Critical data storage method

The double encryption method with different keys and data mixing in external memory addresses the security and complexity issues in existing critical data storage methods, ensuring secure and immediate detection of data changes.

FR3155077A1Pending Publication Date: 2025-05-09STMICROELECTRONICS INT NV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
FR2023012138
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-08
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

Existing methods for storing critical data in external memory lack security and complexity, failing to immediately detect changes in critical data.

Method used

A double encryption process using different encryption keys, followed by mixing the encrypted data in external memory, ensures secure storage and immediate detection of changes in critical data.

Benefits of technology

The proposed method provides a secure and reliable way to store critical data in external memory, preventing unauthorized access and modification, while ensuring immediate detection of data changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for Storing Critical Data This description relates to a method for storing critical data blocks (Data200) from an electronic device (200) in an external memory (202) of said electronic device (200), comprising the following steps: - obtaining first encrypted data blocks (EA(Data200)) by encrypting critical data blocks (Data200) using a first encryption key (2063); - obtaining second encrypted data blocks (EB(Data200)) by encrypting critical data blocks (Data200) using a second encryption key (2064) different from the first encryption key (2063); and - storing the first and second encrypted data blocks (EA(Data200), EB(Data200)) in said memory (202). Figure for the abstract: Fig. 2
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for storing critical data Technical field

[0001] The present description relates generally to electronic circuits and devices, and more particularly to the security of critical data used in these circuits and devices. The present description relates more specifically to a method of storing critical data in an external memory. Prior art

[0002] Storing critical data in an electronic device is a task that is part of the general security management of said electronic device.

[0003] It would be desirable to improve, at least in part, certain aspects of the known method of storing critical data in an external memory. Summary of the invention

[0004] There is a need for a method of storing critical data that is more secure.

[0005] There is a need for a method of storing critical data in a memory external that is more secure.

[0006] There is a need for a method of storing critical data that does not add complexity to the process.

[0007] There is a need for a method of storing critical data that can immediately detect a change in the critical data.

[0008] There is a need for an electronic device capable of performing the method described above for storing critical data.

[0009] One embodiment makes it possible to overcome all or part of the drawbacks of known methods for storing critical data.

[0010] One embodiment provides a method of storing critical data blocks of an electronic device in a memory that is external to said electronic device, comprising the following steps: - obtaining first encrypted blocks of data by encrypting critical data blocks using a first encryption key; - obtaining second encrypted blocks of data by encrypting critical data blocks using a second encryption key different from the first encryption key; and - storing the first and second encrypted data blocks in said memory.

[0011] Another embodiment provides an electronic device adapted to store critical data blocks in a memory which is external to said electronic device by performing the following steps: - obtaining first encrypted data blocks by encrypting critical data blocks using a first encryption key; - obtaining second encrypted data blocks by encrypting critical data blocks using a second encryption key different from the first encryption key; and -storing the first and second encrypted data blocks in said memory.

[0012] According to one embodiment, said first and second encrypted data blocks are mixed in said memory.

[0013] According to one embodiment, in said memory, each data item composing said first encrypted data block is stored immediately before the corresponding second encrypted data block.

[0014] According to one embodiment, the first and second encrypted data blocks are obtained by applying the AES system to said critical data.

[0015] According to one embodiment, said first encrypted data blocks are obtained using the following steps: (a) combining critical data blocks with a first data word; and (b) encrypting the result of step (a) with said first encryption key.

[0016] According to one embodiment, said second encrypted data blocks are obtained using the following steps: (c) combining the critical data blocks with said first encrypted data blocks; and (d) encrypting the result of step (c) using the second encryption key.

[0017] According to one embodiment, said memory is a DRAM memory.

[0018] According to one embodiment, said electronic device comprises a processor capable of processing critical blocks of data.

[0019] Another embodiment provides a method of recovering critical blocks of data stored in a memory using the method described above.

[0020] Another embodiment provides a device capable of recovering critical blocks of data stored in a memory using the method described previously.

