Safe startup of a processing unit

A monotonic counter-based method controls access to startup codes and data in stages, addressing security gaps in existing startup processes by ensuring codes and data are only accessible at increasing isolation levels, thus enhancing security and integrity.

FR3121526B1Active Publication Date: 2025-10-31STMICROELECTRONICS (ALPS) SAS +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2021003313
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-03-31
Publication Date
2025-10-31
Estimated Expiration
2041-03-31

AI Technical Summary

Technical Problem

Existing methods for starting up processing devices do not adequately protect access to startup codes and sensitive data during the initialization phase, which is critical for security and confidentiality.

Method used

A method utilizing a monotonic counter to generate and manage counting values that control access to memory areas, ensuring that startup codes and data are read and executed in stages based on increasing isolation levels, with access control circuits preventing access based on count values, thereby enhancing security.

Benefits of technology

The solution provides robust protection for startup codes and sensitive data by ensuring they are only accessible at specific stages, enhancing the security and integrity of the startup process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000016_0000
    Figure 00000016_0000
  • Figure 00000017_0000
    Figure 00000017_0000
  • Figure 00000018_0000
    Figure 00000018_0000
Patent Text Reader

Abstract

Secure Startup of a Processing Unit This description relates to a method for starting a processing device (102), the method comprising: - the generation (303), by a monotonic counter and during a first startup phase, of a first count value; - the transmission, by the monotonic counter, of the first count value to a memory access control circuit; - the reading (305), based on the first count value, of the first data stored in the memory; - the generation (309), by said counter and during a second startup phase, of a second count value greater than the first count value, the memory access control circuit (104) being configured so that the reading of the first data is not permitted based on the second count value. Figure for the abbreviation: Fig. 3
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Safe startup of a processing unit technical field

[0001] This description relates to the field of methods and devices for the safety of electronic circuits, and in particular a device and a method for performing a safe start-up of such a circuit. Previous technique

[0002] The startup of a processing device is based on the execution of code such as software and / or firmware. The startup sequence of a device is a sensitive step in terms of security, as it generally involves setting parameters related to the device's security and / or processing sensitive data in terms of confidentiality, integrity, and authenticity, such as encryption keys.

[0003] Although solutions exist to make startup codes immutable, it would be desirable to further protect access to these codes and sensitive data when starting a processing device. Summary of the invention

[0004] There is a need to improve the security of the procedures for starting up treatment devices.

[0005] An embodiment overcomes all or part of the drawbacks of known treatment devices.

[0006] One embodiment provides a method for starting a treatment device, the method comprising: - the generation, by a monotonic counter and during a first start-up phase, of a first counting value; - the transmission, by the monotonic counter, of the first counting value to a memory access control circuit; - reading, based on the first count value, the first data stored in memory; - the generation, by said counter and during a second start-up phase, of a second count value greater than the first count value, the memory access control circuit being configured so that the reading of the first data is not allowed on the basis of the second count value.

[0007] According to one embodiment, the first data includes first start codes.

[0008] According to one embodiment, the first startup codes are executed before the generation, by the monotone counter, of the second count value, the first start-up codes including an instruction to increment the monotone counter to cause the generation of the second count value.

[0009] According to one embodiment, the memory is a volatile memory.

[0010] According to one embodiment, the memory is a non-volatile memory.

[0011] According to one embodiment, the memory access control circuit is configured so that reading the first data is not allowed based on a count value greater than the first count value.

[0012] According to one embodiment, the method further comprises reading, on the basis of the first count value, second data stored in memory and associated with a second start-up phase.

[0013] According to one embodiment, the method further comprises: - the transmission, via the monotonic counter, of the second counting value to memory; and - reading second and / or third data stored in memory based on the second count value.

[0014] According to one embodiment, the first counting value corresponds to an initialization value of the monotonic counter during a first start of the processing device, the method further comprising, a second start of the processing device during which the monotonic counter is initialized to the second counting value.

[0015] According to one embodiment, the method further comprises another start of the processing device, after the first and second starts, during which the monotonic counter is initialized again to the first counting value if a condition on the state of the device is satisfied.

[0016] According to one embodiment, the condition on the state of the processing device corresponds to the programming state of one or more bits stored non-volatilely in a memory area or another memory.

[0017] According to one embodiment, the method further comprises, before the generation of the second count value, reading, on the basis of the first count value, one or more first encryption keys stored in memory, the memory access control circuit being configured so that reading the first encryption keys is not allowed on the basis of a count value greater than the first count value.

[0018] According to one embodiment, the method further comprises, after the generation of the second count value, reading on the basis of the second count value one or more second encryption keys stored in memory.

[0019] One embodiment provides a data processing device comprising: - a monotonic counter configured to generate a first counting value; And - a memory comprising an access control circuit and containing an initial startup code, the access control circuit being configured to: - read the initial data based on the first count value; and - do not allow the reading of the first data based on a second count value generated by the monotonic counter and greater than the first count value. Brief description of the drawings

[0020] These features and advantages, as well as others, will be described in detail in the following description of particular embodiments, given by way of non-limiting example, in relation to the accompanying figures, among which:

[0021] [Fig.1] represents, in a very schematic way and in block form, an embodiment of a processing device according to an embodiment of the present description;

[0022] [Fig.2] represents data and codes accessible during a secure boot according to an embodiment of the present description;

[0023] [Fig. 3] is a flowchart representing the operations of a safe start-up process for a processing device according to an example of an embodiment of this description; and

[0024] [Fig.4] is a flowchart representing operations of a safe start-up process of a processing device according to another embodiment of the present description. Description of the implementation methods

[0025] The same elements have been designated by the same reference numerals in the different figures. In particular, structural and / or functional elements common to the different embodiments may have the same reference numerals and may have identical structural, dimensional and material properties.

[0026] For the sake of clarity, only the steps and elements necessary for understanding the described embodiments have been shown and detailed. In particular, the design of processing devices is well known to those skilled in the art, and certain elements have not been detailed in the following description.

[0027] Unless otherwise specified, when referring to two interconnected elements, this means directly connected without any intermediate elements other than conductors, and when referring to two coupled elements, this means that these two elements can be connected or linked by through one or more other elements.

[0028] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "superior", "inferior", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made, unless otherwise specified, to the orientation of the figures.

[0029] Unless otherwise specified, the expressions "approximately", "roughly", and "in the order of" mean within 10%, preferably within 5%.

[0030] Fig. 1 represents, in a very schematic way and in block form, an electronic device 100 comprising a processing device 102 according to an embodiment of the present description.

[0031] The electronic device 100 is for example an electronic card such as a microcircuit board, computer hardware, a microprocessor circuit, etc.

[0032] The processing device 102 includes, for example, a non-volatile memory 104 (NV MEM), for example, a flash memory. The memory 104 includes an access control interface 108 (ACCES CONTROL) connected to a monotonic counter 106 (MONOTONIC COUNTER).

[0033] Monotonic counters are known in the prior art, an example of such a counter being described in the publication "Virtual Monotonic Counters and Count-Limited Objects using a TPM without a Trusted OS" by LFG Sarmenta, M. Van Dijk, CW O'Donnell, J. Rhodes, and S. Devadas, and in particular in Part 3 of this document. This document describes counter implementations in hardware and / or software. The monotonic counter 106, for example, is implemented in hardware by a digital circuit, such as an application-specific integrated circuit (ASIC). The monotonic counter is configured to maintain a count value, accessible on one of the counter's outputs. Following an increment command, the monotonic counter increases its count value by one or more units, but after each increment, the operation is not reversible.Indeed, the monotonic counter is configured so that its count value never decreases. Furthermore, between two increments, the count value is protected against any modification, preventing it from being erased or changed. Only the increment command allows the current value to be replaced with a new value greater than the current value.

[0034] The monotonic counter 106 is configured so that no command, other than resetting the processing device, allows it to return to the previous value once the increment command has been executed. In the case where the value The count value is stored volatilely; each time the processing device is powered off, the count value is lost, and each time the device is powered back on, the monotonic counter generates a new initial count value. If the count value is stored in a non-volatile memory element, then each time the device is restarted, an initial count value is written back to the non-volatile memory element of the monotonic counter.

