METHOD FOR SAFETY OF THE USE OF A DEVICE OPERATIONAL WITH AN ACCESSORY OR CONSUMABLE

DE602019084854T2Active Publication Date: 2026-05-13SEALSQ FRANCE
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
SEALSQ FRANCE
Filing Date
2019-09-03
Publication Date
2026-05-13

AI Technical Summary

Technical Problem

Existing authentication methods for removable peripheral devices are vulnerable to unauthorized access and manipulation due to insecure device processors, allowing unauthenticated components to be used, compromising device security and functionality.

Method used

Implementing a secure microcircuit within the peripheral device to intercept and authenticate commands, perform mutual authentication with the device processor, and transform commands securely, using encryption keys to ensure only authorized operations are executed.

Benefits of technology

Enhances device security by preventing unauthorized use of peripheral components and ensuring reliable authentication, while also preventing refilling of consumables by monitoring resource depletion.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to combating the counterfeiting of accessories or consumables, or more generally, removable peripheral components designed to operate with specific devices. Thus, the invention applies in particular to ink cartridges and toners for printers, refills for perfume diffusers or electronic cigarettes, power supply batteries, headphones or earphones, etc.

[0002] There is a need to protect the distribution of such peripheral components, in particular to prevent the use of peripheral components of insufficient quality which could damage the devices with which they are used.

[0003] To control the marketing and / or use of such removable peripheral devices, some devices include a mechanism for authenticating the device. Furthermore, some removable peripheral devices are designed to implement an authentication procedure with the device for which they are adapted. The device's authentication of the peripheral device relies on authentication data recorded or stored by the peripheral device. Access to this authentication data must therefore be protected. The level of protection for such authentication data generally corresponds to the cost of the device storing the authentication data, with the understanding that the higher the level of protection, the higher its cost. WO 2009 / 113286 A1 constitutes the relevant prior art.

[0004] The scope of the invention is defined by the independent claims.

[0005] Several authentication techniques for such peripheral components have been proposed to address this need. These techniques include special marking methods for authentic peripheral components, which may involve holograms.

[0006] It has also been proposed to associate a secure microcircuit with a peripheral device to store authentication data. This microcircuit can connect to the device's processor and implement cryptographic functions. The use of such a microcircuit is assumed to offer the highest level of security, given that it can be very difficult to copy. This microcircuit is used to implement an authentication procedure, generally based on a challenge-response protocol. This protocol involves sharing secret data and cryptographic functions between the microcircuit and the processor of the device receiving the peripheral device. This solution appears secure if both the microcircuit and the processor involved in the authentication procedure are secure. However, the device's processor is generally not secure.As a result, if the program executed by this processor is compromised (modified by an unauthorized person), the authentication performed is not reliable.

[0007] For example, the ink supply in a conventional inkjet printer is managed by the printer's processor, which is generally not secure. The program executed by this processor includes cryptographic functions to authenticate the ink cartridges (or other peripheral components), and control functions that send simple commands to the cartridges and receive status data from them. As a result, the program executed by the printer's processor can be modified to perform the cartridge control functions without first executing the cartridge authentication procedure or without taking into account the result of this authentication procedure.

[0008] It is therefore advisable to enhance security when using a removable peripheral component with a device, particularly to prevent the device from using an unauthenticated peripheral component. It may also be advisable to prevent the refilling of a consumable peripheral component.

[0009] Embodiments relate to a method for controlling a removable peripheral component, comprising steps of: intercepting, by an internal secure microcircuit of the peripheral component, a command received by the peripheral component and intended to be executed by a control circuit of the peripheral component, performing a mutual authentication procedure between the secure microcircuit and a processor of a device in communication with the peripheral component, and if the mutual authentication is successful: transforming, by the microcircuit, a received command into a command executable by the control circuit, transmitting, by the microcircuit to the control circuit, the transformed command, and executing the transformed command by the control circuit.

[0010] According to one embodiment, the process includes steps consisting of: receiving, by the microcircuit, a command to be processed previously encrypted using a first encryption key, decrypting, by the microcircuit, the encrypted command, using a second encryption key, the encrypted command being correctly decrypted if the second encryption key corresponds to the first encryption key, and transmitting, by the microcircuit, the decrypted command to the circuit to be controlled of the peripheral organ.

[0011] According to one embodiment, the commands received by the peripheral organ are systematically deciphered by the microcircuit.

