Processing system, related integrated circuit, device and method
By introducing password verification and protection circuits into the processing system, combined with a temporary password store and overwrite signal, the security issues of reference password updates and management are resolved, ensuring the security and analyzability of the device at different stages of its lifecycle.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- STMICROELECTRONICS INT NV
- Filing Date
- 2025-11-05
- Publication Date
- 2026-05-08
AI Technical Summary
In existing processing systems, the updating and management of reference passwords pose security risks, especially in multi-user environments, which may lead to device unavailability or difficulties in analysis.
By employing a combination of cryptographic verification and protection circuits, and managing the update of reference passwords through a temporary password store and overwrite signals, secure access control is ensured at different lifecycle stages.
It enables secure updates and management of reference passwords at different lifecycle stages, reducing the risk of unauthorized access to devices and improving system security and analyzability.
Smart Images

Figure CN121996584A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of this disclosure relate to processing systems, and more particularly to solutions for updating the passwords of processing systems. Summary of the Invention
[0002] In view of the above, one object of various embodiments of this disclosure is to provide a solution for updating one or more passwords of a processing system.
[0003] According to one or more embodiments, one or more of the above objectives are achieved by means of a processing system having the features specifically set forth in the appended claims. Furthermore, the embodiments also relate to related integrated circuits, devices, and methods.
[0004] The scope of protection is defined in the appended claims, which are an integral part of the technical teachings of the disclosure provided herein.
[0005] As mentioned above, various embodiments of this disclosure relate to a processing system. The processing system includes: a non-volatile memory including a memory region arranged to store cryptographic data; cryptographic verification circuitry; and protection circuitry managing access to the non-volatile memory (e.g., for updating the cryptographic data). Specifically, in various embodiments, the memory region includes a first memory slot arranged to store a first master password, a second memory slot arranged to store a second master password, and a third memory slot arranged to store a security password. The memory region may include additional slots for storing other master passwords and / or other security passwords.
[0006] In various embodiments, the password verification circuit is configured to receive a password verification command including a password and a slot number. Furthermore, the password verification circuit is configured to determine whether the slot number is associated with a first master password or a second master password. Specifically, in response to determining that the slot number is associated with a first master password, the password verification circuit determines whether the received password corresponds to the first master password, and in response to determining that the received password corresponds to the first master password, sets an overwrite signal to indicate successful verification of the first master password. In some embodiments, in response to determining that the slot number is associated with a second master password, the password verification circuit determines whether the received password corresponds to the second master password, and in response to determining that the received password corresponds to the second master password, sets an overwrite signal to indicate successful verification of the second master password.
[0007] For example, the overwrite signal may include a first signal and a second signal, and the password verification circuit may be configured to assert the first signal to indicate successful verification of the first master password and to deassert the first signal to not indicate successful verification of the first master password, and to assert the second signal to indicate successful verification of the second master password and to deassert the second signal to not indicate successful verification of the second master password.
[0008] Similarly, in various embodiments, the password verification circuit can be configured to determine whether a slot number is associated with a security password. Accordingly, in response to determining that a slot number is associated with a security password, the password verification circuit can determine whether a received password corresponds to a security password, and in response to determining that a received password corresponds to a security password, set an overwrite signal to indicate successful verification of the security password.
[0009] For example, to implement the password verification operation, the processing system may also include a password store and a configuration circuit configured to transfer password data from non-volatile memory to the password store. Accordingly, in this case, the password verification circuit may be configured to provide slot numbers to the password store and receive the corresponding passwords associated with those slot numbers from the password store.
[0010] In various embodiments, a security password can be used to selectively disable one or more protections. For example, in this case, the processing system may include circuitry and additional protection circuitry configured to enable access to the circuitry in response to a determination that an overwrite signal indicates successful verification of the security password.
[0011] In various embodiments, the master password may be used to selectively enable (at least) write access to the security password. Accordingly, in various embodiments, the protection circuitry is configured to receive write requests for writing a new security password to a third memory slot arranged to store the security password. For this purpose, the processing system may include processing circuitry (such as a microprocessor) and / or a communication interface configured to provide password verification commands and write requests.
[0012] In various embodiments, in a first operating mode (such as a field lifecycle phase), the protection circuitry determines whether the security access data indicates that a third memory slot is associated with a first master password or a second master password. For example, the protection circuitry may be configured to determine the operating mode based on lifecycle data and / or configuration data indicating a lifecycle phase of the processing system.
[0013] For example, to manage secure access data, the protection circuitry may include a register that provides secure access data, wherein a field of the secure access data indicates whether a third memory slot, arranged to store a secure password, is associated with a first master password, a second master password, or is unallocated. Specifically, in various embodiments, even when the configuration circuitry of the processing system requests multiple programming operations on a field of the secure access data, the protection circuitry only allows a single programming operation on that field. To this end, the protection circuitry may be configured to receive configuration data from the configuration circuitry and determine whether a field of the secure access data indicates that the third memory slot is (still) unallocated. Accordingly, in response to determining that a field of the secure access data indicates that the third memory slot is unallocated, the protection circuitry may overwrite the corresponding bit of the field of the secure access data with the corresponding bit of the received configuration data. Otherwise, the protection circuitry may disable writing to the field of the secure access data.
[0014] For example, in order to receive configuration data from the configuration circuit, the protection circuit may be associated with an address, wherein the non-volatile memory includes an additional memory region arranged to store frames of configuration data, each frame of configuration data including an address and corresponding configuration data. Accordingly, in this case, the configuration circuit may be configured to sequentially read frames of configuration data from the non-volatile memory, determine whether the address of the frame of configuration data corresponds to the address associated with the protection circuit, and, in response to determining that the address of the frame of configuration data corresponds to the address associated with the protection circuit, transmit the configuration data frame of configuration data to the protection circuit.
[0015] Furthermore, in various embodiments, the protection circuit determines whether the overwrite signal indicates successful verification of the first master password or the second master password. Accordingly, in response to determining that the security access data indicates that the third memory slot is associated with the first master password and the overwrite signal indicates successful verification of the first master password, the protection circuit enables the writing of a new security password to the third memory slot. In some embodiments, in response to determining that the security access data indicates that the third memory slot is associated with the first master password and the overwrite signal does not indicate successful verification of the first master password, the protection circuit blocks write access, i.e., prohibits the writing of a new security password to the third memory slot. Similarly, in response to determining that the security access data indicates that the third memory slot is associated with the second master password and the overwrite signal indicates successful verification of the second master password, the protection circuit may enable the writing of a new security password to the third memory slot arranged to store the security password.
[0016] In various embodiments, the protection circuitry can also selectively enable updates to the master password. For example, in various embodiments, the protection circuitry is configured to receive a write request for writing a new master password to a first memory slot arranged to store the first master password. For example, in a first operating mode (e.g., a field lifecycle phase), the protection circuitry can determine whether an overwrite signal indicates successful verification of the first master password. Then, in response to determining that the overwrite signal indicates successful verification of the first master password, the protection circuitry can enable writing the new master password to the first memory slot. In some embodiments, in response to determining that the overwrite signal does not indicate successful verification of the first master password, the protection circuitry can prevent writing the new master password to the first memory slot.
[0017] In various embodiments, the protection circuitry can also support additional operating modes. For example, in a second operating mode (such as a production lifecycle phase), the protection circuitry can enable write access to the first master password and security password, i.e., without password verification.
[0018] In various embodiments, in a third operating mode (such as a software development lifecycle phase), the protection circuitry can be configured to determine whether security access data indicates that a third memory slot is (already) associated with a first master password, associated with a second master password, or unassigned. Furthermore, the protection circuitry can determine whether an overwrite signal indicates successful verification of the first or second master password. Specifically, in response to determining that security access data indicates the third memory slot is associated with a second master password or is unassigned, the protection circuitry can enable writing a new security password to the third memory slot. Moreover, in response to determining that security access data indicates the third memory slot is associated with a first master password and an overwrite signal indicates successful verification of the first master password, the protection circuitry can enable writing a new security password to the third memory slot. In some embodiments, in response to determining that security access data indicates the third memory slot is associated with a first master password and an overwrite signal does not indicate successful verification of the first master password, the protection circuitry can prevent writing a new security password to the third memory slot. Attached Figure Description
[0019] Embodiments of the present disclosure will now be described with reference to the accompanying drawings, which are provided by way of non-limiting example only, in which:
[0020] Figure 1 An example of an electronic system including multiple processing systems is shown in some embodiments;
[0021] Figure 2 and Figure 3 Examples of processing systems in some embodiments are shown;
[0022] Figure 4 and Figure 5Examples of processing systems including protection circuitry and password verification circuitry in some embodiments are shown;
[0023] Figure 6 Embodiments of a processing system according to the present disclosure are shown in some embodiments;
[0024] Figure 7 Embodiments of a cryptographic verification circuit according to the present disclosure are shown in some embodiments;
[0025] Figure 8A and Figure 8B An embodiment of the password verification command in some embodiments is shown;
[0026] Figure 9 An embodiment of a configuration circuit configured to read cryptographic data and configuration data from non-volatile memory is shown in some embodiments;
[0027] Figure 10 An embodiment of a non-volatile memory arranged to store cryptographic data is shown in some embodiments, wherein the non-volatile memory is associated with protection circuitry.
[0028] Figure 11 Another embodiment of a non-volatile memory arranged to store cryptographic data is shown in some embodiments;
[0029] Figure 12 The configuration shown in some embodiments is configured to update the storage to Figure 11 An example of a system for processing cryptographic data using non-volatile memory;
[0030] Figure 13 An embodiment of secure password control data is shown in some embodiments;
[0031] Figure 14 The following are shown in some embodiments for use Figure 11 The first part of the protection circuit for the non-volatile memory;
[0032] Figure 15 The following are shown in some embodiments for use Figure 11 The second part of the protection circuit for the non-volatile memory; and
[0033] Figure 16 Another embodiment of the password verification command in some embodiments is shown. Detailed Implementation
[0034] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the embodiments. Embodiments may be practiced without one or more of these specific details, or using other methods, components, materials, etc. In other instances, well-known structures, materials, or operations are not shown or described in detail to avoid obscuring aspects of the embodiments.
[0035] Throughout this specification, the phrase "an embodiment" or "an embodiment" refers to a specific feature, structure, or characteristic associated with that embodiment being included in at least one embodiment. Therefore, the phrases "in one embodiment" or "in an embodiment" appearing throughout this specification do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0036] The references provided herein are for convenience only and do not explain the scope or meaning of the embodiments.
[0037] Figure 1 A typical electronic system, such as a vehicle's electronic system, is shown, including multiple processing systems 10, such as embedded systems or integrated circuits, for example, field-programmable gate arrays (FPGAs), digital signal processors (DSPs), or microcontrollers (e.g., dedicated to the automotive market).
[0038] For example, Figure 1 The diagram shows three processing systems 101, 102, and 103, which are connected via a suitable communication system 20. This communication system may include, for example, a vehicle control bus, such as a Controller Area Network (CAN) bus, and possibly a multimedia bus, such as a Media Oriented System Transport (MOST) bus, which is connected to the vehicle control bus via a gateway. Typically, the processing systems 10 are located in different locations within the vehicle and may include, for example, an engine control unit, a transmission control unit (TCU), an anti-lock braking system (ABS), a body control module (BCM), and / or a navigation and / or multimedia audio system. Accordingly, one or more of the processing systems 10 may also implement real-time control and adjustment functions. These processing systems are typically identified as electronic control units (ECUs).
[0039] Figure 2 A block diagram of an exemplary digital processing system 10 (such as a microcontroller) is shown, which can be used as... Figure 1 Any one of the processing systems 10.
[0040] In the considered example, the processing system 10 includes a microprocessor 102 programmed via software instructions, typically a central processing unit (CPU). Typically, the software executed by the microprocessor 102 is stored in a non-volatile program memory 104, such as flash memory or EEPROM. Therefore, the memory 104 is configured to store the firmware of the processing unit 102, which includes software instructions to be executed by the microprocessor 102. Generally, the non-volatile memory 104 can also be used to store other data, such as configuration data, for example, calibration data.
[0041] The microprocessor 102 is also typically associated with volatile memory 104b, such as random access memory (RAM). For example, memory 104b can be used to store temporary data.
[0042] like Figure 2 As shown, communication with the memories 104 and / or 104b is typically performed via one or more memory controllers 100. The memory controllers 100 may be integrated into the microprocessor 102 or connected to the microprocessor 102 via a communication channel, such as the system bus of the processing system 10. Similarly, the memories 104 and / or 104b may be integrated with the microprocessor 102 in a single integrated circuit, or the memories 104 and / or 104b may be in the form of separate integrated circuits and connected to the microprocessor 102, for example, via traces on a printed circuit board.
