Semiconductor device

A semiconductor device with access prohibited areas and a checksum validation system addresses the cost issue by securely masking unauthorized access, maintaining security without additional costly measures.

JP2025108252APending Publication Date: 2025-07-23ROHM CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024002062
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-10
Publication Date
2025-07-23

AI Technical Summary

Technical Problem

Existing semiconductor devices face increased development costs due to the need for additional security measures, such as IP and special memory controllers, to prevent security information leakage when memory controller failures occur.

Method used

Incorporating a memory with multiple access prohibited areas storing unique device information, a memory controller, an address decoder, and a checksum calculation and comparison system to validate the integrity of data access, masking unauthorized attempts.

Benefits of technology

This approach effectively prevents unauthorized access to sensitive information without significantly increasing development costs, ensuring secure operation by blocking access to prohibited areas.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025108252000001_ABST
    Figure 2025108252000001_ABST
Patent Text Reader

Abstract

To provide a semiconductor device that suppresses increases in development costs and other expenses associated with the semiconductor device.SOLUTION: The semiconductor device includes a memory having a plurality of access-prohibited regions (the first to the Nth, where N is a natural number of 1 or greater) for storing information specific to the semiconductor device, a memory controller for controlling the memory, an address decoder for selecting a device to be accessed on the basis of instructions from the memory controller, a first calculation unit that calculates a checksum of the address value corresponding to each of the multiple access-prohibited regions and the data recorded in the multiple access-prohibited regions, multiple storage units that store the address value, data, and checksum, and a comparison unit that compares the checksum stored in each of the multiple storage units with an expected checksum value, and if the checksum matches the expected value, outputs a determination result indicating that the checksum matches the expected value to the address decoder. The address decoder masks the address on the basis of the determination result.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a semiconductor device.

Background Art

[0002] Patent Document 1 discloses a semiconductor device including a memory, a memory controller, and a processor.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Here, when a failure or the like occurs in the memory controller and the memory access prohibited area can be confirmed from the common data bus, security information (chip-specific information, product information, etc.) may leak. For this reason, in the prior art, as a countermeasure when a failure occurs in the memory controller, attempts have been made to introduce an IP (Internet Protocol) for improving the security of the system and to develop a special memory controller. Therefore, in the prior art, there is a possibility of increasing the development cost of the semiconductor device.

[0005] Based on the above circumstances, an object of the present disclosure is to provide a semiconductor device that suppresses an increase in the development cost of the semiconductor device.

Means for Solving the Problems

[0006] To solve the above problems, a semiconductor device according to the present disclosure includes a memory having a plurality of access prohibited areas from the first to the Nth (N is a natural number of 1 or more) that store unique information of the semiconductor device, a memory controller that controls the memory, an address decoder that selects a device to be accessed based on an instruction from the memory controller, a first calculation unit that calculates a checksum of values of addresses corresponding to each of the plurality of access prohibited areas and data recorded in the plurality of access prohibited areas, a plurality of holding units that hold the address values, the data, and the checksum, and a comparison unit that compares the checksum held in each of the plurality of holding units with an expected value of the checksum and outputs a determination result indicating that they match to the address decoder when the checksum matches the expected value. The address decoder masks the address based on the determination result.

[0007] To solve the above problems, a semiconductor device according to the present disclosure includes a memory having a plurality of access prohibited regions from the first to the Nth (N is a natural number of 1 or more) that store unique information of the semiconductor device, a memory controller that controls the memory, an address decoder that selects a device to be accessed based on an instruction from the memory controller, a value of an address corresponding to each of the plurality of access prohibited regions, and a first calculation unit that calculates a checksum of the data recorded in the plurality of access prohibited regions, a first holding unit that holds the checksum calculated by the first calculation unit corresponding to the value of the address corresponding to the first access prohibited region and the data recorded in the first access prohibited region, a second calculation unit that calculates a checksum based on the checksum held in the first holding unit, the value of the address corresponding to the second access prohibited region, and the checksum calculated by the first calculation unit corresponding to the data recorded in the second access prohibited region, a second holding unit that holds the checksum calculated by the second calculation unit, a third calculation unit that calculates a checksum based on the checksum held in the second holding unit, the value of the address corresponding to the third access prohibited region, and the checksum calculated by the first calculation unit corresponding to the data recorded in the third access prohibited region, a third holding unit that holds the checksum calculated by the third calculation unit, and a comparison unit that compares the checksum held in the third holding unit with an expected value corresponding to a specific read order of the first to the Nth data recorded in the plurality of access prohibited regions, and outputs a determination result indicating the match to the address decoder when the checksum matches the expected value. The address decoder masks the address based on the determination result.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Embodiments for Carrying Out the Invention

[0009] Hereinafter, embodiments will be described with reference to the drawings. In addition, the same or similar reference numerals are given to the same functions and configurations, and the description thereof will be omitted as appropriate.

