Semiconductor integrated circuit device

The semiconductor integrated circuit device addresses security vulnerabilities by allowing release data input through a unique protocol, enhancing access control and bit length flexibility without emulator dependence, thereby improving security against brute-force attacks.

JP2025098735APending Publication Date: 2025-07-02ROHM CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023215068
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-20
Publication Date
2025-07-02

AI Technical Summary

Technical Problem

Existing semiconductor integrated circuit devices face security vulnerabilities due to brute-force decoding of fixed-length collation data, allowing unauthorized access, and require emulator-specific modifications to enhance security, which is challenging for independent circuit changes.

Method used

A semiconductor integrated circuit device with a central processing circuit, non-volatile memory, and a release data input interface circuit that allows input of release data using a unique communication protocol, enabling access control without relying on an emulator interface circuit, and optionally includes a release data arithmetic circuit to convert data bit lengths.

Benefits of technology

Enhances security by allowing input of release data without emulator dependence, enabling flexible bit length adjustments and improved access control, thus strengthening protection against unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025098735000001_ABST
    Figure 2025098735000001_ABST
Patent Text Reader

Abstract

To provide a semiconductor integrated circuit device that enables inputting release data for external control of the semiconductor integrated circuit device without relying on an emulator interface circuit.SOLUTION: A semiconductor integrated circuit device 100 includes: a central processing circuit 110; a non-volatile memory 111 that stores software programs and verification data; an emulator interface circuit 112 that transmits and receives data between an emulator 130 and the central processing circuit 110 and the non-volatile memory 111; a release data input interface circuit 116 that requests and receives release data; and a comparison circuit 118 that, when the release data input via the release data input interface circuit 116 is compared with the verification data and found to match, permits the emulator interface circuit 112 about access of the emulator 130 to the central processing circuit 110 and the non-volatile memory 111.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a semiconductor integrated circuit device, and more particularly to an integrated circuit including a central processing circuit and a semiconductor integrated circuit device having a security function for protecting a software program from unauthorized acts.

Background Art

[0002] A semiconductor integrated circuit device equipped with a central processing circuit and a non-volatile memory can be connected to an emulator for the purpose of emulating or debugging the operation of a software program stored in the non-volatile memory. In such a semiconductor integrated circuit device, communication with the central processing circuit and the non-volatile memory is permitted only when the input data input from the emulator matches the reference data stored in the non-volatile memory.

[0003] For example, Patent Document 1 below discloses a protection device having an input means for inputting collation data, a reading means for reading reference data from a memory, a comparing means for comparing the collation data and the reference data, and a releasing means for releasing the security lock of the microcomputer according to the comparison result.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, in the invention described in Patent Document 1 above, if a brute-force decoding attempt is made against reference data of a fixed bit length, it will eventually match the reference data. For example, when the bit length of the collation data is N bits, 2 NBy attempting to input combinations, eventually, it will match the reference data, and it will be possible to release the security lock. Therefore, in the case of the protection device of the invention described in Patent Document 1 above, there is a risk that the security may be breached in a relatively short time.

[0006] To enhance the security strength, a method such as expanding the bit length of the collation data to be input can be considered. However, in order to expand the bit length of the collation data to be input, it is necessary to change the firmware that operates the emulator, and it has not been easy to freely perform circuit modifications for the purpose of enhancing security without depending on the specifications of the emulator.

[0007] In view of the above circumstances, an object of the present invention is to provide a semiconductor integrated circuit device that enables input of release data for making the semiconductor integrated circuit device controllable from the outside without depending on an emulator interface circuit.

Means for Solving the Problems

[0008] To solve the above problems, a semiconductor integrated circuit device according to the present invention includes a central processing circuit, a non-volatile memory that stores a software program and collation data, an emulator that performs trial and analysis of the operation of the software program in the central processing circuit, an emulator interface circuit that transmits and receives data between the central processing circuit and the non-volatile memory, a release data input interface circuit that requests and receives release data, and a comparison circuit that compares the release data input via the release data input interface circuit with the collation data and, when they match, permits the emulator to access the central processing circuit and the non-volatile memory with respect to the emulator interface circuit.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Embodiments for Carrying Out the Invention

[0010] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.

[0011] [Comparative Example] First, the semiconductor integrated circuit device 500 of the comparative example will be described with reference to FIG. 1. The semiconductor integrated circuit device 500 of the comparative example includes a central processing unit (CPU) 510 and a non-volatile memory 511. A software program (not shown) executed by the central processing unit 510 is stored in the non-volatile memory 511. Also, verification data is stored at a specific address in the non-volatile memory 511.

[0012] The semiconductor integrated circuit device 500 also includes an emulator interface circuit 512, a CPU interface circuit 513, a non-volatile memory interface circuit 514, a verification data storage buffer 515, a release data storage buffer 516, and a comparison circuit 517.

[0013] The emulator interface circuit 512 performs data transmission and reception between the emulator 520 and the central processing unit 510 via the CPU interface circuit 513, and data transmission and reception between the emulator interface circuit 512 and the non-volatile memory 511 via the non-volatile memory interface circuit 514.

[0014] The CPU interface circuit 513 permits or prohibits data transmission and reception between the emulator interface circuit 512 and the central processing unit 510 in response to an instruction from the comparison circuit 517. The non-volatile memory interface circuit 514 permits or prohibits data transmission and reception between the emulator interface circuit 512 and the non-volatile memory 511 in response to an instruction from the comparison circuit 517.

[0015] The verification data storage buffer 515 stores the verification data read from the non-volatile memory 511 by the non-volatile memory interface circuit 514. The release data storage buffer 516 stores the release data input from the emulator 520 via the emulator interface circuit 512. The comparison circuit 517 compares the verification data stored in the verification data storage buffer 515 with the release data stored in the release data storage buffer 516. When the verification data and the release data do not match as a result of the comparison, the comparison circuit 517 outputs a prohibition signal to the CPU interface circuit 513 and the non-volatile memory interface circuit 514. On the other hand, when the verification data and the release data match as a result of the comparison, the comparison circuit 517 outputs a permission signal to the CPU interface circuit 513 and the non-volatile memory interface circuit 514.

[0016] The semiconductor integrated circuit device 500 further includes an input buffer 518 and an output buffer 519, which transmit and receive data between the emulator 520 and the emulator interface circuit 512.

[0017] Next, the operation of the semiconductor integrated circuit device 500 of the above comparative example will be described. When the semiconductor integrated circuit device 500 is activated, during the initialization sequence until the central processing circuit 510 is activated, the non-volatile memory interface circuit 514 reads the verification data from the non-volatile memory 511 and stores it in the verification data storage buffer 515.

[0018] When the emulator 520 is connected to the semiconductor integrated circuit device 500, the emulator interface circuit 512 communicates with the emulator 520 according to a predetermined protocol via the input buffer 518 and the output buffer 519, and recognizes that the emulator 520 is connected. Next, the emulator interface circuit 512 requests the emulator 520 to input release data.

[0019] In response to this, the emulator 520 requests the user to input release data. When the release data is input to the emulator 520, the emulator 520 transmits the release data to the emulator interface circuit 512 via the input buffer 518. The emulator interface circuit 512 stores the release data in the release data storage buffer 516.

[0020] The comparison circuit 517 compares the verification data stored in the verification data storage buffer 515 with the release data stored in the release data storage buffer 516. When both match, the comparison circuit 517 outputs a permission signal to the CPU interface circuit 513 and the non-volatile memory interface circuit 514. In response to this permission signal, the CPU interface circuit 513 permits communication between the central processing circuit 510 and the emulator interface circuit 512. Also, in response to the above permission signal, the non-volatile memory interface circuit 514 permits communication between the non-volatile memory 511 and the emulator interface circuit 512.

[0021] As a result, the emulator 520 can execute control of software programs by the central processing circuit 510, trace, monitor the software programs being executed, read, write, rewrite data in the non-volatile memory 511, etc.

[0022] However, in the semiconductor integrated circuit device 500 of the above comparative example, the emulator 520 and the emulator interface circuit 512 had to communicate using a specific communication protocol depending on the specifications of the semiconductor integrated circuit device 500 and the emulator 520. Also, after recognizing the connection of the emulator, the emulator interface circuit 512 had to receive release data of a fixed length, for example, a fixed bit length, depending on the specifications of the semiconductor integrated circuit device 500 and the emulator 520.

[0023] Therefore, when attempting to identify by brute force for fixed-length verification data, when the bit length of the verification data is N bits, 2N If the input of the combination is tried, it may match the verification data at some point, and there was a risk that the verification data would be identified in a relatively short time.

[0024] To enhance security strength, there are methods such as expanding the bit lengths of the release data and the verification data. However, in that case, circuit modifications are required to expand the bit lengths of the release data and the verification data in the emulator interface circuit 512, the verification data storage buffer 515, the release data storage buffer 516, and the comparison circuit 517. Also, it is necessary to modify the firmware that operates the emulator 520 to accommodate the expanded release data. Modifying the emulator 520 is only possible for the company that develops the emulator 520 and cannot be done independently by the company that develops the semiconductor integrated circuit device 500.

[0025] [Embodiment 1] Next, with reference to FIG. 2, the semiconductor integrated circuit device 100 according to Embodiment 1 will be described. The semiconductor integrated circuit device 100 of Embodiment 1 includes a central processing unit (CPU) 110 and a non-volatile memory 111. The non-volatile memory 111 stores a software program (not shown) executed by the central processing unit 110 and verification data. The verification data is stored at a specific address in the non-volatile memory 111.

[0026] The semiconductor integrated circuit device 100 also includes an emulator interface circuit 112, a CPU interface circuit 113, a non-volatile memory interface circuit 114, and a verification data storage buffer 115. Further, the semiconductor integrated circuit device 100 includes a release data input interface circuit 116, a release data storage buffer 117, and a comparison circuit 118.

[0027] The semiconductor integrated circuit device 100 further includes an input buffer 119 for the emulator, an output buffer 120 for the emulator, an input buffer 121 for the release data input device, and an output buffer 122 for the release data input device.

[0028] The emulator interface circuit 112 performs data transmission and reception between an emulator 130 that tries and analyzes the operations in the central processing circuit 110 of a software program, the central processing circuit 110, and the non-volatile memory 111. Specifically, the emulator interface circuit 112 performs data transmission and reception between the emulator 130 and the central processing circuit 110 via the CPU interface circuit 113. Further, the emulator interface circuit 112 performs data transmission and reception between the emulator 130 and the non-volatile memory 111 via the non-volatile memory interface circuit 114. The emulator interface circuit 112 performs data transmission and reception with the emulator 130 using a communication protocol unique to the emulator rather than a general-purpose communication method.

[0029] The CPU interface circuit 113 permits or prohibits data transmission and reception between the emulator interface circuit 112 and the central processing circuit 110 according to an enable signal or a disable signal from the comparison circuit 118. The non-volatile memory interface circuit 114 permits or prohibits data transmission and reception between the emulator interface circuit 112 and the non-volatile memory 111 according to an enable signal or a disable signal from the comparison circuit 118.

[0030] The verification data storage buffer 115 stores verification data read from the non-volatile memory 111 by the non-volatile memory interface circuit 114.

[0031] The release data input interface circuit 116 requests and receives release data from the release data input device 140 described later. The release data input interface circuit 116 performs data transmission and reception with the release data input device 140 using a serial communication protocol. Examples of the serial communication protocol to be used include UART (Universal Asynchronous Receiver / Transmitter), SPI (Serial Peripheral Interface), I2C (Inter-Integrated Circuit), and the like. Note that the communication protocol used by the release data input interface circuit 116 is different from the unique communication protocol used by the emulator interface circuit 112.