[0043] In the example under consideration, microprocessor 102 may have been associated with one or more (hardware) resources / peripherals 106 selected from the following group:
[0044] One or more communication interfaces IF, for example, for exchanging data via communication system 20, such as Universal Asynchronous Receiver / Transmitter (UART), Serial Peripheral Interface Bus (SPI), Inter-Integrated Circuit (ICI), etc. 2 C) Controller Area Network (CAN) bus, and / or Ethernet interface, and / or debug interface; and / or
[0045] One or more analog-to-digital converters (ADCs) and / or digital-to-analog converters (DAs); and / or
[0046] One or more dedicated digital components (DCs), such as hardware timers and / or counters, or cryptographic coprocessors; and / or
[0047] One or more analog components AC, such as comparators, sensors (e.g., temperature sensors), etc.; and / or
[0048] One or more mixed-signal components MSC, such as PWM (pulse width modulation) drivers.
[0049] Generally, a dedicated digital component (DC) can also correspond to an FPGA integrated in the processing system 10. For example, in this case, the memory 104 can also include program data for such an FPGA.
[0050] Accordingly, the digital processing system 10 can support different functions. For example, the behavior of the microprocessor 102 is determined by firmware (e.g., software instructions to be executed by the microprocessor 102 of the microcontroller 10) stored in the memory 104. Therefore, by installing different firmware, the same hardware (microcontroller) can be used for different applications.
[0051] In this regard, the next generation of such processing systems 10 (e.g., microcontrollers suitable for use in automotive applications) is expected to exhibit increased complexity, mainly due to the increased number of requested functions (new protocols, new features, etc.) and stricter constraints on execution conditions (e.g., lower power consumption, increased computing power and speed, etc.).
[0052] For example, a more sophisticated multi-core processing system 10 has recently been proposed. For instance, such a multi-core processing system can be used for (parallel) execution. Figure 1 The processing system 10 shown includes several processing systems, such as several ECUs of the vehicle.
[0053] Figure 3 An example of a multi-core processing system 10 is shown. Specifically, in the example considered, the processing system 10 includes multiple (n) processing cores 1021...102 connected to a (on-chip) communication system 114. n For example, in the context of a real-time control system, processing cores 1021...102 n It can be an ARM Cortex®-R52 core. Generally, the communication system 114 may include one or more bus systems, such as those based on an Advanced Scalable Interface (AXI) bus architecture and / or a Network on Chip (NoC).
[0054] For example, as illustrated in the example of processing core 1021, each processing core 102 may include a microprocessor 1020 and a communication interface 1022 configured to manage communication between the microprocessor 1020 and the communication system 114. Typically, the communication interface 1022 is a master interface, configured to forward a given (read or write) request from the microprocessor 1020 to the communication system 114 and to forward an optional response from the communication system 114 to the microprocessor 1020. In some embodiments, the communication interface 1022 includes a slave interface. For example, in this way, a first microprocessor 1020 may send a request to a second microprocessor 1020 (via the communication interface 1022 of the first microprocessor, the communication system 114, and the communication interface 1022 of the second microprocessor).
[0055] Generally speaking, each processing core has 1021...102 n It may also include additional local resources, such as one or more local memories 1026, which are typically identified as tightly coupled memory (TCM).
[0056] As mentioned earlier, processing cores 1021...102 n These memories are typically configured to exchange data with non-volatile memory 104 and / or volatile memory 104b. In the multi-core processing system 10, these memories are typically system memory, i.e., memory allocated to processing cores 1021...102. n Shared. However, as mentioned earlier, each processing core has 1021...102... n It may include one or more additional local memories 1026.
[0057] For example, such as Figure 3 As shown, the processing system 10 may include one or more memory controllers 100 configured to connect at least one non-volatile memory 104 and at least one volatile memory 104b to the communication system 114. As mentioned earlier, one or more of the memories 104 and / or 104b may be integrated into an integrated circuit of the processing system 10, or may be externally connected to an integrated circuit.
[0058] As mentioned earlier, processing system 10 may include one or more resources 106, such as one or more communication interfaces or coprocessors (e.g., cryptographic coprocessors). Resources 106 are typically connected to communication system 114 via corresponding communication interfaces 1062. Generally, communication interfaces 1062 include at least slave interfaces. For example, in this way, processing core 102 can send a request to resource 106, and resource 106 can return given data. Generally, one or more of communication interfaces 1062 may also include corresponding master interfaces. For example, such a master interface may be useful where a resource must initiate communication to exchange data with another circuit (such as resource 106 or processing core 102) connected to communication system 114 via (read and / or write) requests. For example, for this purpose, communication system 114 may actually include an Advanced Peripheral Bus (APB) and an Advanced Microcontroller Bus Architecture (AMBA) High Performance Bus (AHB) for connecting resources / peripherals 106 to the AMBA AHB bus.
[0059] This processing system 10 typically also includes one or more direct memory access (DMA) controllers 110. For example, such as Figure 3 As shown, the DMA controller 110 can be used to exchange data directly with memory (e.g., memory 104b) based on requests received from resource 106. For example, in this way, the communication interface IF can directly read data from memory 104b (via the DMA controller 110) and transfer that data without exchanging additional data with processing unit 102. Generally, the DMA controller 110 can communicate with one or more memories via communication system 114 or via one or more dedicated communication channels.
[0060] Therefore, a modern processing system 10 can include a large number of circuits and functions. This also means that the security framework of such a processing system 10 is becoming increasingly complex, which determines the increased time and complexity of the testing phase. Typically, the security framework is based on the concept of resource protection, that is, given a set of resources, the framework is designed so that access to one or more resources can be selectively blocked or granted based on specific conditions. For example, one of these conditions could be based on a password, that is, access to the resource is blocked until the correct password is provided.
[0061] For example, U.S. Patent US10,949,570 B2 discloses a possible solution for resource conservation, which is incorporated herein by reference. For example, as Figure 4As shown, one or more of the circuits 160 of the processing system 10 may be associated with a protection circuit 150 configured to control access to the respective circuits 160 (such as memory controller 100, processing circuit 102, and / or resource / peripheral device 106).
[0062] For example, a corresponding access request (CMD) can be received from another circuitry of the processing system 10 (such as processing circuitry 102) or a communication interface IF (such as a debug interface). For example, protection circuitry 150 is typically configured to control access to one or more internal circuitries 160 of the processing system 10 via external debugging tools, or to control the possibility of performing write (or similar read) access to a specific memory region (such as a memory region of non-volatile memory 104). For example, the use of a debug interface (such as a JTAG (Joint Test Action Group) interface) can be disabled by interrupting the connection between the internal debug interface and a pin that can be connected to an external debugger (via protection circuitry 150). Accordingly, in this way, the debug interface will not respond to external requests provided to the corresponding pins.
[0063] Generally, while some circuits 160 may not have access restrictions, access to other circuits 160 may be blocked by default or selectively based on configuration data (i.e., protection may be activated). For example, as also described in U.S. Patents US 10,740,041 B2 and US 10,922,015 B2 (which are incorporated herein by reference for this purpose), protection for a given circuit 160 may be selectively activated based on the lifecycle stage of the processing system 10 as indicated by the lifecycle data LCD. For example, the lifecycle data LCD may correspond to a bit sequence that may indicate one of the following stages:
[0064] "Production" (LC0) occurs when the processing system 10 (e.g., a microcontroller) is located within the chip architecture;
[0065] "Customer delivery" (LC1) occurs when the processing system 10 has been delivered to a first-tier customer (e.g., the manufacturer of the engine control unit);
[0066] "OEM production" (LC2) refers to production where the equipment has been shipped to the next level of customer (e.g., an automotive manufacturer).
[0067] "Field" (LC3) refers to the installation of equipment in a final product (e.g., in a car sold on the market);
[0068] "Fault Analysis" (LC4) occurs when the equipment is returned to the manufacturer or software developer of the processing system 10 for diagnostic purposes.
[0069] Typically, lifecycle data LCDs are written such that once a certain stage is reached, it cannot be reverted to a previous stage; that is, the lifecycle can only be advanced. This can be achieved, for example, through one-hot coding, where a fuse blows each time a given stage is reached. For example, advancing the lifecycle to the next stage can be accomplished by the entity that owns the device in the current lifecycle stage (e.g., a chip manufacturer advances the lifecycle when it is shipped to the customer delivery stage; a Tier 1 customer advances the lifecycle when it is shipped to the OEM production stage, etc.). For example, in this case, each protection 150 of the processing system 10 can be in one of the following states:
[0070] a) Lifecycle data LCD indication protection is disabled, regardless of configuration data CD (e.g., in phase LC0 or LC4).
[0071] b) Lifecycle data LCD indication protection can be selectively enabled, and configuration data CD indication protection can be disabled (e.g., in phases LC1 and LC2).
[0072] c) Lifecycle data LCD indication protection can be selectively enabled, and configuration data CD indication protection is enabled (e.g., in phases LC1 and LC2); or
[0073] d) Lifecycle data LCD indicates that protection is enabled, regardless of configuration data CD (e.g., stage LC3).
[0074] Accordingly, in order to grant access to the protected circuit 160, the processing system 10 may include a password verification circuit 152 configured to overwrite one or more of the protections 150 when a specific password is provided. Generally, some protections 150 may become inaccessible once activated, or a given password may only disable a subset of the given protections.
[0075] In the considered example, at least one reference key / keyword RK is stored in the processing system 10 in some way. For example, the reference key RK may be hardwired or stored in the non-volatile memory 104 of the processing system 10. In this case, the processing system 10 is typically configured to restrict read access to the memory region containing the reference key RK to ensure that the reference key RK remains confidential. For example, a possible solution for storing the reference key in non-volatile memory is described in the aforementioned cited patent.
[0076] Accordingly, in order to disable at least one protection 150, the user should be able to provide the password verification command VPW, which includes the password / keyword K, to the password verification circuit 152. For example, in the considered example, the user can provide the password K to the password verification circuit 152 via software instructions executed by the processing circuit 102 of the processing system 10 and / or via the communication interface IF of the processing system 10 (such as via a debug interface (e.g., JTAG) or a CAN interface connected to an external debugger).
[0077] For example, circuit 160, password verification circuit 152, and interface IF and / or processing circuit 102 can be connected via communication system 114. In this case, command CMD and password verification command VPW can be transmitted through the same communication system 114, specifying the target address as the address of circuit 160 (for command CMD) or the address of password verification circuit 152 (for password verification command VPW).
[0078] Accordingly, once the password verification circuit 152 receives the password verification command VPW including the password K, the password verification circuit 152 can obtain the reference password RK, compare the password K with the reference password RK, and in response to determining that the two passwords match, the password verification circuit 152 can generate an overwrite signal OW, which is sent to one or more protection circuits 150. Accordingly, in response to the overwrite signal OW, (one or more) protection circuits 150 can disable at least a portion of the corresponding protection.
[0079] However, this could mean that communication between the cryptographic management circuit 150 and the memory controller 100 of the memory 104 is also transmitted via the communication system 114, which could pose a security risk, as the reference cipher RK could be obtained by monitoring transactions exchanged via the communication system 114.
[0080] Figure 5 The modified security architecture is shown. Specifically, it is related to... Figure 4In contrast, the processing system 10 also includes a password upload circuit 154 and a temporary password storage 156. Accordingly, in the considered example, the password verification circuit 152 does not dynamically access one or more original reference passwords RK stored in the non-volatile memory 104. In some embodiments, the password upload circuit 154 reads one or more reference passwords RK at a time and stores them in the temporary password storage 156, which is implemented via registers or RAM and can only be read by the password verification circuit 152. Accordingly, the password verification circuit 152 can compare the received password K with the reference password RK stored in the temporary password storage 156, wherein the read path between the password verification circuit 152 and the temporary password storage 156 is not shared with other circuits of the processing system 10.
[0081] In many known processing circuits 10, one or more reference passwords RK are static. However, this means that if the reference passwords RK are compromised, the situation is irreversible, and the device becomes unusable in terms of security. Accordingly, known processing systems 10 allow updating one or more reference passwords RK stored in non-volatile memory 104. For example, a password change request may require the user to provide the current (old) value of the password and the new value of the password RK. For example, the user may send a password verification command VPW with the current (old) password to unlock the memory area of memory 104 used to store one or more reference passwords RK, and then send a command CMD to reprogram / update the reference passwords RK.
