Computing device and operating method for computing device

By sending control commands to the password module and checking the contents of the computer program and storage area, the problem of the computing device in the prior art execution of unsafe programs is solved, and the security and practicality are improved.

CN112236771BActive Publication Date: 2025-05-13ROBERT BOSCH GMBH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN201980040932.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-08-13
Filing Date
2019-05-22
Publication Date
2025-05-13
Estimated Expiration
2039-05-22

AI Technical Summary

Technical Problem

Existing computing devices lack effective security checks when executing computer programs, making it difficult to prevent execution of unsafe computer programs or programs compromised by attackers.

Method used

By sending a first control command to the cryptographic module, characterizing the allocation of the computer program and/or storage area, the cryptographic module checks the contents of the computer program or storage area to ensure its security.

Benefits of technology

Dynamic inspection of computer programs and storage area contents is realized, the security of the computing device is improved, and the execution of unsafe programs is prevented.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112236771B_ABST
    Figure CN112236771B_ABST
Patent Text Reader

Abstract

A computing device having at least one computing core for executing a first computer program, wherein the computing device is configured to access a storage device, in particular in order to load the first computer program, wherein the computing device is configured to send a first control command to at least one cryptographic module, the first control command characterizing the first computer program and / or a storage area of ​​the storage device assigned to the first computer program, wherein the cryptographic module is particularly configured to check the computer program characterized by the first control command or the storage area of ​​the storage device assigned to the first computer program, wherein the computing device is configured to execute the first computer program.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a computing device having at least one computing core for executing a first computer program, wherein the computing device is designed to access a storage device, in particular to load the first computer program. Such a computing device is used, for example, in a control device of a motor vehicle, for example in the form of a so-called embedded system.

[0002] The present disclosure also relates to a method for operating such a computing device. Summary of the invention

[0003] The object of the present invention is to specify a computing device having increased safety and increased availability.

[0004] This object is achieved in a computing device of the type mentioned at the outset in that the computing device is designed to send a first control command to at least one cryptographic module, the first control command characterizing the first computer program and / or a storage area of ​​the storage device assigned to the first computer program, wherein the cryptographic module is in particular designed to check the computer program characterized by the first control command or the storage area of ​​the storage device assigned to the first computer program, wherein the computing device is designed to execute the first computer program. Advantageously, this makes it possible to initiate a check of the first computer program by the cryptographic module. Advantageously, this provides the possibility of checking the content of the first computer program or the storage area storing the first computer program, for example, to check for deviations from a predeterminable content. Advantageously, this makes it possible, for example, to prevent the execution of an unsafe computer program or a computer program that has been corrupted by an attacker by the computing device. Further advantageously, one or more storage areas to be checked can be signaled to the cryptographic module by means of the first control command (for example, address information, which storage blocks should be checked), so that, for example, this information does not have to be preconfigured. Rather, one or more memory areas or computer programs to be checked can be signaled dynamically (for example during operation of the cryptographic module or the computing device) by means of the first control command, thereby further increasing flexibility.

[0005] In a preferred embodiment, the storage device can be arranged or provided outside the computing device (and in particular also outside the cryptographic module). However, in other preferred embodiments, the storage device can also be integrated into the computing device. In yet another preferred embodiment, a system, in particular a single-chip system (SoC) can advantageously also be provided, which has a computing device according to an embodiment, a storage device and a cryptographic module according to an embodiment.

[0006] In other preferred embodiments, the computing device is configured to receive a response of the cryptographic module to the first control command or to read the response from the cryptographic module (for example, from a storage area of ​​the cryptographic module to which the computing device can access in a read manner (preferably only read, not write)), wherein the response comprises, in particular, information about a check result of a computer program characterized by the control command or a check result of a storage area of ​​the storage device assigned to the first computer program.

