Home Gateway: the next battle ground Majid Bemanian Security & Networking Marketing www.imgtec.com
Home Gateway in Transition The next battleground Fast changing consumer demands solutions that allow operators to rapidly introduce new services Home Energy Home Security Gaming Household Appliance Monitor and mange home environment and security Home Gateway Secure personal healthcare, fitness and video exchange Broadband Conn. Energy management & household appliances VoIP Connected medicine cabinet, pantries, Public Hotspots over residential CPE Impact CPEs become increasingly complex Lifecycle of CPEs mismatch with rapid pace of innovation Home Services Imagination Technologies US Summit May 2015 2
Home Gateway Challenges Resiliency, Scalability, Protection & Service Provisioning Broadband Home Gateway Local Area Gaming LTE DSL Cable PON Baseline S/W (Routing, Switching, Networking) Wi-Fi (private hotspot) 100/1000Mbit Storage (SATA, USB3.0) Public Hotspot IoT Services Zigbee Bluetooth 802.11n/ac Home Energy Home Appliance Home Security Imagination Technologies US Summit May 2015 3
Secure Fabric OmniShield How to Secure a Platform? Hardware supported virtualized + Hardware supported virtualized GPU + Secure Fabric + Trusted + Virtualized or para-virtualized connectivity and offloads + Root of Trust = Base-Line Services IoT Service Trusted MIPS Virtualized Cores PowerVR Virtualized GPU Cores Ensigma NPU Public Hotspot Service Deployment of multiple containers fully isolated and protected Ensigma RPU Root of Trust Memory Imagination Technologies US Summit May 2015 4
Hardware Software Home Gateway True Isolation Virtualization Benefits Mature and proven technology H/W Firewall high level of security Secure services can only affect their container Highest flexibility and performance IP protection provided through system partitioning Secure Extranet Broadband App s Network Interface Baseline Software IPC Trusted MIPS Heterogeneous Platform Secure Fabric Offloads RoT DRAM Secure Intranet LAN App s Kernel Network Interface WAN LAN Imagination Technologies US Summit May 2015 5
Breaking the 2-Zone Barrier Secure heterogeneous operation Binding of + GPU into secure containers VM0 VM1 VM7 Binding VM1 VM7 Up to 7 Secure containers (current configuration) Concurrent and independent Secure operation Coherent and Isolated operation Trusted Env. Secure Rich App/ Rich App/ Os Secure Containers (scales to 255) up to 31 GPU up to 7 Trusted VZ I6400 Cluster RoT GPU Cluster H/W VZ Guest-ID H/W VZ Domain-ID Secure Fabric Heterogeneous Operation Domain-ID DDR Memory R TE VM1 VM7 Unified Memory Isolated and Protected +GPU bindings Imagination Technologies US Summit May 2015 6
Root Guest H/W Thread Realtime secure operation in virtual environment Intersection of Isolation and Concurrency Isolation Concurrency Virtualization RT RT Single Thread H/W VZ Context Switch RT RT RT switches context enforcing CoS, QoS and isolation. Response time adequate for many applications. H/W Multi-Threading enable concurrent operation of Applications. Context switch at rate of clock T0 Multi-Threading T1 T2 Quad Thread Concurrent RT RT RT RT T3 t 0 t 1 t 2 t 3 t 4 t 5 t 0 t 5 Imagination Technologies US Summit May 2015 7
Root Root Guest Guest H/W Thread Realtime secure operation in virtual environment Isolation Concurrent Multi-domain Execution Environment Zero overhead & real-time Concurrency Virtualization Virtualized Multi-Threading Multi-Threading RT RT RT RT RT RT Single Thread H/W VZ Context Switch RT RT RT T0 RT RT T1 T0 T1 T2 Quad Thread Concurrent t t 0 t 1 t 2 t 3 t 4 t 0 t 5 5 t 0 t 3 t 7 T2 Quad Thread RT RT T3 RT RT T3 Imagination Technologies US Summit May 2015 8
Root Root Guest Guest H/W Thread Realtime secure operation in virtual environment Automotive System Use case Navigation Linux Virtualization Lower Priority / Framerate RT RT RT Cluster Secure RT High Priority 60 FPS Multi-Threading RT RT Single Thread H/W VZ Context Switch Infotainment Linux/Android Medium Priority / Framerate RT RT RT T0 RT T1 T0 T1 T2 T3 Quad Thread ADAS Linux Variable Priority GPU Compute Concurrent t t 0 t 1 t 2 t 3 t 4 t 0 t 5 5 T2 Quad Thread RT RT T3 RT RT RT t 0 t 3 Imagination Technologies t7 US Summit May 2015 9
Resiliency, protection & services provisioning Home gateway use case Broadband Home Gateway Local Area Gaming LTE DSL Cable PON Baseline S/W (Routing, Switching, Networking) Wi-Fi (private hotspot) 100/1000Mbit Storage (SATA, USB3.0) Public Hotspot IoT Services Zigbee Bluetooth 802.11n/ac Home Energy Home Appliance Secure Domain Applications Secure Domain Applications Secure Domain Applications Home Security MIPS trusted hypervisor Secure Fabric (NoC) Memory Ensigma RPU/NPU Imagination Technologies US Summit May 2015 10
Summary Virtualization is indispensable to the future of embedded system design A virtualized environment offers flexible software management and integration 1. Hardware firewall-grade security 2. Scalability 3. Reliability OmniShield is the foundation of providing multiple Trusted Execution Domains MIPS Multi-Threading enables real-time operation of trusted functions w/ zero penalty Total cost of ownership is dramatically reduced OmniShield is the right technology for the secure digital world Imagination Technologies US Summit May 2015 11
Thank you! www.imgtec.com