Microprocessor equipped with a security hardware module

The microprocessor integrates a hardware security module to calculate and verify integrity codes, addressing vulnerabilities to fault injection attacks and enhancing security by ensuring accurate and timely fault detection.

FR3151923B1Active Publication Date: 2025-06-27COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023008277
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-07-31
Publication Date
2025-06-27
Estimated Expiration
2043-07-31

AI Technical Summary

Technical Problem

Existing microprocessors are vulnerable to fault injection attacks, which can alter machine instructions, data, or control flow, compromising the integrity and security of cryptographic systems and critical systems.

Method used

A microprocessor equipped with an arithmetic and logic unit, a main bank of registers, and a hardware security module that calculates and verifies integrity codes using a pre-programmed function parameterized by a secret key, ensuring that integrity codes are calculated without using the result of the instruction and triggering fault reports only when necessary.

Benefits of technology

The solution effectively enhances the security of the microprocessor by preventing unauthorized modifications to integrity codes and reducing the likelihood of untimely fault reports, thereby improving the overall security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000030_0000
    Figure 00000030_0000
  • Figure 00000030_0001
    Figure 00000030_0001
  • Figure 00000031_0000
    Figure 00000031_0000
Patent Text Reader

Abstract

Microprocessor equipped with a hardware security module The security module (28) is configured to: - when a data item Di is written in a register Ri,0 of the microprocessor: - calculate a code Ci, α2 using a function Qα2 parameterized by a secret key α2, then - record the code Ci, α2 in a register of an auxiliary bank and mark this register as having been updated, - only when all the registers of the auxiliary bank have been marked, the triggering, at a time tr1, of the replacement of a current secret key α1 by the key α2 and, for any new arithmetic and logic instruction whose execution begins after this time tr1, the use of the key α2 and the codes Ci, α2 recorded in the auxiliary bank of registers in place, respectively, of the key α1 and codes Ci, α1, to calculate and verify a Crest-t code. Fig. 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Microprocessor equipped with a hardware security module

[0001] The invention relates to a microprocessor equipped with a security hardware module and a method for executing a machine code using this microprocessor.

[0002] To obtain information about a binary code or to cause an unexpected operation of the binary code, many attacks are possible. For example, attacks known as "fault injection" or "fault attack" in English can be implemented. These attacks consist of disrupting the operation of the microprocessor or the memory containing the binary code, by various physical means such as changes in the supply voltages, changes in the clock signal, exposure of the microprocessor to electromagnetic waves and others.

[0003] Using such attacks, an attacker can alter the integrity of machine instructions or data to, for example, recover a secret key of a cryptographic system, bypass security mechanisms such as the verification of a PIN code during authentication or simply prevent the execution of a function essential for the security of a critical system.

[0004] These attacks can cause three types of faults, called execution faults, during the execution of the binary code:

[0005] 1) an alteration of the instructions of the executed machine code,

[0006] 2) an alteration of the data stored in the main memory or in microprocessor registers, and

[0007] 3) an alteration of the control flow of the machine code.

[0008] The control flow corresponds to the execution path followed during the execution of the machine code. The control flow is classically represented in the form of a graph known as a control flow graph.

[0009] To detect such execution faults, it has already been proposed to associate an integrity code with each data item processed by the microprocessor. Then, the integrity code associated with the result of the instruction that processes this data is calculated from the integrity codes of the processed data. Thus, if a fault occurs during the execution of this instruction, the result obtained does not correspond to the calculated integrity code. This makes it possible to detect this fault.

[0010] The integrity code is constructed from the data and, in addition, using a secret key known only to the microprocessor. Thus, it is difficult for an attacker to modify an integrity code so that it corresponds to a faulty result since it does not know the secret key. However, it must always be possible to construct the integrity code of the result using the integrity codes associated with the processed data and without using the result of the instruction executed by the arithmetic and logic unit. For example, such a solution is described in application EP4089559. The hardware circuits described in this application EP4089559 for calculating the integrity code corresponding to a particular arithmetic and logic operation are simple and fast because the function Qa used to calculate the integrity code uses conditional permutations for this purpose. More precisely, the function Qa uses permutations parameterized by a secret key a.Thus, thanks to the use of this Qa function, the calculation of integrity codes is fast so that it does not slow down or very little the execution of the machine code by the microprocessor.

[0011] However, the secret key a used by the function Qa can be determined quite easily from the moment when several pairs (D;, Qa(Di)) are known, where D; is a data item and Qa(Di) is the integrity code calculated for the data item D; using the function Qa. This therefore constitutes a weakness of the microprocessor which implements this function Qa and which can be used to compromise the security of the microprocessor.

[0012] The objective is to propose a microprocessor whose security can be improved while using hardware circuits for calculating the integrity code as simple and fast as those disclosed in application EP4089559.

[0013] The invention therefore relates to a microprocessor equipped with an arithmetic and logic unit, a main bank of registers and a hardware security module, in which:

[0014] a) the arithmetic and logic unit is capable of executing an arithmetic and logic instruction comprising an opcode and one or more operands which, when executed by the arithmetic and logic unit of the microprocessor, causes the performance of an operation Di*D2*...*Dn and the recording of the result of this operation in a register Rre, po of the main bank of registers, where:

[0015] - the index n is equal to the number of data D; processed by the arithmetic instruction and logical, the index n being greater than or equal to one,

[0016] - Di to Dn are data recorded, respectively, in registers Ri>0 to Rn>0 of the main bank of registers, the size, in number of bits, of each of these data Di being equal to 2d, where d is an integer greater than two,

[0017] - the registers Ri o to Rn>0 are the registers designated by the operands of the instruction arithmetic and logic,

[0018] - the symbol “*” is the arithmetic or logical operation designated by the opcode of arithmetic and logic instruction,

[0019] b) the security hardware module is configured to perform the following operations:

[0020] 1) each time an instruction to load a data item D; into a register R; o of the main register bank is executed by the microprocessor:

[0021] - the calculation of a code Ci>ai using a relation Ci>ai = Q.dtDj, where the function Qai is a pre-programmed function configured by a current secret key pre-recorded in the security hardware module and known only to the security hardware module, and

[0022] - recording the calculated code Ci>ai in a register Ri>b corresponding to the register Rij0, from a first auxiliary bank of registers,

[0023] 2) in parallel with the execution, by the arithmetic and logic unit, of the instruction arithmetic and logic which causes the operation Di*D2*...*Dn to be carried out, and the result of this operation to be recorded in the register Rre, po of the main bank of registers, the calculation of a code Cres t using the codes Ci,ai, C2,ab ... , Cn>c(i recorded in the first auxiliary bank of registers and without using the result Dres p, then

[0024] 3) verification that the calculated Cres t code corresponds to a Cres p code obtained from of the Dres p result and the triggering of the reporting of an execution fault if the Cres-t code does not correspond to the Cres p code and, otherwise, the inhibition of this reporting,

[0025] wherein the security hardware module is also configured to perform the following operations:

[0026] 4) each time that a data D; is written in a register Ri0 of the main bank of registers and before triggering the replacement of the current secret key al by a new secret key a2:

[0027] - the calculation of a code Ci>a2 using a relation Ci>a2 = Q^D;) where the function Qa2 is the same preprogrammed function as the Qai function except that the current secret key al is replaced by the new secret key a2, then

[0028] - recording the calculated code Ci>a2 in a register R; 2, corresponding to the register Rij0, from a second auxiliary bank of registers and marking this register as having been updated,

[0029] 5) only when all registers of the second auxiliary bank have been marked as having been updated, the triggering, at a time trb of the replacement of the current secret key al by the new secret key a2 and, from this time trb for any new arithmetic and logic instruction whose execution begins after this time trb the use of the secret key a2 and the codes Ci>c(2 recorded in the second auxiliary bank of registers in place, respectively, of the secret key al and the codes Ci,ai recorded in the first auxiliary bank of registers to calculate and verify the code Crest-t-

[0030] Embodiments of this microprocessor may include one or more of the following features:

[0031] 1) The security hardware module is configured for, after the time trb for any arithmetic and logic instruction whose execution began before time tri and whose execution has not yet been completed at time trb continues to use the secret key al and the codes Ci>ai recorded in the first auxiliary bank of registers to finalize the calculation of the code Crest-t and for the verification of this code Cres.t.