[0032] Alternatively, the release data input interface circuit 116 may be configured using the general-purpose input / output interface (GPIO: General Purpose Input / Output) mounted on the semiconductor integrated circuit device 100. That is, data transmission and reception with the release data input device 140 can be performed by any method using an existing communication method such as a serial communication method or a parallel communication method using the general-purpose input / output interface.

[0033] The release data storage buffer 117 stores the release data input from the release data input device 140 via the release data input interface circuit 116. Note that the release data storage buffer 117 may be a register, a FIFO (First In First Out) memory mounted on the release data input interface circuit 116, or a general-purpose memory (RAM) provided inside the semiconductor integrated circuit device 100.

[0034] The comparison circuit 118 compares the release data input and stored in the release data storage buffer 117 via the release data input interface circuit 116 with the verification data stored in the verification data storage buffer 115. As a result of the comparison, if the release data and the verification data do not match, the comparison circuit 118 performs the following operations. That is, the comparison circuit 118 outputs a prohibition signal to the CPU interface circuit 113, the non-volatile memory interface circuit 114, the emulator input buffer 119, and the emulator output buffer 120.

[0035] On the other hand, as a result of the comparison, if the release data and the verification data match, the comparison circuit 118 permits the emulator 130 to access the central processing unit circuit 110 and the non-volatile memory 111 via the emulator interface circuit 112. Specifically, the comparison circuit 118 outputs a permission signal to the CPU interface circuit 113, the non-volatile memory interface circuit 114, the emulator input buffer 119, and the emulator output buffer 120.

[0036] The emulator input buffer 119 and the emulator output buffer 120 transmit and receive data between the emulator 130 and the emulator interface circuit 112, and permit or prohibit the transmission and reception according to the permission signal or the prohibition signal from the comparison circuit 118. That is, when the comparison circuit 118 does not permit the emulator 130 to access the central processing unit circuit 110 and the non-volatile memory 111, the communication in the emulator input buffer 119 and the emulator output buffer 120 is invalidated according to the prohibition signal. On the other hand, when the comparison circuit 118 permits the emulator 130 to access the central processing unit circuit 110 and the non-volatile memory 111, the communication in the emulator input buffer 119 and the emulator output buffer 120 is validated according to the permission signal.

[0037] The input buffer 121 for the release data input device and the output buffer 122 for the release data input device perform data transmission and reception between the release data input device 140 and the release data input interface circuit 116.

[0038] Next, the operation of the semiconductor integrated circuit device 100 of Embodiment 1 will be described. When the semiconductor integrated circuit device 100 is activated, during the initialization sequence until the central processing circuit 110 is activated, the non-volatile memory interface circuit 114 reads the verification data from the non-volatile memory 111 and stores it in the verification data storage buffer 115.

[0039] Also, the comparison circuit 118 outputs a prohibition signal to the CPU interface circuit 113, the non-volatile memory interface circuit 114, the input buffer 119 for the emulator, and the output buffer 120 for the emulator. Therefore, even if the emulator 130 is connected to the semiconductor integrated circuit device 100, data input and output via the input buffer 119 for the emulator and the output buffer 120 for the emulator cannot be performed. As a result, communication between the emulator 130 and the emulator interface circuit 112 is in a state where it cannot be established.

[0040] When the release data input device 140 is connected to the semiconductor integrated circuit device 100, the release data input interface circuit 116 communicates with the release data input device 140 via the input buffer 121 for the release data input device and the output buffer 122 for the release data input device. When recognizing that the release data input device 140 is connected, the release data input interface circuit 116 requests the input of release data from the release data input device 140.

[0041] Upon receiving this, the unlocking data input device 140 requests the user to input unlocking data. When the unlocking data is input to the unlocking data input device 140, the unlocking data input device 140 transmits the unlocking data to the unlocking data input interface circuit 116 via the input buffer 121 for the unlocking data input device. The unlocking data input interface circuit 116 stores the unlocking data in the unlocking data storage buffer 117.