[0021] According to one embodiment, said method comprises the following steps: - obtaining first and second encrypted data blocks from said memory; - decryption of the first encrypted data blocks using the first encryption key; - decrypting the second encrypted data blocks using the second encryption key; and - comparing the results of the two decryption steps, if they are identical, the critical data blocks can be used.

[0022] According to one embodiment, if the result of the two decryption steps is not identical, the critical data blocks cannot be used.

[0023] According to one embodiment, the step of obtaining the first and second encrypted data blocks from said memory comprises a step of separating the first and second encrypted data. Brief description of the drawings

[0024] These characteristics and advantages, as well as others, will be explained in detail in the following description of particular embodiments given without limitation in relation to the attached figures among which:

[0025] [Fig.l] represents, very schematically and in the form of blocks, an example of an electronic device capable of executing the embodiment described in relation to figures 2 to 4;

[0026] [Fig.2] represents, very schematically and in the form of blocks, a first embodiment of a method for storing critical data;

[0027] [Fig.3] represents, in block form, a step of the embodiment of [Fig.2];

[0028] [Fig.4] represents, very schematically and in the form of blocks, an example of execution of the first embodiment of [Fig.2]; and

[0029] [Fig.5] represents, very schematically and in the form of blocks, a second embodiment of a method for storing critical data. Description of the embodiments

[0030] The same elements have been designated by the same references in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same references and may have identical structural, dimensional and material properties.

[0031] For the sake of clarity, only the steps and elements useful for understanding the described embodiments have been shown and are detailed.

[0032] Unless otherwise specified, when referring to two elements connected to each other, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") to each other, this means that these two elements can be connected or be connected by means of one or more other elements.

[0033] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made unless otherwise specified to the orientation of the figures.

[0034] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "of the order of" mean to within 10%, preferably to within 5%.

[0035] The embodiments described below relate to the storage of critical data in memory and the corresponding retrieval method. In the following, critical data is data whose access is limited to one or more particular persons and / or devices. In most cases, when a processor or circuit processes sensitive data, this data is stored in a memory that said processor or circuit trusts. This is more convenient for security purposes.

[0036] A trusted memory is often a memory that is mounted on the same chip as the processor or circuit, and with which secure communication is possible. Due to space restrictions in electronic devices, it is common for a trusted memory to not have sufficient storage capacity to process all the necessary critical data. To achieve this, it is more practical to use an untrusted memory to store critical data. An untrusted memory, hereinafter referred to as an external memory, is a memory with which secure communication is not possible. Therefore, an untrusted memory is often not mounted on the same chip as the processor or circuit.

[0037] If critical data is stored in an untrusted memory, a means of securing the critical data must nevertheless be implemented. The embodiments described below relate to a secure method for storing critical data in an untrusted memory, as well as the corresponding recovery method. For this purpose, the method comprises a double encryption step with different encryption keys and a step of mixing the encrypted data. This prevents the data from being accessed and / or modified by an unauthorized person or circuit. These methods are described in more detail in Figures 2 to 4.

[0038] [Fig. 1] represents, very schematically and in the form of blocks, an electronic device 100 capable of executing the method of storing critical data described in relation to FIGS. 2 to 4.

[0039] The device 100 is an electronic device suitable for processing data, and more particularly for processing critical data.

[0040] The device 100 comprises a processor 101 (CPU) capable of processing data. According to one example, the device 100 may comprise several processors, each adapted to process different types of data. According to a particular example, the device 100 may comprise at least one processor adapted to process critical data.

[0041] The device 100 further comprises one or more memories 102 (MEM) in which data, for example critical data, is stored. According to one example, the device 100 comprises a plurality of types of memories, such than a ROM, a RAM, a volatile memory and / or a non-volatile memory. According to a particular example, the device 100 may comprise one or more memories that the processor 101 trusts and that have secure access to the processor 101. According to one embodiment, the device 100 comprises one or more external memories, or untrusted memories, that do not have secure access to the processor 101. The method for storing critical data described in relation to FIGS. 2 to 4 relates to the storage of critical data by the processor 101 in an external memory.

[0042] The device 100 further comprises one or more secure elements 103 (SE) adapted to process critical and / or secret data. The secure element 103 may comprise its own processor(s), its own memory(s), etc. According to one example, the method for storing critical data described in relation to FIGS. 2 to 4 may relate to the storage of critical data by the secure element 103 in an external memory.

