Emulation of one-time programmable memory
By programming the enable bit in the non-volatile memory to a protection value and combining it with the control of multiple status bits, the problems of insufficient one-time programmable memory size and imperfect security mechanism are solved, and a flexible security mechanism and highly adaptable memory management are achieved.
Patent Information
- Application Number
- CN202510290018.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2025-03-05
- Filing Date
- 2025-03-12
- Publication Date
- 2025-09-16
AI Technical Summary
The size of the one-time programmable memory depends on the onboard functions and end use of the device, which may not meet user needs and the existing security mechanisms are not perfect.
A security mechanism is implemented by associating a region of a nonvolatile memory with a first enable bit, programming a protection value to prohibit erasure of the content of the region, and limiting the erase operation of the memory through the control of multiple status bits.
The memory erase permission is dynamically adjusted according to the device status, ensuring the effectiveness and flexibility of the security mechanism to meet the needs of users with different purposes.
Smart Images

Figure CN120656514A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates generally to one-time programmable (OTP) memories, and more particularly to methods and circuits for emulating OTP memories. Background Art
[0002] When an electronic device is equipped with a one-time programmable memory, security mechanisms such as, for example, mechanisms that prohibit returning to a previous version and / or state of software (anti-rollback) can be easily implemented on the electronic device.
[0003] However, the size of the one-time programmable memory depends on a number of parameters, such as, for example, the functionality onboard the device, the type of end use of the device, etc., and may not be sufficient for the user of the device. Summary of the Invention
[0004] One embodiment provides a method comprising:
[0005] programming a first enable bit associated with a region of a non-volatile memory of the electronic device to a protection value; and
[0006] Erasure of contents of the first region of the nonvolatile memory is inhibited based on a state of the first enable bit.
[0007] According to one embodiment, the protection value to which the first enable bit is programmed is a function of a state of a configuration bit and / or at least one value associated with a state of the device in which the device is placed among a plurality of possible states of the device.
[0008] According to one embodiment, the configuration bits are programmable only when the device is placed in a first state of a plurality of states.
[0009] According to one embodiment:
[0010] placing the device in a second state of the plurality of states starting from the first state by programming the first state bit; and
[0011] The device is placed in a third state of the plurality of states starting from the first state or the second state by programming a second state bit stored in the one-time programmable memory.
[0012] According to one embodiment, erasure of the non-volatile memory area is authorized when the device is in the first state.
[0013] According to one embodiment, the first status bit is stored in a non-volatile memory.
[0014] According to one embodiment, the configuration bits are stored in a one-time programmable memory.
[0015] According to one embodiment, the configuration bits are stored in non-volatile memory.
[0016] According to one embodiment, the additional bits are stored in a one-time programmable memory of the device, and the protection value to which the first enable bit is programmed is further a function of the additional bits.
[0017] According to one embodiment, the additional bits are only programmable when the device is placed in the second state.
[0018] One embodiment provides a device including a nonvolatile memory including a region associated with a first enable bit programmed to a protection value, access for erasing the region being prohibited based on the protection value.
[0019] According to one embodiment, the protection value to which the enable bit is programmed is a function of the values of the configuration bit, a first state bit stored in non-volatile memory, and a second state bit stored in one-time programmable memory of the device.
[0020] According to one embodiment, the configuration bits are stored in a one-time programmable memory.
[0021] According to one embodiment, the configuration bits are stored in a non-volatile memory, and the one-time programmable memory further includes an additional bit, the protection value to which the enable bit is programmed further being a function of the state of the additional bit.
[0022] According to one embodiment, the state of the first state bit and / or the second state bit determines the state of the device from among the first state, the second state and the third state, and the configuration bit is programmable only when the device is in the first state.
[0023] In one embodiment, a method includes controlling a state of an electronic device. The state is one of a plurality of states of the electronic device, the plurality of states including an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in a non-volatile memory of the electronic device. The transition from the initial state or the test state to the configuration state is controlled by setting a second state bit in a one-time programmable memory of the electronic device. The configuration bits of the electronic device are programmed, wherein the programming of the configuration bits is limited to the initial state of the electronic device. A first enable bit associated with a region of the non-volatile memory of the electronic device is programmed to a protection value, wherein the protection value is a function of the value of the configuration bit. The programming of the first enable bit is limited to the initial state of the electronic device. Erasure of a first region of the non-volatile memory is limited based on the value of the first enable bit.
