Electronic system

By using a matrix bus and a second circuit to generate representative words in the electronic system to verify the credibility of instructions, the problem of memory data being modified by piracy during initialization is solved, thus improving the security of the system.

CN114341851BActive Publication Date: 2025-11-07STMICROELECTRONICS (GRAND OUEST) SAS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080062291.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-09-06
Filing Date
2020-09-02
Publication Date
2025-11-07
Estimated Expiration
2040-09-02

AI Technical Summary

Technical Problem

In existing electronic systems, data stored in memory may be pirated and modified during system initialization, leading to security issues.

Method used

Instructions and operands are retrieved from the internal memory via the controller's matrix bus. During transmission, a second circuit generates a representative word, which is compared with a reference word to verify the reliability of the instruction. If the instruction is not reliable, measures such as restarting or shutting down the system are taken.

Benefits of technology

This effectively ensures that instructions and operands stored in memory are not modified by piracy during system initialization, thus improving the security of electronic systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114341851B_ABST
    Figure CN114341851B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a method for verifying instructions and operands in an electronic system comprising a controller, the method comprising: extracting, by a matrix bus (106) of the controller, via a first circuit (102) of the controller, instructions and operands from at least a first memory (104) internal to the controller; collecting, via a second circuit (110) internal to the controller, the instructions and operands on the matrix bus (106) during the transmission of the instructions and operands to the first circuit (102); and generating a word (DIGEST) representative of the instructions and operands.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority of French patent application 19 / 09826, which is considered as being part of the present specification. TECHNICAL FIELD

[0002] The present disclosure relates generally to electronic systems, and more particularly to systems comprising memories. BACKGROUND

[0003] With the development of connected object fields such as home automation, the security of electronic systems is particularly important. It is particularly important to be able to ensure that the data stored in a memory and executed during the initialization of the system, i.e. the boot instructions and the associated operands, indeed correspond to the expected instructions and not to pirate-modified instructions.

[0004] It is desirable to improve at least one aspect of known electronic systems. SUMMARY

[0005] One embodiment addresses all or some of the drawbacks of known electronic systems.

[0006] One embodiment provides a method for verifying instructions and operands in an electronic system comprising a controller, the method comprising:

[0007] extracting, by means of a matrix bus of the controller, the instructions and the operands from at least a first memory internal to the controller, via a first circuit of the controller;

[0008] collecting the instructions and the operands on the matrix bus, via a second circuit internal to the controller, during the transmission of the instructions and the operands to the first circuit; and

[0009] generating a word representative of the instructions.

[0010] Another embodiment provides an electronic system comprising a controller, the controller comprising: a first circuit configured to extract instructions and operands from at least a first memory internal to the controller, by means of a matrix bus of the controller; a second circuit configured to collect the instructions and the operands on the matrix bus when the instructions and the operands are sent to the first circuit, and to generate a word representative of the instructions and the operands.

[0011] According to one embodiment, the first circuit is configured to execute the instructions, the instructions being boot instructions of the system.

[0012] According to one embodiment, the second circuit is configured to compare the word representative of the instructions with a reference word.

[0013] According to one embodiment, the second circuit is configured to determine that the instruction is trusted when the word representative of the instruction is identical to the reference word, and to determine that the instruction is untrusted when the word representative of the instruction is different from the reference word.

[0014] According to one embodiment, the system is configured to be restarted or shut down if the second circuit determines that the instruction is untrusted.

[0015] According to one embodiment, the second circuit comprises a second memory in which the reference word is stored from the initial programming of the system.

[0016] According to one embodiment, the second circuit determines the beginning of the instruction by comparing the address with the beginning address of the instruction stored in the second memory.

[0017] According to one embodiment, the end of the data is determined by a predetermined duration after the beginning of the instruction, or by comparing the address with the end address of the instruction stored in the second memory.

[0018] According to one embodiment, the first memory is a non-volatile memory internal to the controller, the controller comprising a third memory, the first memory comprising the instruction and the third memory comprising the operand.