[0043] The device 100 further and optionally comprises one or more input / output circuits 104 (RO) enabling the device 100 to transmit and / or receive data and / or power with one or more external electronic devices.

[0044] The device 100 further comprises one or more circuits 105 (FCT1) and 106 (FCT2) implementing one or more functionalities of the device 100. According to one example, the circuits 105 and 106 may comprise particular data processing circuits, such as encryption circuits, or circuits for carrying out measurements, such as sensors.

[0045] The device 100 further comprises one or more communication buses 107 allowing all the circuits of the device 100 to communicate. In [Fig.l], a single bus 107 connecting the processor 101, the memory(ies) 102, the secure element 103 and the circuits 104 to 106 is shown, but, in practice, the device 100 comprises a plurality of communication buses connecting these different elements.

[0046] [Fig. 2] represents, in block form, the execution, by a device 200, of an embodiment of a method for storing critical data in a memory.

[0047] According to one embodiment, the device 200 comprises a processor 201 (CPU) of the type of the processor 101 described in relation to [Fig.l], and a memory 202 (External RAM) which is considered unreliable by the processor 201. The memory 202 is hereinafter referred to as external memory. The processor 201 is capable of processing critical data and must store critical data in the memory 202.

[0048] The processor 201 has access to a private bus 204 (PRIVATE BUS) ensuring secure communication with other circuits or components of the device 200.

[0049] The memory 202 only has access to a public bus 205 (Public BUS) to communicate with the other components of the device 200, and in particular with the processor 201. According to one example, the memory 202 is a random access memory, also called RAM, and more particularly a dynamic random access memory, also called DRAM.

[0050] The device 201 further comprises an encryption and decryption unit 206 (Crypt / Decrypt) adapted to connect the two buses 204 and 205. More particularly, the unit 206 is capable of exchanging critical data with the private bus 204, and of exchanging encrypted data with the public bus 205.

[0051] According to one embodiment, the unit 206 comprises two identical encryption and decryption engines 2061 and 2062 capable of: - encrypt critical data received from the private bus 204; and - decrypt encrypted data received from the public bus 204.

[0052] The only difference between engines 2061 and 2062 is that they work with different encryption and decryption keys 2063 (KeyA) and 2064 (KeyB). In [Fig.2], engine 2061 uses encryption and decryption key 2063, while engine 2062 uses encryption and decryption key 2064.

[0053] To this end, the engines 2061 and 2062 may implement different types of symmetric encryption and decryption algorithms. An example of an encryption and decryption algorithm that may be used is the Advanced Encryption Standard (AES). This particular example is described in detail in relation to [Fig. 5].

[0054] The following method is used to store critical data of the processor 201 in the external memory 202. Some critical data of the processor 201 are considered here. These critical data are divided into critical data blocks Data200 of the same size. The critical data blocks Data200 are sent to the encryption and decryption unit 206, via the private bus 204. Then, the unit 206 uses the two engines 2061 and 2062 to encrypt each critical data block Data200. More particularly, the engine 2061 encrypts each critical data block Data200 using the encryption and decryption key 2063, in order to provide a first encrypted data block EA(Data200). At the same time, the engine 2062 encrypts each critical data block Data200, using the encryption and decryption key 2064, to provide a second encrypted data block EB(Data200).

[0055] The first and second encrypted data blocks EA(Data200) and EB(Data200) are both sent to the memory 202 for storage, via the public bus 205. According to a preferred embodiment, the first and second encrypted data blocks EA(Data200) and EB(Data200) are mixed in the memory 202. A preferred way of mixing the first and second encrypted data blocks EA(Data200) and EB(Data200) in the memory 202 is described in detail in relation to [Fig.3].

[0056] Thus, a method for storing critical data blocks Data200 in the external memory 202 comprises the following steps: - the encryption of each block of critical data Data200 with a first encryption and decryption key 2063 to obtain a first encrypted block of data EA(Data200); - encrypting each critical data block Data200 with a second encryption and decryption key 2064 to obtain a second encrypted data block EB(Data200); and - storing each first and second encrypted data block EA(Data200) and EB(Data200) in the external memory 202, and, for example, mixing said first and second encrypted data blocks EA(Data200) and EB(Data200).

