Method and apparatus for secure decryption of encrypted data
By using a monotonic counter and key derivation circuit in the processing device to generate a count value and derive the encryption key, and then combining it with a cryptographic processor for decryption, the problem of insufficient encryption key security in the processing device is solved, and secure decryption of encrypted data and security protection of the device are achieved.
Patent Information
- Application Number
- CN202210343079.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-03-29
- Filing Date
- 2022-03-31
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2042-03-31
AI Technical Summary
In existing technologies, the security of encryption keys in processing devices is difficult to protect effectively, especially when the device cannot be accessed from the outside, resulting in insufficient security for data decryption.
By using a monotonic counter to generate a count value, combined with a key derivation circuit and a cryptographic processor, an encryption key is derived based on the count value and transmitted to the cryptographic processor for decryption via a dedicated bus. By limiting the decryption time period, the security of encrypted data is ensured.
It enables secure decryption of encrypted data, improves the security of encryption keys in processing devices, prevents unauthorized access and decryption, and ensures data integrity and privacy.
Smart Images

Figure CN115150085B_ABST
Abstract
Description
[0001] Cross Reference to Related Applications
[0002] This application claims priority to French application No. 2103318, filed on March 31, 2021, which is incorporated herein by reference. TECHNICAL FIELD
[0003] The present disclosure relates to the field of methods and devices for protecting electronic circuits, and in particular to devices and methods for decrypting data. BACKGROUND
[0004] Some processing devices include cryptographic processors that need to use encryption keys that are not accessible from outside the device.
[0005] For example, a processing device operates by executing code that is stored in non-volatile memory of the device, which is used over the lifetime of the circuit. For security purposes, certain code is stored in encrypted fashion, and an encryption key can be loaded to decrypt this code. SUMMARY
[0006] In various embodiments, the security of storing such encryption keys is improved.
[0007] One embodiment provides a method of decrypting encrypted data, the method comprising: generating, by a monotonic counter of a processing device, a first count value; deriving, using a key derivation circuit, a first encryption key based on the first count value; transmitting the first encryption key to a cryptographic processor; and decrypting, based on the first encryption key, first encrypted data.
[0008] According to one embodiment, the first encrypted data comprises a first set of one or more other encrypted encryption keys associated with the first count value.
[0009] According to one embodiment, the method further comprises: selecting the first set of other encrypted encryption keys from a memory; and providing the first set of other encrypted encryption keys to the cryptographic processor, wherein decrypting the first data comprises decrypting, by the cryptographic processor, the first set of other encrypted encryption keys based on the first encryption key.
[0010] According to one embodiment, the method further comprises: decrypting, by the cryptographic processor or another cryptographic processor, first other encrypted data stored in a memory or another memory based on the first set of other decrypted encryption keys.
[0011] According to one embodiment, the decrypting of the first other encrypted data is performed by the cryptographic processor, wherein the first set of other decrypted encryption keys is stored in a memory of the cryptographic processor.
[0012] According to one embodiment, the method further comprises generating, by the monotonic counter of the processing device, a second count value; deriving, using the key derivation circuit, a second encryption key based on the second count value; transmitting the second encryption key to the cryptographic processor; and decrypting the second encrypted data based on the second encryption key.
[0013] According to one embodiment, at a first boot of the processing device, the monotonic counter is initialized to the first count value, the method further comprising, at a second boot of the processing device, initializing the monotonic counter to a second count value.
[0014] According to one embodiment, the method comprises another boot of the processing device during which, if a device state condition is met, the monotonic counter is initialized to the first count value.
[0015] According to one embodiment, the state condition corresponds to a programmed state of the memory region.
[0016] According to one embodiment, the memory is configured such that access to the first encrypted data is not allowed based on a count value greater than the first count value.
[0017] According to one embodiment, transmitting the first encryption key to the cryptographic processor is performed via a dedicated bus.
[0018] One embodiment provides a data processing device comprising: a monotonic counter configured to generate a first count value; a key derivation circuit configured to derive, using a key derivation function, a first encryption key based on the first count value; and a cryptographic processor configured to receive the first encryption key and to decrypt first encrypted data based on the first encryption key.
[0019] One embodiment provides a method for decrypting encrypted data, the method comprising: receiving, from a monotonic counter of a processing device, a first count value; deriving, using a key derivation circuit, a first master encryption key based on the first count value and a master encryption key; transmitting the first master encryption key to a cryptographic processor; and decrypting, based on the first master encryption key, a first encryption key stored in a non-volatile memory.
[0020] According to one embodiment, the method further comprises decrypting, based on the first master encryption key, another first encryption key, wherein the first encryption key and the another first encryption key comprise a first set of encrypted encryption keys associated with the first count value.
[0021] According to one embodiment, the non-volatile memory is configured such that access to the first encryption key is not allowed based on a count value greater than the first count value.
[0022] According to one embodiment, the method further comprises transmitting the first encryption key to the cryptographic processor or another cryptographic processor; and decrypting the first encrypted code based on the first encryption key.
