Cryptographic modules and methods for operating the same

By designing a cryptographic module that can receive the first control instructions and perform dynamic verification based on CMAC, the problem that the cryptographic module in the prior art is difficult to effectively control the operation of the computing device, and efficient and flexible storage area content inspection is realized to prevent unsafe program execution.

CN112313651BActive Publication Date: 2025-05-09ROBERT BOSCH GMBH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN201980041324.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-08-13
Filing Date
2019-05-22
Publication Date
2025-05-09
Estimated Expiration
2039-05-22

AI Technical Summary

Technical Problem

Existing cryptographic modules are difficult to effectively temporarily control the operation of computing devices, especially when dynamic verification of storage area contents is required, and they lack flexibility and efficiency.

Method used

A cryptographic module is designed, which can receive the first control instruction, dynamically verify the contents of the storage area accessible by the computing device, perform efficient verification through the key-based message authentication code CMAC, and control the operation of the computing device according to the verification results.

Benefits of technology

It realizes dynamic and efficient verification of the contents of the storage area of ​​the computing device, improves the practicality and flexibility of the password module, and can effectively prevent the execution of computer programs that are unsafe or compromised by attackers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112313651B_ABST
    Figure CN112313651B_ABST
Patent Text Reader

Abstract

A cryptographic module for at least temporarily controlling the operation of at least one computing device, wherein the cryptographic module is configured to check at least one storage area of ​​a storage device that is accessible to the computing device; and the cryptographic module is configured to control the operation of the at least one computing device based on the check; wherein the cryptographic module is configured to receive a first control instruction from the computing device, the first control instruction characterizing at least one storage area of ​​the storage device to be checked; and the cryptographic module is configured to check the storage area characterized by the first control instruction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a cryptographic module and also to an operating method for such a cryptographic module. Background Art

[0002] From DE 10 2009 046436 A1 an encrypted hardware module is known. Summary of the invention

[0003] The object of the present invention is to specify a cryptographic module having increased usability.

[0004] In the case of a cryptographic module of the type mentioned at the outset, this object is achieved in that the cryptographic module is designed to at least temporarily control the operation of at least one computing device; wherein the cryptographic module is designed to check at least one storage area of ​​a storage device that is accessible to the computing device; and the cryptographic module is designed to control the operation of the at least one computing device as a function of the check; wherein the cryptographic module is designed to receive a first control instruction from the computing device, the first control instruction characterizing at least one storage area of ​​the storage device to be checked; and the cryptographic module is designed to check the storage area characterized by the first control instruction. This advantageously provides the possibility of checking the content of a storage area, for example, as a function of deviations from predeterminable content. This advantageously makes it possible, for example, to prevent the execution of an unsafe computer program or a computer program that has been compromised by an attacker from being executed by the computing device. Further advantageously, the storage area or storage areas to be checked (for example, address information, which storage blocks to be checked) can be signaled to the cryptographic module by means of the first control instruction, so that, for example, this information does not have to be preconfigured. Rather, the memory area or areas to be checked can be signaled dynamically (for example during operation of the cryptographic module or the computing device) by means of the first control instruction, thereby further increasing flexibility.

[0005] In preferred embodiments, the storage device can be arranged outside the cryptographic module and the computing device. However, in other preferred embodiments, the storage device can also be integrated into the computing device. In other preferred embodiments, a system on a chip (SoC) can also be advantageously provided, which has a computing device, a storage device and at least one cryptographic module according to these embodiments.

[0006] In other preferred embodiments, the computing device can have at least one computing core and / or a microprocessor and / or a microcontroller or the like.

[0007] In a further preferred embodiment, it is provided that the cryptographic module is designed to perform a check on at least one storage area using a key-based message authentication code CMAC (Cipher-based Message Authentication Code). This allows a particularly efficient check to be achieved. Internet publications on exemplary embodiments of the CMAC method are available, for example, at https: / / doi.org / 10.6028%2Fnist.sp.800-38b Can be retrieved below.

[0008] In a further preferred embodiment, it is provided that the cryptographic module has a storage unit, preferably integrated into the cryptographic module, for storing at least one reference value and / or a reference layout for at least one memory area. In a further preferred embodiment, the reference value can, for example, represent a CMAC value for a predeterminable memory content, which is comparable, for example, to a CMAC value that has been determined when checking at least one memory area by the cryptographic module. If the determined CMAC value deviates from the reference value, an inadmissible change in the memory content of the checked memory area can be inferred.

[0009] In other preferred embodiments, it is provided that the cryptographic module is designed to perform a check based on a reference value. In these embodiments, the check includes, for example, forming a CMAC value based on the storage content of at least one storage area and comparing the CMAC value formed in this way with a reference value, such as the reference value is stored, for example, in a storage unit of the cryptographic module. Alternatively or in addition, in other preferred embodiments, the reference value can also be sent to the cryptographic module by means of the first control instruction. Further alternatively or in addition, in other embodiments, multiple reference values ​​for multiple storage areas to be checked can also be sent to the cryptographic module by means of the first control instruction.

