Android IOMUX Secure Configuration

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

Android IOMUX Secure Configuration

Android IOMUX Secure Configuration

The IOMUX module on i.MX 8M enables flexible I/O multiplexing, allowing users to configure each IO pad as one of selectable functions. The CSU (Central Security Unit) module on i.MX 8M can be used to configure some devices as secure only accessible to protect the security of these devices. But as the IOMUX is Non-Secure accessilbe and thus the pad function can be configured dynamicaly, there is one risk if hackers reconfigure the IO pad to make the device connected to other controller which is accessible to Non-Secure world.

One solution for this issue is configuring the CSU to limit Non-Secure access to IOMUX, all IOMUX registers write operations are routed to Trusty OS. In the Trusty OS, add all sensitive IO resources to one blacklist, the IOMUX driver in Trusty OS should check and deny any write attemption to sensitive registers from Non-Secure world.

One example patch set is attached to show how to assign the IOMUX to secure world and how to route the IOMUX write operations to Trusty OS. In this example, the USB Host pinctrl PAD on i.MX8MP EVK was assigned to secure world. The layout of the example codes are:

 

 

.
├── atf
│   └── 0001-config-iomux-to-secure-write.patch --> ${MY_ANDROID}/vendor/nxp-opensource/arm-trusted-firmware
├── kernel
│   └── 0001-Use-Trusty-OS-to-handle-iomux-registers-written-oper.patch --> ${MY_ANDROID}/vendor/nxp-opensource/kernel_imx/
├── trusty
│   └── 0001-Add-iomux-pinctrl-TEE-handler.patch --> ${MY_TRUSTY}/trusty/hardware/nxp
└── u-boot
    └── 0001-Use-Trusty-OS-to-handle-IOMUX-operation.patch --> ${MY_ANDROID}/vendor/nxp-opensource/uboot-imx

 

 

 