[0023] According to one embodiment, the method further comprises initiating a boot sequence, initializing the monotonic counter providing the first count value and reading and executing the first code obtained from decrypting the first encrypted code.
[0024] According to one embodiment, the method further comprises receiving a second count value from the monotonic counter of the processing device, deriving a second master encryption key based on the second count value using the key derivation circuit, transmitting the second master encryption key to the cryptographic processor, decrypting the second encryption key based on the second master encryption key, transmitting the second encryption key to the cryptographic processor or another cryptographic processor, and decrypting the second encrypted code based on the second encryption key.
[0025] According to one embodiment, at a first boot of the processing device, the monotonic counter is initialized to the first count value, the method further comprises, at a second boot of the processing device, initializing the monotonic counter to a second count value.
[0026] According to one embodiment, the method further comprises performing another boot of the processing device, during which, if a device state condition is met, the monotonic counter is initialized to the first count value, wherein the state condition corresponds to a programmed state of the memory region. BRIEF DESCRIPTION OF DRAWINGS
[0027] The above features and advantages and other features and advantages will be more clearly understood from the following description of specific embodiments, which is given by way of example only, and in conjunction with the accompanying drawings, of which:
[0028] Figure 1 An electronic device according to one embodiment of the present description is represented very schematically in block diagram form;
[0029] Figure 2 illustrates Figure 1 an example of operation of a processing device of
[0030] Figure 3 is a flowchart representing operations of a method of decrypting an encrypted code by a cryptographic processor according to an example of one embodiment of the present description; and
[0031] Figure 4 represents data and code accessible during a secure boot according to another embodiment of the present description;
[0032] Figure 5 is a flowchart representing operations of a secure boot method of a processing device according to an example of one embodiment of the present description; and
[0033] Figure 6 is a flowchart representing operations of a security boot method of a processing device according to another example embodiment of the present specification. DETAILED DESCRIPTION
[0034] The same features are denoted by the same reference signs in the various figures. In particular, structural and / or functional features common to the various embodiments can have the same reference signs and can be provided with the same structural, dimensional and material properties.
[0035] For the sake of clarity, only the operations and elements useful for understanding the embodiments described herein are illustrated and described in detail. In particular, the design of the processing device is well known to the person skilled in the art and certain components are not described hereinafter.
[0036] Unless otherwise stated, when two elements are referred to as being connected together, this means that they are directly connected, without any intermediate element other than a conductor, and when two elements are referred to as being coupled together, this means that the two elements can be connected or they can be coupled via one or more other elements.
[0037] In the following disclosure, unless otherwise stated, when an absolute position qualifier such as the terms "front", "back", "top", "bottom", "left", "right" or the like, or a relative position qualifier such as the terms "above", "below", "higher", "lower" or the like, or an orientation qualifier such as "horizontal", "vertical" or the like, is referred to, reference is made to the orientation shown in the figures.
[0038] Unless otherwise stated, the expressions "about", "approximately", "substantially" and "in the order of" mean within 10%, preferably within 5%.
[0039] Figure 1 An electronic device 100 comprising a processing device 102 is represented very schematically in the form of a block diagram.
[0040] The electronic device 100 is for example an electronic board such as a microcircuit board, a computer hardware, a microprocessor circuit, etc.
[0041] The processing device 102 comprises for example a non-volatile memory 104 (NV MEM), such as a flash memory. Alternatively, other types of non-volatile memory can be used. The processing device 102 further comprises a monotonic counter 106 (MONOTONIC COUNTER).
[0042] Monotonic counters are known in the background art, examples of such counters being described in the publication "Virtual Monotonic Counters and Count-Limited Objects using a TPM without a Trusted OS" by L.F.G. Sarmenta, M. Van Dijk, C.W. O'Donnell, J. Rhodes and S. Devadas, in particular in section 3 of this document. Embodiments of counters implemented in hardware and / or software are described herein. The monotonic counter 106 is for example implemented in hardware by digital circuits such as an Application-Specific Integrated Circuit (ASIC). The monotonic counter is configured to hold a count value accessible at the output of the counter. After an increment command, the monotonic counter increases its count value by one or more units, but after each increment, the operation is irreversible. Indeed, the monotonic counter is configured so that its count value never decreases. Moreover, between two increments, the count value is protected from any modification, so it cannot be erased nor modified. Only the increment command allows replacing the current value by a new value higher than the current value.
[0043] For example, the monotonic counter 106 is configured so that no command other than a reset of the processing device allows returning to a previous value when the increment command is executed. For example, in case the count value is stored in a volatile manner, each time the processing device is switched off (powered off), the count value is lost, and each time the device is switched on again, the monotonic counter generates again the initial count value. In case the count value is stored in a non-volatile storage element. At each reboot, the initial count value is for example written back to the non-volatile storage element of the monotonic counter.
[0044] The processing device 102 further comprises a non-secure general purpose processor 110 (CPU). The general purpose processor 110 is coupled to the monotonic counter 106 as well as to a non-volatile memory 114 (NV MEM) and to the non-volatile memory 104 via a bus 128, for example. The memory 114 is for example a flash memory, but other types of non-volatile memory can be used as well.