[0019] According to one embodiment, the matrix bus comprises buses forming rows and columns, each intersection between a row and a column being configured to allow or not to allow the transfer of information between the row and the column.

[0020] According to one embodiment, the first circuit is coupled to the matrix by a first input / output on which the instruction is transmitted and by at least a second input / output on which the operand is transmitted.

[0021] According to one embodiment, the first memory is coupled to the first and second input / output of the first circuit by the matrix bus, and the third memory is coupled to the third input / output of the first circuit by the matrix bus.

[0022] According to one embodiment, the operand comprises a parameter for initializing at least one element of a protection unit of a memory, of a "watchdog" type circuit, or of a circuit for protecting a non-volatile memory. BRIEF DESCRIPTION OF DRAWINGS

[0023] The above features and advantages, and other features and advantages, will be more clearly understood from the following description of specific embodiments given for by way of illustration and not limitation, in which:

[0024] Figure 1 An embodiment of an electronic system is shown; and

[0025] Figure 2 An embodiment of a method for authenticating instructions and data is shown. DETAILED DESCRIPTION

[0026] In the various figures, similar features are denoted by similar reference signs. In particular, structural and / or functional features common to the various embodiments can have the same references and can be arranged with the same structural, dimensional and material properties.

[0027] For the sake of clarity, only the operations and elements useful for understanding the embodiments described herein are specified and described in detail. In particular, different applications of the embodiments of the electronic system will not be described in detail.

[0028] Unless otherwise stated, when referring to two elements connected together, this means a direct connection, without any intermediate element other than a conductor, and when referring to two elements coupled together, this means that the two elements can be connected or they can be coupled through one or more other elements.

[0029] In the following disclosure, unless otherwise stated, if reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or to relative position qualifiers, such as the terms "above", "below", "higher", "lower", etc., or to direction qualifiers, such as "horizontal", "vertical", etc., reference is made to the orientation shown in the figures.

[0030] Unless otherwise stated, the expressions "approximately", "about", "substantially" and "around" mean within 10%, preferably within 5%.

[0031] Figure 1 An embodiment of an electronic system 100 is shown. The system 100 is a system seeking to protect instructions, such as start-up instructions, from modification. The system 100 corresponds for example to a connected object, such as in the field of home automation. The embodiments described herein are particularly suitable for the type of system that is generally not connected to a network. More precisely, Figure 1 denotes a controller of the system 100.

[0032] The system 100, more precisely said controller of the system, comprises a circuit 102, preferably a processor (μP). The system comprises at least one memory 104 (MEM1). The memory 104 is an internal memory of the controller. The memory 104 is a rewritable non-volatile memory, such as a flash memory. The system also comprises at least one memory 108 (MEM2), such as a volatile memory, for example a RAM memory. The memory 108 is also an internal memory of the controller. Preferably, the memories 104 and 108 are different memories.

[0033] The different elements of the system, in particular the memories 104 and 108 and the processor 102, are coupled by a bus array 106 or interconnection matrix bus, for example an Advanced High-Performance Bus (AHB). The matrix bus 106 is internal to the controller. The matrix bus allows "master" type circuits to be coupled to "slave" type circuits. Each element of the device is coupled to at least one line or at least one column of the matrix. Preferably, the "master" type elements are coupled, preferably connected, to the columns and the "slave" type elements are coupled, preferably connected, to the rows. The rows and columns of the matrix bus are elements of information transport, for example a bus.

[0034] The processor 102 is coupled, preferably connected, to three columns of the matrix 106: a column on which instructions are transported and at least one column on which operands are transported. In the example of figure 1, the processor is coupled, preferably connected, to two columns on which operands are transported. Figure 1

[0035] The memory 104 is coupled, preferably connected, as an example to two rows, for example a row on which instructions are transported and a row on which operands are transported. The memory 108 is coupled, preferably connected, for example to one row of the matrix 106.