[0007] In other preferred embodiments, it is provided that the cryptographic module is constructed to check the first computer program or at least one storage area using a key-based message authentication code CMAC (cipher-based Message Authentication Code). This makes the check particularly effective. For example, an Internet publication related to an exemplary design of the CMAC method can be called up at https: / / doi.org / 10.6028%2Fnist.sp.800-38b. The check result can be written to a storage area of ​​the cryptographic module or to the storage area, and the computing device can access the storage area in a read manner (preferably only read, not write). Therefore, in other preferred embodiments, the computing device can read the check result from this storage area of ​​the cryptographic module.

[0008] In other preferred embodiments, it is provided that the cryptographic module has a storage unit, which is preferably integrated into the cryptographic module, for storing at least one reference value and / or a reference layout of at least one storage area. In other preferred embodiments, the reference value can, for example, represent a CMAC value of a predeterminable storage content, which is comparable, for example, to a CMAC value determined when the cryptographic module checks at least one first computer program or storage area. If the determined CMAC value deviates from the reference value, it can be inferred that an inadmissible change has occurred to the storage area checked and, in particular, to the storage content of the computer program stored therein.

[0009] In other preferred embodiments, it is provided that the cryptographic module is constructed to perform the check according to the reference value. In these embodiments, the check includes, for example, forming a CMAC value according to the storage content of the first computer program or the at least one storage area and comparing the CMAC value formed in this way with the reference value, which is, for example, stored in a storage unit of the cryptographic module. Alternatively or additionally, in other preferred embodiments, the reference value can also be sent to the cryptographic module by the computing device with the aid of the first control command. Further alternatively or additionally, in other embodiments, multiple reference values ​​of multiple computer programs or storage areas to be checked can also be sent to the cryptographic module with the aid of the first control command.

[0010] In other preferred embodiments, the reference layout may contain one or more of the following information: a) the number of computer programs or storage areas in the storage device that can be accessed by the computing device, b) the address area (start address and / or end address) of the computer program or storage area in question, c) the length of the computer program or storage area in question, d) at least one reference value (e.g. CMAC value) of the computer program or storage area in question, e) data related to the cryptographic signature, such as the signature address and / or signature type and / or a reference to a superior certificate ("root certificate"). This information can preferably be stored in a data structure with a plurality of corresponding data fields.

[0011] In other preferred embodiments, the cryptographic module may use the reference value or reference layout to clarify the type and scope of the check of at least one computer program or storage area. For example, the input data set for the check (e.g., CMAC value formation) may be clarified based on the start address and the end address.

[0012] In other preferred embodiments, it is provided that the computing device is designed to execute the first computer program directly after sending the first control command to the cryptographic module, in particular without waiting for a response from the cryptographic module to the first control command and / or without reading the response from the cryptographic module. In these embodiments, the first computer program is therefore already executed by the computing device before the check of the first computer program by the cryptographic module is completed or the computing device reads the result of the check of the first computer program by the cryptographic module (for example, in the form of a response to the first control command). This ensures a particularly fast execution of the first computer program by the computing device and at the same time initiates the check of the first computer program by the cryptographic module at least with the aid of the first control command.

[0013] In other preferred embodiments, it is provided that the computing device is designed to wait for a response of the cryptographic module to the first control command or the response and / or to read the response from the cryptographic module, and to execute the first computer program only after receiving or reading the response. This enables a particularly secure execution of the first computer program, which is only performed after being checked by the cryptographic module.

[0014] In a further preferred embodiment, it is provided that the computing device is designed to control the operation of the computing device as a function of the response. Thus, for example, in the event of a negative check result of the first computer program by the cryptographic module (for example, due to an erroneous change or manipulation of the first computer program in the storage device), an error response can be initiated by the computing device and / or by the cryptographic module. The error response can, for example, provide at least one of the following measures: terminating the execution of the first computer program by the computing device (if possible), preventing the first computer program from being repeatedly or re-executed by the computing device, signaling an error state to an external unit, resetting the computing device, temporarily or permanently deactivating the computing device, deleting the first computer program from the storage device.

