Semiconductor device and control method of semiconductor device

By employing cryptographic key protection circuits in semiconductor devices to generate and encrypt key pairs, the problem of insufficient security in device-specific key generation is solved, achieving robust security and a high level of protection for the encryption key pairs.

CN121997391APending Publication Date: 2026-05-08RENESAS ELECTRONICS CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
RENESAS ELECTRONICS CORP
Filing Date
2025-10-20
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing semiconductor devices have shortcomings in the security of generating device-specific keys, making it difficult to ensure robust security.

Method used

An encryption key pair is generated using a cryptographic key protection circuit and encrypted and decrypted using a public key. This ensures the security of the encryption key pair during storage and use, restricts unauthorized CPU access, and ensures that the encryption key pair is generated and stored within the encryption key protection circuit.

Benefits of technology

It achieves a high level of security for semiconductor devices, ensures the robustness of encryption key pairs during storage and use, prevents unauthorized access and internal analysis, and maintains a high level of security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121997391A_ABST
    Figure CN121997391A_ABST
Patent Text Reader

Abstract

The invention relates to a semiconductor device and a control method of the semiconductor device. A method for controlling a semiconductor device capable of ensuring robust security is provided. The method is implemented by a semiconductor device including a cryptographic key protection circuit, a processor, and a memory. The method includes instructing, by a processor, a cryptographic key protection circuit to generate a cryptographic key pair, generating, by the cryptographic key protection circuit, the cryptographic key pair internally according to the instruction, encrypting, by the cryptographic key protection circuit, the generated cryptographic key pair using a public key, storing, by the processor, the encrypted encryption key pair output from the encryption key protection circuit in a memory, receiving, by the encryption key protection circuit, the encrypted encryption key pair stored in the memory while using the encryption key pair, and decrypting, by the encryption key protection circuit, the encrypted encryption key pair received from the memory using the public key.
Need to check novelty before this filing date? Find Prior Art

Description

Cross-references to related applications

[0001] The disclosure of Japanese Patent Application No. 2024-192785, filed on November 1, 2024, including the specification, drawings and abstract, is incorporated herein by reference in its entirety. Technical Field

[0002] This disclosure relates to a semiconductor device, and more particularly to a semiconductor device with a key protection circuit and a control method thereof. Background Technology

[0003] [Patent Document 1] Japanese Unexamined Patent Application Publication No. 2021-184584

[0004] Conventionally, a semiconductor device has been proposed that maintains both a device-specific key and a public key, and utilizes a cryptographic key protection circuit capable of performing encryption and decryption using the device-specific key and decryption using the public key. The cryptographic key protection circuit performs an activation process in which data encrypted with the public key is decrypted using the public key, then encrypted again using the device-specific key, and written to non-volatile memory. After the activation process, the encrypted data is read from the non-volatile memory, and the cryptographic key protection circuit decrypts it using the device-specific key to provide it to the processor. Summary of the Invention

[0005] On the other hand, conventional methods have aspects that can be further improved in terms of the security of the generation of device-specific keys.

[0006] This disclosure is made to solve the above-mentioned problems and provides a semiconductor device that can ensure robust security and a control method for the semiconductor device.

[0007] Other objects and novel features will become apparent from the description and accompanying drawings in this specification.

[0008] The method disclosed herein is implemented by a semiconductor device including a cryptographic key protection circuit, a processor, and a memory. The method includes: instructing the cryptographic key protection circuit to generate an encryption key pair; the cryptographic key protection circuit internally generating the encryption key pair according to the instruction; encrypting the encryption key pair generated by the cryptographic key protection circuit using a public key pair; storing the encrypted encryption key pair output from the cryptographic key protection circuit in the memory; receiving the encrypted encryption key pair stored in the memory by the cryptographic key protection circuit when using the encryption key pair; and decrypting the encrypted encryption key pair received from the memory by the cryptographic key protection circuit using the public key pair.