[0035] The processing device 102 further comprises a generic processor 110 (CPU). For example, the generic processor 110 is coupled via a bus 116 to the monotonic counter 106, as well as to a RAM (random access memory) 112 and a non-volatile memory 104. The memory 112 and / or the memory 104 store, for example, instructions for controlling the processor 110. The generic processor 110 is further coupled via the bus 116 to a cryptographic processor 114 (CRYPTO). The cryptographic processor 114 receives, via the bus 116, encrypted data and returns the decrypted data and / or receives, via the bus 116, unencrypted data and returns the encrypted data.

[0036] Non-volatile memory stores, for example, several startup codes and / or other data, which are associated with several TIL (temporal isolation level) levels. The startup codes are, for example, software and / or firmware codes. In the example of [Fig. 1], the non-volatile memory 104 includes a first area 118 in which a first startup code and / or some initial data (CODE0) are stored. The memory 104 further includes a second area 120, in which a second startup code and / or some initial data (CODE1) are stored, as well as a third area 122 in which a third startup code and / or some initial data (CODE2) are stored. The first, second, and third startup codes and / or data are, for example, associated with three corresponding TIL levels. Although the case of three sets of data is illustrated in [Fig. 1], the non-volatile memory 104 includes a first area 118 in which a first startup code and / or some initial data (CODE0) are stored.[l], in other embodiments, the non-volatile memory 104 may store only two sets of data, or more than three sets of data, in corresponding areas. For example, the first, second, and third data include first, second, and third startup codes.

[0037] The TIL isolation level depends on the count value generated by the monotone counter 106. In one example, the TIL value is equal to the count value of the monotone counter 106, although it would be possible to modify the count value in order to generate the TIL value.

[0038] During startup, the reading of the first, second and third codes and / or Data and / or the execution of the first, second, and third startup codes are performed in stages, each stage being associated with a corresponding isolation level. The access control circuit 108 of memory 104 is configured so that reading these codes / data is controlled according to the isolation level of the stage. The first data and / or the first code, for example, is associated with the isolation level, or TIL value, of 0, and the access control circuit 108 is configured so that this data and / or code is only accessible for reading when the current TIL count value is equal to 0. When the count value is incremented, for example, following the execution of the first code, the access control circuit 108 locks area 118, and the first data and / or the first code is then no longer accessible for reading.Following an increment, the current count value changes, for example, to 1, and the data and / or start codes associated with isolation level 1, for example the second start code, are executed.

[0039] In certain cases, the access control circuit 108 is configured to allow the reading of one or more data associated with isolation levels higher than the current TIL value. The lower the isolation level, the greater the level of protection. Isolation level 0 therefore provides the most protection, as the corresponding data can only be read when the count value is equal to 0. Thus, each isolation level corresponds to a level of protection for the contents of the memory areas associated with it.

[0040] The access control mechanism implemented by circuit 108 can be implemented in several ways.

[0041] In a first example, when the circuit 108 receives a read request associated with one or more addresses in memory 104, it is configured to compare this / these address(es) to the address ranges associated with areas 118, 120, 122 of memory 104. If it is an address in an area associated with a TIL value lower than the current value, the circuit 108 is configured for example to block the read operation.

[0042] In a second example, the circuit 108 is configured to disable a read circuit for any area 118, 120, 122 of the memory 104 associated with a TIL value lower than the current value. For example, one or more logic gates, such as OR or AND gates, are coupled in the output path of each area 118, 120, and 122 of the memory 104 and also receive an enable signal generated on the basis of the TIL value, allowing each output path to be selectively disabled.

[0043] The fact that the count value cannot be decremented during the operating period of the device 100 allows for the protection of start-up codes. once their execution is complete, because the access control circuit 108 prevents the reading of data and / or the execution of codes associated with TIL isolation levels lower than the current level.

[0044] In certain embodiments, one or more of the start-up data and / or codes and the associated isolation levels are reserved for parameterization phases of the device 102 or for distinct entities in the chain from the manufacturer to the end user. For example, an intermediate entity between the manufacturer of the processing device and the end user of the electronic device 100 may need to install start-up data and / or codes that are specific to the use of the device 100. In this case, one or more of the lowest start-up data and / or codes, for example those associated with isolation level 0, are reserved for the manufacturer of the processing device 102, and other start-up data and / or codes are reserved for the intermediate entity.

[0045] In certain embodiments, the content of memory areas 118, 120, and 122 includes other data in addition to the startup codes of the processing device. For example, other data sensitive in terms of confidentiality is stored in association with at least one of the first, second, and third codes and / or data. For example, this other data includes encryption keys used during the execution of the startup codes associated with them. In the example of [Fig. 2], memory areas 200, 202, and 204 store sensitive data associated respectively with the startup codes 118, 120, and 122 stored in the non-volatile memory 104. Areas 200, 202, and 204 are, for example, separate areas from areas 118, 120, and 122, but remain associated with a level of isolation corresponding to that of the startup codes to which the data is linked.This sensitive data includes, for example, one or more encryption keys stored in each zone 200, 202 and 204, and each of these zones is contained in non-volatile memory 104. According to another embodiment, each zone 200, 202 and 204 is a sub-zone of the corresponding zone 118, 120 and 122.

[0046] Figure [Fig.2] represents data and codes accessible during a secure boot according to an embodiment of the present description.

[0047] During a first step 210 of the processing device startup illustrated at the top of [Fig. 2], the current count value is, for example, equal to 0. In the example of [Fig. 2], an isolation level of 0 is associated with a first code (CODE0) as well as with some initial sensitive data (KEY0). The access control circuit 108 is configured, for example, so that this first code and this initial data are exclusively accessible when the current count value is equal to 0. However, during step 210, the access control circuit allows, for example, access to all memory areas 200, 202, and 204, as well as to all areas 118, 120 and 122. Indeed, in some cases, in order for example to anticipate subsequent steps in the startup process, one or more of the other startup codes CODE1, CODE2 are accessible for reading during step 210.

[0048] For example, once the first code (CODE0) is executed, the generic processor 110 commands a first increment of the current count value by the monotonic counter 106. For example, the first code includes a command requesting the increment of the counter. This command is, for example, transmitted to a control register (not shown) of the monotonic counter.

[0049] After this first increment, the current count value of the monotonic counter 106 is, for example, equal to 1, corresponding to the second step 211 of the startup. The access control circuit 108 receives the new current count value and is configured to prevent, based on this count value being greater than 0, any access to the first code as well as to the first data associated with isolation level 0. In other words, memory areas 118 and 200 are locked based on any count value strictly greater than 0.

[0050] Insulation level 1 is associated with a second code (CODE1) contained in zone 120 and with second data (KEY1) contained in zone 202. According to one embodiment, the third code (CODE2), for example associated with insulation level 2 and contained in zone 122, is accessible for reading on the basis of the current count value equal to 1.

[0051] For example, once the second code (CODE1) is executed, the generic processor 110 commands a second increment of the current count value by the monotone counter 106. For example, after this second increment, the current count value of the monotone counter 106 is equal to 2, corresponding to the third step 212 of the startup. Isolation level 2 is associated with the third code (CODE2) as well as with third data (KEY2). The access control circuit 108 receives the new count value and is configured to prevent, based on this count value being greater than 1, any access to the first and second codes as well as to the first and second data that are associated with isolation levels less than or equal to 1.

[0052] According to one embodiment, when the last startup code is executed, for example the third startup code, the generic processor 110 commands a third increment of the current count value by the monotonic counter. The access control circuit 108 then locks all access to the first, second, and third startup codes as well as to the first, second, and third data points.

[0053] According to another embodiment, when the last start code is executed, for example the third start code, the current count value is not incremented by the monotone counter 106 and access to the third start code as well as to the third data remains authorized by the access control circuit.

[0054] Figure 3 is a flowchart representing the operations of a secure startup process for a processing device according to an example embodiment of the present description. This process is implemented, for example, by the generic processor 110, the monotonic counter 106 and the access control circuit 108, of the processing device in Figure 1.

[0055] In step 301 (LAUNCH BOOT SEQUENCE), the processing device 102 starts up. In one example, this is the first startup of the device 102 after its production. In another example, it is a startup performed by an intermediary entity between the manufacturer of the device 102 and its end user. Yet another example, it is a so-called operational startup of the electronic device 100 performed by the end user.