[0012] According to one embodiment, the first encryption key and the second encryption key are the same key of a symmetric encryption algorithm, or the first encryption key is a processor private key and the second encryption key is a public key forming with the private key a key pair of an asymmetric encryption algorithm, or the first encryption key includes a processor private key and a microcircuit public key, and the second encryption key includes a processor public key, forming with the processor private key a key pair of an asymmetric encryption algorithm, and a microcircuit private key forming with the microcircuit public key a key pair of an asymmetric encryption algorithm.

[0013] According to one embodiment, the process includes steps consisting of: encrypting, by the microcircuit, a state data of the circuit to be controlled, using a third encryption key, transmitting the encrypted state data to the processor, and receiving and decrypting, by the processor, the encrypted state data, using a fourth encryption key, the encrypted state data being correctly decrypted if the fourth encryption key corresponds to the third encryption key.

[0014] According to one embodiment, the third encryption key and the fourth encryption key are the same key of a symmetric encryption algorithm, or the third encryption key is a private key of the microcircuit and the fourth encryption key is a public key forming with the private key a key pair of an asymmetric encryption algorithm, or the third encryption key comprises a private key of the microcircuit and a public key of the processor, and the fourth encryption key comprises a public key of the microcircuit, forming with the private key of the microcircuit a key pair of an asymmetric encryption algorithm, and a private key of the processor, forming with the public key of the processor a key pair of an asymmetric encryption algorithm.

[0015] According to one embodiment, the peripheral component is a consumable, the process comprising steps consisting of: determining, by the microcircuit, whether a resource supplied by the peripheral component, of consumable type, is exhausted, and if the resource is determined to be exhausted, rejecting, by the microcircuit, a command to be processed intended for the control circuit of the peripheral component, aimed at using the resource.

[0016] According to one embodiment, the process includes steps consisting of: transmitting, by the processor to the microcircuit, a function in the form of executable code to be executed by the microcircuit, and executing, by the microcircuit, the received function.

[0017] Embodiments may also relate to a removable peripheral component comprising a control circuit capable of processing commands received from outside the peripheral component, and a peripheral component authentication microcircuit integrated into the peripheral component, the peripheral component being configured so that commands intended for the control circuit are intercepted by the microcircuit, the microcircuit being configured to: execute a mutual authentication procedure with a processor of a device, placed in communication with the microcircuit, and if the mutual authentication procedure is successful, transform a command received by the peripheral component into a command executable by the control circuit, and transmit the transformed command to the control circuit.

[0018] According to one embodiment, the microcircuit is configured to implement the previously defined process.

[0019] According to one embodiment, at least a part of the circuit to be controlled is enclosed in a secure space, under the supervision of the microcircuit, the microcircuit being configured to reject a command when an attack on the secure space is detected.

[0020] According to one embodiment, the microcircuit and at least part of the circuit to be controlled are combined within an integrated component.

[0021] According to one embodiment, a function normally executed by the device's processor is at least partially relocated to the microcircuit, the microcircuit then being configured to receive commands capable of triggering the at least partially relocated function.

[0022] Examples of embodiments of the invention will be described below, by way of non-limiting example, in relation to the accompanying figures, among which: there figure 1 is a schematic view of a conventional printer with one or more removable ink cartridges, the figure 2 is a schematic view of a control processor for a device associated with a conventional removable peripheral component, the figure 3 is a schematic view of a control processor for a device associated with a conventional removable peripheral component, according to one embodiment, the figures 4 et 5 schematically represent steps executed by the control processor and the microcircuit of the removable peripheral component, according to several embodiments.

[0023] There figure 1 represents a device 1 comprising a control processor DPR, and one or more removable peripheral components P1, P2. Device 1 can be a printer, a fragrance diffuser, a personal computer, a mobile phone, an electronic cigarette, etc. The peripheral component can be an ink cartridge, a refill of fragrance or spray liquid, a power supply battery, a connecting cable to an external device, external memory, headphones, a keyboard, etc.

[0024] The DPR processor typically includes a DMC processing unit, for example, a microprocessor or microcontroller, which manages the device's functions. The DMC can be connected to RAM and non-volatile MEM memory, for example, EEPROM (Electrically Erasable Programmable Read-Only Memory) or Flash memory. To authenticate a removable peripheral device P1, P2, the DMC processing unit is preferably configured to cooperate with an AMC microcircuit integrated into each device P1, P2 to be authenticated. The DMC can be connected to the peripheral device P1, P2 via an ADB bus and a CX connector. The ADB bus can be, for example, I2C, or a proprietary bus. The connection between the DMC and the AMC microcircuit can alternatively be wireless, such as RFID or radio.

