Microcontroller configuration method

By detecting faults in the nonvolatile memory of the microcontroller and setting lock mode, the security and user experience issues of fault handling during configuration phase are solved, and configuration reloading without power outage is achieved.

CN120020660APending Publication Date: 2025-05-20STMICROELECTRONICS INT NV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411621586.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-11-06
Filing Date
2024-11-14
Publication Date
2025-05-20

AI Technical Summary

Technical Problem

During the microcontroller configuration stage, nonvolatile memory is sensitive to external factors, which may cause failure, and the prior art needs to power off and restart when a fault is detected, affecting the user experience.

Method used

Provides a configuration method by detecting a fault in nonvolatile memory and incrementing the counter, if the counter exceeds the threshold N, the microcontroller is set to lock mode, and the configuration can only be reloaded after power-off, avoiding power-off restarts.

Benefits of technology

It realizes the reloading of the configuration without power off when a fault is detected, improving the security and user experience of configuration loading operations, while effectively preventing attacks when necessary.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120020660A_ABST
    Figure CN120020660A_ABST
Patent Text Reader

Abstract

The invention relates to a configuration method of a microcontroller. The present description relates to a configuration method of a microcontroller provided with a non-volatile memory in which, during implementation of an operation of loading a microcontroller configuration based on data from the non-volatile memory, if a fault is detected, a new configuration loading operation is implemented at least once without powering off the microcontroller.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications (one or more)

[0002] This application claims the benefit of priority of French Patent Application No. FR2312642, filed on November 17, 2023, with the title "Procédé de configuration d’un microcontrôleur". Technical Field

[0003] This description generally relates to methods for configuring a microcontroller and to microcontrollers implementing these methods. Background Art

[0004] Many electronic circuits, such as microcontrollers, during their power-up, start a configuration phase based on parameters stored in a memory.

[0005] Such a memory may be sensitive to external factors such as temperature or magnetic field. This sensitivity may create faults during the configuration phase, which are exploited during an attack. Summary of the Invention

[0006] There is a need to ensure optimal security during the microcontroller configuration phase while limiting the impact on the user experience.

[0007] Embodiments overcome all or part of the drawbacks of known methods.

[0008] Embodiments provide a method for configuring a microcontroller provided with a non-volatile memory, wherein, during an operation of implementing the loading of the microcontroller configuration based on data from the non-volatile memory, if a fault is detected, then at least one new configuration loading operation is implemented without powering off the microcontroller.

[0009] Embodiments provide a microcontroller provided with a non-volatile memory, wherein, during an operation of implementing the loading of the microcontroller configuration based on data from the non-volatile memory, if a fault is detected, then at least one new configuration loading operation is implemented without powering off the microcontroller.

[0010] According to an embodiment, if no fault is detected during the operation of implementing the loading of the microcontroller configuration from the non-volatile memory, then the microcontroller boot process is implemented.

[0011] According to an embodiment, a counter is incremented at each new successive implementation of the loading operation related to the fault detection.

[0012] According to an embodiment, when the counter exceeds a threshold N, then the microcontroller is set to a locked mode.

[0013] According to an embodiment, starting from when the microcontroller is set to the locked mode, then only by powering off the microcontroller can a new operation of loading the configuration of the microcontroller from the non-volatile memory be achieved.

[0014] According to an embodiment, fault detection is achieved by comparing error correction codes.

[0015] According to an embodiment, fault detection is achieved by comparing cyclic redundancy codes.

[0016] According to an embodiment, fault detection is based on data from the non-volatile memory.

[0017] According to an embodiment, fault detection is implemented by the memory interface of the microcontroller.

[0018] According to an embodiment, the non-volatile memory is an MRAM type memory.

