SECURE START OF A PROCESSING UNIT
Patent Information
- Application Number
- DE602022021023
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-03-31
- Filing Date
- 2022-03-28
- Publication Date
- 2025-09-10
- Estimated Expiration
- 2042-03-28
AI Technical Summary
Existing methods for securing the startup of processing devices do not adequately protect access to startup codes and sensitive data, such as encryption keys, during the initialization phase.
A method and device utilizing a monotonic counter to generate and increment count values, controlling access to memory areas based on these values, ensuring that only authorized data and codes are read and executed at specific stages of the startup process, thereby enhancing security.
The solution provides robust protection for startup codes and sensitive data by preventing unauthorized access and execution, adapting to various boot architectures, and ensuring secure initialization.
Description
Technical field
[0001] The present description relates to the field of methods and devices for the security of electronic circuits, and in particular a device and a method for carrying out a secure start-up of such a circuit. Prior art
[0002] The startup of a processing device is based on the execution of codes such as software and / or firmware codes. The startup sequence of a device is a sensitive step in terms of security, as it generally involves the adjustment of parameters related to the security of the device and / or the processing of sensitive data in terms of confidentiality, integrity and authenticity such as encryption keys.
[0003] Although solutions exist to make startup codes immutable, it would be desirable to further protect access to these codes and sensitive data when starting a processing device.
[0004] Document US 2014 / 310535 describes an electronic device with a FLASH memory component. Document US 2006 / 090084 describes a secure processing environment. Document WO 2019 / 239121 describes a key protection device. Summary of the invention
[0005] There is a need to improve the security of start-up procedures for treatment devices.
[0006] One embodiment overcomes all or part of the drawbacks of known treatment devices.
[0007] One embodiment provides a method of starting a processing device, the method comprising: generating, by a monotonic counter and during a first start-up phase, a first count value; transmitting, by the monotonic counter, the first count value to a memory access control circuit; reading, on the basis of the first count value, first data associated with the first start-up phase and stored in the memory, the first data comprising first start-up codes; executing the first start-up codes, the first start-up codes comprising an instruction to increment the monotonic counter to a second count value greater than the first count value;and - the generation, by said counter and during a second start-up phase, of the second counting value greater than the first counting value, the memory access control circuit being configured so that the reading of the first data is not authorized on the basis of the second counting value.;
[0008] According to one embodiment, the memory is a volatile memory.
[0009] According to one embodiment, the memory is a non-volatile memory.
[0010] According to one embodiment, the memory access control circuit is configured such that reading of the first data is not permitted based on a count value greater than the first count value.
[0011] According to one embodiment, the method further comprises reading, based on the first count value, second data stored in the memory and associated with the second start phase.
[0012] According to one embodiment, the method further comprises: transmitting, by the monotonic counter, the second count value to the memory; and reading second and / or third data stored in the memory based on the second count value.
[0013] According to one embodiment, the first count value corresponds to an initialization value of the monotonic counter during a first start-up of the processing device comprising the first and second start-up phases, the method further comprising a second start-up of the processing device during which the monotonic counter is initialized to the second count value.
[0014] According to one embodiment, the method further comprises another startup of the processing device, after the first and second startups, during which the monotonic counter is initialized again to the first count value if a condition on the state of the device is satisfied.
[0015] According to one embodiment, the condition on the state of the processing device corresponds to the programming state of one or more bits stored non-volatilely in an area of the memory or other memory.
[0016] According to one embodiment, the method further comprises, before generating the second count value, reading, based on the first count value, one or more first encryption keys stored in the memory, the memory access control circuit being configured such that reading of the first encryption keys is not authorized based on a count value greater than the first count value.
[0017] According to one embodiment, the method further comprises, after generating the second count value, reading based on the second count value one or more second encryption keys stored in the memory.
