Starting a memory
The method verifies and secures memory writes by ensuring non-sensitive data is the last group written, erasing sensitive data if found, and writing non-sensitive data to prevent unauthorized access due to power-down attacks.
Patent Information
- Application Number
- FR2024002336
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-08
- Publication Date
- 2025-09-12
AI Technical Summary
Existing memory writing methods lack security for sensitive data, fail to ensure complete erasure, and are vulnerable to power-down attacks, which can expose sensitive data.
A method for writing data to memory that includes verifying the last group of data written, ensuring it is non-sensitive, and if sensitive, erasing it, followed by writing non-sensitive reference data, with metadata checks to confirm correct writing and detect power-down attacks.
Ensures secure storage of sensitive data by detecting incomplete writes and power-down attacks, guaranteeing complete erasure of sensitive data, and preventing unauthorized access.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Starting a memory Technical field
[0001] The present description relates generally to electronic systems and devices, and more particularly to the storage of data by electronic systems and devices. The present description relates, more specifically, to a method of writing data into memory, and to an associated method of starting a memory. Prior art
[0002] It is very common to store data in a memory of an electronic system or device. When this data includes sensitive data, such as secret data, it is important to ensure that all steps related to the data writing and erasing process have been carried out.
[0003] It would be desirable to be able to improve, at least in part, certain aspects of the methods for storing data in memory. Summary of the invention
[0004] There is a need for more secure memory writing methods.
[0005] There is a need for methods of booting a memory that can check that the last write operation was completed correctly.
[0006] There is a need for methods of storing sensitive information that ensure efficient erasure of such data.
[0007] There is a need for memory boot methods that can detect a power-down attack.
[0008] There is a need for electronic devices implementing such methods.
[0009] One embodiment overcomes all or part of the drawbacks of known memory writing methods.
[0010] One embodiment overcomes all or part of the drawbacks of known memory startup methods.
[0011] One embodiment provides a method of writing a group of data to memory, wherein the last group of data written to memory comprises only non-sensitive data.
[0012] One embodiment provides a method for starting a memory in which it is checked whether the last group of data written to memory comprises at least one sensitive data item.
[0013] One embodiment provides a method for starting a memory in which if the last group of data written includes sensitive data, an operation for erasing the last copy of said group of data is implemented.
[0014] An embodiment further provides, after the implementation of an erasure operation during the startup method, the implementation of an operation of writing a group of data comprising only non-sensitive reference data following the last group of data written.
[0015] One embodiment provides a method for verifying the writing of data in a memory comprising the following successive steps: - check whether the last group of data written to memory includes at least one sensitive data item; - if said group includes at least one sensitive data item, delete a first group of data of which at least one address is indicated in at least one first metadata item of data from said last group of data.
[0016] Another embodiment provides an electronic device comprising a memory, adapted to implement a method for verifying the writing of data from said memory comprising the following successive steps: - check whether the last group of data written to memory includes at least one sensitive data item; - if said group includes at least one sensitive data item, delete a first group of data of which at least one address is indicated in at least one first metadata item of data from said last group of data.
[0017] According to one embodiment, the erasure step is followed by a step of writing a second group of data comprising only non-sensitive reference data.
[0018] According to one embodiment, if said group does not include any sensitive data, no erasure step is implemented.
[0019] According to one embodiment, said memory is a non-volatile memory.
[0020] According to one embodiment, each data item comprises a second metadata item indicating whether the data is sensitive or non-sensitive.
[0021] According to one embodiment, each data item comprises a third metadata item indicating the validity of said data item.
[0022] According to one embodiment, each data item comprises a fourth metadata item indicating whether the data item is the last data item in a data group.
[0023] According to one embodiment, the method for verifying the writing of data in said memory is implemented when said memory is started.
[0024] According to one embodiment, the method for verifying the writing of data in said memory is implemented before a phase of writing data in said memory.
[0025] According to one embodiment, the memory is a non-volatile memory.
[0026] According to one embodiment, each time data groups are written, the last The data group to be written includes only non-sensitive data.
[0027] Another embodiment provides a method of starting an electronic device comprising said memory comprising the starting method described above. Brief description of the drawings
[0028] These characteristics and advantages, as well as others, will be explained in detail in the following description of particular embodiments given without limitation in relation to the attached figures among which:
[0029] [Fig.l] represents, very schematically and in the form of blocks, an electronic device adapted to implement the modes of implementation described in relation to figures 2 to 4;
[0030] [Fig.2] represents, in the form of blocks, the structure of data to be stored in memory;
[0031] [Fig. 3] represents a block diagram illustrating a mode of implementation of a method of writing data to memory; and
[0032] [Fig.4] represents a block diagram illustrating a mode of implementation of a method for starting a memory. Description of the embodiments
[0033] The same elements have been designated by the same references in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same references and may have identical structural, dimensional and material properties.