[0019] According to an embodiment, the non-volatile memory is a phase change type memory. Description of the Drawings

[0020] The above-mentioned features and advantages, as well as other features and advantages, will be described in detail with reference to the accompanying drawings in the disclosure of specific embodiments given as illustrations and not limitations, in which:

[0021] Figure 1 An example of a microcontroller of the type to which the embodiment is applicable is shown very schematically in the form of a block diagram; and

[0022] Figure 2 Is shown in the form of a block diagram Figure 1 Of the configuration method of the microcontroller. Detailed Description of the Embodiment

[0023] Similar features in each figure are denoted by similar reference numerals. In particular, the common structural and / or functional features in each embodiment may have the same reference numerals, and the same structures, dimensions, and material properties may be arranged.

[0024] For clarity, only those steps and elements that contribute to understanding the embodiment are shown and described in detail.

[0025] Unless otherwise indicated, when referring to two elements connected together, this means a direct connection without any intermediate element other than a conductor, and when referring to two elements coupled together, this means that the two elements can be connected or they can be coupled via one or more other elements.

[0026] In the following description, when referring to absolute position determiners such as "front", "rear", "upper", "lower", "left", "right", etc., or relative position determiners such as "top", "bottom", "upper part", "lower part", etc., or orientation determiners such as "horizontal", "vertical", etc., unless otherwise specified, they refer to the orientation of the drawings.

[0027] Unless otherwise specified, the expressions "about", "approximate", "substantially", and "about" mean plus or minus 10%, preferably plus or minus 5%.

[0028] Figure 1 An example of a microcontroller 100 of the type to which the embodiments are applicable is shown very schematically in the form of a block diagram.

[0029] The microcontroller 100 includes a non-volatile memory 104 (NVM) of, for example, the FLASH or MRAM or phase change memory type, which is capable of communicating via a communication bus 114 with a non-volatile memory interface 106 (MEM interface), which is configured to write data to or read data from the non-volatile memory 104.

[0030] The microcontroller 100 also includes, for example, a processing unit 110 (CPU), which includes one or more processors controlled by instructions stored in an instruction memory 112 (INSTR MEM). The instruction memory 112 is, for example, a volatile memory of the random access (RAM) type. The processing unit 110 and the memory 112 communicate, for example, via a system (data, address, and control) bus 140. The memory 104 is coupled to the system bus 140 via the non-volatile memory interface 106 and via the bus 114. The device 100 also includes an input / output interface 108 (I / O interface) coupled to the system bus 140 for external communication.

[0031] The microcontroller 100 may integrate other circuits for implementing other functions (for example, one or more volatile and / or non-volatile memories, or other processing units), represented by block 116 (FCT) in Figure 1 which. Among these other circuits, the microcontroller 100 includes, for example, a read-only or static memory 118 (ROM).

[0032] The microcontroller implements a configuration (OBL, option byte loading) phase, in other words, a configuration operation, based on parameters stored in the memory, such as user option bytes, during its power-on. During this configuration phase, the configuration parameters are loaded from the memory 104 into, for example, the processing unit 110.

[0033] For example, the memory 104 is sensitive to temperature or an external magnetic field, which may affect the cycle and also affect programming or reading. An attack by a hacker may also exploit this sensitivity to modify the configuration of the microcontroller 100. Therefore, the configuration phase depending on the data from the memory 104 is particularly critical and should be protected. One solution is to lock the microcontroller operation immediately once a fault is detected during the configuration phase and only allow unlocking the microcontroller 100 after the microcontroller 100 is powered off. However, the disadvantage of this solution is that if the fault is only temporary and not related to an attack, then this solution will degrade the user experience.

[0034] The described embodiments provide that during the operation of loading the microcontroller configuration based on data from the non-volatile memory 104, if a fault is detected, then at least one new configuration loading operation is implemented.

[0035] This allows, if a temporary interference during the configuration operation causes a fault, then the microcontroller to restart the configuration loading operation without the user powering off the microcontroller.

[0036] This further enables ensuring the security of the configuration loading operation, because if a fault is detected, then the microcontroller indeed enters the boot phase.

[0037] Figure 2 is shown in block diagram form Figure 1 the configuration method of the microcontroller.

[0038] During a first step 202 (power-on), the microcontroller 100 is powered on.