[0025] There figure 2 This represents the DPR processor connected to a microcircuit AM1 of a removable peripheral component P1', according to a classic architecture. In this architecture, a portion W3 of the ADB bus links is connected to the AM1 microcircuit, and another portion W1, W2 of the ADB bus links is connected to one or more other ADV circuits of the peripheral component P1', for example, electromechanical circuits for producing ink jets in a printer ink cartridge. Once the DPR processor has authenticated the AM1 microcircuit, it directly controls the ADV circuit of the component P1'. Consequently, the program executed by the DPR processor can be easily modified to bypass the mutual authentication procedure with the AM1 microcircuit or to have the ADV circuit execute commands even if the authentication procedure has failed.

[0026] In practice, the DMC processing unit can include a microprocessor connected to a microcircuit that houses confidential data and cryptographic functions. The DMC unit can act as the master with respect to the AMC microcircuit, AM1.

[0027] The ADV circuit may include a control circuit for one or more valves or a pump in an ink cartridge ejection device or in a liquid or gas dispensing device for a perfume refill or e-cigarette refill. In the case of a power supply battery, the ADV circuit may include a battery charging control circuit and / or a circuit for supplying power from the battery cells. In the case of external memory (SD card - Secure Digital, USB flash drive - Universal Serial Bus), this circuit may include a clock circuit or a control signal generation or memory cell addressing circuit. In the case of a cable (e.g., a USB cable) carrying multiple electrical connections, the ADV circuit may include one or more switches (e.g., one or more transistors) interposed across the electrical connections.Thus, the ADV circuit can include a simple transistor or an electromechanical device controlled by a single signal from the AMC microcircuit.

[0028] There figure 3 represents the DPR processor connected to a peripheral device P1, according to one embodiment. The peripheral device P1 differs from the peripheral device P1' in that at least one W2 link of the ADB bus is not directly connected to the ADV circuit of the peripheral device, but via the AMC microcircuit integrated into the peripheral device. Thus, in order to directly control a portion of the ADV circuit of device P1, it is necessary to modify the routing of the electrical connections within device P1.

[0029] The identification of component P1 by the DMC unit can be performed using an identifier stored by the AMC microcircuit. Authentication of the peripheral component is ensured by a symmetric cryptographic function and a shared secret authentication data, or by an asymmetric cryptographic function and a private / public key pair certified by a common authority. To prevent unauthorized access to the secret data, the AMC microcircuit incorporates security features that depend on the techniques used to provide this protection and on cost constraints.

[0030] The connection between the DMC unit and the AMC microprocessor can be wired or wireless. In the latter case, device 1 and peripheral component P1 each include wireless transmission circuits connected respectively to the DMC unit and the AMC microcircuit.

[0031] There figure 4 represents steps executed by the DMC processing unit and the AMC microcircuit of a peripheral organ, for example P1. The figure 4 This also represents the ADV circuit to be controlled by the peripheral device, which is typically controlled directly by the DMC processing unit. During step S1, the DMC processing unit and the AMC microcircuit perform a mutual authentication procedure. Step S1 can be triggered by the power-up of device 1, and / or following the connection of peripheral device P1 to the DMC processing unit, for example. The DMC processing unit sends an authentication command and an authentication challenge (e.g., a randomly chosen number) to the AMC microcircuit of device P1. In the case of a symmetric infrastructure, the AMC microcircuit can send the authentication challenge in response, encrypted using a secret key SK shared with the DMC processing unit.The secret key SK can, for example, be obtained using a cryptographic key derivation function applied to an ID identifier of the AMC microcircuit and a master secret key, the derivation function and the master secret being known to both the DMC unit and the AMC microcircuit. The AMC microcircuit ID identifier can then be transmitted by the latter along with the encrypted challenge.

[0032] In the case of an asymmetric infrastructure, the AMC microcircuit can, for example, encrypt the received challenge with a private key SKA and send the resulting encrypted message to the DMC unit, along with the public key PKA associated with the private key SKA, possibly signed by a certificate issued by a trusted authority (for example, the manufacturer of device 1 and / or the peripheral component). The DMC unit verifies the received encrypted challenge by decrypting it using the public key PKA and comparing it to the challenge it sent to the AMC microcircuit. The DMC unit can also verify the authenticity of the public key PKA using the certificate. The AMC microcircuit is considered authentic if the decrypted challenge matches the challenge transmitted to the AMC microcircuit.If the DMC unit fails to authenticate the AMC microcircuit, the DMC unit may take any appropriate action, such as refusing to operate, operating in a degraded manner, and / or notifying the user.