[0036] The system 100 can further comprise other circuits connected to the matrix 106, for example one or more direct memory access circuits 120 (DMA1, DMA2) and circuits running other functions, in the example of figure 1 represented by blocks 122 (FCT2, FCT2). Each DMA is coupled, preferably connected, for example to a column of the matrix 106. Each circuit 122 is coupled, preferably connected, for example to a row of the matrix 106. Figure 1

[0037] Each row crosses all the columns and, conversely, each column crosses all the rows. However, each crosspoint does not correspond to an electrical connection. Each crosspoint corresponds to a possible electrical connection. It is possible to choose which row is electrically connected to which column. Preferably, this is determined during manufacture of the device. Thus, during operation of the device, these connections are fixed.

[0038] Thus, in the device 100, the column 102a coupled, preferably connected, to the input / output of the processor 102 is connected to: the row 104a coupled, preferably connected, to the input / output of the memory 104; and the row 108a coupled, preferably connected, to the input / output of the memory 108. These connections are represented in figure 1 by the points at the interconnections of the rows and columns. Figure 1 Thus, the processor 102 is coupled, preferably connected, to the memory 104 via the column 102a and the row 104a and to the memory 108 via the column 102a and the row 108a.

[0039] In the example of figure 1, the column 102a is connected to the row 104a and to the row 108a. Thus, the column 102a is connected to the memory 104 and to the memory 108. Figure 1 ​​In an embodiment of the application, the following intersections are not configured to allow electrical connections:

[0040] At the intersection between column 102a and row 104b, the row is coupled, preferably connected, to an input / output of the memory 104;

[0041] At the intersection between column 102a and row 122a, the row is coupled, preferably connected, to an input / output of the block FCT1; and

[0042] At the intersection between column 102a and row 122b, the row is coupled, preferably connected, to an input / output of the block FCT2.

[0043] Thus, the processor 102 cannot exchange information with the blocks FCT1 and FCT2 through the row 102a.

[0044] Similarly, in an embodiment of the application, the column 102b coupled, preferably connected, to an input / output of the processor 102 is coupled, preferably connected, to the row 104b and the row 108a, but not to the row 104a, 122a, 122b. Figure 1

[0045] Preferably, the processor 102 is coupled, preferably connected, to the memory 104 through the column 102a on which instructions are transmitted and through the row 104a on which operands are transmitted.

[0046] In an example of the application, the column 102c coupled to an input / output of the processor 102 is coupled, preferably connected, to the rows 108a, 122a and 122b. The column 102c is a column on which operands are transmitted. In an example of the application, the column 102c is not coupled to the rows 104a and 104b. Figure 1 Figure 1 Thus, the processor 102 is preferably not coupled to the memory 104 through the column 102c on which operands are transmitted. However, the processor 102 is coupled to the memory 108 through the column 102c and the row 108a in order to be able to transmit operands.

[0047] The processor 102 can thus receive instructions or operands located in the memory 104 and receive operands located in the memory 108.

[0048] The DMA 120 is coupled, preferably connected, to the rows 104a, 104b, 108a, 122a and 122b through the columns 120a and 120b, respectively.

[0049] The memories 104 and 108 store boot data, preferably stored in the memory 104, meaning system instructions that boot or initialize, and store operands used during booting, preferably stored in the memory 108.​​

[0050] The boot instruction refers to the instruction itself. The boot instruction is executed by the circuit 102 and transmitted by the row 104a of the matrix 106. The boot instruction is preferably in the first instruction executed during the start-up of the system. For example, the boot instruction comprises an operand of at least one element of the following:

[0051] A protection unit of the memory, which can authorize or not authorize the access of different parts of the memory to different peripherals and to different programs,

[0052] A "watchdog" type of circuit, and

[0053] A protection circuit of the non-volatile memory.

[0054] The "watchdog" type of circuit refers to a circuit comprising a timer which, under normal circumstances, is periodically restarted before reaching its final value. If the device is faced with an attack to stop the timer from restarting, the timer reaches its final value and detects an error.