[0045] The general purpose processor 110 is further coupled to a cryptographic processor (CRYPTO) 116 as well as to a RAM (Random Access Memory) 112 via the bus 128.
[0046] The cryptographic processor 116 is further coupled to a key derivation circuit 118 (KDF), which has an input connected to the output of the monotonic counter 106. Specifically, the key derivation circuit 118 receives the current count value (TIL) from the monotonic counter 106 at this input. The count value TIL generated by the monotonic counter 106 is, for example, a time isolation level value, which allows for time control of the decryption operation. Specifically, the key derivation circuit 118 is configured to, for example, generate a master encryption key MK derived by the key derivation function based on the count value TIL generated by the monotonic counter 106 and optionally based on the device master encryption key (HW).
[0047] The master encryption key MK is provided to the cryptographic processor 116, for example, via a dedicated bus 119. The cryptographic processor 116 is configured, for example, to decrypt encrypted data based on the master encryption key MK derived from circuitry 118. A monotonic counter 106 is controlled, for example, to increment its count value TIL during operation of device 102, such as during the boot phase. Since the key derivation function implemented by circuitry 118 takes this count value TIL into account, the decryption of data by the cryptographic processor 116 based on the corresponding master encryption key MK is related to this count value. Therefore, the time period during which data can be decrypted can be limited.
[0048] In one embodiment, the data decrypted based on the master encryption key MK is an encrypted encryption key. For example, non-volatile memory 114 contains encrypted data, such as the encrypted boot code of processing device 102. The encryption key that allows this encrypted data to be decrypted is also encrypted and stored in memory 104. Figure 1 In the example shown, the encrypted encryption keys are stored in regions 122, 124, and 126 (KEYSET0, KEYSET1, and KEYSET2) of memory 104. For example, the key set stored in region 122 is associated with a first TIL count value, the key set stored in region 124 is associated with a second count value TIL that is greater than the first count value, and the key value stored in region 126 is associated with a third count value TIL that is greater than the second count value.
[0049] In some cases, memory 104 includes key selection circuitry 120, which receives, for example, a count value TIL and an index value transmitted by cryptographic processor 112, thereby allowing selection of a given key from each key.
[0050] Figure 2 The diagram shows... Figure 1 This is an example of an operation performed by the processing device 102 to decrypt an encryption key stored in the non-volatile memory 114. Specifically, Figure 2A key derivation circuit (KDF) 118, memories 104, 112 and 114, and a crypto processor (CRYPTO) 116 are illustrated. In Figure 2 The dashed arrows represent data transfer over bus 128, while the solid arrows represent transfer over dedicated buses or connections.
[0051] In Figure 2 The example illustrated shows that the non-volatile memory 114 comprises three encrypted codes 216a, 218a and 220a (CODE0_U, CODE1_U and CODE2_U). These codes are, for example, boot codes. The crypto processor 116 is able to decrypt each of these encrypted codes using an encryption key stored in the memory 104 to generate three corresponding decrypted codes 216b, 218b, 220b (CODE0_C, CODE1_C and CODE2_C). A device master key (HW MASTER KEY) is, for example, securely stored in the non-volatile memory 202, which can be, for example, part of the memory 104. The master encryption key is, for example, a value unique to each device and is, for example, generated based on a PUF - Physically Unclonable Function. The advantage of using a device-specific master encryption key is that it is difficult to clone the device.
[0052] In Figure 2 The selection circuit 120 is represented by a multiplexer which receives the count value TIL and the index value as control signals. In other examples, only one or the other of these values is used for the selection, or the selection is made only in software, for example by the general purpose processor 110 (not illustrated in Figure 2 ).
[0053] In a first operating phase of the device 102, the monotonic counter 106 generates a first count value TIL, for example equal to 0, and transmits this value to the key derivation circuit 118 and to the selection circuit 120. The device master key is also transmitted, for example, to the key derivation circuit 118, which derives a first master encryption key MK0 204 based on the first count value TIL 0 and, in some cases, also on the device master key 202. The key derivation circuit 118 then transmits the key MK0 to the crypto processor 116, allowing one or more encrypted encryption keys to be decrypted from the memory 104. In this example, these are the encrypted encryption keys associated with the count value TIL 0, i.e. the first encryption key {KEY#1.0}MK0 and another encryption key {KEY#2.0}MK0.