[0082] However, when the system is used by different users, not all users will know the new reference password RK. For example, a car manufacturer might change the reference password RK without communicating the new password to the engine control unit manufacturer. In such a case, the engine control unit manufacturer might find it difficult to analyze the engine control unit.
[0083] exist Figures 6 to 16 The following description has referenced Figures 1 to 5 The elements or components described are indicated by the same reference numerals previously used in these figures; in order not to overburden this detailed description, the descriptions of these previously described elements will not be repeated below.
[0084] As mentioned above, this disclosure relates to a solution for updating one or more reference cryptographic keys in a processing system.
[0085] Figure 6A processing system 10a according to this disclosure is illustrated. Specifically, the processing system 10a includes: at least one processing circuit 102, such as a microprocessor 1020; a memory controller 100 for interfacing with non-volatile memory 104a; and a password verification circuit 152a. In various embodiments, the processing core 102, the password verification circuit 152a, and the optional memory controller 100 are connected via a communication system 114. The processing system 10a may also include additional circuitry, such as one or more peripheral devices 106 and / or a DMA controller 110. As previously described, one or more of the circuits 160 of the processing system 10a may be associated with (e.g., included) a corresponding protection circuit 150 configured, for example, to control access to the corresponding circuit 160 (such as the processing circuit 102, memory controller 100, or peripheral device 106) based on lifetime data LCD and / or configuration data CD. Specifically, in various embodiments, the password verification circuit 152a is configured to generate one or more overwrite signals OW, wherein one or more of the protection circuits 150 are configured to disable corresponding protection based on one or more overwrite signals OW. For a general description of these circuits, refer to Figures 1 to 5 The description.
[0086] Figure 7 An embodiment of the password verification circuit 152a is shown. In the considered embodiment, the password verification circuit 152a is (e.g., directly) connected to a password store 156a for receiving a reference password RK to be used for password verification operations. In various embodiments, the password store 156a includes multiple slots PW0, PW1, etc., for storing multiple reference passwords RK.
[0087] In various embodiments, the password store 156a may directly correspond to a dedicated memory slot in the non-volatile memory 104a (e.g., see...). Figure 4 (as disclosed). In some embodiments, the cryptographic store 156a is, for example, a temporary cryptographic store implemented via RAM and / or registers (see, for example, see [link to relevant documentation]). Figure 5 (Disclosure). In the latter case, one or more reference keys RK are stored in the non-volatile memory 104a of the processing system 10a (e.g., a dedicated area of the non-volatile memory 104a), and during the configuration phase of the processing system 10a, (one or more) reference keys RK are transferred from the memory 104a to the temporary key store 156a. In both cases, when the processing unit 102 is activated, (one or more) reference keys RK have been loaded into the key store 156.
[0088] In various embodiments, the password verification circuit 152a includes at least one interface for receiving a password K to be verified. For example, as mentioned earlier, the password verification circuit 152a may receive a password verification command VPW including the password K from the processing unit 102 of the processing system 10a. Accordingly, in order to receive data from the processing circuit 102, the password verification circuit 152a may include an interface 1520. For example, in various embodiments, the processing circuit 102 includes a microprocessor 1020, and the interface 1520 includes one or more registers addressable by the processing unit 102. For example, the interface 1520 may be a slave interface connected to the communication system 114, for example, via a peripheral bridge. Accordingly, in various embodiments, the processing circuit 102 may provide data to the password verification circuit 152a by writing the contents of the register 1520 via software instructions.
[0089] Additionally or alternatively, the password verification circuitry 152a may receive data via a communication interface IF, for example, from another peripheral device 106 or external processing unit 30 of the processing system 10a. For example, in the considered embodiment, the interface IF may be a debug interface (such as a JTAG interface) connected to an external debugger 30. In various embodiments, the (e.g., debug) interface IF may actually be broken down into multiple sub-interfaces connected via a bus 1062, where each sub-interface is associated with a corresponding circuitry of the processing system 10a to be controlled via (e.g., debug) the interface. For example, this is in Figure 7 Taking interface 1060 as an example, interface 1060 can manage only the debugging commands addressed to the password verification circuit 152a.
[0090] In various embodiments, interface 1520 and / or 1060 can therefore provide a password verification command VPW including the password K to be verified. For example, this is in Figure 7 The diagram schematically illustrates that interface 1060 can provide cipher Ka, and interface 1520 can provide cipher Kb. In the considered embodiment, these ciphers Ka and Kb are then provided to multiplexer 1526, which is configured to select either cipher Ka or Kb (based on whether interface 1060 or 1520 is used).
[0091] In various embodiments, interfaces 1520 and 1060 have the same basic function: providing the cipher K to the password verification circuit 152a. Therefore, a single interface could theoretically be used, for example, where bus 1062 corresponds to communication system 114. However, the inventors have observed that it is preferable to have two separate interfaces. In practice, as mentioned earlier, interface 1520 could be a register interface specifically adapted for interfacing with communication system 114 (particularly processing unit 102). In some embodiments, interface 1060 could be part of a debug interface IF, such as a JTAG interface. In practice, in this case, various blocks of the processing system could have associated debug interfaces, which could also be connected via debug bus 1062. Accordingly, a certain protection mechanism could be removed by providing an appropriate cipher via this debug interface (at least if the portion of debug interface 1060 associated with password verification circuit 152a is not disabled).
[0092] For example, in this way, protection circuit 150 can be configured to disable the debug interface of processing circuit 102, for example, based on lifecycle data LCD and / or configuration data CD. Specifically, the debug interface of processing unit 102 can also be connected to bus 1062. Next, a password K can be provided to the debug interface 1060 of password verification circuit 152a using external debugger 30, and password verification circuit 152a can generate a signal OW (or similarly, one or more signals OW0, OW1, etc.), which is sent to protection circuit 150 associated with the debug interface of processing circuit 102. In response to signal OW, protection circuit 150 can then reactivate the debug interface of processing circuit 102, and the developer can use external debugger 30 to analyze processing circuit 102.
[0093] Specifically, in various embodiments, the password store 156a includes multiple slots PW0, PW1, ... In this case, the password verification command VPW may include additional password configuration data CFG associated with the corresponding password K to be verified, and similarly, interfaces 1520 and / or 1060 may provide this additional password configuration data CFG. For example, interface 1060 may provide password configuration information CFGa, and interface 1520 may provide password configuration information CFGb. In the considered embodiments, the corresponding password configuration information CFGa and CFGb are then provided to multiplexer 1528, which is configured to select either the additional password configuration data CFGa or CFGb (based on whether interface 1060 or 1520 is used).
[0094] For example, the additional password configuration data CFG may include slot numbers SLOT, indicating the slots PW0, PW1, ... in the password store 156a for the reference password RK to be used for verification. Accordingly, the password store 156a can provide the corresponding reference password RK stored in the slots PW0, PW1, ... indicated by the slot numbers SLOT.
[0095] For example, Figure 8A and 8B An embodiment of the password verification command VPW is illustrated. Specifically, in the considered embodiment, interface 1520 includes a first register associated with a first address for storing configuration data CFGb and a second register associated with a second address for storing password Kb. Similarly, interface 1060 may include a first register associated with a first address for storing configuration data CFGa and a second register associated with a second address for storing password Ka.
[0096] Accordingly, in various embodiments, the configuration data CFG can be programmed by sending a first command VPW1 to interface 1520 or 1060, wherein the first command VPW1 includes a corresponding first address. For example, Figure 8A An embodiment of the data for the first command VPW1 is shown, which includes the cipher index / slot number PSW_INDEX. Accordingly, interface 1060 can receive command VPW1 and provide the corresponding data as configuration data CFGa, and interface 1520 can receive command VPW1 and provide the corresponding data as configuration data CFGb, wherein the corresponding data PSW_INDEX corresponds to slot number SLOT. For example, in the considered embodiment, each command has 32 data bits, indicated via bit numbers BN 31 to 0. For example, in the considered embodiment, the cipher index / slot number PSW_INDEX has 6 bits (e.g., bits 5 to 0 of command VPW1). In some embodiments, other bits may be reserved or associated with additional configuration data CFG. In various embodiments, the first registers of interfaces 1060 and 1520 may be writable and optionally readable, as shown via rows R (read) and W (write).
[0097] Similarly, in various embodiments, the cipher K can be programmed by sending a second command VPW2 to interface 1520 or 1060, wherein the second command VPW2 includes a corresponding second address. For example, Figure 8BAn embodiment of the data for the second command VPW2 is shown, which includes a cipher PSW. Accordingly, interface 1060 can receive command VPW2 and provide the corresponding data PSW as cipher Ka, and interface 1520 can receive command VPW2 and provide the corresponding data PSW as cipher Kb. For example, in the considered embodiment, the cipher PSW has 32 bits (e.g., bits 31 to 0 of command VPW2). In various embodiments, the second registers of interfaces 1060 and 1520 can be writable but not readable. For example, a read request to the second register can return a predetermined value, such as 0x00. In various embodiments, cipher Ka and Kb can also be stored in multiple registers, each associated with a corresponding address. For example, this allows cipher K to have at least 64 bits, such as 128 bits or 256 bits.
[0098] Accordingly, in various embodiments, the cipher K received via interface 1060 / 1520 and the (selected) reference cipher RK obtained from the cipher store 156a are provided to comparison circuit 1522, which is configured to determine whether the cipher K corresponds to the (selected) reference cipher RK. In response to determining that the cipher K corresponds to the (selected) reference cipher RK, comparison circuit 1522 generates an overwrite signal OW, which indicates that the cipher K is correct, that is, the cipher K corresponds to the (selected) reference cipher RK.
[0099] In various embodiments, the signal OW can be sent directly to one or more of the protection circuits 150, which can thus deactivate the corresponding protection. As previously mentioned, each protection circuit 150 can consider not only the signal OW, but also additional configuration information, such as the previously mentioned lifecycle data LCD and / or configuration data CD, which can be indicated by the signal OW to determine whether the protection can indeed be deactivated.
[0100] In some embodiments, a signal OW is provided to mapping circuit 1524. Specifically, in the considered embodiment, circuit 1524 is configured to generate multiple overwrite signals OW0, OW1, ... based on the signal OW and the slot number SLOT. For example, mapping circuit 1524 can be implemented using combinational logic circuitry or a lookup table configured to determine the mapping between slot number SLOT and overwrite signal OW.
[0101] For example, in various embodiments, a corresponding overwrite signal OW is associated with each slot of the password store 156a, and when passwords K and RK match, only the overwrite signal OW associated with the currently used slot SLOT is asserted (e.g., set to logic high). For example, a given slot number (e.g., slot 4) may be associated with protection circuitry 150 that controls access to the debug interface (e.g., access to debug bus 1062 by external debugger 30). Similarly, a given slot number (e.g., slot 5) may be associated with protection circuitry 150 that regulates read and / or write access to non-volatile memory 104a. Generally, a given slot number (e.g., slot 0) may also represent (e.g., written by the manufacturer of processing system 10a) the master password. Accordingly, ignoring additional lifecycle data LCD and / or configuration data CD that may also be considered, protection can be removed by providing the correct password stored in the slot associated with the corresponding protection 150.
[0102] In various embodiments, circuit 1524 may also include a register, such as a flip-flop or latch, for storing the value of the overwrite signal OW, thereby maintaining the value of the overwrite signal OW when a new password verification is requested.
[0103] Accordingly, in the considered embodiment, circuit 1524 is configured to associate each slot number with a corresponding subset of protection circuits 150. Furthermore, when a received cipher K corresponds to a reference cipher RK for a given slot SLOT, circuit 1524 generates one or more signals OW to notify the subset of protection circuits 150 associated with the given slot SLOT of the cipher match.
[0104] Such as about Figure 5 As described above, when using the temporary password storage 156a, the processing system 10a also includes a password upload circuit. For example, Figure 9 An embodiment of a processing system 10a including configuration circuitry 108 is shown.
[0105] Specifically, in the considered embodiment, non-volatile memory 104a is configured to store configuration data CD. For example, such configuration data CD may include calibration data to ensure consistent hardware behavior, thereby compensating for possible manufacturing process tolerances. This is typically used for calibrating analog components of processing system 10a, such as temperature sensors, analog-to-digital converters, voltage references, etc. Moreover, as mentioned earlier, the configuration data CD can also be used to customize the behavior of hardware (e.g., circuit 160 and / or protection circuit 150) according to different application requirements. For example, as mentioned earlier, once the firmware of processing system 10a has been stored in processing system 10a, some configuration data CD can be written to disable, for example, a debug interface that can be used to download the firmware of processing system 10a.
[0106] In various embodiments, configuration circuitry 108 is configured to read configuration data CDs during a configuration phase that typically begins immediately after power-on of processing system 10a. Specifically, in the considered embodiments, configuration circuitry 108 is configured to read configuration data CDs from non-volatile memory 104a and distribute these configuration data CDs within processing system 10a. For example, in the considered embodiments, the configuration data CDs are stored, for instance, in a reserved memory region of memory 104a in the form of multiple contiguous memory locations. Accordingly, in the considered embodiments, configuration circuitry 108 accesses the reserved memory region containing the configuration data CDs, (e.g., sequentially) reads the configuration data CDs, and transfers the configuration data CDs to corresponding circuitry 160 and / or protection circuitry 150 within processing system 10. As mentioned earlier, circuitry 160 may correspond to any circuitry of processing system 10 that requires configuration data and may correspond, for example, to processing unit 102, peripheral device 106, or memory controller 100.
[0107] For example, each circuit 160 and each protection circuit 150 may be associated with a corresponding configuration data client circuit 112. For example, Figure 9 Two configuration data client circuits 112a and 112b are shown, which provide configuration data to circuit 160 and protection circuit 150, respectively. Generally, each configuration data client circuit 112 can be associated with a single circuit 160 or a single protection circuit 150, and provides configuration data only to the associated circuit 160 or protection circuit 150 (e.g., a specific peripheral device 106). However, configuration data client circuits 112 can also be associated with multiple circuits 160 and / or protection circuits 150. For example, the same configuration data client circuit 112 can be used to provide configuration data CD to circuit 160 and the protection circuit 150 associated with that circuit 160. Generally, configuration data client circuits 112 can also be integrated within the respective circuit 160 or protection circuit 150.
[0108] Accordingly, in various embodiments, configuration circuit 108 may determine corresponding configuration data (selected from configuration data CD) for each target circuit 160 / 150 to be configured, and transmit the configuration data associated with the target circuit 160 / 150 to the corresponding configuration data client circuit 112 associated with the target circuit 160 / 150. Alternatively, while reading the configuration data CD from memory 104a (e.g., sequentially), configuration circuit 108 may determine one or more target circuits of current configuration information and send the current configuration data to one or more configuration data client circuits associated with the corresponding target circuits. Accordingly, each configuration data client circuit 112 is configured to receive configuration data from configuration circuit 108, store it in an internal register, for example, in one or more internal triggers or latches. The data stored in the registers can then be used to generate one or more signals that affect the behavior of one or more circuits 160 and / or protection circuits 150.
[0109] Generally, any communication method can be used to transfer configuration data CD to configuration data client 112, including both serial and parallel communication. For example, configuration circuit 108 and configuration data client circuit 112 can be connected via communication system 114 or an additional bus.
[0110] For example, in Figure 9 In the configuration circuit 108, there are a data reading circuit 1080 configured to read configuration data CD from memory 104a and a scheduling circuit 1082 configured to transmit configuration data CD to configuration data client circuit 112, for example, via communication system 114 or a dedicated communication system.
[0111] Specifically, in various embodiments, the configuration data CD is stored in the form of data frames according to a given format referred to as Device Configuration Format (DCF). For example, each data frame may include two fields: a payload (i.e., the actual data), referred to as the DCF payload; and possible additional data attributes for identifying the recipient of the data, referred to as DCF attributes, where the recipient is one of the configuration data client circuits 112 representing the DCF client. For example, the data attributes may consist of 16 bits or 32 bits, where a given number of bits specifies the address of one of the configuration data clients 112, and the payload may consist of 16 bits or 32 bits. For example, the data read circuit 1080 may be configured to read a 64-bit block from memory 104a, where the first 32 bits contain the data attributes (including the address of the configuration data client), and the last 32 bits contain the configuration data to be transmitted to the address specified in the data attributes.
[0112] Accordingly, in various embodiments, scheduling circuit 1082 is configured to generate a data signal DATA containing a given number of bits (corresponding to the payload bits) of configuration data to be transmitted to a given configuration data client 112, and additional control signals for selecting the target configuration data client 112. For example, in the considered example, scheduling circuit 1082 also generates an address signal ADR containing the address of the target configuration data client circuit 112, and optionally generates a chip select signal CS for signaling that the address signal ADR and the data signal DATA are valid. For example, the address signal ADR (and the chip select signal CS) can be provided to decoder 124, which is configured to activate one of the configuration data client circuits 112 according to the address signal ADR, for example by generating corresponding signals CSa, CSb, and CSc. As mentioned above, scheduling circuit 1082 and various configuration data client circuits 112 can be connected via communication system 114 or a dedicated bus.
[0113] In various embodiments, configuration circuit 108 also includes state control circuitry 1084 configured to manage various configuration phases of processing system 10a. For example, once processing system 10a is powered on, reset module 116 of processing system 10a can generate a reset signal RESET to perform a reset on various components of processing system 10a. For example, the reset signal RESET can correspond to a reset pulse of a given number of clock cycles provided to circuitry 160 of processing system 10a. Similarly, configuration data client circuitry 112 can use the reset signal RESET to set internal registers to a given reset value. Next, in response to the reset, state control circuitry 1084 can activate the configuration phase. Specifically, during the configuration phase, data read circuitry 1080 can read configuration data CD from memory 104a, and scheduling circuitry 1082 can send configuration data CD to various configuration data client circuits 112 to overwrite the reset value.
[0114] Accordingly, in various embodiments, configuration circuitry 108 may also be configured to transmit reference passwords RK to temporary password store 156. For example, in various embodiments, one or more configuration data client circuits 112c are associated with temporary password store 156a (preferably associated with only one). Accordingly, in various embodiments, configuration circuitry 108 is configured to also read reference password(s)RK(s) from memory 104a and send reference password(s)RK(s) to configuration data client 112c associated with temporary password store 156, thereby loading reference password(s)RK(s)(s) into temporary password store 156.
[0115] For example, in the considered embodiments, the temporary password store 156 includes multiple slots PW0, PW1, ..., each slot arranged to store a corresponding reference password RK. In various embodiments, a single configuration data client circuit 112c is associated with the temporary password store 156a. In this case, multiple reference passwords RK can be sent sequentially to the address of the configured data client 112c, and once a reference password RK is received, the temporary password store 156 can store the received reference password into the next slot of internal memory. Alternatively, since in some embodiments, the configuration data client 112 includes internal registers, these registers can also be used directly as memory for the temporary password store 156a. For example, in this case, multiple configuration data client circuits 112c can be associated with the temporary password store 156a, where each configuration data client 112c has a corresponding (single) address. In this case, multiple reference passwords RK can be sent sequentially to the address of the configured data client 112c.
[0116] In various embodiments, one or more reference ciphers RK are stored in memory 104a together with configuration data CD in the form of DCF data frames. These DCF data frames have an address associated with the configuration data client circuit 112c of the temporary cipher store 156 and carry the corresponding reference cipher(s) RK as a payload. In effect, configuration circuit 108 automatically transmits one or more reference ciphers RK to configuration data client circuit(s) 112c, and thus to the temporary cipher store 156a.
[0117] However, the inventors have observed that this can be disadvantageous when a given reference password RK needs to be updated. Accordingly, in various embodiments, one or more reference passwords RK are stored in a dedicated memory location of memory 104a, and configuration circuitry 108 can be configured to transfer one or more reference passwords RK from the dedicated memory location to one or more configuration data client circuits 112c associated with temporary password store 156.
[0118] Figure 10An embodiment of data stored in non-volatile memory 104a is illustrated. Specifically, in the considered embodiment, memory 104a includes memory regions for storing cryptographic data PWD, such as memory slots for storing master password MPW, and multiple memory slots for storing strong security passwords (such as passwords SPW0, SPW1, etc.). For example, in various embodiments, memory 104a may include a number N of memory slots for storing cryptographic data PWD, wherein the number N can be selected, for example, between 6 and 32. Specifically, in the considered embodiment, the master password MPW and the security password SPW are stored in predetermined memory locations, i.e., the memory slot for the master password MPW has address A1, the memory slot for the security password SPW0 has address A2, the memory slot for the security password SPW1 has address A3, and so on.
[0119] Furthermore, in the considered embodiments, the non-volatile memory 104a includes a memory region for storing configuration data CD. For example, the configuration data may begin at a predetermined address ACD. In various embodiments, address ACD is fixed. In some embodiments, the address of the password data PWD may be fixed or programmable. For example, the configuration data CD may be used to configure the starting address of the password data PWD, such as address A1. For example, in this case, the configuration circuit 108 itself may be associated with a configuration data client circuit 112 configured to provide the starting address of the password data PWD. For example, in this case, a DCF frame may be stored in the configuration data CD, wherein the DCF frame includes the address of the configuration data client circuit 112 associated with the configuration circuit 108, and includes the starting address of the password data PWD as a payload.
[0120] As mentioned earlier, the password storage 156a can directly correspond to the password data PWD stored in the memory 104a. That is, the password verification circuit 152a can access the password data PWD in the memory 104a to read a given password according to the slot data SLOT; or, the processing system 10a (e.g., the configuration circuit 108 or another type of password upload circuit) can transmit the password data PWD to the temporary password storage 156a. For example, the master password MPW can correspond to or be transmitted to the password slot PW0, the security password SPW0 can correspond to or be transmitted to the password slot PW1, and so on.
[0121] Specifically, in various embodiments, the processing system 10a may include protection circuitry 150a configured to restrict read and write access to memory 104a (and particularly (at least) memory region PWD) via circuitry different from that of password verification circuitry 152a (when directly used as password store 156a) or configuration circuitry 108 (when transferred to password store 156a). For example, in various embodiments, protection circuitry 150a is configured to disable read and write access based on lifetime data LCD and / or configuration data CD. For example, in various embodiments, the chip manufacturer writes the master password MPW, and optionally one or more security passwords SPW. The chip manufacturer can then advance the lifetime data LCD to the next stage, such as stage LC1. For example, protection circuitry 150a may be configured to automatically disable read and write access once the lifetime stage differs from lifetime stage LC0.
[0122] Accordingly, in this case, the master password MPW can be used to enable write access to the password data PWD. That is, the password management circuit can be configured to receive password verification commands VPW (e.g., the aforementioned commands VPW1 and VPW2), select the password slot for the master password, and provide the password K corresponding to the master password MPW. In response to determining that the password K corresponds to the master password MPW, the password verification circuit 152a can assert an overwrite signal OWA, which is provided to the protection circuit 150a. Specifically, the protection circuit 150a can be configured to disable write protection in response to the overwrite signal OWA, and optionally disable read protection.
[0123] Accordingly, in this manner, processing circuitry 102 or interface IF can be used to provide a master password (MPW) to enable write access to the password data PWD. Next, processing circuitry 102 or interface IF can be used to update one or more of the password data PWD, such as the master password (MPW) or security passwords (SPW). Accordingly, in various embodiments, each security password (SWP) can be associated with a given protection circuitry 150 or a subset of protection circuitry 150, while the master password can be used to (at least) disable write access to the password data PWD.
[0124] However, when processing system 10a is to be analyzed by different entities (such as chip manufacturers, engine control unit manufacturers, and automobile manufacturers), these entities must know the cryptographic data. This can be particularly complex when large software development teams are involved and the passwords should be updatable.
[0125] Therefore, the modified embodiment will be described below, wherein the processing system 10a is configured to use multiple master passwords. Specifically, Figure 11An embodiment of cryptographic data PWD suitable for storage in non-volatile memory 104a is shown.
[0126] In the considered embodiments, memory 104a again includes a (first) memory region configured to store cryptographic data PWD and a (second) memory region configured to store configuration data CD. Specifically, in the considered embodiments, the cryptographic data PWD includes a plurality of memory slots arranged to store a plurality of master passwords MPW and a plurality of memory slots arranged to store a plurality of security passwords SPW. For example, in various embodiments, the cryptographic data PWD includes a first memory slot arranged to store a first master password MPW0 and a second memory slot arranged to store a second master password MPW1. In various embodiments, the cryptographic data PWD includes one or more additional memory slots arranged to store one or more additional master passwords (such as a third master password MPW2).
[0127] For example, the slot allocated to the master password (MPW) may begin at memory address AMPW, the slot allocated to the security password (SPW) may begin at memory address ASPW, and the configuration data (CD) may begin at memory address ACD. In various embodiments, addresses ACD, AMPW, and ASPW are fixed, for example, hardwired. However, addresses AMPW and / or ASPW may also be programmable, for example, based on configuration data ACD. In various embodiments, the memory slot for the security password (SPW) is located directly after the memory slot for the master password (MPW).
[0128] Accordingly, such as Figure 12 As shown, in various embodiments, the processing system 10a includes configuration circuitry 108 configured to read configuration data CD from non-volatile memory 104a and transmit the configuration data CD to one or more circuits 160, such as processing circuitry 102, memory controller 100, peripheral device 106, etc. In various embodiments, configuration circuitry 108 may also provide lifetime data LCD. For example, configuration circuitry 108 may be configured to read lifetime data LCD from memory 104a or another non-volatile memory (such as one-time programmable memory).
[0129] In various embodiments, the processing system 10a also includes protection circuitry 150a configured to control (write and optional read) access to the non-volatile memory 104a, as shown via command CMD. The processing system 10a may also include additional protection circuitry 150, for example, for one or more circuits in circuitry 160.
[0130] In various embodiments, the processing system 10a further includes a password verification circuit 152a configured to provide one or more overwrite signals to the protection circuit 150a. Specifically, in various embodiments, the password verification circuit 152a provides multiple signals OWM indicating whether a correct master password has been provided, and the index of the provided master password. For example, in Figure 12 In this circuit, the password verification circuit 152a provides a corresponding overwrite signal for each master password MPW, such as overwrite signals OWM0, OWM1, and OWM2 for master passwords MPW0, MPW1, and MPW2 respectively. The password verification circuit 152a is configured to assert a given overwrite signal in response to detecting that a corresponding correct master password MPW has been provided via a password verification command VPW. For example, when the verification of master password MPW0 is successful, i.e., when the password verification command VPW indicates the slot number of master password MPW0, for example via data PSW_INDEX, and provides the password K corresponding to master password MPW0, for example via data PSW, the password verification circuit 152a asserts signal OWM0. Similarly, in response to the successful verification of master password MPW1, signal OWM1 can be asserted. However, other signals can also be used to indicate that a successful verification of a given master password has been performed, such as a signal indicating that a successful verification of a master password has been performed and a signal indicating which master password has been verified (such as the slot number SLOT of the password verification command VPW).
[0131] Accordingly, in various embodiments, protection circuit 150a is configured to control write and possible read access to non-volatile memory 104a based on overwrite signals OWM (such as signals OWM0, OWM1, and OWM2) provided by configuration data CD, lifecycle data LCD, and / or password verification circuit 152a. Embodiments of the operation of protection circuit 150a will be described below.
[0132] As mentioned earlier, in order to execute the password verification command VPW, the password verification circuit 152a can be configured to access the password data PWD. As previously stated, the password storage library 156a can directly correspond to the password data PWD stored in the non-volatile memory 104a; that is, the password verification circuit 152a can be configured to access the non-volatile memory 104a, for example, by using the slot number SLOT and the addresses AMPW and / or ASPW, in order to read the reference password RK for a given password verification operation.
[0133] Alternatively, the password data PWD can be transferred to a temporary password store 156a. For example, the master password MPW0 can be associated with password slot PW0, the master password MPW1 with password slot PW1, the master password MPW2 with password slot PW2, the security password SPW0 with password slot PW3, the security password SPW1 with password slot PW4, and so on. For example, in various embodiments, the temporary password store 156a includes a number of slots corresponding to the number of memory slots containing the password data PWD, wherein the processing system 10a is configured to transfer the contents of each memory slot of the password data PWD to the corresponding slot in the temporary password store 156a. In various embodiments, the processing system 10a can be configured to transfer only the memory slots containing the password data PWD, including the programmed password. For example, in Figure 12 In this configuration, the configuration circuit 108 or another password upload circuit is configured to transfer password data PWD from non-volatile memory 104a to temporary password storage 156a, and the password verification circuit 152a is configured to access the temporary password storage 156a, for example, by using slot number SLOT, in order to read the reference password RK for password verification operations.
[0134] In various embodiments, the password verification circuit 152a and / or protection circuit 150a may also be configured to receive configuration data CD from the configuration circuit 108. For example, in various embodiments, the password verification circuit 152a and / or protection circuit 150a include one or more corresponding configuration data client circuits 112 connected to the configuration circuit 108. For possible embodiments of the communication system between the configuration circuit 108, the configuration data client circuits 112, and the system therebetween, see [reference needed]. Figure 9 The description.
[0135] Specifically, in various embodiments, each master password (MPW) is associated with a given user or user group (such as a chip manufacturer, engine control unit manufacturer, and automobile manufacturer). Specifically, in various embodiments, a first master password (MPW0) is associated with the manufacturer of the processing system 10a (e.g., a chip manufacturer), and a second master password (MPW1) is associated with a software developer (such as an engine control unit developer). One or more additional master passwords may be associated with other software developers; for example, a third master password (MPW2) may be associated with an automobile manufacturer.
[0136] Accordingly, once the processing system 10a is manufactured, the non-volatile memory 104a is empty, that is, the password data PWD and configuration data CD are not programmed. Moreover, the lifecycle data LCD corresponds to the unprogrammed value indicating the first lifecycle stage LC0 (such as the production stage).
[0137] Next, the manufacturer of processing system 10a (such as a chip manufacturer) can program the first master password MPW0 by accessing non-volatile memory 104a. For example, in various embodiments, protection circuitry 150a can be configured to disable write protection of memory 104a (particularly the memory area used to store password data PWD) when the lifecycle data LCD corresponds to stage LC0.
[0138] In various embodiments, the manufacturer of the processing system 10a may also program it to be arranged in one or more memory locations for storing security passwords (SPWs) and / or one or more configuration data CDs. As mentioned earlier, in various embodiments, each security password (SPW) may be associated with a given protection.
[0139] Specifically, such as Figure 12 As shown, in various embodiments, protection circuitry 150a includes one or more registers 1502 configured to store security password access data SPW_CTR, wherein protection circuitry 150a is configured to receive configuration data CD from configuration circuitry 108 and selectively store the received configuration data into one or more registers 1502. For example, when using DCF frames, the corresponding DCF frame of the configuration data CD stored in non-volatile memory 104a may include an address associated with one or more registers 1502. Specifically, in various embodiments, the security password access data SPW_CTR indicates a corresponding index of the master password MPW required to access the corresponding memory slot for each memory slot arranged to store the security password SPW.
[0140] For example, Figure 13 An embodiment of the security password access data SPW_CTR is illustrated. Specifically, in the considered embodiment, field SI is associated with each memory slot arranged to store the security password SPW; for example, field SI0 is associated with the memory slot arranged to store security password SPW0, field SI1 is associated with the memory slot arranged to store security password SPW1, and so on. For example, in the considered embodiment, each field SI has two bits, but more bits may also be used.
[0141] In various embodiments, a single register 1502 is used to store the security password access data SPW_CTR, for example, 16 fields SI0 to SI15 for the corresponding 16 security passwords SPW. However, multiple registers 1502 may also be used to store the security password access data SPW_CTR for more security passwords SPW and / or fields SI with more bits.
[0142] Accordingly, such as Figure 11As shown, in various embodiments, the manufacturer of processing system 10a may store frames of configuration data to a configuration data CD, wherein the frames of configuration data include addresses associated with one or more registers 1502 as addresses, and corresponding security password access data SPW_CTR0 as payloads. Accordingly, in various embodiments, when processing system 10a is powered on, configuration circuit 108 sequentially reads the configuration data CD and transmits the configuration data CD to the corresponding circuit, thereby transmitting the security password access data SPW_CTR0 to protection circuit 150a.
[0143] Similarly, software developers (such as engine control unit manufacturers) can program a second master password MPW1 by accessing non-volatile memory 104a. In various embodiments, the developed software can also be programmed to store one or more memory locations arranged to store a security password SPW and / or one or more configuration data CDs. Specifically, in various embodiments, the software developer can store frames of configuration data to the configuration data CD, wherein the frames of configuration data include an address associated with one or more registers 1502 as an address, and a payload including the corresponding security password access data SPW_CTR1. Accordingly, in the considered embodiment, when the processing system 10a is powered on, the configuration circuit 108 sequentially reads the configuration data CD and transmits it to the corresponding circuit, thereby transmitting the security password access data SPW_CTR1 to the protection circuit 150a.
[0144] Similarly, when supported, additional software developers (such as automakers) can program a third master password MPW2 by accessing non-volatile memory 104a. In various embodiments, additional software can also be developed and programmed to be arranged to store a security password SPW and / or one or more configuration data CDs in one or more memory locations. Specifically, in various embodiments, the additional software developer can store frames of configuration data to the configuration data CD, wherein the frames of configuration data include addresses associated with one or more registers 1502 as addresses, and the corresponding security password access data SPW_CTR2 as payloads. Accordingly, in the considered embodiments, when processing system 10a is powered on, configuration circuitry 108 sequentially reads the configuration data CD and transmits the configuration data CD to the corresponding circuitry, thereby transmitting the security password access data SPW_CTR2 to protection circuitry 150a.
[0145] Accordingly, in various embodiments, the protection circuit 150a (e.g., the corresponding configuration data client circuit 112) can receive one or more of the security password access data SPW_CTR0, SPW_CTR1, and SPW_CTR2. However, in various embodiments, the slots of the assigned security password SPW are not reallocated.
[0146] Therefore, in various embodiments, in response to receiving secure password access data, protection circuit 150a (e.g., the corresponding configuration data client circuit 112) is configured to compare the value of each field SI of the secure password access data SPW_CTR stored in register 1502 with a predetermined value indicating an unprogrammed field SI. In response to determining that the value of a given field SI of the secure password access data SPW_CTR has a predetermined value, protection circuit 150a updates that field SI using the corresponding bit of the received secure password access data. Accordingly, in this way, a first value different from the predetermined value is stored in the given field SI of the secure password access data SPW_CTR. For example, in various embodiments, the following bit sequence can be used for each field SI:
[0147] The first value, such as "11", indicates that the corresponding field SI has not been programmed;
[0148] The second value, such as "00", indicates that the security password SPW associated with the corresponding field SI is assigned to the master password MPW0;
[0149] The third value, such as "01", indicates that the security password SPW associated with the corresponding field SI is assigned to the master password MPW1; and
[0150] The fourth value, such as "10", indicates that the security password SPW associated with the corresponding field SI is assigned to the master password MPW2 (when supported).
[0151] Accordingly, in this case, the bits of each field SI of register(s)(one or more) will initially (e.g., in response to a reset) have a value set to a predetermined / unprogrammed value (such as "11"). Next, in response to receiving security password access data from configuration circuitry 108, protection circuitry 150a overwrites the bit values of the given field SI, which are still set to the predetermined / unprogrammed values. Accordingly, in various embodiments, protection circuitry 150a implements write protection for each field SI, i.e., once a given slot of the security password SPW is assigned to a given master password MPW, the corresponding programming cannot be changed by appending frames of additional configuration data to the configuration data CD.
[0152] Accordingly, by using configuration data CD, each memory slot for the security password SPW can be assigned a given master password (or can remain unassigned). Specifically, in various embodiments, when the assigned master password is provided, protection circuit 150a uses this information to enable write access to a given memory slot arranged to store the security password SPW.
[0153] For example, Figure 14 An embodiment of the protection circuit 150a is shown. Specifically, Figure 14 Only a portion of the circuitry managing access to a given memory slot i of non-volatile memory, arranged to store the corresponding security password SPWi, is shown. Accordingly, Figure 14 The circuit shown can actually be repeated for each memory slot arranged to store the security cipher SPW.
[0154] Specifically, as mentioned earlier, protection circuit 150a is configured to manage write and optional read access to memory slot i, which is arranged to store the corresponding security password SPWi, as schematically shown via electronic switch 1504. For example, protection circuit 150a can enable access to memory slot i when enable signal EN is asserted, and can disable access to memory slot i when enable signal EN is deasserted.
[0155] For example, consistent with the foregoing, the enable signal EN can be generated based on lifecycle data LCD and / or configuration data CD. For example, in the considered embodiment, protection circuit 150a includes protection control circuit 1506, implemented using combinational logic, configured to enable or disable access to memory slot i based on lifecycle data LCD and optional configuration data CD, for example via the enable signal EN. In various embodiments, protection control circuit 1506 is configured to also enable or disable access to memory slot i based on overwrite signals OWM (e.g., signals OWM0, OWM1, and OWM3) received from password verification circuit 152a and security password control data SPW_CTR provided by register 1502, for example via the enable signal EN.
[0156] For example, in various embodiments, the processing system 10a is configured to support the following sequence of lifecycle stages, each stage having associated corresponding lifecycle data LCD:
[0157] The “production” stage LC0, for example, when the processing system 10a is in the chip architecture;
[0158] The “software development” phase LC1, for example, when the processing system 10a has been shipped to a first-tier customer (e.g., the manufacturer of the engine control unit);
[0159] The “Field” phase LC3, for example, when the equipment is installed in the final product (e.g., in a car sold on the market);
[0160] The “fault analysis” phase LC4, for example, when the equipment is shipped back to the manufacturer or software developer of the processing system 10a for diagnostic purposes.
