Method of writing a key into non-volatile memory
The method uses pre-calculated CRCs to verify key writing in non-volatile memory, ensuring secure and error-free storage without compromising security, addressing the need for reliable verification in existing technologies.
Patent Information
- Application Number
- FR2023001053
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-02-03
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2043-02-03
AI Technical Summary
Existing methods for writing security keys to non-volatile memory lack a reliable verification process that maintains security, as they often require test interfaces that compromise key security during verification.
A method involving pre-calculated cyclic redundancy codes (CRC) is used to verify the writing of security keys by storing a first CRC in a register, copying the key to a second register, and calculating a second CRC on the attached message, considering the writing valid only if the second CRC equals zero, ensuring security without exposing the key.
This method ensures secure and error-free writing of keys to non-volatile memory by maintaining the same security level as the key, without requiring external verification, thus preventing key extraction.
Smart Images

Figure 00000010_0000 
Figure 00000010_0001 
Figure 00000011_0000
Abstract
Description
Title of the invention: Method for writing a key in a non-volatile memory Technical field
[0001] The present description relates generally to methods of writing a key in a non-volatile memory and the associated electronic circuits. Prior art
[0002] In an electronic circuit, certain digital codes constituting keys, called security keys, must be written and stored in a non-volatile memory and made inaccessible from outside the circuit. In other words, these keys are likely to be manipulated by the integrated circuit in which they are located but must not be able to be extracted from this circuit. However, during manufacturing, and more particularly during a circuit customization phase, these keys are transferred into the circuit. It is necessary to verify that the writing has been carried out correctly. Verification methods exist but they lead to a reduction in security. Summary of the invention
[0003] There is a need for a method of writing a key to non-volatile memory that allows verification that the key has been correctly written while maintaining the security level.
[0004] One embodiment overcomes all or part of the drawbacks of known methods for writing a key in a non-volatile memory.
[0005] One embodiment provides a method for verifying a writing of a key in a non-volatile memory comprising the following steps: - storing in a register of an interface of said memory, a first cyclic redundancy code of said key, precalculated; - write the security key to a non-volatile memory area; - copy the security key written in said area to a second register of said interface; - calculate a second cyclic redundancy code on a message formed by the copied security key to which the first cyclic redundancy code is attached; if the second cyclic redundancy code is equivalent to the zero value, consider the writing of the security key in said non-volatile memory as valid.
[0006] In one embodiment, if the second cyclic redundancy code is not equivalent to the zero value, then one of the steps is invalid.
[0007] One embodiment provides a method of writing a key to a non-volatile memory. volatile of an integrated circuit comprising at least one communication interface with the exterior of the circuit, comprising the steps of: - transferring from outside the circuit: a key into a second register of an interface of the non-volatile memory; and a first pre-calculated cyclic redundancy code into a first register of said interface; - calculating a result of a third cyclic redundancy code on a message formed by the key to which the first pre-calculated cyclic redundancy code is attached; if the third cyclic redundancy code is equivalent to zero, then writing the security key in the second register is considered valid and is followed by the steps of the above method.
[0008] In one embodiment, if the third cyclic redundancy code is not equivalent to the zero value, then one of said steps is not valid.
[0009] In one embodiment, the second and / or third cyclic redundancy code equivalent to the zero value is 0x00.
[0010] In one embodiment, the key is encoded over 128 bits.
[0011] In one embodiment, the cyclic redundancy codes are coded on 8 or 16 bits.
[0012] In one embodiment, the second register is configured to be non-readable except for a transfer from the interface to the memory and vice versa.
[0013] In one embodiment, the non-volatile memory is a FLASH memory.
[0014] One embodiment provides an electronic circuit configured to implement such a method. Brief description of the drawings
[0015] These characteristics and advantages, as well as others, will be explained in detail in the following description of particular embodiments given without limitation in relation to the attached figures among which:
[0016] [Fig.l] represents an example of an integrated circuit of the type to which the described embodiments apply;
[0017] [Fig.2] represents, schematically, partially and in the form of blocks, a non-volatile memory device according to one embodiment;
[0018] [Fig. 3] represents, in the form of blocks, steps of an implementation mode of a method for verifying the writing of a key in a non-volatile memory; and
[0019] [Fig.4] represents, in the form of blocks, steps of another mode of implementation of a method for verifying the writing of a key in a non-volatile memory. Description of the embodiments
[0020] The same elements have been designated by the same references in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same references and may have identical structural, dimensional and material properties.
[0021] For the sake of clarity, only the steps and elements useful for understanding the embodiments described have been shown and are detailed.
[0022] Unless otherwise specified, when referring to two elements connected to each other, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") to each other, this means that these two elements can be connected or be connected by means of one or more other elements.
[0023] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made unless otherwise specified to the orientation of the figures.
[0024] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "of the order of" mean to within 10%, preferably to within 5%.
[0025] [Fig.l] represents an example of an integrated circuit 100 of the type to which the described embodiments apply.