[0033] The AMC microcircuit also requests authentication of the DMC unit, either in a similar or other manner. If authentication of the DMC unit fails, the AMC microcircuit may refuse to provide the information it contains, and / or reject all or part of the commands received, and / or take any other appropriate action.

[0034] In one embodiment, all commands received by peripheral device P1 and intended for the ADV circuit are intercepted by the AMC microcircuit. Therefore, the DMC unit cannot directly control the ADV circuit from peripheral device P1, but only through the AMC microcircuit. To this end, the DMC unit and the AMC microcircuit perform steps S2 to S5 to transmit a CMD command to the ADV circuit. In step S2, the DMC unit encrypts the CMD command using the SSK secret key or the SKD private key of the AMC microcircuit. In step S3, the resulting encrypted ECM command is transmitted to peripheral device P1. In step S4, the AMC microcircuit receives and decrypts the encrypted ECM command using the SSK secret key or the PKD public key. In step S5, the decrypted CMD command is transmitted by the AMC microcircuit to the ADV circuit.

[0035] Thus, only the AMC microcircuit can execute the CMD command by the ADV circuit. Without knowledge of the SSK secret key or the SKD private key, the DMC unit cannot encrypt the CMD command to be transmitted to the ADV circuit. If the CMD command is transmitted to the peripheral device P1 unencrypted, or encrypted using a different key, the AMC microcircuit will attempt to decrypt it with the SSK or PKD key, resulting in an invalid command for the ADV circuit. If the CMD command is transmitted correctly encrypted to the peripheral device P1, but the AMC microcircuit does not possess the corresponding SSK secret key or PKD public key for the SKD secret key used, the AMC microcircuit will be unable to decrypt the encrypted ECM command, and therefore cannot execute it through the ADV circuit.

[0036] According to one embodiment, the commands transmitted between the DMC unit and the AMC microcircuit are also encrypted using the AMC microcircuit's PKA public key, so that only the latter can decrypt them, using the SKA private key.

[0037] In one embodiment, the status data of peripheral device P1 is not transmitted directly from P1 to the DMC unit, but via the AMC microcircuit. To this end, the DMC unit and the AMC microcircuit perform steps S6 to S9 to transmit STS status data from peripheral device P1 to the DMC unit. In step S6, the AMC microcircuit receives STS status data from peripheral device P1, for example, following the transmission of a command sent to device P1. In step S7, the AMC microcircuit encrypts the STS status data using the AMC microcircuit's secret key SSK or private key SKA. In step S8, the resulting encrypted EST data is transmitted to the DMC unit. At step S9, the DMC unit receives and decrypts the EST encrypted data using the SSK secret key or the PKA public key corresponding to the SKA private key.

[0038] According to one embodiment, the STS state data transmitted between the AMC microcircuit and the DMC unit is also encrypted using the DMC unit's PKD public key, so that only the DMC unit can decrypt it using the SKD private key.

[0039] The AMC microcircuit can be configured to control the use of the peripheral component P1, based on executed CMD commands and / or STS status data. Thus, if component P1 is a consumable, the AMC microcircuit can monitor the depletion of the resource (ink, fragrance, etc.) supplied by the consumable and block its use when the resource is expected to be exhausted. In this way, it is possible to prevent the consumable from being refilled, especially with an unsuitable product.

[0040] In one embodiment, all or part of the sensitive control functions of the ADV circuit, normally executed by the DMC unit, are implemented by the AMC microcircuit. The DMC unit is configured to send commands to the microcircuit to trigger these functions. This transfer of functions to the AMC microcircuit leads to a modification of the set of commands that can be issued by the DMC unit to the peripheral device P1. Consequently, a conventional peripheral device (without the AMC microcircuit or with a microcircuit used only for peripheral device authentication) cannot operate with the DMC unit. In this case, it may not be necessary to encrypt the CMD commands issued by the DMC unit to the peripheral device P1.