[0057] Once the first and second encrypted data blocks EA(Data200) and EB(Data200) are stored in the memory, a method for recovering the critical data is as follows. Both the first and second encrypted data blocks EA(Data200) and EB(Data200) are recovered from the external memory 202.

[0058] The first and second encrypted data blocks EA(Data200) and EB(Data200) are sent to the encryption and decryption unit 206, via the public bus 205. Each encrypted data block is decrypted by an engine 2061 or 2062. More particularly, the first encrypted data block EA(Data200) is decrypted using the engines 2061 and the key 2063, the key 2063 having been used to obtain the encrypted data block EA(Data200). The second encrypted data block EB(Data200) is decrypted using the engines 2062 and the key 2064, the key 2064 having been used to obtain the encrypted data blocks EB(Data200). The two decrypted data blocks are then compared. If they are identical, the correct critical data blocks Data200 have been retrieved and can be sent to the processor 201, via the private bus 204.If they are not identical, the correct critical Data200 data blocks were not recovered because they were corrupted. The processor cannot use the decrypted data blocks.

[0059] Thus, a method for recovering the critical data blocks Data200 which have been stored in the external memory 202 using the previous method comprises the following steps: - obtaining the first and second encrypted data blocks EA(Data200) and EB(Data200) from the external memory 202; - decryption of the first encrypted blocks of data EA(Data200) using the first encryption key 2063; - decrypting the second encrypted data blocks EB(Data200) using the second encryption key 2064; and - comparing the results of the two decryption steps, if they are identical, the critical data blocks can be used by the processor.

[0060] One of the advantages of these methods is to allow a processor to store critical data in unreliable memory.

[0061] [Fig.3] represents, in block form, a step of mixing the encrypted data of the example of [Fig.2].

[0062] [Fig.3] represents certain critical blocks of data Data300 as they are before being stored in an external memory, i.e. in a processor 301 (CPU).

[0063] [Fig. 3] also shows the first and second encrypted data blocks EA(Data300) and EB(Data300) resulting from the storage method described in relation to [Fig. 2]. The first and second encrypted data blocks EA(Data300) and EB(Data300) are both stored in an external memory 302 (External RAM).

[0064] According to one embodiment, the first and second encrypted blocks of data EA(Data300) and EB(Data300) are mixed in the memory 302. In other words, the two complete versions of the encrypted data are not written in a single block in the memory 302, but are separated into several blocks of data written in different parts of the memory.

[0065] According to a preferred embodiment, each first encrypted block of data EA(Data300) is stored between two second encrypted blocks of data EB(Data300). Similarly, each second encrypted block of data EB(Data300) is stored between two first encrypted blocks of data EA(Data300). In other words, each first encrypted block of data EA(Data300) is stored immediately before the corresponding second encrypted block of data EB(Data300). Similarly, each second encrypted block of data EB(Data300) is stored immediately before the corresponding first encrypted blocks of data EA(Data300).

[0066] Thus, if someone wants to corrupt the critical data blocks Data300 by accessing the memory 302, it is very likely that two different parts of the first and second encrypted data blocks will be corrupted. It is then extremely unlikely that the two corrupted data blocks will decrypt to give identical results. There is a concept of "diffusion" in encryption algorithms, according to which if a single bit of the encrypted data is changed, this will affect all the bits in the decrypted block (and not just the nearby bits) and will change about half of them, on average.

[0067] [Fig.4] represents, in block form, an example of execution of the embodiment of the methods described in relation to [Fig.2].

[0068] More particularly, [Fig. 4] represents a method 340 for storing critical data in a memory according to the embodiment described in relation to the [Fig.2], and a method 350 for recovering this critical data from the memory according to the embodiments described in relation to [Fig.2].

[0069] The method 340 therefore comprises the following steps.

[0070] During a first step 341 (Data200), the processor 201 of [Fig.2] wishes to store certain critical data blocks Data200 in the external memory 202.