[0026] The device 100 comprises a non-volatile memory 104 (FLASH MEMORY), for example of the FLASH memory type, capable of communicating, via a communication bus 114, with a non-volatile memory interface 106 (FLASH INTERFACE) configured to write or read data in and from the non-volatile memory 104.
[0027] The device 100 further comprises, for example, a processing unit 110 (CPU) comprising one or more processors under control of instructions stored in an instruction memory 112 (INSTR MEM). The instruction memory 112 is for example of the random access type (Random Access Memory, RAM). The processing unit 110 and the memory 112 communicate, for example, via a system bus 140 (data, address and command). The FLASH memory 104 is connected to the system bus 140 via the non-volatile memory interface 106 and via the bus 114. The device 100 further comprises an input / output interface 108 (I / O interface) connected to the system bus 140 to communicate with the outside.
[0028] The device 100 can integrate other circuits implementing other functions (for example, one or more volatile and / or non-volatile memories, other processing units), symbolized by a block 116 (FCT) in [Fig.l].
[0029] The described embodiments relate to writing a key into the non- volatile 104 or an area thereof, via a transfer of this key from the interface 106 in which this key is stored in a write-only memory or register (not readable from the bus 140). When the key is transferred from the interface 106 to the memory 104, the corresponding area of the memory 104 can no longer be read from the outside (via the bus 140).
[0030] A difficulty lies in the need to ensure that the key can be transferred, without error, into the memory 104 without this key needing to be read there for verification by an interface accessible from outside the circuit.
[0031] Indeed, one solution would be to keep "open", i.e. operational, a test interface which generally equips the circuit in order to access the memory 104 after writing the key and verify its consistency with the original key. However, conversely, it is desirable to deactivate the test interface before any key storage in the circuit in order to avoid a flaw in the security of the keys.
[0032] Typically, to verify that the writing of a data item was carried out without error, without having to verify bit by bit, a hashing procedure is used, providing a reduced-size code of this data item. One of the most common verification codes is the cyclic redundancy code or CRC. The CRC calculation is generally carried out in hardware by a finite state machine and is added to the end of the data item that it signs, and stored with it. A CRC is characterized by its number of bits, which determines its robustness in terms of error detection.
[0033] An example of application of the described embodiments concerns the writing of a key authorizing the unlocking (opening for access from the outside) of the memory, for example for debugging purposes. In such a case, the key must be able to be stored by the manufacturer in the memory 104 without it being able to be subsequently taken outside the circuit.
[0034] According to the embodiments described, provision is made to carry out the verification of a CRC linked to a key by a program of the interface 106 by storing this CRC in a volatile manner in the interface 106. This verification is carried out at least during its transfer from the interface 106 to a dedicated area of the memory 104, and preferably both during the storage of this key in this interface 106 and during its transfer from the interface 106 to a dedicated area of the memory 104. The CRC of the key is therefore not stored in the circuit but is provided by the manufacturer or the personalization operator to the circuit.
[0035] [Fig.2] represents, schematically, partially and in the form of blocks, a non-volatile memory device 100 according to one embodiment.
[0036] More particularly, the example shown illustrates an embodiment of the non-volatile memory interface 106 and the non-volatile memory 104.
[0037] The non-volatile memory interface 106 includes storage registers volatile 206 (VOL MEM), including a register dedicated to storing key(s) 212 (KEYREG), and an area 214 which, after an instruction (OPTRST) has been executed, receives the copy by a state machine of the user option values.
[0038] According to one example, register 212 is configured to be writable and not readable except for transfer to and from memory 104. In other words, register 212 is not readable via bus 140, for example by microcontroller 110.
[0039] In the example shown, the non-volatile memory 104, for example of the flash type, comprises a first region 216 (USER FLASH) and a second region 218 (USER OPTION). The second region 218 corresponds for example to a section of user option bytes.
[0040] [Fig. 3] represents, in the form of blocks, steps of an embodiment of a method for verifying the writing of a key in the non-volatile memory 104 according to one embodiment.
[0041] The writing is illustrated by a step 310 (Launch prog operation in NVM memory (OPTSRT)) during which the key is transferred from the interface 106, for example from the register 212, to the dedicated area 218 of the flash memory 104, by the execution of instructions of a program contained in the interface 106.
[0042] In a step 312 (OBL - Load Key in volatile reg (KEYREG)), the key is read in the area 218 and transferred, via the bus 114, into the dedicated register 212 of the interface 106. This transfer may correspond to the execution of instructions for loading the user options stored in the area 218 (OBL, Option Byte Loading in English). The user option bytes are used to preconfigure the non-volatile memory device 100 before starting the calculation units for example. These bytes are for example loaded automatically after a reset or after a request from the program of the interface 106.
[0043] In a step 314 (Write pre-computed 8b-CRC in volatile Reg), a pre-computed result of the CRC of the key is stored in one of the registers 206. The pre-computed CRC is coded, for example, on 8 bits or on 16 bits.