[0010] (Embodiment) FIG. 1 is a diagram showing a configuration example of a semiconductor device according to an embodiment of the present disclosure. The semiconductor device 100 may include a program counter 1, a memory controller 2, an address decoder 3, a memory 4, a first calculation unit 5, and a determination result output circuit 6.

[0011] The program counter 1 may be interpreted as an address register that holds the address (location) on the memory 4 where the instruction to be executed is stored.

[0012] The memory controller 2 may be interpreted as a circuit that controls the memory 4. The memory controller 2 may perform operations such as writing data to the memory 4 and reading data from the memory 4.

[0013] The address decoder 3 may be interpreted as a circuit that selects the device to be accessed based on an instruction from the memory controller 2. Specifically, the address decoder 3 may be interpreted as a circuit that selectively drives the memory 4 and the like based on the input address signal.

[0014] The memory 4 may be interpreted as a non-volatile memory. The memory 4 may include first to Nth (N is a natural number of 1 or more) access prohibited regions 41 that store unique information of the semiconductor device 100, and a user program storage 42. The access prohibited region 41 may be interpreted as a region that stores unique information of the semiconductor device 100 (chip), a region that stores information for which user access is prohibited, and the like. A checksum expected value 43 may be set in the memory 4. Details of the expected value 43 will be described later.

[0015] The first calculation unit 5 may be interpreted as a checksum calculation unit that calculates checksums (CS-1 to CS-N). N may be interpreted as a natural number of 1 or more. Hereinafter, "checksum (CS-1 to CS-N)" may be simply referred to as "checksum". The checksum may be interpreted as a checksum of the values of the first to Nth addresses corresponding to each of the plurality of access prohibited areas 41 and the first to Nth data recorded in the plurality of access prohibited areas 41.

[0016] The determination result output circuit 6 may be interpreted as a circuit that determines the validity of the content of an access prohibited area or the like in order to block unauthorized access to the access prohibited area 41 via the common data bus 9 from the external IF (Inter Face) 7, the peripheral circuit 8, etc.

[0017] With reference to FIG. 2, a configuration example of the determination result output circuit 6 will be described. FIG. 2 is a diagram showing a configuration example of the determination result output circuit. The determination result output circuit 6 may include a plurality of holding units 61 and a comparison unit 62.

[0018] The plurality of holding units 61 may be interpreted as the first to Nth FF (Flip-Flop) circuits that hold the values of the first to Nth addresses recorded in the memory 4, the data (such as access prohibited information) held at these addresses, and the checksum calculated by the first calculation unit 5.

[0019] The plurality of holding units 61 may be reset, for example, when the power supply of the semiconductor device 100 is started, and may hold the first to Nth checksums calculated by the first calculation unit 5 after being reset, and may hold the result of the comparison unit 62.

[0020] Specifically, among the plurality of holding parts 61, the first holding part may hold the value of the first address of the memory 4, the data held at the address, and the checksum (CS-1) of these. Among the plurality of holding parts 61, the second holding part may hold the value of the second address of the memory 4, the data held at the address, and the checksum (CS-2) of these. Among the plurality of holding parts 61, the third holding part may hold the value of the third address of the memory 4, the data held at the address, and the checksum (CS-3) of these. Among the plurality of holding parts 61, the Nth holding part may hold the value of the Nth address of the memory 4, the data held at the address, and the checksum (CS-N) of these.

[0021] The comparison part 62 may compare the checksum held in each of the plurality of holding parts 61 with the expected value 43 of the checksum. Specifically, the checksum held in each of the first to Nth of the plurality of holding parts 61 may be compared with the expected value 43 of the checksum.

[0022] The value when all the checksums held in each of the plurality of holding parts 61 are normal may be set as the expected value 43. For example, the value (CS-1X) when the checksum (CS-1) of the first holding part is normal, the value (CS-2X) when the checksum (CS-2) of the second holding part is normal, the value (CS-3X) when the checksum (CS-3) of the third holding part is normal, the value (CS-NX) when the checksum (CS-N) of the Nth holding part is normal, etc. may be set as the expected value 43.

