Method of operating a non-volatile memory

The method of validating transactions based on attribute comparisons in the non-volatile memory operating system effectively prevents malicious modifications to memory sector configurations, ensuring secure and continuous availability of configurations throughout the circuit lifecycle.

FR3155620A1Pending Publication Date: 2025-05-23STMICROELECTRONICS INT NV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
FR2023012668
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-17
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Existing non-volatile memory operating methods fail to prevent malicious applications from modifying the configuration of memory sectors, while also limiting the availability of memory sector configurations throughout the circuit lifecycle.

Method used

A method of operating a non-volatile memory that validates transactions requesting configuration value modifications by comparing transaction attributes with sector access attributes, using a memory interface that implements a register with an association table to manage sector configurations.

Benefits of technology

This solution effectively prevents malicious applications from modifying memory sector configurations while ensuring that sector configurations remain available throughout the product lifecycle, enhancing security and usability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method of operating a non-volatile memory The present description relates to a method of operating a non-volatile memory, comprising the validation of a transaction, requesting a modification of a configuration value (HCD, Write protection, write mode) of a sector of the memory, after comparison of the attributes of the transaction with access attributes of said sector of said memory. Figure for the abstract: Fig. 3
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method of operating a non-volatile memory Technical field

[0001] The present description relates generally to the methods of operating a non-volatile memory as well as the electronic circuits implementing these methods. Prior art

[0002] Many electronic circuits such as microcontrollers use applications, for example boot programs (BOOT in English), which are loaded into a non-volatile memory of the circuit. These applications may want to configure certain sectors of the non-volatile memory. However, malicious applications may want to modify the configuration of memory sectors linked to other applications. Summary of the invention

[0003] There is a need to provide non-volatile memory operating methods that prevent memory sector configuration modifications by malicious applications while allowing memory sector configuration throughout the circuit lifecycle.

[0004] One embodiment overcomes all or part of the drawbacks of the known methods.

[0005] One embodiment provides a method of operating a non-volatile memory. volatile, including the validation of a transaction, requesting a modification of a configuration value of a sector of memory, after comparing the attributes of the transaction with access attributes of said sector of said memory.

[0006] According to one embodiment, the transaction is validated when all the attributes of the transaction have a security level greater than or identical to the access attributes of said corresponding sector of said memory.

[0007] According to one embodiment, a register with an association table is configured to store said configuration value for each sector of the memory.

[0008] According to one embodiment, the value of a given index bit of said table corresponds to the configuration value of a sector having the same index.

[0009] According to one embodiment, a memory interface is configured to allow or deny a transaction based on attributes of the transaction and access attributes of memory sectors.

[0010] According to one embodiment, the memory interface is configured to implement said register with association table.

[0011] According to one embodiment, the validation of the transaction is carried out by the memory interface.

[0012] According to one embodiment, the attributes of the transaction are the attributes of an application implementing said transaction.

[0013] According to one embodiment, the attributes of the transaction comprise an access restriction level, an addressing mode restriction level, and a program access prohibition level taken from a first, a second and a third program access prohibition level; and the attributes of the sector comprise the access restriction level, the addressing mode restriction level, and a program access prohibition level taken from a fourth, a fifth and a sixth program access prohibition level.

[0014] According to one embodiment, a transaction having an attribute corresponding to a first access restriction level can access a sector having the first or a second access restriction level; a transaction having an attribute corresponding to a first addressing mode restriction level can access a sector having a second addressing mode restriction level; a transaction having an attribute corresponding to the second access restriction level cannot access a sector having the first access restriction level; and a transaction having an attribute corresponding to a second addressing mode restriction level cannot access a sector having the first addressing mode restriction level.

[0015] According to one embodiment, a transaction having an attribute corresponding to a first program access prohibition level can access a sector having as an attribute a fourth, a fifth or a sixth program access prohibition level; a transaction having an attribute corresponding to a second program access prohibition level can access a sector having as an attribute the fifth and the sixth protection levels but cannot access a sector having as an attribute the fourth program access prohibition level; and a transaction having an attribute corresponding to a third program access prohibition level can access a sector having as an attribute the sixth program access prohibition level but cannot access a sector having as an attribute the fourth or the fifth program access prohibition level.

[0016] According to one embodiment, the attributes of the memory sector are either the attributes of a previous transaction or default attributes defined by the first level of access restriction, the second level of addressing mode restriction, and the fourth level of program access prohibition.

[0017] According to one embodiment, the configuration value corresponds to a mode of cycling, a write-protect mode, or a write mode.

[0018] One embodiment provides an electronic circuit, comprising a non-volatile memory interface and a non-volatile memory, configured to implement the method described above.