[0161] In this configuration, processing system 10a may support two master cryptography, MPW0 and MPW1. In various embodiments, processing system 10a is configured to support one or more “additional software development” phases LC2 between phases LC1 and LC3, each phase having associated corresponding lifecycle data LCD. For example, phase LC2 may be activated before equipment manufactured by a first-tier customer is shipped to a next-tier customer (e.g., an automotive manufacturer). In this configuration, processing system 10a may also support one or more additional master cryptography, such as master cryptography MPW2.
[0162] For example, in various embodiments, in response to the determination of the lifecycle data LCD indicating the "production" phase LC0, the protection control circuit 1506 is configured to enable write and optional read access to all security passwords SPW, i.e., enable access to each memory slot i. As mentioned earlier, during the production lifecycle phase LC0, the manufacturer of processing system 10a can program the master password MPW0. Moreover, the manufacturer of processing system 10a can program one or more security passwords SPW and store data SPW_CFG0 to configuration data CD so as to assign one or more security passwords SPW to the master password MPW0, or possibly another master password MPW, for example, by setting a bit of the corresponding field SI of data SPW_CFG0 to a second value (e.g., "00").
[0163] In various embodiments, in response to determining the lifecycle data indicating the "software development" phase LC1, the protection control circuit 1506 is configured to enable write and optional read access to a given memory slot i when the given memory slot i has not yet been assigned to the master password MPW, for example, when the bit of the corresponding field SIi of the security password configuration data SPW_CFG stored in register 1502 has a first value (e.g., "11").
[0164] Furthermore, in various embodiments, the protection control circuit 1506 is configured to enable write and optional read access to a given memory slot i when it is associated with the master password MPW1, for example, in response to determining that a bit of the corresponding field SIi has a third value (e.g., "01"). Accordingly, in various embodiments, access to the security password SPW associated with the master password MPW1 is enabled during the software development lifecycle phase LC1.
[0165] Accordingly, in the considered embodiments, when memory slot i is associated with master password MPW0, access to a given memory slot i is prohibited, for example, in response to determining that a bit of the corresponding field SIi has a second value (e.g., "00"). In various embodiments, protection control circuitry 1506 can therefore be configured to enable write and optional read access to memory slot i associated with master password MPW0 when a signal received from password verification circuitry 152a indicates successful password verification of master password MPW0, for example, in response to determination signal OWM0 being asserted.
[0166] In various embodiments, in response to determining that lifecycle data indicates an “additional software development” phase LC2 (when supported), protection control circuitry 1506 is configured to enable write and optional read access to a given memory slot i when the given memory slot i has not yet been assigned to the master password MPW, for example, when the bit of the corresponding field SIi of the security password configuration data SPW_CFG stored in register 1502 has a first value (e.g., “11”).
[0167] Furthermore, in various embodiments, the protection control circuit 1506 is configured to enable write and optional read access to a given memory slot i when it is associated with the master password MPW2, for example, in response to determining that a bit of the corresponding field SIi has a fourth value (e.g., "10"). Accordingly, in various embodiments, access to the security password SPW associated with the master password MPW2 is enabled during an additional software development lifecycle phase LC2.
[0168] In various embodiments, when memory slot i is associated with master password MPW0 or MPW1, for example, access to a given memory slot i is prohibited in response to determining that a bit of the corresponding field SIi has a second value (e.g., "00") or a third value (e.g., "01"). In various embodiments, protection control circuit 1506 can therefore be configured to enable write and optional read access to memory slot i associated with master password MPW0 when a signal received from password verification circuit 152a indicates successful password verification of master password MPW0, for example, in response to a determination signal OWM0 being asserted. Similarly, protection control circuit 1506 can be configured to enable write and optional read access to memory slot i associated with master password MPW1 when a signal received from password verification circuit 152a indicates successful password verification of master password MPW1, for example, in response to a determination signal OWM1 being asserted.
[0169] In various embodiments, in response to determining that the lifecycle data indicates the "field" phase LC3, the protection control circuit 1506 is configured to disable write and read access to a given memory slot i. In various embodiments, the protection control circuit 1506 is configured to enable write and optional read access to the memory slot i associated with a given master password i when a signal received from the password verification circuit 152a indicates successful password verification of the corresponding master password, for example, in response to determining that for memory slot i associated with master password MPW0, the signal OWM0 is asserted. Accordingly, in various embodiments, the security password associated with a given master password MPW can only be refreshed (reprogrammed) after a successful challenge to the corresponding master password MPW, wherein the chip manufacturer knows master password MPW0, the first-level software developer knows master password MPW1, and the OEM production customer knows master password MPW2.
[0170] Accordingly, in various embodiments, the protection control circuit 1506 can be configured to disable access to memory slot i by default and selectively enable access to memory slot i based on the lifecycle data LCD, the field SIi of the security password configuration data SPW_CFG associated with memory slot i, and the overwrite signal OWM provided by the password verification circuit 152a.
[0171] For example, in various embodiments, in response to determining that the lifecycle data LCD indicates the production lifecycle stage LC0, the protection control circuit 1506 is configured to enable access to the memory slot i, for example, by asserting the enable signal EN.
[0172] In various embodiments, in response to determining the lifecycle data LCD indicating the software development lifecycle stage LC1, the protection control circuit 1506 is configured to:
[0173] In response to the determination that the memory slot i is not allocated, for example, in response to the determination that the memory slot i has a first value, such as "11", access to the memory slot i is enabled;
[0174] In response to the determination that the memory slot i is assigned to the master password MPW0 by the field SIi, for example, in response to the determination that the field SIi has a second value, such as "00", it is determined whether the overwrite signal OWM indicates that a successful password verification of the master password MPW0 has been performed, for example, by determining whether the overwrite signal OWM0 is asserted, and in response to the determination that the overwrite signal OWM indicates that a successful password verification of the master password MPW0 has been performed, access to the memory slot i is enabled; and
[0175] In response to the determination field SIi indicating that memory slot i is assigned to master password MPW1, for example, in response to the determination field SIi having a third value, such as "01", access to memory slot i is enabled.
[0176] In various embodiments, in response to determining that the lifecycle data LCD indicates an additional software development lifecycle stage LC2 (when supported), the protection control circuit 1506 is configured to:
[0177] In response to the determination that the memory slot i is not allocated, for example, in response to the determination that the memory slot i has a first value, such as "11", access to the memory slot i is enabled;
[0178] In response to the determination that the SIi field indicates that memory slot i is assigned to master password MPW0 or MPW1, for example, in response to the determination that the SIi field has a second value, such as "00" or a third value, such as "01", determine whether the overwrite signal OWM indicates that a successful password verification of the corresponding master password MPW0 or MPW1 has been performed, and in response to the determination that the overwrite signal OWM indicates that a successful password verification of the corresponding master password MPW0 or MPW1 has been performed, enable access to memory slot i; and
[0179] In response to the determination field SIi indicating that memory slot i is assigned to the master password MPW2, for example, in response to the determination field SIi having a fourth value, such as "10", access to memory slot i is enabled.
[0180] In various embodiments, in response to determining that the lifecycle data LCD indicates the field stage LC3, the protection control circuit 1506 is configured to: in response to determining that the field SIi indicates that the memory slot i is assigned to the master password MPW0, MPW1 or MPW2, determine whether the overwrite signal OWM indicates that a successful password verification of the corresponding master password MPW0, MPW1 or MPW2 has been performed, and in response to determining that the overwrite signal OWM indicates that a successful password verification of the corresponding master password MPW0, MPW1 or MPW2 has been performed, enable access to the memory slot i.
[0181] In various embodiments, in response to the determination of the lifecycle data LCD indicating fault analysis phase LC4, the protection control circuit 1506 is configured to maintain disabled access to memory slot i. In fact, no password refresh is typically required during the fault analysis phase LC4.
[0182] Figure 15 An embodiment of a portion of the circuitry managing access to a given memory slot i of non-volatile memory 104a, arranged to store a corresponding master password MPWi (e.g., master password MPW0, MPW1, or MPW2). Accordingly, Figure 15 The circuit shown can be repeated for each memory slot arranged to store the master password MPW.
[0183] Specifically, as mentioned earlier, protection circuit 150a is configured to manage write and optional read access to memory slot i, which is arranged to store the corresponding master password MPWi, as schematically shown again via electronic switch 1504. For example, when the enable signal EN is asserted, protection circuit 150a can enable access to memory slot i; and when the enable signal EN is deasserted, protection circuit 150a can disable access to memory slot i.
[0184] In the considered embodiment, protection circuit 150a includes protection control circuit 1508, which, for example, is implemented using combinational logic circuitry and configured to enable or disable access to memory slot i based on lifetime data LCD and optional configuration data CD, for example via an enable signal EN. In various embodiments, various protection control circuits 1506 and 1508 may also be combined and, for example, implemented using one or more combinational logic circuits.
[0185] For example, in various embodiments, in response to determining that the lifecycle data LCD indicates production lifecycle stage LC0, the protection control circuit 1508 is configured to enable access to memory slot i, for example, by asserting the enable signal EN. Accordingly, in various embodiments, all master passwords MPW can be written during stage LC1.
[0186] In various embodiments, in response to determining the lifecycle data LCD indicating the software development lifecycle stage LC2, the protection control circuit 1506 is configured to:
[0187] In response to determining that memory slot i is arranged to store master password MPW0, determine whether the overwrite signal OWM indicates that a successful password verification of master password MPW0 has been performed, for example by determining whether the overwrite signal OWM0 is asserted, and in response to determining that the overwrite signal OWM indicates that a successful password verification of master password MPW0 has been performed, enable access to memory slot i.
[0188] In response to determining that memory slot i is configured to store the master password MPW1, access to memory slot i is enabled.
[0189] In various embodiments, in response to determining that the lifecycle data LCD indicates an additional software development lifecycle stage LC2 (when supported), the protection control circuit 1506 is configured to:
[0190] In response to determining that memory slot i is configured to store master password MPW0 or MPW1, it is determined whether the overwrite signal OWM indicates that a successful password verification of the corresponding master password MPW0 or MPW1 has been performed, for example, by determining whether the corresponding overwrite signal OWM0 or OWM1 has been asserted, and in response to determining that the overwrite signal OWM indicates that a successful password verification of the corresponding master password MPW0 or MPW1 has been performed, access to memory slot i is enabled; and
[0191] In response to determining that memory slot i is configured to store the master password MPW2, access to memory slot i is enabled.
[0192] In various embodiments, in response to determining that the lifecycle data LCD indicates the field stage LC3, the protection control circuit 1508 is configured to determine whether the overwrite signal OWM indicates that a successful password verification of the corresponding master password MPW0, MPW1, or MPW2 has been performed, and in response to determining that the overwrite signal OWM indicates that a successful password verification of the corresponding master password MPW0, MPW1, or MPW2 has been performed, access to memory slot i is enabled, that is, access to the memory slot arranged to store the master password MPW0 is enabled for master password MPW0, access to the memory slot arranged to store the master password MPW1 is enabled for master password MPW1, and so on.
[0193] In various embodiments, in response to the determination of the lifecycle data LCD indicating the fault analysis phase LC5, the protection control circuit 1508 is configured to maintain access to memory slot i disabled.
[0194] Accordingly, in various embodiments, during the development lifecycle phases (LC0, LC1, and optionally LC2), each user can write a corresponding master password, for example, MPW0 for LC0, MPW1 for LC1, and MPW2 for LC2. Furthermore, each user can write an unassigned security password SPW and a security password SPW associated with the corresponding master password MPW via the data SPW_CTR.
[0195] As mentioned earlier, in various embodiments, the user can also write a master password (MPW) associated with the user in a subsequent development lifecycle phase (e.g., a user in phase LC0 can write the master password MPW1 for user phase LC1). Furthermore, the user can also write one or more security passwords (SPWs) and associate the security passwords (SPWs) with the master passwords (MPWs) of the user in a subsequent development lifecycle phase via the data SPW_CTR.
[0196] In various embodiments, when a user wants to write the master password MPW associated with the user of the previous development lifecycle phase (e.g., a user in phase LC1 wants to write the master password MPW0 of user phase LC0) and the corresponding security password SPW associated with the master password MPW of the user of the previous development lifecycle phase, a password challenge for the corresponding master password is required.