添付
%3CLINGO-SUB%20id%3D%22lingo-sub-1477089%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EAndroid%20IOMUX%20%E3%81%AE%E5%AE%89%E5%85%A8%E3%81%AA%E6%A7%8B%E6%88%90%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1477089%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3Ei.MX%208M%E3%81%AEIOMUX%E3%83%A2%E3%82%B8%E3%83%A5%E3%83%BC%E3%83%AB%E3%81%AF%E3%80%81%E6%9F%94%E8%BB%9F%E3%81%AAI%2FO%E5%A4%9A%E9%87%8D%E5%8C%96%E3%82%92%E5%8F%AF%E8%83%BD%E3%81%AB%E3%81%97%E3%80%81%E3%83%A6%E3%83%BC%E3%82%B6%E3%83%BC%E3%81%AF%E5%90%84IO%E3%83%91%E3%83%83%E3%83%89%E3%82%92%E9%81%B8%E6%8A%9E%E5%8F%AF%E8%83%BD%E3%81%AA%E6%A9%9F%E8%83%BD%E3%81%AE1%E3%81%A4%E3%81%A8%E3%81%97%E3%81%A6%E6%A7%8B%E6%88%90%E3%81%A7%E3%81%8D%E3%81%BE%E3%81%99%E3%80%82i.MX%208M%20%E3%81%AE%20CSU(Central%20Security%20Unit)%E3%83%A2%E3%82%B8%E3%83%A5%E3%83%BC%E3%83%AB%E3%82%92%E4%BD%BF%E7%94%A8%E3%81%97%E3%81%A6%E3%80%81%E4%B8%80%E9%83%A8%E3%81%AE%E3%83%87%E3%83%90%E3%82%A4%E3%82%B9%E3%82%92%E3%82%BB%E3%82%AD%E3%83%A5%E3%82%A2%E3%81%AB%E8%A8%AD%E5%AE%9A%E3%81%A7%E3%81%8D%E3%80%81%E3%81%93%E3%82%8C%E3%82%89%E3%81%AE%E3%83%87%E3%83%90%E3%82%A4%E3%82%B9%E3%81%AE%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E3%82%92%E4%BF%9D%E8%AD%B7%E3%81%99%E3%82%8B%E3%81%9F%E3%82%81%E3%81%A0%E3%81%91%E3%81%AB%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E5%8F%AF%E8%83%BD%E3%81%A7%E3%81%99%E3%80%82%E3%81%9F%E3%81%A0%E3%81%97%E3%80%81IOMUX%E3%81%AFNon-Secure%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E3%81%A7%E3%81%82%E3%82%8A%E3%80%81%E3%83%91%E3%83%83%E3%83%89%E6%A9%9F%E8%83%BD%E3%82%92%E5%8B%95%E7%9A%84%E3%81%AB%E6%A7%8B%E6%88%90%E3%81%A7%E3%81%8D%E3%82%8B%E3%81%9F%E3%82%81%E3%80%81%E3%83%8F%E3%83%83%E3%82%AB%E3%83%BC%E3%81%8CIO%E3%83%91%E3%83%83%E3%83%89%E3%82%92%E5%86%8D%E6%A7%8B%E6%88%90%E3%81%97%E3%81%A6%E3%80%81%E3%83%87%E3%83%90%E3%82%A4%E3%82%B9%E3%82%92%E9%9D%9E%E3%82%BB%E3%82%AD%E3%83%A5%E3%82%A2%E3%81%AA%E4%B8%96%E7%95%8C%E3%81%8B%E3%82%89%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E5%8F%AF%E8%83%BD%E3%81%AA%E4%BB%96%E3%81%AE%E3%82%B3%E3%83%B3%E3%83%88%E3%83%AD%E3%83%BC%E3%83%A9%E3%83%BC%E3%81%AB%E6%8E%A5%E7%B6%9A%E3%81%99%E3%82%8B%E3%81%A8%E3%80%81%E3%83%AA%E3%82%B9%E3%82%AF%E3%81%8C1%E3%81%A4%E7%99%BA%E7%94%9F%E3%81%97%E3%81%BE%E3%81%99%E3%80%82%3C%2FP%3E%0A%3CP%3E%E3%81%93%E3%81%AE%E5%95%8F%E9%A1%8C%E3%81%AE%E8%A7%A3%E6%B1%BA%E7%AD%96%E3%81%AE%201%20%E3%81%A4%E3%81%AF%E3%80%81IOMUX%20%E3%81%B8%E3%81%AE%E9%9D%9E%E3%82%BB%E3%82%AD%E3%83%A5%E3%82%A2%20%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E3%82%92%E5%88%B6%E9%99%90%E3%81%99%E3%82%8B%E3%82%88%E3%81%86%E3%81%AB%20CSU%20%E3%82%92%E8%A8%AD%E5%AE%9A%E3%81%99%E3%82%8B%E3%81%93%E3%81%A8%E3%81%A7%E3%80%81%E3%81%99%E3%81%B9%E3%81%A6%E3%81%AE%20IOMUX%20%E3%83%AC%E3%82%B8%E3%82%B9%E3%82%BF%E3%81%AE%E6%9B%B8%E3%81%8D%E8%BE%BC%E3%81%BF%E6%93%8D%E4%BD%9C%E3%81%AF%20Trusty%20OS%20%E3%81%AB%E3%83%AB%E3%83%BC%E3%83%86%E3%82%A3%E3%83%B3%E3%82%B0%E3%81%95%E3%82%8C%E3%81%BE%E3%81%99%E3%80%82Trusty%20OS%20%E3%81%A7%E3%81%AF%E3%80%81%E3%81%99%E3%81%B9%E3%81%A6%E3%81%AE%E6%A9%9F%E5%AF%86%E6%80%A7%E3%81%AE%E9%AB%98%E3%81%84%20IO%20%E3%83%AA%E3%82%BD%E3%83%BC%E3%82%B9%E3%82%92%201%20%E3%81%A4%E3%81%AE%E3%83%96%E3%83%A9%E3%83%83%E3%82%AF%E3%83%AA%E3%82%B9%E3%83%88%E3%81%AB%E8%BF%BD%E5%8A%A0%E