[0055] The boot data, meaning the boot instruction and the operand, are written in the memory during the initial programming of the system. The boot data are not meant to be modified outside of a complete reprogramming of the system, which would involve a complete erasure of the memories 104 and 108. Such a reprogramming would then be considered as a new initial programming of the system. Thus, a modification of the boot instruction involves a piracy attempt, for example an attempt to bypass the security measures of the system 100.

[0056] The system 100 comprises a circuit 110 for verifying the instructions, preferably comprising an internal memory 112 and various logic circuits 114. Preferably, the circuit 110, the processor 102, the matrix bus 106 and the memories 104 and 108 are part of the same microcontroller.

[0057] The various logic circuits 114 comprise a circuit 114-2 (MONITOR) configured to monitor the matrix bus 106. More precisely, the circuit 114-2 is configured to monitor all the liaisons of the matrix bus. In particular, the logic circuit 114-2 monitors the passage of the instruction address sent by the memory 104 on the column 102b and on the row 104b. The logic circuit 114 comprises a circuit 114-4 (ACCUMULATE) configured to collect the data on the liaisons of the matrix bus and to obtain a word (DIGEST) representative of the boot data, and a circuit (114-6 (COMPARE) configured to compare the representative word with a reference word (REFERENCE).

[0058] The internal memory 112, preferably corresponding to a register, comprises data related to the authentication of the boot instructions. In particular, the register of the memory 112 comprises a reference word REFERENCE and a representative word DIGEST. In addition, the register of the memory 112 can comprise elements characterizing the boot instructions, such as the address of the first instruction (@START) and the address of the last instruction (@END).

[0059] All boot data are transmitted by the matrix bus between a first data, preferably the first instruction, identified by its address @START, and a last data, preferably the last instruction to be verified, identified by its address @END. Preferably, only the data stored by the memories 104 and 106 are provided between the first data and the last data. However, information transmitted on other rows or columns, such as data, can be transmitted between the first data and the last data and can also be used to generate the representative word.

[0060] Alternatively, several sequences of data can be used to form the representative word, these sequences possibly being separated by sequences of data not used in the formation of the representative word. The internal memory preferably stores the start and end addresses of each of said sequences used to generate the representative word.

[0061] The data used to generate the representative word are such that between the first data and the last data, the instructions and operands transmitted to the processor 102 are always exactly the same, preferably in the same order. Preferably, the generation of the representative word is always done by the instructions and at least one operand.

[0062] Preferably, the circuit 110 comprises:

[0063] - a wiring (114-2) allowing the monitoring of the data transmitted on all the rows and columns of the matrix bus;

[0064] - a logic element (114-2) allowing the determination of the start and end of the data for the verification, such as a logic element allowing the comparison of the addresses transmitted on the rows and columns 104a and 102a;

[0065] a logic element (114-4) allowing the generation of the representative word;

[0066] - a logic element (114-6) allowing the comparison of binary words and thus the comparison of the representative word DIGEST with the reference word REFERENCE;

[0067] a clock allowing the synchronization of the elements of the circuit 110; and

[0068] a register 112 in which the reference word and the addresses of the start and end of the sequence of data to be verified are stored.

[0069] Figure 2An embodiment of a method for authenticating instructions is shown, for example, by the system 100 of Figure 1 is completed.

[0070] The method comprises a first step 200, during which the processor 102 sends a request to the memory 104 to extract (EXTRACT) the bootstrap instructions. This step is completed during the start-up of the system 100.

[0071] The bootstrap instructions are next sent through the matrix bus 106 to the circuit 102, with the aim of being executed by the processor 102.

[0072] The circuit 110 can be configured to determine the start of the bootstrap instructions by monitoring the data bus and identifying the first instruction itself.

[0073] Alternatively, the circuit 110 monitors the bus 106 and is configured to identify the first bootstrap instruction sent by the memory 104. To do this, for example, the address of the instruction that passes through the address bus (step 202, "= @START?") is compared with the address @START of the first bootstrap instruction.

[0074] Alternatively, the circuit 110 can be configured to determine the start of the bootstrap instructions without having to compare the address of the instruction being sent with a preprogrammed address. For example, the circuit 110 can consider that the first instruction sent by the memory 104 is the first bootstrap instruction.