[0024] In one embodiment, an electronic device includes a memory and a processing circuit system coupled to the memory. The memory includes a non-volatile memory and a one-time programmable memory. In operation, a first enable bit stored in the memory is associated with a first region of the non-volatile memory, and erasure of the first region of the non-volatile memory is restricted based on the value of the first enable bit. The device has multiple states, including an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in the non-volatile memory. The transition from the initial state or the test state to the configuration state is controlled by setting a second state bit in the one-time programmable memory of the electronic device. Programming of the configuration bits stored in the memory is restricted to the initial state of the electronic device. Programming of the first enable bit is a function of the value of the configuration bit, and programming of the first enable bit is restricted to the initial state of the electronic device.
[0025] In one embodiment, a system includes a non-volatile memory, a one-time programmable memory, and a processing circuit system. In operation, a first enable bit is associated with a first area of the non-volatile memory, and erasure of the first area of the non-volatile memory is restricted based on the value of the first enable bit. The device has multiple states, including an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in the non-volatile memory. The transition from the initial state or the test state to the configuration state is controlled by setting a second state bit in the one-time programmable memory. Programming of the configuration bits stored in the memory is restricted to the initial state of the electronic device. Programming of the first enable bit is a function of the value of the configuration bit, and programming of the first enable bit is restricted to the initial state of the electronic device.
[0026] In one embodiment, the contents of a non-transitory computer-readable medium cause a processing circuit system to perform a method. The method includes controlling a state of an electronic device. The state is one of a plurality of states of the electronic device, the plurality of states including an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in a non-volatile memory of the electronic device. The transition from the initial state or the test state to the configuration state is controlled by setting a second state bit in a one-time programmable memory of the electronic device. The method includes programming configuration bits of the electronic device, wherein programming of the configuration bits is limited to the initial state of the electronic device; programming a first enable bit associated with a region of the non-volatile memory of the electronic device to a protection value, wherein the protection value is a function of the value of the configuration bit, and programming of the first enable bit is limited to the initial state of the electronic device; and limiting erasure of a first region of the non-volatile memory based on the value of the first enable bit. In one embodiment, the contents include instructions executable by the processing circuit system. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] The above features and advantages and other features and advantages will be described in detail in the remainder of the disclosure of specific embodiments which are provided by way of illustration and not limitation, with reference to the accompanying drawings in which:
[0028] Figure 1 is a block diagram illustrating an electronic device;
[0029] Figure 2 is a flowchart illustrating the steps of an embodiment of the present disclosure; and
[0030] Figure 3 An example of implementation of a one-time programmable memory emulation method according to an embodiment of the present disclosure is illustrated. DETAILED DESCRIPTION
[0031] In the various figures, the same features are represented by the same reference numerals. In particular, common structural and / or functional features in various embodiments may have the same reference numerals and may be provided with the same structure, dimensions, and material properties.
[0032] For clarity, only those steps and elements that are useful for understanding the described embodiments are shown and described in detail.
[0033] Unless otherwise specified, when two elements are referred to as being connected together, this means a direct connection without any intermediate elements other than conductors, and when two elements are referred to as being coupled together, this means the two elements may be connected or coupled via one or more other elements.
[0034] In the following description, when reference is made to absolute position qualifiers (such as "front", "back", "up", "down", "left", "right", etc.) or relative position qualifiers (such as "top", "bottom", "upper", "lower", etc.) or orientation qualifiers (such as "horizontal", "vertical", etc.), reference should be made to the orientation of the accompanying drawings unless otherwise stated.
[0035] Unless otherwise indicated, "about," "approximately," "substantially," and "on the order of" mean plus or minus 10%, for example, plus or minus 5%.
[0036] Figure 1 is a block diagram illustrating an electronic device 100 including a processing circuit 102 according to an embodiment of the present disclosure.