3%81%99%E3%82%8B%E3%81%A8%E3%80%81Trusty%20OS%20%E3%81%AE%20IOMUX%20%E3%83%89%E3%83%A9%E3%82%A4%E3%83%90%E3%83%BC%E3%81%AF%E3%80%81%E9%9D%9E%E3%82%BB%E3%82%AD%E3%83%A5%E3%82%A2%E3%81%AA%E4%B8%96%E7%95%8C%E3%81%8B%E3%82%89%E3%81%AE%E6%A9%9F%E5%AF%86%E6%80%A7%E3%81%AE%E9%AB%98%E3%81%84%E3%83%AC%E3%82%B8%E3%82%B9%E3%82%BF%E3%81%B8%E3%81%AE%E6%9B%B8%E3%81%8D%E8%BE%BC%E3%81%BF%E8%A9%A6%E8%A1%8C%E3%82%92%E3%83%81%E3%82%A7%E3%83%83%E3%82%AF%E3%81%97%E3%81%A6%E6%8B%92%E5%90%A6%E3%81%99%E3%82%8B%E5%BF%85%E8%A6%81%E3%81%8C%E3%81%82%E3%82%8A%E3%81%BE%E3%81%99%E3%80%82%3C%2FP%3E%0A%3CP%3EIOMUX%E3%82%92%E3%82%BB%E3%82%AD%E3%83%A5%E3%82%A2%E3%83%AF%E3%83%BC%E3%83%AB%E3%83%89%E3%81%AB%E5%89%B2%E3%82%8A%E5%BD%93%E3%81%A6%E3%82%8B%E6%96%B9%E6%B3%95%E3%81%A8%E3%80%81IOMUX%E3%81%AE%E6%9B%B8%E8%BE%BC%E3%81%BF%E6%93%8D%E4%BD%9C%E3%82%92Trusty%20OS%E3%81%AB%E3%83%AB%E3%83%BC%E3%83%86%E3%82%A3%E3%83%B3%E3%82%B0%E3%81%99%E3%82%8B%E6%96%B9%E6%B3%95%E3%82%92%E7%A4%BA%E3%81%99%E3%81%9F%E3%82%81%E3%81%AB%E3%80%81%E3%83%91%E3%83%83%E3%83%81%E3%82%BB%E3%83%83%E3%83%88%E3%81%AE%E4%BE%8B%E3%81%8C%20%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Fpwmxy87654%2Fattachments%2Fpwmxy87654%2Fimx-processors%2540tkb%2F5703%2F1%2Fiomux_secure_fix.tar.gz%22%20target%3D%22_self%22%3E%E6%B7%BB%E4%BB%98%3C%2FA%3E%20%E3%81%95%E3%82%8C%E3%81%A6%E3%81%84%E3%81%BE%E3%81%99%E3%80%82%E3%81%93%E3%81%AE%E4%BE%8B%E3%81%A7%E3%81%AF%E3%80%81i.MX8MP%20EVK%20%E3%81%AE%20USB%20%E3%83%9B%E3%82%B9%E3%83%88%20pinctrl%20PAD%20%E3%81%8C%E3%82%BB%E3%82%AD%E3%83%A5%E3%82%A2%20%E3%83%AF%E3%83%BC%E3%83%AB%E3%83%89%E3%81%AB%E5%89%B2%E3%82%8A%E5%BD%93%E3%81%A6%E3%82%89%E3%82%8C%E3%81%A6%E3%81%84%E3%81%BE%E3%81%99%E3%80%82%E3%82%B5%E3%83%B3%E3%83%97%E3%83%AB%E3%82%B3%E3%83%BC%E3%83%89%E3%81%AE%E3%83%AC%E3%82%A4%E3%82%A2%E3%82%A6%E3%83%88%E3%81%AF%E6%AC%A1%E3%81%AE%E3%81%A8%E3%81%8A%E3%82%8A%E3%81%A7%E3%81%99%E3%80%82%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CBR%20%2F%3E%0A%3CPRE%20class%3D%22lia-code-sample%20language-markup%22%3E%3CCODE%20translate%3D%22no%22%3E.%0A%E2%94%9C%E2%94%80%E2%94%80%20atf%0A%E2%94%82%20%20%20%E2%94%94%E2%94%80%E2%94%80%200001-config-iomux-to-secure-write.patch%20--%26gt%3B%20%24%7BMY_ANDROID%7D%2Fvendor%2Fnxp-opensource%2Farm-trusted-firmware%0A%E2%94%9C%E2%94%80%E2%94%80%20kernel%0A%E2%94%82%20%20%20%E2%94%94%E2%94%80%E2%94%80%200001-Use-Trusty-OS-to-handle-iomux-registers-written-oper.patch%20--%26gt%3B%20%24%7BMY_ANDROID%7D%2Fvendor%2Fnxp-opensource%2Fkernel_imx%2F%0A%E2%94%9C%E2%94%80%E2%94%80%20trusty%0A%E2%94%82%20%20%20%E2%94%94%E2%94%80%E2%94%80%200001-Add-iomux-pinctrl-TEE-handler.patch%20--%26gt%3B%20%24%7BMY_TRUSTY%7D%2Ftrusty%2Fhardware%2Fnxp%0A%E2%94%94%E2%94%80%E2%94%80%20u-boot%0A%20%20%20%20%E2%94%94%E2%94%80%E2%94%80%200001-Use-Trusty-OS-to-handle-IOMUX-operation.patch%20--%26gt%3B%20%24%7BMY_ANDROID%7D%2Fvendor%2Fnxp-opensource%2Fuboot-imx%3C%2FCODE%3E%3C%2FPRE%3E%0A%3CBR%20%2F%3E%0A%3CBR%20%2F%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1477089%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CLINGO-LABEL%3EAndroid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ei.MX%208M%20%7C%20i.MX%208M%20Mini%20%7C%20i.MX%208M%20Nano%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
評価なし
バージョン履歴
最終更新日:
‎06-20-2022 07:42 PM
更新者: