Storage method

FR3154823B1Active Publication Date: 2026-09-04STMICROELECTRONICS INT NV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023011617
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-10-25
Publication Date
2026-09-04
Estimated Expiration
2043-10-25

AI Technical Summary

Technical Problem

Existing electronic systems face challenges in securely storing sensitive data, such as encryption and application keys, due to vulnerabilities in current data storage processes.

Method used

A secure data storage process is implemented using multiple secure elements, where sensitive data is divided into parts and distributed across these elements, with a correspondence table recording the distribution to ensure secure storage and recovery.

Benefits of technology

This approach enhances the security of sensitive data storage by making it resistant to side-channel attacks and ensuring that each data storage process has a unique electrical signature, thereby improving overall data protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000009_0000
    Figure 00000009_0000
  • Figure 00000010_0000
    Figure 00000010_0000
  • Figure 00000010_0001
    Figure 00000010_0001
Patent Text Reader

Abstract

Storage Method This description relates to a method for storing data (102) in an electronic system (100) comprising at least two secure elements (104-1, …, 104-N), comprising the following successive steps: - dividing said data (102) into at least two parts; and - distributing and storing each of said at least two parts in one of said at least two secure elements (104-1, …, 104-N). Figure for the abstract: Fig. 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Storage method Technical field

[0001] The present description relates generally to electronic systems and devices. More particularly, the present description relates to the storage of sensitive data in an electronic system. Prior art

[0002] Nowadays, many electronic systems and devices use sensitive data, including encryption and / or decryption keys or application keys, and sometimes need to store them to do so. It can be important to store this data securely.

[0003] It would be desirable to be able to improve, at least in part, certain aspects of the storage of sensitive data in an electronic system. Summary of the invention

[0004] There is a need for storage of sensitive data in a more secure electronic system.

[0005] There is a need for electronic systems that store sensitive data more securely.

[0006] One embodiment overcomes all or part of the drawbacks of known methods for storing sensitive data in an electronic system.

[0007] One embodiment overcomes all or part of the drawbacks of known electronic systems storing sensitive data securely.

[0008] One embodiment provides a method for storing sensitive data in an electronic system using multiple secure elements.

[0009] One embodiment provides an electronic system storing sensitive data by distributing it across several secure elements.

[0010] One embodiment provides a method for storing data in an electronic system comprising at least two secure elements, comprising the following successive steps: - divide said data into at least two parts; and - distribute and store each of said at least two parts in one of said at least two secure elements.

[0011] Another embodiment provides an electronic system, comprising at least two secure elements, and adapted to store data by following the following successive steps: - divide said data into at least two parts; and - distribute and store each of said at least two parts in one of said at least two secure elements.

[0012] According to one embodiment, the distribution of said at least two parts in said at least two secure elements is recorded in a row, or a column, of a correspondence table.

[0013] According to one embodiment, the correspondence table is stored in a single location of the system accessible to each of said at least two secure elements.

[0014] According to one embodiment, a copy of the correspondence table is stored in each of said at least two secure elements.

[0015] According to one embodiment, the distribution is different for each data item stored in said system.

[0016] According to one embodiment, said distribution is chosen by choosing a line from said correspondence table.

[0017] According to one embodiment, the choice of said line of said correspondence table is carried out using a counter.

[0018] According to one embodiment, each of said at least two secure elements is included in at least one operating domain of said system.

[0019] According to one embodiment, each at least one operating domain further comprises at least one electronic device.

[0020] According to one embodiment, said at least two secure elements are embedded secure elements.

[0021] According to one embodiment, said data is an application key.

[0022] According to one embodiment, said system is a motor vehicle.

[0023] According to one embodiment, the method comprises the following successive steps: - recover said at least two parts of said data stored in said at least two secure elements; - form said data using said at least two parts.

[0024] According to one embodiment, the formation of said data is carried out using said correspondence table. Brief description of the drawings

[0025] These characteristics and advantages, as well as others, will be explained in detail in the following description of particular embodiments given without limitation in relation to the attached figures among which:

[0026] [Fig.l] represents an embodiment of an electronic system; and

[0027] [Fig.2] represents two block diagrams illustrating a mode of implementation of a storage method and a method of retrieving data stored in the electronic system of [Fig.l]. Description of the embodiments

[0028] The same elements have been designated by the same references in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same references and may have identical structural, dimensional and material properties.

[0029] For the sake of clarity, only the steps and elements useful for understanding the described embodiments have been shown and are detailed.

[0030] Unless otherwise specified, when referring to two elements connected to each other, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") to each other, this means that these two elements can be connected or be connected by means of one or more other elements.

[0031] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made unless otherwise specified to the orientation of the figures.

[0032] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "of the order of" mean to within 10%, preferably to within 5%.

