Method for remotely programming a programmable device
The method for remotely programming programmable devices using unique device-specific data and a PUF-based second program code ensures secure and reliable delivery of sensitive results, addressing vulnerabilities in untrusted environments.
Patent Information
- Application Number
- JP2023501233
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-07-06
- Filing Date
- 2021-07-06
- Publication Date
- 2025-07-02
- Estimated Expiration
- 2041-07-06
AI Technical Summary
Existing programmable devices in untrusted environments are vulnerable to interception, hacking, and malicious attacks, leading to risks of software modification, replication, and unauthorized access to sensitive information or services.
A method involving a first program code that obtains unique data specific to a programmable device, generates a second program code based on this data, and transmits it securely to ensure the sensitive result is provided only when executed on the correct device, using a Physical Unclonable Function (PUF) to enhance security.
The solution effectively protects sensitive results by ensuring they are provided only on the intended device, making it difficult for attackers to replicate or modify the program code, thus enhancing security and integrity.
Smart Images

Figure 0007701967000001 
Figure 0007701967000002 
Figure 0007701967000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of remotely programmable devices, such as hardware, designed to provide sensitive services on untrusted remote platforms or to perform functions that are to be secured. For this purpose, the present disclosure relates to a method for remotely programming a programmable device designed to provide a desired sensitive result. The present disclosure further relates to such a programmable device and a provider for remotely providing program code to such a programmable device.
Background Art
[0002] Platforms in untrusted environments tend to be intercepted, forged, or hacked in order to search for and utilize sensitive or valuable information. In an environment based on a remote information source, it is possible for a hacker to bypass the communication with the remote source and appear to be part of a trusted system in order to gain access to such information or services.
[0003] The risk of having to deal with misbehavior can also exist during other operations, for example, when remotely upgrading software on such a programmable device. The software can be subject to malicious attacks, such as reverse engineering attacks performed by external parties for several purposes. Some attacks may attempt to modify the software, for example, bypass certain features, add malicious code segments thereto, copy the software to understand how it operates, or read it out.
[0004] In an attempt to overcome such concerns, some devices are configured to generate identifiers using a so-called True Random Number Generator (TRNG), also known as a Hardware Random Number Generator (HRNG). Such a generator is a device that generates random numbers from physical processes rather than simply being algorithm-based. Considering that the physical processes used by such generators are based on microscopic phenomena that generate low-level signals, prediction is defined as impossible. However, generating numbers using a TRNG to provide unique numbers is not efficient enough because once the generated value is known, any hacker can mimic the solution for replication purposes.
[0005] U.S. Patent Application Publication No. 2019 / 305927 (A1) discloses node-lock based bitstream security. More specifically, this document discloses an approach to FPGA (Field Programmable Gate Array) security that provides protection against in-field bitstream reprogramming and protection against intellectual property (IP) infringement while enabling wireless reconfiguration without encryption.
[0006] U.S. Patent Application Publication No. 2014 / 258736 (A1) discloses a system and method for maintaining integrity and security in an untrusted computing platform. More specifically, this document discloses a method of generating a secret cryptographic key based on a physically unclonable function (PUF) in at least one hardware component of a trusted processor, then generating a first public key and a first secret key using the aforementioned secret cryptographic key, and executing instruction codes corresponding to a first software program.
[0007] U.S. Patent No. 8,918,647 (B1) discloses an authentication system, and more specifically, relates to hardware authentication and binding authentication for protection against forgery and destruction by replacement.
[0008] Accordingly, there is a need for an efficient and reliable solution to prevent such threats and at least partially overcome the aforementioned problems and drawbacks. More specifically, such a solution should be capable of at least protecting the integrity and sensitivity of valuable services or information for which such programmable devices on a remote platform are designed. This solution should be able to efficiently prevent the replication of valuable related products or services and, if any, should further be able to provide a secure upgrade of the remote platform. SUMMARY OF THE INVENTION
[0009] To address this concern, in a first aspect, the present disclosure is As defined in claim 1, for remotely programming a programmable device designed to provide expected sensitive results propose a method .
