Method for detecting an attempt at linear extraction of the contents of a memory
The method addresses the inefficiency in detecting linear extraction attempts by inserting security markers and discontinuity instructions into microcontroller memory, effectively triggering alerts upon non-detection, thus enhancing security.
Patent Information
- Application Number
- FR2022009624
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-09-22
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-09-22
AI Technical Summary
Existing methods for detecting attempts at linear extraction of memory contents in microcontrollers are inefficient and prone to false alerts, lacking simplicity and effectiveness in counteracting invasive attacks.
A method that involves inserting discontinuity instructions and/or security markers into the program code, which are monitored for detection. If a security marker or discontinuity instruction is not detected within a predefined timeframe or number of instructions, a predefined alert action is triggered.
This method effectively detects linear code extraction attempts by ensuring the presence of security markers or discontinuity instructions, thereby preventing unauthorized access and protecting sensitive information.
Smart Images

Figure 00000039_0000 
Figure 00000039_0001 
Figure 00000040_0000
Abstract
Description
Title of the invention: Method for detecting an attempt at linear extraction of the contents of a memory Technical field
[0001] The present invention relates to a method for detecting an attempt to linearly extract the contents of a memory of a microcontroller or a processor as well as an electronic circuit configured to detect such an extraction attempt. Prior art
[0002] Smart card hacking has become a common phenomenon. Since about the early 1990s, almost all types of smart card processors used in European, and later American and Asian, pay-TV conditional access systems have been successfully reverse-engineered. Illicit clone cards that decrypt TV channels without generating revenue for the broadcaster have been sold. The industry has had to update security processor technology several times already, and the challenge is far from over.
[0003] The article by O. Kômmerling et al. “Design Principles for Tamper-Resistant Smartcard Processors” USENIX Workshop on Smartcard Technology, 1999 presents examples of integrated circuit attacks and some countermeasure techniques.
[0004] We can distinguish two main families of attacks: invasive and non-invasive.
[0005] In the case of a non-invasive attack, the attacked card is not physically damaged and the equipment used in the attack can generally be disguised as a normal smart card reader.
[0006] As for invasive attacks, these are physical probing attacks consisting of accessing the interconnections of the logic of an integrated circuit with a probe (metal needle positioned by means of a micromanipulator on the metal tracks).
[0007] The probe can be connected to an oscilloscope (via an amplifier if necessary) in order to allow the reading of internal data manipulated by the target circuit.
[0008] The probe may also be driven by a signal generator and used to force an arbitrary logic value onto an internal node of the target circuit (e.g. to force a circuit into a given unsafe state by setting the value of a control signal).
[0009] This attack technique can be passive (for simple listening: “eaves-dropping” in English) and / or active and generating an error in the circuit.
[0010] An ion gun (Focused Ion Beam (FIB) in English) is generally used. to access the interconnections to be probed. The ion gun is a failure analysis instrument used in microelectronics to dig holes in integrated circuits, cut interconnect tracks, and (re)create electrical contacts between tracks.
[0011] Dmitry Nedospasov's doctoral thesis entitled "Security of the IC backside" describes invasive attacks, including linear code mining techniques.
[0012] The publication of Johannes Obermaier and Vincent Immler “The past, present, and future of physical security enclosures: From battery-backed monitoring to PUF-based inherent security and beyond” Journal of Hardware and Systems Security, Aug 2018, and that of
[0013] Phil Isaacs et al. “Tamper Proof, Tamper Evident Encryption Technology” Pan Pacific Symposium. SMTA, 2013 present examples of protective enclosure countermeasures.
[0014] The program code of a secure circuit comprises several parts stored in its Flash or ROM memories (it can be executed from a ROM, Flash or RAM memory). This code is protected against rereading under penalty of jeopardizing the security of the range of secure circuits considered.
[0015] Knowledge of the code allows for the development of hardware and software attacks. It is imperative for a manufacturer or user of a secure circuit to protect the confidentiality of the code, by preventing its extraction, or "dump" in English.
[0016] Linear code extraction consists of an attacker rereading the code of a circuit in the correct order from the first memory address to the last (otherwise the code is unusable).
[0017] The rereading of the code of a circuit is blocked before its commercialization. Hence the use by attackers of invasive attack techniques to carry out linear code extraction.
[0018] It should be noted that linear code extraction can also be used to extract secret keys and other confidential information stored in a circuit.
[0019] In the aforementioned thesis, some techniques for protection against linear code extraction are mentioned, such as burying security-relevant signals in the lower metal layers of the circuit, adding sensors or randomizing program execution with register redundancy, etc. Statement of the invention
[0020] There is a need to further improve the methods for detecting an attempt at linear extraction of the contents of an electronic memory, in particular by terms of simplicity of implementation and efficiency. Detection method
[0021] The invention aims to meet this objective and has as its subject, according to one of its aspects, a method for detecting an attempt at linear extraction of a program code recorded in a memory of an electronic circuit, the code comprising program instructions which, to be read by a microprocessor core, are loaded sequentially via an instruction bus into an instruction register for storing the instructions controlled at least by a clock signal and a reset signal, the loading of each instruction into the instruction register being carried out on an edge of the clock signal, the code comprising discontinuity instructions and / or so-called “security marker” instructions inserted among the program instructions so as to be read during the execution of the program, the method comprising the triggering of a predefined alert action,in case of non-detection of a discontinuity instruction or a security marker, according to a predefined monitoring rule.
[0022] Discontinuity instructions are defined as the set of program instructions that can control the flow of execution of the program (conditional and unconditional branching, jump, function call and return, etc.). Generally, a discontinuity instruction breaks the linear execution of the program, so that the execution of this instruction results in the transition to an instruction having an address that is not consecutive to that of said discontinuity instruction.
[0023] By "linear execution" of the program, we mean the execution of its instructions in the order of their consecutive memory addresses.
[0024] By "security marker" is meant a particular instruction inserted into the code stored in the memory in order to protect it against linear extraction of its contents. A security marker has the same structure as the instructions of the instruction set used by the electronic circuit in question. The security marker comprises for example 32 bits of information if it is used in circuits using this instruction size.
[0025] Linear code extraction involves an attacker successively reading the code instructions.
[0026] Linear code fetching may include probing the instruction bus and asserting the reset signal so that the microprocessor core reads only null instructions.
[0027] Thanks to the invention, it is possible to easily detect such a linear code extraction attack, in particular by detecting the absence of a discontinuity instruction or a security marker.
[0028] The predefined monitoring rule may be the non-detection of an instruction of discontinuity or a safety marker for a predefined duration and / or after a predefined number of program instructions have been read and / or after a predefined number of clock cycles. Safety markers
[0029] Preferably, the security markers are inserted into the code with variable periodicity. This makes it difficult for the attacker to detect and / or identify them.
[0030] The periodicity of insertion of the security markers can be pseudo-random.
[0031] The security markers are preferably inserted into the code so that the execution of the program instructions located between two consecutive security markers corresponds to a number of clock cycles lower than that leading to the triggering of the predefined alert action.
[0032] Two consecutive security markers are preferably arranged such that the number of clock cycles causing the predefined alert action to be triggered is greater than the maximum number of clock cycles required to execute the program instructions located between the two security markers.
[0033] Indeed, the number of clock cycles required to execute an instruction may be variable (and cannot be known in advance for some of them). Thus, the number of clock cycles leading to the triggering of the predefined alert action is preferably considered for a worst case, being greater than the maximum number of clock cycles required to execute the program instructions located between two consecutive security markers.
[0034] At least one security marker is preferably inserted at the beginning and at the end of the code of a function forming part of the program.
[0035] At least one security marker is preferentially inserted at the destination address of a branch instruction.
[0036] At least one security marker is preferably inserted at the beginning or at the end of the code of a loop forming part of the program.
[0037] Inserting security markers in the case of a function, branch or loop reduces the number of instructions executed between two consecutive security markers and avoids triggering the predefined alert action without reason.
[0038] In one embodiment, the security markers are encoded so as to have at least one particular bit of weight corresponding to the same weight as that of at least one characteristic bit of a branch instruction, the particular bit having the same encoded value of the characteristic bit, so as to trigger the predefined alert action in the event of an attack by forcing to the complementary binary value of the characteristic bit.
[0039] Indeed, for certain instruction encodings (depending on the manufacturers), the instructions branching have a characteristic value on a particular bit.
[0040] If we consider, for example, a set of instructions coded on 16 bits (the same reasoning also applies to instructions on 32 and 64 bits), we can reason for example by considering that all the branch instructions have their most significant index bit (bit 15 in this case) at the value 1. However, it is the branch instructions which introduce discontinuities during the execution of a code (thereby preventing a linear extraction).
[0041] Thus, an attacker can carry out an invasive linear code extraction attack by forcing this characteristic bit (bit 15, most significant) of the instructions to 0, including the branch instructions during the execution of the code. Due to the setting of this bit to zero, the branch instructions of the code are no longer interpreted as branch instructions. The instruction pointer (intended to contain the memory address of an instruction to be executed) is then incremented so as to successively read all the instructions of the code (as long as the characteristic bit is forced to 0). The attacker then does not need to force the reset signal of the instruction register. Such an attack is particularly suitable for the case where the instruction register does not have a reset signal.