[0019] One embodiment provides a method of operating a non-volatile memory, wherein: - a first and a second successive transaction request a modification of a configuration value of the same memory zone of said non-volatile memory, the attributes of the first transaction having a higher security level than those of the second transaction; and - the second transaction is refused. Brief description of the drawings

[0020] These characteristics and advantages, as well as others, will be explained in detail in the following description of particular embodiments given without limitation in relation to the attached figures among which:

[0021] [Fig.l] represents, very schematically and in the form of blocks, an example of an integrated circuit of the type to which the described embodiments apply;

[0022] [Fig.2] represents an example of a method of operation of the circuit of [Fig.l];

[0023] [Fig.3] represents a method of operating the circuit of [Fig.l] according to one embodiment;

[0024] [Fig.4] represents a method of operating the circuit of [Fig.3] according to one embodiment; and

[0025] [Fig.5] represents a method of operating the circuit of [Fig.3] according to one embodiment. Description of the embodiments

[0026] The same elements have been designated by the same references in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same references and may have identical structural, dimensional and material properties.

[0027] For the sake of clarity, only the steps and elements useful for understanding the embodiments described have been shown and are detailed.

[0028] Unless otherwise specified, when referring to two elements connected between them, it means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") between them, it means that these two elements can be connected or be linked through one or more other elements.

[0029] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made unless otherwise specified to the orientation of the figures.

[0030] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "of the order of" mean to within 10%, preferably to within 5%.

[0031] [Fig.l] represents, very schematically and in the form of blocks, an example of an integrated circuit 100 of the type to which the described embodiments apply. The circuit 100 is for example a microcontroller.

[0032] The circuit 100 comprises a non-volatile memory 104 (NVM), for example of the FLASH or phase change memory (PCM) type, capable of communicating, via a communication bus 114, with a non-volatile memory interface 106 (NVM INTERFACE) configured to write or read data in and from the non-volatile memory 104.

[0033] The circuit 100 further comprises, for example, a processing unit 110 (CPU) comprising one or more processors under control of instructions stored in an instruction memory 112 (INSTR MEM). The instruction memory 112 is, for example, a volatile memory of the random access type (Random Access Memory, RAM). The processing unit 110 and the memory 112 communicate, for example, via a system bus 140 (data, address and control). The non-volatile memory 104 is connected to the system bus 140 via the non-volatile memory interface 106 and via the bus 114. The device 100 further comprises an input / output interface 108 (I / O interface) connected to the system bus 140 to communicate with the outside.

[0034] The circuit 100 may integrate other circuits implementing other functions (for example, one or more volatile and / or non-volatile memories, or other processing units), symbolized by a block 116 (FCT) in [Fig.l]. Among these other circuits, the circuit 100 comprises for example a read-only or static memory 118 (ROM).

[0035] [Fig.2] represents an example of a method of operation of the circuit of [Fig.l].

[0036] More particularly, [Fig.2] represents an example of a method of operation of the memory 104.

[0037] In the example shown, data relating to a first, a second and a third application (Appl, App2 and App3), are stored in different sectors of the memory 104. The applications Appl, App2 and App3 are defined with attributes including an access permission or access restriction level, a privilege level, and a program access prohibition level.

[0038] The access restriction level of an application defines, for example, accessibility of memory areas. The privilege level of an application defines, for example, addressing mode restrictions. The program access prohibition level defines, for example, access prohibitions for other applications, or data used by other applications.

[0039] Access to the different sectors is achieved by implementing transactions through the applications.

[0040] In one example, an application defined to have a first level of access restriction (secure, Sec), has more rights than an application with a second level of access restriction (non-secure, NS). The first and second levels of access restriction are for example implemented with the TrustZone protocol of the ARM® CORTEX-M architecture. In one example, an application defined to have a first level of privileges (priviledged, Priv) has more rights than an application with a second level of privileges (unpriviledged, unPriv). The first and second levels of privileges are for example those implemented with an ARM architecture. An application implemented in the first privilege mode (Priv), in other words in the first addressing mode restriction mode, has for example its own space with physical addresses.An application implemented in the second privilege mode (unPriv), that is, in the second addressing mode restriction mode, has, for example, its own space with virtual addresses and cannot have access to other memory-related processes that would directly use physical addresses. In one example, an application defined with a first program access prohibition level of HDPL1 has more rights than an application with a second program access prohibition level of HDPL2. Similarly, an application defined with the second program access prohibition level of HDPL2 has more rights than an application with a third program access prohibition level of HDPL3.The program access denial levels HDPL1, HDPL2 and HDPL3 correspond, for example, to protection levels for successively installed startup programs, the aim being that a startup program installed afterward cannot access a previously installed startup program. The protection levels are implemented, for example, using a monotonic counter.