[0042] The comparison circuit 118 compares the verification data stored in the verification data storage buffer 115 with the unlocking data stored in the unlocking data storage buffer 117. If they do not match, the comparison circuit 118 outputs a prohibition signal to the CPU interface circuit 113, the non-volatile memory interface circuit 114, the input buffer 119 for the emulator, and the output buffer 120 for the emulator. Therefore, communication between the emulator 130 and the emulator interface circuit 112 cannot be performed.

[0043] On the other hand, assume that the verification data stored in the verification data storage buffer 115 matches the unlocking data stored in the unlocking data storage buffer 117. In that case, the comparison circuit 118 outputs a permission signal to the CPU interface circuit 113, the non-volatile memory interface circuit 114, the input buffer 119 for the emulator, and the output buffer 120 for the emulator.

[0044] Upon receiving this permission signal, the input buffer 119 for the emulator and the output buffer 120 for the emulator permit communication between the emulator 130 and the emulator interface circuit 112. Also, upon receiving the above permission signal, the CPU interface circuit 113 permits communication between the central processing circuit 110 and the emulator interface circuit 112. Furthermore, upon receiving the above permission signal, the non-volatile memory interface circuit 114 permits communication between the non-volatile memory 111 and the emulator interface circuit 112.

[0045] As a result, the emulator 130 can execute control of the software program by the central arithmetic processing circuit 110, trace, monitor the software program during execution, read, write, rewrite data in the non-volatile memory 111, and so on.

[0046] According to the semiconductor integrated circuit device 100 of the first embodiment, release data for making the semiconductor integrated circuit device 100 controllable from the outside can be input without depending on the emulator 130 and the emulator interface circuit 112. That is, the release data input device 140 can input release data to the release data input interface circuit 116 using a communication protocol different from the communication protocol determined by the specifications of the emulator 130. That is, it is possible to make the communication protocol of the emulator interface circuit 112 different from the communication protocol of the release data input interface circuit 116. Also, it is possible to change the bit length of the verification data without depending on the specifications determined by the company that develops the emulator 130.

[0047] [Embodiment 2] Next, with reference to FIG. 3, the semiconductor integrated circuit device 100A according to the second embodiment will be described. The semiconductor integrated circuit device 100A of the second embodiment is different from the semiconductor integrated circuit device 100 of the first embodiment in that conversion key data is stored in the non-volatile memory 111A and that it has a release data arithmetic circuit 123A, but the other configurations are substantially the same. Therefore, in the semiconductor integrated circuit device 100A of the second embodiment, for the components similar to those of the semiconductor integrated circuit device 100 of the first embodiment, the symbol "A" is added to the same reference numerals, and the detailed description thereof is omitted.

[0048] The release data arithmetic circuit 123A of the second embodiment converts the release data input via the release data input interface circuit 116A into converted data by performing a predetermined operation on the release data.

[0049] For example, the decryption data calculation circuit 123A converts the converted key data read from the non-volatile memory 111A into post-conversion data. Specifically, the decryption data calculation circuit 123A converts decryption data with a relatively large bit length such as 256 bits into post-conversion data with a relatively short bit length such as 8 bits using the conversion key data. More specifically, the decryption data calculation circuit 123A uses a message authentication code algorithm such as CMAC (Cipher-based Message Authentication Code) to convert the decryption data into post-conversion data that is a message authentication code. Alternatively, the decryption data calculation circuit 123A may use a predetermined hash function to convert the decryption data into post-conversion data that is a hash value. Note that when using a hash function, conversion key data is not required.

[0050] The decryption data calculation circuit 123A may be configured to select whether to convert the decryption data into post-conversion data using a message authentication code algorithm or using a hash function. When using a message authentication code algorithm, the conversion key data is read from the non-volatile memory 111A, and the decryption data is converted into post-conversion data using the conversion key data. On the other hand, when using a hash function, the decryption data is converted into post-conversion data using a preset hash function.

[0051] Next, the operation of the semiconductor integrated circuit device 100A of the second embodiment will be described. When the semiconductor integrated circuit device 100A is activated, during the initialization sequence until the central processing unit circuit 110A is activated, the non-volatile memory interface circuit 114A reads the verification data from the non-volatile memory 111A and stores it in the verification data storage buffer 115A. Also, the decryption data calculation circuit 123A reads and stores the conversion key data from the non-volatile memory 111A.