[0071] In a step 342 (Copy), after step 341, the processor 201 creates a copy of the critical data blocks Data200 and sends the two copies to the encryption and decryption unit 206 via the private bus 204.

[0072] During a step 343 (Encrypt KeyA), after step 342, the engine 2061 of the encryption and decryption unit 206 encrypts the first copy of the critical data blocks Data200 using the first encryption and decryption key 2063. First encrypted data EA(Data200) are generated.

[0073] During a step 344 (Encrypt KeyB), after step 342, the engine 2062 of the encryption and decryption unit 206 encrypts the second copy of the critical data blocks Data200 using the second encryption and decryption key 2064. Second encrypted data EB(Data200) are generated.

[0074] In a step 345 (EAB(Data200)), after steps 343 and 344, the first and second encrypted data blocks EA(Data200) and EB(Data200) are both sent to the memory 202 for storage, via the public bus 205. According to preferred embodiments, the first and second encrypted data blocks EA(Data200) and EB(Data200) are mixed in the memory 202, for example using the mixing method described in detail in relation to [Fig.3].

[0075] The method 350 comprises the following steps.

[0076] During a first step 351 (Retrieve), the data EAB(Data200) are retrieved in the form of first and second encrypted blocks of data EA(Data200) and EB(Data200) in the memory 202.

[0077] During a step 352 (Decrypt KeyA), after step 351, each first encrypted block of data EA (Data200) is then decrypted using the encryption and decryption key 2063 in order to obtain a first copy of a block of data Data200.

[0078] In a step 353 (Decrypt KeyB), after step 351, each second encrypted block of data EB(Data200) is then decrypted using the decryption and decryption key 2064 to obtain a second copy of a block of data Data200.

[0079] In a step 354 (Comp), after steps 352 and 352, the two copies of each critical data block Data200 are compared. If the comparison is successful (output Y of block 354), the next step is step 355 (Use). Otherwise (output N of block 354), the next step is step 356 (Error).

[0080] During a step 355 (Use), each copy of the critical data blocks Data200 is identical, which means that the data EAB(Data200) has not been corrupted when stored in the memory 202. The processor 201 can use the critical data Data200 safely.

[0081] During a step 356 (Error), at least one copy of a critical data block Data200 is not identical, which means that the data EAB(Data200) has been corrupted during its storage in the memory 202. According to one example, an error message can be sent to the processor 201. According to another example, the two copies of the critical data blocks Data200 can be sent to the processor for analysis.

[0082] [Fig.5] represents, in block form, the execution of a variant of the embodiment of the methods described in relation to [Fig.2].

[0083] More particularly, [Fig.5] represents the execution of a method 401 for storing critical data in an external memory, and of a method 402 for recovering said data. According to one embodiment, the methods 401 and 402 both use the AES algorithm to encrypt and decrypt the data. More particularly, the methods 401 and 402 use the chaining of several AES operations, generally called AES-CBC for the English AES-Cipher-Block-Chaining, or chaining of block encryption by AES.

[0084] The method 401 for storing critical data in an external memory is as follows. The critical data is sent by a processor of the type of processor 201 of [Fig. 2] to an encryption and decryption unit of the encryption and decryption unit 206 of [Fig. 2]. The unit creates two copies of blocks of the critical data, hereinafter called Data400-1 (Plaintext Block1) and Data400-2 (Plaintext Block2).

[0085] The first copy Data400-1 is combined with a first data word Seed400-1 using a logical EXCLUSIVE OR operation 403, also called an XOR operation, and then an encryption operation 404 is used, with an encryption key KeyA4, to obtain a first encrypted copy Data EA4(Data400-1) (Ciphertext Black IA). According to one example, the encryption operation 404 is an implementation of an AES encryption operation. Then, the second copy Data400-2 is combined with the first encrypted copy Data EA4(Data400-1), using the XOR operation 403, and then the encryption operation 404 is used, with the encryption key KeyA4, to obtain a second encrypted copy Data EA4(Data400-2) (Ciphertext Black 2A). This results in two different encrypted data.