[0037] The processing circuit 102 is, for example, an electronic card such as a microcircuit card, computer hardware, a microprocessor circuit, etc. For example, the electronic device 100 including the processing circuit 102 is a connected object such as a smartphone, a connected watch, etc., on which one or more applications are installed.
[0038] According to one embodiment, circuit 102 includes non-volatile memory 104 (NV MEM), such as NOR flash and / or NAND flash. For example, circuit 102 also includes volatile memory 106 (RAM). For example, volatile memory 106 is RAM (random access memory). Memories 104 and 106 are coupled, for example, via bus 108.
[0039] The circuit 102 further comprises a processor 110 (CPU), for example, coupled to the bus 108. The processor 110 is configured to execute an application having application code stored in the non-volatile memory 104, for example.
[0040] According to one embodiment, circuit 102 further includes one or more one-time programmable (OTP) memories 112, for example, coupled to bus 108. For example, one or more memories 112 are fuse-type or anti-fuse-type memories. For example, in their initial state, a bit of one or more memories 112 has a value of 1. When the value of one or more bits of memory 112 changes from 1 to 0, it is said to be burned out.
[0041] For example, the one or more memories 112 are configured to, for example, burn one or more bits upon each update of a software application or firmware (e.g., firmware of the device). Thus, the one or more memories 112 provide an anti-rollback mechanism. In another example, the one or more memories 112 are configured to burn one or more bits when the device 100 leaves an initial state, such as, for example, a state that enables programming and / or configuration of the device 102, for example, to be supplied to an intermediary entity between a manufacturer of the circuit 102 and an end user of the device 100 and / or to place it on the market.
[0042] In some cases, the size of memory 112 is insufficient to implement security mechanisms and / or other functions that require the use of one-time programmable memory.
[0043] According to one embodiment, the non-volatile memory 104 includes one or more blocks or sectors that can be configured to be protected to prevent their contents from being erased. In other words, one or more blocks of the non-volatile memory 104 can be configured to act as one-time programmable memory.
[0044] For example, each of the one or more blocks of non-volatile memory 104 is associated with a configuration bit stored in memory 104 and / or memory 112. The state of the configuration bit then determines whether the associated block is protected from being erased.
[0045] For example, the memory 104 is a NOR flash memory and includes one or more sectors that are protected from being erased. For example, each sector includes 16 bytes. For example, the bytes of each block initially have the value 0xff. When a write request is required on one of these blocks (for example, a write request from a processor), the first byte of the block is programmed to the value 0xfe or the value 0x1, for example. For example, when a request is made to write the first byte with the value 0xff, it is necessary to erase the block. The block is protected from being erased, the write request is subsequently rejected, and the first byte of the block remains at the previously programmed value.
[0046] For example, memory 104 is a NAND flash memory and includes one or more sectors protected from erasure. For example, each sector includes 16 payload bytes and 8 error correction code (ECC) bytes, each payload byte being associated with 4 ECC bits. For example, the payload and ECC bytes of each block initially have a value of 0xff. When a write request is requested on one of these blocks (e.g., a write request from a processor), the first byte of the block is programmed with a value of 0xfe, and the four associated ECC bits are programmed with a value corresponding to, for example, 0xfe. For example, the second byte of the block is programmed with a value of 0x1, and the four associated ECC bits are programmed with a value corresponding to, for example, 0x1. For example, when a request is made to write the first byte with a value of 0xff, the block needs to be erased. The block is protected from erasure, the write request is subsequently denied, and the first byte in the block remains at the previously programmed value. In fact, within a block of NAND memory, the bytes of the block can be programmed sequentially or non-sequentially. However, each byte can only be programmed once. In fact, for each write of a byte, the ECC bits are programmed, and the ECC bits that encode the error code depend on the data item written in that byte. For example, the value 0xfe can be written in the first byte. However, if you want to write a value other than 0xfe in the first byte, the write will fail because the memory controller of the NAND memory ( Figure 1 (not shown) before writing, it checks whether the byte is 0xff and whether the 4 ECC bits associated with the byte are programmed to the value 1. Then, this behavior is the same for all bytes. In other words, the behavior is the same for 16 bytes.