[0054] In this example, the first encrypted key {KEY#2.0}MK0 is decrypted. The key KEY#2.0 resulting from this decryption is for example retained in the cryptographic processor 116 before being further used to decrypt the first encrypted code 216a. The first encrypted code 216a is then transmitted to the cryptographic processor 116 and decrypted using the key KEY#2.0. The key KEY#1.0 resulting from the decryption of the other encrypted key {KEY#1.0}MK0 is for example used to decrypt the other encrypted code not represented in Figure 2 In this example, the first encrypted key {KEY#2.0}MK0 is decrypted. The key KEY#2.0 resulting from this decryption is for example retained in the cryptographic processor 116 before being further used to decrypt the first encrypted code 216a. The first encrypted code 216a is then transmitted to the cryptographic processor 116 and decrypted using the key KEY#2.0. The key KEY#1.0 resulting from the decryption of the other encrypted key {KEY#1.0}MK0 is for example used to decrypt the other encrypted code not represented in
[0055] In a second operating phase of the device 102, the monotonic counter 106 generates a second count value TIL, for example equal to 1. The first unencrypted code 216b or another code executed during the first operating phase for example comprises an instruction to increment the monotonic counter 106. After this increment of the count value TIL, the key derivation circuit 118 is no longer able to derive the master encryption key MK0 since the value of TIL is greater than the first value TIL0. Moreover, in some examples, the selection circuit 120 is configured to inhibit access to the encrypted encryption keys associated with the count value TIL0 based on the count value TIL being greater than 0.
[0056] The second count value TIL is transmitted to the key derivation circuit 118 as well as to the selection circuit 120. The device master key is for example also transmitted to the key derivation circuit 118 which derives a second master encryption key MK1 208 based on the second count value TIL1 and in some cases also based on the device master key 202. The key derivation circuit 118 then transmits the key MK1 to the cryptographic processor 116, thereby enabling decryption of one or more encrypted encryption keys from the memory 104. In this example, these are the encrypted encryption keys associated with the count value TIL1, i.e. the encrypted key {KEY#1.1}MK1.
[0057] In this example, the encrypted key {KEY#1.1}MK1 is decrypted. The key KEY#1.1 206 resulting from this decryption is for example retained in the cryptographic processor 116 before being further used to decrypt the second code 218a. The second encrypted code 218a is then transmitted to the cryptographic processor 116 and decrypted using the key KEY#1.1. The second unencrypted code 218b corresponding to the decryption of the first encrypted code 218a is for example transmitted to the memory 112 and for example executed by the processor 110.
[0058] In a third operating phase of the device 102, the monotonic counter 106 generates a third count value TIL, for example equal to 2. For example, the second unencrypted code 218b or another code executed during the second operating phase comprises an instruction to increment the monotonic counter 106. After this increment of the count value TIL, the key derivation circuit 118 is no longer able to derive the master encryption keys MK0 and MK1, since the value of TIL is greater than the first and second values TIL0 and TIL1. Additionally, in some examples, the level value TIL2 is transmitted to the selection circuit 120, which is configured to, based on a count value TIL greater than 1, disable access to the encrypted encryption keys associated with the count values TIL0 and TIL1.
[0059] The third count value TIL is transmitted to the key derivation circuit 118 as well as to the selection circuit 120. The device master key is also transmitted to the key derivation circuit 118, which derives a third master encryption key MK2 212 based on the second count value TIL2 and, in some cases, also based on the device master key 202. The key derivation circuit 118 then transmits the key MK2 to the cryptographic processor 116, allowing decryption of one or more encrypted encryption keys of the memory 104. In this example, these are the encryption keys associated with the count value TIL2, i.e. the encryption keys {KEY#3.2}MK2.
[0060] In this example, the encryption keys {KEY#3.2}MK2 are decrypted. The keys KEY#3.2 214 resulting from this decryption are for example retained in the cryptographic processor 116 and are then in turn used to decrypt the third code 220a. The third encrypted code 220a is then transmitted to the cryptographic processor 116 and decrypted using the keys KEY#3.2. The third unencrypted code 220b corresponding to the decryption of the second encrypted code 220a is for example transmitted to the memory 112 and for example executed by the processor 110.
[0061] Figure 3 is a flowchart representing the operations of a method for decrypting encrypted code according to one embodiment of the present specification. This method is for example implemented by the general processor 110, the monotonic counter 106, the selection circuit 120 and the cryptographic processor 108 of the processing device of Figure 1
[0062] In step 301 (initialize counter), the monotonic counter 106 is initialized to an initial value, which is a natural number. In the example where the count value TIL is stored in a volatile manner, each power-up of the processing device causes the count value to be initialized, for example to 0. In another example where the count value is stored on a non-volatile storage element, each power-up of the processing device causes the current count value to be replaced with the initial count value, for example equal to 0. Step 301 occurs, for example, after the boot of the processing device 102.
[0063] In some embodiments, the initial count value generated upon power-up can vary depending on the context of the processing device. For example, one or more count values correspond to an isolation level reserved for the manufacturer of the device 102, and the power-up of an intermediary entity between the manufacturer and the end user and / or the end user will trigger a count value higher than these reserved count values. For example, if the count value 0 is reserved for the manufacturer, the power-up of an intermediary entity between the manufacturer and the end user and / or the end user will trigger a count value equal to 1 and the sensitive data associated with the isolation level 0 will not be accessible. For example, once the manufacturing is completed, one or more bits stored in the non-volatile memory 104 or other memory are programmed to ensure that the count value is initialized to 1. In one example, these bits correspond to a signature protection value indicating the initial count value to be applied. For example, the signature is generated based on an encryption key and can for example correspond to a MAC (Message Authentication Code) signature. This value is provided, for example by the bus 128, to the monotonic counter 106. The monotonic counter 106 can then be restarted to 0 or another value during the lifetime of the device by changing the signature protection value.