[0032] 2) The security hardware module is configured to:

[0033] - between the time tri and a time tdb for any arithmetic and logic instruction whose execution began before time tri and whose execution has not yet finished at time trb continue to use the secret key al and the codes Ci>ai recorded in the first auxiliary bank of registers to finalize the calculation of the code Crest-t and for the verification of this code Cres t ,and

[0034] - from time tdi:

[0035] - each time that a data D; is written in a register Rij0 of the main bank of registers and before triggering the replacement of secret key a2 by a new secret key a3:

[0036] - the calculation of a code CijC(3 using a relation CijC(3 = Qa3(Di) where the function Qa3 is the same preprogrammed function as the Qai function except that the secret key al is replaced by the secret key a3, then

[0037] - recording the code Ci,a3 calculated in the register Ri>b corresponding to the register Ri>0, from the first auxiliary bank of registers,

[0038] - in response to the trigger, at a time tr2 after the time tdb of the rem replacement of the secret key a2 by the new secret key a3, for any new arithmetic and logic instruction whose execution begins after this time tr2, the use of the secret key a3 and the codes Ci,a3 recorded in the first auxiliary bank of registers in place, respectively, of the secret key a2 and the codes Ci>a2 recorded in the second auxiliary bank of registers to calculate and verify the code Crestf

[0039] 3) The security hardware module is configured to trigger a counter which counts the number of clock cycles elapsed since time L, and compares the number of clock cycles counted by this counter to a predetermined number, time tdi corresponding to the time when the value of this counter crosses this predetermined number and the predetermined number being chosen between 5 and 300.

[0040] 4) The security hardware module includes a computing unit capable of:

[0041] - in parallel with the execution, by the arithmetic and logic unit, of the instruction arithmetic and logic which causes the operation Di*D2*...*Dn to be carried out, to execute the calculation of the code Cres_t using the codes Ci,ab C2>c(i , ... , Cn>c(i recorded in the first auxiliary bank of registers and without using the result Dres p, and

[0042] - to record the calculated Cres t code in the first auxiliary bank of registers as that code Crest_t,ai.

[0043] 5) The microprocessor comprises a hardware instruction processing chain comprising a succession of stages which process one after the other each instruction to be executed in the machine code, this succession of stages comprising at least the following stages: an instruction loader, a decoder, and the arithmetic and logic unit, each of these stages being able to work in parallel with the other stages.

[0044] 6)

[0045] - the main register bank comprises at least two address ports and at least two data ports to allow simultaneous loading of two data to be processed by the arithmetic logic unit,

[0046] - the first and second auxiliary register banks each comprise at least two address ports and at least two data ports to allow the simultaneous loading of two codes to be processed by the computing unit.

[0047] 7) The function Qa is defined by the following relation: Qa(Di) = P o Fa(Di), where P is a predetermined function and Fa is a function defined by the following relation: Fa(D i)= E0o.. .o Eq o ... o ENbE i(Di), where each function Eq is a stage of transpositions and the index q is an order number between zero and NbE-1, where NbE is an integer greater than one and less than or equal to d, each stage Eq of transpositions being defined by the following relation: Eq(x) = Tam,qo.. .o Taj,qo ... o Tai,qo Tao,q(x), where:

[0048] - x is a variable whose size, in number of bits, is equal to the size of the data Di,

[0049] - Tajjq is a conditional transposition, parameterized by the parameter ajjq, which permutes two blocks of bits B2j+i>q and B2j>q of the variable x when the parameter aj>q is equal to a first value and which does not permute these two blocks of bits when the parameter aj>q is equal to a second value, the transposition Taj>q being distinguished from all the other transpositions of the function Fa by the fact that it is the only one which permutes the two blocks B2|+Lq and B2j>q when the parameter aj>q is equal to the first value, the blocks B2j+i>q and B2j q of all the transpositions Taj>q of the stage Eq being different from each other and not overlapping so that all the transpositions Taj>q of the stage Eq can be executed in parallel,

[0050] - "m+1" is the total number of transpositions Taj>q of the stage Eq,

[0051] - "j" is an order number identifying the Taj transposition q among the other trans floor positions Eq,

[0052] - the symbol "o" denotes the operation of composition of functions,

[0053] - the concatenation of the bits of all the parameters (¾ of all the stages Eq is equal to the value of the secret key a, and

[0054] - for all stages Eq for which q is less than NbE-1 and for all trans positions Tajjq of this stage, the blocks B2j+i>q and B2j>q are located inside the same block of larger size permuted by a transposition of the upper stage Eq+i when the parameter of this transposition of the upper stage Eq+i is equal to the first value.

[0055] The invention also relates to a method for executing a binary code using a microprocessor equipped with an arithmetic and logic unit, a main bank of registers and a hardware security module, in which:

[0056] a) the arithmetic and logic unit executes an arithmetic and logic instruction comprising an opcode and one or more operands which, when executed by the arithmetic and logic unit of the microprocessor, causes the performance of an operation Di*D2*...*Dn and the recording of the result of this operation in a register Rre, po of the main bank of registers, where:

[0057] - the index n is equal to the number of data D; processed by the arithmetic instruction and logical, the index n being greater than or equal to one,

[0058] - Di to Dn are data recorded, respectively, in registers Ri o to Rn>0 of the main bank of registers, the size, in number of bits, of each of these data Di being equal to 2d, where d is an integer greater than two,

[0059] - the registers Ri>0 to Rn>0 are the registers designated by the operands of the instruction arithmetic and logic,

[0060] - the symbol “*” is the arithmetic or logical operation designated by the opcode of arithmetic and logic instruction,

[0061] b) the security hardware module performs the following operations:

[0062] 1) each time an instruction to load a data item D; into a register R; o of the main register bank is executed by the microprocessor:

[0063] - the calculation of a code Ci>ai using a relation Ci>ai = Q„|(D,), where the function Qai is a pre-programmed function configured by a secret key pre-recorded in the security hardware module and known only to the security hardware module, and

[0064] - recording the calculated code Ci>ai in a register R; b corresponding to the register Rij0, from a first auxiliary bank of registers,

[0065] 2) in parallel with the execution, by the arithmetic and logic unit, of the instruction arithmetic and logic which causes the operation Di*D2*...*Dn to be carried out and the result of this operation to be recorded in the register Rre, po of the main bank of registers, the calculation of a code Cres t using the codes Ci,ai, C2>c(i , ... , Cn>c(i recorded in the first auxiliary bank of registers and without using the result Dres p, then

[0066] 3) verification that the calculated Cres t code corresponds to a Cres p code obtained from of the Dres p result and the triggering of the reporting of an execution fault if the Cres-t code does not correspond to the Cres p code and, otherwise, the inhibition of this si- reported,

[0067] in which the security hardware module also performs the following operations:

[0068] 4) each time that a data D; is written in a register Ri0 of the main bank of registers and before triggering the replacement of the secret key al by a new secret key a2:

[0069] - the calculation of a code Ci>a2 using a relation Ci>a2 = CWDi) where the function Qa2 is the same preprogrammed function as the Qai function except that the secret key al is replaced by the secret key a2, then

[0070] - recording the calculated code Ci>a2 in a register R; 2, corresponding to the register Rij0, of a second auxiliary bank of registers and marking this register Ri2 as having been updated,

[0071] 4) only when all registers of the second auxiliary bank have been marked as having been updated, the triggering, at a time trb, of the replacement of the secret key al by the secret key a2 and, from this time trb for any new arithmetic and logic instruction whose execution begins after this time trb the use of the secret key a2 and the codes Ci>c(2 recorded in the second auxiliary bank of registers in place, respectively, of the secret key al and the codes Ci,ai recorded in the first auxiliary bank of registers to calculate and verify the code Crest-f

[0072] The invention will be better understood on reading the description which follows, given solely by way of non-limiting example and made with reference to the drawings in which:

[0073] - [Fig.l] is a schematic illustration of the architecture of an electronic calculator electronics capable of executing binary code;

[0074] - [Fig.2] is a schematic illustration of the structure of a hardware module of securing used in the calculator of [Fig.l],

[0075] - [Fig.3] is a flowchart of a method of executing binary code by the cal culator of [Fig.l].