[0009] The semiconductor device disclosed herein includes: a cryptographic key protection circuit; a processor that instructs the cryptographic key protection circuit to generate a cryptographic key pair; and a memory. The cryptographic key protection circuit includes: a cryptographic key generation unit that internally generates a cryptographic key pair according to instructions from the processor; an encryption unit that encrypts the generated cryptographic key pair using a public key pair and outputs the encrypted cryptographic key pair for storage in the memory; and a decryption unit that, when the cryptographic key pair is used, decrypts the encrypted cryptographic key pair stored in the memory using the public key pair.

[0010] The method disclosed herein is implemented by a semiconductor device including a protection circuit with guaranteed appropriate security strength, a processor, and a memory. The method includes: instructing the protection circuit to generate an encryption key pair by the processor; the protection circuit internally generating the encryption key pair according to the instruction; encrypting the encryption key pair generated by the protection circuit using a public key pair; outputting the encrypted encryption key pair from the protection circuit by the processor for storage in the memory; receiving the encrypted encryption key pair stored in the memory by the protection circuit when utilizing the encryption key pair; and decrypting the encrypted encryption key pair received from the memory by the protection circuit using the public key pair.

[0011] Another semiconductor device disclosed herein includes protection circuitry with a guaranteed appropriate level of security; a processor that instructs the protection circuitry to generate an encryption key pair; and a memory. The protection circuitry includes: an encryption key generation unit that internally generates an encryption key pair according to instructions from the processor; an encryption unit that encrypts the generated encryption key pair using a public key pair and outputs the encrypted encryption key pair for storage in the memory; and a decryption unit that, when the encryption key pair is used, decrypts the encrypted encryption key pair stored in the memory using the public key pair.

[0012] The semiconductor device and control method disclosed herein can ensure robust security. Attached Figure Description

[0013] Figure 1 This is a block diagram illustrating the configuration of a semiconductor system 1 according to an embodiment of the present disclosure.

[0014] Figure 2 This is a flowchart illustrating the generation of a cryptographic key pair in a semiconductor device 15 according to an embodiment of the present disclosure.

[0015] Figure 3 This is a flowchart illustrating the key generation process of a cryptographic key protection circuit 14 according to an embodiment of the present disclosure.

[0016] Figure 4 This is a flowchart illustrating the use of a key pair in a semiconductor device 15 according to an embodiment of the present disclosure.

[0017] Figure 5 This is a flowchart illustrating the cryptographic key extraction process of a cryptographic key protection circuit 14 according to an embodiment of the present disclosure.

[0018] Figure 6 This is a diagram illustrating an example of using a cryptographic key pair according to an embodiment of this disclosure. Detailed Implementation

[0019] The embodiments will be described in detail with reference to the accompanying drawings. In the drawings, the same or corresponding parts are indicated by the same reference numerals and their descriptions will not be repeated.

[0020] Figure 1 This is a block diagram illustrating the configuration of a semiconductor system 1 according to an embodiment of the present disclosure. (See reference...) Figure 1 Semiconductor system 1 includes semiconductor device 15. Although not shown, semiconductor device 15 can be connected to other communication semiconductor devices, peripheral devices, external memory, etc., and is configured to be mounted on a system board.

[0021] Semiconductor device 15 constitutes a microcontroller and includes a central processing unit (CPU) 12, a memory 16, a cryptographic key protection circuit 14, and a bus 18. The key protection circuit 14 is a protection circuit with a guaranteed appropriate security strength, such as a security IP. These components are interconnected via bus 18. The memory 16 stores an encryption key pair 161 encrypted with a public key, which will be described later. The cryptographic key protection circuit 14 has functions such as key management and preventing processing from unauthorized CPU 12. The key protection circuit 14 includes various functional blocks. Specifically, the cryptographic key protection circuit 14 includes a public key storage unit 141, a CPUID storage unit 142, an access determination unit 143, a cryptographic key generation unit 144, an encryption unit 145, and a decryption unit 146.