[0010] In other preferred embodiments, the reference layout may contain one or more of the following information: a) the number of storage areas in the storage device, which are accessible to the computing device, b) the address range of the relevant storage area (starting address and / or end address), c) the length of the relevant storage area, d) at least one reference value (e.g. CMAC value) for the relevant storage area, e) data about the encrypted signature, such as the signature address and / or signature type and / or a reference to a superior certificate ("root certificate"). This information may preferably be stored in a data structure having a plurality of corresponding data fields.

[0011] In other preferred embodiments, the cryptographic module can use the aforementioned reference values ​​or reference layouts to determine the type and scope of the check of at least one storage area. For example, based on the start address and the end address, a set of input data for the check (e.g., CMAC value formation) can be determined.

[0012] In other preferred embodiments, it is provided that the cryptographic module is designed to keep the computing device in a reset state, wherein in particular the cryptographic module is designed to keep the computing device in a reset state until the test is completed. This prevents the computing device from executing a computer program corresponding to the storage area to be tested as long as the test has not yet been completed. While the computing unit is held in the reset state, the computing unit cannot execute the computer program. Particularly advantageously, for the initialization of a system having a cryptographic module and a computing device, the time expiration can also be set so that: the cryptographic module is first activated; and directly after the activation of the cryptographic module, the cryptographic module puts the computing device in a reset state in order to prevent the execution of software from the storage area that may not have been checked by the computing device.

[0013] In a further preferred embodiment, it is provided that the cryptographic module is designed to ascertain within the scope of a check whether the content of the at least one memory area corresponds to a predefinable memory content and to terminate the reset state for the computing device if the check has shown that the content of the at least one memory area corresponds to the predefinable memory content. It can then be assumed that the content of the at least one memory area is in compliance with the specification, that is to say in particular has not been manipulated.

[0014] In a further preferred embodiment, it is provided that the cryptographic module is designed to keep the computing device in the reset state further if the check has shown that the content of the at least one memory area does not correspond to the predefinable memory content. In a further preferred embodiment, the check whether the content of the at least one memory area corresponds to the predefinable memory content can be performed by forming a CMAC value based on the actual memory content and comparing the CMAC value obtained in this way with a reference CMAC value.

[0015] In other preferred embodiments, it is provided that at least one storage area has at least one computer program for the computing device, in particular a boot loader or a boot manager, which is provided for execution on the computing device. As a result, the boot loader can advantageously already be checked by the cryptographic module, that is to say the computer program for the computing device which is usually executed as the first program when the computing device is initialized and which controls, for example, which (other) computer programs are started or executed by the computing device. This advantageously ensures that, directly after the computing device is initialized, only a computer program previously checked by the cryptographic module is executed by the computing device, or at least the boot loader is not manipulated.

[0016] In other preferred embodiments, the above-described inspection can be performed for storage contents or computer programs different from the boot loader mentioned, for example, for computer programs to be executed after the startup process (boot) of the computing device. In this case, corresponding advantages are obtained for the continued operation of the computing device. In particular, it can be prevented that the computer program that is compromised is executed by the computing device. Particularly advantageously, it can also be ensured that it is not possible to compromise, for example, a communication to be protected by cryptographic technology (for example, by mixing in a manipulated computer program) from the beginning (for example, from the system startup), and the computing device (for example, in order to exchange data with another component) is to perform the communication, and the manipulated computer program abuses or transmits to an unauthorized recipient a (secret) encrypted key that may be processed. In other advantageous embodiments, the computing device can advantageously (especially dynamically) notify the password module with a signal by means of a first control instruction (and or by means of other (comparable to the first control instruction) control instructions: which other storage contents or computer programs are to be checked by the password module.

[0017] In other preferred embodiments, it is provided that the cryptographic module is designed to provide the computing device with first data, in particular an encrypted key, wherein in particular the cryptographic module is designed to make the first data only partially or not even available to the computing device as a result of a check. If, for example, within the scope of the above-described check (for example, when comparing corresponding CMAC values), it is found that the content of the checked storage area corresponds to a predeterminable value, it can be inferred that there is original, unmanipulated software and the computing device can be allowed to access the first data, in particular the encrypted key, stored in the cryptographic module. However, if the above-described check shows that the content of the checked storage area does not correspond to the predeterminable value, that is, the checked software has potentially been manipulated, it can be provided that the cryptographic module completely prohibits the computing device from accessing the encrypted key or other first data stored in the cryptographic module or available via the cryptographic module, thereby advantageously preventing the computing device from removing the encrypted key from the cryptographic module under the control of the manipulated software. In other preferred embodiments, it is also conceivable that, depending on the type of verified storage content, the computing device is given access to a first subset of encrypted keys stored in the cryptographic module, but not to a second subset of encrypted keys.

[0018] In other preferred embodiments, it is provided that the cryptographic module is at least partially, in particular completely, designed as a hardware circuit. In other embodiments, it can be provided that the cryptographic module has at least one computing core and / or a working memory (RAM) and / or a non-volatile memory (e.g. a flash EEPROM) and / or at least one cryptographic unit (preferably at least partially, further preferably completely designed as a hardware circuit), which is designed, for example, to perform a CMAC calculation and / or to perform a comparison of a plurality of CMAC values ​​(e.g. determined CMAC values / reference CMAC values ​​for a specific storage area).