[0076] In this description, the terminology, conventions and definitions of the terms used in this text are introduced in a chapter I. Then, detailed examples of embodiments are described in a chapter II with reference to the figures. In a chapter III, variants of these embodiments are presented. Finally, the advantages of the different embodiments are specified in a chapter IV.

[0077] Chapter I: Definitions, terminologies and conventions:

[0078] In the figures, the same references are used to designate the same elements.

[0079] In the remainder of this description, the well-known characteristics and functions of the skilled person are not described in detail.

[0080] A “program” designates a set of one or more predetermined functions that one wishes to have executed by a microprocessor.

[0081] An “instruction” means a machine instruction executable by a microprocessor. Such an instruction consists of:

[0082] - an opcode, or operation code, encoding the nature of the operation to be executed, and

[0083] -one or more operands defining the value(s) of the parameters of this operation.

[0084] The registers in which the data to be processed by an instruction are stored are typically identified by one or more operands of the instruction. Similarly, the register in which the result of the execution of an instruction is to be stored may also be identified by an operand of that instruction.

[0085] By "logic instruction" is meant an instruction in the microprocessor instruction set which, when executed by the arithmetic logic unit, records in a register Rres_p of the microprocessor the result of a Boolean operation. The opcode of the logic instruction identifies the Boolean operation to be executed by the arithmetic logic unit to modify or combine the data Di to Dn. Subsequently, the symbol "&" is used to generically designate a Boolean operation. Thus, the notation Di&D2&. . .&Dn generically designates a Boolean operation executed by the microprocessor 2 between the data Di to Dn. In the case where n = 1, the Boolean operation is the complement operation also known as the Boolean operation "NOT". In the case where n is greater than or equal to two, the Boolean operation is chosen from the group consisting of the following Boolean operations and their composition:

[0086] - the logical operation “OR”,

[0087] - the logical operation “EXCLUSIVE OR”,

[0088] - the logical operation “AND”.

[0089] By "arithmetic instruction" is meant an instruction in the microprocessor instruction set which, when executed by the arithmetic logic unit, records in a register Rres p of the microprocessor the result of an arithmetic operation. An arithmetic operation is different from a Boolean operation. Typically, an arithmetic operation belongs to the group consisting of bit shift operations, bit rotation operations, addition operations, multiplication operations and division operations.

[0090] By "Arithmetic and logic instruction" is meant both a logic instruction and an arithmetic instruction and the symbol is used to generically designate the corresponding Boolean or arithmetic operation. Hereinafter, unless otherwise indicated, the term "instruction" means an arithmetic and logic.

[0091] A “machine code” is a set of machine instructions. It is typically a file containing a succession of bits with the value “0” or “1”, these bits coding the instructions to be executed by the microprocessor. The machine code is directly executable by the microprocessor, that is to say without requiring prior compilation or interpretation.

[0092] A “binary code” is a file containing a succession of bits bearing the value “0” or “1”. These bits encode data and instructions to be executed by the microprocessor. Thus, the binary code comprises at least one machine code and, in addition, generally, digital data processed by this machine code.

[0093] We speak of execution of a function to designate the execution of the instructions carrying out this function.

[0094] The size of a data is equal to the number of bits contained in this data.

[0095] Chapter II: Example of embodiment

[0096] [Fig.l] represents an electronic computer 1 comprising a microprocessor 2, a main memory 4 and a mass storage medium 6. For example, the computer 1 is a computer, a smartphone, an electronic tablet, a smart card or the like.

[0097] The microprocessor 2 here comprises:

[0098] - a hardware chain 10 for processing the instructions to be executed,

[0099] - a set 12 of registers,

[0100] - a data input / output interface 16, and

[0101] - a bus 17 which connects the different components of the microprocessor 2 together.

[0102] The memory 4 is configured to store instructions of a binary code 31 of a program to be executed by the microprocessor 2. The memory 4 is a random access memory. Typically, the memory 4 is a volatile memory. The memory 4 may be a memory external to the microprocessor 2 as shown in [Fig.l]. In this case, the memory 4 is, for example, produced on a substrate mechanically separated from the substrate on which the various elements of the microprocessor 2 are produced, such as the chain 10.

[0103] By way of illustration, the binary code 31 comprises in particular a machine code 32 of a secure function. Each secure function corresponds to a set of several lines of code, for example several hundreds or thousands of lines of code, recorded at successive addresses in the memory 4. Here, each line of code corresponds to a machine word. Thus, a line of code is loaded into a register of the microprocessor 2 in a single read operation. Similarly, a line of code is written into the memory 4 by the microprocessor 2 in a single write operation. Each line of code encodes either a single instruction or a single piece of data.

[0104] The medium 6 is typically a non-volatile memory. For example, it is a memory of the EEPROM or Flash type. Here, it contains a backup copy 41 of the binary code 31. Typically, it is this copy 41 which is automatically copied into the memory 4 to restore the code 31, for example, after a power outage or similar or just before the execution of the code 31 begins.

[0105] By way of illustration, the microprocessor 2 complies with the ARM (“Advanced Risk Machine”) architecture version 7 and supports instruction sets such as Thumbl and / or Thumb2. An instruction set defines in a restrictive manner the syntax of the instructions that the microprocessor 2 is capable of executing. This instruction set therefore defines in particular all the possible opcodes for an instruction.

[0106] In this exemplary embodiment, the assembly 12 comprises general registers that can be used to store any type of data and dedicated registers. Unlike the general registers, the dedicated registers are dedicated to the storage of particular data generally automatically generated by the microprocessor 2.

[0107] In this embodiment, the assembly 12 comprises a main bank 120 of registers and two auxiliary banks 121 and 122 of registers. The auxiliary banks 121 and 122 are identical to the main bank 120.

[0108] The bank 120 is used to store the data processed and used by the processing chain 10. For this purpose, the bank 120 is configured to allow simultaneous reading of several data and writing of several data. For this, typically, the bank 120 comprises several address ports and several read / write ports.

[0109] Typically, the bank 120 has 64 or 32 registers or less and generally more than eight registers. The size of each register of the bank 120 is equal to the size of the data processed by the arithmetic and logic unit of the microprocessor 2. The size, in number of bits, of each data processed is equal to 2d, where d is an integer greater than two. For example, here, the size of each data is equal to 32 bits or 64 bits.

[0110] The interface 16 is in particular capable of acquiring data and instructions, for example, from the memory 4 and / or the support 6 external to the microprocessor 2.

[0111] Chain 10 is better known by the English term "pipeline". Chain 10 makes it possible to start executing an instruction of the machine code while the processing, by chain 10, of the previous instruction of this machine code is not yet finished. Such processing chains are well known and only the elements of chain 10 necessary for understanding the invention are described in more detail.

[0112] The chain 10 typically comprises the following stages:

[0113] - an 18 instruction loader,

[0114] - an instruction decoder 20,

[0115] - an arithmetic and logic unit 22 which executes the instructions,

[0116] - a rewrite circuit 24,

[0117] - a memory access module 26, and

[0118] - a hardware security module 28.

[0119] The loader 18 loads the next instruction to be executed by the unit 22 from the memory 4. More precisely, the loader 18 loads the instruction of the machine code 32 to which an ordinal counter 27 points. Unless its value is modified by the execution of a branch instruction, the value of the ordinal counter 27 is incremented by a regular step each time an instruction is executed by the arithmetic and logic unit 22. The regular step is equal to the difference between the addresses of two immediately consecutive instructions in the machine code 32.