[0022] The public key storage unit 141 stores the public key in a state where it cannot be read from outside the cryptographic key protection circuit 14. In this case, the public key can be stored in the public key storage unit 141 within the cryptographic key protection circuit 14 via a special command. Alternatively, it can be internally embedded during the assembly of the key protection circuit 14.

[0023] CPUID storage unit 142 stores the identifier CPUID of the CPU that is allowed to access. In this respect, the identifier CPUID can be stored in CPUID storage unit 142 within the cryptographic key protection circuit 14 via a special command. Alternatively, it can be embedded during the assembly of the key protection circuit 14. Alternatively, the identifier CPUID of the CPU that first accesses the cryptographic key protection circuit 14 can be stored in CPUID storage unit 142.

[0024] Access determination unit 143 determines whether the access to the encryption key protection circuit 14 originates from a pre-authorized CPU. Specifically, access determination unit 143 determines whether the access originates from the CPU corresponding to the identifier CPUID stored in CPUID storage unit 142. If the access originates from the CPU corresponding to the registered identifier CPUID, access determination unit 143 continues the process; if the access originates from a CPU that does not correspond to the registered identifier CPUID, the process is rejected.

[0025] The key generation unit 144 generates key pairs under predetermined instructions. In this example, a cryptographic key pair for a public key system (such as RSA or elliptic curve cryptography) is described, but it is not limited to this and can be similarly applied to cryptographic key pairs following other methods.

[0026] The encryption unit 145 uses the public key stored in the public key storage unit 141 to encrypt the encryption key pair generated by the encryption key generation unit 144, and outputs it to the CPU 12.

[0027] The decryption unit 146 uses the public key stored in the public key storage unit 141 to decrypt the password key 161 encrypted with the public key stored in the memory 16, and outputs it to the CPU 12.

[0028] Figure 2 This is a flowchart illustrating the generation of a cryptographic key pair in a semiconductor device 15 according to an embodiment of the present disclosure. (See also:) Figure 2 The CPU 12 of the semiconductor device 15 determines whether the power supply is on (step S2).

[0029] If CPU 12 determines that power is on ("Yes" in step S2), it outputs a key generation instruction to the cryptographic key protection circuit 14 (step S4). Specifically, CPU 12 outputs a key generation instruction to the key protection circuit 14 based on program code stored in memory 16 triggered by the initial power-on. Note that CPU 12 may not always be required to output a key generation instruction to the cryptographic key protection circuit 14 when there is no initial power-on.

[0030] Next, the encryption key protection circuit 14 performs a key generation process (step S6) according to the key generation instruction from the CPU 12. The details of the key generation process will be described later.

[0031] Next, the CPU 12 stores the encrypted key pair output from the encryption key protection circuit 14 into the memory 16 (step S8).

[0032] Then, the process ends.

[0033] Figure 3 This is a flowchart illustrating the key generation process of an encryption key protection circuit 14 according to an embodiment of the present disclosure. (See also:) Figure 3 The encryption key protection circuit 14 determines whether the identifier CPUID of the CPU output key generation instruction matches the identifier CPUID stored in the identifier memory (step S10). Specifically, the access determination unit 143 determines whether the identifier CPUID of the CPU 12 input together with the key generation instruction matches the identifier CPUID stored in the CPUID storage unit 142.

[0034] In step S10, if the encryption key protection circuit 14 determines that the CPU identifier CPUID of the CPU in the output key generation indication does not match the CPUID stored in the CPUID storage unit 142 ("No" in step S10), it determines that CPU access is not allowed and terminates the process (returns). If the CPUID of the output key generation indication does not match the CPUID stored in the CPUID storage unit 142 and does not instruct the encryption key generation unit 144 to generate an encryption key, the access determination unit 143 determines that it is an unauthorized access.