[0019] In other preferred embodiments, it is provided that the cryptographic module is designed to check the boot loader of the computing device, for example by means of a CMAC calculation, and after successful checking of the boot loader, to release the execution of the boot loader (for example by releasing the reset state of the computing device), and preferably, in particular after releasing the boot loader, to wait for a first control instruction, which can be output, for example, under the control of the boot loader. This advantageously ensures that in a manner consistent with the principle of these embodiments, both the boot loader of the computing device can be checked (in particular, the first control instruction of the computing device can be successful without the computing device already being actively operating for this purpose), and one or more further computer programs for the computing device can be checked, wherein after successful checking of the boot loader of the computing device, the computing device can advantageously determine by means of the first control instruction itself which (other) storage areas or computer programs (in addition to the already checked boot loader) are to be checked by the cryptographic module.

[0020] Other preferred embodiments relate to a method for operating a cryptographic module for at least temporarily controlling the operation of at least one computing device, wherein the cryptographic module checks at least one storage area of ​​a storage device that is accessible to the computing device, and based on the check, the cryptographic module controls the operation of the at least one computing device, wherein the cryptographic module receives a first control instruction from the computing device, the first control instruction characterizing at least one storage area of ​​the storage device to be checked, and the cryptographic module checks the storage area characterized by the first control instruction.

[0021] Other preferred embodiments relate to a computing device having at least one cryptographic module according to these embodiments or for at least one cryptographic module according to these embodiments, wherein the computing device is designed to send a first control instruction to at least one cryptographic module, wherein the first control instruction characterizes at least one storage area of ​​the storage device to be checked. As a result, the computing device can advantageously (in particular dynamically) inform the cryptographic module which storage area or storage areas are to be checked by the cryptographic module according to the principle of these embodiments.

[0022] In other preferred embodiments, it is provided that the computing device is configured to receive a second control instruction from at least one cryptographic module, wherein the second control instruction signals a successful check of a storage area to be checked of the storage device, wherein in particular the computing device is configured to execute at least one computer program after receiving the second control instruction, wherein the at least one computer program is associated with the storage area to be checked, in particular the at least one computer program is at least partially (preferably completely) located in the storage area to be checked.

[0023] Further preferred embodiments relate to a SoC having a computing device and at least one cryptographic module according to these embodiments.

[0024] Further advantageous embodiments are the subject matter of the dependent claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Further features, possible applications and advantages of the invention are apparent from the following description of an exemplary embodiment of the invention, which is shown in the figures of the accompanying drawings. All described or shown features form the subject matter of the invention by themselves or in any combination, regardless of their summary in the claims or their references and regardless of their description or illustration in the description or in the drawings.

[0026] In the attached picture:

[0027] Figure 1 schematically shows a simplified block diagram of a cryptographic module according to an implementation form,

[0028] Figure 2 schematically shows a simplified block diagram of a cryptographic module according to other implementation forms,

[0029] Figure 3 A simplified flow chart of a method according to an embodiment is schematically shown.

[0030] Figure 4 A simplified flow chart of a method according to another embodiment is schematically shown.

[0031] Figure 5 A simplified block diagram of other implementation forms is schematically shown.

[0032] Figure 6 schematically shows a simplified block diagram of a cryptographic module according to other implementation forms,

[0033] Figure 7 A simplified flow chart schematically shows a method according to other embodiments, and

[0034] Figure 8 A data structure according to an implementation form is schematically shown. DETAILED DESCRIPTION

[0035] Figure 1A simplified block diagram of a cryptographic module 100 according to an embodiment is schematically shown. The cryptographic module 100 is provided for at least temporarily controlling the operation of at least one computing device 200. The cryptographic module 110 is particularly designed to check at least one storage area 310, 320, 330 of a storage device 300 that is accessible to the computing device 200, and the cryptographic module 110 is designed to control the operation of the at least one computing device 200 as a function of the check; wherein the cryptographic module 100 is designed to receive a first control instruction A1 from the computing device 200, which characterizes at least one storage area 310 of the storage device 300 to be checked, and the cryptographic module 100 is designed to check the storage area characterized by the first control instruction A1. This advantageously provides the possibility of checking the content of a storage area, for example, as a function of deviations from a predeterminable content. This advantageously makes it possible, for example, to prevent the execution of an unsafe computer program or a computer program compromised by an attacker from being executed by the computing device 200. Further advantageously, the storage area 310 to be checked or the storage areas 310, 320, 330 to be checked (e.g. address information indicating which memory blocks are to be checked) can be signaled to the cryptographic module 100 by means of the first control instruction A1, so that, for example, this information does not need to be preconfigured. More precisely, the storage area to be checked or the storage areas to be checked can be signaled dynamically (e.g. during operation of the cryptographic module 100), thereby further increasing flexibility.

[0036] In a preferred embodiment, as exemplarily shown in Figure 1 As shown in FIG. 1 , a storage device 300 may be arranged outside the cryptographic module 100 and the computing device 200 .