[0033] The embodiments described below relate to the storage of data, and more particularly of secret or sensitive data, in an electronic device comprising several, at least two, secure elements.

[0034] Hereinafter, "sensitive" or "secret" refers to data representing sensitive and / or secret information whose content is not intended to be public.

[0035] [Fig.l] represents, very schematically and in the form of blocks, an embodiment of a system 100 adapted to store one or more sensitive and / or secret data in a secure manner.

[0036] The system 100 is a complex electronic system of the type of a computer, or an electronic system of a motor vehicle.

[0037] The system 100 comprises a router 101 (ROUTER) adapted to receive and transmit data. According to one example, the router 101 is an internet communication module, such as a module having access to the fifth generation (5G) mobile telephone network, or a module having access to the internet using a Wi-Fi type wireless communication protocol. The router 101 is therefore adapted to receive and transmit data within the system 100, but also with one or more other electronic systems external to the system 100.

[0038] According to one embodiment, the router 101 is particularly suitable for receiving one or more data 102 (Key) to be stored in the system 100. The data 102 are, for example, sensitive and / or secret data. According to one embodiment, the data 102 are encryption and / or decryption keys, or application keys. Here, an "application key" is a data item making it possible to make one or more functionalities and / or one or more data sets of an electronic system accessible. An embodiment of a method for securely storing the data 102 and an embodiment of a method for recovering such stored data are described in relation to [Fig. 2].

[0039] The system 100 is adapted to implement a multitude of functionalities which are grouped into several operating domains. In the example illustrated in [Fig.l], the system comprises N operating domains 103-1 (DCU1), 103-2 (DCU2), ... and 103-N (DCUN), N being an integer greater than or equal to two. Each operating domain 103-i, i being an integer varying from 1 to N, comprises at least one secure element 104-i and one or more, generally several, electronic devices 105 (CPU) each adapted to implement one or more functionalities.

[0040] According to a practical example, if the system 100 is a motor vehicle. A first operating domain may concern the engine domain, and include the electronic devices managing, for example, the injection, the engine operating modes, the sensors for monitoring the proper functioning and / or wear of the engine, etc. A second operating domain may concern safety within the vehicle, and include the electronic devices managing, for example, tire pressure, brakes, emergency calls, etc. A third operating domain may concern the passenger compartment of the vehicle, and include the electronic devices managing, for example, the air conditioning, heating, lighting, etc.A fourth area of ​​operation may concern the multimedia content of the vehicle, and include electronic devices managing, for example, a radio or car radio, a sound system, one or more screens, etc.

[0041] Each secure element 104-i comprises one or more storage means, such as a register or a memory, for storing data securely. In particular, each secure element 104-i is resistant to a side channel attack. According to one example, all or part of the secure elements 104-1 to 104-N are embedded secure elements.

[0042] [Fig. 2] comprises two block diagrams (A) and (B) illustrating a mode of implementation of storing data in the system 100 described in relation to [Fig. 1]. More particularly, diagram (A) represents a mode of implementation of a method 200 for storing data in the system 100, and diagram (B) re presents a mode of implementation of a method 250 for recovering data already stored in the system 100.

[0043] When the system 100 needs to securely store data of the data type 102, the method 200 is executed.

[0044] At an initial step 201 (Receive Key), the system 100 receives a Key data item to be stored, for example of the type of data item 102 described previously.

[0045] At a step 202 (Divide Key), subsequent to the initial step 201, the Key data is divided into several data items hereinafter called parts of the Key data item. For this, the Key data item is divided, split, segmented or fractioned into several parts. More particularly, the Key data item is divided for example into M parts, M being an integer greater than or equal to two. According to one example, M is the number of secure elements 104-1 to 104-N included in the system 100. According to one embodiment, M is less than or equal to N. According to a preferred embodiment, M is equal to N.

[0046] At a step 203 (LUT), subsequent to step 202, a look-up table (LUT) is used to prepare the storage of the parts Keyl to KeyM in the system. According to one embodiment, each part Keyj, j being an integer between 1 and M, is stored in a secure element 104-i. According to one embodiment, the distribution of the parts Keyl to KeyM in the elements 104-1 to 104-N is recorded in a look-up table.

[0047] More particularly, each column of the correspondence table corresponds to a secure element 104-i, and a row of the correspondence table comprises the order in which the parts Keyl to KeyM are stored in the secure elements 104-1 to 104-N. According to a variant, the rows and columns of the correspondence table can be reversed. According to one embodiment, each data item stored in the system comprises a different distribution of these parts in the secure elements.

[0048] According to one embodiment, the correspondence table comprises a finite number of lines, and for each data item to be stored in the system, a line is chosen, for example in a secure manner.