[0041] According to an embodiment illustrated by the figure 5The DMC processing unit is configured to transmit the executable code of a function function (FCT) to the peripheral device P1, to be executed by the microcircuit AMC after the successful completion of the mutual authentication step S1. To this end, the DMC and the microcircuit AMC perform steps S11 through S15. In step S11, the DMC encrypts the executable code of the function FCT using the DMC's SSK secret key or SKD secret key. In step S12, the DMC transmits the encrypted EFT executable code to the microcircuit AMC. In step S13, the microcircuit AMC receives and decrypts the encrypted EFT executable code using the SSK key or the PKD public key corresponding to the SKD key. If the executable code of the FCT function has been successfully transmitted to the AMC microcircuit, and if the DMC unit and the AMC microcircuit have used corresponding keys to encrypt and decrypt this executable code, the microcircuit can perform the FCT function.In step S14, the AMC microcircuit executes the transmitted executable code from the FCT function. The execution of the FCT function produces one or more CMD commands, which are then transmitted to the ADV circuit (step S15). In step S16, the ADV circuit can respond by transmitting one or more STS status messages, which are also transmitted to the AMC microcircuit. These STS status messages can be processed by the microcircuit and retransmitted in a different format to the DMC unit. The messages transmitted to the DMC unit can also be encrypted by executing, for example, steps S6 to S9.

[0042] Therefore, to control a peripheral device that does not include the AMC microcircuit, it is necessary to extensively modify the program executed by the DMC unit. Similarly, the program executed by the DMC unit must be extensively adapted to the previously described characteristics of the peripheral device P1.

[0043] The DMC unit can be secured in a manner analogous to the AMC microcircuit, or it can be associated with a secure microcircuit that performs all or part of the cryptographic operations carried out with the AMC microcircuit, such as mutual authentication and encryption and decryption operations.

[0044] In one embodiment, all or part of the ADV circuit can be protected in a secure environment, for example by a mesh of conductive wires connected to the AMC microcircuit. The AMC microcircuit is then configured to detect any physical damage to this mesh and take appropriate action against such an attack, such as ceasing to execute all or part of the received commands.

[0045] In one embodiment, the ADV circuit includes a MEMS (MicroElectroMechanical System) integrated component, and the AMC microcircuit is integrated within this component. Thus, the AMC microcircuit and the component form a secure unit that is very difficult to modify, for example, to directly control the component without using the AMC microcircuit.

[0046] It will be readily apparent to those skilled in the art that the present invention is susceptible to various embodiments and applications. In particular, the invention is not limited to encrypting commands issued by the DMC unit. It is essential that these commands differ in form from the commands that can be processed by the ADV circuit of the peripheral device, the AMC microcircuit being configured to transform the received commands into commands executable by the ADV circuit. As previously mentioned, transferring functions normally performed by the DMC unit to the AMC microcircuit requires modifying the set of commands that can be transmitted from the DMC unit to the AMC microcircuit. Thus, if the peripheral device associated with apparatus 1 does not include the AMC microcircuit, it is necessary to extensively modify the program executed by the DMC unit so that it issues the commands expected by the ADV circuit.If the DMC unit is secured or associated with a secure element, the program loaded into the DPR processor can be secured, for example, by means of a signature on the executable program, calculated using an encryption key from the device manufacturer, so that the program cannot be modified by an unauthorized person. If the secure element of device 1 does not authenticate the program executed by the DMC unit, the secure element can take any appropriate action, such as blocking the use of the device.

[0047] Nor is it necessary for all commands that can be transmitted to the peripheral device P1 to be transformed or encrypted; some of these commands can be directly retransmitted to the ADV circuit by the AMC microcircuit without prior transformation. Thus, commands transmitted without transformation to the ADV circuit can, for example, be secondary commands not required for the execution of a primary function of the peripheral device P1.

[0048] Furthermore, the CMD command transmitted to the ADV circuit may include one or more digital or analog signals, adapted to control the ADV circuit.

Claims

1. A method of controlling a removable peripheral device, comprising: intercepting, by a secure microcircuit (AMC) internal to the peripheral device (P1), a command received by the peripheral device and intended to be executed by a circuit to be controlled (ADV) of the peripheral device, the command being encrypted using a first encryption key (SSK, SKD), performing a mutual authentication procedure between the secure microcircuit and a processor (DMC) of a device (1) in communication with the peripheral device, and if the mutual authentication succeeds: transforming, by the microcircuit, the received command into a command (CMD) executable by the circuit to be controlled, said transformation comprising a decryption of the encrypted command using a second encryption key (SSK, PKD), the encrypted command being correctly decrypted if the second encryption key corresponds to the first encryption key, transmitting, by the microcircuit to the circuit to be controlled, the decrypted command, and executing the decrypted command by the circuit to be controlled.