[0039] In a subsequent step 204 (OBL), the configuration loading operation is implemented, for example, by the memory interface 106 to load the configuration data of the microcontroller 100, for example, in byte form.

[0040] In a step 206 (user OBL integrity?) after step 204, a fault detection operation of the configuration loading operation is implemented, for example, via the memory interface 106. In the example, step 206 includes checking the integrity or match of an error correction code or a cyclic redundancy code related to the loaded user option byte.

[0041] If no fault is detected (branch "yes"), then step 208 (CPU boot) is executed. During this step 208, for example, a method of booting the microcontroller 100 is implemented using the processing unit 110 and / or by loading and executing a boot program in the memory 104.

[0042] If a fault is detected (branch "No"), then step 210 (counter < N) is executed. During this step 210, a counter implemented, for example, in the memory interface 106 is incremented at each successive restart of the configuration loading operation related to the fault detection. When the value of the counter exceeds a threshold N, for example, N = 2 to 10, then step 212 (chip locking) is executed. If the counter value is below the threshold (branch "Yes"), then the method restarts at step 204 for a new configuration loading operation without powering down.

[0043] During this step 212, the microcontroller is set to the locked mode. In this mode, the microcontroller is, for example, no longer accessed in read or write mode and, for example, no longer executes any tasks. In this mode, only by powering down, for example, by disconnecting the battery that powers the microcontroller 100, can it return to step 202.

[0044] Figure 2 The method disclosed enables repeating the configuration loading operation in case of a detected fault without powering down the microcontroller 100 and this up to a predetermined number of repetitions N. This situation corresponds, for example, to transient faults unrelated to an attack. If one or more faults are still detected despite several successive repetitions of the configuration loading operation, then it may be an attack and the microcontroller will be set to the locked mode so that it can be protected and not disclose secrets such as encryption keys.

[0045] The value of the threshold N can be selected according to the robustness against attacks or external physical parameters. Thus, if N = 2, then the attack will be stopped very quickly, but in the case of relatively long temporary disturbances, this will quickly lock the microcontroller. The higher N, the longer the attack may last, but the more likely it is to give way to external disturbances without powering down the microcontroller 100.

[0046] Various embodiments and variants have been described. Those skilled in the art will understand that certain features of these various embodiments and variants can be combined and other variants will occur to those skilled in the art. In particular, the fault detection during step 206 can include checking values other than those related to the user option bytes or using error checking methods other than error correction codes or cyclic redundancy codes.

[0047] Finally, based on the functional indications given above, the actual implementation of the described embodiments and variants is within the capabilities of those skilled in the art. In particular, although the method has been described in the context of a microcontroller, those skilled in the art will be able to apply the method to other types of electronic circuits, such as a system-on-chip (SOC) using a configuration phase based on data stored in a memory, using their knowledge.

[0048] A method for configuring a microcontroller (100) provided with a non-volatile memory (104) can be generally summarized as including: during an operation of implementing the configuration of the microcontroller (100) by loading data from the non-volatile memory (104), if a fault is detected, then at least one new configuration loading operation is performed without powering down the microcontroller.

[0049] A microcontroller (100) provided with a non-volatile memory (104) can be generally summarized as including: during an operation of implementing the loading of the microcontroller configuration based on data from the non-volatile memory (104), if a fault is detected, then at least one new configuration loading operation is implemented without powering down the microcontroller.

[0050] If no fault is detected during the operation of implementing the loading of the microcontroller configuration from the non-volatile memory (104), then a method for booting the microcontroller can be implemented.

[0051] At each new consecutive implementation of the loading operation related to fault detection, a counter can be incremented.

[0052] When the counter exceeds a threshold N, then the microcontroller can be set to a locked mode.

[0053] From the time when the microcontroller is set to the locked mode, then only by powering down the microcontroller can a new operation of loading the configuration of the microcontroller (100) from the non-volatile memory (104) be implemented.

[0054] Fault detection can be achieved by comparing an error correction code (ECC).

[0055] Fault detection can be achieved by comparing a cyclic redundancy code (CRC).

[0056] Fault detection can be achieved based on data from the non-volatile memory (104).