[0034] For the sake of clarity, only the steps and elements useful for understanding the described embodiments have been shown and are detailed.
[0035] Unless otherwise specified, when referring to two elements connected to each other, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") to each other, this means that these two elements can be connected or be connected by means of one or more other elements.
[0036] In the following description, when referring to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., are used, unless otherwise specified, to refer to the orientation of the figures.
[0037] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "of the order of" mean to within 10%, preferably to within 5%.
[0038] The embodiments described below relate to the storage of data in memory, and more particularly, to a method of writing data in memory making it possible to detect an attack by power supply cutoff. More specifically, the present description relates to an embodiment of a method of writing groups of data in memory in which the last group of data written in memory only comprises non-sensitive data, i.e. does not comprise any sensitive data. The present description further relates to an embodiment of a method of starting a memory in which it is checked whether the last group of data written in memory is composed exclusively of non-sensitive data, and remedies this, optionally, if this is not the case.
[0039] Furthermore, the embodiments described below are particularly suitable for all types of applications using the storage of data in memory, and in particular the storage of sensitive and non-sensitive data in memory.
[0040] [Fig.l] is a block diagram representing, very schematically, an architecture of an example of an electronic device 100 adapted to implement a method of starting a memory.
[0041] The electronic device 100 comprises a processor 101 (CPU) adapted to implement different processing of data stored in memories and / or provided by other circuits of the device 100. According to one embodiment, the processor 101 is adapted to implement a method of starting a memory.
[0042] The electronic device 100 further comprises different types of memories 102 (MEM), including, for example, a non-volatile memory, a volatile memory, and / or a read-only memory. Each memory 102 is adapted to store different types of data. According to one embodiment, the device 100 comprises at least one non-volatile memory adapted to store sensitive data and non-sensitive data. According to a preferred embodiment, the memory 102 is a non-volatile memory.
[0043] The electronic device 100 further comprises, for example, a secure element 103 (SE) adapted to process sensitive and / or secret data. The secure element 103 may comprise its own processor(s), its own memory(s), etc. According to one embodiment, the secure element 101 is adapted to implement a method for starting a memory.
[0044] The electronic device 100 may further comprise interface circuits 104 (IN / OUT) adapted to send and / or receive data originating from outside the device 100. The interface circuits 104 may further be adapted to implement a data display, for example, a display screen.
[0045] The electronic device 100 further comprises different circuits 105 (FCT1) and 106 (FCT2) adapted to perform different functions. For example, the circuits 105 and 106 may comprise measurement circuits, data conversion circuits, etc. According to one embodiment, the circuits 105 and 106 may comprise a circuit adapted to implement a method for starting a memory.
[0046] The electronic device 100 further comprises one or more data buses 107 adapted to transfer data between its different components.
[0047] According to a particular example, the electronic device 100 is adapted to implement computer programs, and in particular a computer program making it possible to implement a method of starting a memory.
[0048] [Fig. 2] represents, very schematically and in the form of blocks, a data item 200 adapted to be stored in one of the memories 102 of the device 100 described in relation to [Fig. 1]. More particularly, the data item 200 is adapted to be stored in the non-volatile memory of the device 100. According to one embodiment, the memory 102 is a non-volatile memory.
[0049] According to one embodiment, the data 200 is composed of its content 201 (DATA) and metadata 202 (Metadata) making it possible to characterize the data 200.
[0050] The content 201 of the data 200 represents the actual information that the data 200 carries.
[0051] The metadata 202 comprises several metadata each representing a characteristic of the data 200. According to one example, each metadata of the metadata 202 is one or more bits of data.
[0052] According to one embodiment, the metadata 202 comprises an identification metadata 203 (Block ID) allowing a data manager to find all the copies of the same data item written in memory. In other words, all the copies of the same data item have the same addressing metadata 203. According to one embodiment, the addressing metadata 203 makes it possible, when writing the data item 200 in memory, to launch an operation to erase the previous copy(ies) of the data item 200 already written in memory. Other uses of the metadata 203 are within the reach of those skilled in the art. According to one example, the metadata 203 is a word of several data bits.