[0035] On the other hand, if the encryption key protection circuit 14 determines that the CPU identifier CPUID of the CPU in the output key generation instruction matches the CPUID stored in the CPUID storage unit 142 (Yes in step S10), it generates an encryption key pair (step S12). The access determination unit 143 instructs the encryption key generation unit 144 to generate a key, and the encryption key generation unit 144 generates an encryption key pair of a public key and a private key according to the instruction.

[0036] Next, the encryption key protection circuit 14 encrypts the encryption key pair using the public key (step S14). The encryption unit 145 encrypts the encryption key pair generated by the encryption key generation unit 144 using the public key stored in the public key storage unit 141.

[0037] Next, the encryption key protection circuit 14 outputs the encrypted encryption key pair (step S16). The encryption unit 145 outputs the encryption key pair encrypted with the public key to the CPU 12. Then, the process ends (returns).

[0038] CPU 12 stores the encryption key pair, which is encrypted with a public key and output from encryption key protection circuit 14, into memory 16.

[0039] Figure 4 This is a flowchart illustrating the use of an encryption key pair in a semiconductor device 15 according to an embodiment of the present disclosure. (See also:) Figure 4 The CPU 12 of the semiconductor device 15 determines whether there is a request to use the encryption key (step S20).

[0040] In step S20, CPU 12 maintains the state of step S20 until a request to use the encryption key is received.

[0041] On the other hand, if the CPU 12 determines that there is a request to use the encryption key (Yes in step S20), it retrieves the encrypted encryption key pair from memory (step S22).

[0042] Next, the CPU 12 outputs the retrieved encrypted key pair to the encryption key protection circuit 14 (step S23).

[0043] Then, the encryption key protection circuit 14 performs the encryption key extraction process (step S24). Details of the encryption key extraction process will be described later.

[0044] Then, the process ends.

[0045] Figure 5 This is a flowchart illustrating the encryption key extraction process of the encryption key protection circuit 14 according to an embodiment of the present disclosure. (See also...) Figure 5 The encryption key protection circuit 14 determines whether the CPU identifier CPUID of the CPU output key extraction instruction matches the stored identifier CPUID (step S30). Specifically, the access determination unit 143 determines whether the CPU identifier CPUID of the CPU 12 input together with the key extraction instruction matches the identifier CPUID stored in the CPUID storage unit 142.

[0046] In step S30, if the encryption key protection circuit 14 determines that the CPU identifier CPUID of the CPU in the output key extraction instruction does not match the CPUID stored in the CPUID storage unit 142 ("No" in step S30), it determines that CPU access is not allowed and ends the process (returns). If the CPUID of the CPU in the output key extraction instruction does not match the CPUID stored in the CPUID storage unit 142, and the decryption unit 146 is not instructed to decrypt the encryption key, the access determination unit 143 determines that it is an unauthorized access.

[0047] On the other hand, if the encryption key protection circuit 14 determines that the CPU identifier CPUID of the CPU in the output key generation instruction matches the CPUID stored in the CPUID storage unit 142 (Yes in step S30), it decrypts the encryption key pair (step S32). The access determination unit 143 outputs the retrieved encrypted encryption key pair to the decryption unit 146, and the decryption unit 146 decrypts the encryption key pair encrypted with the public key.

[0048] Next, the encryption key protection circuit 14 outputs the decrypted encryption key pair (step S34). The decryption unit 146 outputs the decrypted encryption key pair to the CPU 12. Then, the process ends (returns).

[0049] Figure 6 This is a diagram illustrating an example of the use of an encryption key pair according to an embodiment of this disclosure. Reference Figure 6 This example describes a scenario where a user uses a pair of cryptographic keys to perform authentication processing with a semiconductor system 1 and a cloud server 5.

[0050] refer to Figure 6 Semiconductor system 1 sends the public key to cloud server 5 (sequence Sq0) according to the user's instructions. Figure 5 In the flowchart, the public key is paired with the private key in the encryption key pair decrypted by the encryption key protection circuit 14 for communication with the cloud server. The cloud server 5 receives the public key from the semiconductor system 1, uses the public key to encrypt the claim key held by the cloud server side, and sends it to the semiconductor system 1 (sequence Sq2).