[0023] When the checksum matches the expected value 43, the comparison part 62 may output a determination result 62a indicating the match to the address decoder 3. For example, when the checksum (CS-1) does not match the expected value 43 (CS-1X), the output of the comparison part 62 is at a low level (L), and when they match, the output of the comparison part 62 changes from the low level (L) to the high level (H), and the determination result 62a is output. The remaining checksums (CS-2 to CS-N) are processed in the same way.

[0024] When the address decoder 3 receives the determination result 62a, it executes a process of masking the address. Specifically, when the address decoder 3 receives the determination result 62a, it may mask the address decoding information of the access prohibited area 41 with the determination result 62a. For example, the address decoder 3 that has received the determination result 62a indicating that the checksum (CS-1) matches the expected value 43 (CS-1X) masks the first address. The addresses corresponding to the remaining checksums (CS-2 to CS-N) are processed in the same way. The masking may be interpreted as a process of hiding the original address and switching to an address such as a CPU address where the memory 4 is not implemented (an address in a different area) according to the result of receiving the determination result 62a for the address decoding information of the access prohibited area 41. By causing the CPU to execute an address where the memory 4 is not implemented, a system error is intentionally generated to interrupt the CPU operation. Thereby, it becomes possible to notify the detection of an unauthorized access occurrence. As a specific implementation method, an example is conceivable in which the determination result 62a is used as a selector switch for the input from the address decoder 3 and the address where the memory is not implemented in the CPU.

[0025] Note that the numbers from the first to the Nth and the corresponding addresses may be arbitrarily set, and may be set to values necessary for determining the normality at the startup of the system including the semiconductor device 100.

[0026] Next, the operation of the semiconductor device 100 will be described. Immediately after the power-on of the semiconductor device 100, when reading addresses, data, etc. from the first to the Nth addresses in the read sequence of the access prohibited area 41, the checksum of the address and the read content is stored in the corresponding holding unit 61. The comparison unit 62 compares all the calculation results of the values currently held by the holding unit 61 with the expected value 43, stores the result in the flip-flop (holding unit 61), and outputs the output of the flip-flop to the address decoder 3. When the output of the comparison unit 62 changes from the low level (L) to the high level (H), the address decoding logic in the address decoder 3 determines that all the data in the access prohibited area 41 has been read normally. After that, when the address input to the address decoder 3 is the address of the access prohibited area 41, the address is masked by the output of the comparison unit 62 to prevent unauthorized access to the area. As a result, in the user program execution sequence, access from the external IF 7, peripheral circuit 8, etc. to the access prohibited area 41 is completely blocked, and it is possible to prevent the reading of data in the area that the user wishes to keep undisclosed.

[0027] In general, in the semiconductor device 100, it is prohibited to place user program code in the access prohibited area 41, and the access prohibited area 41 is developed as an area inaccessible from the user program. Therefore, when the semiconductor device 100 is operating normally, the access prohibited area 41 is not referenced from the user program during user program execution. When an abnormality occurs during user program execution, the memory controller 2 manages the operations of the memory 4, the external IF 7, the common data bus 9, etc. so that the system behaves safely. However, when a failure occurs in the memory controller 2 due to a malicious operation from the external IF 7 or the like, and an abnormality occurs in the memory controller 2, and furthermore, when the access decode logic of the access prohibited area 41 escapes from the management of the memory controller 2, the access prohibited area 41 becomes a state where it can be confirmed from the common data bus 9. Especially when the access prohibited area 41 contains information that the user does not want to disclose, it may cause serious security information leakage. For this reason, in the prior art, there has been a problem that the introduction of IP for improving the security of the system and the development of the memory controller 2 are required, resulting in an increase in development costs.

[0028] On the other hand, according to the semiconductor device 100 of the present disclosure, since it is possible to prevent the reading of data in an area that the user does not want to disclose, a secure system can be constructed at low cost.

[0029] (Modification example) FIG. 3 is a diagram showing a configuration example of a semiconductor device according to a modification example. The semiconductor device 100A according to the modification example includes a determination result output circuit 6A instead of the determination result output circuit 6. A configuration example of the determination result output circuit 6A will be described with reference to FIG. 4. FIG. 4 is a diagram showing a configuration example of the determination result output circuit shown in FIG. 3.

[0030] The determination result output circuit 6A may include a checksum holding unit 70 and a comparison unit 62.

[0031] The checksum holding unit 70 may include a first holding unit 61-1, a second calculation unit 80-2, a second holding unit 61-2, a third calculation unit 80-3, a third holding unit 61-3, an Nth calculation unit 80-N, and an Nth holding unit 61-N.

[0032] The first holding unit 61-1 may hold the checksum (e.g., CS-1) calculated by the first calculation unit 5 corresponding to the value of the address corresponding to the first access prohibited area 41 and the data recorded in the first access prohibited area 41.

[0033] Based on the checksum held in the first holding unit 61-1, the value of the address corresponding to the second access prohibited area 41, and the checksum (e.g., CS-2) calculated by the first calculation unit 5 corresponding to the data recorded in the second access prohibited area 41, the second calculation unit 80-2 may calculate a new checksum (e.g., CS-X1).

[0034] The second holding unit 61-2 may hold the checksum (e.g., CS-X1) calculated by the second calculation unit 80-2.

[0035] Based on the (e.g., CS-X1) held in the second holding unit 61-2, the value of the address corresponding to the third access prohibited area 41, and the checksum (e.g., CS-3) calculated by the first calculation unit 5 corresponding to the data recorded in the third access prohibited area 41, the third calculation unit 80-3 may calculate a new checksum (e.g., CS-X2).

[0036] The third holding unit 61-3 may hold the checksum (e.g., CS-X2) calculated by the third calculation unit 80-3.

[0037] Based on the (e.g., CS-X2) held in the third holding unit 61-3, the value of the address corresponding to the Nth access prohibited area 41, and the checksum (e.g., CS-N) calculated by the first calculation unit 5 corresponding to the data recorded in the Nth access prohibited area 41, the Nth calculation unit 80-N may calculate a new checksum (e.g., CS-XN).

[0038] The N-th holding unit 61-N may hold a checksum (e.g., CS-XN) calculated by the N-th calculation unit 80-N.

[0039] The comparison unit 62 compares the checksums held in the third holding unit 61-3 to the N-th holding unit 61-N with an expected value 43 corresponding to a specific read order of the first to N-th data recorded in the plurality of access prohibited areas 41, and when the checksum matches the expected value 43, a determination result 62a indicating the match may be output to the address decoder 3.

[0040] In this way, the determination result output circuit 6A has a function of assuming a case where the read order of data in the access prohibited area 41 is discontinuous and determining the legitimacy of the read order such as the address. The expected value 43 recorded in the memory 4 may be interpreted as the expected value 43 when all read orders are performed in a normal order.

[0041] Next, the operation of the semiconductor device 100A will be described. Immediately after the power-on of the semiconductor device 100A, in the read sequence of the access prohibited area 41, when reading the addresses, data, etc. from the first to the Nth, the checksum of the read addresses and data, and the operation result held at the previous timing are used as non-operation values to recalculate the checksum, and the result is held. That is, the semiconductor device 100A recalculates the checksum using the result of the previous operation, the current address, and the current data at all addresses, and holds it in a flip-flop. The semiconductor device 100A compares the content of the held flip-flop with the expected value 43, holds the result in the flip-flop (holding unit 61), and outputs the output of the flip-flop to the address decoder 3. The address decoding logic in the address decoder 3 determines that all the data in the access prohibited area 41 has been read normally when the output of the comparison unit 62 changes from the low level (L) to the high level (H). Thereafter, when the address input to the address decoder 3 is the address of the access prohibited area 41, the address is masked by the output of the comparison unit 62 to prevent unauthorized access to the area. Thereby, in the user program execution sequence, the access from the external IF7 to the access prohibited area 41 is completely blocked, and the reading of the data in the area that the user wants to keep non-disclosed can be prevented.

[0042] In addition, the following supplementary notes are disclosed regarding the above description.

[0043] (Supplementary Note 1) A memory having a plurality of access prohibited areas from the first to the Nth (N is a natural number of 1 or more) for storing unique information of the semiconductor device, A memory controller for controlling the memory, An address decoder for selecting an access target device based on an instruction from the memory controller, A first calculation unit for calculating a checksum of the values of the addresses corresponding to each of the plurality of access prohibited areas and the data recorded in the plurality of access prohibited areas, A plurality of holding units that hold the value of the address, the data, and the checksum; A comparison unit that compares the checksum held in each of the plurality of holding units with an expected value of the checksum, and outputs, to the address decoder, a determination result indicating that they match when the checksum matches the expected value; comprising; The address decoder masks the address based on the determination result, a semiconductor device.