[0064] In step 303 (derive MKi through KDF) following step 301, the monotonic counter 106 transmits the current count value TILi to the key derivation circuit 118. The key derivation circuit 118 generates the derived master key MKi based on the value of the level TIL i and, in some cases, based on the device master key. Other parameters can also be considered to derive the derived master key MKi.
[0065] In step 305 (transmit MKi to CRYPTO), following step 303, the derived master key MKi is transmitted to the cryptographic processor 116.
[0066] In step 307 (select key index), the index value of the encrypted encryption key is identified, for example from the memory 104, along with the count value TIL i in some cases, is transmitted to the selection interface 120.
[0067] As an example, in step 307, the general purpose processor 110 instructs decryption of the encryption code for which the encryption key is associated with the value of the level TIL i. The index value information identifying the corresponding encryption key is for example transmitted to the selection circuit 120, and the selection circuit 120 selects the corresponding encrypted encryption key based on the level value TIL i and the index value.
[0068] Step 307 is presented as an example, and other ways of selecting the key from the memory 104 are possible.
[0069] In step 309 (transmit KEY_U index on TIL i to CRYPTO), after step 307, the encrypted encryption key selected in step 307 is transmitted to the crypto processor 116, for example over the bus 128. In another example, the selected encrypted encryption key is transmitted to the crypto processor 116 over a dedicated bus (not shown) that specifically connects the memory 104, in particular the regions 122, 124 and 126, and the crypto processor 116.
[0070] In step 311 (decrypt KEY_U index), after step 309, the crypto processor 116 decrypts the encryption key transmitted to the crypto processor 116 in step 309 using the derived master key MKi generated in step 303. The unencrypted encryption key is thus obtained and for example retained in a memory of the crypto processor 116. In other words, the unencrypted encryption key is not transmitted to any other processor or any memory of the device 102.
[0071] In step 313 (transmit CODE_U on TIL i to CRYPTO), the encryption code CODE_U is transmitted to the crypto processor 116 over the data bus 128, for example under control of the general purpose processor 110.
[0072] In step 315 (decrypt CODE U), after step 315, the encrypted code and / or data CODE U is decrypted by the cryptographic processor 116 using the encryption key selected in step 307 and decrypted in step 311. Once the CODE U code has been decrypted, it is transmitted, for example, over the bus 128 to the RAM 112 memory, which is then executed by the general purpose processor 110. For example, after executing the decrypted code, the method continues to step 317 (other code on TIL i?), in which the general purpose processor 110 determines whether other encrypted code and / or data, for example, stored in the memory 114 and having an encryption key associated with the count value TIL i, is waiting to be decrypted. If this is the case (branch Y), the method continues at step 307, in which a new index value for the new code is determined, and the encrypted encryption key associated with the level value TIL and identified by the new index value is selected by the selection circuit 120.
[0073] If, after step 317, all encrypted code associated with the encryption key associated with the count value TIL i has been correctly decrypted and transmitted to the RAM 112 memory, (branch N) the method continues to step 319 (wait for new TIL i value), in which the selection circuit 120 is waiting for a new count value TIL i. For example, when moving from one operating phase to another of the processing circuit 102, the count value TIL i is incremented. When the monotonic counter 106 generates a new count value TIL i, the method resumes at step 303 and the new encryption key associated with the TIL level value lower than the new TIL level value is no longer accessible.
[0074] Figures 4-6 An embodiment of the present description is illustrated in which the encrypted data is boot code and / or encryption keys associated with those codes, and the level value TIL is incremented at the end of each step in the boot sequence. Each level value TIL also corresponds to one or more boot codes associated with each boot step; these codes will not be accessible while the current level value TIL is greater than its associated level value TIL.
[0075] In Figure 4In the illustrated example, memory areas 406, 408 and 409 store sensitive data associated with boot code 400, 402 and 404 respectively stored in non-volatile memory 114. Areas 406, 408 and 409 are for example separate areas from areas 400, 402 and 404 but remain associated with an isolation level corresponding to the isolation level of the boot code with which the data is associated. The sensitive data comprises for example one or more encryption keys stored in each area 406, 408 and 409 and each of these areas is contained in non-volatile memory 104. According to another embodiment, each area 406, 408 and 409 is a sub-area of corresponding area 400, 402 and 404.
[0076] At start-up Figure 4 During a first step 410 of the processing device illustrated at the top, the current count value is for example equal to 0. At the end of step 410, the current count value is for example equal to 1. Figure 4 In the illustrated example, isolation level 0 is associated with a first code (CODE0) and first sensitive data (KEY0) contained in area 400. Memory access control circuit 114 (not illustrated) and selection circuit 120 are configured for example so that the first code and the first data are exclusively accessible when the current count value is equal to 0. However, during step 410, access control circuit and selection circuit authorize for example access to all memory areas 400, 402 and 404 and to all areas 406, 408 and 409. Indeed, in some cases, in order to anticipate subsequent steps in the boot method, one or more other boot codes (CODE1, CODE2) can be accessed for reading during step 410.