[0042] If the bit-level encoding of a security marker is characterized by a high-order bit at 0, it will not be corrupted by forcing the high-order bit to 0. The detection method is then ineffective against linear extraction by forcing a bit (allowing branch instructions to be disabled).
[0043] The choice of an adequate coding of the security marker makes it possible to guarantee the effectiveness of the detection method against the forcing of a bit to a given level leading to a vulnerability.
[0044] Continuing with the previous example, choosing a coding of the most significant bit at 1 for the security marker (same value and same characteristic bit as for the branch instructions) ensures that forcing this bit to 0 prevents the security marker from being recognized. In the absence of detection of the security marker, the predefined alert action is thus triggered.
[0045] Security markers can be inserted into the code during the compilation phase of the code, the code then being loaded into memory during programming of the circuit.
[0046] Alternatively, security markers are inserted into the code during execution of the latter, in particular when reading program instructions from memory.
[0047] In this case, the memory contains control logic with a logic block that periodically inserts a security marker among the program instructions when they are read.
[0048] The logic block notably sends a wait cycle command to the microprocessor core when loading a security marker into the instruction register so that the microprocessor core inserts a wait cycle into the execution flow when receiving the security marker. In another embodiment, the microprocessor core is configured to recognize a security marker and renew the request to read the instruction that was shifted by the insertion of the security marker. This mode of operation saves memory space and also allows for simpler implementation of the detection method, because the program does not have to be modified since no security marker is inserted therein.
[0049] Preferably, the security markers are different from each other by their payload. This makes it possible to create confusion for the attacker and to make it more difficult to circumvent the detection method.
[0050] In one embodiment, the program instructions and security markers are stored in encrypted form in the memory and are decrypted before being loaded into the storage register. Discontinuity Instructions
[0051] Instead of detecting the absence of security markers, it is possible to detect the absence of discontinuity instructions. It is then no longer necessary to include security markers in the code, which has a lower increase in execution time, compared to the use of security markers in the program, since the execution of a security marker requires at least one clock cycle. In addition, the detection method according to this variant can be applied without modification of the compiler.
[0052] In one embodiment, the method comprises, during a step of analyzing the code before loading it into the register, inserting at least one discontinuity instruction with linear execution into a portion of the code comprising program instructions whose execution corresponds to a number of clock cycles that can cause the triggering of the predefined alert action. This makes it possible to avoid triggering a false alert, while there is no attack in progress.
[0053] By "linearly executed discontinuity instruction" is meant a discontinuity instruction generating a linear execution of the program. Thus, the insertion of the linearly executed discontinuity instruction in said portion of code does not affect the sequential execution of the instructions of this portion of code located consecutively in the memory.
[0054] The insertion of the linearly executed discontinuity instruction can be carried out during the compilation of the code, this instruction being stored in the memory and having a memory address. The linearly executed discontinuity instruction then generates in this case a unitary increment of the memory address of the instructions which follow it.
[0055] Alternatively, the insertion of the linearly executed discontinuity instruction is performed after reading the instructions to be loaded from memory and before loading these instructions into the instruction register. The linearly executed discontinuity instruction then has no memory address in this case, and results in the memory addresses of the instructions that follow it being maintained. This option makes it possible not to modify the compiler, and not to increase the memory area.
[0056] The predefined alert action may comprise at least one of the following actions: resetting the electronic circuit, erasing the memory, resetting the memory read address, taking non-consecutive values by the memory read address so that the extraction of the code becomes non-linear, and skipping a section of code, in particular a sensitive section to be protected.
[0057] In one embodiment, the detection method is implemented permanently to protect the entire program code, the first instruction of the latter being able to be a discontinuity instruction or a security marker. In this case, the attack detection logic is permanently activated (and by construction cannot be disengaged).
[0058] In another embodiment, the detection method is implemented in a configurable manner via the configuration of a fuse, in particular of the one-time programmable type, or of a variable in non-volatile memory, in particular a Flash or EEPROM type memory, during the programming phase of the circuit, the value stored in the fuse or in the non-volatile memory being read at the start of the circuit, in particular when it is powered up or when it wakes up after resetting, said value making it possible to activate the detection method, and the first instruction of the program code being a discontinuity instruction or a security marker, if the method is activated.In this case of configurable implementation, the stored value (in the fuse or non-volatile memory) is read at circuit start-up (power-up or wake-up after reset, also called "reset") and allows either to activate the detection process or to keep it inactive. This choice is final for the entire duration of use of the circuit.
[0059] The detection method can be implemented to protect at least a portion of the program code delimited by a start address and an end address, the method being activated as soon as a program instruction whose address is between the start address and the end address is read to be executed, being deactivated as soon as a program instruction not belonging to said portion of code is read to be executed. In this case, the detection method for said at least one portion of code is permanently activated and cannot be disengaged, i.e. each time instructions belonging to said portion of code are executed, the detection method is activated.
[0060] The detection method applies to any type of memory that can contain program code for execution by a microprocessor core.
[0061] The memory may be embedded in the same integrated circuit as the microprocessor core executing the instructions, for example an embedded memory of the Flash or RAM type, or an external memory of the DRAM type. Electronic circuit
[0062] The invention also relates, according to another of its aspects, to an electronic circuit comprising at least one memory, a microprocessor core, an instruction bus, a read bus, an address bus and an instruction register for storing instructions controlled at least by a clock signal and a reset signal, the memory being connected to the instruction register by the instruction bus, the instruction register being connected to the microprocessor core by the read bus, the microprocessor core comprising an instruction pointer intended to contain the memory address of an instruction to be executed, the microprocessor core being connected to the memory by the address bus, the circuit being configured to detect an attempt at linear extraction of a program code stored in the memory, the code comprising program instructions which, to be read by the microprocessor core,are loaded sequentially via the instruction bus into the instruction register on command of the clock signal, the code comprising discontinuity instructions and / or so-called “security marker” instructions inserted among the program instructions so as to be read during the execution of the program, the core of the microprocessor comprising a protection circuit against an attempt at linear extraction capable of triggering a predefined alert action in the event of non-detection of a discontinuity instruction or a security marker according to a predefined monitoring rule.
[0063] Instruction or clock cycle load counter
[0064] The protection circuit preferably comprises an instruction or clock cycle loading counter, the instruction or clock cycle loading counter preferably being decreasing, in particular configured to be decremented at each instruction loading in the instruction register or at each clock cycle, the instruction or clock cycle loading counter being in particular configured to be periodically reset to a configurable value, the reset of the instruction or clock cycle loading counter being in particular regularly carried out by a security marker before reaching an alarm threshold, in particular zero, the protection circuit being preferentially configured to trigger the predefined alert action when the instruction or clock cycle loading counter reaches the alarm threshold. Continuity instruction counter
[0065] In one embodiment, the circuit according to the invention comprises a continuity instruction counter configured to be decremented each time a continuity instruction is executed, the continuity instruction counter preferably being configured to be periodically reset to a configurable value, the resetting of the continuity instruction counter being regularly carried out by the execution of a discontinuity instruction before reaching an alarm threshold, in particular zero, the protection circuit being configured to trigger the predefined alert action when the continuity instruction counter reaches the alarm threshold.
[0066] By "continuity instruction" is meant an instruction generating a linear execution of the program and which is not a discontinuity instruction.
[0067] The configurable value for resetting the continuity instruction counter can be set either during an initialization phase which precedes the execution of a program, or on the fly during the execution of the program.
[0068] Alternatively, this counter is reset to a value permanently fixed by the hardware design of the circuit.
[0069] In the event that the continuity instruction counter reaches the alarm threshold, an absence of discontinuity instruction is detected, and the predefined alert action is triggered.
[0070] Alternatively, the continuity instruction counter is increasing instead of decreasing.
[0071] The continuity instruction counter may be located in the core of the microprocessor, in particular in the protection circuit. Alternatively, it is located in the core of the microprocessor outside the protection circuit. It may also be located outside the core of the microprocessor, for example between the memory and the core.
[0072] It is possible to have several counters distributed in different locations. The interest is to counter an attack deactivating the signal used by the counter so that the latter remains frozen and is no longer able to detect an attack. The use of several counters with detection of the predefined alert action if the counters take different values makes it possible to thwart this type of attack. Indeed, the multiplicity of counters and their different locations complicates the task for the attacker who will have to deceive each of the counters.
[0073] The information that an instruction has been executed can come from any internal information source: for example a control signal, a status signal, variations in the instruction address.
[0074] Linearly executed discontinuity instruction insertion block
[0075] The circuit according to the invention may comprise a block for inserting discontinuity instructions with linear execution, this block being a circuit located outside the memory, communicating with the latter and with the instruction register, this block being configured to insert at least one discontinuity instruction with linear execution into a portion of the read code comprising program instructions whose execution corresponds to a number of clock cycles that can cause the triggering of the predefined alert action. This makes it possible to avoid triggering a false alert, while there is no attack in progress, in particular when the reset value of the continuity instruction counter is fixed, by resetting the counter before reaching the alarm threshold.