[0075] The circuit 110 can be configured to monitor the bus 106 during a preprogrammed duration in order to identify the first bootstrap instruction. If the first bootstrap instruction is not identified during this duration, the circuit 110 determines that there is a problem in the bootstrap instructions and that the security of the system can be compromised.

[0076] According to one embodiment, the circuit 110 can be configured to monitor the bus 106 during a preprogrammed duration in order to find the last bootstrap instruction of the sequence to be verified. If the last bootstrap instruction is not found during this duration, the circuit 110 determines that there is a problem at the level of the bootstrap instructions and that the security of the system can be compromised.

[0077] When the first bootstrap instruction is identified (branch Y of step 202), each data passing through the matrix bus is collected by the circuit 102 on the one hand in order to be implemented (step 204, "IMPLEMENT"), and on the other hand by the circuit 110 (step 206, "COLLECT"). Thus, the circuit 110 monitors the matrix bus 106 and directly reads the instructions and their addresses in the instructions, for example on the columns 102a and 102b, and the operands, for example on the column 102c. Steps 204 and 206 are performed in parallel, so the data are processed in parallel by the circuits 102 and 110.

[0078] The circuit 110 next determines (step 208) whether the sent instruction is the last instruction. For example, the address on the address bus of the sent instruction is compared with the address of the last boot instruction @END. If the address of the sent instruction is different from the address @END (branch N of step 208), the steps 204 and 206 are returned to in order to send the following data. If the address of the sent instruction is equal to the address @END (branch Y in step 208), it is considered that the sending of the boot data is complete and the next step is entered.

[0079] The end of the instructions, in other words the end of the sequence of boot data to be verified, can alternatively be determined by a duration tl corresponding to the time taken by the set of boot data to be sent to the circuit 102. The end of the boot data corresponds to the time t + tl, where t is the start time of the boot data (for example the time of step 202). The duration tl is for example stored in the internal memory 112.

[0080] In step 209 (GENERATE) following step 208 (branch Y), the boot data collected by the circuit 110 on the matrix bus are used to generate a representative word (DIGEST). According to one example, the data collected on the matrix bus are all stored in the internal memory 112 and the representative word is generated from all the stored instructions in a single pass. According to another example, the circuit 110 can update the representative word each time data are collected by the circuit 110 in step 206.

[0081] After the end of the sending of the data and after the generation of the determined representative word DIGEST, that is to say after step 209, the representative word is compared with a reference word (REFERENCE) stored in the memory 112.

[0082] Each time the system is initialized, the reading order of the boot instructions is the same. The circuit 102 extracts the same boot instructions and the same operands in the same order on the matrix bus. Thus, without modification, the representative word is the same each time the system is initialized.

[0083] Thus, if the representative word is different from the reference word (branch N of step 210), this means that the instructions implemented and / or the operands provided do not correspond to the provided and trusted instructions and the security system can be compromised. Protective measures can then be taken (step 212), for example restarting the system or shutting it down.

[0084] In the case where the reference word and the representative word are identical, this means that the implemented instructions are trusted instructions and the operands are trusted. The boot of the system 100 can thus continue.

[0085] Preferably, the circuit 110 is switched off after the authentication of the start-up data. The circuit 110 will then be switched on again only after the next start-up of the system, for example by receiving a restart signal.

[0086] The addresses @START and @END, the duration t1 and the reference word REFERENCE have been written in the memory 112, for example, during the initial programming of the system. The addresses @START and @END, the duration t1 and the reference word REFERENCE are determined, for example, once, for example by simulation on a simulator, and then written in the memory 104 by a plurality of similar systems.

[0087] Alternatively, the initial programming of each system can comprise the step of determining these values for the system under consideration.

[0088] Different functions can be used to generate the representative word DIGEST from the data. For example, a hash function can be used. Likewise, any function capable of generating a signature from data can be used.

[0089] The size of the boot instructions is preferably less than 5 kilobytes, for example between approximately 2 and approximately 3 kilobytes.