[0037] In a further preferred embodiment, it is provided that the cryptographic module 100 is designed to perform a check of at least one storage area 310, 320, 330 using a key-based message authentication code CMAC. This allows a particularly efficient check to be achieved. Internet publications on exemplary embodiments of the CMAC method are available, for example, at https: / / doi.org / 10.6028%2Fnist.sp.800-38b It can be retrieved under (“NIST Special Publication 800-38B Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication”).

[0038] In other preferred embodiments, it is provided that the cryptographic module 100 has an optional (preferably integrated into the cryptographic module 100) storage unit 102 for storing at least one reference value R and / or a reference layout for at least one storage area 310, 320, 330 (or in other embodiments, for the entire storage device 300). Preferably, the computing device 200 or other components other than the cryptographic module 100 cannot access the storage unit 102.

[0039] In other preferred embodiments, the reference value R can represent, for example, a CMAC value for a predefinable memory content, which is comparable, for example, to a CMAC value that has been determined during a check of at least one memory area 310, 320, 330 by cryptographic module 100. If the determined CMAC value deviates from the reference value R, an inadmissible change in the memory content of the checked memory area 310, 320, 330 can be inferred.

[0040] In other words, it is provided in preferred embodiments that the cryptographic module 100 is designed to perform a check based on a reference value R. In these embodiments, the check includes, for example, forming a CMAC value based on the storage content of at least one storage area 310, 320, 330 and comparing the CMAC value formed in this way with a reference value R, as the reference value R is stored, for example, in a storage unit 102 of the cryptographic module 100. Advantageously, a corresponding reference value (for example a CMAC value) can be stored in the storage unit 102 of the cryptographic module 100 for each storage area 310, 320, 330 to be checked.

[0041] In other preferred embodiments, the reference layout, which can also be stored in the memory unit 102 of the cryptographic module 100, can contain one or more of the following information: a) the number of storage areas 310, 320, 330 in the memory device 300, which can be accessed by the computing device 200, b) the address range of the relevant storage area 310, 320, 330, c) the length of the relevant storage area 310, 320, 330, d) at least one reference value (e.g. CMAC value) of the relevant storage area 310, 320, 330, e) data about the encrypted signature, such as the signature address and / or the signature type and / or the signature reference to the superior certificate. In other embodiments, it is particularly preferred that the reference layout includes at least some of the above data (e.g. reference values ​​and storage areas) for the boot loader of the computing device 200, so that the cryptographic module 100 can even verify the boot loader of the computing device 200.

[0042] In other preferred embodiments, the cryptographic module 100 can use the aforementioned reference value R or the reference arrangement in order to determine the type and scope of the check of the at least one memory area 310 , 320 , 330 .

[0043] Alternatively or in addition, in other preferred embodiments, the reference value R or the reference layout (or other control information, which characterizes the reference value R and / or the reference layout) can be sent to the cryptographic module by means of the first control instruction A1. This can be done, for example, under the control of a boot loader in other embodiments. Therefore, in other embodiments, at least for some potentially checkable storage areas, the storage of the reference value R or the reference layout in the cryptographic module 100 (especially beyond the temporary buffer) can also be omitted.

[0044] Figure 2 A simplified block diagram of another embodiment is schematically shown. A system on a chip (SoC) 1000 is shown, which has an integrated computing device 200a and an integrated cryptographic module 100a, which has, for example, the aforementioned Figure 1 The system on chip 1000 also has an integrated memory device 300a, which the computing device 200a can access. In particular, computer programs or modules that are intended to be executed by the computing device 200a are stored in a corresponding storage area (not shown) of the memory device 300a and can be checked by the integrated cryptographic module 100a according to these embodiments.

[0045] Figure 3 A simplified flow chart of a method according to an implementation form is shown. In step 400, the cryptographic module 100 ( Figure 1 ) checks at least one storage area 310 , 320 , 330 of the storage device 300 , and in a subsequent step 410 , the cryptographic module 100 controls the operation of the computing device 200 according to the check 400 .

[0046] In other preferred embodiments, the cryptographic module 100 ( Figure 1 ) is designed to keep the computing device 200 in a reset state, wherein in particular the cryptographic module 100 is designed to keep the computing device 200 in a reset state until the check is completed. This prevents the computing device 200 from executing a computer program corresponding to the storage area 310, 320, 330 to be checked as long as the check has not yet been completed. While the computing unit 200 is held in the reset state, it cannot execute a computer program.

[0047] In other preferred embodiments, it is provided that the cryptographic module 100 is configured to determine within the scope of a check whether the content of at least one storage area 310, 320, 330 corresponds to a predefined storage content; and if the check has shown that the content of at least one storage area corresponds to a predefined storage content, the reset state for the computing device 200 is terminated.

[0048] Particularly preferably, the cryptographic module 100 is designed to keep the computing device 200 in the reset state if the check has shown that the content of the at least one storage area does not correspond to the predefinable storage content. In other preferred embodiments, the check of whether the content of the at least one storage area corresponds to the predefinable storage content can be performed in the following way: a CMAC value is formed based on the actual storage content and the CMAC value obtained in this way is compared with a reference CMAC value.