[0015] In other preferred embodiments, it is provided that a) the memory device is integrated into the computing device and / or b) the memory device is arranged outside the computing device.

[0016] Further preferred embodiments relate to a method for operating a computing device having at least one computing core for executing a first computer program, wherein the computing device is designed to access a storage device, in particular to load the first computer program, wherein the computing device sends a first control command to at least one cryptographic module, the first control command characterizing the first computer program and / or a storage area of ​​the storage device assigned to the first computer program, wherein the cryptographic module is designed to check the first computer program characterizing the control command or the storage area of ​​the storage device assigned to the first computer program, and wherein the computing device executes the first computer program.

[0017] In other preferred embodiments, it is provided that the computing device receives a response of the cryptographic module to the first control command or reads the response from the cryptographic module, wherein the response contains, in particular, information about a check result of a computer program characterized by the control command or a check result of a storage area of ​​the storage device assigned to the first computer program.

[0018] In other preferred embodiments, it is provided that the computing device executes the first computer program directly after sending the first control command to the cryptographic module, in particular without waiting for the cryptographic module's response to the first control command or the response and / or without reading the response from the cryptographic module (in particular before starting the first computer program).

[0019] Other preferred embodiments relate to a cryptographic module, in particular for at least one computing device according to an embodiment, wherein the cryptographic module is configured to receive a first control command from the computing device that characterizes a first computer program and / or a storage area of ​​the storage device that is assigned to the first computer program, wherein the cryptographic module is configured to check the computer program characterized by the first control command or the storage area of ​​the storage device that is assigned to the first computer program. As already described above, the check can be performed in other preferred embodiments using the CMAC method.

[0020] In a further preferred embodiment, it is provided that the cryptographic module is designed to determine a response to the first control command, wherein the response has in particular information about a check result of a computer program characterized by the control command or a check result of a storage area of ​​the storage device assigned to the first computer program.

[0021] Other preferred embodiments relate to a system having at least one computing device according to an embodiment, at least one storage device, and at least one cryptographic module according to an embodiment, wherein in particular the at least one computing device and the at least one storage device and the at least one cryptographic module are arranged on the same semiconductor substrate, in particular in the form of a SoC.

[0022] Further advantageous embodiments emerge from the disclosure of the present invention.

[0023] Further features, possible applications and advantages of the invention are apparent from the following description of exemplary embodiments of the invention, which are illustrated in the figures of the accompanying drawings. All features described or illustrated here constitute the subject matter of the invention individually or in any combination, regardless of their description or illustration in the description or drawings or the rest of the disclosure of the invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In the attached picture:

[0025] Figure 1 Schematically shows a simplified block diagram of a computing device according to one embodiment,

[0026] Figure 2 Schematically shows a simplified block diagram of a computing device according to another embodiment,

[0027] Figure 3 A simplified block diagram of another embodiment is schematically shown.

[0028] Figure 4 Schematically shows a simplified block diagram of a cryptographic module according to one embodiment,

[0029] Figure 5 A simplified flow chart of a method according to one embodiment is schematically shown,

[0030] Figure 6 A simplified flow chart of a method according to another embodiment is schematically shown.

[0031] Figure 7 schematically shows a simplified flow chart according to another embodiment, and

[0032] Figure 8 A data structure according to one embodiment is schematically shown. DETAILED DESCRIPTION

[0033] Figure 1 Schematically, a simplified block diagram of a computing device 100 according to one embodiment is shown. The computing device 100 has at least one computing core 110 for executing a first computer program PRG1, which is for example at least temporarily stored in a storage device 200 accessible to the computing device 100. The storage device 200 comprises, for example, a working memory (RAM) and / or a non-volatile memory (for example a flash EEPROM).

[0034] In the present case, the computing device 100 accesses the storage device 200 by means of a first data connection DV1, which may have, for example, at least one address and / or data bus. In other embodiments, a boot loader BL for the computing device 100 and, if necessary, other computer programs (not shown) may also be stored in the storage device 200.

