Method for verifying execution of a software program
Patent Information
- Application Number
- CN202210938480.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-08-05
- Filing Date
- 2022-08-05
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2042-08-05
AI Technical Summary
因此,该其它技术还通过要求包含地址的变量的“易失性”特性而使验证的编程复杂化,并且使用附加的和非优化的资源(易失性变量是不对其应用编译优化的变量)
Smart Images

Figure CN115827420B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application claims priority to French application No. 2108499, filed on 5 August 2021, which is incorporated herein by reference. Technical Field
[0003] The embodiments relate to a method for verifying the execution of a software program. Background Technology
[0004] The fault injection technique used in reverse engineering allows unusual behavior in the operation of electronic systems (such as microcontrollers) to be caused by intentionally introducing errors (“fault injection”) in order to extract secret information.
[0005] For example, after a fault is injected into the system, the registers of the processing unit (called the processor) can be modified.
[0006] Software operations performed by the processor are typically programmed to implement flow control that prevents these modifications. However, programming is done in a high-level language (often a "programming language" such as C code), while instructions in a low-level language or "machine language" such as assembly code, generated by compilation (or "assembly"), may not exhibit the expected behavior.
[0007] For example, after a write to a peripheral device, flow control typically performs a read-back on the peripheral device to verify that the value has been written. However, when a register containing the peripheral address is modified via fault injection, a write and read can be performed at the same erroneous address. Therefore, it is incorrect to verify that data was correctly written to an address but not to detect it. Thus, flow control is ineffective for this error.
[0008] Traditional techniques for addressing this problem involve implementing the write operation in one function and then implementing the read operation in another function.
[0009] However, on the one hand, this technology makes programming more complex, and on the other hand, some security recommendations require that verification be performed immediately after data is written to ensure that the protection is truly effective before any further execution can proceed. In practice, this technology is not applicable.
[0010] Another common technique for addressing this problem involves using a combination of specific instructions in high-level code to generate volatile variables in RAM memory (for “random access memory” elements known to those skilled in the art) to carry addresses, and to force the addresses to be reloaded from the RAM memory location into registers before performing a reread.
[0011] In other words, this alternative technique introduces specific high-level language coding to use addresses in RAM memory indirectly ("indirect" means "addressing," or "use of memory location"). Therefore, this other technique also complicates the verification programming by requiring the "volatile" nature of variables containing addresses and by using additional, non-optimized resources (volatile variables are those to which compiler optimizations are not applied). Furthermore, this use of volatile variables does not replace the steps of compiling the assembly code generated by the verification. Summary of the Invention
[0012] The embodiments and implementations relate to verifying the execution of software programs, particularly in verifying security to prevent, for example, fault injection.
[0013] The embodiments provide a method for verifying write operations that is simple in terms of programmable protection operations, efficient in terms of resource execution and consumption, and reliable in terms of security.
[0014] The embodiments provide a method for verifying the execution of a software program that includes at least one write operation to a destination address allocated in a register and a verification operation using "mnemonic" instructions, which are instructions that require the compiler to use specific instructions. In this regard, the compiler generates a reallocation of the same destination address in the same register after the write and before rereading, so as to erase any faults injected into the destination address in a simple, efficient, and reliable manner.
[0015] A mnemonic is a term, symbol, or name used to define or specify computer functions. In computer science, mnemonics are used to provide users with a means of quickly accessing instructions, functions, services, or procedures, thereby bypassing the more time-consuming methods typically used to execute or process them.
[0016] According to one aspect, a method is provided for verifying the execution of a compiled software program stored in the program memory of a processor and executed by the processor. The method includes at least one write operation, which includes allocating a destination address in a processor register and writing data at the location pointed to by the destination address contained in the register. The compiled verification operation includes reallocating the same destination address in the same register, reading the data contained at the location pointed to by the destination address contained in the register after reallocation, and comparing the read data with the written data.