[0077] For example, as soon as first code CODE0 is executed, general purpose processor 110 controls a first increment of the current count value by monotonic counter 106. For example, the first code comprises a command requesting the counter to be incremented. The command is for example transmitted to a control register (not illustrated) of the monotonic counter.
[0078] After this first increment, the current count value of monotonic counter 204 is for example equal to 1, corresponding to a second boot step 511. Access control circuit and selection circuit 120 receive the new current count value and are configured to prevent any access to the first code and the first data associated with isolation level 0 based on this count value being greater than 0. In other words, memory areas 400 and 406 are locked based on any count value strictly greater than 0.
[0079] Isolation level 1 is associated with a second code (CODE1) contained in area 402 and with second data (KEY1) contained in area 408. According to one embodiment, a third code (CODE2) associated with isolation level 2 and contained in area 404 can be accessed for reading based on the current count value being equal to 1.
[0080] For example, once the second code CODEl is executed, the general-purpose processor 110 controls a second increment of the current count value by the monotonic counter 106. For example, after this second increment, the current count value of the monotonic counter 106 is equal to 2, corresponding to a third boot step 412. The isolation level 2 is associated with a third code CODE2 and a third data (KEY2). The access control circuit and the selection circuit 120 receive the new count value and are configured to prevent any access to the first and second codes and to the first and second data associated with an isolation level lower than or equal to 1, based on this count value greater than 1.
[0081] According to one embodiment, when the last boot code (e.g. the third boot code) is executed, the general-purpose processor 110 controls a third increment of the current count value by the monotonic counter. The access control circuit and the selection circuit 120 then lock any access to the first, second and third boot codes and to the first, second and third data.
[0082] According to another embodiment, when the last boot code (e.g. the third boot code) is executed, the current count value is not incremented by the monotonic counter 106 and the access control circuit still allows access to the third boot code and to the third data.
[0083] Figure 5 is a flowchart representing operations of a secure boot method of a processing device according to an example embodiment of the description. The method is implemented by the general-purpose processor 110, the monotonic counter 106, the access control circuit and the selection circuit 120 of the processing device, for example. Figure 1
[0084] In step 501 (start of the boot sequence), the processing device 102 is started. In one example, this is the first boot of the device 102 after its manufacturing. In another example, it is a boot performed by an intermediate entity between the manufacturer of the device 102 and its end user. In yet another example, it is a so-called operational boot of the electronic device 100 performed by the end user.
[0085] In step 503 (initialize the counter), after step 501, the monotonic counter is initialized to an initial value, the initial value being a natural number. In an example where the count value is stored in a volatile manner, each boot of the processing device causes the count value to be initialized, for example to 0 or 1. In another example where the count value is stored in a non-volatile manner, each boot of the processing device causes the current count value to be replaced by the initial count value, for example equal to 0 or equal to 1.
[0086] In certain embodiments, the initial count value generated upon booting can vary depending on the state or context of the processing device 102. For example, one or more count values correspond to one or more isolation levels reserved for an initial setup phase of the device 102, including for example installation of firmware. Data and / or code associated with these isolation levels are for example used for this initial setup.
[0087] For example, after manufacturing, the processing device 102 has a context "blank" and the initial count value is equal to the value reserved for setup, such as 0. Once the setup is completed, the context of the device becomes for example "setup completed". With this new context, a count value greater than the reserved count value will be triggered, for example equal to 1, for example by an intermediary entity between the manufacturer and the end user and / or by the end user powering up the device 102. Thus, the boot code and sensitive data associated with the isolation level corresponding to the reserved count value will not be accessible.
[0088] For example, the context of the device is detected by the presence of a voltage on a boot pin of the device, for example applied by adding a jumper between the boot pin and another pin of the supply voltage. Additionally or alternatively, the context of the device is detected by the value of one or more bits stored in a non-volatile, protected manner in the memory 104 or another memory.
[0089] In one example, the general purpose processor 110 is arranged to detect the context of the device 102 upon powering up the device 102 and to configure the initial count value of the monotonic counter 106 accordingly. In another example, the monotonic counter 106 is arranged to detect the context of the device 102 itself upon powering up the device 102 and to configure its initial count value itself.
[0090] In step 505 (read and execute code at level i), the data and boot code associated with isolation level i are read by the general purpose processor 110 and the boot code associated with isolation level i is executed following step 503. Once the code of level i is executed, the general purpose processor 110 compares the count value i to the value N at step 507 (i = N?), where N is the count value associated with the last step of the boot sequence, in other words the boot code of isolation level N is executed last according to embodiments of the present description. For example, in the example of Figure 4 N is equal to 2. If i is not equal to N (N branch), the method continues to step 509 (i = i + 1) where the general purpose processor triggers an increment of the count value. For example, the count value is increased from i to i + 1. The increment can also increase the i value by several units. The method then continues at step 505.