[0120] The decoder 20 decodes the instruction loaded by the loader 18 to obtain configuration signals which configure the microprocessor 2 and, in particular the unit 22, so that it executes, typically during the next clock cycle, the loaded instruction. One of these configuration signals codes the nature of the operation to be executed by the unit 22. This configuration signal comes from or is constructed from the opcode of the loaded instruction. Other configuration signals indicate, for example, whether the instruction is an instruction to load data from the memory 4 or to write data into the memory 4. These configuration signals are transmitted to the unit 22. Other configuration signals comprise the values ​​of the loaded operands. Depending on the instruction to be executed, these signals are transmitted to the set 12 of registers or to the unit 22.

[0121] Unit 22 executes the decoded instructions one after the other.

[0122] The rewrite circuit 24 is capable of recording the result of the execution of a instruction by unit 22 in one or more of the registers of the set 12 of registers.

[0123] The memory access module 26 is capable, via the interface 16, of loading the data to be processed by the unit 22 into the set 12 of registers as well as saving data recorded in the set 12 in the memory 4.

[0124] The module 28 is capable of automatically executing the various operations necessary to secure the execution of the arithmetic and logic instructions by the unit 22. The module 28 operates independently and without using the unit 22. Thus, it is capable of working in parallel with the unit 22. For this purpose, it comprises in particular a secure non-volatile memory 29 and a calculation unit 30. No access to this memory 29 without going through the intermediary of the module 28 is provided. In this embodiment, the module 28 is configured to execute operations such as the following operations:

[0125] - verify an integrity code,

[0126] - construct an integrity code Ci from a data item D;,

[0127] - construct the integrity code Cres t of a result Dres p from integrity codes Ci, has to Cn,has processed data.

[0128] To carry out this last operation, the unit 30 comprises several hardware calculation circuits. Each of these hardware calculation circuits constructs an integrity code Cres t of the result Dres p from the integrity codes Ci,a to Cn,a of the data Di to Dn processed by the unit 22 and without directly using the result Dres p produced by the unit 22. Here, there is a hardware calculation circuit for the logic instructions and a hardware calculation circuit for each arithmetic instruction whose execution must be secure. Here, these hardware calculation circuits are the same as those described in application EP4089559. Their description is therefore not repeated here.

[0129] Unit 30 works in parallel with unit 22. It can be seen as another arithmetic and logic unit but specialized in the calculation of CreSf codes

[0130] The memory 29 is used to store the secret information necessary for the operation of the module 28. Here, it therefore includes in particular the secret keys ak used by the module 28 to secure the execution of the instructions by the unit 22.

[0131] [Fig.2] shows in more detail an embodiment of the security module 28. In [Fig.2], the benches 121 and 122 are considered as part of the module 28.

[0132] The module 28 comprises, in addition to the unit 30, in particular hardware circuits 40 and 42 for conditional permutation, a key generator 44 and a counter 46.

[0133] The conditional permutation hardware circuit 40 is capable of calculating the integrity code C i,a of a data item D; loaded into the bank 120 by the memory access module 26. For this, the circuit 40 implements the following relation: C; = Q. / Dj, where:

[0134] - the index i identifies the data D;, and

[0135] - function Qa is a function preprogrammed in module 28 and parameterized by the secret key a.

[0136] The function Qa is the function described in detail in application EP4089559. Here, it is simply recalled that the function Qa is defined by the following relation: Q<,(D,) = P o Fa(Di), where P is a predetermined function and Fa is a function defined by the following relation: Fa(Di)= E0o.. .o Eq o ... o ENbE_i(Di), where each function Eq is a stage of transpositions and the index q is an order number between zero and NbE-1, where NbE is an integer greater than one and less than or equal to d. Each stage Eq of transpositions is defined by the following relation: Eq(x) = Tamqo.. .o Taj,qo ... o Tai,qo T ao.q(x), where:

[0137] - x is a variable whose size, in number of bits, is equal to the size of the data Di,

[0138] - Taj,q is a conditional transposition, parameterized by the parameter aj q,

[0139] - "m+1" is the total number of transpositions Taj,q of the stage Eq,

[0140] - "j" is an order number identifying the Tajjq transposition among the other trans positions of the stage Eq, and

[0141] - the symbol "o" denotes the operation of composition of functions.

[0142] For example, here, the function P is the identity function.

[0143] Each conditional transposition Tajjq permutes two blocks of bits B2j+i>q and B2j>q of the variable x when the parameter aj>q is equal to a first value, for example one, and which does not permute these two blocks of bits when the parameter aj>q is equal to a second value, for example zero. The transposition Taj>q is distinguished from all the other transpositions of the function Fa by the fact that it is the only one which permutes the two blocks B2j+i>q and B2j>q when the parameter aj>q is equal to the first value. The blocks B2j+i>q and B 2j>q of all the transpositions Taj>q of the stage Eq are different from each other and do not overlap so that all the transpositions Taj>q of the stage Eq can be executed in parallel.

[0144] For all the stages Eq for which q is less than NbE-1 and for all the transpositions Taj>q of this stage, the blocks B2j+ijq and B2j>q are located inside the same block of larger size permuted by a transposition of the upper stage Eq+i when the parameter of this transposition of the upper stage Eq+i is equal to the first value.

[0145] The concatenation of the bits of all the parameters aj>q of all the stages Eq is equal to the value of the secret key a.

[0146] The conditional permutation hardware circuit 42 is capable of calculating the integrity code C i of a data item D; written in the bank 120 by the rewriting circuit 24. For this, the circuit 42 is structurally identical to the circuit 40.

[0147] The generator 44 generates keys a for use by the unit 30 and the conditional permutation circuits 40, 42. For example, the generator 44 is a random or pseudo-random number generator.

[0148] The counter 46 makes it possible to count a predetermined number Nc of clock cycles of the microprocessor 2. During a clock cycle, the unit 22 executes at most one instruction. The number Nc is chosen to be greater than or equal to a number Nmin. The number Nmin is equal to the minimum number of clock cycles necessary to ensure that the execution of all the instructions currently being executed by the microprocessor 2 at the time when the counter 46 begins to count the clock cycles is completed at the end of the Nmin clock cycles counted. Conversely, here, the number Nc is also chosen to be close to Nmin. For example, the number Nc is less than 10Nmin or 5Nmin and, preferably, less than 2Nmin. For this, in the majority of cases, the number Nc is chosen between 5 and 500 or between 5 and 300.

[0149] Memory 29 comprises in particular:

[0150] - a KO register intended to contain a first secret key,

[0151] - a register Kl intended to contain a second secret key different from the first secret key, and

[0152] - a register T intended to mark the registers of banks 121 and 122 which have been updated day.

[0153] The size of the register T is equal to the number of registers contained in each of the banks 121 and 122.

[0154] Subsequently, the register of bank 120 which contains the data D; is noted Ri 0. The registers of banks 121 and 122 which each contain an integrity code associated with the data D; are noted, respectively, Ru and R; 2. The bit of register T which indicates whether registers Ri4 and Ri2 have been updated is noted T;.

[0155] The operation of the microprocessor 2 to secure the execution of arithmetic and logic instructions will now be described in more detail with reference to [Fig.3]

[0156] The method begins with an initialization phase 60. During phase 60, the binary code 3 is loaded into the memory 4 from the medium 6. All the registers of the banks 120, 121 and 122 are initialized to zero. All the bits T; of the register T are also initialized to zero. Finally, the generator 44 generates two secret keys a1 and a2 and stores them in the registers, respectively, KO and KL. The register KO is marked as being the one which contains the current secret key and the bank 121 is marked as being the current auxiliary bank. Subsequently, the register KO or Kl which is marked as being the one which contains the current secret key is called the “current KO or Kl register”. The register KO or Kl which is not marked as being the one which contains the current secret key is called the “non-current KO or Kl register”. Similarly, the auxiliary bench that is not marked as the current auxiliary bench is called a "non-current auxiliary bench".

[0157] Then, a phase 62 of execution of the binary code 31 by the microprocessor 2 begins.

[0158] At the start of phase 62, during a step 68, counter 46 is triggered. Counter 46 automatically increments by one at the start of each clock cycle.