[0049] In a further preferred embodiment, it is provided that at least one memory area has at least one computer program, in particular a boot loader for a computing device, which is provided for execution on the computing device. Advantageously, the boot loader can thus already be checked by cryptographic module 100, that is to say the computer program for the computing device which is executed as the first program during the initialization of computing device 200. This advantageously ensures that only computer programs which have been previously checked by the cryptographic module are executed by the computing device directly after the initialization of the computing device.

[0050] In other preferred embodiments, the above-described check can also be performed for storage contents or computer programs other than the boot loader mentioned, for example, for such a computer program to be executed after the startup process (booting) of the computing device. In this case, corresponding advantages are obtained for the continued operation of the computing device. In particular, it can be prevented that a compromised computer program is executed by the computing device.

[0051] In other preferred embodiments, it is provided that cryptographic module 100 is designed to provide first data, in particular an encrypted key, to computing device 200, wherein cryptographic module 100 is in particular designed to, depending on check 400 ( Figure 3 ), the first data are only partially or not even available to the computing device 200. If, for example, within the scope of the above-described test 400 (for example, when comparing corresponding CMAC values), it is found that the tested storage area 310 ( Figure 1) corresponds to a predeterminable value, it can be inferred that original, unmanipulated software is present and that computing device 200 can be allowed to access first data, in particular encrypted keys, stored in cryptographic module 100. Computing device 200 can use the encrypted keys obtained from the cryptographic module, for example, to cryptographically protect communication with other units, such as other computing units (not shown), for example, by encrypting messages and / or forming CMAC values ​​for the messages.

[0052] However, if the above-described check shows that the content of the checked memory area does not correspond to a predefinable value, that is, has potentially been manipulated, it can be provided that the cryptographic module 100 completely prevents the computing device 200 from accessing the encrypted keys or other first data stored in the cryptographic module or available via the cryptographic module, thereby advantageously preventing the computing device from retrieving the encrypted keys from the cryptographic module under the control of manipulated software. In other preferred embodiments, it is also conceivable that, depending on the type of checked memory content, the computing device (e.g., a boot loader or regular software, which is to be executed only after the boot loader is executed) is given access to a first subset of the encrypted keys stored in the cryptographic module, but not to a second subset of the encrypted keys.

[0053] Figure 4 A simplified flow chart of a method according to another embodiment is shown. In step 420, the cryptographic module 100 ( Figure 1 ) for initialization. In this case, for example, a reference layout stored in the storage unit 102 can be read and evaluated, or parts thereof and / or configuration data for the cryptographic module 100 can be read and evaluated. Optionally, the computing device 200 can also be placed in its reset state in step 420 and temporarily remain in the reset state. In step 422 ( Figure 4 ), and then checking at least one storage area 310 ( Figure 1 ), in which the at least one storage area 310, for example, a boot loader program for the computing device 200 is stored. The check in step 422 involves, for example, the formation of a CMAC value for the boot loader program. In this case, the determined CMAC value is then compared in step 424 with a reference value determined in advance and stored for the boot loader, which can be loaded from the storage unit 102, for example, by the cryptographic module 100.

[0054] If comparison 424 shows that the CMAC value for the boot loader program currently stored in the storage area 310 formed in the check in step 422 is consistent with a CMAC reference value determined in advance (for example when manufacturing the cryptographic module 100 and / or parameterizing the cryptographic module 100 in a cryptographically secure environment) and stored in the storage unit 102, the cryptographic module 100 can end the reset state of the computing device 200, see step 426, and the computing device 200 can then proceed with its normal operation and can execute the boot loader program from the storage area 310.

[0055] However, if comparison 424 shows that the CMAC value for the boot loader program currently stored in storage area 310 formed in the check in step 422 is inconsistent with the previously determined CMAC reference value, then branching occurs to step 428, in which the computing device 200 continues to be maintained in its reset state by the cryptographic module 100 in order to prevent the computing device 200 from executing a potentially compromised boot loader.

[0056] Optionally, in step 426 , the computing device 200 may also be given access to one or more encrypted keys that can be provided by the cryptographic module 100 .

[0057] Further optionally, after step 426, the computing device may send a first control instruction A1 ( Figure 1 ), see step 426a ( Figure 4 ), for example, in order to indicate to the cryptographic module 100 which storage area or which computer program is to be checked next by the cryptographic module 100. Then, also optionally, a corresponding (other) check can be performed by the cryptographic module 100 according to the first control instruction A1, see step 426b.

[0058] Figure 5A simplified block diagram of other embodiments is schematically shown. Area 100' essentially includes steps performed on the cryptographic module 100 side, and area 200' essentially includes steps performed on the computing device 200 side. In step S1, the cryptographic module 100 is activated. Directly after the activation of the cryptographic module 100, the cryptographic module 100 keeps the computing device 200 in its reset state. In step S2, the cryptographic module 100 checks the first computer program SW1 for the computing device 200. Preferably, the first computer program SW1 can be a boot loader BL for the computing device 200. The check in step S2 includes, for example, forming a CMAC value based on the corresponding storage content of the first computer program SW1 or a storage device storing the first computer program SW1, and comparing it with a reference CMAC value. The cryptographic module can, for example, retrieve the following information from the reference data stored in the storage unit 102: which storage area is to be checked and which (e.g. CMAC) reference value is to be used for this purpose.