[0076] The linearly executing discontinuity instruction insertion block is alternatively integrated into the memory.
[0077] An analysis of the program prior to its loading into the program memory of the circuit allows an appropriate choice of the reset value of the continuity instruction counter if the latter is configurable, or to determine the need to insert discontinuity instructions with linear execution and where to place them appropriately. If the reset value of the continuity instruction counter is fixed and is not high enough, it is probably useful to insert at least one discontinuity instruction with linear execution in the portions of code comprising a long sequence of continuity instructions likely to trigger a false alarm. An alternative is the addition of a hardware block for inserting discontinuity instructions with linear execution as defined above.
[0078] Linear Execution Discontinuity Instruction Counter
[0079] In one embodiment, in addition to the continuity instruction counter, the circuit according to the invention comprises a linear execution discontinuity instruction counter configured to be decremented each time a linear execution discontinuity instruction is executed, the linear execution discontinuity instruction counter preferably being configured to be periodically reset to a configurable value, the reset of the linear execution discontinuity instruction counter being regularly performed by the execution of a non-linear execution discontinuity instruction before reaching an alarm threshold, in particular zero, the protection circuit being configured to trigger the predefined alert action when the linear execution discontinuity instruction counter reaches the alarm threshold.
[0080] Of course, a "non-linearly executed discontinuity instruction", as opposed to a linearly executed discontinuity instruction, is a discontinuity instruction that causes a non-linear variation in the instruction address. In other words, the instruction address does not increment in a unitary manner following the execution of the non-linearly executed discontinuity instruction.
[0081] The configurable value for resetting the linear execution discontinuity instruction counter can be set either during an initialization phase which precedes the execution of a program, or on the fly during the execution of the program.
[0082] Alternatively, the linearly executed discontinuity instruction counter is reset to a value permanently fixed by the hardware design of the circuit.
[0083] Alternatively, the linearly executed discontinuity instruction counter is increasing instead of decreasing.
[0084] The information that an instruction is a discontinuity instruction can come from any internal information source: for example, a control signal, a status signal, variations in the instruction address. In particular, the information that a discontinuity instruction generates linear execution can ideally come from variations in the instruction address. However, this information can be crossed with other sources of information: for example, a control signal, a status signal. For example, on the cv32e40p core (RISCV instruction set), there is a ^branch^aken” signal making it possible to identify, during the execution of a branch instruction, whether its execution is linear or not.
[0085] In the event that the linearly executed discontinuity instruction counter reaches the alarm threshold, an absence of a discontinuity instruction causing a non-linear variation of the instruction address is detected, and the predefined alert action is triggered.
[0086] The linear execution discontinuity instruction counter allows, among other things, the detection of attacks consisting of injecting into the core only discontinuity instructions generating a linear execution, for example a branch instruction whose condition is never met. This type of attack can deactivate the write enable signal (write_enable) of the instruction register so that the instruction contained in the register (which is in this case a linear execution discontinuity instruction) is stored there as long as the write enable signal is deactivated. The continuity instruction counter alone will not be able to detect this type of attack, given that it is permanently reset by the stored discontinuity instruction.
[0087] The linearly executed discontinuity instruction counter also allows for the detection of attacks consisting of forcing the instruction address to vary linearly, for example an attack consisting of forcing the multiplexer control signal providing the instruction address, so as to select the input that causes the instruction address to vary linearly, regardless of the instruction executed in the core. This attack causes all discontinuity instructions to be linearly executed. The continuity instruction counter alone cannot detect such an attack, as it is reset with each discontinuity instruction entering the core. However, the linearly executed discontinuity instruction counter will never be reset and will decrement with each discontinuity (linearly executed) instruction, so the attack will be detected. Cycle counter
[0088] In addition to the continuity instruction counter, the circuit according to the invention may comprise a cycle counter intended to detect an absence of execution of instructions, configured to increment at each clock cycle, the resetting of the cycle counter, in particular to zero, being regularly carried out by the execution of an instruction before reaching an alarm threshold, in particular a configurable value, the protection circuit being configured to trigger the predefined alert action when the cycle counter reaches the alarm threshold.
[0089] The alarm threshold of this counter can be a threshold defined from the specifications of the core, taking into account the maximum number of cycles necessary for the execution of an instruction of the code. If this threshold is reached, there is detection of an absence of execution of instructions.
[0090] The cycle counter is reset at each instruction executed (from the same signal as that decrementing the continuity instruction counter).
[0091] The cycle counter may be used in combination with the continuity instruction counter and optionally the linearly executed discontinuity instruction counter.
[0092] In the case of an attack deactivating the signal containing the information that an instruction has been executed (internal signal which can be deactivated commonly with the write authorization signal of the instruction register), the continuity instruction counter will not decrement, nor will the linear execution discontinuity instruction counter. Therefore, the continuity instruction counter alone or combined where appropriate with the linear execution discontinuity instruction counter cannot detect this type of attack. However, the cycle counter will detect the absence of instruction execution and the predefined alert action will be triggered in order to signal the attack in progress.
[0093] Linear execution sequence length counter
[0094] In one embodiment, the circuit according to the invention comprises a linear execution sequence length counter intended to detect a sequence of continuity and / or discontinuity instructions with linear execution of length exceeding a given length, configured to increment at each execution of an instruction or at each clock cycle, the resetting, in particular to zero, of the linear execution sequence length counter being regularly carried out by the variation of at least one signal from the microprocessor core indicating the end of execution of a linear execution sequence before reaching an alarm threshold, the protection circuit being configured to trigger the predefined alert action when the linear execution sequence counter reaches the alarm threshold.
[0095] The linear execution sequence length counter makes it possible to detect linear execution sequences of excessive length with regard to the instruction set used.
[0096] This counter measures the length of linear execution sequences. In effect, the number of times instructions are loaded from memory in a linear fashion is counted.
[0097] The variant with linear execution sequence length counter no longer requires the addition of new instructions. It is a detection by observation only. Thus, the execution time and the size of the program in memory are not modified. On the other hand, the latency of detecting an attack will be greater.
[0098] The variant with linear execution sequence length counter allows, among other things, to detect all the attacks previously described (activation of the reset of the instruction register, storage of an instruction in the instruction register, forcing linear variation of the instruction address, etc.).
[0099] Said at least one signal from the microprocessor core indicating the end of execution of a linear execution sequence may come from the observation of the read address transmitted by the microprocessor core to the memory.
[0100] The alarm threshold can be a configurable value or permanently fixed to the hardware design of the circuit. In the case where the threshold is a configurable value, it can be set at the compilation of the program or on the fly during the execution of the program (the threshold can be adapted to each portion of code, so as to ensure low detection latency).
[0101] The alarm threshold of the linear execution sequence length counter can be set so as to generate no detection on the normal execution of programs representative of the selected instruction set.
[0102] If this threshold is reached, an excessively long linear execution sequence is detected.
[0103] The linear execution sequence length counter is alternately descending (instead of ascending).
[0104] In addition to measuring the length of linear execution sequences from the va- nations of the instruction address, it is possible to check the consistency of the variations of the instruction address with the variation of other signals of the core, for example from the variations of the control signal of the multiplexer providing the instruction address, of a status or control signal, etc.
[0105] The linear execution sequence length counter may have different locations in the circuit.
[0106] It can be connected to the instruction address bus. Thus, it is possible to count the length of a linear execution sequence by reading the address (unit increment when successive addresses follow one another).
[0107] The linear execution sequence length counter can be connected to the internal signals of the core. Thus, it is possible to count the length of a linear execution sequence by observing these signals, for example as long as the address multiplexer control is maintained by selecting the "linear increment of address" input, the linear execution sequence continues.
[0108] The linear execution sequence length counter can be connected to the instruction bus. Thus, it is possible to count the length of a linear execution sequence by observing specific bits of the instruction (for example, bits of the funct3 and opcode fields of the code of a RISC-V core instruction) so as to know whether or not it is a discontinuity instruction.
[0109] The memory can be of the Flash, ROM, RAM or DRAM type. In the latter case, the memory is external, i.e. not embedded in the same integrated circuit as the microprocessor core executing the instructions.
[0110] The circuit may include a decryption circuit located between the memory and the instruction register for decrypting the program instructions and the security markers before loading them into said register. This applies to the case where the program instructions and the security markers are stored in encrypted form in the memory.
[0111] In one embodiment, at least a portion of the program code delimited by a start address and an end address is protected against linear extraction by the protection circuit, the start address and the end address being stored during programming of the circuit in a non-volatile memory protected against erasure and modification.
[0112] The protection circuit preferably comprises registers for loading said start and end addresses, into which said addresses are loaded when the circuit is started, the protection circuit being configured in particular to determine whether the instruction whose address is contained in the instruction pointer belongs to said at least one portion of code by comparing this address with the start and end addresses. If this is the case, the detection method is activated. The choice of protected portions of code may concern, for example, the startup phase (boot phase) of the circuit and / or the parts of the code implementing security functions (use of cryptographic tools, for example).
[0113] In one embodiment, the circuit comprises a so-called "watchdog" circuit used to restart the circuit in the event of a program malfunction, the watchdog circuit comprising a watchdog counter incremented at the edge of a clock supplied by an oscillator internal to the circuit, the watchdog circuit being configured in reset mode so as to emit a signal to reset the circuit when the watchdog counter reaches a predefined value, the watchdog counter being reset periodically by executing an instruction to reset this counter.
[0114] The circuit may include a hardware fuse allowing permanent activation of the watchdog circuit, so that when the fuse is blown during programming of the circuit, the watchdog circuit is permanently activated in reset mode.
[0115] The invention also relates, according to another of its aspects, to the use of the electronic circuit comprising the hardware fuse allowing permanent activation of the watchdog circuit, the fuse being blown and the instructions for resetting the watchdog counter being used as security markers. Protection method
[0116] The invention also relates, according to another of its aspects, to a method for protecting a program code comprising the insertion into this code of discontinuity instructions or security markers for the implementation of the detection method according to the invention.
[0117] In one embodiment, said insertion is performed during programming of the code.
[0118] In another embodiment, said insertion is carried out during or at the end of the compilation of the code.
[0119] Alternatively, said insertion is carried out after reading the code of the instructions to be loaded from the memory and before loading these instructions into the instruction register. Brief description of the drawings
[0120] The invention may be better understood by reading the detailed description which follows, of non-limiting examples of its implementation, and by examining the attached drawing, in which:
[0121] [Fig-1] [Fig.l] schematically represents an example of a circuit of the state of the technique, not protected against linear extraction of the code contained in the circuit memory;
[0122] [Fig.2] [Fig.2] is a view analogous to [Fig.l] schematically representing an example of a linear code extraction attack;
[0123] [Fig.3] [Fig.3] is a view similar to [Fig.2] schematically illustrating a decryption of the code instructions;
[0124] [Fig.4] [Fig.4] is a view similar to [Fig.3] schematically representing a first example of a circuit according to the invention;
[0125] [Fig.5] [Fig.5] schematically represents a second example of a circuit according to the invention with modified memory control logic;
[0126] [Fig.6] [Fig.6] schematically shows an example of a portion of code protected according to the invention;
[0127] [Fig.7] [Fig.7] schematically represents a function call within a code that risks triggering a false alert;
[0128] [Fig.8] [Fig.8] is analogous to [Fig.7] with the addition of safety markers to prevent a false alarm from being triggered;
[0129] [Fig.9] [Fig.9] schematically represents a connection within a code which risks triggering a false alert;
[0130] [Fig. 10] [Fig. 10] is analogous to [Fig.9] with the addition of safety markers to prevent a false alarm from being triggered;
[0131] [Fig. 11] [Fig. 11] schematically represents a loop within a code that risks triggering a false alert;
[0132] [Fig. 12] [Fig. 12] is analogous to [Fig.l 1] with the addition of safety markers to prevent a false alarm from being triggered;
[0133] [Fig. 13] [Fig. 13] schematically represents a third example of a circuit according to the invention in which the instruction register is part of the microprocessor core;
[0134] [Fig. 14] [Fig. 14] schematically illustrates a fourth example of a circuit according to the invention in which the memory is external;
[0135] [Fig. 15] [Fig. 15] represents a fifth example of a circuit according to the invention identical to that of [Fig.4] but without a decryption circuit;
[0136] [Fig. 16] [Fig. 16] schematically illustrates an example of a portion of code in which a discontinuity instruction with linear execution is inserted;
[0137] [Fig. 17] [Fig. 17] schematically represents two examples of code portions in which a linearly executed discontinuity instruction is inserted into (right example) and outside the memory saving the code (left example);
[0138] [Fig. 18] [Fig. 18] schematically illustrates a sixth example of a circuit according to the invention with a continuity instruction counter and a linearly executed discontinuity instruction insertion block;
[0139] [Fig. 19] [Fig. 19] schematically represents an example of a sequence of instructions to be executed following a storage attack in the instruction register of a discontinuity instruction generating a linear execution;
[0140] [Fig.20] [Fig.20] schematically illustrates a seventh example of a circuit according to the invention with a linearly executed discontinuity instruction counter and an example of an attack for forcing the multiplexer control signal providing the instruction address;
[0141] [Fig.21] [Fig.21] schematically represents an eighth example of a circuit according to the invention with a cycle counter and an example of an attack blocking the signal that an instruction has been executed; and
[0142] [Fig.22] [Fig.22] schematically illustrates a ninth example circuit according to the invention showing different locations of a linear execution sequence length counter. Detailed description
[0143] [Fig.l] schematically illustrates an electronic circuit 1 according to the state of the art. The circuit 1 comprises a memory 10, a microprocessor core 14, an instruction bus 11, a read bus 13, an address bus 15 and an instruction register 12 for storing instructions, controlled by a clock signal clk and a reset signal reset for resetting the contents of the instruction register 12 to zero.
[0144] The memory 10 is connected to the instruction register 12 by the instruction bus 11.
[0145] Memory 10 contains program code whose instructions pass from the memory 10, via the instruction bus 11, to be loaded sequentially into the instruction register 12 on an edge of the clock signal clk, for example on the rising edge of the clock.
[0146] The instruction register 12 is connected to the core of the microprocessor 14 by the read bus 13 via which the instruction to be executed passes to the core of the microprocessor 14.
[0147] The core of the microprocessor 14 comprises an instruction pointer 140 intended to contain the memory address of the instruction to be executed.
[0148] The core of the microprocessor 14 is connected to the memory 10 by the address bus 15. The address bus contains the memory address of the instruction to be executed following the instruction currently being executed.
[0149] [Fig.2] is a view similar to [Fig.l] schematically representing an example of a linear extraction attack on the code contained in the memory 10.
[0150] In a preliminary step, the attacker must find the interconnections of circuit 1.
[0151] In a first step, the attacker places a probe 200 on the reset signal to force the reset of the instruction register 12. Thus, the core of the microprocessor 14 receives null instructions: 00000 ... 0 which it interprets as instructions without effect (no operation, or nop). The core of the microprocessor 14 therefore moves on to reading the next instruction and so on. By this, the attacker succeeds in causing a linear and progressive reading of the program code contained in the memory 10, instruction after instruction.
[0152] In a second step, the attacker finds the interconnections of the instruction bus 11 and places one or more probes 201 there. Thus, the attacker manages to read the instructions of the code successively and bit by bit.
[0153] In a third optional step, the attacker places a probe 202 on the clock signal terminal clk to know when to read the data on the instruction bus 11.
[0154] This is an example of an attack that is extremely difficult to counter since the attacker replaces all instructions read from memory with null instructions (nops) in the instruction register 12, by forcing the reset of the instruction register 12.
[0155] Furthermore, secure circuit codes are generally encrypted. However, this does not protect them against linear extraction by probing, because the code must be decrypted before its execution.
[0156] [Fig.3] is a view similar to [Fig.2], schematically illustrating a circuit of decryption 16 of the code instructions. As shown in the figure, the probes 200, 201, 202 are placed downstream of the decryption circuit 16, which allows the attacker to read the instructions already decrypted.
[0157] [Fig.4] is a view similar to [Fig.3] schematically representing a first example of circuit 1 according to the invention.
[0158] Circuit 1 has the same architecture as that described above, namely a memory 10, a microprocessor core 14, an instruction bus 11, a read bus 13, an address bus 15 and an instruction register 12 for storing instructions controlled by a clock signal clk and a reset signal reset for resetting the contents of the instruction register 12. The decryption circuit 16 remains optional and is present in the case where the instructions are stored in the memory in encrypted form. [Fig. 15] illustrates the circuit of [Fig.4] without decryption circuit 16.
[0159] In one embodiment shown in [Fig.13], the instruction register 12 is part of the microprocessor core 14.
[0160] The memory 10 is for example of the Flash, ROM, RAM or DRAM type. In the latter case shown in [Fig. 14], the memory 10 is external, that is to say not embedded in the same electronic circuit 1 as the microprocessor core 14 executing the instructions.
[0161] The program code stored in the memory 10 is modified to include protection instructions called "security markers" inserted among the program instructions so as to be read during the execution of the program. For example, the security markers are inserted into the code with a variable periodicity to make their detection and / or identification difficult. In order to deceive an observer and make the detection and / or identification of the security markers even more complicated, it is possible for them to be different from each other, in particular by their payload.
[0162] The core of the microprocessor 14 comprises a protection circuit 18 against an attempt at linear extraction, capable of triggering a predefined alert action 300 in the event of non-detection of a security marker according to a predefined monitoring rule.
[0163] The predefined monitoring rule may be the non-detection of a security marker for a predefined duration and / or after a predefined number of program instructions have been read.