[0047] In the case of NOR type memory, it is not possible to first write the value 0xfe and then write the value 0x1 in the same byte. In fact, the least significant bit of the byte will be programmed to the value 0 when 0xfe is first written, and then programmed to the value 1 when the same bit is written the second time. However, NOR type memory technology provides for erasing blocks to reprogram bits with a value of 0 to a value of 1.
[0048] According to one embodiment, the selection of blocks in memory 104 for which erase protection is activated is configurable only when circuit 102 is in a programming and / or configuration state. This state is, for example, the initial state of circuit 102 when it is in the hands of its manufacturer and before it is handed over to an intermediary entity, such as between the manufacturer and the end user, and / or before it is placed on the market.
[0049] Figure 2 is a flowchart illustrating the steps of an embodiment of the present disclosure.
[0050] Figure 3 An example of implementation of a one-time programmable memory emulation method according to an embodiment of the present disclosure is illustrated.
[0051] At step 200 (level 0), the circuit 102 is in its initial state. For example, the circuit 102 is in the hands of its manufacturer and has not yet been handed over to an intermediate entity and / or its end user.
[0052] For example, the initial state of the circuit is defined by the states of two state bits. For example, when the two state bits are programmed to a value of 0, the circuit 102 is in the initial state. For example, the two state bits include a first state bit lvl1 stored in the memory 104 and a second state bit lvl2 stored in one of the memories 112.
[0053] According to one embodiment, when the circuit 102 is in its initial state, the blocks 300 (sectors) of the memory 104 may be configured to be protected from being erased for the remainder of the lifetime of the device 100. For example, the blocks of the memory 104 may also be configured to be protected from being written to for the remainder of the lifetime of the device 100. In other words, in the initial state of the circuit 102, the blocks 300 of the memory 104 may be configured to prevent them from being erased and / or written to.
[0054] For example, the block 300 includes 8 blocks of 16 bytes each. In the example where the memory 104 is of the NAND type, each block 300 includes 8 error code bytes in addition to the 16 payload bytes.
[0055] In one example, a byte TestConfig for configuring block 300 is stored, for example, in a memory in memory 112. Each bit of the configuration byte is then associated with a block in blocks 300. The bits of the configuration byte are then programmed in step 200. For example, when a bit of the configuration byte is burned out, e.g., takes the value 0, this indicates that the associated block in memory 104 is protected from being erased. Therefore, after a bit of the configuration byte is burned out, the operation is irreversible.
[0056] In another example, the configuration byte TestConfig is stored in the memory 104. Thus, when write access to the byte TestConfig is granted, the configuration of the block 300 can be changed. In this example, an additional byte ProdConfig is stored in the memory 112.
[0057] For example, when the circuit 102 is in its initial state, the protection against erasure of the memory block 104 is disabled. In other words, the contents of the memory block 104 that is protected from erasure can be modified and / or erased during step 200. This therefore allows the contents of the protected block to be tested and, if necessary, modified.
[0058] At step 201 (stage 1), circuit 102 is placed in an intermediate or test state. For example, the transition of the circuit from the initial state to the intermediate state is performed by programming a first state bit lvl1 stored in memory 104, for example. For example, when the first state bit lvl1 is programmed to a value of 0, circuit 102 is in the intermediate state. Subsequently, the circuit 102 can be returned to the initial state by reprogramming the first state bit lvl1 to, for example, a value of 1.
[0059] In the example where the configuration bytes are stored in memory 104 and memory 112 includes an additional byte ProdConfig, the intermediate entity has the option of burning bits of the additional byte to indicate whether it wants one or more blocks in block 300 to be protected from erasure. For example, write access to the byte ProdConfig is only authorized during the implementation of step 201. The programming of the byte ProdConfig is thus deterministic. Furthermore, the byte ProdConfig is programmed according to the value of the byte TestConfig.
[0060] For example, in step 202 (level 2), circuit 102 is placed in a final state or configuration state. For example, step 202 is performed before device 100 is delivered to its end user. Circuit 102 is moved to the final state, for example, by programming a second state bit lv12 stored in memory 112. For example, when the second state bit is programmed to a value of 0, circuit 102 is in the final state. Therefore, the second state bit is included in memory 112, and after circuit 102 enters the final state, it is not possible to return to step 200 and / or step 201.
