Method of configuring a microcontroller

The method addresses the vulnerability of microcontrollers to anomalies during configuration by repeatedly attempting the configuration loading without powering down and using a counter to determine when to block the microcontroller, thus ensuring security and minimizing user experience degradation.

FR3155602A1Pending Publication Date: 2025-05-23STMICROELECTRONICS INT NV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
FR2023012642
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-17
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Microcontrollers are vulnerable to anomalies during the configuration phase due to sensitivity to external factors like temperature and magnetic fields, which can be exploited during attacks, compromising security while degrading user experience.

Method used

Implement a method where if an anomaly is detected during the configuration loading operation from non-volatile memory, a new loading operation is attempted without powering down the microcontroller, with a counter to track consecutive anomalies, and the microcontroller is put into a blocking mode only after exceeding a threshold, requiring a power-down to resume.

Benefits of technology

This approach ensures optimal security during the configuration phase by preventing the microcontroller from entering the startup phase if anomalies are detected, while minimizing the impact on user experience by allowing temporary disturbances to be resolved without powering down the device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for configuring a microcontroller The present description relates to a method for configuring a microcontroller provided with a non-volatile memory, in which, during an implementation of a configuration loading operation of the microcontroller from data in the non-volatile memory, if an anomaly is detected, then a new configuration loading operation is implemented at least once without the microcontroller being powered down. Figure for the abstract: Fig. 2
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for configuring a microcontroller Technical field

[0001] The present description relates generally to methods for configuring microcontrollers as well as to microcontrollers implementing these methods. Prior art

[0002] When powered up, many electronic circuits such as microcontrollers start with a configuration phase based on parameters stored in a memory.

[0003] This memory is potentially sensitive to external elements such as temperature or magnetic fields. This sensitivity can cause anomalies during the configuration phase which are exploited during attacks. Summary of the invention

[0004] There is a need to ensure optimal security during the configuration phase of microcontrollers while limiting the impact on the user experience.

[0005] One embodiment overcomes all or part of the drawbacks of the known methods.

[0006] One embodiment provides a method of configuring a microcontroller having a non-volatile memory, wherein, when implementing a configuration loading operation of the microcontroller from data in the non-volatile memory, if an anomaly is detected, then a new configuration loading operation is implemented at least once without the microcontroller being powered down.

[0007] One embodiment provides a microcontroller having a non-volatile memory, wherein, when implementing a configuration loading operation of the microcontroller from data in the non-volatile memory, if an anomaly is detected, then a new configuration loading operation is implemented at least once without the microcontroller being powered down.

[0008] According to one embodiment, if, during the implementation of an operation of loading the configuration of the microcontroller from the non-volatile memory, no anomaly is detected, then a procedure for starting the microcontroller is implemented.

[0009] According to one embodiment, a counter is incremented with each new consecutive implementation of said loading operation linked to a detection of an anomaly.

[0010] According to one embodiment, when the counter exceeds a threshold N, then the microcontroller is put into a blocking mode.

[0011] According to one embodiment, from the moment the microcontroller has been put into the blocking mode, then only a power-down of the microcontroller allows a new operation of loading the configuration of the microcontroller from the non-volatile memory to be implemented.

[0012] According to one embodiment, the anomaly detection is implemented by comparing error correction codes.

[0013] According to one embodiment, the anomaly detection is implemented by comparison of cyclic redundancy codes.

[0014] According to one embodiment, the anomaly detection is implemented from data in the non-volatile memory.

[0015] According to one embodiment, the anomaly detection is implemented by a memory interface of the microcontroller.

[0016] According to one embodiment, the non-volatile memory is an MRAM type memory.

[0017] According to one embodiment, the non-volatile memory is a phase change type memory. Brief description of the drawings

[0018] These characteristics and advantages, as well as others, will be explained in detail in the following description of particular embodiments given without limitation in relation to the attached figures among which:

[0019] [Fig.l] represents, very schematically and in the form of blocks, an example of a microcontroller of the type to which the described embodiments apply;

[0020] [Fig.2] represents in block form a method of configuring the microcontroller of [Fig.l]. Description of the embodiments

[0021] The same elements have been designated by the same references in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same references and may have identical structural, dimensional and material properties.

[0022] For the sake of clarity, only the steps and elements useful for understanding the embodiments described have been represented and are detailed.

[0023] Unless otherwise specified, when referring to two elements connected to each other, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") to each other, this means that these two elements can be connected or be connected by means of one or more other elements.

[0024] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made unless otherwise specified to the orientation of the figures.

[0025] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "of the order of" mean to within 10%, preferably to within 5%.

[0026] [Fig.l] represents, very schematically and in the form of blocks, an example of a microcontroller 100 of the type to which the described embodiments apply.

[0027] The microcontroller 100 comprises a non-volatile memory 104 (NVM), for example of the FLASH or MRAM or phase change memory type, capable of communicating, via a communication bus 114, with a non-volatile memory interface 106 (MEM INTERFACE) configured to write or read data in and from the non-volatile memory 104.

[0028] The microcontroller 100 further comprises, for example, a processing unit 110 (CPU) comprising one or more processors under control of instructions stored in an instruction memory 112 (INSTR MEM). The instruction memory 112 is, for example, a volatile memory of the random access type (Random Access Memory, RAM). The processing unit 110 and the memory 112 communicate, for example, via a system bus 140 (data, address and command). The memory 104 is connected to the system bus 140 via the non-volatile memory interface 106 and via the bus 114. The device 100 further comprises an input / output interface 108 (FO interface) connected to the system bus 140 to communicate with the outside.

[0029] The microcontroller 100 may integrate other circuits implementing other functions (for example, one or more volatile and / or non-volatile memories, or other processing units), symbolized by a block 116 (FCT) in [Fig.l]. Among these other circuits, the microcontroller 100 comprises for example a read-only or static memory 118 (ROM).

[0030] When powered up, the microcontroller implements a phase, in other words a configuration operation (OBL, Option Byte Loading in English) based on parameters, for example user option bytes (Option bytes in English) stored in a memory. During this configuration phase, the configuration parameters are loaded from the memory 104 to, for example, the processing unit 110.

[0031] The memory 104 is for example sensitive to temperature or to an external magnetic field, which can impact cycling but also programming or even reading. Attacks perpetrated by hackers can also take advantage of this sensitivity in order to modify the configuration of the microcontroller 100. The configuration phase, which depends on data from the memory 104, is therefore particularly critical and it is appropriate to secure it. One solution would be to block the operation of the microcontroller as soon as an anomaly is detected during the configuration phase and to only allow the unlocking of the microcontroller 100 after it has been powered down. This solution nevertheless has the disadvantage of degrading the user experience if the anomaly is only temporary and is not linked to an attack.

[0032] The described embodiments propose that, during an implementation of an operation of loading a configuration of the microcontroller from data of the non-volatile memory 104, if an anomaly is detected, then a new configuration loading operation is implemented at least once.

[0033] This allows that, when a temporary disturbance causes an anomaly during the configuration operation, then the microcontroller restarts the configuration loading operation without the user necessarily powering down the microcontroller.

[0034] This also makes it possible to preserve the security of the configuration loading operation because the microcontroller does not enter the startup phase if an anomaly is detected.

[0035] [Fig.2] represents in block form a method of configuring the microcontroller of [Fig.l].

[0036] In a first step 202 (Power up), the microcontroller 100 is powered up.

[0037] In a subsequent step 204 (OBL), the configuration loading operation is implemented for example by the memory interface 106 to load the configuration data, for example in the form of bytes, from the microcontroller 100.

[0038] In a step 206 (User OB integrity?), subsequent to step 204, an operation for detecting an anomaly in the configuration loading operation is implemented, for example via the memory interface 106. In one example, step 206 consists of verifying the integrity, or the correspondence, of error correction codes or cyclic redundancy codes linked to the loaded user option bytes.

[0039] If no anomaly is detected (branch Y), then a step 208 (CPU boots) is performed. In this step 208, a procedure for starting the microcontroller 100 is implemented, for example with the processing unit 110 and / or by loading and executing startup programs in the memory 104.