[0164] The protection circuit 18 comprises for example, as illustrated, a decreasing instruction or clock cycle loading counter 20, configured to be decremented at each instruction loading in the instruction register 12 or at each clock cycle, and which is periodically reset to a configurable positive value.
[0165] The resetting of the instruction or clock cycle load counter 20 is regularly performed by a safety marker before reaching zero. If the instruction or clock cycle load counter 20 reaches zero, the protection circuit 18 is configured to trigger the predefined alert action 300.
[0166] The instruction or clock cycle load counter 20 may alternatively be incremented from zero in which case the predefined alert action 300 is triggered when the instruction or clock cycle load counter 20 reaches a predefined value (optionally configurable). The configurable predefined value may be a value contained in the payload of the previously executed security marker.
[0167] The predefined alert action 300 can be: resetting the circuit 1, erasing the memory 10, resetting the memory read address to zero (in which case the attacker reads the same short initial instruction sequence indefinitely), assigning inconsistent non-consecutive values to the memory read address, in particular by loading a random value into the memory address register at each clock cycle (in which case the code extraction becomes non-linear), skipping a code section, in particular a sensitive section to be protected (in which case the attacker extracts useless code), etc.
[0168] Security markers can be inserted into the code during the compilation phase of the code, the code then being loaded into memory during programming of the circuit.
[0169] Alternatively, security markers are inserted into the code during execution of the latter, in particular when reading program instructions from memory.
[0170] This embodiment is shown in [Fig.5] where the memory 10 contains control logic having a logic block 100 periodically inserting a security marker among the program instructions as they are read. In this case, the code stored in the memory 10 does not include a security marker and the memory control logic is modified so as to insert the security markers on the fly as the program instructions are read from the memory.
[0171] Logic block 100 sends a wait cycle command 115 to the microprocessor core 14 when loading a security marker into the instruction register 12 so that the microprocessor core 14 inserts a wait cycle into the execution flow when receiving the security marker. Thus, the microprocessor core 14 is notified of the receipt of a security marker rather than the instruction whose address it provided via the address bus 15.
[0172] [Fig.6] illustrates a schematic example of a portion of code protected according to the invention.
[0173] The security markers are preferably inserted into the code with a variable periodicity, so that the execution of the program instructions located between two consecutive security markers corresponds to a number of clock cycles less than that causing the triggering of the predefined alert action.
[0174] It should be noted that the number of clock cycles required to execute an instruction may be variable (and cannot be known in advance for some of them). The number of clock cycles leading to the triggering of the predefined alert action is therefore preferably considered for a worst case, being greater than the maximum number of clock cycles required to execute the program instructions located between two consecutive security markers.
[0175] Like any binary instruction, a security marker essentially comprises two fields: Yopcode which allows the marker to be identified, and the payload which can for example be varied to deceive an observer, making it very difficult to circumvent the detection of the attack. For example, it is possible to fix in the payload the initial value taken by the counter or to impose a payload value following a particular logic (increasing, decreasing, alternating, single value, etc.) in order to introduce variability allowing the attacker to be deceived. The usefulness of the payload is in fact to be able to optionally make variable the maximum number of clock cycles to be respected between two security markers under penalty of triggering the predefined alert action.
[0176] Additionally, if a program code includes special instructions such as a function call, a branch (jump), a loop, etc., the insertion of the security markers must be done while ensuring not to trigger a false alert.
[0177] [Fig.7] schematically represents a function call within a code of this type.
[0178] Function 2 is nested in the code "Function 1" and is called between instructions 7 and 8.
[0179] The execution of Function 2 leads to an increase in the number of executed instructions (and thus the number of elapsed clock cycles) between two security markers, risking triggering the predefined alert action 300 without reason if no precautions are taken.
[0180] A solution to this problem is illustrated in [Fig.8] where two security markers are added respectively at the beginning and at the end of the code of function 2, thus reducing the number of clock cycles separating two security markers below the activation threshold of the predefined alert action 300.
[0181] [Fig.9] schematically represents a connection within a code that risks triggering a false alert.
[0182] In the example illustrated, the connection is made from instruction 3 to instruction 7, i.e. a jump of 4 addresses.
[0183] At execution, the jump instruction prevents the execution of the security marker placed before instruction 6. This results in an increase in the number of instructions executed (and therefore the number of clock cycles elapsed) between two security markers at the risk of triggering the predefined alert action 300 without reason.
[0184] A solution to this problem is illustrated in [Fig.10] where a security marker is inserted at the destination address of the branch instruction.
[0185] [Fig. 11] schematically represents a loop within a code that may trigger a false alert.
[0186] In the illustrated example, the validity of a condition following instruction 8 causes the reading to loop back to the address of instruction 5 (which corresponds to a jump of 4 addresses backward).
[0187] In fact, the loop is executed as long as the condition is met, and each time instructions 5 to 8 are executed again, which leads to an increase in the number of executed instructions (and thus the number of elapsed clock cycles) between two security markers, risking triggering the predefined alert action 300 without reason.
[0188] A solution to this problem is illustrated in [Fig.12] where a safety marker is added at the head of the loop. The jump to the beginning of the loop in this case corresponds to 5 addresses backward.
[0189] The safety marker can alternatively be added at the end of the loop.
[0190] Without having to add security markers in the code, it is also possible to detect the absence of discontinuity instructions, according to the same principle.
[0191] Indeed, instead of having an instruction or clock cycle loading counter 20, the circuit 1, in particular the protection circuit 18 of the microprocessor 14, may comprise a continuity instruction counter 21, as illustrated in [Fig. 18]. This counter 21 may be configured to be decremented each time a continuity instruction is executed, the continuity instruction counter 21 being preferably configured to be periodically reset to a configurable value, the resetting of the continuity instruction counter 21 being regularly carried out by the execution of a discontinuity instruction before reaching an alarm threshold, in particular zero, the protection circuit 18 being configured to trigger the predefined alert action 300 when the continuity instruction counter 21 reaches the alarm threshold.
[0192] If we consider the example of the portion of code shown in [Fig. 16] and take as an example a decreasing continuity instruction counter 21, initialized to 4 and having an alarm threshold of zero, this counter will be reset by the linearly executed discontinuity instruction at address 6. It will decrease when instructions 7 to 10 are executed, and will reach zero when instruction 10 is executed, which will trigger a false alarm since there is no attack. To avoid this, it is useful either to increase the initial value of counter 21, or to insert a linearly executed discontinuity instruction between program instructions 7 to 10 whose execution corresponds to a number of clock cycles that can trigger the predefined alert action, without reason. In this case, the linearly executed discontinuity instruction is inserted between instructions 9 and 10.
[0193] [Fig. 17] shows two possibilities for inserting a linearly executed discontinuity instruction into the code portion of [Fig. 16]: either during code compilation ([Fig. 17] on the right), or outside memory and before loading the instructions into the instruction register ([Fig. 17] on the left).
[0194] When the linearly executed discontinuity instruction is inserted during code compilation, it is stored in memory and has a memory address. In the example shown in [Fig. 17] on the right, the linearly executed discontinuity instruction is inserted between instructions 9 and 10. It then takes the memory address 10 and in this case causes a unit increment of the memory address instructions that follow it, as shown in [Fig. 17] on the right.
[0195] When the linearly executed discontinuity instruction is inserted outside the memory and before the instructions are loaded into the instruction register, it then does not have a memory address, and causes the memory addresses of the instructions that follow it to be maintained. In [Fig. 17] on the left, the linearly executed discontinuity instruction is inserted between instructions 9 and 10 at the time when the microprocessor core is waiting to receive instruction 10. It therefore receives the discontinuity instruction instead of instruction 10, in order to avoid the untimely triggering of an alarm. A mechanism is then triggered which causes the core to continue requesting instruction 10. The core is for example configured to recognize a linearly executed discontinuity instruction and renew the request to read instruction 10 which was shifted by the insertion of the linearly executed discontinuity instruction.The core eventually receives instruction 10 to execute. In this case, the individual instructions retain their memory addresses. The discontinuity instruction has been inserted into the stream of instructions read from memory for execution by the core.
[0196] [Fig. 18] schematically represents a linearly executed discontinuity instruction insertion block 400 which is a circuit located outside the memory 10, communicating with it and with the instruction register 12. This variant makes it possible not to modify the compiler, and not to increase the memory surface.
[0197] [Fig. 19] schematically represents an example of a sequence of instructions to be executed following a storage attack in the instruction register of a discontinuity instruction generating a linear execution. In this case, it is a branch instruction whose condition is never fulfilled: beq rO, rl, imm (beq meaning "branch if equal"). The registers rO and rl being different, the branch to the address imm will never take place. This type of attack deactivates the write enable signal ('write_enable') of the instruction register 12 so that the instruction contained in the register (beq rO, rl, imm, which is in this case a discontinuity instruction with linear execution) is stored there for as long as the write enable signal is deactivated.The continuity instruction counter 21 alone will not be able to detect this kind of attack, since it is permanently reset by the stored discontinuity instruction (beq rO, rl, imm).