[0017] Specifically, the steps of the write operation and the verification operation are compilation instructions, i.e. machine language instructions, which are usually automatically generated by the compiler from the code of the programming language.
[0018] Therefore, in the approach according to this aspect, the compiler is "forced" to perform a reallocation of the destination address in the register, and thus, fault injection in the contents of the register after the first allocation of the destination address may affect write operations, but will be "erased" for read verification operations. The verification operation is then able to identify and detect the fault.
[0019] According to one embodiment, a verification operation is performed on all immediate allocations of data in the register (e.g., the destination address of a write operation performed during the execution of the at least one write operation), where an immediate allocation is writing data in the register at an address defined by a shift of a value added to an absolute address.
[0020] In practice, fault injection is particularly problematic when it affects the absolute address placed in a register to perform an immediate allocation, especially when it affects the address value reflected during write verification. In fact, during immediate allocation, the address defined by the shift on the absolute address is often temporarily stored in a register so that data residing at that address can be accessed.
[0021] Therefore, this implementation allows for generalized blocking of all immediate allocations implemented for write operations.
[0022] According to one embodiment, the execution of the software program includes programming programming language code into machine language instructions, and when compiled from mnemonics in the programming language code, at least one machine language instruction specifically for implementing the reassignment is required.
[0023] In other words, in programming languages, mnemonics need to generate one or more machine language instructions during compilation specifically for implementing reallocation (e.g., instructions in an assembler for reloading registers).
[0024] Therefore, the compiler is forced to “forget” in its compilation context that a given register contains (theoretically) the same value as required to perform register verification.
[0025] Machine language instructions generated during compilation are typically specified by their associated "mnemonics" or "opcodes" (short for "opcode"). Mnemonics are symbolic representations that are easier for humans to read and identify than the numerical opcodes of instructions in assembly machine language, which are generated when the code is programmed into a programming language. In high-level programming languages, the code used to generate the corresponding machine language opcodes during compilation is also called a "mnemonic symbol."
[0026] Therefore, in this implementation, the compiler benefits advantageously from the need to reallocate mnemonics.
[0027] According to one embodiment, at least one write operation and a verification operation are performed during the execution of the same function of the software program.
[0028] According to one embodiment, the execution of the same function of a software program includes compiling code to implement resource optimization, which includes reusing the contents already allocated in registers for individual instructions with the same function.
[0029] In practice, optimizations to a function during compilation can generate, in a way that is unexpectedly prior to the result, the effect of injecting errors into the verification address at the write address. On the other hand, it is advantageous not to use a separate function to perform the verification itself.
[0030] In one implementation, the verification operation involves generating an error message if the data read and the data written are not the same.
[0031] According to another aspect, a computer program product including instructions is also provided, which, when executed by a computer, cause the computer to perform the methods as defined above.
[0032] According to another aspect, a non-transitory computer-readable medium including instructions that, when executed by a computer, cause the computer to perform the methods as defined above are also provided.
[0033] According to another aspect, an apparatus is also provided, the apparatus comprising: a processor; and a program memory configured to contain a compiled software program to be executed by the processor, the software program including instructions that, when executed by the processor, cause the processor to perform the methods as defined above. Attached Figure Description
[0034] To gain a more complete understanding of the invention and its advantages, reference is now made to the following description in conjunction with the accompanying drawings, wherein:
[0035] Figure 1 A method for verifying the execution of a software program is shown;
[0036] Figure 2 An example of high-level language code is shown;
[0037] Figure 3 This demonstrates assembly language in a low-level language; and
[0038] Figure 4 An example of a device configured to implement the method of the present invention is shown. Detailed Implementation
[0039] Figure 1This represents a method 100 for verifying the execution of a software program, which is actually stored in the program memory MP of a processing unit (also known as a processor). Figure 4 In, and by the processor CPU ( Figure 4 ) Execution. Steps 111-129 of method 100 correspond to the actions of the device that executes the program after compiling programming code such as code C.