[0051] Semiconductor system 1 acquires the encrypted claim key (sequence Sq4). Next, semiconductor system 1 decrypts the encrypted claim key (sequence Sq6). Specifically, semiconductor system 1 uses a private key paired with the public key to decrypt the encrypted claim key. The private key used for decryption can be determined by the encryption key protection circuit 14 based on... Figure 5 The flowchart in the document decrypts the private key in the encryption key pair.

[0052] Next, semiconductor system 1 uses a claim key to encrypt the authentication information (sequence Sq8).

[0053] Next, semiconductor system 1 sends authentication information (sequence Sq9) encrypted with a declaration key to cloud server 5.

[0054] Cloud server 5 obtains the authentication information encrypted with the claim key (sequence Sq10). Then, cloud server 5 decrypts the authentication information using the claim key (sequence Sq12).

[0055] Subsequently, cloud server 5 performs authentication processing based on the authentication information (sequence Sq14).

[0056] Then, cloud server 5 registers the public key (sequence Sq16) of the certified semiconductor system 1.

[0057] Next, cloud server 5 generates a certificate (serial Sq18) for semiconductor system 1 for authentication.

[0058] Then, cloud server 5 encrypts the certificate with the registered public key and sends it to semiconductor system 1 (sequence Sq20).

[0059] Semiconductor system 1 receives an encryption certificate (sequence Sq22) sent from cloud server 5.

[0060] Next, semiconductor system 1 decrypts the encrypted certificate (sequence Sq24). Specifically, semiconductor system 1 uses a private key paired with the public key to decrypt the encrypted certificate. The private key used for decryption can be a private key from the encrypted key pair decrypted in encryption key protection circuit 14, such as... Figure 5 The flowchart is shown.

[0061] Next, semiconductor system 1 stores the decrypted certificate (sequence Sq26). Then, semiconductor system 1 uses the stored certificate to execute requests for various services to cloud server 5 (sequence Sq28).

[0062] Through this process, semiconductor system 1 is able to perform authentication processing with cloud server 5 while ensuring a robust and secure state.

[0063] In the decryption process of semiconductor system 1 in this example, a private key from the encryption key pair decrypted in encryption key protection circuit 14 is used, as follows: Figure 5As shown in the flowchart. Therefore, decryption cannot be performed without access to the encryption key protection circuit 14, thus ensuring a high level of security. Furthermore, the generation of the encryption key pair according to this disclosure occurs within the encryption key protection circuit 14. Therefore, it is difficult to obtain the encryption key pair without accessing the encryption key protection circuit 14. At this point, access to the encryption key protection circuit 14 is restricted; the CPUs that can access it are pre-restricted, and unauthorized CPUs cannot access it. In other words, obtaining the encryption key pair from the encryption key protection circuit 14 is challenging, thus allowing a high level of security to be maintained in a simple manner.

[0064] Furthermore, since the encryption key pair generated by the encryption key protection circuit 14 is stored in the memory 16 in an encrypted state, it is impossible to decrypt the encryption key pair stored in the memory 16, thus ensuring a high level of security.

[0065] Furthermore, the method according to this disclosure does not have the original data in the encryption key pair presented within the encryption key protection circuit 14, so a secure state can be maintained even if the internal workings of the encryption key protection circuit 14 can be analyzed.

[0066] Although this disclosure has been specifically described based on the above embodiments, this disclosure is not limited to these embodiments, and it goes without saying that various modifications can be made without departing from its essential points.

Claims

1. A method implemented by a semiconductor device, said semiconductor device including an encryption key protection circuit, a processor, and a memory, said method comprising: The processor instructs the encryption key protection circuit to generate an encryption key pair; The encryption key pair is generated internally by the encryption key protection circuit according to the instruction; The encryption key pair generated by the encryption key protection circuit using the public key pair is encrypted; The encrypted encryption key pair, output by the processor from the encryption key protection circuit, is stored in the memory; The encryption key protection circuit receives the encrypted encryption key pair stored in the memory when using the encryption key pair; as well as The encryption key protection circuit uses a public key to decrypt the encrypted encryption key pair received from the memory.