[0090] The size of the representative word is for example less than or equal to 32 kilobytes. The size of the representative word is preferably independent of the size of the words stored in the memory.

[0091] The start @START and end @END addresses of the boot instructions can for example form an address range of the memory 104, all the boot instructions being in this range. Thus, if an instruction is sent on the bus with an address outside this range between the beginning and the end of the instructions, the circuit 110 can detect a problem and for example stop the boot of the system 100. For example, a piracy attack can consist in making the circuit 110 seek to extract the boot instructions from a memory other than the memory 104, for example the memory 108. The instruction sent is then outside the authorized range and can thus identify an attack. To do this, the circuit 114-2 monitors the addresses of the data sent until the end of the boot instructions.

[0092] As a variant, the boot instructions can comprise, or can use, data located outside the range formed by the start (@START) and end (@END) addresses of the instructions. For example, a part of the boot instructions can be located in any other memory, for example in the memory 108. The internal memory can comprise a number of address ranges, optionally in a number of memories, comprising trusted boot data. These data are collected by the circuit 110, for example by means of the data bus 106, and also used to generate the representative word DIGEST. For example, these data should be the same each time the system is started, like the boot instructions located in the memory 104.

[0093] Another solution is to verify the instructions stored in the memory before sending the start instruction to make sure that the stored instructions indeed correspond to trusted instructions. However, without modifying the instructions stored in the memory, a pirate can cause the sent instructions to be different from the provided instructions, which would not be detected. One advantage of the embodiments described here is that they can identify modifications that occur during the transmission of the instructions.

[0094] An advantage of the described embodiments is that the elements are internal elements of the controller. In particular, the memory is an internal memory of the controller. The link between the circuits 102 and 110 and the memory is thus more secure.

[0095] Another advantage is that the verification of the code is done by the same controller that implements the instructions. Thus, the system does not have to have a second controller. Moreover, the circuit 110 does not include a processor, the comparison and calculation being made by logic circuits. The circuit 110 thus has a structure that is easy to implement.

[0096] Various embodiments and variants have been described. The person skilled in the art will understand that certain features of these embodiments can be combined and that other variants will readily suggest themselves to the person skilled in the art. In particular, the embodiments described here can be applied to instruction sets other than boot instructions. These instruction sets are the same instruction set at each execution.

[0097] Finally, the practical implementation of the embodiments and variants described herein is within the capabilities of the person skilled in the art based on the functional description provided above.

Claims

1. A method for verifying instructions and operands in an electronic system comprising a controller, the method comprising: extracting, via a first circuit (102) of the controller, instructions and operands from at least a first memory (104) internal to the controller by means of a matrix bus (106) of the controller; determining, by a second circuit internal to the controller, a start of the instructions by comparing an address of each instruction on the matrix bus to a start address stored in a second memory internal to the controller; determining, by the second circuit internal to the controller, an end of the instructions by comparing the address of each instruction on the matrix bus to an end address stored in the second memory; based on the determining of the start and end of the instructions, collecting the instructions and operands on the matrix bus (106) during the transferring of the instructions and operands to the first circuit (102) via the second circuit (110) internal to the controller, wherein the collecting of the instructions and operands starts in response to the determining of the start of the instructions, and wherein the collecting of the instructions and operands ends in response to the determining of the end of the instructions; and generating a word (DIGEST) representative of the instructions.

2. The method of claim 1, further comprising executing the instructions by the first circuit (102), the instructions being boot instructions of the electronic system.

3. The method of claim 1 or 2, further comprising comparing, by the second circuit (110), the word representative of the instructions to a reference word.

4. The method of claim 3, further comprising determining, by the second circuit (110), the instructions to be trusted in response to the word representative of the instructions being the same as the reference word.

5. The method of claim 3, further comprising determining, by the second circuit (110), the instructions to be untrusted in response to the word representative of the instructions being different from the reference word.

6. The method of claim 5, further comprising rebooting or shutting down the electronic system in response to the instructions being untrusted.