[0010] In an embodiment, the method comprises: - transmitting a first program code to a programmable device, the first program code being configured to obtain at least one unique data that is unique and physically specific to the programmable device; - searching for the unique data for generating a second program code configured to provide an expected sensitive result while the second program code is being executed on the programmable device that generates the unique data; - transmitting the second program code to the programmable device so as to load the second program code into the programmable device.
[0011] Thanks to this solution, the functional state of the second program code provides the expected sensitive results only when the second program code is executed on a single and specific programmable device, i.e., the device that generates unique data after executing the first program code, and more specifically, on the device that executed the first program code. It can be modified so as to be able to be done. This means that even when the second program code is made available to a third party for execution on a third-party programmable device similar to the one generating the unique data, the result provided by this device will be different from the expected sensitive result. Therefore, the second program code is advantageously tied to a unique programmable device, so that even though this device is physically located on a remote and untrusted platform that may be subject to a number of malicious attacks, the result provided by the second program code is efficiently protected against such attacks as it provides the expected sensitive result only when executed by this unique programmable device. Further, the second program code can be modified so that reverse engineering becomes more difficult and its actual design is reconfigured only when executed on a specific programmable device.
[0012] Preferably, the first program code and the second program code are designed by a provider remotely linked to the programmable device via a communication channel.
[0013] According to one embodiment, the unique data results from, or is derived from, a Physical Unclonable Function (PUF) applied to at least one component of the programmable device.
[0014] In one embodiment, the second program code is transformed by a reversible function depending on the unique data. Preferably, the reversible function is a mathematical function or a logical function.
[0015] In another embodiment, the second program code is transformed by replacing at least one searchable program code portion from the unique data with a modified portion.
[0016] According to one embodiment, the second program code is global program code common to a set of distinguishable programmable devices and is configured to be individualized by an individual setting message for at least one programmable device of the set, the individual setting message being based on the specific data of the associated programmable device.
[0017] Preferably, the associated programmable device comprises a unique function, the unique function being configured to provide a first key from an individual setting message used as input data in the unique function, the first key being further used as input to the global program code to provide a sensitive result expected from the global program code.
[0018] In one embodiment, the global program code is an encryption algorithm.
[0019] Preferably, the expected sensitive result is a second key, preferably an activation key or an encryption key.
[0020] In one embodiment, at least one of the step of transmitting and the step of searching is secured by at least one of an authentication process and an encryption process.
[0021] In another embodiment, at least one of the first program code and the second program code is a netlist, source code, or machine code.
[0022] Preferably, when the communication channel is at least partially provided by a global network or by an untrusted communication channel, the first program code is transmitted to the programmable device in a secure manner to guarantee the authenticity and integrity of the first program code.
[0023] According to a second aspect, the present disclosure also relates to a programmable device designed to be remotely programmed according to any of its embodiments, or according to any possible combination of these embodiments, according to the method described above that can be executed to provide an expected sensitive result. This programmable device As defined in the claims. In an embodiment, the programmable device is , - at least one unique data that is unique and physically specific to the programmable device, and - a first program code configured to obtain the unique data, and a second program code configured to provide an expected sensitive result based on the unique data, a communication interface for receiving; - at least one memory for storing the first and second program codes, - a processor or a hardware state machine for executing the first and second program codes.
[0024] In a third aspect, the present disclosure relates to a provider for remotely providing program code to at least one programmable device according to any of its embodiments, or according to any possible combination of these embodiments, according to the method described above that can be executed. This provider As defined in the claims. In an embodiment, the provider is , - a program code generator for generating a first program code configured to obtain at least one unique data that is unique and physically specific to the programmable device, and a second program code configured to provide an expected sensitive result based on the unique data, - a communication interface configured to be connected to a communication channel for transmitting the first and second program codes to the programmable device and receiving the unique data therefrom.
[0025] Other embodiments and advantages are disclosed in the detailed description.
Brief Description of the Drawings
[0026] The solutions and embodiments proposed in this disclosure should be construed as non-limiting examples and will be better understood by referring to the accompanying drawings.