[0198] Thus, a linear execution discontinuity instruction counter 22 (shown in [Fig.20]) makes it possible, among other things, to detect this type of attack consisting of injecting into the core only discontinuity instructions generating a linear execution. In addition to the continuity instruction counter 21, the circuit 1, in particular the protection circuit 18, may comprise a linear execution discontinuity instruction counter 22 configured to be decremented each time an instruction is executed. linear execution discontinuity instruction, the linear execution discontinuity instruction counter 22 being preferentially configured to be periodically reset to a configurable value, the resetting of the linear execution discontinuity instruction counter 22 being regularly carried out by the execution of a non-linear execution discontinuity instruction before reaching an alarm threshold, in particular zero, the protection circuit 18 being configured to trigger the predefined alert action 300 when the linear execution discontinuity instruction counter 22 reaches the alarm threshold.
[0199] Let us take an example with the portion of code of [Fig. 19], a decreasing continuity instruction counter 21, initialized to 4, and a decreasing linearly executed discontinuity instruction counter 22, initialized to 8, the alarm thresholds of both counters being zero. Counter 21 will be reset to 4 at each instruction "beq rO, rl, imm" and will not decrease, while counter 22 will decrement at each instruction until the one at address 9 where it will reach its alarm threshold, causing the predefined alert action to be triggered.
[0200] The combination of counters 21 and 22 also makes it possible to counter another type of attack consisting of forcing the instruction address to vary linearly. [Fig.20] schematically illustrates an example of such an attack. The control signal 203 of a multiplexer 25 contained in the core 14 and providing the instruction address is forced so as to select the input generating a linear variation of the instruction address.
[0201] Thus, whatever the instruction (continuity or discontinuity), it will always be linearly executed. The continuity instruction counter 21 alone cannot detect such an attack, being reset with each discontinuity instruction entering the core. However, the linearly executed discontinuity instruction counter 22 will never be reset and will decrement with each discontinuity instruction (linearly executed), so the attack will be detected.
[0202] [Fig.21] illustrates the case of an attack deactivating the signal 204 containing the information that an instruction has been executed, internal signal 204 which can be deactivated commonly with the write_enable signal of the instruction register (the probe 200 is placed no longer on the reset which has not been shown for the sake of simplification, but on the write_enable signal of the instruction register 12). In this case, the continuity instruction counter 21 will not decrement, nor will the linear execution discontinuity instruction counter 22. Therefore, the continuity instruction counter 21 alone or combined where appropriate with the linear execution discontinuity instruction counter 22 cannot detect this type of attack, hence the interest in having a cycle counter 23 capable of detecting the absence of instruction execution.
[0203] The circuit 1, in particular the protection circuit 18, may therefore comprise a cycle counter 23 intended to detect an absence of execution of instructions, the counter 23 being configured to increment at each clock cycle, the resetting of the cycle counter 23, in particular to zero, being regularly carried out by the execution of an instruction before reaching an alarm threshold, in particular a configurable value, the protection circuit 18 being configured to trigger the predefined alert action 300 when the cycle counter 23 reaches the alarm threshold.
[0204] The cycle counter 23 may be used in combination with the continuity instruction counter 21 and optionally the linearly executed discontinuity instruction counter 22 (shown in dotted lines in [Fig.21] to indicate that it is optional).
[0205] Furthermore, in another embodiment, it is possible to detect linear execution sequences of excessive length with respect to the set of instructions used, by means of a linear execution sequence length counter 24.
[0206] The circuit 1 may therefore comprise a linear execution sequence length counter 24 intended to detect a sequence of continuity instructions and / or discontinuity instructions with linear execution of length exceeding a given length, configured to increment at each execution of an instruction or at each clock cycle, the resetting, in particular to zero, of the linear execution sequence length counter 24 being regularly carried out by the variation of at least one signal from the core of the microprocessor 14 indicating the end of execution of a linear execution sequence before reaching an alarm threshold, the protection circuit 18 being configured to trigger the predefined alert action when the linear execution sequence counter reaches the alarm threshold.
[0207] This variant with linear execution sequence length counter allows, among other things, to detect all the attacks previously described (activation of the reset of the instruction register, storage of an instruction in the instruction register, forcing linear variation of the instruction address, etc.).
[0208] The linear execution sequence length counter 24 may have different locations in the circuit 1, as shown in [Fig.22].
[0209] It can be connected to the instruction address bus 15. Thus, it is possible to count the length of a linear execution sequence by reading the address (unit increment when successive addresses follow one another).
[0210] The linear execution sequence length counter 24 can be connected to the internal signals of the core. Thus, it is possible to count the length of a linear execution sequence by observing these signals, for example as long as the control of the address multiplexer is maintained by selecting the "linear increment of the address" input, the linear execution sequence continues.
[0211] The linear execution sequence length counter 24 can be connected to the instruction bus 12. Thus, it is possible to count the length of a linear execution sequence by observing specific bits of the instruction (for example bits of the funct3 and opcode fields of the code of an instruction for RISC-V core) so as to know whether or not it is a discontinuity instruction.
[0212] The variants previously described in [Fig. 13] (instruction register forming part of the microprocessor core) and in [Fig. 14] (external memory) are reproducible on the embodiments aiming to detect an absence of discontinuity instruction rather than a security marker.
[0213] An example of a field of application of the present invention is the protection of secure circuits (for example smart cards, secure microcontrollers, etc.) against the extraction of their program and the sensitive data they contain (cryptography keys, various rights, etc.).
[0214] An example of a market affected by linear code extraction is that of printer ink cartridges (linear extraction of the code from manufacturer cartridges to sell compatible copies) which can therefore be protected by a secure chip according to the invention.
[0215] The invention is not limited to the embodiments described above. For example, it is possible to implement the detection method according to the invention in a purely software manner by implementing it in microcontrollers, in particular real-time microcontrollers, known as watchdog microcontrollers, by using the intrinsic reset mechanism of the watchdog circuit. The counters previously described can be increasing, decreasing, or any other variant.
[0216] Characteristics of the invention according to its different aspects are given below, organized in the form of items. Each independent item relates to an independent object of the invention, which can be combined with other items or with other characteristics of the invention disclosed above.
[0217] Iteml. Method for detecting an attempt at linear extraction of a program code stored in a memory (10) of an electronic circuit (1), the code comprising program instructions which, to be read by a microprocessor core (14), are loaded sequentially via an instruction bus (11) into an instruction register (12) for storing the instructions controlled at least by a clock signal (clk) and a reset signal (reset), the loading of each instruction into the instruction register (12) being carried out on an edge of the clock signal (clk), the code comprising discontinuity instructions and / or so-called "security marker" instructions inserted among the program instructions so as to be read during the execution of the program, the method comprising the triggering of a predefined alert action (300), in the event of non- detection of a discontinuity instruction or a security marker, according to a predefined monitoring rule.
[0218] Item 2. Method according to item 1, the predefined monitoring rule being the non-detection of a discontinuity instruction or a security marker for a predefined duration and / or after a predefined number of program instructions have been read and / or after a predefined number of clock cycles.
[0219] Item 3. Method according to item 1 or 2, the security markers being inserted into the code with a variable periodicity and / or the security markers being inserted into the code in such a way that the execution of the program instructions located between two consecutive security markers corresponds to a number of clock cycles lower than that causing the triggering of the predefined alert action (300), two consecutive security markers preferably being arranged in such a way that the number of clock cycles causing the triggering of the predefined alert action is greater than the maximum number of clock cycles necessary for the execution of the program instructions located between the two security markers.
[0220] Item4. Method according to any one of the preceding items, at least one security marker being inserted at the beginning and at the end of the code of a function forming part of the program and / or at least one security marker being inserted at the destination address of a branch instruction and / or at least one security marker being inserted at the beginning or at the end of the code of a loop forming part of the program.
[0221] Item 5. Method according to any one of the preceding items, the security markers being coded so as to have at least one particular bit of weight corresponding to the same weight as that of at least one characteristic bit of a branch instruction, the particular bit having the same encoded value of the characteristic bit, so as to trigger the predefined alert action (300) in the event of an attack by forcing to the complementary binary value of the characteristic bit.
[0222] Itemô. Method according to any one of the preceding items, the security markers being inserted into the code during the execution of the latter, in particular when reading the program instructions from the memory (10), the memory (10) preferably containing a control logic provided with a logic block (100) periodically inserting a security marker among the program instructions when they are read, the logic block (100) transmitting in particular a wait cycle command (115) to the core of the microprocessor (14) when loading a security marker into the instruction register (12) so that the core of the microprocessor (14) inserts a wait cycle into the execution flow when receiving the security marker.
[0223] Item 7. Method according to any one of the preceding items, the security markers being different from each other by their payload.
[0224] Item 8. Method according to item 1 or 2, comprising during a step of analyzing the code before loading it into the register, the insertion of at least one discontinuity instruction with linear execution in a portion of the code comprising program instructions whose execution corresponds to a number of clock cycles which can cause the triggering of the predefined alert action (300).
[0225] Item 9. Method according to item 8, the insertion of the discontinuity instruction with linear execution being carried out during the compilation of the code, this instruction being stored in the memory (10) and having a memory address.