[0059] If the check S2 does not result in a match between the two CMAC values, it is concluded that the first computer program SW1 has been manipulated or is damaged, and the process branches to step S21, in which, for example, the computing device 200 is deactivated. If the check S2 results in a match between the two CMAC values, it can be concluded that the first computer program SW1 is intact and can be executed by the computing device 200. In this case, the process branches from step S2 to step S3, in which the computing device 200 is released, that is to say, the reset state that was caused or previously maintained is released. The computing device 200 can then execute the first computer program SW1, and in the present invention, the boot loader is therefore started, see step S4.

[0060] In other preferred implementation forms, for example, under the control of the boot loader SW1, the computing device 200 may send the previously referenced Figure 1 The first control instruction A1 already described, see step S5 , wherein the first control instruction A1 represents at least one (further) memory area of ​​the memory device 300 to be checked or represents the corresponding computer program SW2 , for example indicating the relevant address or address range in the memory device.

[0061] In the present invention, the following situation is taken as an example, in the second storage area 320 of the storage device, a second computer program SW2 for the computing device 200 is provided, and the second computer program should be the subject of the subsequent verification by the cryptographic module 100. Correspondingly, the computing device 200 sends the mentioned first control instruction A1 to the cryptographic module 100, and the cryptographic module 100 performs the verification of the second computer program SW2 in step S6. The verification according to step S6 can preferably be carried out, for example, similarly to the verification according to step S2. The cryptographic module 100 can read out the corresponding CMAC reference value for the second computer program SW2 from the internal storage unit 102. Alternatively or in addition, the corresponding CMAC reference value for the second computer program SW can be sent by the boot loader BL to the cryptographic module also with the help of the first control instruction A1.

[0062] If the check according to step S6 has shown that the second computer program SW2 is intact, the cryptographic module 100 can signal this to the computing device 200 by means of the second control instruction A2. Upon receipt of the second control instruction A2, the computing device 200 accordingly moves to the next step S7, which, for example, involves the execution of the second computer program SW2. However, if the check according to step S6 has shown that the second computer program SW2 is not intact, the cryptographic module 100 also signals this to the computing device 200 by means of the second control instruction A2 (alternatively, the transmission of the second control instruction A2 can be skipped, and after the expiration of a predeterminable waiting time without receiving the second control instruction A2 from the cryptographic module, the computing device 200 can conclude that the check was unsuccessful). In this case, after receiving the second control instruction A2 (or after the expiration of the time without receiving the second control instruction A2), the computing device 200 moves to step S8, which leads to an error response. The error reaction according to step S8 can involve, for example, deactivation or deletion of the second computer program SW2 .

[0063] In other preferred embodiments, the method can be continued by checking further computer programs or corresponding memory areas with the aid of cryptographic module 100 , see step S9 .

[0064] In other preferred embodiments, the cryptographic module 100 can record a record or log file about successful and / or unsuccessful tests. For example, if the test of the storage area 310, 320, 330 or the software contained therein fails (for example, the deviation of the measured CMAC value from the reference CMAC value is identified), the cryptographic module 100 can store an error item. In other embodiments, for example, when the subsequent cryptographic module and / or computing device is started, the record or log file or part thereof can be evaluated, and the continued operation of the computing device 200 can be controlled based on the evaluation. For example, in some embodiments, if the previous test fails, the reboot process (execution of the boot loader BL) can be prevented. Alternatively or in addition, at least one interrupt request ("Interrupt") can be generated, and / or the computing device 200 can be reset ("reset").

[0065] Figure 6 A simplified block diagram of a cryptographic module 100b according to other embodiments is schematically shown. The cryptographic module 100b has a computing core or processor 110, a working memory 120, a non-volatile memory 130 (e.g., a flash EEPROM) and optionally a cryptographic unit 140, which is designed to execute one or more cryptographic algorithms or at least parts thereof. For example, the cryptographic unit 140 can be designed to execute the determination of the CMAC value described above.

[0066] The principle of these embodiments advantageously enables targeted checking of computer programs, for example, provided for computing device 200, with regard to their authenticity and / or integrity, by means of cryptographic methods, for example by determining the CMAC value described above and comparing it with a reference value. This makes it possible to determine particularly efficiently, for example, whether a boot loader is safe for computing device 200 or whether the boot loader has been manipulated by an attacker (or whether the boot loader has been accidentally modified by an error). In this case, the CMAC value calculated based on the actual storage area that holds the boot loader does not correspond to the reference value known to cryptographic module 100.

[0067] Another advantage of the principle according to these embodiments is that, depending on the security and / or real-time performance of the computer programs SW1, SW2 for the computing device 200, a relatively fine-grained check of these computer programs can be implemented, so that individual computer programs can also be selectively checked by the cryptographic module. Particularly advantageously, for example, a selective check of the boot loader for the computing device 200 can quickly put the computing device 200 into a safe bootable state. Advantageously, for example, at least temporarily in parallel with the start-up of the computing device 200, under the control of the boot loader SW1 or at a later time (advantageously, in particular dynamically triggered by the first control instruction A1), a check of other computer programs SW2 that may also be necessary or desired can be performed. In other words, when the principle according to these embodiments is applied, it is not always necessary to check the entire memory of the storage device 300 at once, but individual storage areas 310, 320, 330 can be checked flexibly by the cryptographic module 100 at a predeterminable time.

