processor core, wherein the first processor core is configured to send a first access request carrying the first security level identifier and an address of a second peripheral to be accessed, wherein the second physical resource comprises a second processor core and the second peripheral, wherein the security isolation apparatus further comprises an authentication circuit configured to:
receive the first access request;
obtain a third security level identifier of the second peripheral based on the address;
perform authentication based on the first security level identifier and the third security level identifier; and
forward the first access request to the second peripheral when the authentication succeeds.
7 . The security isolation apparatus of claim 6 , wherein the authentication circuit device is further configured to determine, when a third security level of the first processor core corresponding to the first security level identifier is higher than a fourth security level of the second peripheral corresponding to the third security level identifier, that the authentication succeeds, and wherein the first access request is a write request or a read request.
8 . The security isolation apparatus of claim 5 , wherein the first physical resource comprises a first processor core and a second peripheral, wherein the second physical resource comprises a second processor core, wherein the second processor core is configured to send a second access request carrying the second security level identifier and an address of the second peripheral to be accessed, wherein the security isolation apparatus further comprises an authentication circuit configured to:
receive the second access request;
obtain a third security level identifier of the second peripheral based on the address;
perform authentication based on the third security level identifier and the second security level identifier; and
forward the second access request to the second peripheral when the authentication succeeds.
9 . The security isolation apparatus of claim 8 , wherein the authentication circuit is further configured to determine, when a third security level of the second processor core corresponding to the second security level identifier is lower than a fourth security level of the second peripheral corresponding to the third security level identifier and when the second access request is a read request, that the authentication succeeds.
10 . The security isolation apparatus of claim 1 , wherein the first subsystem is configured to process a first service of the first security level, wherein the second subsystem is configured to process a second service of the second security level or a third service of a non-security level, wherein the first security level and the second security level are levels in an automotive safety integration level (ASIL), and wherein the non-security level is quality management (QM).
11 . A method comprising,
providing a first subsystem and a second subsystem of a security isolation apparatus, wherein the first subsystem and the second subsystem are comprised in a same chip, wherein the first subsystem comprises a first processor core, an interrupt controller and a first physical resource having a first security level, wherein the second subsystem comprises a second processor core, a first peripheral, and a second physical resource having a second security level, and wherein the first security level is higher than the second security level;
receiving, by the interrupt controller, an interrupt signal from the first peripheral of the second subsystem; and
controlling, by the interrupt controller when receiving the interrupt signal, the first processor core or the second processor core to suspend a running program and execute a program from the interrupt signal.
12 . The method of claim 11 , wherein the second subsystem further comprises a second peripheral, and wherein the method further comprises sending, by the second peripheral, an interrupt signal to the interrupt controller.
13 . The method of claim 12 , wherein the second physical resource comprises an interrupt configuration register and a third processor core, wherein the first physical resource comprises a fourth processor core, and wherein before sending the interrupt signal, the method further comprises:
writing, by the third processor core, interrupt information into the interrupt configuration register, wherein the interrupt information comprises an interrupt attribute of the interrupt signal from the second peripheral;
reading, by the fourth processor core, the interrupt information from the interrupt configuration register; and
configuring, by the fourth processor core, the interrupt information in the interrupt controller to enable the interrupt controller to control the first processor core or the second processor core to execute the program from the second peripheral.
14 . The method of claim 13 , wherein reading the interrupt information comprises obtaining, by the first processor core, an interrupt configuration request from the interrupt configuration register to trigger the first processor core to read the interrupt information.
15 . The method of claim 11 , wherein the first security level and the second security level are comprised in an initialization phase of a system using firmware.
16 . The method of claim 11 , wherein the first physical resource comprises a first security level identifier, and wherein the second physical resource comprises a second security level identifier.
17 . The method of claim 16 , wherein the first physical resource comprises a first processor core, wherein the second physical resource comprises a second peripheral, and wherein the method further comprises:
sending, by the first processor core, a first access request to an authentication circuit of the security isolation apparatus, wherein the first access request carries the first security level identifier and an address of the second peripheral to be accessed;
obtaining, by the authentication circuit, a third security level identifier of the second peripheral based on the address;
performing, by the authentication circuit, authentication based on the first security level identifier and the third security level identifier, and
forwarding, by the authentication circuit, the first access request to the second peripheral when the authentication succeeds.
18 . The method of claim 17 , wherein performing the authentication comprises determining, when a third security level of the first processor core corresponding to the first security level identifier is higher than a fourth security level of the second peripheral corresponding to the third security level identifier, that the authentication succeeds, and wherein the first access request is a write request or a read request.
19 . The method of claim 16 , wherein the first physical resource comprises a first processor core and a first peripheral, wherein the second physical resource comprises a second processor core, and wherein the method further comprises:
sending, by the second processor core, a second access request to an authentication circuit of the security isolation apparatus, wherein the second access request carries the second security level identifier and an address of the first peripheral to be accessed;
receiving, by the authentication circuit, the second access request;
obtaining, by the authentication circuit, a third security level identifier of the first peripheral based on the address;
performing authentication based on the third security level identifier and the second security level identifier; and
forwarding the second access request to the first peripheral when the authentication succeeds.
20 . A chip comprising:
a second subsystem comprising a second processor core, a first peripheral, and a second physical resource, wherein the second physical resource has a second security level; and
a first subsystem comprising:
a first processor core;
a first physical resource, wherein the first physical resource has a first security level, and wherein the first security level is higher than the second security level; and
an interrupt controller configured to:
receive an interrupt signal from the first peripheral of the second subsystem; and
control, when receiving an interrupt signal, the first processor core or the second processor core to suspend a running program and to execute a program from the interrupt signal.