[0035] The computing device 100 is configured to load and execute a first computer program PRG1. The computing device 100 is also configured to send a first control command A1 characterizing the first computer program PRG1 and / or a storage area (e.g., an address area in the address space of the storage device 200) assigned to the first computer program PRG1 to at least one cryptographic module 300. The cryptographic module 300 is configured to check the computer program PRG1 characterized by the first control command A1 or the storage area of ​​the storage device 200 assigned to the first computer program PRG1. This advantageously enables the cryptographic module 300 to initiate and execute a check of the first computer program PRG1. Advantageously, this provides the possibility of checking the content of the first computer program PRG1 or the storage area storing the first computer program PRG1, for example, checking for deviations from predefined content. This advantageously prevents the computing device 100 from executing an unsafe computer program PRG1 or a computer program PRG1 that has been corrupted by an attacker, for example. It is further advantageous that one or more memory areas to be checked can be signaled to the cryptographic module 300 by means of the first control command A1 (e.g. address information, which memory blocks should be checked), so that, for example, this information does not have to be preconfigured. Rather, one or more memory areas to be checked or the computer program PRG1 can be signaled dynamically by means of the first control command A1 (e.g. during the operation of the cryptographic module 300 or the computing device 100), thereby further increasing flexibility.

[0036] In other preferred embodiments, the storage device 200 can be arranged or disposed outside the computing device 100 (and in particular also outside the cryptographic module 300). The cryptographic module 300 can access the storage device 200, for example, via a second data connection DV2, which in other embodiments can also be constructed identically or similarly to the first data connection DV1.

[0037] However, in other preferred embodiments, see Figure 2 The storage device 200a can also be integrated into the computing device 100a. The computing core 110 can access the storage device 200a via the data connection DV1', and the cryptographic module 300 can access the storage device 200a via the data connection DV2'. The control command for starting the check of the first computer program PRG1 is in Figure 2 Indicated by reference symbol A1'.

[0038] In still other preferred embodiments, see Figure 3It is also advantageous to provide a system 1000, in particular a single-chip system (SoC) 1000, which has a computing device 100, a storage device 200 and a cryptographic module 300. All components 100, 200, 300 are preferably arranged on the same semiconductor substrate 1000a.

[0039] Figure 4 A simplified block diagram of a cryptographic module 300 according to one embodiment is schematically shown. The cryptographic module 300 has a computer program PRG1 ( Figure 1 ) and a storage unit 302 for at least one reference value R and / or reference layout of the computer program PRG1, and a computing unit 304, which is configured to perform the above-mentioned check on the computer program PRG1 and is preferably completely configured as a hardware circuit. Alternatively, the computing unit 304 can also have a computing core 304a and a storage device 304b for operating software, which controls the operation of the cryptographic module 300. The cryptographic module 300 also has a result storage unit 306, the computing device 100 ( Figure 1 , 3 )、100a( Figure 2 ) can access storage unit 306 in a read manner but not in a write manner.

[0040] Figure 5 A simplified flowchart of a method according to an embodiment is schematically shown. In step 400, the computing device 100 ( Figure 1 ) sends a control command A1 to the cryptographic module 300, which control command in the present case exemplarily characterizes the first computer program PRG1 or its storage area in the storage device 200. The cryptographic module 300 is thereby informed of which computer program or which storage area of ​​the storage device 200 should be checked. In step 410 ( Figure 5 ), the computing device 100 executes the first computer program PRG1, in particular without waiting for the check. In an optional step 420, the computing device 100 executes the first computer program PRG1, for example directly from Figure 4 The result storage unit 306 reads the response or result A2 ( Figure 3 ). In an optional step 430, the computing device 100 controls its operation as a function of the result A2. The response or result A2 can, for example, contain information about the result of the check of the computer program PRG1 characterized by the control command A1 or the result of the check of the storage area of ​​the memory device 200 assigned to the first computer program PRG1.