[0226] Item 10. Method according to item 8, the insertion of the discontinuity instruction with linear execution being carried out after reading the instructions to be loaded from the memory (10) and before loading these instructions into the instruction register (12).
[0227] Item 1. Method according to any one of the preceding items, the predefined alert action (300) comprising at least one of the following actions: resetting the electronic circuit (1), erasing the memory (10), resetting the memory read address (10), taking non-consecutive values by the memory read address so that the extraction of the code becomes non-linear, and skipping a section of code, in particular a sensitive section to be protected.
[0228] Iteml2. Method according to any one of the preceding items, being implemented permanently to protect the entire program code, the first instruction of the latter being in particular a discontinuity instruction or a security marker.
[0229] Iteml3. Method according to any one of the preceding items, being implemented in a configurable manner via the configuration of a fuse, in particular of the once programmable type, or of a variable in non-volatile memory, in particular a Flash or EEPROM type memory, during the programming phase of the circuit, the value stored in the fuse or in the non-volatile memory being read at the start of the circuit, in particular at its power-up or at its wake-up after reset, said value making it possible to activate the detection method, and the first instruction of the program code being a discontinuity instruction or a security marker, if the method is activated.
[0230] Item 14. Method according to any one of items 1 to 12, being implemented to protect at least a portion of the program code delimited by a start address and an end address, the method being activated as soon as a program instruction whose address is between the start address and the end address is read to be executed, being deactivated as soon as a program instruction not belonging to said portion of code is read to be executed, said portion of code corresponding in particular to the start-up phase of the circuit or a part of code implementing security functions, in particular cryptographic tools graphics.
[0231] Item 15. Electronic circuit (1) comprising at least one memory (10), a microprocessor core (14), an instruction bus (11), a read bus (13), an address bus (15) and an instruction register (12) for storing instructions controlled at least by a clock signal (clk) and a reset signal (reset), the memory (10) being connected to the instruction register (12) by the instruction bus (11), the instruction register (12) being connected to the microprocessor core (14) by the read bus (13), the microprocessor core (14) comprising an instruction pointer (140) intended to contain the memory address of an instruction to be executed, the microprocessor core (14) being connected to the memory (10) by the address bus (15), the circuit (1) being configured to detect an attempt at linear extraction of a program code stored in the memory (10), the code comprising program instructions which,to be read by the microprocessor core (14), are loaded sequentially via the instruction bus (11) into the instruction register (12) on command of the clock signal (clk), the code comprising discontinuity instructions and / or instructions called "security markers" inserted among the program instructions so as to be read during the execution of the program, the core of the microprocessor (14) comprising a protection circuit (18) against an attempt at linear extraction capable of triggering a predefined alert action (300) in the event of non-detection of a discontinuity instruction or a security marker according to a predefined monitoring rule.
[0232] Item 16. Circuit according to the preceding item, at least one portion of the program code delimited by a start address and an end address being protected against linear extraction by the protection circuit (18), the start address and the end address being stored during programming of the circuit (1) in a non-volatile memory protected against erasure and modification, the protection circuit (18) preferably comprising registers for loading said start and end addresses, into which said addresses are loaded when starting the circuit (1), the protection circuit (18) being configured in particular to determine whether the instruction whose address is contained in the instruction pointer (140) belongs to said at least one portion of code by comparing this address with the start and end addresses.
[0233] Item 17. Circuit according to one of the two preceding items, comprising a so-called "watchdog" circuit used to restart the circuit (1) in the event of a program malfunction, the watchdog circuit comprising a watchdog counter incremented at the edge of a clock supplied by an oscillator internal to the circuit (1), the watchdog circuit being configured in reset mode so as to emit a signal for resetting the circuit (1) when the watchdog counter reaches a value predefined, the watchdog counter being reset periodically by the execution of a reset instruction for this counter.
[0234] Iteml8. Circuit according to the preceding item, comprising a hardware fuse allowing permanent activation of the watchdog circuit, so that when the fuse is blown during programming of the circuit, the watchdog circuit is permanently activated in reset mode.
[0235] Iteml9. Use of the circuit according to the previous item, the fuse being blown and the watchdog counter reset instructions being used as safety markers.
[0236] Item 20. Circuit according to any one of items 15 to 18, the protection circuit (18) comprising an instruction or clock cycle loading counter (20) configured to be decremented each time an instruction is loaded into the instruction register (12) or each clock cycle, the instruction or clock cycle loading counter (20) being configured to be periodically reset to a configurable value, the resetting of the instruction or clock cycle loading counter (20) being regularly carried out by a security marker before reaching an alarm threshold, in particular zero, the protection circuit (18) being configured to trigger the predefined alert action (300) when the instruction or clock cycle loading counter (20) reaches the alarm threshold.
[0237] Item 21. Circuit according to any one of items 15 to 18, comprising a continuity instruction counter (21) configured to be decremented each time a continuity instruction is executed, the continuity instruction counter (21) being preferably configured to be periodically reset to a configurable value, the resetting of the continuity instruction counter being regularly carried out by the execution of a discontinuity instruction before reaching an alarm threshold, in particular zero, the protection circuit (18) being configured to trigger the predefined alert action (300) when the continuity instruction counter (21) reaches the alarm threshold.
[0238] Item 22. Circuit according to any one of items 15 to 21, except item 20, comprising a linear execution discontinuity instruction insertion block (400) being a circuit located outside the memory (10), communicating with the latter and with the instruction register (12), this block being configured to insert at least one linear execution discontinuity instruction into a portion of the read code comprising program instructions whose execution corresponds to a number of clock cycles which can cause the predefined alert action (300) to be triggered.
[0239] Item 23. Circuit according to item 21, comprising a counter of instructions of dis linear execution continuity (22) configured to be decremented each time a linear execution discontinuity instruction is executed, the linear execution discontinuity instruction counter (22) being preferably configured to be periodically reset to a configurable value, the reset of the linear execution discontinuity instruction counter (22) being regularly carried out by the execution of a non-linear execution discontinuity instruction before reaching an alarm threshold, in particular zero, the protection circuit (18) being configured to trigger the predefined alert action (300) when the linear execution discontinuity instruction counter (22) reaches the alarm threshold.
[0240] Item 24. Circuit according to item 21 or 23, comprising a cycle counter (23) intended to detect an absence of execution of instructions, configured to increment at each clock cycle (clk), the resetting of the cycle counter, in particular to zero, being regularly carried out by the execution of an instruction before reaching an alarm threshold, in particular a configurable value, the protection circuit (18) being configured to trigger the predefined alert action (300) when the cycle counter (23) reaches the alarm threshold.
[0241] Item25. Circuit according to any one of items 15 to 19, comprising a linear execution sequence length counter (24) intended to detect a sequence of continuity instructions and / or discontinuity instructions with linear execution of length exceeding a given length, configured to increment at each execution of an instruction or at each clock cycle, the resetting, in particular to zero, of the linear execution sequence length counter (24) being regularly carried out by the variation of at least one signal from the core of the microprocessor (14) indicating the end of execution of a linear execution sequence before reaching an alarm threshold, the protection circuit (18) being configured to trigger the predefined alert action (300) when the linear execution sequence counter (24) reaches the alarm threshold.
[0242] Item 26. Method for protecting a program code comprising the insertion into this code of discontinuity instructions or security markers for the implementation of the method according to any one of items 1 to 14.
[0243] Item 27. Method according to item 26, said insertion being carried out during the programming of the code.
[0244] Item 28. Method according to item 26, said insertion being carried out during or at the end of the compilation of the code.
[0245] Item 29. Method according to item 26, said insertion being carried out after reading from the memory (10) storing the code of the instructions to be loaded and before loading these instructions into the instruction register (12).
Claims
Claims
1. Method for detecting an attempt at linear extraction of a program code stored in a memory (10) of an electronic circuit (1), the code comprising program instructions which, to be read by a microprocessor core (14), are loaded sequentially via an instruction bus (11) into an instruction register (12) for storing the instructions controlled at least by a clock signal (clk) and a reset signal (reset), the loading of each instruction into the instruction register (12) being carried out on an edge of the clock signal (clk), the code comprising discontinuity instructions and / or so-called "security marker" instructions inserted among the program instructions so as to be read during the execution of the program, the method comprising the triggering of a predefined alert action (300), in the event of non-detection of a discontinuity instruction or a security marker,according to a predefined monitoring rule.,
2. Method according to the preceding claim, the predefined monitoring rule being the non-detection of a discontinuity instruction or a security marker for a predefined duration and / or after a predefined number of program instructions have been read and / or after a predefined number of clock cycles.
3. Method according to one of the two preceding claims, the security markers being inserted into the code with a variable periodicity and / or the security markers being inserted into the code in such a way that the execution of the program instructions located between two consecutive security markers corresponds to a number of clock cycles lower than that causing the triggering of the predefined alert action (300), two consecutive security markers preferably being arranged in such a way that the number of clock cycles causing the triggering of the predefined alert action is greater than the maximum number of clock cycles necessary for the execution of the program instructions located between the two security markers.