[0041] In the text, a transaction implemented by an application has the same attributes as the application implementing this transaction.

[0042] The sectors of the memory 104 are defined with different access attributes. These access attributes are for example the access permission or restriction level, the privilege level, and a program access prohibition level.

[0043] A sector can for example be defined with the first or second level of Sec, NS access restriction. Thus, an application defined with the second NS access restriction level cannot have access to a sector defined with the first Sec access restriction level. An application defined with the first Sec access restriction level can have access to a sector defined with the first or second Sec, NS access restriction level.

[0044] A sector can further be defined with the first or second level of privileges Priv, unPriv. Thus, an application defined with the second level of privileges unPriv cannot have access to a sector defined with the first level of privileges Priv. An application defined with the first level of privilege Priv can have access to a sector defined with the first or second level of privileges Priv, unPriv.

[0045] A sector may further be defined with a fourth, fifth or sixth program access prohibition level OB-HDP, HDP-EXT, non-HDP. Thus, an application defined with the first program access prohibition level HDPL1, which is for example a first startup program stage, may have access to a sector defined with the fourth, fifth or sixth program access prohibition levels OB-HDP, HDP-EXT, non-HDP. An application defined with the second program access prohibition level HDPL2, which is for example a second startup program stage, may have access to a sector defined with the fifth or sixth protection levels HDP-EXT, non-HDP but not to a sector defined with the fourth program access prohibition level OB-HDP.An application defined with the third program access prohibition level HDPL3, which is for example a third boot program stage, can have access to a sector defined with the sixth program access prohibition level non-HDP but not to a sector defined with the fourth or fifth program access prohibition level OB-HDP, HDP-EXT. .

[0046] In addition to the attributes, each sector of the memory 104 is configured with one or more configuration values, stored in registers, and which correspond for example to a high cycling mode (HCD), a write protection mode or a write mode.

[0047] In write protection mode, sectors with this configuration do not accept any write access requests. They can nevertheless be read.

[0048] In the example shown, the memory sectors of memory 104, referenced Sector#0, Sector#1, Sector#2, are used by the first application Appl.

[0049] A disadvantage of the example shown is that the sector configuration value, written by an application with a given protection level, can be modified by an application with fewer permissions. Thus, in a For example, the application Appl, with program access denial level HDPL1, can write the configuration value of sectors Sector#0, Sector#l, Sector#2 as HCD. For example, the application App2, with program access denial level HDPL2, can disable the HCD mode of these sectors, which can lead to a denial of service.

[0050] In another example, the application Appl, whose attributes are defined with the first access restriction level Sec, the first privilege level Priv, and the program access prohibition level HDPL1, has written the configuration value of the sectors Sector#0, Sector#l, Sector#2 as write protection. The application App2, whose attributes are defined with the first access restriction level Sec, the second privilege level unPriv, and the program access prohibition level HDPL2, can for example decrease the number of sectors configured in write protection mode. This results in a modification of the application Appl.

[0051] Another disadvantage of the example shown is that the configuration value(s) are not available throughout the entire life cycle of the product, which is limiting.

[0052] To overcome these drawbacks, the embodiments described propose a method of operating the memory 104, comprising the validation of a transaction requesting a modification of a configuration value of a sector of the memory 104 after comparison of the attributes of the transaction with access attributes of said sector of said memory.

[0053] This makes it possible to make the memory sectors available for all applications without compromising on security. In addition, the different configurations of the sectors remain available for all applications at each stage of the product life cycle, for example during customization at different subcontractors.

[0054] [Fig.3] represents a method of operating the circuit of [Fig.l] according to one embodiment.

[0055] In a step 302 (START) the method starts.

[0056] In a following step 303 (APP TRANSACTION DEMANDS MEMORY SECTOR CONFIGURATION REGISTER CHANGE), a transaction generated by an application requests a change of configuration value, relating to a sector referenced for example with an index “i”. In other words, the transaction requests a write in the configuration register.

[0057] In a following step 304 (TRANSACTION ATTRIBUTES COHERENT WITH SECTOR ATTRIBUTES?), the memory interface 106 checks the consistency between the attributes of the transaction, in other words of the application implementing the transaction, and the access attributes of the sector of index “i”. If the application issuing the transaction has permission to access the sector referenced “i” then the transaction is accepted (Y branch) in a later step 305 (TRANSACTION VALIDATED). If the application issuing the transaction does not have permission to access the sector referenced "i" then the transaction is rejected (N branch) in a later step 306 (END PROCESS) and an error is returned via bus 114 or there is no reaction (operation called write ignore) for example.