[0041] In a further preferred embodiment, it is provided that the cryptographic module 300 is designed to check the first computer program PRG1 or at least one storage area using a key-based message authentication code CMAC (Cipher-based Message Authentication Code). This makes the check particularly effective. For example, an Internet publication on an exemplary design of the CMAC method can be found at https: / / doi.org / 10.6028%2Fnist.sp.800-38b. The result of the check can be written, for example, to the result storage area 306 ( Figure 4 ), the computing device 100, 100a can access the result storage area 306 in a read manner (preferably only read but not write). Therefore, in other preferred embodiments, the computing device 100, 100a can read the inspection result from the storage area 306 of the cryptographic module 300. Alternatively or additionally, in other embodiments, the cryptographic module 300 can also send the response or result A2 to the computing device 100, 100a.

[0042] Figure 6 Schematically shows a method for operating a cryptographic module 300 ( Figure 4 ) is a simplified flow chart of the method. In step 500 ( Figure 6 ), the cryptographic module 300 receives a first control command A1 from the computing device 100, 100a. In step 510, the cryptographic module 300 checks the first computer program PRG1 characterized by the first control command A1, for example using a CMAC calculation. In an optional step 520, the cryptographic module 300 determines a response A2 to the first control command A1, wherein the response A2 has information about the result of the check 510 of the computer program PRG1 characterized by the control command A1 or the result of the check 510 of the storage area of ​​the storage device 200, 200a assigned to the first computer program PRG1.

[0043] Figure 7 A simplified block diagram of another embodiment is schematically shown. Area 100' substantially includes steps performed on the computing device 100 side, and area 300' substantially includes steps performed on the cryptographic module 300 side. In step S1, the cryptographic module 100 is activated or initialized. In step S2, the computing device 100 is activated or initialized. In some embodiments, steps S1, S2 can preferably be performed at least substantially simultaneously with each other, or staggered in time with each other.

[0044] After initialization S2, the computing device 100 executes a startup program PRG0 (eg, a boot loader BL ( Figure 1 ) or a program started by the boot loader BL). In step S3, a first control command A1' is sent to the cryptographic module 300, which first control command characterizes the first computer program PRG1 to be checked by the cryptographic module 100, for example describes the address area allocated to the first computer program in the storage device 200, 200a. The computing device 100 then directly executes the first computer program PRG1, see step S3a, in particular without waiting for the result of the check of the first computer program PRG1 by the cryptographic module 300. As a result, the first computer program PRG1 becomes available in the computing device, see step S3a. Figure 7 Block PRG1.

[0045] After the cryptographic module 300 has obtained the first control command A1', see step S4, the cryptographic module 300 checks the first computer program PRG1 in step S5. The check in step S5 includes, for example, forming a CMAC value based on the first computer program PRG1 or the corresponding storage content of the storage device 200, 200a storing the first computer program PRG1 and comparing it with a reference CMAC value R. The cryptographic module 300 can, for example, obtain information about which storage area is to be checked and which (for example CMAC) reference value R is to be used for this purpose from the reference data (and / or the first control command A1') stored in the storage unit 302. In step S6, the cryptographic module 300 preferably stores the check result from step S5 internally (in particular in the memory 302 or a storage area that no other unit can access in a read or write manner) and sends a corresponding response A2' to the computing device 100 in step S7. Alternatively, the check result from step S5 can also (if necessary additionally) be stored in step S6 in result storage unit 306, from which it can be read by computing device 100. In other embodiments, it is also conceivable that once check S5 has been completed, the cryptographic module sends an interrupt request (“interrupt”) A2′ to the computing device.

[0046] As referenced above Figure 3As already mentioned, in other preferred embodiments, it is provided that the cryptographic module 300 has a storage unit 302, preferably integrated in the cryptographic module 300, for storing at least one reference value R and / or a reference layout of at least one storage area or at least one computer program PRG1 to be checked. In other preferred embodiments, the reference value R can represent, for example, a CMAC value of the computer program PRG1 or of a predeterminable memory content, which is comparable, for example, to a CMAC value determined when the cryptographic module checks at least one first computer program or storage area. If the determined CMAC value deviates from the reference value R, it can be inferred that an inadmissible change has occurred to the storage content of the checked storage area.