[0044] In a step 316 (CRC (KEY+ precomputed CRC) = 0), a second CRC is calculated on a message formed by the key to which the precomputed code is attached. The second code is calculated by the same state machine as the precomputed code. Thus, if it has a zero value (0, or 0x0 for a byte), this means that the key written in the memory 104 does not contain an error. In this case (output branch Y of block 316), the key is considered valid (block 318 - Key Write operation successful). Otherwise (branch N of block 316), the writing of the key is considered invalid (block 307 - Key Write operation failed). Step 307 is, for example, followed by a return to step 310 for rewriting the key in the memory 104.
[0045] The method of [Fig.3] makes it possible, by means of the CRC calculation carried out on a message formed by the key to which the CRC of this key is attached, to check that the writing of the key in the non-volatile memory is valid, without having to reuse the key itself, and by maintaining a security level identical to the security level of the security key itself. For example, if the key is coded on 128 bits, the security level of the key is maintained at 128 bits and is not affected by the number of bits of the CRC.
[0046] [Fig.4] represents, in the form of blocks, steps of another mode of implementation of a method for verifying the writing of a key in a non-volatile memory.
[0047] Compared to [Fig.3], [Fig.4] illustrates steps for verifying the writing of the key from outside the circuit to the dedicated register 212 of the interface 106.
[0048] In a step 402 (Write Key in volatile Register (KEYREG)), the key is written, from outside the circuit, into the register 212.
[0049] In a step 404 (Write pre-computed 8b-CRC in volatile Reg), a pre-computed result of the CRC of the key written in step 402 is stored in one of the registers 206 of the interface 106. The pre-computed CRC is coded, for example, on 8 bits or on 16 bits. This pre-computed result is, for example, loaded, at the same time as the key from outside the circuit (to be verified).
[0050] In a step 406 (CRC (KEY+ precomputed CRC) = 0), a second CRC is calculated on a message formed by the key to which the precomputed code is attached. The second code is calculated by the same state machine as the precomputed code. Thus, if it has a zero value (0, or 0x0 for a byte), this means that the key written in the register 212 does not contain an error. In this case (output branch Y of block 406), the key is considered valid (block 408 - Key Write operation successful). Otherwise (branch N of block 406), the writing of the key is considered invalid (block 307 - Key Write operation failed).
[0051] After step 408, the method is similar to that of the example of [Fig.3] from step 310.
[0052] The writing method of [Fig.4] makes it possible, by virtue of the cyclic redundancy code carried out on a message formed by the security key to which the precalculated code is attached, to check that the writing of the security key in the second register 212 is valid before it is written to the zone 218 of the non-volatile memory 104 while maintaining a security level identical to the security level of the security key itself.
[0053] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will occur to those skilled in the art. In particular, the non-volatile memory 104 is, for example, a memory FLASH but the person skilled in the art could consider other types of non-volatile memories such as phase change memories.
[0054] Finally, the practical implementation of the embodiments and variants described is within the reach of the person skilled in the art from the functional indications given above. In particular, even if the examples are described for a 128-bit security key and 8-bit cyclic redundancy codes, the person skilled in the art will be able to implement security keys coded on a higher or lower number of bits as long as the validity of the writing of the key during steps 316 or 406 is equivalent to obtaining the zero value of the cyclic redundancy code carried out on a message formed by the copied security key to which the precalculated code is attached.
Claims
Claims
1. Method for verifying a writing of a key in a non-volatile memory (104) comprising the following steps: - storing in a register (206) of an interface (106) of said memory, a first cyclic redundancy code of said key, precalculated; - writing the security key in an area (218) of the non-volatile memory (104); - copying the security key written in said area (218) to a second register (212) of said interface (106); - calculating a second cyclic redundancy code on a message formed by the copied security key to which the first cyclic redundancy code is attached; if the second cyclic redundancy code is equivalent to the zero value, considering the writing of the security key in said non-volatile memory (104) as valid.
2. The method of claim 1, wherein if the second cyclic redundancy code is not equivalent to the zero value, then one of the steps is invalid.
3. Method for writing a key in a non-volatile memory of an integrated circuit comprising at least one interface for communication with the outside of the circuit, comprising the steps of: - transferring from outside the circuit: a key into a second register (212) of an interface of the non-volatile memory; and a first pre-calculated cyclic redundancy code in a first register of said interface; - calculating a result of a third cyclic redundancy code on a message formed by the key to which the first pre-calculated cyclic redundancy code is attached; if the third cyclic redundancy code is equivalent to zero, then the writing of the security key, in the second register (212) is considered valid and is followed by the steps of the method according to claim 1 or 2.
4. The method of claim 3, wherein if the third cyclic redundancy code is not equivalent to the zero value, then one of said steps is invalid.
5. A method according to any one of claims 1 to 4, wherein the second and / or third cyclic redundancy code equivalent to the zero value is 0x00.
6. A method according to any one of claims 1 to 5, wherein the key is encoded over 128 bits.
7. A method according to any one of claims 1 to 6, wherein the cyclic redundancy codes are encoded on 8 or 16 bits.
8. A method according to any one of claims 1 to 7, wherein the second register (212) is configured to be non-readable except for a transfer from the interface to the memory and vice versa.
9. A method according to any one of claims 1 to 8, wherein the non-volatile memory (104) is a FLASH memory.