[0018] One embodiment provides a data processing device comprising: a monotonic counter configured to generate a first count value; and a memory comprising an access control circuit and containing first data associated with a first phase, the access control circuit being configured to: authorize reading, based on the first count value, of the first data, the first data comprising first start codes; authorize execution, based on the first count value, of the first start codes, the first start codes comprising an instruction to increment the monotonic counter to a second count value greater than the first count value; and not authorize reading of the first data based on the second count value. Brief description of the drawings
[0019] These and other features and advantages will be set forth in detail in the following description of particular embodiments given without limitation in relation to the attached figures, among which: there figure 1 represents, very schematically and in the form of blocks, an embodiment of a processing device according to an embodiment of the present description; figure 2 represents data and codes accessible during a secure boot according to an embodiment of the present description; the figure 3 is a flowchart representing operations of a method for secure startup of a processing device according to an exemplary embodiment of the present description; and the figure 4 is a flowchart representing operations of a method for securely booting a processing device according to another exemplary embodiment of the present description. Description of the embodiments
[0020] The same elements have been designated by the same references in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same references and may have identical structural, dimensional and material properties.
[0021] For the sake of clarity, only the steps and elements useful for understanding the described embodiments have been shown and are detailed. In particular, the design of processing devices is well known to those skilled in the art and certain elements have not been detailed in the following description.
[0022] Unless otherwise specified, when referring to two elements connected together, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") together, this means that these two elements can be connected or be connected by means of one or more other elements.
[0023] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made unless otherwise specified to the orientation of the figures.
[0024] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "of the order of" mean to within 10%, preferably to within 5%.
[0025] There figure 1 represents, very schematically and in the form of blocks, an electronic device 100 comprising a processing device 102 according to an embodiment of the present description.
[0026] The electronic device 100 is for example an electronic card such as a microcircuit card, hardware for computer use, a microprocessor circuit, etc.
[0027] The processing device 102 comprises, for example, a non-volatile memory 104 (NV MEM), for example a flash memory. The memory 104 comprises an access control interface 108 (ACCES CONTROL) connected to a monotonic counter 106 (MONOTONIC COUNTER).
[0028] Monotonic counters are known in the prior art, an example of such a counter being described in the publication "Virtual Monotonic Counters and Count-Limited Objects using a TPM without a Trusted OS" by LFG Sarmenta, M. Van Dijk, CW O'Donnell, J. Rhodes and S. Devadas, and in particular in part 3 of this document. This document describes implementations of counters implemented in hardware and / or software. The monotonic counter 106 is for example implemented in hardware by a digital circuit, such as a custom integrated circuit (ASIC, from the English "Application Specific Integrated Circuit"). The monotonic counter is configured to maintain a count value, accessible on an output of the counter. Following an increment command, the monotonic counter increases its count value by one or more units but, following each increment, the operation is not reversible.In fact, the monotonic counter is configured so that its count value never decreases. In addition, between two increments, the count value is, for example, protected against any modifications, so that it cannot be erased or changed. Only the increment command allows the current value to be replaced by a new value greater than the current value.
[0029] The monotonic counter 106 is configured so that no command, apart from a reset of the processing device, allows returning to the previous value once the increment command has been executed. In the case where the counting value is stored in a volatile manner, each time the processing device is powered down, the counting value is lost and each time the device is powered up again, the monotonic counter generates an initial counting value again. In the case where the counting value is stored in a non-volatile storage element, at each restart, an initial counting value is for example rewritten in the non-volatile storage element of the monotonic counter.
[0030] The processing device 102 further comprises a generic processor 110 (CPU). For example, the generic processor 110 is coupled via a bus 116 to the monotonic counter 106 as well as to a RAM (random access memory) 112 and to the non-volatile memory 104. The memory 112 and / or the memory 104 stores, for example, instructions for controlling the processor 110. The generic processor 110 is further coupled via the bus 116 to a cryptographic processor 114 (CRYPTO). The cryptographic processor 114 receives, via the bus 116, encrypted data and returns the decrypted data and / or receives, via the bus 116, unencrypted data and returns the encrypted data.