[0197] In various embodiments, the field lifecycle phase LC3 always requires a successful password challenge to the master password (MPW) in order to write the MPW or its associated security password (SPW). Accordingly, in this case, each developer user can only update the corresponding master password (MPW) and the corresponding security password (SPW).
[0198] In various embodiments, the fault analysis lifecycle phase LC4 does not allow access to the password data PWD.
[0199] Figure 16 Another embodiment of the password verification command VPW is shown. Specifically, in the considered embodiment, at least when specifying the slot number associated with the master password MPW via, for example, the password index PSW_INDEX of the master password MPW or the security password SPW, it is also necessary to specify the index PSW_SLOT_INDEX. For example, in the considered embodiment, bits 22 to 16 of the command VPW1 are used to specify the index PSW_SLOT_INDEX.
[0200] Accordingly, in various embodiments, in response to receiving a password verification command VPW for the master password MPW, the password verification circuit 152a and the protection circuit 150a are configured to disable access to all memory slots of the password data PWD, except for memory slot i (of the master password MPW or security password SPW) specified via the index PSW_SLOT_INDEX in memory 104a. Specifically, for memory slot i, the password verification circuit 152a and the protection circuit 150a can be configured to enable access when the aforementioned additional conditions are met. For example, to enable write access to the master password MPW0, the password verification command VPW may include:
[0201] The index PSW_INDEX indicates the slot number SLOT of the master cipher MPW0 to be used for password verification operations, for example, 0;
[0202] The master password MPW0 serves as the cipher data PSW; and
[0203] The index PSW_SLOT_INDEX indicates the slot number SLOT in non-volatile memory for the master password MPW0, for example, 0.
[0204] For example, in various embodiments, the password verification circuit 152a can be configured to provide a corresponding overwrite signal for each memory slot i, such as OWM1i, OWM2i, and optionally OWM3i. Specifically, in this case, in response to successful password verification of a given master password (e.g., master password MPW1), the password verification circuit 152a can assert an overwrite signal associated with the corresponding master password MPW and the memory slot i indicated by the index PSW_SLOT_INDEX. Alternatively, the protection circuit 150a can receive the index PSW_SLOT_INDEX and enable access to memory slot i only based on the aforementioned data.
[0205] Accordingly, in various embodiments, the processing system 10a can be configured to perform various operations, for example, via the password verification circuit 152a and the protection circuit 150a. Specifically, in response to receiving a password verification command VPW, the processing system 10a can determine whether the received password K corresponds to the master password indicated by the slot index SLOT / password index PSW_INDEX. Accordingly, in response to receiving an access (e.g., write or read) request CMD for a given memory slot i, the processing system 10a can determine whether the configuration data CD and / or the lifetime data LCD indicate that access is disabled. In response to determining that the configuration data CD and / or the lifetime data LCD indicate that access is not disabled, the processing system 10a can execute the access request, for example, writing the data received via the write request CMD to the given memory slot i.
[0206] In some embodiments, in response to determining that the configuration data CD and / or lifecycle data LCD indicate that access is disabled, the processing system 10a may, for example, determine whether to allow access to a given memory slot i by the received master password enabled based on the security password access data SPW_CTR.
[0207] In various embodiments, when the index SPW_SLOT_INDEX is not used, in response to determining that the master password MPW is allowed to enable access to a given memory slot i, the processing system 10a may have executed an access request, for example, writing data received using the write request CMD to the given memory slot i of the memory 104a.
[0208] In various embodiments, when using the index SPW_SLOT_INDEX, the processing system 10a can also determine whether a given memory slot i corresponds to the index SPW_SLOT_INDEX. In this case, in response to determining that the master password is allowed to enable access to the given memory slot i and that the given memory slot i corresponds to the index SPW_SLOT_INDEX, the processing system 10a can execute an access request, for example, writing data received via a write request CMD to the given memory slot i.
[0209] In various embodiments, when the master password MPW stored in the password store has a predetermined value, for example, when the unprogrammed bits of memory 104a have a value of "1" and all bits of the master password MPS are set to "0", the password management circuit can be configured to disable the update function for a given master password MPW and the associated security password SPW.
[0210] Of course, without prejudice to the principles of this disclosure, the details of the construction and embodiments may vary extensively relative to what has been described and illustrated herein by way of example only, without departing from the scope of this disclosure as defined by the appended claims.
[0211] A processing system (10a) is summarized as including: a non-volatile memory (104a) including a memory region arranged for storing cryptographic data (PWD), wherein the memory region includes a first memory slot arranged for storing a first master password (MPW0), a second memory slot arranged for storing a second master password (MPW1), and a third memory slot arranged for storing a security password (SPW0); and a password verification circuit (152a) configured to: receive a password verification command (VPW) including a password (K, PSW) and a slot number (SLOT, PSW_INDEX), and determine whether the slot number (SLOT, PSW_INDEX) matches the first master password (M). The received password (K, PSW) is associated with either the slot number (SLOT, PSW_INDEX) or the second master password (MPW1). In response to determining that the slot number (SLOT, PSW_INDEX) is associated with the first master password (MPW0), the received password (K, PSW) is determined (1522) to correspond to the first master password (MPW0). An overwrite signal (OW; OWM) is set in response to determining that the received password (K, PSW) corresponds to the first master password (MPW0), indicating successful verification of the first master password (MPW0). The received password (K, PSW) is also determined (1522) in response to determining that the slot number (SLOT, PSW_INDEX) is associated with the second master password (MPW1). The protection circuit (150a) is configured to: receive a write request (CMD) for writing a new security password to the third memory slot arranged to store the security password (SPW0), and in a first operating mode (LC3): determine whether the security access data (SIi, SPW_CTR) indicates that the third memory slot corresponds to the first master password (MPW1) or the second master password (MPW1). Associating the second master password (MPW1), determining whether the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0) or the second master password (MPW1), in response to determining that the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the first master password (MPW0) and the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0), enabling the writing of the new security password to the third memory slot, in response to determining that the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the first master password and the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0), enabling the writing of the new security password to the third memory slot, in response to determining that the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the first master password and the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0), enabling the writing of the new security password to the third memory slot.If the overwrite signal (OWM) does not indicate successful verification of the first master password (MPW0), writing the new security password to the third memory slot is prohibited. In response to determining that the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the second master password (MPW1) and that the overwrite signal (OW; OWM) indicates successful verification of the second master password (MPW1), writing the new security password to the third memory slot arranged to store the security password (SPW0) is enabled.
[0212] The processing system (10a) includes: a password store (156a); a configuration circuit (108) configured to transfer the password data (PWD) from the non-volatile memory (104a) to the password store (156a); wherein the password verification circuit (152a) is configured to provide the slot number (SLOT, PSW_INDEX) to the password store (156a) and receive from the password store (156a) the corresponding password associated with the slot number (SLOT, PSW_INDEX).
[0213] The password verification circuit (152a) is configured to: determine whether the slot number (SLOT, PSW_INDEX) is associated with the security password (SPW0), and in response to determining that the slot number (SLOT, PSW_INDEX) is associated with the security password (SPW0), determine (1522) whether the received password (K, PSW) corresponds to the security password (SPW0), and in response to determining that the received password (K, PSW) corresponds to the security password (SPW0), set the overwrite signal (OW) to indicate successful verification of the security password (SPW0); wherein the processing system (10a) includes a circuit (160) and an additional protection circuit (150), wherein the additional protection circuit (150) is configured to enable access to the circuit (160) in response to determining that the overwrite signal (OW) indicates successful verification of the security password (SPW0).
[0214] The protection circuit (150a) includes a register (1502) that provides the security access data (SIi, SPW_CTR), wherein a field (SIi) of the security access data (SPW_CTR) indicates whether the third memory slot arranged to store the security password (SPW0) is associated with the first master password (MPW0), associated with the second master password (MPW1), or unallocated, wherein the protection circuit (150a) is configured to: receive configuration data (CD) from the configuration circuit (108) of the processing system (10a), determine whether the field (SIi) of the security access data (SPW_CTR) indicates that the third memory slot is unallocated, and in response to determining that the field (SIi) of the security access data (SPW_CTR) indicates that the third memory slot is unallocated, overwrite the bits of the field (SIi) of the security access data (SPW_CTR) with the corresponding bits of the received configuration data (CD).
[0215] The protection circuit (150) is associated with an address, wherein the non-volatile memory (104a) includes an additional memory region arranged to store frames of configuration data (CD), each frame of the configuration data (CD) including an address and corresponding configuration data, wherein the configuration circuit (108) is configured to: sequentially read the frames of the configuration data (CD) from the non-volatile memory (104a); determine whether the address of the frame of configuration data corresponds to an address associated with the protection circuit (150); and, in response to determining that the address of the frame of configuration data corresponds to an address associated with the protection circuit (150), transfer the configuration data of the frame of configuration data to the protection circuit.
[0216] The protection circuit (150) is configured to: receive a write request (CMD) for writing a new master password to the first memory slot arranged to store the first master password (MPW0), and in the first operating mode (LC3): determine whether the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0), enable writing the new master password to the first memory slot in response to determining that the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0), and prohibit writing the new master password to the first memory slot in response to determining that the overwrite signal (OW; OWM) does not indicate successful verification of the first master password (MPW0).
[0217] The protection circuit (150) is configured to determine an operating mode based on lifecycle data (LCD) and / or configuration data (CD) indicating the lifecycle stage of the processing system (10a), wherein the first operating mode preferably corresponds to the field lifecycle stage.
[0218] The protection circuit (150a) is configured to enable write access to the first master password (MPW0), the second master password (MPW1), and the security password (SPW0) in a second operating mode (LC0), such as during the production lifecycle phase.
[0219] The protection circuit (150a) is configured to: in a third operating mode (LC1), such as during a software development lifecycle phase: determine whether the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the first master password (MPW0), associated with the second master password (MPW1), or unassigned; determine whether the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0) or the second master password (MPW1); and in response to determining that the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the second master password (MPW1) or unassigned, enable the new security... A password is written to the third memory slot; in response to determining that the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the first master password (MPW0) and the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0), writing the new security password to the third memory slot is enabled; and in response to determining that the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the first master password (MPW0) and the overwrite signal (OW; OWM) does not indicate successful verification of the first master password (MPW0), writing the new security password to the third memory slot is disabled.
[0220] The overwrite signal (OW; OWM) includes a first signal (OWM0) and a second signal (OWM1), wherein the password verification circuit (152a) is configured to: assert the first signal (OWM0) to indicate successful verification of the first master password (MPW0) and deassert the first signal (OWM0) to not indicate successful verification of the first master password (MPW0), and assert the second signal (OWM1) to indicate successful verification of the second master password (MPW1) and deassert the second signal (OWM1) to not indicate successful verification of the second master password (MPW1).
[0221] The processing system (10a) includes processing circuitry (102) and / or a communication interface (IF) configured to provide the password verification command (VPW) and the write request (CMD).
[0222] An integrated circuit, such as a microcontroller, is generally defined as including a processing system (10a).
[0223] An apparatus, such as a vehicle, is generally defined as including a plurality of processing systems (10a) and a communication system (20) for exchanging data between said processing systems (10a).
[0224] A method for operating a processing system (10a), wherein the processing system (10a) is generally defined as including a non-volatile memory (104a) comprising a memory region arranged for storing cryptographic data (PWD), wherein the memory region includes a first memory slot arranged for storing a first master cipher (MPW0), a second memory slot arranged for storing a second master cipher (MPW1), and a third memory slot arranged for storing a security cipher (SPW0), the method comprising the steps of: receiving a password verification command (VPW) including a cipher (K, PSW) and a slot number (SLOT, PSW_INDEX), and determining the slot number (SLOT, PSW_INDEX). In response to determining that the slot number (SLOT, PSW_INDEX) is associated with the first master password (MPW0) or the second master password (MPW1), it is determined (1522) whether the received password (K, PSW) corresponds to the first master password (MPW0), and in response to determining that the received password (K, PSW) corresponds to the first master password (MPW0), an overwrite signal (OW; OWM) is set to indicate successful verification of the first master password (MPW0), and in response to determining that the slot number (SLOT, PSW_INDEX) is associated with the second master password (MPW1), an overwrite signal (OW; OWM) is set to indicate successful verification of the first master password (MPW0). Associating with, determining (1522) whether the received password (K, PSW) corresponds to the second master password (MPW1), and in response to determining that the received password (K, PSW) corresponds to the second master password (MPW1), setting the overwrite signal (OW; OWM) to indicate successful verification of the second master password (MPW1), receiving a write request (CMD) for writing a new security password to a third memory slot arranged to store the security password (SPW0), and determining whether security access data (SIi, SPW_CTR) indicates that the third memory slot corresponds to the first master password (MPW0) or the second master password (MPW1). Associating with the first master password (MPW0) or the second master password (MPW1), determining whether the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0) or the second master password (MPW1), in response to determining that the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the first master password (MPW0) and the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0), enabling the writing of the new security password to the third memory slot, in response to determining that the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the first master password (MPW0) and the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0), enabling the writing of the new security password to the third memory slot, in response to determining that the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the first master password (MPW0) and the overwrite signal (OW; OWM) indicates successful verification of the first master password (MPW0), enabling the writing of the new security password to the third memory slot.The overwrite signal (OW; OWM) does not indicate successful verification of the first master password (MPW0), prohibiting the writing of the new security password to the third memory slot. Furthermore, in response to determining that the security access data (SIi, SPW_CTR) indicates that the third memory slot is associated with the second master password (MPW1) and that the overwrite signal (OW; OWM) indicates successful verification of the second master password (MPW1), the writing of the new security password to the third memory slot arranged to store the security password (SPW0) is enabled.