[0047] In other preferred embodiments, it is provided that the cryptographic module 300 is designed to perform the check according to the reference value R. In these embodiments, the check comprises, for example, forming a CMAC value according to the first computer program PRG1 or the storage content of at least one storage area, and comparing the CMAC value formed in this way with the reference value R ( Figure 4 ), which is for example stored in the storage unit 302 of the cryptographic module 300. Alternatively or additionally, in other preferred embodiments, the reference value R can also be sent by the computing device 100, 100a to the cryptographic module 300 by means of the first control command A1. Further alternatively or additionally, in other embodiments, multiple reference values ​​R of multiple storage areas or computer programs PRG1, BL, ... to be checked can also be sent to the cryptographic module 300 by means of the first control command A1.

[0048] In other preferred embodiments, the reference layout may contain one or more of the following information: a) the number of computer programs or storage areas in the storage device that the computing device can access, b) the address area (start address and / or end address) of the computer program or storage area in question, c) the length of the computer program or storage area in question, d) at least one reference value (e.g. CMAC value) of the computer program or storage area in question, e) data related to the cryptographic signature, such as the signature address and / or the signature type and / or a reference to a superior certificate ("root certificate"). This information can preferably be stored in a data structure with a plurality of corresponding data fields, see Figure 8 , for example, in storage unit 302 ( Figure 3 ).

[0049] In other preferred embodiments, the cryptographic module 300 may use the aforementioned reference values ​​or reference layouts to clarify the type and scope of the check on at least one computer program PRG1 or storage area. For example, the set of input data for the check (e.g., CMAC value formation) may be clarified based on the start address and the end address.

[0050] In other particularly preferred embodiments, it is provided that the computing device 100, 100a is designed to directly send 400 (the first control command A1) to Figure 5 ) to the cryptographic module 300, in particular without waiting for a response of the cryptographic module 300 to the first control command A1 or the response and / or without reading 420 the response from the cryptographic module 300. In these embodiments, the first computer program PRG1 is therefore already executed by the computing device 100, 100a before the check of the first computer program PRG1 by the cryptographic module 300 is completed or before the computing device 100, 100a reads the result of the check of the first computer program PRG1 by the cryptographic module 300 (for example in the form of a response A2, A2' to the first control command) (see Figure 7 This ensures that the first computer program PRG1 is executed particularly quickly by the computing device 100 , 100 a and that, at the same time, the checking of the first computer program PRG1 by the cryptographic module 300 is already initiated by means of the first control command.

[0051] In other preferred embodiments, it is provided that the computing device 100, 100a is designed to wait for the response of the cryptographic module 300 to the first control command A1 or the response A2 and / or read the response A2 from the cryptographic module 300, and execute the first computer program PRG1 only after receiving or reading the response. This enables a particularly safe execution of the first computer program PRG1, which is only performed after being checked by the cryptographic module 300.

[0052] In a further preferred embodiment, as already mentioned above, the computing device 100, 100a is designed to control the operation of the computing device 100, 100a as a function of the response A2. Thus, for example, in the case of a negative result of the check of the first computer program PRG1 by the cryptographic module 300 (for example due to an erroneous change in the storage device 200, 200a or manipulation of the first computer program (for example by an attacker)), an error reaction can be initiated by the computing device 100, 100a and / or by the cryptographic module 300. The error reaction can, for example, provide at least one of the following measures: aborting the execution of the first computer program PRG1 by the computing device 100, 100a (if possible), preventing the first computer program PRG1 from being repeated or re-executed by the computing device 100, 100a, signaling an error state to an external unit, resetting (resetting) the computing device 100, 100a (in particular by the cryptographic module 300), temporarily or permanently deactivating the computing device 100, 100a, deleting the first computer program PRG1 from the storage device 200, 200a.