[0040] If an anomaly is detected (branch N), then a step 210 (Counter <N) est réalisée. Dans cette étape 210, un compteur, par exemple mis en oeuvre dans l’interface mémoire 106, est incrémenté à chaque recommencement consécutif de the configuration loading operation linked to the detection of an anomaly. When the value of the counter exceeds a threshold N, for example N=2 to 10, then a step 212 (Chip locked) is carried out. If the value of the counter is lower than the threshold (branch Y) then the method starts again at step 204 for a new configuration loading operation without the need for a power-down.

[0041] In this step 212, the microcontroller is put into a blocking mode. In this mode, the microcontroller is for example no longer accessible in reading or writing, and for example no longer performs tasks. In this mode, only a power-down, for example by disconnecting a battery powering the microcontroller 100, will make it possible to return to step 202.

[0042] The method presented in [Fig.2] makes it possible to restart the configuration loading operation, without powering down the microcontroller 100 as long as an anomaly is detected, and this until reaching the predetermined number of restarts N. This case corresponds for example to transient anomalies which are not linked to an attack. If one or more anomalies are still detected despite the fact that the configuration loading operation is repeated several times consecutively, then it may be an attack and the microcontroller will be put into the blocking mode so that it can be secured and secrets, such as encryption keys, cannot be revealed.

[0043] The value of the threshold N may be chosen according to the robustness to attacks or to external physical parameters. Thus if N=2 then an attack will be stopped very quickly but this will block the microcontroller quickly in the event of a relatively long temporary disturbance. The higher N is, the longer the attack can last but the more it will be possible to let an external disturbance pass without having to power down the microcontroller 100.

[0044] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will occur to those skilled in the art. In particular, the anomaly detection during step 206 may consist of verifying values ​​other than those linked to user option bytes or the use of error verification methods other than error correction codes or other than cyclic redundancy codes.

[0045] Finally, the practical implementation of the embodiments and variants described is within the reach of the person skilled in the art from the functional indications given above. In particular, even if the method has been described in the case of a microcontroller, the person skilled in the art will be able to use his knowledge to apply this method to other types of electronic circuits such as systems on chip (System on chip, SOC, in English) using a configuration phase from data stored in a memory.

Claims

Claims

1. A method of configuring a microcontroller (100) having a non-volatile memory (104), wherein, when implementing a configuration loading operation of the microcontroller (100) from data in the non-volatile memory (104), if an anomaly is detected, then a new configuration loading operation is implemented at least once without the microcontroller being powered down.

2. Method according to claim 1 in which, if, during the implementation of an operation of loading the configuration of the microcontroller from the non-volatile memory (104) no anomaly is detected, then a procedure for starting the microcontroller is implemented.

3. Method according to claim 1 or 2, in which a counter is incremented at each new consecutive implementation of said loading operation linked to a detection of an anomaly.

4. The method of claim 3, wherein when the counter exceeds a threshold N, then the microcontroller is put into a blocking mode.

5. Method according to claim 4, in which, from the moment when the microcontroller has been put into the blocking mode, then only a power-down of the microcontroller allows a new operation of loading the configuration of the microcontroller (100) from the non-volatile memory (104) to be implemented.

6. A method according to any one of claims 1 to 5, wherein the anomaly detection is implemented by comparing error correction codes (ECC).

7. A method according to any one of claims 1 to 6, wherein the anomaly detection is implemented by comparing cyclic redundancy codes (CRC).

8. A method according to any one of claims 1 to 7, wherein the anomaly detection is carried out from data in the non-volatile memory (104).

9. The method of claim 8, wherein the anomaly detection is implemented by a memory interface (106) of the microcontroller (100).

10. A method according to any one of claims 1 to 9, wherein the non-volatile memory (104) is an MRAM type memory.

11. A method according to any one of claims 1 to 9, wherein the non-volatile memory (104) is a phase change type memory.

12. A microcontroller (100) having a non-volatile memory (104) and configured to implement the method of any preceding claim.

Citation Information

Patent Citations

  • Device used in clock and reset module of low-power-consumption microprogrammed control unit

    CN106774633A

  • Abnormal power failure data storage device suitable for microcontroller

    CN115079803A

  • Programmable logic auto write-back

    US20060050568A1