Distributed dynamic memory management unit (mmu)-based secure inter-processor communication
Abstract
A first processor and a second processor are configured to communicate secure inter-processor communications (IPCs) with each other. The first processor effects secure IPCs and non-secure IPCs using a first memory management unit (MMU) to route the secure and non-secure IPCs via a memory system. The first MMU accesses a first page table stored in the memory system to route the secure IPCs and accesses a second page table stored in the memory system to route the non-secure IPCs. The second processor effects at least secure IPCs using a second MMU to route the secure IPCs via the memory system. The second MMU accesses the second page table to route the secure IPCs.
Claims
exact text as granted — not AI-modified1 - 33 . (canceled)
34 . A system for providing security in inter-processor communication on an integrated circuit chip, the system comprising:
a shared memory system; a first processor in communication with the shared memory system, the first processor configured to effect secure inter-processor communications and non-secure inter-processor communications using a first memory management unit to separately route the secure inter-processor communications and the non-secure inter-processor communications via the shared memory system, and a second processor in communication with the shared memory system, the second processor configured to effect at least secure inter-processor communications using a second memory management unit to route the secure inter-processor communications via the shared memory system, the first processor executes a first secure memory segmentation software layer, a non-secure application program, and a secure application program, non-secure inter-processor communications issued by the non-secure application program being routed to the first memory management unit via the first secure memory segmentation software layer, secure inter-processor communications associated with the secure application program being routed between the secure application program and the first memory management unit via the first secure memory segmentation software layer.
35 . The system of claim 34 , wherein the first memory management unit is configured to access a first secure page table stored in the shared memory system to route the secure inter-processor communications and access a separate second non-secure page table stored in the shared memory system to route the non-secure inter-processor communications.
36 . The system of claim 34 , wherein the second memory management unit is configured to access the first secure page table stored in the shared memory system to route the secure inter-processor communications.
37 . The system of claim 34 , wherein the second processor executes a second secure memory segmentation software layer.
38 . The system of claim 35 , wherein:
the first processor is a central processing unit; and the second processor is a central processing unit, the second memory management unit being further configured to access the separate second non-secured page table stored in the shared memory system.
39 . The system of claim 34 , wherein the first processor is a central processing unit.
40 . The system of claim 34 , wherein the second processor is a digital signal processor.
41 . The system of claim 34 , wherein secure inter-processor communications associated with the secure application program are routed between the secure application program and the first memory management unit via the secure memory segmentation software layer, secure inter-processor communications associated with the secure application program are broadcast across a network on the integrated circuit chip.
42 . The system of claim 41 , wherein the secure application program is a first secure application program, the second processor executes a second secure application program, the second secure memory segmentation software layer selectively providing secure inter-processor communications received on the network to the second secure application program by determining whether a secure inter-processor communication received on the network indicates the second secure application program is an intended recipient.
43 . The system of claim 34 , wherein the memory system is a cache memory on the integrated circuit chip.
44 . A method for providing security in inter-processor communication on an integrated circuit chip, comprising:
a first processor and a second processor communicating secure inter-processor communications with each other via a shared memory system; wherein the first processor in communication with the shared memory system effects secure inter-processor communications and non-secure inter-processor communications using a first memory management unit to separately route the secure inter-processor communications and the non-secure inter-processor communications via the shared memory system; and wherein the second processor in communication with the shared memory system effects at least secure inter-processor communications using a second memory management unit to route the secure inter-processor communications via the shared memory system, wherein the first processor executes a first secure memory segmentation software layer, a non-secure application program, and a secure application program, non-secure inter-processor communications issued by the non-secure application program being routed to the first memory management unit via the first secure memory segmentation software layer, secure inter-processor communications associated with the secure application program being routed between the secure application program and the first memory management unit via the first secure memory segmentation software layer.
45 . The method of claim 44 , wherein the first memory management unit accesses a first secure page table stored in the memory system to route the secure inter-processor communications and accesses a separate second non-secure page table stored in the memory system to route the non-secure inter-processor communications.
46 . The method of claim 44 , wherein the second memory management unit accesses the first secure page table stored in the shared memory system to route the secure inter-processor communications.
47 . The method of claim 44 , wherein the second processor executes a second secure memory segmentation software layer.
48 . The method of claim 44 , wherein:
the first processor is a central processing unit; and the second processor is a central processing unit, the second memory management unit further accessing the separate second non-secured page table stored in the shared memory system.