[0086] In parallel, the second copy Data400-2 is also combined with a second data word Seed400-2, using the XOR operation 403, then the encryption operation 404 is used, with another encryption key KeyB4, to obtain a second encrypted copy Data EB4(Data400-2) (Ciphertext Black IB). Then, the first copy Data400-1 is also combined with the second encrypted copy Data EB4(Data400-2) using the XOR operation 403, and the encryption operation 404 is used, with the encryption key KeyB4, to obtain a first encrypted copy Data EB4(Data400-1) (Ciphertext Black 2B). This again results in two different encrypted data blocks.

[0087] All encrypted data blocks EA4(Data400-1), EA4(Data400-2), EB4(Data400-1) and EB4(Data400-2) may be stored in the memory. According to a preferred embodiment, all encrypted data EA4(Data400-1), EA4(Data400-2), EB4(Data400-1) and EB4(Data400-2) may be mixed and stored in the memory, as described in connection with [Fig.3].

[0088] The method 402 for recovering critical data blocks is as follows. All encrypted data blocks EA4(Data400-1), EA4(Data400-2), EB4(Data400-1) and EB4(Data400-2) are recovered from memory.

[0089] Each encrypted block of data EA4(Data400-1) is decrypted using a decryption operation 405 and the key KeyA4, and then separated from the data word Seed400-1 using the XOR operation 403. According to one example, the encryption operation 404 is an implementation of an AES decryption operation. Each encrypted block of data EA4(Data400-2) is decrypted using the decryption operation 405, and then separated from the encrypted block of data EA4(Data400-1) using the XOR operation 403. The copy Data400-1 is then to be recovered as a result of the two operations.

[0090] Similarly, each encrypted block of data EB4(Data400-2) is decrypted using a decryption operation 405 and the key KeyB4, and then separated from the data word Seed400-2 using the XOR operation 403. Each encrypted block of data EB4(Data400-1) is decrypted using the decryption operation 405, and then separated from the encrypted block of data EB4(Data400-2) using the XOR operation 403. The copy Data400-2 must then be recovered as a result of the two operations.

[0091] Comparison steps of each data block are then performed to determine whether the decrypted data blocks are all identical. The advantage of using the AES-CBC algorithm is that it ensures that an attacker cannot simply look for two encrypted blocks that decrypt into identical values ​​using the two keys. They must look for two pairs of encrypted blocks that decrypt into two pairs of identical values. This doubles the resistance to brute force attacks.

[0092] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will occur to those skilled in the art.

[0093] Finally, the practical implementation of the embodiments and variants described is within the reach of those skilled in the art from the functional indications given above.

Claims

Claims

1. Method for storing (401) critical data blocks (Data200; Data300; Data400-1, Data400-2) of an electronic device (100; 200) in a memory (103; 202; 302) external to said electronic device (100; 200), comprising the following steps: - obtaining first encrypted data blocks (EA(Data200); EA(Data300); EA4(Data400-1), EA4(Data400-2)) by encrypting critical data blocks (Data200; Data300; Data400-1, Data400-2) using a first encryption key (2063; KeyA4); - obtaining second encrypted data blocks (EB(Data200); EB(Data300); EB4(Data400-l), EB4(Data400-2)) by encrypting critical data blocks (Data200; Data300; Data400-l, Data400-2) using a second encryption key (2064; KeyB4) different from the first encryption key (2063; KeyA4); and - storing the first and second encrypted data blocks (EA(Data200), EB(Data200); EA(Data300), EB(Data300);EA4(Data400-l), EB4(Data400-2), EA4(Data400-l), EB4(Data400-2)) in said memory (103; 202; 302).;

2. The method of claim 1, wherein said first and second encrypted data blocks (EA(Data200, EB(Data200); EA(Data300), EB(Data300); EA4(Data400-1), EA4(Data400-2), EB4(Data400-1), EB4(Data400-2)) are mixed in said memory (103; 202; 302).

3. Method according to claims 1 or 2, wherein, in said memory (103; 202; 302), each data composing said each first encrypted data block (EA(Data200); EA(Data300); EA4(Data400-1), EA4(Data400-2)) is stored immediately before the corresponding second encrypted data block (EA(Data200); EA(Data300); EA4(Data400-1), EA4(Data400-2)).