[0044] (Appendix 2) A memory having a plurality of access prohibited areas from the first to the Nth (N is a natural number of 1 or more) that store unique information of a semiconductor device; A memory controller that controls the memory; An address decoder that selects a device to be accessed based on an instruction from the memory controller; A first calculation unit that calculates a checksum of the value of the address corresponding to each of the plurality of access prohibited areas and the data recorded in the plurality of access prohibited areas; A first holding unit that holds the checksum calculated by the first calculation unit corresponding to the value of the address corresponding to the first access prohibited area and the data recorded in the first access prohibited area; A second calculation unit that calculates a checksum based on the checksum held in the first holding unit, the value of the address corresponding to the second access prohibited area, and the checksum calculated by the first calculation unit corresponding to the data recorded in the second access prohibited area; A second holding unit that holds the checksum calculated by the second calculation unit; A third calculation unit that calculates a checksum based on the checksum held in the second holding unit, the value of the address corresponding to the third access prohibited area, and the checksum calculated by the first calculation unit corresponding to the data recorded in the third access prohibited area; A third holding unit that holds the checksum calculated by the third calculation unit; Compare the checksum held by the third holding unit with an expected value corresponding to a specific read order of the first to Nth data recorded in the plurality of access prohibited areas. When the checksum matches the expected value, output a determination result indicating the match to the address decoder to a comparison unit; comprising; The address decoder masks the address based on the determination result, a semiconductor device.

Explanation of symbols

[0045] 1 Program counter 2 Memory controller 3 Address decoder 4 Memory 5 First calculation unit 6, 6A Determination result output circuit 7 External IF 8 Peripheral circuit 9 Common data bus 41 Access prohibited area 42 User program area 43 Expected value 61 Holding unit 61-1 First holding unit 61-2 Second holding unit 61-3 Third holding unit 61-N Nth holding unit 62 Comparison unit 62a Determination result 70 Checksum holding unit 80 Calculation unit 80-2 Second calculation unit 80-3 Third calculation unit 80-N Nth calculation unit 100, 100A Semiconductor device

Claims

1. A memory having a plurality of access prohibited areas from the first to the Nth (N is a natural number of 1 or more) for storing unique information of a semiconductor device, A memory controller for controlling the memory, An address decoder for selecting an access target device based on an instruction from the memory controller, A first calculation unit for calculating a checksum of a value of an address corresponding to each of the plurality of access prohibited areas and data recorded in the plurality of access prohibited areas, A plurality of holding units for holding the value of the address, the data, and the checksum, A comparison unit that compares the checksum held in each of the plurality of holding units with an expected value of the checksum, and when the checksum matches the expected value, outputs a determination result indicating the match to the address decoder, Comprising, The address decoder masks the address based on the determination result, a semiconductor device.

2. A memory having a plurality of access prohibited areas from the first to the Nth (N is a natural number of 1 or more) for storing unique information of a semiconductor device, A memory controller for controlling the memory, An address decoder for selecting an access target device based on an instruction from the memory controller, A first calculation unit for calculating a checksum of a value of an address corresponding to each of the plurality of access prohibited areas and data recorded in the plurality of access prohibited areas, A first holding unit that holds the checksum calculated by the first calculation unit corresponding to the value of the address corresponding to the first access prohibited area and the data recorded in the first access prohibited area, A second calculation unit for calculating a checksum based on the checksum held in the first holding unit, the value of the address corresponding to the second access prohibited area, and the checksum calculated by the first calculation unit corresponding to the data recorded in the second access prohibited area, A second holding unit that holds the checksum calculated by the second calculation unit, A third calculation unit for calculating a checksum based on the checksum held in the second holding unit, the value of the address corresponding to the third access prohibited area, and the checksum calculated by the first calculation unit corresponding to the data recorded in the third access prohibited area, A third holding unit that holds the checksum calculated by the third calculation unit, Compare the checksum held in the third holding unit with an expected value corresponding to a specific read order of the first to Nth data recorded in the plurality of access prohibited regions, and when the checksum matches the expected value, output a determination result indicating the match to the address decoder. A comparison unit; comprising; The address decoder masks the address based on the determination result, a semiconductor device.

Citation Information

Patent Citations

  • System and method for storing data

    JP2002182977A