[0031] Non-volatile memory stores, for example, several boot codes and / or other data, which are associated with several TIL (temporal isolation level) isolation levels. Boot codes are, for example, software and / or firmware codes. In the example of the figure 1 , the non-volatile memory 104 comprises a first area 118 in which a first start code and / or first data (CODE0) are stored. The memory 104 further comprises a second area 120, in which a second start code and / or second data (CODE1) are stored, as well as a third area 122 in which a third start code and / or third data (CODE2) are stored. The first, second and third start codes and / or data are for example associated with three corresponding TIL isolation levels. Although the case of three sets of data is illustrated in the figure 1, in other embodiments, the non-volatile memory 104 may store only two sets of data, or more than three sets of data, in corresponding areas. For example, the first, second, and third data include first, second, and third startup codes.
[0032] The TIL isolation level depends on the count value generated by the monotonic counter 106. In one example, the TIL value is equal to the count value of the monotonic counter 106, although it would be possible to modify the count value in order to generate the TIL value.
[0033] During a startup, the reading of the first, second and third codes and / or data and / or the execution of the first, second and third startup codes are performed in stages, each stage being associated with a corresponding isolation level. The access control circuit 108 of the memory 104 is configured so that the reading of these codes / data is controlled according to the isolation level of the stage. The first data and / or the first code are for example associated with the isolation level, or TIL value, 0 and the access control circuit 108 is configured so that these data and / or codes are only accessible for reading when the current TIL count value is equal to 0. When the count value is incremented, for example following the execution of the first code, the access control circuit 108 locks the area 118, the first data and / or the first code are then no longer accessible for reading.Following an increment, the current count value changes to 1, for example, and the data and / or start codes associated with isolation level 1, for example the second start code, are executed.
[0034] In some cases, the access control circuit 108 is configured to allow the reading of one or more data associated with isolation levels higher than that of the current TIL value. The lower the isolation level, the greater the protection level. Isolation level 0 is therefore the level providing the most protection, because the corresponding data can be read only when the count value is equal to 0. Thus, each isolation level corresponds to a level of protection of the contents of the memory areas associated with it.
[0035] The access control mechanism implemented by circuit 108 can be implemented in several ways.
[0036] In a first example, when the circuit 108 receives a read request associated with one or more addresses in the memory 104, it is configured to compare this / these address(es) to the address ranges associated with the areas 118, 120, 122 of the memory 104. If it is an address in an area associated with a TIL value lower than the current value, the circuit 108 is for example configured to block the read operation.
[0037] In a second example, the circuit 108 is configured to disable a read circuit of any area 118, 120, 122 of the memory 104 associated with a TIL value less than the current value. For example, one or more logic gates, such as OR gates or AND gates, are coupled into the output path of each area 118, 120, and 122 of the memory 104 and also receive an enable signal generated based on the TIL value to selectively disable each output path.
[0038] The fact that the count value cannot be decremented during the operating period of the device 100 allows the protection of the start-up codes once they have been executed, because the access control circuit 108 prevents the reading of data and / or the execution of codes associated with TIL isolation levels lower than the current level.
[0039] In some embodiments, one or more of the data and / or startup codes and the associated isolation levels are reserved for parameterization phases of the device 102 or for separate entities in the chain from the manufacturer to the end user. For example, an intermediate entity between the manufacturer of the processing device and the end user of the electronic device 100 may be required to install data and / or startup codes that are specific to the use of the device 100. In this case, one or more of the “lowest” data and / or startup codes, for example associated with isolation level 0, are for example reserved for the manufacturer of the processing device 102, and other data and / or startup codes are reserved for the intermediate entity.
[0040] The contents of the memory areas 118, 120, and 122 include, in some embodiments, other data in addition to the startup codes of the processing device. For example, other privacy-sensitive data is stored in association with at least one of the first, second, and third codes and / or data. For example, this other data includes encryption keys used when executing the startup codes associated with it. In the example of the figure 2, memory areas 200, 202 and 204 store sensitive data associated respectively with the start codes 118, 120 and 122 stored in the non-volatile memory 104. The areas 200, 202 and 204 are for example areas distinct from the areas 118, 120 and 122, but remain associated with an isolation level corresponding to that of the start codes to which the data are linked. This sensitive data includes for example one or more encryption keys stored in each area 200, 202 and 204 and each of these areas is contained in the non-volatile memory 104. According to another embodiment, each area 200, 202 and 204 is a sub-area of the corresponding area 118, 120 and 122.