[0091] If, as a result of the comparison step 507, the count value is equal to N (branch Y), the method ends at step 511 (end of boot) where the boot of the processing device ends. According to one embodiment, the current count value remains equal to N after step 511. According to another embodiment, the count value is incremented in step 511 and the current count value becomes equal to N+1. In this second case, the access control circuit and the selection circuit are configured to prevent access to all boot code based on this count value.
[0092] Figure 6 is a flowchart representing the operations of a secure boot method of a processing device according to another example embodiment of the present specification. This method is implemented, for example, by the general purpose processor 110, the monotonic counter 106, and the access control circuit and the selection circuit 120 of the processing device of Figure 1
[0093] Steps 601 and 603 are similar to steps 501 and 503 of the processing device of Figure 5 and will not be described again.
[0094] In step 605 (access code on levels i and i+1 and execute code on level i), after step 603, the general purpose processor 110 accesses data and boot code associated with the isolation level i+1 and the boot code(s) associated with the isolation level i are executed.
[0095] In one example, the data or code associated with the isolation level i contains one or more encryption or non-encrypted encryption keys that will be used when executing one or more codes associated with the isolation level i+1. Thus, for example, write access is granted to the memory region associated with the isolation level i+1 to provide the keys to the code associated with the isolation level i+1.
[0096] In another example, the code associated with the isolation level i contains instructions for verifying the integrity of the data and / or code associated with the isolation level i+1. Thus, in order to perform this verification, read access is allowed to the memory region associated with the isolation level i+1.
[0097] In step 607 (i=i+1), after step 605, the count value is incremented. For example, the count value is increased from i to i+1. In other examples, the increment increases i by several units.
[0098] In step 609 (i=N?), the general purpose processor 110 compares the count value i to the value N, where N is defined as described with respect to step 507 of the processing device of Figure 5 If the value i is not equal to N (branch N), the method returns to step 605.
[0099] In the case where the count value is equal to N in the comparison step 609 (branch Y), the method continues to step 613 (execution of the code at level N), in which the boot code(s) associated with the isolation level N is executed.
[0100] The boot processing device ends with step 615 (end of boot), which is similar to step 511 in Figure 5 and will not be described again.
[0101] Figure 6 The implementation of the method shown in Figure 5 allows for interleaved reading of the boot code. Indeed, when the count value is lower than the level value, the boot code associated with the isolation level is read. This saves time with respect to the implementation of the method shown in
[0102] One advantage of the described embodiments is that the code, as well as the confidential, sensitive data, is effectively protected by the use of a monotonic counter and a key derivation circuit to lock the decryption of the encryption key.
[0103] Various embodiments and variants have been described. The person skilled in the art will understand that certain features of these embodiments can be combined and that other variants will readily suggest themselves to the person skilled in the art. In particular, different types of processors can be used. Furthermore, the number of isolation levels can vary.
[0104] Finally, the practical implementation of the embodiments and variants described herein is within the capabilities of the person skilled in the art based on the functional description provided above. In particular, the implementation of the encryption key is within the capabilities of the person skilled in the art.
Claims
1. A method for decrypting encrypted data, the method comprising: generating, by a monotonic counter of a processing device, a first count value; deriving, using a key derivation circuit, a first encryption key based on the first count value; transmitting the first encryption key to a cryptographic processor; decrypting, based on the first encryption key, first encrypted data stored in a non-volatile memory; and preventing access to the first encrypted data based on a current count value from the monotonic counter that is greater than the first count value, wherein the first encrypted data includes a first set of one or more further encrypted encryption keys associated with the first count value.
2. The method of claim 1, wherein the non-volatile memory comprises a plurality of separate non-volatile memories.
3. The method of claim 1, further comprising: selecting, from the non-volatile memory, the first set of one or more further encrypted encryption keys; and providing the first set of one or more further encrypted encryption keys to the cryptographic processor, wherein decrypting the first encrypted data comprises decrypting, by the cryptographic processor, the first set of one or more further encrypted encryption keys based on the first encryption key.
4. The method of claim 3, further comprising: decrypting, by the cryptographic processor or another cryptographic processor, first other encrypted data stored in the non-volatile memory or another memory based on the decrypted first set of one or more further encrypted encryption keys.
5. The method of claim 4, wherein decrypting the first other encrypted data is performed by the cryptographic processor, the decrypted first set of one or more further encrypted encryption keys being stored in the non-volatile memory of the cryptographic processor.
6. The method of claim 1, further comprising: generating, by the monotonic counter of the processing device, a second count value; deriving, using the key derivation circuit, a second encryption key based on the second count value; and transmitting the second encryption key to the cryptographic processor; and decrypting, based on the second encryption key, second encrypted data.
7. The method of claim 6, wherein the monotonic counter is initialized to the first count value at a first boot of the processing device, the method further comprising initializing the monotonic counter to the second count value at a second boot of the processing device. performing another boot of the processing device if a device state condition is met, during which the monotonic counter is initialized to the first count value.