[0053] The principles according to the embodiments have the following advantages in particular: a) manipulation of the contents of the storage devices 200, 200a (and changes due to errors), such as manipulation of the computer programs PRG1, BL stored in the storage devices 200, 200a, is effectively detected during the runtime of the computing devices 100, 100a and the cryptographic module 300 ("runtime manipulation detection", RTMD); b) secure booting (i.e., starting) of the software PRG1 (e.g., application software) on the computing device 200 is ensured ("trusted boot"); c) advantageously, the computer program PRG1 or other data subsequently stored in the storage devices 200, 200a can also be checked according to the principles according to the embodiments ("secure flashing"); d) access to cryptographic keys provided by the cryptographic module if necessary and access to other sensitive information can be controlled based on the check according to the embodiments ("security access”), e) the boot sequence (the sequence in which computer programs are processed when the computing unit 100 is started) can be selected arbitrarily without compromising security; f) by using the cryptographic module 300, if necessary in conjunction with a dedicated hardware circuit, efficient and secure cryptographic functions, such as CMAC formation, for example based on 128-bit AES (Advanced Encryption Standard), g) by setting, for example, according to Figure 8DS, the operation of the cryptographic module 300 can be flexibly adapted to different memory layouts and other configurations of the computing devices 100, 100a, h) by transmitting a first control command A1, the program PRG1 or the memory area to be checked can be dynamically (for example, during the operation of the cryptographic module) signaled to the cryptographic module 300, i) by also executing 410 ( immediately before the (complete) execution of the check by the cryptographic module 300 Figure 5 ) a first computer program PRG1, resulting in a particularly short startup time of the computer program PRG1.

Claims

1. A computing device (100; 100a) having at least one computing core (110) for executing a first computer program (PRG1), wherein the computing device (100; 100a) is configured to access a storage device (200; 200a) in order to load the first computer program (PRG1), wherein the computing device (100; 100a) is configured to send (400) a first control command (A1; A1') to at least one cryptographic module (300), the first control command characterizing the first computer program ( a computer program (PRG1) characterized by the first control command (A1) or a storage area of ​​the storage device (200; 200a) assigned to the first computer program (PRG1), wherein the cryptographic module (300) is designed to check (510) the computer program (PRG1) characterized by the first control command (A1) or a storage area of ​​the storage device (200; 200a) assigned to the first computer program (PRG1), wherein the computing device (100; 100a) is designed to execute (410) the first computer program (PRG1), in, The computing device (100; 100a) is designed to receive a response (A2; A2') of the cryptographic module (300) to the first control command (A1) or to read (420) the response (A2; A2') from the cryptographic module (300), wherein the response (A2; A2') contains information about a check result of a first computer program (PRG1) characterized by the control command (A1; A1') or a check result of a storage area of ​​the storage device (200; 200a) assigned to the first computer program (PRG1), and The computing device (100; 100a) is configured to control (430) the operation of the computing device (100; 100a) according to the response (A2; A2').

2. The computing device (100; 100a) according to claim 1, wherein: The computing device (100; 100a) is designed to execute the first computer program (PRG1) directly after sending (400) the first control command (A1; A1') to the cryptographic module (300).

3. The computing device (100; 100a) according to claim 2, wherein: The computing device (100; 100a) is configured to execute the first computer program (PRG1) directly after sending (400) the first control command (A1; A1') to the cryptographic module (300), without waiting for a response of the cryptographic module (300) to the first control command (A1; A1') or the response (A2) and / or without reading (420) the response (A2) from the cryptographic module (300).

4. The computing device (100; 100a) according to any one of the preceding claims 1 to 3, wherein: The computing device (100; 100a) is configured to wait for a response of the cryptographic module (300) to the first control command (A1; A1') or the response (A2; A2') and / or to read the response (A2; A2') from the cryptographic module (300), and to execute the first computer program (PRG1) only after receiving or reading (420) the response (A2; A2').