[0061] For example, when both the first state bit lvl1 and the second state bit lvl2 have a value of 1, in other words, when the circuit 102 is in the initial state, write access to the byte TestConfig is authorized. Similarly, when the memory 112 includes the byte ProdConfig, write access to the byte ProdConfig is authorized when the first state bit lvl1 has a value of 0 and the second state bit has a value of 1. In this example, when the byte ProdConfig is programmed based on the value of the byte TestConfig, writing the state bit lvl2 to a value of 0 can be achieved.
[0062] For example, an authorization byte, EraseAllow, is stored, for example, in memory 104. For example, the value of the byte EraseAllow is calculated based on various elements stored in memory 104, such as, for example, the value of status bit lvl1 and the byte TestConfig; and / or based on values stored in memory 112, such as, for example, the value of status bit lvl2 and the byte ProdConfig. For example, the byte EraseAllow is then stored in a register. For example, the value of this byte is calculated via logic hardware (such as, for example, logic gates) and is based on the contents of memories 104 and 112. The register storing the byte EraseAllow is then coupled to a memory controller, for example. The memory controller is then configured to authorize or not authorize erasure of a block based on the value of the byte EraseAllow. For example, during the implementation of steps 200, 201, and 202, upon receiving a request to erase one of the blocks in memory 104, the value of the bit of the authorization byte associated with the block requested to be erased is calculated.
[0063] In the example where configuration bytes are stored in memory 112, for each block of memory 104 identified, for example, by an integer x in the range of 0 to 7, the enable bit EraseAllow[x] (e.g., bit x of the authorization byte) is such that EraseAllow[x] = (LVL1 AND LVL2) OR TestConfig[x], where LVL1 is the state of the first state bit lvl1, LVL2 is the state of the second state bit lvl2, and TestConfig[x] is the state of the bits associated with block x in the byte TestConfig. For example, when the bit EraseAllow[x] is equal to 0, any request to erase the associated block is denied. Thus, any block can be erased during step 200. During steps 201 and / or 202, erasure of the block identified by integer x is authorized only if the associated TestConfig[x] bit is programmed in step 200 to authorize erasure of the block.
[0064] In the case where the configuration bytes are stored in memory 104, the additional byte ProdConfig stored in memory 112 is available for writing only during step 201 (in other words, when circuit 102 is in an intermediate state). However, during the implementation of step 202, in other words, when circuit 102 is in its final state, the value of the byte ProdConfig cannot be modified.
[0065] In this example, bit x of the authorization byte is then calculated as EraseAllow[x] = (LVL1 AND LVL2) OR (TestConfig[x] AND LVL2) OR (Not(LVL2) AND ProdConfig[x]). Thus, during step 201, the intermediate entity can modify and configure blocks 300 that are protected from erasure or not protected from erasure.
[0066] Various embodiments and variations have been described. Those skilled in the art will appreciate that certain features of these different embodiments and variations may be combined, and those skilled in the art will be able to envision other variations. In particular, with respect to memory 112, although in the described embodiments, the bits of memory 112 are burned out when the value of memory 112 is equal to 0, it is entirely conceivable that the burned-out bits have a value of 1. Those skilled in the art will be able to adapt the calculation of the bits of the EraseAllow byte accordingly. Furthermore, although the described example illustrates 8 configurable blocks of 16 bytes each, more or fewer blocks may be configured. The size of these blocks may also be different from 16 bytes. Those skilled in the art will be able to adapt the size of the configuration and authorization bytes accordingly.
[0067] Finally, based on the functional indications given above, the actual implementation of the described embodiments and variants is within the capabilities of a person skilled in the art.
[0068] In one embodiment, a method includes programming a first enable bit (EraseAllow[x]) associated with a region of nonvolatile memory (104) of an electronic device (100) to a protection value; and disabling erasure of contents of the first region of nonvolatile memory based on a state of the first enable bit.
[0069] The protection value to which the first enable bit (EraseAllow[x]) is programmed may be a function of a state of a configuration bit (TestConfig[x]) and / or at least one value (LVL1, LVL2) associated with one of a plurality of possible states of the device.
[0070] Configuration bits (TestConfig[x]) may only be programmable when the device is placed in a first state of a plurality of states.