[0053] According to one example, the metadata 202 comprises a write verification metadata 204 (Checksum) which indicates whether the content 201 of the data item 200 has been written correctly. In other words, the metadata 204 can make it possible to verify whether the operation of writing the data item 200 has taken place and / or whether it has taken place correctly. This metadata 204 is always written at the end of the writing process in memory of data 200. In one example, metadata 204 is a word of multiple data bits. In another example, metadata 204 is a single data bit.
[0054] According to one example, the metadata 202 includes a write-end metadata 205 (Commit Bit) indicating whether the data 200 is the last data item in a group of data being written. Indeed, it is rare to write only one data item at a time to memory. It is more common to write data in groups to a memory. Thus, if the write-end metadata 205 indicates that the data 200 is the last data item in a group of data to be written, this means that all the other data in the group has been written to memory. According to one example, the metadata 205 is a single data bit.
[0055] According to one embodiment, the metadata 202 comprises a metadata 206 (Wipe Bit) indicating whether the data 200 is sensitive or non-sensitive data. Here, "sensitive data" refers to data whose content is not intended to be accessible to the public. According to one example, secret data is sensitive data. Thus, if the metadata 206 indicates that the data 200 is sensitive data, this means that the content 201 of the data 200 includes one or more sensitive information. Conversely, if the metadata 206 indicates that the data 200 is non-sensitive data, this means that the content 201 of the data 200 does not include any sensitive information. According to one example, the metadata 206 is a single bit of data.
[0056] It should be noted that, according to one embodiment, a group of data to be written into a memory may comprise sensitive data and / or non-sensitive data.
[0057] [Fig. 3] is a block diagram illustrating an exemplary method of writing groups of data to memory 300.
[0058] According to one embodiment, the method 300 relates to writing in a memory, of the type of a memory 102 of the device 100 described in relation to [Fig. 1], one or more groups of data of the type of data 200 described in relation to [Fig. 2],
[0059] In an initial step 301 (Write Frames), all the data of the data group(s) to be written are written into the memory. According to one example, the data of each data group are written sequentially into the memory, i.e. one at a time, and one after the other.
[0060] In a step 302 (Shred Copy), following step 301, the last copy of the group of data written in the memory is erased. For this, the addressing metadata 203 of the data are used. In other words, the data designated by the addresses of the addressing metadata 203 of the data of the group of data are all erased. According to one example, an erasure step may be an erasure step, that is to say a step of destruction of the written data, or perhaps a step of rewriting other data on the data already written.
[0061] A disadvantage of this memory writing method is that if a power-down attack is implemented between steps 301 and 302, old copies of sensitive data may not be deleted correctly. The startup method described in relation to [Fig.4] makes it possible to overcome this disadvantage.
[0062] [Fig.4] is a block diagram illustrating a mode of implementation of a method 400 for starting a memory in which groups of data have been written, of the type of data 200 described in relation to [Fig.2], using the method of writing to memory 300 described in relation to [Fig.3].
[0063] At an initial step 401 (Boot Mem), the memory is started. According to one embodiment, this memory is of the type of one of the memories 102 described in relation to [Fig.l], for example a non-volatile memory. This start-up step may be part of a method of starting a device comprising the memory, such as the device 100 of [Fig.l].
[0064] At a step 402 (Tearing?), following step 401, the memory, or an ancillary circuit, can implement a verification of the last group of data written in the memory to check whether this last writing step has been carried out in full and / or correctly. This step 402 makes it possible to check whether step 301 of [Fig.3] has been carried out correctly or not. For this, a metadata of the type of metadata 204 of the last written data can be verified. If this verification indicates a problem (output Y of block 402), a step 403 (Anti-tearing) is implemented, otherwise (output N of the block, a step 404 (Last Written Data) is implemented.
[0065] In step 403, it has been detected that the last write operation could not be carried out completely and / or correctly. An operation or a rewrite and / or data recovery operation may be implemented. Such operations are within the scope of the person skilled in the art. This step may either cancel the rest of the startup process, or may be followed by step 406 described below.
[0066] In step 404 (Last Written Data?), following step 402, it was verified that the last data written to memory was written correctly and / or in full. It is now verified whether or not the last group of data written to the memory includes sensitive data. Here, the term last group written to the memory refers to the last group of data that was written to the memory before it was stopped. In other words, the last group of data written to the memory is the group of data for which the write operation is the most recent. This last group can be indicated by the value of a metadata item of the type of metadata 205 described in relation to [Fig. 2], or be indicated by its place in the memory.