[0058] Steps 302 to 306 are for example carried out at any time during the product life cycle.

[0059] In one example, a Bitmap register is used to store the configuration values ​​for each sector. In this case, the value of bit "i" of the configuration value register corresponds to the configuration value of the sector referenced with index "i". The implementation of the bitmap allows for ease of implementation.

[0060] The following tables TABLE 1, TABLE 2 and TABLE 3 summarize the cases where a transaction attribute is of a higher security level than an access attribute of a sector "i". In other words, an attribute of a transaction requesting write access to the sector configuration register is of a higher security level or the same as an access attribute of a sector "i" if the authorization of access to the bit "i" of the configuration register of the sector "i" is accepted. In other words, the attributes of the transaction have a higher security level or the same as the access attributes of the sector when the application implementing the transaction has rights higher than or the same as the access attributes of the sector.

[0061] [Tables 1] Attributes of the transaction requesting write access to the sector configuration register Allow access to bit "i" of the configuration register of sector "i" HDPL1 Accepted for all bits and protection levels HDPL2 Accepted for bit "i" of the configuration register only if sector "i" has the fifth or sixth program access prohibition level as attribute HDP-EXT, non-HDP HDPL3 Accepted for bit "i" of the configuration register only if sector "i" has the sixth non-HDP program access prohibition level as attribute

[0062] [Tables2] Attributes of the transaction requesting write access to the sector configuration register Authorization of access to the "i" bit of the configuration register of sector "i" Sec Accepted for the "i" bit of the configuration register if the sector "i" has the first or second level of access restriction as attribute Sec, NS NS Accepted for the "i" bit of the configuration register only if the sector "i" has the second level of access restriction as attribute NS

[0063] [Tables3] Attributes of the transaction requesting write access to the sector configuration register Allow access to the "i" bit of the configuration register of sector "i" Priv Accepted for the "i" bit of the configuration register if sector "i" has the first or second privilege level attribute Priv, unPriv unPriv Accepted for the "i" bit of the configuration register only if sector "i" has the second privilege level attribute unPriv

[0064] If the authorization to access bit “i” of the configuration register of sector “i” is not accepted in just one of the three tables, then the transaction is, for example, ignored (write ignore command) or refused.

[0065] In one example, by default, memory sectors are defined upon reset by the first level of access restriction (Sec), the second level of addressing mode restriction (unPriv), and the fourth level of program access prohibition (OB-HDP).

[0066] [Fig.4] represents a method of operating the circuit of [Fig.3] according to one embodiment. More particularly, the example of [Fig.4] represents the case where the application Appl has as attributes the first level of access restriction Sec, the first level of privileges Priv, and the first level of access prohibition of program HDPL1. In the example shown, application App2 has as attributes the first access restriction level Sec, the first privilege level Priv, and the second program access prohibition level HDPL2. In this example, application Appl has reserved the sector with index i=8, using memory interface 106, and defining it as having the first access restriction level Sec, the first privilege level Priv, and the fourth program access prohibition level OB-HDP. Application 1 configures sector 8, for example by changing the index bit 8 in the configuration register (write mode reg), with one of the modes among high cycle mode HCD, write protection mode (Write protection) or a write mode (write mode). Next, in the example shown, the application App2 attempts to modify the value of the index bit 8 in the register containing the configuration values ​​write mode reg.By applying the method of [Fig.3], the application App2 cannot modify the values ​​of the configuration register at the level of the index bit 8 because the permission level of the transaction, in other words of the application App2, does not allow it to access the sector of index 8. In fact, the application App2 has as attribute the second level of program access prohibition HDPL2 which does not give access to the sectors protected by the fourth level of program access prohibition OB-HDP.

[0067] [Fig.5] represents a method of operating the circuit of [Fig.3] according to one embodiment.

[0068] More particularly, the example of [Fig.5] represents the case where the application Appl and the application App2 are similar to the example of [Fig.4]. In addition, a third application App3 has as attributes the second access restriction level NS, the first privilege level Priv, and the second program access prohibition level HDPL2. In this example, the application App3 has reserved the sector of index i= 14, using the memory interface 106, and defining it as having the second access restriction level NS, the first privilege level Priv, and the fifth program access prohibition level HDP-EXT. Application 3 configures, for example, sector 14, for example by changing index bit 14 in the configuration register (write mode reg), with one of the modes among high cycle mode HCD, write protection mode or a write mode.Then, in the example shown, the application App2 attempts to modify the value of the index bit 14 in the register comprising the configuration values ​​write mode reg. By applying the method of [Fig.3], the application App2 is authorized, by the memory interface 106, to modify the values ​​of the configuration register at the level of the index bit 14, in other words the configuration values ​​of the sector of index 14, because the permission level of the transaction, here the first access restriction mode Sec, allows it to access the sectors configured with the . second level of NS access restriction.