7. The method of claim 3, further comprising storing the reference word in the second memory from an initial programming of the electronic system.

8. The method of claim 1 or 2, wherein the first memory (104) is a non-volatile memory internal to the controller, the controller comprises a third memory (108), the first memory comprises the instructions, and the third memory comprises the operands.

9. The method of claim 1 or 2, wherein the matrix bus comprises buses forming rows and columns, each intersection between a row and a column being configured to allow or not allow transfer of information between the row and the column.

10. The method of claim 1 or 2, wherein the first circuit is coupled to the matrix by a first input / output and at least a second input / output, wherein the instructions are transferred on the first input / output and the operands are transferred on the second input / output. ​ 11. The method of claim 10, wherein: the first memory (104) is a non-volatile memory internal to the controller, the controller comprising a third memory (108), the first memory comprising the instructions and the third memory comprising the operands, the first memory (104) is coupled to first and second inputs / outputs of the first circuit (102) by the matrix bus (106) and the third memory (108) is coupled to a third input / output of the first circuit by the matrix bus.

12. The method of claim 1 or 2, wherein the operands comprise parameters for initializing at least one element of a protection unit of a memory, a "watchdog" type of circuit, or a circuit for protecting a non-volatile memory.

13. An electronic system comprising: a controller, the controller comprising: a first memory; a second memory; a matrix bus; a first circuit (102) configured to extract instructions and operands from at least the first memory (104) using the matrix bus; and a second circuit (110) configured to: determine a start of the instructions by comparing an address of each instruction on the matrix bus to a start address stored in the second memory; determine an end of the instructions by comparing the address of each instruction on the matrix bus to an end address stored in the second memory; based on the determination of the start and the end of the instructions, collect the instructions and the operands sent to the first circuit (102) on the matrix bus, wherein the collection of instructions and operands starts in response to the determination of the start of the instructions, and wherein the collection of the instructions and the operands ends in response to the determination of the end of the instructions, and generate a word (DIGEST) representing the instructions.

14. The electronic system of claim 13, wherein the first circuit (102) is configured to execute the instructions, the instructions being boot instructions of the electronic system.

15. The electronic system of claim 13 or 14, wherein the second circuit (110) is configured to compare the word representing the instructions to a reference word.

16. The electronic system of claim 15, wherein the second circuit (110) is configured to determine the instructions as trusted when the word representing the instructions is identical to the reference word, and to determine the instructions as untrusted when the word representing the instructions is not identical to the reference word.

17. The electronic system of claim 16, wherein the electronic system is configured to be re-booted or turned off if the second circuit (110) determines the instructions as untrusted.

18. The electronic system of claim 15, wherein the reference word is stored from an initial programming of the electronic system.

19. The electronic system of claim 13 or 14, wherein the first memory (104) is a non-volatile memory internal to the controller, the controller comprises a third memory (108), the first memory comprises the instruction, and the third memory comprises the operand.

20. The electronic system of claim 13 or 14, wherein the matrix bus comprises buses forming rows and columns, each intersection between a row and a column is configured to allow or not allow information transfer between the row and the column.

21. The electronic system of claim 13 or 14, wherein the first circuit is coupled to the matrix through a first input / output and at least a second input / output, wherein the instruction is transmitted on the first input / output and the operand is transmitted on the second input / output.

22. The electronic system of claim 21, wherein: the first memory (104) is a non-volatile memory internal to the controller, the controller comprises a third memory (108), the first memory comprises the instruction, and the third memory comprises the operand, and the first memory (104) is coupled to the first and second input / output of the first circuit (102) through the matrix bus (106), and the third memory (108) is coupled to the third input / output of the first circuit through the matrix bus.

23. The electronic system of claim 13 or 14, wherein the operand comprises a parameter for initializing at least one element of a memory protection unit, a "watchdog” type of circuit, or a circuit for protecting a non-volatile memory.

Citation Information

Patent Citations

  • Secure boot devices, systems, and methods

    CN108027861A

  • Secure system boot monitor

    US20190236281A1