4. A method according to any one of the preceding claims, at least one security marker being inserted at the beginning and at the end of the code of a function forming part of the program and / or at least one security marker being inserted at the destination address of a branch instruction and / or at least one security marker being inserted at the beginning or end of the code of a loop that is part of the program.
5. Method according to any one of the preceding claims, the security markers being coded so as to have at least one particular bit of weight corresponding to the same weight as that of at least one characteristic bit of a branch instruction, the particular bit having the same encoded value of the characteristic bit, so as to trigger the predefined alert action (300) in the event of an attack by forcing to the complementary binary value of the characteristic bit.
6. A method according to any preceding claim, wherein the security markers are inserted into the code during execution thereof, in particular when reading program instructions from the memory (10), the memory (10) preferably containing control logic having a logic block (100) periodically inserting a security marker among the program instructions as they are read, the logic block (100) in particular transmitting a wait cycle command (115) to the microprocessor core (14) when loading a security marker into the instruction register (12) so that the microprocessor core (14) inserts a wait cycle into the execution flow upon receiving the security marker.
7. A method according to any preceding claim, wherein the security markers differ from each other in their payload.
8. Method according to claim 1 or 2, comprising during a step of analyzing the code before loading it into the register, the insertion of at least one discontinuity instruction with linear execution in a portion of the code comprising program instructions whose execution corresponds to a number of clock cycles which can cause the triggering of the predefined alert action (300).
9. Method according to the preceding claim, the insertion of the linearly executed discontinuity instruction being carried out during the compilation of the code, this instruction being stored in the memory (10) and having a memory address.
10. Method according to claim 8, the insertion of the linearly executed discontinuity instruction being carried out after reading the instructions to be loaded from the memory (10) and before loading these instructions into the instruction register (12).
11. A method according to any preceding claim, the action predefined alert (300) comprising at least one of the following actions: resetting the electronic circuit (1), erasing the memory (10), resetting the memory read address (10), taking non-consecutive values by the memory read address so that the extraction of the code becomes non-linear, and skipping a section of code, in particular a sensitive section to be protected.
12. Method according to any one of the preceding claims, being implemented permanently to protect the entire program code, the first instruction of the latter being in particular a discontinuity instruction or a security marker.
13. Method according to any one of the preceding claims, being implemented in a configurable manner via the configuration of a fuse, in particular of the once programmable type, or of a variable in non-volatile memory, in particular a Flash or EEPROM type memory, during the programming phase of the circuit, the value stored in the fuse or in the non-volatile memory being read at the start of the circuit, in particular when it is powered up or when it wakes up after resetting, said value making it possible to activate the detection method, and the first instruction of the program code being a discontinuity instruction or a security marker, if the method is activated.
14. Method according to any one of claims 1 to 12, being implemented to protect at least a portion of the program code delimited by a start address and an end address, the method being activated as soon as a program instruction whose address is between the start address and the end address is read to be executed, being deactivated as soon as a program instruction not belonging to said portion of code is read to be executed, said portion of code corresponding in particular to the start-up phase of the circuit or a part of code implementing security functions, in particular cryptographic tools.
15. Electronic circuit (1) comprising at least one memory (10), a microprocessor core (14), an instruction bus (11), a read bus (13), an address bus (15) and an instruction register (12) for storing instructions controlled at least by a clock signal (clk) and a reset signal (reset), the memory (10) being connected to the instruction register (12) by the instruction bus (11), the register
16.
17. instruction register (12) being connected to the microprocessor core (14) by the read bus (13), the microprocessor core (14) comprising an instruction pointer (140) intended to contain the memory address of an instruction to be executed, the microprocessor core (14) being connected to the memory (10) by the address bus (15), the circuit (1) being configured to detect an attempt at linear extraction of a program code stored in the memory (10), the code comprising program instructions which, to be read by the microprocessor core (14), are loaded sequentially via the instruction bus (11) into the instruction register (12) on command of the clock signal (clk), the code comprising discontinuity instructions and / or so-called "security marker" instructions inserted among the program instructions so as to be read during the execution of the program,the core of the microprocessor (14) comprising a protection circuit (18) against an attempt at linear extraction capable of triggering a predefined alert action (300) in the event of non-detection of a discontinuity instruction or a security marker according to a predefined monitoring rule., Circuit according to the preceding claim, at least a portion of the program code delimited by a start address and an end address being protected against linear extraction by the protection circuit (18), the start address and the end address being stored during programming of the circuit (1) in a non-volatile memory protected against erasure and modification, the protection circuit (18) preferably comprising registers for loading said start and end addresses, into which said addresses are loaded when starting the circuit (1), the protection circuit (18) being in particular configured to determine whether the instruction whose address is contained in the instruction pointer (140) belongs to said at least one portion of code by comparing this address with the start and end addresses. Circuit according to one of the two preceding claims, comprising a so-called "watchdog" circuit used to restart the circuit (1) in the event of a malfunction of the program, the watchdog circuit comprising a watchdog counter incremented at the edge of a clock supplied by an oscillator internal to the circuit (1), the watchdog circuit being configured in reset mode so as to emit a signal for resetting the circuit (1) when the watchdog counter reaches a preset value, the watchdog counter being reset periodically by the execution of a reset instruction for this counter.
18. A circuit according to the preceding claim, comprising a hardware fuse allowing permanent activation of the watchdog circuit, so that when the fuse is blown during programming of the circuit, the watchdog circuit is permanently activated in reset mode.
19. Use of the circuit according to the preceding claim, the fuse being blown and the watchdog counter reset instructions being used as security markers.
20. A circuit according to any one of claims 15 to 18, the protection circuit (18) comprising an instruction or clock cycle loading counter (20) configured to be decremented each time an instruction is loaded into the instruction register (12) or each clock cycle, the instruction or clock cycle loading counter (20) being configured to be periodically reset to a configurable value, the resetting of the instruction or clock cycle loading counter (20) being regularly performed by a security marker before reaching an alarm threshold, in particular zero, the protection circuit (18) being configured to trigger the predefined alert action (300) when the instruction or clock cycle loading counter (20) reaches the alarm threshold.
21. Circuit according to any one of claims 15 to 18, comprising a continuity instruction counter (21) configured to be decremented each time a continuity instruction is executed, the continuity instruction counter (21) being preferably configured to be periodically reset to a configurable value, the resetting of the continuity instruction counter being regularly carried out by the execution of a discontinuity instruction before reaching an alarm threshold, in particular zero, the protection circuit (18) being configured to trigger the predefined alert action (300) when the continuity instruction counter (21) reaches the alarm threshold.
22. A circuit according to any one of claims 15 to 21, except claim 20, comprising a linearly executed discontinuity instruction insertion block (400) being a circuit located outside the memory (10), communicating with it and with the register of instructions (12), this block being configured to insert at least one discontinuity instruction with linear execution into a portion of the read code comprising program instructions whose execution corresponds to a number of clock cycles which can cause the triggering of the predefined alert action (300).
23. A circuit according to claim 21, comprising a linearly executed discontinuity instruction counter (22) configured to be decremented upon each execution of a linearly executed discontinuity instruction, the linearly executed discontinuity instruction counter (22) being preferably configured to be periodically reset to a configurable value, the reset of the linearly executed discontinuity instruction counter (22) being regularly carried out by the execution of a non-linearly executed discontinuity instruction before reaching an alarm threshold, in particular zero, the protection circuit (18) being configured to trigger the predefined alert action (300) when the linearly executed discontinuity instruction counter (22) reaches the alarm threshold.
24. Circuit according to claim 21 or 23, comprising a cycle counter (23) intended to detect an absence of execution of instructions, configured to increment at each clock cycle (clk), the resetting of the cycle counter, in particular to zero, being regularly carried out by the execution of an instruction before reaching an alarm threshold, in particular a configurable value, the protection circuit (18) being configured to trigger the predefined alert action (300) when the cycle counter (23) reaches the alarm threshold.
25. A circuit according to any one of claims 15 to 19, comprising a linear execution sequence length counter (24) for detecting a sequence of continuity instructions and / or discontinuity instructions with linear execution of a length exceeding a given length, configured to increment at each execution of an instruction or at each clock cycle, the resetting, in particular to zero, of the linear execution sequence length counter (24) being regularly carried out by the variation of at least one signal from the core of the microprocessor (14) indicating the end of execution of a linear execution sequence before reaching an alarm threshold, the protection circuit (18) being configured to trigger the predefined alert action (300) when the execution sequence counter linear (24) reaches the alarm threshold.
26. Method for protecting a program code comprising the insertion into this code of discontinuity instructions or security markers for implementing the method according to any one of claims 1 to 14.
27. Method according to the preceding claim, said insertion being carried out during the programming of the code.
28. Method according to claim 26, said insertion being carried out during or at the end of the compilation of the code.
29. Method according to claim 26, said insertion being carried out after reading from the memory (10) storing the code of the instructions to be loaded and before loading these instructions into the instruction register (12).