[0041] There figure 2 represents data and codes accessible during a secure boot according to an embodiment of the present description.
[0042] During a first step 210 of starting the processing device illustrated at the top of the figure 2 , the current count value is for example equal to 0. In the example of the figure 2 , an isolation level 0 is associated with a first code (CODE0) as well as with first sensitive data (KEY0). The access control circuit 108 is configured, for example, so that this first code and this first data are exclusively accessible when the current count value is equal to 0. However, during step 210, the access control circuit authorizes for example access to all the memory areas 200, 202 and 204, as well as to all the areas 118, 120 and 122. Indeed, in certain cases, in order for example to anticipate subsequent steps in the startup method, one or more of the other startup codes CODE1, CODE2 are accessible for reading during step 210.
[0043] For example, once the first code (CODE0) is executed, the generic processor 110 commands a first increment of the current count value by the monotonic counter 106. For example, the first code includes a command requesting the incrementation of the counter. This command is for example transmitted to a control register (not shown) of the monotonic counter.
[0044] After this first incrementation, the current count value of the monotonic counter 106 is for example equal to 1, corresponding to the second step 211 of the start. The access control circuit 108 receives the new current count value, and is configured to prevent, on the basis of this count value greater than 0, any access to the first code as well as to the first data which are associated with the isolation level 0. In other words, the memory areas 118 and 200 are locked on the basis of any count value strictly greater than 0.
[0045] Isolation level 1 is associated with a second code (CODE1) contained in zone 120 as well as with second data (KEY1) contained in zone 202. According to one embodiment, the third code (CODE2), for example associated with isolation level 2 and contained in zone 122, is accessible for reading on the basis of the current count value equal to 1.
[0046] For example, once the second code (CODE1) is executed, the generic processor 110 commands a second incrementation of the current count value by the monotonic counter 106. For example, after this second incrementation, the current count value of the monotonic counter 106 is equal to 2, corresponding to the third step 212 of the start. The isolation level 2 is associated with the third code (CODE2) as well as with third data (KEY2). The access control circuit 108 receives the new count value, and is configured to prevent, on the basis of this count value greater than 1, any access to the first and second codes as well as to the first and second data which are associated with the isolation levels less than or equal to 1.
[0047] According to one embodiment, when the last start code is executed, for example the third start code, the generic processor 110 commands a third incrementation of the current count value by the monotonic counter. The access control circuit 108 then locks all access to the first, second and third start codes as well as to the first, second and third data.
[0048] According to another embodiment, when the last start code is executed, for example the third start code, the current count value is not incremented by the monotonic counter 106 and access to the third start code as well as to the third data remains authorized by the access control circuit.
[0049] There figure 3is a flowchart representing operations of a secure startup method of a processing device according to an exemplary embodiment of the present description. This method is implemented for example by the generic processor 110, the monotonic counter 106 and the access control circuit 108, of the processing device of the figure 1 .
[0050] In a step 301 (LAUNCH BOOT SEQUENCE) the processing device 102 starts. In one example, this is the first start-up of the device 102 after its production. In another example, this is a start-up performed by an intermediary entity between the manufacturer of the device 102 and its end user. In yet another example, this is a so-called operational start-up of the electronic device 100 performed by the end user.
[0051] In a step 303 (INITIALIZE COUNTER), subsequent to step 301, the monotonic counter is initialized to an initial value, being a natural integer. In the example in which the counting value is stored in a volatile manner, each power-up of the processing device causes the initialization of the counting value, for example to 0 or 1. In another example in which the counting value is stored on non-volatile storage elements, each power-up of the processing device causes the current counting value to be replaced by the initial counting value, for example equal to 0 or 1.