[0159] During phase 62, the machine code instructions are loaded one after the other by the loader 18 and then executed.

[0160] More precisely, for each of these instructions, during a step 70, the loader 18 loads the instruction to be executed.

[0161] Then, during a step 72, the loaded instruction is decoded by the decoder 20.

[0162] Then, during a step 74, the decoded instruction is executed by the unit 22. If the executed instruction is an arithmetic and logical instruction, this causes the performance of an arithmetic or logical operation which is written in the general form Di *D2*...*Dn is the obtaining of the result Dres p of this operation. In the operation Di*D2

[0163] - the index n is equal to the number of data D; processed by the arithmetic instruction and logical, the index n being greater than or equal to one,

[0164] - Di to Dn are data recorded, respectively, in registers Ri>0 to Rn>0 from the main bench 120,

[0165] - the registers Ri>0 to Rn>0 are the registers designated by the operands of the instruction arithmetic and logic,

[0166] - the symbol “*” is the arithmetic or logical operation designated by the opcode of arithmetic and logic instruction.

[0167] Here, the bank 120 contains only the data D; to be processed and none of the integrity codes Cij(lk of this data.

[0168] During a step 76, the rewrite circuit 24 writes the result Dres p delivered by the unit 22 following the execution of an arithmetic and logic instruction in a register Rre, po of the bank 120.

[0169] During a step 78, the module 26 loads, into the bank 120, the data D; to be processed by the unit 22 before the unit 22 begins processing these data D;. The loading of a data item Di into the bank 120 is typically triggered by the execution of a load instruction by the unit 22. Conversely, during step 78, the module 26 can also trigger the transfer of a data item D; recorded in the bank 120 to the memory 4. Such a transfer is generally also triggered by the execution of a write instruction by the unit 22. Generally, to optimize the transfer of data between the memory 4 and the microprocessor 2, cache memories are used. The use of cache memories being conventional, this is not described here in detail.

[0170] Each of steps 70 to 78 can be executed in parallel with the others, which makes it possible in particular to start executing an instruction before the end of the execution of the previous instruction(s).

[0171] In parallel with steps 70 to 78, the module 28 secures the operation of the microprocessor 2 against, in particular, fault injection attacks. For this, as explained below, the module 28 frequently changes the current secret key. Thus, the module 28 successively uses the keys a1, a2, a3, ..., ak, where k designates the order number of the secret key in the succession of secret keys used. Subsequently, ak designates the current key and ak+1 designates the next current key.

[0172] Each time an instruction to load a data item D; into a register Ri0 of the bank 120 is executed by the microprocessor 2, during a step 80, the circuit 40 calculates the code CijC(k using a relation CijC(k = Qak(Di). The function Qak is the function Qa, previously described, parameterized by the current secret key ak. During the first iteration of step 80, the current secret key is the key al recorded in the register KO.

[0173] Then, during a step 82, the code Cij(lk is recorded in the corresponding register of the current auxiliary bank. Thus, during the first execution of step 82, the code C i>al is recorded in the register Ru of bank 121. For example, for this, the calculated code Cij(lk is supplied to the module 26 at the same time as the data D; and the module 26 records the data D; in the register R; 0 of bank 120 and, in parallel, the code Cij(lk in the corresponding register of the current auxiliary bank.

[0174] In parallel with the execution, by unit 22 of the instruction which causes the operation Di*D2*...*Dn to be carried out and the result Dres p of this operation to be recorded in the register Rres_Pjo, during a step 90, unit 30 calculates a code CreSf. For this, the unit uses the codes Ckak, C2j(lk , ... , Cn>(lk recorded in the current auxiliary bank and the current secret key ak. During the first iteration of step 90, it is therefore the codes C2>ai, ... , Cn,ai and the key al which are used. The code Cres t is calculated without using the result Dres p.

[0175] Then, during a step 92, the unit 30 records the calculated Cres-t code in the corresponding register of the current auxiliary bank as Cres-Pj integrity code. <ik associé à la donnée Dres p. Lors de la première itération de l’étape 92, le code Cres t est donc enregistré en tant que code Cres-Pj<ii dans le registre Rres-Pji du banc 121.

[0176] During a step 100, each time that a data item D; is written in a register R^o of the bank 120, the circuit 42 calculates the code CijC(k+i using the relation CijC(k+i = Qak+i(Di). The function Qak+i is the function Qa, previously described, parameterized by the next secret key ak+1 recorded in the non-current register KO or Kl. The code Cij(lk+i is then recorded in the corresponding register of the non-current auxiliary bank. During the first iteration of step 100, the code Ci>a2 is therefore recorded in the register R; 2 of the bank 122.

[0177] Step 100 is executed each time the module 26 loads a data D; into the bank 120 and each time the circuit 24 writes a result Dres p into the bank 120.

[0178] In step 100, the module 28 also marks that the register, in which the code C i>ak+i was recorded, has been updated. For this, here, the bit T; of the register T is set to one.

[0179] In parallel with the previous steps, during a step 110, the module 28 detects execution faults of the unit 22 and, here, additionally verifies the integrity of the data recorded in the bank 120.

[0180] To detect an execution fault of the unit 22, during step 110, the module 28 verifies that the Cres t code calculated by the unit 30 corresponds to a Cres_p code defined by the following relation Cres_p = Q <ik(Dres-p), où le résultat Dres p est celui enregistré dans le registre Rres-P,o- Lorsque le code Cres_t calculé par le circuit matériel de l’unité 30 est égal, en absence de faute d’exécution, au code Cres-P, alors il y a correspondance entre les codes Cres t et Cres-P s’ils sont égaux. Dans ce cas, le code Cres-P est calculé à partir de the Dres p data delivered by unit 22 and by implementing the relation Cres_p = Qak(D res.p). When the Cres t code calculated by the hardware circuit of unit 30 is equal, in the absence of an execution fault, to the Dres p result, then there is a correspondence between the Cres-t and Cres_p codes if the Cres t code is equal to the Dres p result.

[0181] If there is no correspondence between the codes Cres p and Cres_t, the module 28 triggers the execution of a step 112 for reporting an execution fault. Otherwise, no reporting of an execution fault is triggered, i.e. the reporting of an execution fault is inhibited.

[0182] The execution of step 110 therefore makes it possible to detect a malfunction of the unit 22 because the Cres t code corresponds to the Cres p code only if the unit 22 has correctly executed the arithmetic and logic instruction.

[0183] Step 110 can also be triggered to check the integrity of a data item recorded in bank 120. In this case, the procedure is as described above except that module 28 uses data item D; and the corresponding integrity code recorded in the current auxiliary bank.

[0184] Step 110 can be triggered:

[0185] - each time a result Dres p is obtained by unit 22, and / or

[0186] - whenever an arithmetic and logic instruction is about to be executed by unit 22, just before its execution, to check the integrity of the data Di contained in the registers Rij0 identified by the operands of the instruction to be executed, and / or

[0187] - each time data from bank 120 is transferred to memory 4.

[0188] During step 112, the module 28 triggers the reporting of an execution fault.

[0189] In response to a signal of an execution fault, during a step 114, the microprocessor 2 implements one or more countermeasures. A large number of countermeasures are possible. The countermeasures implemented may have very different degrees of severity. For example, the countermeasures implemented may range from a simple display or a simple storage of an error message without interrupting the normal execution of the machine code 32 to a permanent shutdown of the microprocessor 2. The microprocessor 2 is considered to be out of service when it is permanently placed in a state where it is incapable of executing any machine code. Between these extreme degrees of severity, there are many other possible countermeasures such as:

[0190] - the indication via a human-machine interface of the detection of mistakes,

[0191] - immediate interruption of the execution of the machine code 32 and / or its reset, And

[0192] - the deletion of the machine code 32 from the memory 4 and / or the deletion of the copy 41 backup and / or deletion of secret data.