[0052] Further, the comparison circuit 118A outputs a prohibition signal to the CPU interface circuit 113A, the non-volatile memory interface circuit 114A, the input buffer 119A for emulator, and the output buffer 120A for emulator. Therefore, even if the emulator 130A is connected to the semiconductor integrated circuit device 100A, data cannot be input or output via the input buffer 119A for emulator and the output buffer 120A for emulator. As a result, communication between the emulator 130A and the emulator interface circuit 112A cannot be established.

[0053] When the release data input device 140A is connected to the semiconductor integrated circuit device 100A, the following operations are performed. That is, the release data input interface circuit 116A communicates with the release data input device 140A via the input buffer 121A for release data input device and the output buffer 122A for release data input device. When recognizing that the release data input device 140A is connected, the release data input interface circuit 116A requests the input of release data from the release data input device 140A.

[0054] In response to this, the release data input device 140A requests the user to input release data. When the release data is input to the release data input device 140A, the release data input device 140A transmits the release data to the release data input interface circuit 116A via the input buffer 121A for release data input device. The release data input interface circuit 116A outputs the release data to the release data arithmetic circuit 123A. The release data arithmetic circuit 123A converts the release data into converted data using the conversion key data read from the non-volatile memory 111A, and stores the converted data in the release data storage buffer 117A.

[0055] The comparison circuit 118A compares the verification data stored in the verification data storage buffer 115A with the converted data stored in the release data storage buffer 117A. When the two do not match, the comparison circuit 118A outputs a prohibition signal to the CPU interface circuit 113A, the non-volatile memory interface circuit 114A, the emulator input buffer 119A, and the emulator output buffer 120A. Therefore, communication between the emulator 130A and the emulator interface circuit 112A cannot be performed.

[0056] On the other hand, assume that the verification data stored in the verification data storage buffer 115A matches the converted data stored in the release data storage buffer 117A. In this case, the comparison circuit 118A outputs a permission signal to the CPU interface circuit 113A, the non-volatile memory interface circuit 114A, the emulator input buffer 119A, and the emulator output buffer 120A.

[0057] Receiving this permission signal, the emulator input buffer 119A and the emulator output buffer 120A permit communication between the emulator 130A and the emulator interface circuit 112A. Also, receiving the above permission signal, the CPU interface circuit 113A permits communication between the central processing circuit 110A and the emulator interface circuit 112A. Further, receiving the above permission signal, the non-volatile memory interface circuit 114A permits communication between the non-volatile memory 111A and the emulator interface circuit 112A.

[0058] Thereby, the emulator 130A can execute control of software programs by the central processing circuit 110A, trace, monitor the software programs being executed, read, write, rewrite data in the non-volatile memory 111A, etc.

[0059] According to the semiconductor integrated circuit device 100A of the above-described Embodiment 2, since it has the release data arithmetic circuit 123A, it is possible to make the bit length of the release data input from the release data input device 140A different from the bit length of the collation data. That is, a developer who manufactures the semiconductor integrated circuit device 100A can increase only the bit length of the release data without changing the bit length of the collation data. As a result, without changing the circuit of the semiconductor integrated circuit device 100A, it is possible to increase the bit length of the release data input from the release data input device 140A, and it becomes easy to increase the security strength.

[0060] In addition, in the above-described Embodiments 1 and 2, the case where the comparison circuits 118 and 118A output a prohibition signal and a permission signal to each of the emulator input buffers 119 and 119A and the emulator output buffers 120 and 120A has been described. In addition to that, the comparison circuits 118 and 118A of the above-described Embodiments 1 and 2 also output a prohibition signal and a permission signal to the CPU interface circuits 113 and 113A and the non-volatile memory interface circuits 114 and 114A. However, the present disclosure is not limited to the above configuration. The comparison circuits 118 and 118A may output a prohibition signal and a permission signal only to the emulator input buffers 119 and 119A and the emulator output buffers 120 and 120A. In that case, communication between the emulator 130, 130A and the emulator interface circuits 112, 112A is enabled or disabled according to the prohibition signal and the permission signal.