2. The method of claim 1, wherein the instruction comprises: The processor instructs the encryption key protection circuit to generate the encryption key when the processor initially powers on the semiconductor device.

3. The method of claim 1, further comprising receiving the instruction from the processor by the encryption key protection circuit. The receipt includes accepting an indication from the processor that has been pre-authorized access, but does not include accepting an indication from the processor that has not been pre-authorized access.

4. The method of claim 2, wherein the instruction comprises: The processor reads the program code stored in the memory when the initial power of the semiconductor device is turned on, and instructs the encryption key protection circuit to generate the encryption key.

5. The method according to claim 1, wherein, The public key is stored within the encryption key protection circuit in a state that prevents it from being accessed from outside the semiconductor device.

6. A semiconductor device, comprising: Encryption key protection circuit; The processor instructs the encryption key protection circuit to generate an encryption key pair; as well as memory, The encryption key protection circuit includes: An encryption key generation unit internally generates the encryption key pair according to instructions from the processor; An encryption unit encrypts the generated encryption key pair using a public key and outputs the encrypted encryption key pair for storage in a memory; and The decryption unit, when using the encryption key pair, decrypts the encrypted encryption key pair stored in the memory using the public key pair.

7. The semiconductor device of claim 6, wherein the processor instructs the encryption key protection circuit to generate the encryption key when the semiconductor device is initially powered on.

8. The semiconductor device of claim 6, wherein the encryption key protection circuitry accepts instructions from the processor that has been pre-authorized access, and does not accept instructions from the processor that has not been pre-authorized access.

9. The semiconductor device of claim 6, wherein the processor reads program code stored in the memory when the semiconductor device is initially powered on, and instructs the encryption key protection circuit to generate the encryption key.

10. The semiconductor device of claim 6, wherein the common key is stored within the encryption key protection circuit in a state inaccessible from outside the semiconductor device.

11. A method implemented by a semiconductor device, said semiconductor device including protection circuitry, a processor, and a memory having guaranteed appropriate safety strength, said method comprising: The processor instructs the protection circuit to generate an encryption key pair; The protection circuit generates the encryption key pair internally according to the instruction; The protection circuit encrypts the encryption key pair generated using the public key. The processor outputs the encrypted encryption key pair from the protection circuit for storage in the memory; The protection circuit receives the encrypted encryption key pair stored in the memory when using the encryption key pair; as well as The protection circuit uses a public key to decrypt the encrypted key pair received from the memory.

12. The method of claim 11, wherein the instruction comprises: The processor instructs the protection circuit to generate the encryption key when the processor initially powers on the semiconductor device.

13. The method of claim 1, further comprising receiving the instruction from the processor by the protection circuit. The receipt includes accepting an indication from the processor that pre-authorized access has been granted, but does not include accepting an indication from the processor that unauthorized access has been granted.

14. The method of claim 12, wherein the instruction includes the processor accessing program code stored in the memory when the semiconductor device is initially powered on, and instructing the protection circuit to generate the encryption key.

15. The method of claim 11, wherein the public key is stored within the protection circuit in a state inaccessible from outside the semiconductor device.

16. A semiconductor device, comprising: The protection circuit has an appropriate level of safety. The processor instructs the protection circuit to generate an encryption key pair; as well as memory, The protection circuit includes: An encryption key generation unit internally generates the encryption key pair according to the instructions from the processor; An encryption unit encrypts the generated encryption key pair using a public key and outputs the encrypted encryption key pair for storage in the memory; and The decryption unit, when using the encryption key pair, decrypts the encrypted encryption key pair stored in the memory using the public key pair.

Citation Information

Patent Citations

  • Semiconductor device and electronic system using the same

    JP2021184584A