[0193] As the 32 machine code is executed, all the bits T; of the T register are set to one. This assumes that the 32 machine code uses all the registers of bank 120. This is generally the case. Furthermore, in the particular case of a machine code which does not use all the registers of bank 120, it is always possible to add to such a machine code additional instructions which use the registers which, in the absence of these additional instructions, were not used.

[0194] During a step 130, the module 28 triggers the replacement of the key ak by the key ak+1 as soon as the following two conditions are simultaneously satisfied:

[0195] - Condition 1): All bits T; of register T are equal to one, and

[0196] - Condition 2): Counter 46 has finished counting Nc clock cycles.

[0197] Condition 1) indicates that all registers in the non-current auxiliary bank have been marked as having been updated. In the first iteration, the non-current auxiliary bank is bank 122.

[0198] Condition 2) is satisfied as soon as the value of counter 46 is greater than the number Nc.

[0199] The instant at which the module 28 triggers the replacement of the secret key ak by the secret key ak+1 is noted “trk” thereafter.

[0200] In step 130, the module 28 changes the current key and the current auxiliary bank. To change the current key, the module 28 selects the non-current register KO or Kl and then marks this selected register as being the one which contains, from now on, the current key. Thus, from now on, the key ak+1 becomes the new current key ak and the previous current key is noted ak-1. The module 28 also selects the non-current auxiliary bank and marks it as being the new current auxiliary bank. The old current auxiliary bank becomes the new non-current auxiliary bank. Thus, the one of the two auxiliary banks 121 and 122 which was the current auxiliary bank before the time trk becomes the non-current auxiliary bank after the time trk and vice versa.

[0201] After the first iteration of step 130, the current key is now that contained in the register Kl, i.e. the key a2, and the current auxiliary bank is bank 122. From then on, for any new instruction whose execution begins after this instant trB, it is the secret key a2 and the codes Ci,a2 which are used during the execution of steps 80, 82, 90, 92, 100 and 110.

[0202] During step 130, the module 28 re-initializes the counter 46 to trigger the counting of Nc clock cycles again.

[0203] At time trk, for all the arithmetic and logic instructions currently being executed in the processing chain 10, the unit 30 is calculating the code(s) CreS-t using the codes Ci>c[ki, C2j <ik i, ... , Cri.,lk4 et la précédente clé courante ak-1. An arithmetic and logic instruction currently executing at time trk is an instruction whose execution began before time trk and whose execution has not yet completed at time trk. Thus, for these instructions in execution, even after time trk, it is preferable to keep the codes Cij(lk_i, C 2>ak_i, ... , Cri.„k । and the previous current key ak-1 available so as not to distort the calculations in progress of one or more codes CreSf Indeed, for the instructions in execution, the hardware circuits of the unit 30 were configured before time trk and this configuration is not modified after time trk. Thus, after time trk, the hardware calculation circuits of the unit 30 continue, for all the calculations of code Cres t in progress at time trk, to use the previous current auxiliary bank and the previous current key ak-1, that is to say the current bank and the current key as they were before time trk.Therefore, if the contents of the previous current auxiliary bank or if the previous current key are immediately modified after time trk, this can distort the calculations of the Cres_t codes in progress at time trk and therefore, ultimately, trigger untimely reports of execution faults while there was no fault during the execution of the arithmetic and logic instruction by unit 22. .

[0204] Similarly, if a verification of a Cres t code was in progress at time trk, it is also preferable to keep the codes Ci.ak-i, C^-i, ••• , Cn>c(k_i and the key ak-1 available so as not to trigger untimely reports of execution errors.

[0205] Here, to avoid this, after the time trk, during a step 132, the module 28 inhibits any modification of the previous current key ak-1 until a time tdk. Thus, during the interval [trk; tdk], the module 28 continues to use the secret key ak-1 and the codes Ci>c[ki to finalize the current calculations of the codes CresM and the current verifications of codes CreSf. In addition, during the interval [trk; tdk], the module 28 inhibits any modification of the register T. Thus, the bits T; remain unchanged even if a new code Ci>c[ki is written in the previous current auxiliary bank.

[0206] Here, the time tdk is equal to the time at which the counter 46 has finished counting Nc clock cycles. At the time tdk, the execution of the instructions and checks currently being executed at the time trk is finished so that the unit 30 no longer uses the key ak-1 and the codes Cij(lk_i.

[0207] At time tdk, during a step 134, the generator 44 generates a new key ak+1 and records it in the non-current register KO or Kl which contains the previous current key ak-1. Thus, from time tdk, the previous current key ak-1 is replaced by the next current key ak+1. During step 134, the module 28 also resets the register T and therefore sets all the bits T; to zero. Thus, everything previously described is repeated and, in particular, the replacement of the current key ak by a new current key ak+1 generated randomly or pseudo-randomly.

[0208] Chapter III: Variants:

[0209] The security module may comprise more than two auxiliary banks of registers. For example, in a particular embodiment, the security module additionally comprises a third auxiliary bank of registers and a third register K2. This third auxiliary bank may be used to further accelerate the frequency of changing the keys ak. This is illustrated in the particular case of replacing the key a2 with the key a3. Here, the key a3 is generated before the instant trb and not at the instant td i, and recorded in the register K2. Then, between the instants tri and tr2, and without waiting for the instant tdB each time that a data item D; is written in a register Ri0 of the main bank of registers, the security module calculates and then records in the third auxiliary bank of registers, the code Cij(l3.Thus, thanks to the use of the third auxiliary bank, it is possible to start filling this third auxiliary bank with the codes Ci>a3 without waiting for the instant tdh, that is to say the instant from which the codes Ci>ai contained in the auxiliary bank 121 are no longer used. Then, at the instant tr2, for any new arithmetic operation executed, the security module uses the codes CijC(3 recorded in the third auxiliary bank to calculate the code Crest-f From the instant tr2, the codes contained in the auxiliary bank 121 are no longer used. From then on, it is possible to start writing the codes Ci,a4 in the auxiliary bank 121 without waiting for the instant td2 and therefore to repeat the above process using the auxiliary bank 121 instead of the third auxiliary bank.

[0210] In another variant, more than three auxiliary banks of registers can be used.

[0211] Other embodiments of the auxiliary register banks are possible. In particular, the microprocessor may comprise a single set of registers containing Nr registers. Each of the registers in this set contains a first, a second and a third bit range of the same size. In this case, the first, the second and the third bit range correspond to the registers, respectively, R ij0, Ri.i and Ri2 previously described. In this case, each register bank is implemented in the same register set by partitioning each register in this set into three distinct ranges of the same size. Therefore, the address ports are common to the three register banks. On the other hand, the data ports are distinct. More precisely, the data port of the register set is then partitioned into three data ports corresponding, respectively, to the main bank 120, to the auxiliary bank 121 and to the auxiliary bank 122.

[0212] The auxiliary banks 121 and 122 are not necessarily identical to the main bank 120. For example, if the size of the integrity codes is less than the size of the processed data, the size of the registers of banks 121 and 122 is then less than the size of the registers of bank 120.

[0213] Marking the registers of banks 121 and 122 as having been updated can be done differently. For example, in step 134, the register T is not reset. Instead, in the next iteration of step 130, condition 1) is replaced by the following condition Ibis): All bits T; of the register T are equal to zero. Then, once condition Ibis) has been used in step 130, it is automatically replaced by condition 1) and so on. Therefore, in this embodiment, conditions 1) and Ibis) are used alternately. In another variant, instead of using a single register T common to banks 121 and 122 to do this, it is possible to use two registers T1 and T2 associated, respectively, with banks 121 and 122. Registers T1 and T2 are each identical to register T.Registers Tl and T2 work like register T except that to mark that a register in bank 121 has been updated, only register Tl is used and to mark that a register in bank 122 has been updated, only register T2 is used.

[0214] Alternatively, the Cres-t code calculated by the unit 30 is only used during a verification step 110 triggered as soon as the result Dres p and the Crest-t code have been calculated. The Crest-t code calculated by the unit 30 is not recorded in one of the auxiliary banks. In this case, if no execution fault is signaled during step 110, the Cres t code recorded in the registers Rres t,i and Rest t,2 are calculated by the conditional permutation circuit 42 directly from the result Dres p recorded in the register Rres t,o- Thus, in this case, the CresM>ak and Crest-t codes, <ik+i sont calculés à l’aide des relations suivantes . CresPtîCtk Qak(Dres_p) et Crest-t,ctk+i Qak+i(Lres_p).