5. The computing device (100; 100a) according to any one of the preceding claims 1 to 3, wherein: a) the storage device (200; 200a) is integrated into the computing device (100; 100a), and / or wherein, b) the storage device (200; 200a) is arranged outside the computing device (100; 100a).

6. A method for operating a computing device (100; 100a), the computing device having at least one computing core (110) for executing a first computer program (PRG1), wherein the computing device (100; 100a) is designed to access a storage device (200; 200a) in order to load the first computer program (PRG1), wherein the computing device (100; 100a) sends (400) a first control command (A1) to at least one cryptographic module (300), the first control command characterizing the first computer program (PRG1). a computer program (PRG1) and / or a storage area of ​​the memory device (200; 200a) assigned to the first computer program (PRG1), wherein the cryptographic module (300) is designed to check (510) the computer program (PRG1) characterized by the control command (A1) or the storage area of ​​the memory device (200; 200a) assigned to the first computer program (PRG1), wherein the computing device (100; 100a) executes (410) the first computer program (PRG1), in, The computing device (100; 100a) receives a response (A2; A2') of the cryptographic module (300) to the first control command (A1; A1') or reads (420) the response (A2; A2') from the cryptographic module (300), wherein the response (A2; A2') contains information about a check result of the computer program (PRG1) characterized by the control command (A1; A1') or a check result of a storage area of ​​the storage device (200; 200a) assigned to the first computer program (PRG1), The computing device (100; 100a) controls (430) the operation of the computing device (100; 100a) according to the response (A2; A2').

7. The method according to claim 6, wherein: The computing device (100; 100a) executes the first computer program (PRG1) after sending the first control command (A1; A1') to the cryptographic module (300).

8. The method according to claim 7, wherein: The computing device (100; 100a) executes the first computer program (PRG1) directly after sending the first control command (A1; A1') to the cryptographic module (300).

9. The method according to claim 7, wherein: The computing device (100; 100a), after sending the first control command (A1; A1') to the cryptographic module (300), executes the first computer program (PRG1) without waiting for a response of the cryptographic module (300) to the first control command (A1; A1') or the response (A2; A2') and / or without reading the response (A2; A2') from the cryptographic module (300).

10. A cryptographic module (300) for at least one computing device (200; 200a) according to any one of claims 1 to 5, wherein the cryptographic module (300) is designed to receive (500) from the computing device (200; 200a) a first control command (A1; A1') characterizing a first computer program (PRG1) and / or a storage area of ​​the storage device (200; 200a) assigned to the first computer program (PRG1), wherein the cryptographic module (300) is designed to check (510) the computer program (PRG1) characterizing the first control command (A1; A1') or the storage area of ​​the storage device (200; 200a) assigned to the first computer program (PRG1).

11. The cryptographic module (300) according to claim 10, wherein: The cryptographic module (300) is designed to determine (520) a response (A2; A2') to the first control command (A1; A1').

12. The cryptographic module (300) according to claim 11, wherein: The response (A2; A2') contains information about a result of a check of the computer program (PRG1) characterized by the control command (A1; A1') or a result of a check of a storage area of ​​the memory device (200; 200a) assigned to the first computer program (PRG1).

13. The cryptographic module (300) according to any one of claims 10 to 12, wherein: The cryptographic module (300) is designed to perform a check (510) on at least one computer program (PRG1) or a memory area using a key-based message authentication code CMAC.

14. System (1000) having at least one computing device (100; 100a) according to any one of claims 1 to 5, at least one storage device (200; 200a) and at least one cryptographic module (300) according to any one of claims 10 to 12.

15. The system according to claim 14, wherein the at least one computing device (100; 100a) and the at least one storage device (200; 200a) and the at least one cryptographic module (300) are arranged on a same semiconductor substrate (1000a).

Citation Information

Patent Citations

  • Memory card and security method therefor

    US20080141042A1

  • Method for verifying a memory block of a nonvolatile memory

    US20130117578A1

  • Method for manipulation protection

    US20160241404A1