[0071] By programming the first state bit (lvl1), starting from the first state, the device (100) can be set to the second state among the multiple states; and by programming the second state bit (lvl2) stored in the one-time programmable memory (112), starting from the first state or the second state, the device can be set to the third state among the multiple states.
[0072] In one embodiment, erasure of the non-volatile memory area (104) is authorized when the device (100) is in the first state.
[0073] In one embodiment, the first status bit (lvl1) is stored in a non-volatile memory (104).
[0074] In one embodiment, the configuration bits (TestConfig[x]) are stored in a one-time programmable memory (112).
[0075] In one embodiment, the configuration bits (TestConfig[x]) are stored in non-volatile memory (104).
[0076] In one embodiment, additional bits (ProdConfig[x]) are stored in a one-time programmable memory (112) of the device, and the protection value to which the first enable bit (EraseAllow[x]) is programmed is a function of the additional bits.
[0077] In one embodiment, the additional bits (ProdConfig[x]) are only programmable when the device (100) is placed in the second state (lvl1).
[0078] In one embodiment, a device includes a nonvolatile memory (104) including a region associated with a first enable bit (EraseAllow[x]) programmed to a protection value, access for erasing the region being prohibited based on the protection value.
[0079] In one embodiment, the protection value to which the enable bit (EraseAllow[x]) is programmed is a function of the values of the configuration bit (TestConfig[x]), a first state bit (lvl1) stored in the non-volatile memory (104), and a second state bit (lvl2) stored in the one-time programmable memory (112) of the device.
[0080] The configuration bits (TestConfig[x]) may be stored in a one-time programmable memory (112).
[0081] The configuration bits (TestConfig[x]) may be stored in the non-volatile memory (104), and the one-time programmable memory (112) may also include additional bits (ProdConfig[x]), the protection value to which the enable bit is programmed further being a function of the state of the additional bits.
[0082] The state of the first state bit and / or the second state bit (lvl1, lvl2) can be selected from the first state,
[0083] The state of the device is determined in the second state and the third state, and the configuration bits (TestConfig[x]) are only programmable when the device is in the first state.
[0084] In one embodiment, a method includes controlling a state of an electronic device. The state is one of a plurality of states of the electronic device, the plurality of states including an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in a non-volatile memory of the electronic device. The transition from the initial state or the test state to the configuration state is controlled by setting a second state bit in a one-time programmable memory of the electronic device. The configuration bits of the electronic device are programmed, wherein the programming of the configuration bits is limited to the initial state of the electronic device. A first enable bit associated with a region of the non-volatile memory of the electronic device is programmed to a protection value, wherein the protection value is a function of the value of the configuration bit. The programming of the first enable bit is limited to the initial state of the electronic device. Erasure of a first region of the non-volatile memory is limited based on the value of the first enable bit.
[0085] In one embodiment, when the device is in an initial state, erasure of the non-volatile first area is enabled.
[0086] In one embodiment, the configuration bits are stored in a one-time programmable memory.
[0087] In one embodiment, the configuration bits are stored in non-volatile memory. In one embodiment, the additional bits are stored in a one-time programmable memory of the electronic device, and the protection value is a function of the configuration bits and the additional bits. In one embodiment, the additional bits are programmable only when the device is placed in a test state.
[0088] In one embodiment, an electronic device includes a memory and a processing circuit system coupled to the memory. The memory includes a non-volatile memory and a one-time programmable memory. In operation, a first enable bit stored in the memory is associated with a first region of the non-volatile memory, and erasure of the first region of the non-volatile memory is restricted based on the value of the first enable bit. The device has multiple states, including an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in the non-volatile memory. The transition from the initial state or the test state to the configuration state is controlled by setting a second state bit in the one-time programmable memory of the electronic device. Programming of the configuration bits stored in the memory is restricted to the initial state of the electronic device. Programming of the first enable bit is a function of the value of the configuration bit, and programming of the first enable bit is restricted to the initial state of the electronic device.
[0089] In one embodiment, erasure of the first region of the non-volatile memory is enabled when the device is in the first state.
[0090] In one embodiment, the configuration bits are stored in a one-time programmable memory.