[0215] Other methods of generating a new secret key are possible. For example, the security module comprises a memory in which a large number of pre-generated secret keys are pre-recorded. The generation of a secret key then consists only of selecting from this memory one of the secret keys recorded there.

[0216] In another embodiment, the new secret key is generated before the time trk or tdk and then recorded in a temporary memory of the security module. When the number Nc of clock cycles has elapsed, the secret key contained in this temporary memory is copied into the register containing the previous current key to replace this previous current key.

[0217] In a simplified embodiment, continuing to use the previous secret key ak-1 and the codes CijC(ki between the times trk and tdk is omitted. In other words, step 132 is omitted. In this case, the change of keys can cause unwanted reports of execution faults. However, these unwanted reports of execution faults are not necessarily blocking if this does not occur frequently and therefore cannot be confused with an attempted attack by fault injection. For this, typically, in this simplified embodiment, the secret key is changed less frequently.

[0218] The number Nc can be chosen to be greater than 300 or 1000. However, the higher the value of the number Nc, the slower the frequency of changing the keys ak.

[0219] Alternatively, each data item D; processed by the microprocessor is a masked data item obtained by performing the following operation: D; = Dic XOR M, where:

[0220] - Di>c is clear and unmasked data,

[0221] - M is a mask, of the same size as the data Dic, and

[0222] - XOR denotes the Boolean operation “EXCLUSIVE OR”.

[0223] The fact that the data D; is a masked data does not change anything in what has been described previously because the function Qa is a homomorphic function with respect to the Boolean operations and therefore in particular with respect to the “EXCLUSIVE OR” operation.

[0224] Several of the variants described above can be combined in the same embodiment.

[0225] Chapter IV: Advantages of the embodiments described:

[0226] Pre-calculating the codes CijC(k+i before triggering the replacement of the secret key ak by a new secret key ak+1 and then recording the codes CijC(k+i thus pre-calculated in the non-current auxiliary bank makes it possible to immediately have the necessary codes CijC(k+i available as soon as the replacement of the secret key ak by the new secret key ak+1 is triggered. This makes it possible to limit the slowdown in the execution of the machine code caused by the replacement of the secret key ak by the secret key ak+1 because it is not necessary to suspend the execution of the new instructions by the hardware processing chain 10 for a period of time necessary for the calculation of the different codes Cij(lk+i and then for the replacement, in the auxiliary bank 121, of each code Cij(lk by the corresponding code Cij(lk+i.Therefore, the replacement of one key by another can be done more frequently without this substantially slowing down the execution of the machine code by the microprocessor. It is therefore possible to quickly change the keys ak, which improves the security of the microprocessor 2. .

[0227] Furthermore, triggering the replacement of the key ak by the key ak+1 only when all the registers of the auxiliary bank containing the codes Cij(lk+i have been updated makes it possible to avoid untimely reports of execution faults. Indeed, it may happen that a data item D; is used during a period |tk H tj, then unused during the following period [tk ; tk+i] to be used again during the period [t k+i ; tk+2]. In this case, the code CijC(k+i is recorded in one of the auxiliary banks during the period [tk i, tk]. If the triggering of the replacement of the key ak by the key ak+1 is not conditioned on the fact that all the registers of the auxiliary bank containing the code CijC(k+i are marked as having been updated, during the period [tk ; tk+i], the code Cij(lk+2 is not calculated because the data D; is not used during this period. Therefore, during the following period [tk+i ; tk+2], when the data D; is processed by the arithmetic and logic unit, the code Crest cannot be correctly calculated since the code Cij(lk+2 does not exist in the auxiliary register banks. Ultimately, this therefore systematically triggers the reporting of an execution fault when the result Cres t is verified. By preventing the transition to the next period until all the registers in the auxiliary register banks have been marked as having been updated, this problem is avoided.

[0228] Continuing to use the previous current key ak-1 and the codes Cij(lk -1 after the time trk for all arithmetic operations whose execution began before the time trk makes it possible to avoid untimely reports of execution faults. In addition, these untimely reports of execution faults are avoided without it being necessary to intervene in the configuration and the internal registers of the processing hardware chain. Thus, these untimely reports are avoided without slowing down the execution of the machine code.

[0229] Recording the codes CijC(+2 in the non-current auxiliary bank instead of the codes CijC(k which were previously recorded there, makes it possible to change the secret key frequently while using only two auxiliary banks of registers. This therefore simplifies the hardware implementation of the security module.

[0230] Choosing the duration of the interval [trk; tdk] between 5 and 300 microprocessor clock cycles makes it possible to accelerate the frequency at which the keys ak are changed while limiting or eliminating the untimely reports of execution faults caused by a change of keys.

[0231] The fact that the Cres t code calculated by the unit 30 is recorded as Crest-t code„

Claims

Claims

1. Microprocessor equipped with an arithmetic and logic unit (22), a main bank (120) of registers and a hardware security module (28), in which: a) the arithmetic and logic unit (22) is capable of executing an arithmetic and logic instruction comprising an opcode and one or more operands which, when executed by the arithmetic and logic unit of the microprocessor, causes the performance of an operation Di *D2*...*Dn and the recording of the result of this operation in a register Rre, po of the main bank of registers, where: - the index n is equal to the number of data D; processed by the arithmetic and logic instruction, the index n being greater than or equal to one, - Di to Dn are data recorded, respectively, in registers Ri>0 to Rn>0 of the main bank of registers, the size, in number of bits, of each of these data D; being equal to 2d, where d is an integer greater than two, - the registers Ri>0 to Rn>0 are the registers designated by the operands of the arithmetic and logic instruction, - the symbol “*” is the arithmetic or logical operation designated by the opcode of the arithmetic and logical instruction, b) the security hardware module is configured to perform the following operations: 1) each time an instruction to load data D; into a register Rij0 of the main register bank is executed by the microprocessor: - the calculation of a code Ci,ai using a relation Ci,ai = Qai(Di), where the function Qai is a preprogrammed function parameterized by a current secret key al pre-recorded in the security hardware module and known only to the security hardware module, and - the recording of the calculated code Ci>ai in a register Ru, corresponding to the register Ri>0, of a first auxiliary bank of registers, 2) in parallel with the execution, by the arithmetic and logic unit, of the arithmetic and logic instruction which causes the operation Di*D2*...*Dn to be carried out and the recording of the result of this operation in the register Rre, po of the main bank of registers, the calculation of a code Cres t using the codes C2.ai, ... , Cn,ai recorded in the first auxiliary bank of registers and without using the result Dres p, then 3) checking that the calculated Cres t code corresponds to a Cres_p code obtained from the result Dres p and triggering the reporting of an execution fault if the Cres t code does not correspond to the Cres_p code and, if not, inhibiting this reporting, characterized in that the security hardware module (28) is also configured to execute the following operations: 4) each time that a data item D; is written in a register Ri0 of the main bank of registers and before triggering the replacement of the current secret key al by a new secret key a2: - calculating a code Ci>a2 using a relation Ci>a2 = CWDi) where the function Qa2 is the same preprogrammed function as the function Qai except that the current secret key al is replaced by the new secret key a2, then - recording the calculated code Ci>c(2 in a register Ri2, corresponding to the register Rij0,of a second auxiliary bank of registers and the marking of this register as having been updated, 5) only when all the registers of the second auxiliary bank have been marked as having been updated, the triggering, at a time trb of the replacement of the current secret key al by the new secret key a2 and, from this time trb for any new arithmetic and logic instruction whose execution begins after this time trH the use of the secret key a2 and the codes Ci>a2 recorded in the second auxiliary bank of registers in place, respectively, of the secret key al and the codes Ci>ai recorded in the first auxiliary bank of registers to calculate and verify the code Crest.t.,

2. Microprocessor according to claim 1, in which the security hardware module (28) is configured to, after time hj, for any arithmetic and logic instruction whose execution began before time tri and whose execution has not yet ended at time trH, continue to use the secret key al and the codes Ci>ai recorded in the first auxiliary bank of registers to finalize the calculation of the code Crest.t and for the verification of this code CreSf.