[0040] In practice, method 100 can be implemented by a computer program that includes instructions which, when executed by a computer, cause the instructions to make the computer implement method 100.
[0041] In practice, method 100 can be implemented by a non-transitory computer-readable medium including instructions that, when executed by a computer, cause the latter to implement method 100.
[0042] The execution of the program involves one or more operations that write data DATwr to a memory location (called the destination address) specified by address AD. In this example, only one write operation 110 is performed. The memory location may belong to a peripheral device, such as non-volatile memory used to store data, or any other peripheral device, such as writing one or more control bits to a status register.
[0043] Write operation 110 includes the allocation 111 of the destination address AD in register R0, that is, loading register R0 with the value of the destination address AD, and then writing 113, that is, writing "WR()" at the location "@" pointed to by the destination address contained in register R0.
[0044] If a fault is injected into the contents of register R0 by FLT between allocation 111 and write 113, then data DATwr will be written to the wrong location with an incorrect address.
[0045] Then, the verification operation 120 (the purpose of which is to verify that the data has been correctly written to the memory location with the destination address) first includes the reallocation 121 of the same destination address AD in the same register R0.
[0046] Therefore, the possible fault injection FLT in the contents of register R0 is erased, and the non-faulty destination address AD is loaded into register R0.
[0047] After reallocation 121, the verification operation performs a read 123 "RD" of the data "DATrd" contained at the location pointed to by the destination address AD contained in register R0.
[0048] Then, in step 125, the read data “DATrd” is compared with the written data “DATwr” in step 113.
[0049] If the data “DATrd” read by the comparison 125-Y identifier is the same as the data “DATwr” written, then the verification operation 120 did not detect an anomaly, and the processor is in normal state 127.
[0050] If the data “DATrd” read by comparison 125-N is different from the data “DATwr” written, then the verification operation 120 has detected an anomaly and generates an error message ERR in step 129.
[0051] In fact, if a fault injection FLT is performed in register R0 between allocation step 111 and write step 113, the data DATwr is not written to the memory location; instead, the memory location contains the data DATrd read in read step 123.
[0052] Furthermore, a second fault injection is implemented between the reallocation step 121 and the read step 123 to generate the same error address during the read step 123 as during the write step 113. For the verification method 100, implementing the second fault injection is sufficient to provide satisfactory protection against fault injection.
[0053] Figure 2 An example of code using the high-level language H_LVL_LANG (also known as a programming language) is shown, in which code C implements the following... Figure 1 The verification method described is 100.
[0054] The line of code for implementing the encoding write operation is marked as 110, and the line of code for implementing the encoding verification operation is marked as 120.
[0055] The code "FLASH->CR|=FLASH_CR_SEC_PROT1;" means "modify flash->cr by performing a logical OR operation with its current value and FLASH_CR_SEC_PROT1", and corresponds to the basic write operation of the high-level language H_LVL_LANG.
[0056] The loop "do{}while((FLASH->CR&FLASH_CR_SEC_PROT1)!=FLASH_CR_SEC_PROT1);" means that "the action within the brackets {} will be executed as long as the element FLASH->CR does not contain the value FLASH_CR_SEC_PROT1".
[0057] This corresponds to the mechanism typically used to ensure that the action (i.e., the write) within the brackets of "do{}" can be completed. In practice, the peripheral device performing the write may be much slower than the processing unit executing the code, and the "while" loop allows waiting until the peripheral device has performed the write.
[0058] The line "FMB();" corresponds to a mnemonic call, which requires at least one assembly instruction to implement the previously mentioned... Figure 1 The redistribution step 121 is described.
[0059] Finally, the code "if((FLASH->CR&FLASH_CR_SEC_PROT1) != FLASH_CR_SEC_PROT1)" means "true if FLASH->CR does not have the value FLASH_CR_SEC_PROT1, otherwise false", and corresponds to Figure 1 Method 100 compares with 125. Implicitly, "true" and "false" are determined by comparison 125. Figure 1 The generated error message has two states.