[0225] The method includes: storing a first master password (MPW0) in the first memory slot of the non-volatile memory (104a), storing a security password (SPW0) in the third memory slot of the non-volatile memory (104a), and setting the security access data (SIi, SPW_CTR) to indicate that the third memory slot is associated with the first master password (MPW0).
[0226] The various embodiments described above can be combined to provide other embodiments. All U.S. patents, U.S. patent application publications, U.S. patent applications, foreign patents, foreign patent applications and non-patent publications listed in the application data sheets referenced in this specification are incorporated herein by reference in their entirety. Where necessary, aspects of the embodiments may be modified to employ concepts from various patents, applications and publications to provide further embodiments.
[0227] Based on the detailed description above, these and other modifications can be made to the embodiments. Generally, the terminology used in the following claims should not be construed as limiting the claims to the specific embodiments disclosed in this claim and specification, but should be interpreted to include all possible embodiments and the full scope of the equivalents conferred by these claims. Accordingly, the claims are not limited to this disclosure.
Claims
1. A processing system, comprising: The non-volatile memory includes a memory region configured to store cryptographic data, wherein the memory region includes a first memory slot arranged to store a first master password, a second memory slot arranged to store a second master password, and a third memory slot arranged to store a security password. The password verification circuit is configured as follows: Receive a password verification command including the password and slot number; Determine whether the slot number is associated with the first master password or the second master password; In response to determining the slot number associated with the first master password: Determine whether the received password corresponds to the first master password; and In response to determining that the received password corresponds to the first master password, an overwrite signal is set to indicate the successful verification of the first master password; as well as In response to determining the association between the slot number and the second master password: Determine whether the received password corresponds to the second master password; as well as In response to determining that the received password corresponds to the second master password, an overwrite signal is set to indicate the successful verification of the second master password; as well as The protection circuit is configured as follows: Receive a write request for writing a new security password to a third memory slot configured to store security passwords; as well as In the first operating mode: Determine whether the secure access data indicates that the third storage slot is associated with the first master password or the second master password; Determine whether the overwrite signal indicates successful verification of the first or second master password; In response to the determination that the security access data indicates that the third memory slot is associated with the first master password and the overwrite signal indicates that the first master password has been successfully verified, the writing of the new security password to the third memory slot is enabled. In response to the determination that the security access data indicates that the third memory slot is associated with the first master password and the overwrite signal does not indicate successful verification of the first master password, writing a new security password to the third memory slot is prohibited. as well as In response to the determination that the security access data indicates that the third memory slot is associated with the second master password and the overwrite signal indicates that the second master password has been successfully verified, the writing of the new security password to the third memory slot configured to store the security password is enabled.
2. The processing system according to claim 1, comprising: Password storage; as well as The configuration circuit is set to transfer cryptographic data from non-volatile memory to the cryptographic store. The password verification circuit is configured to provide a slot number to the password store and receive the corresponding password associated with the slot number from the password store.
3. The processing system according to claim 1, wherein the password verification circuit is configured as follows: Determine whether the slot number is associated with a security password; and In response to determining the associated slot number with a security password: Determine whether the received password corresponds to the security password; In response to confirming that the received password matches the security password, an overwrite signal is set to indicate successful verification of the security password. The processing system includes circuitry and additional protection circuitry, wherein the additional protection circuitry is configured to enable access to the circuitry in response to a determination that an overwrite signal indicates successful verification of a security password.
4. The processing system of claim 1, wherein the protection circuitry includes a register providing security access data, wherein a field of the security access data indicates whether a third memory slot configured to store a security password is associated with a first master password, associated with a second master password, or unallocated, wherein the protection circuitry is configured to: Receive configuration data from the configuration circuitry of the processing system; Determine whether the field for security access data indicates that a third storage slot is not allocated; and In response to the field indicating that the security access data is not allocated, the corresponding bits of the security access data field are overwritten with the corresponding bits of the received configuration data.
5. The processing system of claim 4, wherein the protection circuitry is associated with an address, wherein the non-volatile memory includes an additional memory region arranged to store frames of configuration data, each frame of configuration data including an address and corresponding configuration data, wherein the configuration circuitry is configured to: Frames of configuration data are read sequentially from non-volatile memory; Determine whether the address of the configuration data frame corresponds to the address associated with the protection circuit; and In response to determining that the address of the configuration data frame corresponds to the address associated with the protection circuit, the configuration data frame is transmitted to the protection circuit.
6. The processing system of claim 1, wherein the protection circuit is configured as follows: Receive a write request for writing a new master password to a first memory slot configured to store the first master password; as well as In the first operating mode: Determine whether the overwrite signal indicates successful verification of the first master key; In response to the confirmation of a successful verification of the first master password by an overwrite signal, write the new master password into the first memory slot; as well as In response to the determination that the overwrite signal does not indicate successful verification of the first master password, writing the new master password into the first memory slot is prohibited.
7. The processing system of claim 1, wherein the protection circuit is configured to determine an operating mode based on lifecycle data or configuration data indicating a lifecycle stage of the processing system, wherein the first operating mode corresponds to a field lifecycle stage.
8. The processing system of claim 1, wherein the protection circuit is configured as follows: In the second operating mode, write access to the first master password, the second master password, and the security password is enabled.
9. The processing system of claim 1, wherein the protection circuit is configured as follows: In the third operating mode: Determine whether the security access data indicates that the third storage slot is associated with the first master password, the second master password, or is unassigned; Determine whether the overwrite signal indicates successful verification of the first or second master password; In response to determining that the security access data indicates that the third memory slot is associated with the second master password or is not assigned, enable writing a new security password to the third memory slot; In response to the determination that the security access data indicates that the third memory slot is associated with the first master password and the overwrite signal indicates that the first master password has been successfully verified, the writing of the new security password to the third memory slot is enabled. as well as In response to the determination that the security access data indicates that the third memory slot is associated with the first master password and that the overwrite signal does not indicate successful verification of the first master password, writing a new security password to the third memory slot is prohibited.
10. The processing system of claim 1, wherein the overwrite signal comprises a first signal and a second signal, wherein the password verification circuit is configured to: Assert the first signal to indicate successful verification of the first master key and cancel the assertion of the first signal to not indicate successful verification of the first master key; and Assert the second signal to indicate successful verification of the second master cipher and deassert the second signal to not indicate successful verification of the second master cipher.
11. The processing system of claim 1, comprising a communication interface or processing circuit configured to provide password verification commands and write requests.
12. An integrated circuit comprising the processing system according to claim 1.
13. An apparatus comprising a plurality of processing systems according to claim 1 and a communication system for exchanging data between the plurality of processing systems.
14. A method comprising: Receive a password verification command including the password and slot number; Determine whether the slot number is associated with the first master password or the second master password; In response to determining the slot number associated with the first master password: Determine whether the received password corresponds to the first master password; and In response to determining that the received password corresponds to the first master password, an overwrite signal is set to indicate the successful verification of the first master password; In response to determining the association between the slot number and the second master password: Determine whether the received password corresponds to the second master password; as well as In response to determining that the received password corresponds to the second master password, an overwrite signal is set to indicate the successful verification of the second master password; Receive a write request for writing a new security password to a third memory slot configured to store security passwords; Determine whether the secure access data indicates that the third storage slot is associated with the first master password or the second master password; Determine whether the overwrite signal indicates successful verification of the first or second master password; In response to the determination that the security access data indicates that the third memory slot is associated with the first master password and the overwrite signal indicates that the first master password has been successfully verified, the writing of the new security password to the third memory slot is enabled. In response to the determination that the security access data indicates that the third memory slot is associated with the first master password and the overwrite signal does not indicate successful verification of the first master password, writing a new security password to the third memory slot is prohibited. as well as In response to the determination that the security access data indicates that the third memory slot is associated with the second master password and the overwrite signal indicates that the second master password has been successfully verified, the writing of the new security password to the third memory slot configured to store the security password is enabled.
15. The method of claim 14, comprising: The first master password is stored in the first memory slot of the non-volatile memory; Store the security password in a third memory slot of non-volatile memory; as well as Configure secure access data to indicate that the third storage slot is associated with the first master password.
16. An apparatus comprising: The non-volatile memory includes a memory region arranged to store cryptographic data, wherein the memory region includes a first memory slot arranged to store a first master password, a second memory slot arranged to store a second master password, and a third memory slot arranged to store a security password. The password verification circuit is configured as follows: Receive a password verification command including the password and slot number; Determine whether the slot number is associated with the first master password or the second master password; Based on the determination that the slot number is associated with the first master password and that the received password corresponds to the first master password, an overwrite signal is set to indicate the successful verification of the first master password; as well as Based on the determination that the slot number is associated with the second master password and that the received password corresponds to the second master password, an overwrite signal is set to indicate the successful verification of the second master password; The protection circuit is configured as follows: Receive a write request for writing a new security password to a third memory slot that is configured to store the security password; as well as In the first operating mode: Determine whether the secure access data indicates that the third storage slot is associated with the first master password or the second master password; Determine whether the overwrite signal indicates successful verification of the first or second master password. Based on the determination that the security access data indicates that the third memory slot is associated with the first master password and the overwrite signal indicates that the first master password has been successfully verified, the writing of the new security password to the third memory slot is enabled. Based on the determination that the security access data indicates that the third memory slot is associated with the first master password and that the overwrite signal does not indicate successful verification of the first master password, writing new security passwords into the third memory slot is prohibited. as well as Based on the determination that the security access data indicates that the third memory slot is associated with the second master password and the overwrite signal indicates that the second master password has been successfully verified, the writing of the new security password to the third memory slot configured to store the security password is enabled.
17. The apparatus of claim 16, comprising: Password storage; as well as The configuration circuit is set to transfer cryptographic data from non-volatile memory to the cryptographic store. The password verification circuit is configured to provide a slot number to the password store and receive the corresponding password associated with the slot number from the password store.
18. The apparatus of claim 16, wherein the password verification circuit is configured as follows: Determine whether the slot number is associated with a security password; and In response to determining the associated slot number with a security password: Determine whether the received password corresponds to the security password; and In response to confirming that the received password matches the security password, an overwrite signal is set to indicate successful verification of the security password. The processing system includes circuitry and additional protection circuitry, wherein the additional protection circuitry is configured to enable access to the circuitry in response to a determination that an overwrite signal indicates successful verification of a security password.
19. The apparatus of claim 16, wherein the protection circuitry includes a register providing security access data, wherein a field of the security access data indicates whether a third memory slot arranged to store a security password is associated with a first master password, associated with a second master password, or unallocated, wherein the protection circuitry is configured to: Receive configuration data from the configuration circuitry of the processing system; Determine whether the field for security access data indicates that a third storage slot is not allocated; and In response to the indication that the third memory slot is not allocated by the field indicating that the security access data is determined, the corresponding bits of the security access data field are overwritten with the corresponding bits of the received configuration data.
20. The apparatus of claim 16, wherein the protection circuitry is associated with an address, wherein the non-volatile memory includes an additional memory region arranged to store frames of configuration data, each frame of configuration data including an address and corresponding configuration data, wherein the configuration circuitry is configured to: Frames of configuration data are read sequentially from non-volatile memory; Determine whether the address of the configuration data frame corresponds to the address associated with the protection circuit; and In response to determining that the address of the configuration data frame corresponds to the address associated with the protection circuit, the configuration data frame is transmitted to the protection circuit.
Citation Information
Patent Citations
Processing system, related integrated circuit, device and method
US10740041B2
Processing system, related integrated circuit, device and method
US10922015B2
Processing system, related integrated circuit and method
US10949570B2