4. A method according to any one of claims 1 to 3, wherein the first and second encrypted blocks of data are obtained by applying the AES method to the critical data (Data200; Data300; Data400-1, Data400-2).

5. The method of claim 4, wherein said first encrypted data blocks (EA4(Data400-1), EB4(Data400-2)) are obtained using the following steps: (a) combining critical data blocks (Data400-1, Data400-2) with a first data word (Seed400-1, Seed400-2); and (b) encrypting the result of step (a) with said first encryption key (KeyA4, KeyB4).

6. A method according to claim 4 or 5, wherein said second encrypted data blocks (EA4(Data400-2), EB4(Data400-1)) are obtained using the following steps: (c) combining critical data blocks (Data400-2, Data400-1) with said first encrypted data blocks (EA4(Data400-1), EB4(Data400-2)); and (d) encrypting the result of step (c) with said second encryption key (KeyA4, KeyB4).

7. A method according to any one of claims 1 to 6, wherein said memory (103; 202; 302) is a DRAM memory (103; 202; 302).

8. A method according to any one of claims 1 to 7, wherein said electronic device (100; 200) comprises a processor capable of processing critical data blocks (Data200; Data300; Data400-1, Data400-2).

9. A method of recovering critical blocks of data stored in a memory (103; 202; 302) using the method according to any one of claims 1 to 8.

10. Method according to claim 9, comprising the following steps: - obtaining first and second encrypted blocks of data (EA(Data200), EB(Data200); EA(Data300), EB(Data300); EA4(Data400-l), EB4(Data400-2), EA4(Data400-l), EB4(Data400-2)) in said memory (103; 202; 302); - decrypting the first encrypted blocks of data (EA(Data200); EA(Data300); EA4(Data400-l), EA4(Data400-2)) using the first encryption key (2063; KeyA4); - decrypting the second encrypted data blocks (EB(Data200); EB(Data300); EB4(Data400-1), EB4(Data400-2)) using said second encryption key (2064; KeyB4); and - comparison of the results of the two decryption steps, if they are identical, the critical data blocks (Data200; Data300; Data400-l, Data400-2) can be used.

11. A method according to claim 9 or 10, wherein, if the result of the two decryption steps is not identical, the critical data blocks (Data200; Data300; Data400-1, Data400-2) cannot be used.

12. A method according to any one of claims 9 to 11, wherein the step of obtaining the first and second encrypted blocks of data (EA(Data200), EB(Data200); EA(Data300), EB(Data300); EA4(Data400-1), EB4(Data400-2), EA4(Data400-1), EB4(Data400-2)) from said memory (103; 202; 302) comprises a step of separating the first and second encrypted blocks of data.

13. Electronic device (100; 200) adapted to store critical data blocks (Data200; Data300; Data400-1, Data400-2) in a memory (103; 202; 302) which is external to said electronic device (100; 200) by performing the following steps: - obtaining first encrypted data blocks (EA(Data200); EA(Data300); EA4(Data400-1), EA4(Data400-2)) by encrypting the critical data blocks (Data200; Data300; Data400-1, Data400-2) using a first encryption key (2063; KeyA4); - obtaining second encrypted data blocks (EB(Data200); EB(Data300); EB4(Data400-l), EB4(Data400-2)) by encrypting critical data blocks (Data200; Data300; Data400-l, Data400-2) using a second encryption key (2064; KeyB4) different from the first encryption key (2063; KeyA4); and - storing the first and second encrypted data blocks (EA(Data200), EB(Data200); EA(Data300), EB(Data300);EA4(Data400-l), EB4(Data400-2), EA4(Data400-l), EB4(Data400-2)) in said memory (103; 202; 302).;

14. A device capable of recovering critical blocks of data stored in a memory (103; 202; 302) using the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Memory authentication with redundant encryption

    US20140006797A1

  • Host controller and system-on-chip

    US20150371055A1

  • Techniques for leveraging multiple cryptographic algorithms for authenticating data

    US20180129826A1