[0060] In the write implementation comparison 125 ( Figure 1 In this example of the code, if the data read and the data written are not the same, then in the "true" state 129 ( Figure 1 An error message is generated in the "false" state 127 if the data read and the data written are the same. Figure 1 Error messages are generated in the )
[0061] For example, the mnemonic instruction "FMB()" is designed to perform a reallocation of all immediate allocations that occur during code compilation. Figure 1 ).
[0062] Specifically, the memory instruction "FMB()" can be provided to perform a reallocation of all immediately allocated data in the registers. Figure 1 For example, the destination address of a write operation performed during the compilation and execution of at least one write operation 110.
[0063] Immediate allocation is writing data that exists at the address defined by the shift of the value added to the absolute address "[PC, #0x34]" into a register. Figure 3 The absolute address PC is usually the current address of the program execution, and is called the program counter.
[0064] Also specifically, the mnemonic instruction "FMB()" is designed to force an immediate reallocation of allocations that occur during the compilation and execution of the same function in the software program.121 Figure 1 ).
[0065] In other words, the mnemonic instruction invoked by the code "FMB()" provides a memory fault barrier that is easy to use and efficient in its execution.
[0066] Therefore, by calling the mnemonic instruction "FMB()", programmers can request and specify the compiler's behavior in high-level code such as H_LVL_LANG in C, according to the flow control they wish to implement.
[0067] Now for reference Figure 3 It shows Figure 2 The compilation of the high-level code H_LVL_LANG into the low-level language L_LVL_LANG (also known as machine language or assembly code).
[0068] The compiled assembly code line used to implement the write operation is marked as 110, and the compiled assembly code line used to implement the verification operation is marked as 120.
[0069] Figure 2 The high-level code line H_LVL_LANG is reproduced above its corresponding assembly code line in the compiler.
[0070] Assembly code lines are identified by the program counter PC 0x2000'1024-0x2000'1040, and each line's assembly instruction is identified by the numeric opcode OPC and the mnemonic name MNEM. In the following text, each assembly instruction will be specified by its mnemonic name MNEM and / or the corresponding value of the program counter PC. The last column of each instruction line, VARVAL, shows the data and variables used in the execution of the individual instructions, or more generally, the operands.
[0071] Therefore, write operation 110 begins at line 0x2000′1024 with the allocation of the destination address in register R0, where the instruction LDR.N controls the loading of the data contained at address “PC, #0x34” in register R0.
[0072] Address "PC, #0x34" is the immediate allocation of the contents at the address obtained by shifting #0x34 to the value of the absolute address PC. The absolute address is the current address of the program counter PC, which is 0x2000'1024 for the instruction LDR.N. Therefore, the data loaded into register R0 is located at the destination address AD(...) containing the write operation. Figure 1 The line containing the program counter PC0 of the write operation contains the destination address AD(...). Figure 1 ).
[0073] The instruction LDR at line 0x2000'1026 loads the content pointed to by the value of register R0, i.e., the destination address AD in the second register R1. Figure 1 The contents of the memory cell.
[0074] The instruction ORRS.W at line 0x2000'1028 is a write operation of the mask #268435456…, which represents the data to be written, “FLASH_CR_SEC_PROT1”, in the value R1 of the second register R1.
[0075] The instruction STR at line 0x2000'102c loads the value of the second register R1, which means that the data "FLASH_CR_SEC_PROT1" will be written to the content [R0] pointed to by the value of register R0 (that is, in the memory cell at the destination address).
[0076] The instructions from lines 0x2000′102e to 0x2000′1032 execute an optional "while" loop by reloading the LDR into the content pointed to by the value of R0 in register R1, comparing this content with the previous value #3 (LSLS means "level shift") of register R1, and executing branch BPL.N to line 0x2000′1024, which is the beginning of write operation 110, as long as the comparison does not detect an identifier.