[0052] In some embodiments, the initial count value generated following a power-up may vary depending on the state, or context, of the processing device 102. For example, one or more count values correspond to one or more isolation levels reserved for an initial parameterization phase of the device 102, including for example the installation of firmware. The data and / or codes associated with these isolation levels are for example used for this initial parameterization.
[0053] For example, following manufacturing, the processing device 102 has the "blank" context and the initial count value is equal to a value reserved for parameterization, such as 0. Once parameterization is complete, the context of the device becomes, for example, "parameterization complete". With this new context, powering up the device 102, performed for example by an intermediate entity between the manufacturer and the end user and / or by the end user, will then trigger a count value greater than the reserved count value, and for example equal to 1. The startup code(s), as well as the sensitive data, associated with the isolation level corresponding to the reserved count value will, consequently, be inaccessible.
[0054] For example, the context of the device is detected by the presence of a voltage on a start pin of the device, this voltage being applied for example by the addition of a jumper between the start pin and another pin at a supply voltage. In addition or alternatively, the context of the device is detected by the value of one or more bits stored in a non-volatile and protected manner in the memory 104, or in another memory.
[0055] In one example, the generic processor 110 is arranged to detect the context of the device 102 when the device 102 is powered on, and to configure the initial count value of the monotonic counter 106 accordingly. In another example, the monotonic counter 106 is arranged to itself detect the context of the device 102 and to configure its initial count value itself, when the device 102 is powered on.
[0056] In a step 305 (READ AND EXECUTE CODE ON LEVEL i), subsequent to step 303, the data and the start codes associated with the isolation level i are read by the generic processor 110 and the start codes associated with the isolation level i are executed. Once the codes of the level i have been executed, the generic processor 110 compares, in a step 307 (i=N?), the count value i with the value N, N being the count value associated with the last step in the start sequence, in other words the start codes of the isolation level N are the last to be executed according to the embodiment of the present description. For example, in the example of the figure 2, N is equal to 2. If i is not equal to N (branch N), the method continues in a step 309 (i=i+1) in which the generic processor triggers the incrementation of the count value. For example, the count value goes from i to i+1. It is also possible that the incrementation increases the count value by several units. The method then resumes at step 305.
[0057] In the case where, following the comparison step 307, the count value is equal to N (Y branch), the method ends in a step 311 (END OF BOOT) in which the startup of the processing device ends. According to one embodiment, the current count value remains equal to N following step 311. According to another embodiment, the count value is incremented during step 311, and the current count value becomes equal to N+1. In this second case, the access control circuit is then configured to prevent any access to all the startup codes on the basis of this count value.
[0058] There figure 4is a flowchart representing operations of a secure startup method of a processing device according to another exemplary embodiment of the present description. This method is implemented for example by the generic processor 110, the monotonic counter 106 and the access control circuit 108, of the processing device of the figure 1 .
[0059] Steps 401 and 403 are similar to steps 301 and 303 of the figure 3 , and will not be described again in detail.
[0060] In a step 405 (ACCESS CODE ON LEVELS i AND i+1, EXECUTE CODE ON LEVEL i), subsequent to step 403, the data and the start codes associated with the isolation levels i+1 are accessible by the generic processor 110 and the start code(s) associated with the isolation level i are executed.
[0061] In one example, the data or codes associated with isolation level i contain one or more encryption keys, encrypted or not, which will be used during the execution of one or more codes associated with isolation level i+1. Thus, write access is for example authorized on the memory area(s) associated with isolation level i+1 in order to provision the keys to the codes associated with isolation level i+1.
[0062] In another example, the codes associated with isolation level i contain instructions for verifying the integrity of the data and / or codes associated with isolation level i+1. Thus, read access to the memory area(s) associated with isolation level i+1 is authorized in order to perform this verification.
[0063] In a step 407 (i=i+1), subsequent to step 405, the count value is incremented. For example, the count value goes from i to i+1. In other examples, the increment increases i by several units.