[0069] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will occur to those skilled in the art. In particular, sector configuration values ​​other than the configuration values ​​corresponding to the high cycle mode (HCD), the write protection mode, or the write mode may be implemented.

[0070] Finally, the practical implementation of the embodiments and variants described is within the reach of the person skilled in the art from the functional indications given above. In particular, even if the examples presented use a register with an association table, it is possible to implement the method of [Fig.3] without an association table, to the detriment, however, of simplicity of implementation.

Claims

Claims

1. Method of operating a non-volatile memory, comprising the validation of a transaction, requesting a modification of a configuration value (HCD, Write protection, write mode) of a sector of the memory, after comparing the attributes of the transaction with access attributes of said sector of said memory.

2. The method of claim 1, wherein the transaction is validated when all attributes of the transaction have a security level greater than or identical to the access attributes of said corresponding sector of said memory.

3. A method according to claim 1 or 2, wherein a register with association table is configured to store said configuration value for each sector of the memory.

4. The method of claim 3, wherein the value of a given index bit of said table corresponds to the configuration value of a sector having the same index.

5. A method according to any one of claims 1 to 4, wherein a memory interface (106) is configured to allow or deny a transaction based on attributes of the transaction and access attributes of memory sectors.

6. Method according to claim 5 in its dependency on claim 3, in which the memory interface (106) is configured to implement said register (write mode reg) with association table.

7. The method of claim 5 or 6, wherein the validation of the transaction is performed by the memory interface (106).

8. Method according to any one of claims 1 to 7, in which the attributes of the transaction are the attributes of an application (Appl, App2, App3) implementing said transaction.

9. A method according to any one of claims 1 to 8, wherein: the attributes of the transaction comprise an access restriction level (Sec, NS), an addressing mode restriction level (Priv, unPriv), and a program access prohibition level taken from among a first, a second and a third program access prohibition level (HDPL1, HDPL2, HDPL3); and the attributes of the sector comprise the access restriction level (Sec, NS), the addressing mode restriction level (Priv, unPriv), and a program access prohibition level taken from among a

10.

11.

12. fourth, fifth and sixth levels of program access prohibition (OB-HDP, HDP-EXT, non-HDP). The method of claim 9, wherein: a transaction having an attribute corresponding to a first access restriction level (Sec) can access a sector having the first or a second access restriction level (Sec, NS); a transaction having an attribute corresponding to a first addressing mode restriction level (Priv) can access a sector having a second addressing mode restriction level (unPriv); a transaction having an attribute corresponding to the second access restriction level (NS) cannot access a sector having the first access restriction level (Sec); and a transaction having an attribute corresponding to a second addressing mode restriction level (unPriv) cannot access a sector having the first addressing mode restriction level (Priv). A method according to any one of claims 9 to 10, wherein: a transaction having an attribute corresponding to a first program access prohibition level (HDPL1) can access a sector having as an attribute a fourth, a fifth or a sixth program access prohibition level (OB-HDP, HDP-EXT, non-HDP); a transaction having an attribute corresponding to a second program access prohibition level (HDPL2) can access a sector having as an attribute the fifth and sixth protection levels (HDP-EXT, non-HDP) but cannot access a sector having as an attribute the fourth program access prohibition level (OB-HDP); and a transaction having an attribute corresponding to a third program access prohibition level (HDPL3), can access a sector having as an attribute the sixth program access prohibition level (non-HDP) but cannot access a sector having as an attribute the fourth or fifth program access prohibition levels (OB-HDP, HDP-EXT). The method of claim 11, wherein the attributes of the memory sector are either the attributes of a previous transaction or default attributes defined by the first access restriction level (Sec), the second addressing mode restriction level (unPriv), and the fourth level of program access prohibition (OB-HDP).

13. A method according to any one of claims 1 to 12, wherein the configuration value corresponds to a cycling mode (HCD, power mode, user mode), a write protection mode (Write protection) or a write mode (write mode).

14. An electronic circuit (100), comprising a non-volatile memory interface (106) and a non-volatile memory (104), configured to implement the method according to any one of the preceding claims.

Citation Information

Patent Citations

  • Configurable Memory Protection

    US20080276051A1

  • Memory protection

    US20160299720A1

  • Protecting access to microcontroller memory blocks

    US6952778B1