[0077] The instruction LDR.N at line 0x2000'1034 is required in assembly code L_LVL_LANG by the mnemonic code "FMB()" in high-level language H_LVL_LANG, and corresponds to the reallocation of the same destination address in the same register R0.
[0078] The destination address is contained in line (not shown) at program counter PC0x2000'1058, so register R0 is reloaded with LDR.N by the immediate allocation of the contents at address 0x2000'1058, which is defined for this instruction by shift #0x24 added to the current address 0x2000'1034 of program counter PC.
[0079] Then, after reassigning line 0x2000'1034, the instruction LDR on line 0x2000'1036 executes the step of reading the data [R0] contained at the location pointed to by the value of register R0 (i.e., the value of the memory cell at the destination address). Figure 1 (123 in the middle).
[0080] Furthermore, the instruction LSLS at line 0x2000'1038 performs the comparison step between reading and writing data by comparing LSLS with the content pointed to by the previous value of register R0. Figure 1 In 125), LSLS is the content pointed to by the value of the reallocated register R0.
[0081] It will be noted that the compilation of the high-level code H_LVL_LANG allows for resource optimization, including reusing the contents allocated in registers R0 and R1 for instructions that do not have the same function.
[0082] However, when the compiler encounters the mnemonic "FMB()" during compilation, it must perform data reallocation in all registers containing data obtained through immediate allocation. The compiler should "forget" register R0 in its compilation context; R1 contains the same value required for the verification.
[0083] In this case, this means that if there are multiple registers to be reallocated due to multiple immediate allocations, then multiple assembly instructions are added (e.g., LDR.N for line 0x2000'1034). In other words, the mnemonic "FMB()" forces the compiler to repeat several immediate allocations, which will generate an addition of several assembly instructions.
[0084] Figure 4 It shows the configuration to implement about Figure 1 Examples of devices using the described method, such as MCUs (e.g., microcontrollers).
[0085] The device includes a processor (CPU), i.e., a processing unit, and a program memory (PM) configured to contain compiled software programs L_LVL_LANG, such as those previously mentioned. Figure 3 As described, so that it can be executed by the processor CPU.
[0086] Therefore, the software program includes methods 100 that, when executed by the processor CPU, cause the processor CPU to implement them. Figure 1 (instructions).
[0087] The processor MPU's program memory (PM) specifically contains information about... Figure 3 The memory locations of registers R0 and R1 are described, as well as instruction lines 0x2000'1024 to 0x2000'1040 that specifically contain the assembly code L_LVL_LANG.
[0088] The device MCU also includes peripheral devices PRPH1…PRPHn, such as non-volatile memory, communication interfaces on the data bus, or sensitive processing units such as cryptographic processing.
[0089] The non-volatile memory PRPH1 may include regions with hierarchical access permissions, such as regions referred to as "secure" regions and "unsecure" regions.
[0090] The destination address AD (with software program write operation) Figure 1 The memory location of ) can, for example, belong to the safe region of non-volatile memory PRPH1.
[0091] Access to the PRPH1 region of memory is specifically managed by the processor CPU and can be achieved through fault injection techniques (FLT). Figure 1 Damage, as previously described.
[0092] Therefore, implementation of method 100 allows the device MCU to resist fault injection and thus protects data belonging to or intended to belong to the safe zone of the non-volatile memory PRPH1.
[0093] On the other hand, it has a destination address AD (controlled by the write operation of a software program). Figure 1 The memory location of ) can, for example, belong to the encryption processing unit PRPHn.
[0094] Furthermore, the fault injection technique FLT (Fault Tolerance) in the processing of the CPU... Figure 1 It can gain unauthorized access to secret information and sensitive processing operations of the encryption processing unit PRPHn.
[0095] And here again, the implementation of method 100 allows the device MCU to resist fault injection and thus prevents unauthorized access to the sensitive processing unit PRPHn.