[0061] Further, the comparison circuits 118 and 118A may output a prohibition signal and a permission signal to one of the emulator input buffers 119 and 119A and the emulator output buffers 120 and 120A. In that case, in addition to the above configuration, the comparison circuits 118 and 118A are configured to output a prohibition signal and a permission signal to the CPU interface circuits 113 and 113A and the non-volatile memory interface circuits 114 and 114A.

Description of Reference Numerals

[0062] 100, 100A Semiconductor integrated circuit device 110, 110A Central processing circuit 111, 111A Non-volatile memory 112, 112A Emulator interface circuit 113, 113A CPU interface circuit 114, 114A Non-volatile memory interface circuit 115, 115A Verification data storage buffer 116, 116A Release data input interface circuit 117, 117A Release data storage buffer 118, 118A Comparison circuit 119, 119A Input buffer for emulator 120, 120A Output buffer for emulator 121, 121A Input buffer for release data input device 122, 122A Output buffer for release data input device 123A Release data arithmetic circuit 130, 130A Emulator 140, 140A Release data input device 500 Semiconductor integrated circuit device 510 Central processing circuit 511 Non-volatile memory 512 Emulator interface circuit 513 CPU interface circuit 514 Non-volatile memory interface circuit 515 Verification data storage buffer 516 Release data storage buffer 517 Comparison circuit 518 Input buffer 519 Output buffer 520 Emulator

Claims

1. A central processing circuit, A non-volatile memory for storing a software program and verification data, An emulator for trial and analysis of the operation of the software program in the central processing circuit, and an emulator interface circuit for transmitting and receiving data between the central processing circuit and the non-volatile memory, A release data input interface circuit for requesting and receiving release data, A comparison circuit that permits the emulator to access the central processing circuit and the non-volatile memory via the emulator interface circuit when the release data input via the release data input interface circuit or the converted data calculated from the release data matches the verification data. A semiconductor integrated circuit device comprising:

2. The emulator interface circuit is connected to at least one of an input buffer to which a signal from the emulator is input and an output buffer for outputting a signal to the emulator, When the comparison circuit does not permit access to the central processing circuit and the non-volatile memory via the emulator interface circuit, communication in the input buffer and the output buffer is invalidated, When the comparison circuit permits access to the central processing circuit and the non-volatile memory via the emulator interface circuit, communication in the input buffer and the output buffer is validated. The semiconductor integrated circuit device according to claim 1.

3. The semiconductor integrated circuit device according to claim 1, wherein the communication protocol of the emulator interface circuit is different from the communication protocol of the release data input interface circuit.

4. Further comprising a release data calculation circuit, The release data is converted into the converted data, which is a message authentication code, by the release data calculation circuit, The comparison circuit permits the emulator to access the central processing circuit and the non-volatile memory via the emulator interface circuit when the converted data matches the verification data. The semiconductor integrated circuit device according to claim 1.

5. The semiconductor integrated circuit device according to claim 4, wherein the release data calculation circuit converts the release data into the converted data, which is a message authentication code, using a message authentication code algorithm.

6. The release data calculation circuit converts the release data into the converted data which is a hash value using a hash function, the semiconductor integrated circuit device according to claim 4.

7. The release data calculation circuit selects whether to convert the release data into the converted data which is a message authentication code using a message authentication code algorithm or to convert the release data into the converted data which is a hash value using a hash function. When using the message authentication code algorithm, convert key data is read from the non-volatile memory, and the release data is converted into the converted data using the read convert key data. When using the hash function, the release data is converted into the converted data using a preset hash function, the semiconductor integrated circuit device according to claim 4.

8. The bit length of the verification data is shorter than the bit length of the release data input via the release data input interface circuit, the semiconductor integrated circuit device according to any one of claims 4 to 7.

Citation Information

Patent Citations

  • Security protecting device

    JP2007094632A