[0091] In one embodiment, the configuration bits are stored in non-volatile memory. In one embodiment, the additional bits are stored in a one-time programmable memory of the electronic device, and the protection value is a function of the configuration bits and the additional bits. In one embodiment, the additional bits are programmable only when the device is placed in a test state.
[0092] In one embodiment, a system includes a non-volatile memory, a one-time programmable memory, and a processing circuit system. In operation, a first enable bit is associated with a first area of the non-volatile memory, and erasure of the first area of the non-volatile memory is restricted based on the value of the first enable bit. The device has multiple states, including an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in the non-volatile memory. The transition from the initial state or the test state to the configuration state is controlled by setting a second state bit in the one-time programmable memory. Programming of the configuration bits stored in the memory is restricted to the initial state of the electronic device. Programming of the first enable bit is a function of the value of the configuration bit, and programming of the first enable bit is restricted to the initial state of the electronic device.
[0093] In one embodiment, in operation, when the device is in an initial state, erasure of the first region of the non-volatile memory is enabled.
[0094] In one embodiment, the configuration bits are stored in non-volatile memory.
[0095] In one embodiment, the processing circuitry is operable to execute an application. In one embodiment, the system is a smartphone and the application is a smartphone application.
[0096] In one embodiment, the contents of a non-transitory computer-readable medium cause a processing circuit system to perform a method. The method includes controlling a state of an electronic device. The state is one of a plurality of states of the electronic device, the plurality of states including an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in a non-volatile memory of the electronic device. The transition from the initial state or the test state to the configuration state is controlled by setting a second state bit in a one-time programmable memory of the electronic device. The method includes programming configuration bits of the electronic device, wherein programming of the configuration bits is limited to the initial state of the electronic device; programming a first enable bit associated with a region of the non-volatile memory of the electronic device to a protection value, wherein the protection value is a function of the value of the configuration bit, and programming of the first enable bit is limited to the initial state of the electronic device; and limiting erasure of a first region of the non-volatile memory based on the value of the first enable bit. In one embodiment, the contents include instructions executable by the processing circuit system.
[0097] In one embodiment, the configuration bits are stored in non-volatile memory.
[0098] Some embodiments may take the form of or include a computer program product. For example, according to one embodiment, a computer readable medium is provided, comprising a computer program adapted to perform one or more of the methods or functions described above. The medium may be a physical storage medium, such as, for example, a read-only memory (ROM) chip, or a disk, such as a digital versatile disk (DVD-ROM), a compact disk (CD-ROM), a hard disk, a memory, a network, or a portable media item, which is read by an appropriate drive or via an appropriate connection, including being encoded in one or more bar codes or other related codes, which are stored on one or more such computer readable media and are readable by an appropriate reader device.
[0099] In addition, in some embodiments, some or all of these methods and / or functions may be implemented or provided in other manners, such as at least partially implemented or provided in firmware and / or hardware, including but not limited to one or more application-specific integrated circuits (ASICs), digital signal processors, discrete circuit systems, logic gates, standard integrated circuits, controllers (e.g., by executing appropriate instructions, and including microcontrollers and / or embedded controllers), field programmable gate arrays (FPGAs), complex programmable logic devices (CPLDs), etc., as well as devices using RFID technology, and various combinations thereof.
[0100] The various embodiments described above can be combined to provide further embodiments. Aspects of the embodiments can be modified, if necessary, to employ concepts of the various patents, applications, and publications to provide further embodiments.
[0101] These and other changes can be made to the embodiments in light of the above detailed description. Generally, in the following claims, the terms used should not be construed to limit the claims to the specific embodiments disclosed in the specification and claims, but should be construed to encompass all possible embodiments and the full scope of equivalents to which such claims are entitled. Therefore, the claims are not limited by this disclosure.