Claims
1. A method for verifying the execution of a compiled software program, the compiled software program being stored in a processor's program memory and executed by the processor, the method comprising: Perform a write operation, the write operation comprising: allocating a destination address in a register of the processor, and writing data at the location pointed to by the destination address included in the register; and Perform a verification operation, which includes: reallocating the same destination address in the same register, reading data at the location pointed to by the destination address included in the register after the reallocation, and comparing the read data with the written data.
2. The method of claim 1, wherein the reallocation of the verification operation comprises: The reallocation is performed for all immediate allocations of data in the registers made during the execution of the write operation.
3. The method of claim 2, wherein each immediate allocation comprises: Data is written to the register at the address specified by the shift of the value added to the absolute address.
4. The method according to claim 1, wherein the execution of the software program comprises: The programming language code is programmed into machine language instructions, wherein when compiled from the mnemonics in the programming language code, machine language instructions specifically for implementing the reassignment are required.
5. The method according to claim 1, wherein the write operation and the verification operation are implemented in the execution of the same function of the software program.
6. The method of claim 5, wherein the execution of the same function of the software program comprises: The code compilation implements resource optimization, which includes: reusing the contents allocated in the registers for individual instructions with the same function.
7. The method of claim 1, wherein comparing the read data with the written data comprises: An error message is generated when the data read is different from the data written.
8. A non-transitory computer-readable medium comprising instructions that, when executed by a computer, cause the computer to perform the method according to claim 1.
9. An apparatus comprising: processor; A program memory configured to contain a compiled software program intended to be executed by the processor, the software program including instructions that, when executed by the processor, cause the processor to perform a write operation and a subsequent verification operation; The write operation includes: allocating a destination address in a register of the processor, and writing data to the location pointed to by the destination address in the register; and The verification operation includes: reallocating the same destination address in the same register, reading data at the location pointed to by the destination address included in the register after the reallocation, and comparing the read data with the written data.
10. The device of claim 9, wherein the reallocation of the verification operation comprises: The reallocation is performed for all immediate allocations of data in the registers made during the execution of the write operation.
11. The device of claim 10, wherein each immediate allocation comprises: Data is written to the register at the address specified by the shift of the value added to the absolute address.
12. The device of claim 9, wherein the execution of the software program comprises: The programming language code is programmed into machine language instructions, wherein when compiled from the mnemonics in the programming language code, machine language instructions specifically for implementing the reassignment are required.
13. The device of claim 9, wherein the write operation and the verification operation are implemented in the execution of the same function of the software program.
14. The device of claim 13, wherein the execution of the same function of the software program comprises: The code compilation implements resource optimization, which includes: reusing the contents allocated in the register for separate instructions with the same function.
15. The device of claim 9, wherein comparing the read data with the written data comprises: An error message is generated when the data read is different from the data written.
16. A method of operating a computer device including a processor, the method comprising: The processor executes software programs by programming language code into machine language instructions; Perform a write operation, the write operation comprising: allocating a destination address in a register of the processor, and writing data at the location pointed to by the destination address included in the register; and Perform a verification operation, the verification operation comprising: reallocating the same destination address in the same register, reading data including data at the location pointed to by the destination address included in the register after the reallocation, and comparing the read data with the written data, wherein machine language instructions specifically for performing the reallocation are required when compiled from mnemonics in the programming language code.
17. The method of claim 16, wherein the reallocation of the verification operation comprises: The reallocation is performed for all immediate allocations of data in the registers made during the execution of the write operation.
18. The method of claim 17, wherein each immediate allocation comprises: Data is written to the register at the address specified by the shift of the value added to the absolute address.
19. The method of claim 16, wherein the write operation and the verification operation are implemented in the execution of the same function of the software program.
20. The method of claim 19, wherein the execution of the same function of the software program comprises: The code compilation implements resource optimization, which includes: reusing the contents allocated in the register for separate instructions with the same function.
Citation Information
Patent Citations
FR2108499A5
Register read / write ordering
CN108027767A
Cryptographic computing using encrypted base addresses and used in multi-tenant environments
US20200201789A1