[0067] If the last group of data written includes only non-sensitive data (output NS of block 404), the next step is a step 405 (Run). If the last group of data written includes at least one sensitive data (output S of block 404), the next step is a step 406 (Shred Previous Copy).
[0068] In step 405, the last group of data written in the memory only comprises non-sensitive data, this indicates that the last operation of writing a group of data was carried out without incident. The memory can therefore be used, without carrying out other operations, and, in particular without carrying out other erasing operations beforehand.
[0069] In step 406, the last group of data written in the memory comprises at least one sensitive data item, this indicates that there is a risk that the last operation of writing groups of data in memory was stopped before being completed. This would therefore indicate that the operation of erasing the last copy of the groups of data written recently may not have been carried out. Thus, if necessary, an erasure operation of the type of operation 302 is implemented. In other words, the last copy of at least the last group of data written in the memory is erased, using for this the addressing metadata 203 of the data of the group. In other words, the data designated by the addresses of the metadata of the data of the last group of data written are all erased.
[0070] In an optional step 407 (Write Dummy), following step 406, a group of data comprising only non-sensitive reference data is written after the last group of data written before the memory is stopped. This makes it possible to avoid a new erasure operation if the memory is stopped again without any other data having been written following the data tested in step 404.
[0071] The step following step 407 is step 405. If step 407 does not take place, step 406 is followed by step 405.
[0072] An advantage of this embodiment is that it makes it possible to detect that a write operation has been stopped before being completed. More particularly, this startup method makes it possible to detect power-down attacks, which could, in this case, allow access to old copies of sensitive data that have not yet been erased.
[0073] Another advantage of this embodiment is that it guarantees the erasure of old copies of sensitive data even after a power outage.
[0074] As stated previously, the method of starting the memory can be integrated into a method of starting an electronic device comprising said memory.
[0075] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will occur to those skilled in the art. business. According to one example, the verification step 404 of the method 400 may further comprise a verification of the verification metadata 204 of the last data written in the memory.
[0076] Furthermore, it should be noted that the startup method can also be implemented, not at the time of memory startup, but before a phase of writing data to memory. In this case, we speak rather of a write verification method.
[0077] Finally, the practical implementation of the embodiments and variants described is within the reach of those skilled in the art from the functional indications given above.
Claims
Claims
1. Method for verifying the writing of data in a memory (102) comprising the following successive steps: - verifying (404) whether the last group of data (200) written in the memory (102) comprises at least one sensitive data item; - if said group comprises at least one sensitive data item, erasing (406) a first group of data of which at least one address is indicated in at least one first metadata item (203) of a data item (200) of said last group of data.
2. Method according to claim 1, in which the erasing step (406) is followed by a writing step (407) of a second group of data comprising only non-sensitive reference data.
3. A method according to claim 1 or 2, wherein if said group does not include any sensitive data, no erasure step is performed.
4. A method according to any one of claims 1 to 3, wherein said memory (102) is a non-volatile memory.
5. A method according to any one of claims 1 to 4, wherein each data item (200) comprises a second metadata item (206) indicating whether the data item is sensitive or non-sensitive.
6. Method according to any one of claims 1 to 5, in which each data (200) comprises a third metadata (204) indicating the validity of said data (200).
7. Method according to any one of claims 1 to 6, in which each data (200) comprises a fourth metadata (205) indicating whether the data (200) is a last data of a group of data.
8. A method according to any one of claims 1 to 7, wherein the method of verifying writing of data in said memory is implemented at startup of said memory.
9. Method according to any one of claims 1 to 7, wherein the method of verifying writing of data in said memory is implemented before a phase of writing data in said memory.
10. A method according to any one of claims 1 to 9, wherein the memory is a non-volatile memory.
11. A method of writing (300) to a memory (102), comprising the write verification method according to any one of claims 1 to 10, wherein at each writing of groups of data, the last group of data to be written comprises only non-sensitive data.
12. A method of starting an electronic device (100) comprising a memory (102) comprising the write verification method according to any one of claims 1 to 10.
13. Electronic device (100) comprising a memory (102), adapted to implement a method for verifying the writing of data from said memory (102) comprising the following successive steps: - verifying (404) whether the last group of data (200) written in the memory (102) comprises at least one sensitive data item; - if said group comprises at least one sensitive data item, erasing (406) a first group of data of which at least one address is indicated in at least one first metadata item (203) of a data item (200) of said last group of data.
Citation Information
Patent Citations
Dynamic encryption method based on FPGA and control card
CN116186706A
File management method and files
US20010047447A1
Sensitive data protection
US9614826B1