3. Microprocessor according to claim 2, in which the security hardware module is configured to: - between the time tri and a time tdb for any arithmetic and logic instruction whose execution began before the time tri and whose execution has not yet finished at the time trb continue to use the secret key al and the codes Ci,ai recorded in the first auxiliary bank of registers to finalize the calculation of the Crest-t code and for the verification of this Cres t code, and - from time tdi: - each time that a data item D; is written in a register Ri0 of the main bank of registers and before the triggering of the replacement of the secret key a2 by a new secret key a3: - the calculation of a code Ci>a3 using a relation Ci>a3 = Qa3(Di) where the function Qa3 is the same preprogrammed function as the function Q„, except that the secret key al is replaced by the secret key a3, then - the recording of the calculated code Ci>a3 in the register Ru, corresponding to the register Ri>0, of the first auxiliary bank of registers, - in response to the triggering, at a time tr2 subsequent to time tdh of the replacement of the secret key a2 by the new secret key a3, for any new arithmetic and logic instruction whose execution begins after this time tr2,the use of the secret key a3 and the codes Cija3 recorded in the first auxiliary bank of registers instead of, respectively, the secret key a2 and the codes Ci,a2 recorded in the second auxiliary bank of registers to calculate and verify the code Crest-f,

4. Microprocessor according to claim 3, in which the hardware security module is configured to trigger a counter which counts the number of clock cycles elapsed since the instant and compares the number of clock cycles counted by this counter to a predetermined number, the instant tdi corresponding to the instant when the value of this counter crosses this predetermined number and the predetermined number being chosen between 5 and 300.

5. Microprocessor according to any one of the preceding claims, in the security hardware module comprises a calculation unit (30) capable: - in parallel with the execution, by the arithmetic and logic unit (22), of the arithmetic and logic instruction which causes the operation Di*D2*...*Dn to be carried out, to execute the calculation of the code Cres t using the codes Ci,ai, C2,ai , , Cnai recorded in the first auxiliary bank of registers and without using the result Dres p, and - to record the calculated Cres-t code in the first auxiliary bank of registers as the code Crest-t,ai-

6. Microprocessor according to any one of the preceding claims, in which the microprocessor comprises a hardware chain (10) for processing instructions comprising a succession of stages which process one after the other each instruction to be executed from the machine code, this succession of stages comprising at least the following stages: an instruction loader (18), a decoder (20), and the arithmetic and logic unit (22), each of these stages being able to work in parallel with the other stages.

7. Microprocessor according to claim 6, in which: - the main bank (120) of registers comprises at least two address ports and at least two data ports to allow the simultaneous loading of two data to be processed by the arithmetic and logic unit (22), - the first and second auxiliary banks (121, 122) of registers each comprise at least two address ports and at least two data ports to allow the simultaneous loading of two codes to be processed by the calculation unit (30).

8. Microprocessor according to any one of the preceding claims, in which the function Qa is defined by the following relation: Qa(Di) = P o Fa(Di), where P is a predetermined function and Fa is a function defined by the following relation: Fa(Di)= E0o.. .o Eq o ... o ENbE-i (Di), where each function Eq is a stage of transpositions and the index q is an order number between zero and NbE-1, where NbE is an integer greater than one and less than or equal to d, each stage Eq of transpositions being defined by the following relation: Eq(x) = Tamqo.. .o Taj>qo ... o Tal>qo Tao>q(x), where: - x is a variable whose size, in number of bits, is equal to the size of the data D;, - Taj>q is a conditional transposition, parameterized by the parameter aj>q, which permutes two blocks of bits B2j+i>q and B2j>q of the variable x when the parameter aj>q is equal to a first value and which does not permute these two blocks of bits when the parameter aj>q is equal to a second value, the transposition Taj>q being distinguished from all the other transpositions of the function Fa by the fact that it is the only one which permutes the two blocks B2j+i>q and B2j>q when the parameter aj>q is equal to the first value, the blocks B2j+i>q and B2j>q of all the transpositions Taj>q of the stage Eq being different from each other and not overlapping so that all the transpositions Taj>q of the stage Eq can be executed in parallel, - "m+1" is the total number of transpositions Taj>q of the stage Eq, - "j" is an order number identifying the transposition Taj>q among the;

9. other transpositions of the Eq stage, - the symbol "o" denotes the operation of composition of functions, - the concatenation of the bits of all parameters aj>q of all stages E q is equal to the value of the secret key a, and - for all stages Eq for which q is less than NbE-1 and for all transpositions Taj>q of this stage, the blocks B2j+i>q and B2j>q are located inside the same block of larger size permuted by a transposition of the upper stage Eq+i when the parameter of this transposition of the upper stage Eq+i is equal to the first value. Method for executing a binary code using a microprocessor equipped with an arithmetic and logic unit, a main bank of registers and a security hardware module, in which: a) the arithmetic and logic unit executes (74) an arithmetic and logic instruction comprising an opcode and one or more operands which, when executed by the arithmetic and logic unit of the microprocessor, causes the performance of an operation Di *D2*...*Dn and the recording of the result of this operation in a register Rres_p>o of the main bank of registers, where: - the index n is equal to the number of data D; processed by the arithmetic and logic instruction, the index n being greater than or equal to one, - Di to Dn are data recorded, respectively, in registers Ri>0 to Rn>0 of the main bank of registers, the size, in number of bits, of each of these data D; being equal to 2d, where d is an integer greater than two, - the registers Ri>0 to Rn>0 are the registers designated by the operands of the arithmetic and logic instruction, - the symbol “*” is the arithmetic or logical operation designated by the opcode of the arithmetic and logical instruction, b) the security hardware module performs the following operations: 1) each time an instruction to load data D; into a register R; 0 of the main register bank is executed by the microprocessor: - the calculation (80) of a code Ci>ai using a relation Ci>ai = Q„|(D,), where the function Qai is a pre-programmed function parameterized by a secret key al pre-recorded in the security hardware module and known only to the security hardware module, and - recording (82) the code Ci,ai calculated in a register R; i, corresponding to the register Rij0, of a first auxiliary bank of registers, 2) in parallel with the execution, by the arithmetic and logic unit, of the arithmetic and logic instruction which causes the operation Di*D2*...*Dn to be carried out and the result of this operation to be recorded in the register Rre, po of the main bank of registers, the calculation (90) of a code Cres t using the codes C2>c(i , , Cn,ai recorded in the first auxiliary bank of registers and without using the result D res-p, then 3) the verification (110) that the calculated Cres t code corresponds to a C res_p code obtained from the Dres p result and the triggering (112) of the signaling of an execution fault if the Cres t code does not correspond to the Cres-P code and, in the opposite case, the inhibition of this signaling, characterized in that the security hardware module also executes the following operations: 4) each time a data D; is written in a register Rij0 of the main bank of registers and before the triggering of the replacement of the secret key al by a new secret key a2: - the calculation (100) of a code CijC(2 using a relation CijC(2 = CWD;) where the function Qa2 is the same preprogrammed function as the function Qai except that the secret key al is replaced by the secret key a2, then - the recording (100) of the calculated code CijC(2 in a register Ri2, corresponding to the register Ri>0, of a second auxiliary bank of registers and the marking of this register R; 2 as having been updated, 4) only when all the registers of the second auxiliary bank have been marked as having been updated, the triggering (130), at a time trB of the replacement of the secret key al by the secret key a2 and, from this time hj, for any new arithmetic and logic instruction whose execution begins after this time hj, the use of the secret key a2 and the codes Ci,a2 recorded in the second auxiliary bank of registers in place, respectively, of the secret key al and the codes Ci>ai recorded in the first auxiliary bank of registers to calculate and verify the code Crestf