9. The method of claim 8, wherein the device state condition corresponds to a programmed state of a region of the non-volatile memory storing the first encrypted data.
10. The method of claim 3 or 9, wherein the non-volatile memory comprises a plurality of separate non-volatile memories. 8. The method of claim 7, further comprising: 11. The method of claim 1, wherein transmitting the first encryption key to the cryptographic processor is performed via a dedicated bus.
12. A data processing device comprising: a monotonic counter configured to generate a first count value; a key derivation circuit configured to derive, using a key derivation function, a first encryption key based on the first count value; a cryptographic processor configured to receive the first encryption key and decrypt, based on the first encryption key, first encrypted data; and a non-volatile memory configured to store the first encrypted data and prevent access to the first encrypted data based on a current count value from the monotonic counter that is greater than the first count value, wherein the first encrypted data comprises a first set of one or more further encrypted encryption keys associated with the first count value.
13. A method for decrypting encrypted data, the method comprising: receiving, from a monotonic counter of a processing device, a first count value; deriving, using a key derivation circuit, a first master encryption key based on the first count value and a master encryption key; transmitting the first master encryption key to a cryptographic processor; decrypting, based on the first master encryption key, a first encryption key stored in a non-volatile memory; and preventing access to the first encryption key based on a current count value from the monotonic counter that is greater than the first count value, wherein the first encryption key comprises a first set of encrypted encryption keys associated with the first count value.
14. The method of claim 13, further comprising: decrypting, based on the first master encryption key, another first encryption key, wherein the another first encryption key comprises the first set of encrypted encryption keys associated with the first count value.
15. The method of claim 13, wherein the non-volatile memory comprises a plurality of separate non-volatile memories.
16. The method of claim 13, further comprising: transmitting the first encryption key to the cryptographic processor or another cryptographic processor; and decrypting, based on the first encryption key, a first encrypted code.
17. The method of claim 16, further comprising: starting a boot sequence; initializing the monotonic counter that provides the first count value; and reading and executing a first decrypted code obtained from decrypting the first encrypted code.
18. The method of claim 13, further comprising: receiving, from the monotonic counter of the processing device, a second count value; deriving, using the key derivation circuit, a second master encryption key based on the second count value; transmitting the second master encryption key to the cryptographic processor; decrypting, based on the second master encryption key, a second encryption key; transmitting the second encryption key to the cryptographic processor or another cryptographic processor; and decrypting, based on the second encryption key, a second encrypted code.
19. A data processing device comprising: a monotonic counter configured to generate a first count value; a key derivation circuit configured to derive, using a key derivation function, a first encryption key based on the first count value; a cryptographic processor configured to receive the first encryption key and decrypt, based on the first encryption key, first encrypted data; and a non-volatile memory configured to store the first encrypted data and prevent access to the first encrypted data based on a current count value from the monotonic counter that is greater than the first count value, wherein the first encrypted data comprises a first set of one or more further encrypted encryption keys associated with the first count value.
20. The data processing device of claim 19, wherein the first encryption key comprises a first set of encrypted encryption keys associated with the first count value.
21. The data processing device of claim 19, wherein the non-volatile memory comprises a plurality of separate non-volatile memories.
22. The data processing device of claim 19, further comprising: a second cryptographic processor configured to receive the first encryption key and decrypt, based on the first encryption key, a first encrypted code.
23. The data processing device of claim 22, further comprising: a boot sequence configured to initialize the monotonic counter that provides the first count value.
24. The data processing device of claim 19, further comprising: a second key derivation circuit configured to derive, using a key derivation function, a second master encryption key based on a second count value from the monotonic counter; a second cryptographic processor configured to receive the second master encryption key and decrypt, based on the second master encryption key, a second encryption key; a second non-volatile memory configured to store the second encryption key and prevent access to the second encryption key based on a current count value from the monotonic counter that is greater than the second count value, wherein the second encryption key comprises a second set of encrypted encryption keys associated with the second count value.
25. The data processing device of claim 24, further comprising: a second boot sequence configured to initialize the monotonic counter that provides the second count value.
26. The data processing device of claim 19, further comprising: a second monotonic counter configured to generate a second count value; a second key derivation circuit configured to derive, using a key derivation function, a second encryption key based on the second count value; a second cryptographic processor configured to receive the second encryption key and decrypt, based on the second encryption key, a second encrypted code.
27. The data processing device of claim 26, further comprising: a second boot sequence configured to initialize the second monotonic counter that provides the second count value.
19. The method of claim 18, wherein the monotonic counter is initialized to the first count value at a first boot of the processing device, the method further comprising initializing the monotonic counter to the second count value at a second boot of the processing device.
20. The method of claim 19, further comprising: if a device state condition is satisfied, performing another boot of the processing device during which the monotonic counter is initialized to the first count value, wherein the device state condition corresponds to a program state of a region of the non-volatile memory.
Citation Information
Patent Citations
Improvements in or relating to coin handling mechanism
FR2103318A5
Code encryption and decryption methods and devices, computer device and storage medium
CN108390759A
Electronic Device with Flash Memory Component
US20140310535A1