2. The method of claim 1, wherein commands (ECM) received by the peripheral device (P1) are systematically decrypted by the microcircuit (AMC).

3. The method of claim 1 or 2, wherein: the first encryption key and the second encryption key are one and the same key (SSK) of a symmetric encryption algorithm, or the first encryption key is a private key (SKD) of the processor (DMC) and the second encryption key is a public key (PKD) forming with the private key a key pair of an asymmetric encryption algorithm, or the first encryption key comprises a private key (SKD) of the processor (DMC) and a public key (PKA) of the microcircuit (AMC), and the second encryption key comprises a public key (PKD) of the processor, forming with the private key of the processor a key pair of an asymmetric encryption algorithm, and a private key (SKA) of the microcircuit forming with the public key of the microcircuit a key pair of an asymmetric encryption algorithm.

4. The method of any of claims 1 to 3, further comprising: encrypting, by the microcircuit (AMC), status data (STS) of the circuit to be controlled (ADV), using a third encryption key (SSK, SKA), transmitting the encrypted status data (EST) to the processor (DMC), and receiving and decrypting, by the processor, the encrypted status data, using a fourth encryption key (SSK, PKA), the encrypted status data being correctly decrypted if the fourth encryption key corresponds to the third encryption key.

5. The method of claim 4, wherein: the third encryption key and the fourth encryption key are one and the same key (SSK) of a symmetric encryption algorithm, or the third encryption key is a private key (SKA) of the microcircuit (AMC) and the fourth encryption key is a public key (PKA) forming with the private key a key pair of an asymmetric encryption algorithm, or the third encryption key comprises a private key (SKA) of the microcircuit (AMC) and a public key (PKD) of the processor (DMC), and the fourth encryption key comprises a public key (PKA) of the microcircuit, forming with the private key of the microcircuit a key pair of an asymmetric encryption algorithm, and a private key (SKD) of the processor, forming with the public key of the processor a key pair of an asymmetric encryption algorithm.

6. The method of any of claims 1 to 5, wherein the peripheral device (P1) is a consumable, the method further comprising: determining, by the microcircuit (AMC), whether a resource supplied by the peripheral device, of consumable type, is exhausted, and if the resource is determined to be exhausted, rejecting, by the microcircuit, a command to be processed (CMD) intended for the circuit to be controlled (ADV) of the peripheral device, directed at using the resource.

7. The method of any of claims 1 to 6, further comprising: transmitting, by the processor (DMC) to the microcircuit (AMC), a function (FCT) in the form of executable code to be executed by the microcircuit, and executing, by the microcircuit, the received function.

8. A removable peripheral device comprising a circuit to be controlled (ADV) capable of processing commands (CMD) received from outside the peripheral device, and a microcircuit (AMC) for authenticating the peripheral device, characterized in that the microcircuit is integrated in the peripheral device and the peripheral device (P1) is configured such that all commands (CMD) intended for the circuit to be controlled (ADV) are intercepted by the microcircuit (AMC), the microcircuit being configured to: perform a mutual authentication procedure with a processor (DMC) of a device (1) in communication with the microcircuit, and if the mutual authentication procedure succeeds, transform a command (ECM) received by the peripheral device in encrypted form into a decrypted command executable by the circuit to be controlled, and transmit the decrypted command to the circuit to be controlled, the microcircuit (AMC) being configured to implement the method of any of claims 1 to 7.

9. The peripheral device of claim 8, wherein at least a part of the circuit to be controlled (ADV) is enclosed in a secure environment, under the supervision of the microcircuit (AMC), the microcircuit being configured to reject a command (ECM) when a breach of the secure environment is detected.

10. The peripheral device of claim 8 or 9, wherein the microcircuit (AMC) and at least a part of the circuit to be controlled (ADV) are associated together within an integrated component.

11. The peripheral device of any of claims 8 to 10, wherein a function normally performed by the processor (DMC) of the device (1) is at least partially offloaded to the microcircuit (AMC), the microcircuit being configured to receive commands capable of triggering the at least partially offloaded function.

12. The peripheral device of any of claims 8 to 11, wherein at least one link (W2) of a command transmission bus (ADB) between an input of the peripheral device and the circuit to be controlled (ADV) passes through the microcircuit (AMC).