[0056] In a step 303 (INITIALIZE COUNTER), subsequent to step 301, the monotonic counter is initialized to an initial value, being a natural number. In the example where the count value is stored volatilely, each power-up of the processing device results in the initialization of the count value, for example to 0 or 1. In another example where the count value is stored on non-volatile memory elements, each power-up of the processing device results in the replacement of the current count value with the initial count value, for example equal to 0 or 1.

[0057] In certain embodiments, the initial count value generated after power-up may vary depending on the state, or context, of the processing device 102. For example, one or more count values ​​correspond to one or more isolation levels reserved for an initial parameterization phase of the device 102, including, for example, the installation of firmware. The data and / or codes associated with these isolation levels are, for example, used for this initial parameterization.

[0058] For example, following manufacturing, the processing device 102 has a "blank" context and the initial count value is equal to a value reserved for parameterization, such as 0. Once parameterization is complete, the device's context becomes, for example, "parameterization complete". With this new context, powering on the device 102, performed, for example, by an intermediary entity between the manufacturer and the end user and / or by the end user, will then trigger a count value higher than the reserved count value, and, for example, equal to 1. The start-up code(s), as well as the sensitive data, associated with the isolation level corresponding to the reserved count value will, therefore, be inaccessible.

[0059] For example, the device context is detected by the presence of a voltage on a device start pin, this voltage being applied, for example, by adding a jumper between the start pin and another pin with a supply voltage. Alternatively, the device context is detected by the value of one or more bits stored non-volatilely and in a protected manner in memory 104, or in another memory.

[0060] In one example, the generic processor 110 is arranged to detect the context of device 102 when device 102 is powered on, and to configure accordingly the initial count value of the monotonic counter 106. In another example, the monotonic counter 106 is arranged to itself detect the context of device 102 and to configure itself its initial count value when device 102 is powered on.

[0061] In a step 305 (READ AND EXECUTE CODE ON LEVEE i), subsequent to step 303, the data and startup codes associated with isolation level i are read by the generic processor 110, and the startup codes associated with isolation level i are executed. Once the codes for level i have been executed, the generic processor 110 compares, in a step 307 (i=N?), the count value i to the value N, N being the count value associated with the last step in the startup sequence; in other words, the startup codes for isolation level N are the last to be executed according to the embodiment of this description. For example, in the example in [Fig. 2], N is equal to 2. If i is not equal to N (branch N), the process continues in a step 309 (i=i+l) in which the generic processor triggers the increment of the count value. For example, the count value goes from i to i+1.It is also possible that the increment increases the count value by several units. The process then resumes at step 305.

[0062] If, following comparison step 307, the count value is equal to N (branch Y), the process terminates at step 311 (END OF BOOT) in which the startup of the processing device is completed. In one embodiment, the current count value remains equal to N after step 311. In another embodiment, the count value is incremented during step 311, and the current count value becomes equal to N+1. In this second case, the access control circuit is then configured to prevent any access to any startup codes based on this count value.

[0063] Figure 4 is a flowchart representing the operations of a safe startup process for a processing device according to another embodiment of this description. This process is implemented, for example, by the generic processor 110, the monotonic counter 106, and the access control circuit 108, of the treatment device of the [Fig. 1].

[0064] Steps 401 and 403 are similar to steps 301 and 303 of [Fig.3], and will not be described again in detail.

[0065] In a step 405 (ACCESS CODE ON LEVEES i AND i+1, EXECUTE CODE ON LEVEE i), subsequent to step 403, the data and startup codes associated with isolation levels i+1 are accessed by the generic processor 110 and the startup code(s) associated with isolation level i are executed.

[0066] In one example, the data or codes associated with isolation level i contain one or more encryption keys, encrypted or not, which will be used during the execution of one or more codes associated with isolation level i+1. Thus, write access is, for example, authorized on the memory area(s) associated with isolation level i+1 in order to provision the keys to the codes associated with isolation level i+1.

[0067] In another example, the codes associated with isolation level i contain instructions aimed at verifying the integrity of the data and / or codes associated with isolation level i+1. Thus, read access to the memory area(s) associated with isolation level i+1 is permitted in order to perform this verification.

[0068] In a step 407 (i=i+l), subsequent to step 405, the count value is incremented. For example, the count value goes from i to i+1. In other examples, the increment increases i by several units.