49 . The method of claim 48 , wherein the first processor executes a non-secure high-level operating system, non-secure inter-processor communications associated with the non-secure high-level operating system being routed between the non-secure high-level operating system and the first memory management unit via the first secure memory segmentation software layer, secure inter-processor communications associated with the secure application program being routed between the secure application program and the first memory management unit via the first secure memory segmentation software layer.
50 . The method of claim 44 , wherein:
the first processor is a central processing unit; and the second processor is digital signal processor.
51 . The method of claim 44 , wherein secure inter-processor communications associated with the secure application program being routed between the secure application program and the first memory management unit via the first secure memory segmentation software layer, secure inter-processor communications associated with the first secure application program being broadcast across a network on the integrated circuit chip.
52 . The method of claim 51 , wherein the secure application program is a first secure application program, wherein the second processor executes a second secure application program, the second secure memory segmentation software layer selectively providing secure inter-processor communications received on the network to the second secure application program by determining whether a secure inter-processor communication received on the network indicates the second secure application program is an intended recipient.
53 . The method of claim 44 , wherein the shared memory system is a cache memory on the integrated circuit chip.
54 . An integrated circuit chip, comprising:
means for a first processor and a second processor to communicate secure inter-processor communications with each other, each of the first processor and the second processor in communication with a shared memory system, means for the first processor to effect secure inter-processor communications and non-secure inter-processor communications using a first memory management unit to separately route the secure inter-processor communications and the non-secure inter-processor communications via the shared memory system; and means for the second processor to effect secure inter-processor communications using a second memory management unit to route the secure inter-processor communications via the shared memory system, the first processor executing a first secure memory segmentation software layer, a non-secure application program, and a secure application program, such that non-secure inter-processor communications issued by the non-secure application program are routed to the first memory management unit via the first secure memory segmentation software layer, secure inter-processor communications associated with the secure application program are routed between the secure application program and the first memory management unit via the first secure memory segmentation software layer.
55 . The integrated circuit chip of claim 54 , wherein the first memory management unit accesses a first secure page table stored in the shared memory system to route the secure inter-processor communications and accesses a separate second non-secure page table stored in the shared memory system to route the non-secure inter-processor communications.
56 . The integrated circuit chip of claim 54 , wherein the second memory management unit accessing the first secured page table stored in the shared memory system to route the secure inter-processor communications.
57 . The integrated circuit chip of claim 54 , wherein the means for the second processor to communicate secure inter-processor communications comprises means for executing a second secure memory segmentation software layer.
58 . The integrated circuit chip of claim 54 , wherein:
the first processor is a central processing unit; and the second processor is a central processing unit, the second memory management unit further accessing the separate second non-secured page table stored in the shared memory system.
59 . A computer program product comprising a non-transitory computer readable medium having computer readable program code embodied therein, said computer readable program code comprising:
first logic configuring a first processor to effect secure inter-processor communications and non-secure inter-processor communications using a first memory management unit to separately route the secure inter-processor communications and the non-secure inter-processor communications via a shared memory system; and second logic configuring a second processor to effect secure inter-processor communications and non-secure inter-processor communications using a second memory management unit to route the secure inter-processor communications and non-secure inter-processor communications via the memory system, wherein the first logic includes a first secure memory segmentation software layer, a non-secure application program, and a secure application program, non-secure inter-processor communications issued by the non-secure application program being routed to the first memory management unit via the first secure memory segmentation software layer, secure inter-processor communications associated with the secure application program being routed between the secure application program and the first memory management unit via the first secure memory segmentation software layer.
60 . The computer program product of claim 59 , wherein the first memory management unit is configured to access a first secure page table stored in the shared memory system to route the secure inter-processor communications and to access a separate second non-secure page table stored in the shared memory system to route the non-secure inter-processor communications.
61 . The computer program product of claim 59 , wherein the second memory management unit is configured to access the first secure page table stored in the memory system to route the secure inter-processor communications.
62 . The computer program product of claim 59 , wherein the second logic includes a second secure memory segmentation software layer.
63 . The computer program product of claim 59 , wherein the first logic includes a non-secure high-level operating system, non-secure inter-processor communications associated with the non-secure high-level operating system being routed between the non-secure high-level operating system and the first memory management unit via the secure memory segmentation software layer, secure inter-processor communications associated with the secure application program being routed between the secure application program and the first memory management unit via the secure memory segmentation software layer.Join the waitlist — get patent alerts
Track US2016012241A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.