Claims
1. A method comprising: Control the state of electronic devices, where The state is one of a plurality of states of the electronic device, wherein the plurality of states include an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in a non-volatile memory of the electronic device, and The transition from the initial state or the test state to the configuration state is controlled by setting a second state bit in a one-time programmable memory of the electronic device; programming the configuration bits of the electronic device, wherein the programming of the configuration bits is limited to the initial state of the electronic device; programming a first enable bit associated with a region of non-volatile memory of the electronic device to a protection value, wherein the protection value is a function of the value of the configuration bit, and programming of the first enable bit is restricted to the initial state of the electronic device; as well as Erasure of the first region of the nonvolatile memory is restricted based on a value of the first enable bit. 2 . The method of claim 1 , wherein the erasure of the first area of the nonvolatile memory is enabled when the device is in the initial state. The method of claim 1 , wherein the configuration bits are stored in the one-time programmable memory. The method of claim 1 , wherein the configuration bits are stored in the non-volatile memory. 5 . The method of claim 4 , wherein additional bits are stored in the one-time programmable memory of the electronic device, and wherein the protection value is a function of the configuration bits and the additional bits. The method of claim 4 , wherein the additional bits can only be programmed when the device is placed in the test state.
7. An electronic device comprising: Memory, including non-volatile memory and one-time programmable memory; as well as processing circuitry coupled to the memory, wherein in operation, a first enable bit stored in the memory associated with a first region of the non-volatile memory, erasure of the first region of the nonvolatile memory is restricted based on a value of the first enable bit, The device has multiple states, including an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in the non-volatile memory, The transition from the initial state or the test state to the configuration state is controlled by setting a second status bit in the one-time programmable memory of the electronic device, programming of configuration bits stored in said memory is restricted to said initial state of said electronic device, The programming of the first enable bit is a function of the value of the configuration bit, and Programming of the first enable bit is limited to the initial state of the electronic device.
8. The device of claim 7, wherein in operation, when the device is in the first state, erasure of the first region of the non-volatile memory is permitted.
9. The apparatus of claim 7, wherein in operation, the configuration bits are stored in the one-time programmable memory.
10. The apparatus of claim 7, wherein in operation, the configuration bits are stored in the non-volatile memory.
11. The device of claim 10, wherein in operation, additional bits are stored in the one-time programmable memory of the electronic device, and the protection value is a function of the configuration bits and the additional bits.
12. The device of claim 10, wherein the additional bit can be programmed only when the device is placed in the test state.
13. A system comprising: Non-volatile memory; One-time programmable memory; as well as processing circuitry, wherein in operation, A first enable bit is associated with a first region of the non-volatile memory, erasure of the first region of the nonvolatile memory is restricted based on a value of the first enable bit, The device has multiple states, including an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in the non-volatile memory, The transition from the initial state or the test state to the configuration state is controlled by setting a second state bit in the one-time programmable memory, programming of configuration bits stored in said memory is restricted to said initial state of said electronic device, The programming of the first enable bit is a function of the value of the configuration bit, and Programming of the first enable bit is limited to the initial state of the electronic device.
14. The system of claim 13, wherein in operation, when the device is in the initial state, erasure of the first area of the non-volatile memory is permitted.
15. The system of claim 13, wherein in operation, the configuration bits are stored in the non-volatile memory.
16. The system of claim 13, wherein the processing circuitry is operative to execute an application.
17. The system of claim 16, wherein the system is a smartphone and the application is a smartphone application.
18. A non-transitory computer-readable medium having content for causing a processing circuit system to perform a method comprising: Control the state of electronic devices, where The state is one of a plurality of states of the electronic device, wherein the plurality of states include an initial state, a test state, and a configuration state. The transition between the initial state and the test state is controlled by setting or resetting a first state bit in a non-volatile memory of the electronic device, and The transition from the initial state or the test state to the configuration state is controlled by setting a second state bit in a one-time programmable memory of the electronic device; programming the configuration bits of the electronic device, wherein the programming of the configuration bits is limited to the initial state of the electronic device; programming a first enable bit associated with a region of non-volatile memory of the electronic device to a protection value, wherein the protection value is a function of the value of the configuration bit, and programming of the first enable bit is restricted to the initial state of the electronic device; as well as Erasure of the first region of the nonvolatile memory is restricted based on a value of the first enable bit.
19. The non-transitory computer readable medium of claim 18, wherein the configuration bits are stored in the non-volatile memory.
20. The non-transitory computer-readable medium of claim 18, wherein the content comprises instructions executable by the processing circuitry.