[0069] In a step 409 (i=N?), the generic processor 110 compares the count value i to the value N, where N is defined as described in relation to step 307 of [Fig. 3]. If the value i is not equal to N (branch N), the process returns to step 405.

[0070] In the case where, during the comparison step 409, the count value is equal to N (branch Y), the process continues to a step 413 (EXECUTE CODE ON LEVEE N) in which the start code(s) associated with the insulation level N are executed.

[0071] The start-up of the processing device ends with a step 415 (END OF BOOT), which is similar to step 311 of [Fig.3], and is not described again in detail.

[0072] The method whose implementation is shown in [Fig. 4] allows for a delayed reading of the start codes. Indeed, the start codes associated with an insulation level are read when the count value is lower than the level value. This saves time compared to the implementation of the method shown in [Fig. 3].

[0073] One advantage of the described embodiments is that startup codes, as well as data sensitive in terms of confidentiality, are protected in an immediacy supported by the use of a monotonic counter to lock access to codes and / or data.

[0074] Another advantage of the described embodiments is that it is easily adaptable to several boot architectures.

[0075] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will be apparent to those skilled in the art. In particular, different types of processors may be used. Furthermore, the number of isolation levels may vary.

[0076] Finally, the practical implementation of the embodiments and variants described is within the reach of a person skilled in the art, based on the functional indications given above.

Claims

Demands

1. A method for starting a processing device (102), the method comprising: - the generation, by a monotonic counter (106) and during a first start-up phase, of a first count value; - the transmission, by the monotonic counter, of the first count value to an access control circuit (108) of a memory (104); - the reading, on the basis of the first count value, of first data (118) associated with the first start-up phase and stored in the memory, the first data comprising first start codes; - the execution of the first start codes, the first start codes comprising an instruction to increment the monotonic counter to a second count value greater than the first count value;and - the generation, by said counter and during a second start-up phase, of the second count value, the memory access control circuit (108) being configured so that reading the first data is not allowed on the basis of the second count value.;

2. Method according to claim 1, wherein the memory (104) is a volatile memory.

3. A method according to claim 1, wherein the memory (104) is a non-volatile memory.

4. A method according to any one of claims 1 to 3, wherein the access control circuit (108) of the memory (104) is configured so that reading the first data (118) is not permitted on the basis of a count value greater than the first count value.

5. A method according to any one of claims 1 to 4, further comprising reading, on the basis of the first count value, second data (120) stored in memory (104) and associated with the second start-up phase.

6. A method according to any one of claims 1 to 5, further comprising: - the transmission, by the monotonic counter (106), of the second counting value to the memory (104); and - reading second and / or third data (120, 122) stored in memory (104) based on the second count value.

7. A method according to any one of claims 1 to 6, wherein the first count value corresponds to an initialization value of the monotonic counter (106) during a first start-up of the processing device (102) comprising the first and second start-up phases, the method further comprising, a second start-up of the processing device during which the monotonic counter is initialized to the second count value.

8. Method according to claim 7, comprising another start of the processing device (102), after the first and second starts, during which the monotonic counter (106) is initialized again to the first counting value if a condition on the state of the device is satisfied.

9. A method according to claim 8, wherein the condition on the state of the processing device corresponds to the programming state of one or more bits stored non-volatilely in a memory area (104) or other memory.

10. A method according to any one of claims 1 to 9, further comprising, prior to the generation of the second count value, reading, on the basis of the first count value, one or more first encryption keys (200) stored in the memory (104), the access control circuit (108) of the memory being configured so that the reading of the first encryption keys is not permitted on the basis of a count value greater than the first count value.

11. A method according to claim 10, further comprising, after the generation of the second count value, reading on the basis of the second count value one or more second encryption keys (202) stored in memory.

12. Data processing device (102) comprising: - a monotonic counter (106) configured to generate a first count value; and - a memory (104) comprising an access control circuit (108) and containing first data associated with a first startup phase, the access control circuit being configured to: - allow the reading, based on the first count value, of the first data (118), the first data including first start codes; - to allow the execution, based on the first count value, of the first startup codes, the first startup codes including an instruction to increment the monotonic counter to a second count value greater than the first count value; and - do not allow the reading of the first data based on the second count value.