[0068] Figure 7 A simplified flow chart of a method according to another embodiment is schematically shown. In step 430, for example, Figure 4 Step S2 of the cryptographic module 100 ( Figure 1 ) Check the boot loader BL of the computing device 200 ( Figure 5 ). After successfully verifying the boot loader BL, see step 432, the cryptographic module 100 releases the execution of the boot loader BL, for example, by not maintaining the reset state of the computing device 200 for a long time by the cryptographic module; and in step 434, the cryptographic module 434 waits for the first control instruction A1, see also Figure 4 .

[0069] Figure 8 A data structure DS according to other preferred embodiments is schematically shown. Optionally, the data structure DS can be used, for example, to store a CMAC reference value or a reference layout for the cryptographic module 100 or the like, for example in the storage unit 102 of the cryptographic module 100. In a preferred embodiment, the data structure DS has a primary index PI, which provides a clear identification. If, for example, there are multiple data structures or data records with this data structure DS, these data structures or data records can be distinguished from each other using corresponding values ​​for the primary index PI. It is conceivable that in the case of multiple data structures managed by the cryptographic module 110 or data records with the mapped data structure DS, a clear value for the mentioned primary index PI is given to each data record.

[0070] Further preferably, the data structure DS may have a starting address ADR1, which, for example, defines the storage device 300 ( Figure 1 ) in a storage area 310 that may be checked (in particular a starting address). For example, this may be a starting address in the storage device 300 at which a computer program, such as the boot loader described above, is stored.

[0071] The data structure DS further preferably has a length specification LEN which specifies the length of the relevant storage area. The data structure DS further preferably has a status field IS which specifies the integrity status of the current data record (e.g. "verified" or "faulty" or the like, e.g. depending on the data record). Figure 3 The data structure DS particularly preferably also has a field REF-CMAC for accommodating a CMAC reference value, such as this CMAC reference value was determined, for example, at the time of production for a computer program (e.g. a boot loader) stored in the memory device 300. The CMAC reference value can then be used by the cryptographic module 100 to check the real-time status or integrity of a computer program that is present in the memory device 300 or in the relevant memory area 310 at the time of the check.

[0072] In other preferred embodiments, the data structure DS may also contain further data fields DF, for example for accommodating a signature address, a signature type, a reference to a corresponding root certificate, and the like.

[0073] The principles according to these embodiments have the following advantages: a) during the runtime of the cryptographic module 100, manipulations of the contents of the memory device 300 can be detected efficiently (e.g. also changes caused by errors), for example manipulations of a computer program stored therein (such as, for example, a boot loader or the like) can be detected (“runtime manipulation detection”, RTMD), b) secure booting (that is to say starting) of software (e.g. applications) on the computing device 200 is ensured (“trusted boot”), c) computer programs SW2 or other data stored in the memory device 300 can also be checked subsequently in accordance with the principles according to these embodiments (“secure boot”), d) based on the checks according to these embodiments, access to cryptographic keys and other sensitive information, which may be provided by the cryptographic module, can be controlled ("security access"), e) the boot sequence (the sequence in which computer programs are processed when the computing unit 200 is started) can be selected arbitrarily without compromising security, f) by using a cryptographic module 100 (possibly with a dedicated cryptographic unit 140), efficient and secure cryptographic functions can be provided, such as CMAC formation (for example based on 128-bit AES (Advanced Encryption Standard)), g) by setting, for example, the Figure 7 By means of a reference layout in the form of a data structure DS, the operation of the cryptographic module 100 can be flexibly adapted to different memory layouts and other configurations of the computing device 200. h) By transmitting a first control instruction A1, the storage area to be checked can be dynamically (for example, during the operation of the cryptographic module) notified to the cryptographic module by a signal.

[0074] Other preferred embodiments relate to the computing device 200 ( Figure 1 ), the computing device 200 has at least one cryptographic module 100 according to these embodiments or is used for at least one cryptographic module 100 according to these embodiments, wherein the computing device 200 is configured to send a first control instruction A1 to at least one cryptographic module 100, wherein the first control instruction A1 characterizes at least one storage area 310 of the storage device 300 to be checked. As a result, the computing device 200 can advantageously (in particular dynamically) inform the cryptographic module 100: according to the principle of these embodiments, which storage area or storage areas are to be checked by the cryptographic module 100 (perhaps in addition to the boot loader BL which can optionally be checked first). In other preferred embodiments, the sending of the first control instruction A1 can be carried out by the boot loader BL ( Figure 5As already mentioned, in other preferred embodiments, the boot loader BL itself or the storage area containing the boot loader BL can already be checked by the cryptographic module 100 beforehand.