[0064] In a step 409 (i=N?) the generic processor 110 compares the count value i to the value N, where N is defined as described in relation to step 307 of the figure 3 . If the value i is not equal to N (branch N) the process returns to step 405.
[0065] In the case where, during the comparison step 409, the count value is equal to N (branch Y), the method continues to a step 413 (EXECUTE CODE ON LEVEL N) in which the start code(s) associated with the isolation level N are executed.
[0066] The startup of the processing device ends with a step 415 (END OF BOOT), which is similar to step 311 of the figure 3 , and is not described again in detail.
[0067] The process whose implementation is presented by the figure 4 allows for offset reading of start codes. In fact, the start codes associated with an insulation level are read when the count value is lower than the level value. This saves time compared to implementing the method presented in the figure 3 .
[0068] An advantage of the described embodiments is that startup codes, as well as privacy-sensitive data, are significantly protected by the use of a monotonic counter to lock access to codes and / or data.
[0069] Another advantage of the described embodiments is that it is easily adaptable to several boot architectures.
[0070] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will occur to those skilled in the art. In particular, different types of processors may be used. In addition, the number of isolation levels may vary.
[0071] Finally, the practical implementation of the embodiments and variants described is within the reach of those skilled in the art from the functional indications given above.
Claims
1. A method for booting a processing device (102), the method comprising: - the generation, by a monotonic counter (106) and during a first boot phase, of a first count value; - the transmission, by the monotonic counter, of the first count value to an access control circuit (108) of a memory (104); - the reading, based on the first count value, of first data values (118) associated to the first boot phase and stored in the memory, the first data values comprising first boot codes; - the execution of the first boot codes, the first boot codes comprising an instruction to increment the monotonic counter to a second count value greater than the first count value; - the generation, by the said counter and during a second boot phase, of the second count value, the access control circuit (108) of the memory (104) being configured so that the reading of the first data values is not authorized based on the second count value.
2. The method according to claim 1, wherein the memory (104) is a volatile memory.
3. The method according to claim 1, wherein the memory (104) is a non-volatile memory.
4. The method according to any one of claims 1 to 3, wherein the access control circuit (108) of the memory (104) is configured such that reading of the first data values (118) is not authorized based on a count value greater than the first count value.
5. The method according to any one of claims 1 to 4, further comprising the reading, based on the first count value, of second data values (120) stored in the memory (104) and associated with the second boot phase.
6. The method according to any one of claims 1 to 5, further comprising: - the transmission, by the monotonic counter (106), of the second count value to the memory (104); and - the reading of second and / or third data values (120, 122) stored in the memory (104) based on the second count value.
7. The method according to any one of claims 1 to 6, wherein the first count value corresponds to an initialization value of the monotonic counter (106) during a first boot of the processing device (102), the method further comprising a second boot of the processing device during which the monotonic counter is initialized to the second count value.
8. The method according to claim 7, comprising a further boot of the processing device (102), after the first and second boots, during which the monotonic counter (106) is initialized again to the first count value if a condition on the state of the device is satisfied.
9. The method according to claim 8, wherein the condition on the state of the processing device corresponds to the programming state of one or more bits stored in a non-volatile manner in an area of the memory (104) or of another memory.
10. The method according to any one of claims 1 to 9, further comprising, before the generation of the second count value, the reading, based on the first count value, of one or more first encryption keys (200) stored in the memory (104), the access control circuit (108) of the memory being configured such that reading of the first encryption keys is not authorized based on a count value greater than the first count value.
11. The method according to claim 10, further comprising, after the generation of the second count value, the reading based on the second count value of one or more second encryption keys (202) stored in the memory.
12. A data processing device (102) comprising: - a monotonic counter (106) configured to generate a first count value; and - a memory (104) comprising a control access circuit (108) and containing first data values associated to a first boot phase, the control access circuit being configured to: - authorize the reading, based on the first count value, of the first boot codes, the first boot codes comprising an instruction to increment the monotonic counter to a second count value greater then the first count value (118); and - not authorize the reading of the first data values based on the second count value.