[0049] According to a preferred embodiment, the system comprises a counter whose value is adapted to choose a line in the correspondence table. This counter can be incremented each time a new data item is stored. Thus, a first data item can be stored using the information from the line of the correspondence table whose number is equal to the value of the counter. Once the storage is complete, the counter is incremented. When a second data item must be stored, another line whose number is equal to the incremented value of the counter is chosen, is stored using the information from the next line, etc. The counter can be stored securely in the system 100.

[0050] Change the distribution of the parts of the data in the secure elements for Each piece of data makes the storage process resistant to covert channel attacks. In fact, each storage has a different electrical signature in this case.

[0051] According to one example, the correspondence table may be stored in the router 102, while being accessible to at least one of the secure elements 104-1 to 104-N, or to all of the secure elements 104-1 to 104-N. According to one variant, each secure element 104-1 to 104-N stores a copy of the correspondence table.

[0052] At a step 204 (Store), subsequent to step 203, the storage of each part Keyl to KeyM in the secure elements 104-1 to 104-N is implemented.

[0053] At a step 205 (Key Stored), subsequent to step 204, the data is stored securely in the system 100.

[0054] Conversely, to retrieve data stored in the system 100 using the storage method 200, the method 250 is executed.

[0055] At an initial step 251 (Key Stored), the Key data was stored in the system 100. For this, the Key data was divided into M parts Keyl to KeyM, and each of these parts was stored in a secure element of the system 100.

[0056] At a step 252 (Get Div), after the initial step 251, all the parts Keyl to KeyM of the Key data are recovered in the different secure elements.

[0057] At a step 253 (LUT), subsequent to step 252, the correspondence table described previously is used to determine the order in which the parts Keyl to KeyM must be combined. To know which line corresponds to the data Key, the value of the counter described previously can be used.

[0058] At a step 254 (Concat), after step 253, the parts Keyl to KeyM are combined, for example concatenated, to obtain the data Key.

[0059] At a step 255 (Get Key), after step 254, the Key data has been recovered and can be used.

[0060] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will occur to those skilled in the art. In particular, to further improve the security of the storage obtained by the method 200, encryption and / or decryption steps may be added.

[0061] Finally, the practical implementation of the embodiments and variants described is within the reach of those skilled in the art from the functional indications given above.

Claims

Claims

1. Method for storing (200) a piece of data (102) in an electronic system (100) comprising at least two secure elements (104-1, 104-N), comprising the following successive steps: - dividing (202) said piece of data (102; Key) into at least two parts (Keyl, KeyM); and - distributing and storing (204) each of said at least two parts (Keyl, ..., KeyM) in one of said at least two secure elements (104-1, ..., 104-N).

2. Method according to claim 1, in which the distribution of said at least two parts (Keyl, ..., KeyM) in said at least two secure elements (104-1, ..., 104-N) is recorded in a row, or a column, of a correspondence table.

3. The method of claim 2, wherein the correspondence table is stored in a single location of the system accessible to each of said at least two secure elements (104-1, ..., 104-N).

4. The method of claim 2, wherein a copy of the correspondence table is stored in each of said at least two secure elements (104-1, ..., 104-N).

5. Method according to any one of claims 1 to 4, wherein the distribution is different for each data (102; Key) stored in said system.

6. A method according to claim 5 as attached to claim 2, wherein said distribution is chosen by choosing a row from said correspondence table.

7. A method according to claim 6, wherein the selection of said row of said correspondence table is performed using a counter.

8. Method according to any one of claims 1 to 7, wherein each of said at least two secure elements (104-1, ..., 104-N) is included in at least one operating domain of said system.

9. The method of claim 8, wherein each at least one operating domain further comprises at least one electronic device.

10. Method according to any one of claims 1 to 9, wherein said at least two secure elements (104-1, ..., 104-N) are embedded secure elements.

11. A method according to any one of claims 1 to 10, wherein said data (102; Key) is an application key.

12. A method according to any one of claims 1 to 11, wherein said system is a motor vehicle.

13. Method for recovering (250) a data item (102; Key) stored using the method according to any one of claims 1 to 12, comprising the following successive steps: - recovering said at least two parts (Keyl, ..., KeyM) of said data item (102; Key) stored in said at least two secure elements (104-1, ..., 104-N); - forming said data item (102; Key) using said at least two parts (Keyl, ..., KeyM).

14. Method according to claim 13, wherein the formation of said data (102; Key) is carried out using said correspondence table.

15. Electronic system (100), comprising at least two secure elements (104-1, ..., 104-N), and adapted to store a data item (102; Key) by following the following successive steps: - dividing (202) said data item (102; Key) into at least two parts (Keyl, ..., KeyM); and - distributing and storing (204) each of said at least two parts (Keyl, ..., KeyM) in one of said at least two secure elements (104-1, ..., 104-N).