[0057] Fault detection can be implemented by a memory interface (106) of the microcontroller (100).

[0058] The non-volatile memory (104) can be an MRAM type memory.

[0059] The non-volatile memory (104) can be a phase change memory.

[0060] The various embodiments described above can be combined to provide further embodiments. All U.S. patents, U.S. patent application publications, U.S. patent applications, foreign patents, foreign patent applications, and non-patent publications cited in this specification and / or listed in the Application Data Sheet are hereby incorporated by reference in their entirety. Aspects of the embodiments may be modified, if necessary, to employ the concepts of various patents, applications, and publications to provide yet further embodiments.

[0061] In view of the foregoing detailed description, these and other changes may be made to the embodiments. In general, in the following claims, the terms used should not be construed as limiting the claims to the specific embodiments disclosed in the specification and the claims, but should be construed to include all possible embodiments and the full scope of equivalents to which such claims are entitled. Thus, the claims are not limited by the disclosure.

Claims

1. A method for configuring a microcontroller provided with a non-volatile memory, comprising: During operation implementing a configuration of the microcontroller loaded with data from a non-volatile memory: In response to detecting the fault, at least one new configuration load operation is performed without powering down the microcontroller.

2. A microcontroller provided with a non-volatile memory, wherein: The microcontroller is configured as: During the operation of implementing loading of the microcontroller configuration based on data from non-volatile memory: In response to detecting the fault, at least one new configuration load operation is enabled without powering down the microcontroller.

3. The method according to claim 1, wherein: In response to no fault being detected during the operation of implementing loading a microcontroller configuration from a non-volatile memory, a method of booting a microcontroller is implemented.

4. The method according to claim 1, wherein: At each new successive implementation of a load operation associated with fault detection, a counter is incremented.

5. The method according to claim 4, wherein: When the counter exceeds a threshold value N, the microcontroller is set in locking mode.

6. The method according to claim 5, wherein: From the moment the microcontroller is set to the lock mode, a new operation of loading the configuration of the microcontroller from the non-volatile memory is only possible by powering off the microcontroller.

7. The method according to claim 1, wherein: Fault detection is achieved by comparing the error correction code ECC.

8. The method according to claim 1, wherein: Fault detection is achieved by comparing the cyclic redundancy code CRC.

9. The method according to claim 1, wherein: Detecting a fault is accomplished based on data from a non-volatile memory.

10. The method according to claim 9, wherein: Detection of faults is implemented by the memory interface of the microcontroller.

11. The method according to claim 1, wherein: The non-volatile memory is an MRAM type memory.

12. The method according to claim 1, wherein: The non-volatile memory is a phase change memory.

13. The microcontroller according to claim 2, wherein: In response to no fault being detected during the operation of implementing loading a microcontroller configuration from a non-volatile memory, a method of booting a microcontroller is implemented.

14. The microcontroller according to claim 2, wherein: At each new successive implementation of a load operation associated with fault detection, a counter is incremented.

15. The microcontroller according to claim 14, wherein: When the counter exceeds a threshold value N, the microcontroller is set in lock mode.

16. The microcontroller according to claim 15, wherein: From the moment the microcontroller is set to the lock mode, a new operation of loading the configuration of the microcontroller from the non-volatile memory is only possible by powering off the microcontroller.

17. The microcontroller according to claim 2, wherein: Fault detection is achieved by comparing the error correction code ECC.

18. The microcontroller according to claim 2, wherein: Fault detection is achieved by comparing the cyclic redundancy code CRC.

19. The microcontroller according to claim 2, wherein: Detecting a fault is accomplished based on data from a non-volatile memory.

20. The microcontroller according to claim 19, wherein: Detection of faults is implemented by the memory interface of the microcontroller.

21. The microcontroller according to claim 2, wherein: The non-volatile memory is an MRAM type memory.

22. The microcontroller according to claim 2, wherein: The non-volatile memory is a phase change memory.

Citation Information

Patent Citations

  • Soupape d'admission pour moteurs a combustion interne

    FR2312642A1