[0075] In other preferred embodiments, the computing device 200 is configured to receive a second control instruction A2 ( Figure 4 ), wherein the second control instruction signals a successful check of the storage area to be checked of the storage device, wherein in particular the computing device 200 is designed to execute at least one computer program SW2 after receiving the second control instruction A2, the at least one computer program SW2 being associated with the storage area to be checked, in particular the at least one computer program SW2 being at least partially (preferably completely) located in the storage area to be checked. In other words, in other preferred embodiments, after successfully checking the storage area to be checked, the cryptographic module 100 can send the second control instruction A2 to the computing device 200 in order to signal the successful check.

Claims

1. A cryptographic module for at least temporarily controlling the operation of at least one computing device, wherein the cryptographic module is configured to: maintaining the computing device in a reset state; verifying at least one storage area of ​​a storage device accessible by the computing device, the boot loader being stored in the at least one storage area, while the computing device remains in a reset state and before the computing device executes a boot loader, wherein the cryptographic module is configured to verify the boot loader of the computing device using a key-based message authentication code (CMAC); controlling the operation of the at least one computing device based on the verification of the at least one storage area, wherein the cryptographic module is configured to end the reset state of the computing device after successfully verifying the boot loader, release the execution of the boot loader, and wait for a first control instruction; receiving the first control instruction from the computing device, the first control instruction characterizing at least one storage area of ​​the storage device to be checked; as well as checking the memory area characterized by the first control instruction, The computing device is unable to execute a computer program while it is held in a reset state.

2. The cryptographic module according to claim 1, wherein: The cryptographic module has a storage unit for storing at least one reference value and / or a reference layout for the at least one storage area.

3. The cryptographic module according to claim 2, wherein: The cryptographic module is designed to carry out the check as a function of the reference value.

4. A cryptographic module according to any one of the preceding claims, wherein: The cryptographic module is designed to keep the computing device in the reset state until the verification is completed.

5. The cryptographic module according to any one of claims 1 to 3, wherein: The cryptographic module is designed to determine within the scope of the check whether the content of the at least one storage area corresponds to a predefinable storage content and to terminate the reset state for the computing device if the check has shown that the content of the at least one storage area corresponds to the predefinable storage content.

6. The cryptographic module according to claim 5, wherein: The cryptographic module is designed to keep the computing device further in the reset state if the check has revealed that the content of the at least one memory area does not correspond to the predefinable memory content.

7. The cryptographic module according to any one of claims 1 to 3, wherein: The cryptographic module is designed to provide first data to the computing device, wherein the first data is an encrypted key.

8. The cryptographic module according to claim 7, wherein: The cryptographic module is designed to make the first data available to the computing device only partially or not at all, as a function of the check.

9. The cryptographic module according to any one of claims 1 to 3, wherein: The cryptographic module is at least partially designed as a hardware circuit.

10. The cryptographic module according to claim 2, wherein: The storage unit is integrated into the cryptographic module.

11. A method for operating a cryptographic module for at least temporarily controlling the operation of at least one computing device, wherein the cryptographic module maintaining the computing device in a reset state; verifying at least one storage area of ​​a storage device accessible by the computing device while the computing device remains in a reset state and before the computing device executes a boot loader, the boot loader being stored in the at least one storage area, wherein the cryptographic module verifies the boot loader of the computing device using a key-based message authentication code (CMAC); controlling the operation of the at least one computing device based on the verification of the at least one storage area, wherein the cryptographic module ends a reset state of the computing device after successfully verifying the boot loader, releases execution of the boot loader, and waits for a first control instruction; receiving a first control instruction from the computing device, the first control instruction characterizing at least one storage area of ​​the storage device to be checked; as well as checking the memory area characterized by the first control instruction, The computing device is unable to execute a computer program while it is held in a reset state.

12. The method according to claim 11, wherein: The cryptographic module holds the computing device in the reset state until the verification is completed.

13. The method according to any one of claims 11 to 12, wherein: The cryptographic module ascertains within the scope of the check whether the content of the at least one storage area corresponds to a predefinable storage content and terminates the reset state for the computing device if the check has shown that the content of the at least one storage area corresponds to the predefinable storage content.

14. The method according to claim 13, wherein: If the check has revealed that the content of the at least one memory area does not correspond to the predefinable memory content, the cryptographic module continues to keep the computing device in the reset state.

15. A computing device having at least one cryptographic module according to any one of claims 1 to 10, wherein the computing device is designed to send a first control instruction to the at least one cryptographic module, wherein the first control instruction characterizes at least one storage area of ​​a storage device to be checked.

16. The computing device of claim 15, wherein: The computing device is designed to receive a second control instruction from the at least one cryptographic module, wherein the second control instruction signals a successful check of the memory area of ​​the memory device to be checked.

17. The computing device of claim 16, wherein: The computing device is designed to execute at least one computer program after receiving the second control instruction, the at least one computer program being associated with the memory area to be checked.

18. The computing device of claim 17, wherein: The at least one computer program is at least partially located in the memory area to be checked.

Citation Information

Patent Citations

  • Cryptographic hardware module or method for updating a cryptographic key

    DE102009046436A1

  • Method for verifying a memory block of a nonvolatile memory

    US20130117578A1

  • Secure Code Verification Enforcement In A Trusted Computing Device

    US20140068766A1

  • Method of securely booting a computer system and a computer system

    US20180150637A1