Figure 1
Figure 2
Figure 3
DETAILED DESCRIPTION OF THE INVENTION
[0027] FIG. 1 shows a schematic diagram of an environment comprising three main entities, namely a provider 10, a user unit 20, and a platform 30 comprising at least a programmable device 35. These entities can be connected to each other through a network, typically an untrusted network such as the Internet. However, a local area network (LAN), such as a private network, can also be used instead of, or in addition to, a wide area network (WAN). Preferably, both the provider 10 and the user unit 20 are remotely connected to the platform 30, whereby the platform 30 can be considered to be located in the cloud. To understand the principle of this solution, for example, it should be noted that it is not necessary for the user unit 20 to be connected to the provider 10 in order to exchange data or messages. Thus, there is no direct connection or link between the provider 10 and the user 20 as shown in FIG. 1, although this may actually be the case.
[0028] Provider 10 is preferably located within a secure area. The provider is typically designed to provide program code 40, particularly program code for a programmable device 35 physically located within platform 30. Such program code 40 is also referred to by those skilled in the art as a "netlist". The so-called netlist, once programmed, can be regarded as a set of source data presented in the form of code for programming a device having at least one desired function or application. The code can be a high-level software language, and the program code 40 can be stored in a so-called source file. The program code typically relates to an instruction code corresponding to a computer program or a software program containing instructions that are executed by a processor in a different sequence to execute the program.
[0029] User unit 20 can be regarded as any type of device that requires the services of platform 30, particularly the services of programmable device 35. Thus, if the programmable device 35 is programmed with an application configured to, for example, perform tasks and / or provide certain services or results, the user unit 20 can be regarded as a device such as a client unit that may be necessary to receive such services or results. For this reason, preferably, as schematically shown in FIG. 1, there is a two-way connection that can be established between the user unit 20 and the platform 30. Although a single user unit 20 is part of the environment shown in FIG. 1, it should be understood that several user units 20 can be connected to the platform 30 to benefit from the services of the programmable device 35.
[0030] Thus, as schematically shown in FIG. 1, the programmable device 35 is located remotely from the provider 10, preferably at a distance from the user unit 20. The platform 30 hosting the programmable device 35 can be an untrusted platform. The programmable device 35 is an electronic device, such as an electronic circuit built on a printed circuit board, and at least one program code 40 can be loaded thereon to provide at least one specific feature or function to the programmable device. Such a function may be designed to process the input 44 in order to provide the expected result as an output 45. The input 44 can be an input signal to be decoded, input data or message to be processed, or simply a request. The output 45 can be used as a response to be sent back to the user unit 20. More preferably, as shown in FIGS. 1 and 2, the programmable device 35 is a reprogrammable hardware element, such as a so-called field programmable gate array (FPGA).
[0031] Each entity 10, 20, 30 comprises a communication interface 11, 21, 31 for exchanging data through at least one communication channel 1 which can be part of a network such as the Internet. FIG. 1 typically represents a conventional architecture where the provider 10 is tasked with generating the program code 40 to be loaded onto the programmable device 35. The program code 40 is transmitted to the remote platform 30 via the communication path 1. Once received by the platform 30, the program code 40 is typically stored in the storage device 32 before being converted by a conversion tool 33, such as a compiler, into a format understandable by the programmable device 35. Once converted into such a format, the converted program code 40’ It is transmitted to the programmable device 35 via its communication interface 35a in order to be loaded into the programmable device 35. Once loaded, the programmable device 35 acquires a specific function for processing the data transmitted as input 44 by the user unit 20 and sending back a response or result as output 45 of the programmable device.
[0032] However, such a method has several weaknesses. In fact, the program code 40 may be hacked at various locations between the provider 10 and the programmable device 35, especially because the platform 30 where the programmable device is located may be an entity that is not secured or trustworthy, or even a shared platform in the cloud, for example. The first attack point is located between the provider 10 and the platform 30, that is, within the communication channel 1 or within the wide area network. During this transfer, a malicious person may intercept, copy, modify, or steal the program code 40 without anyone noticing. The second and third attack points are located within the storage device 32 and within the conversion tool 33, which can be other entry points for hackers. The fourth attack point may be located in the connection that links the conversion tool 33 to the programmable device 35. The last attack point may be located in the programmable device 35, for example, in the memory designed to store the converted program code 40' within the programmable device 35.
[0033] To overcome such drawbacks, the present solution mainly discloses the method shown in FIG. 2. This method is configured to remotely program a programmable device 35 designed to provide an expected sensitive result 45. Such a result is defined as sensitive because, as presented above, it may be a target of an attack. The sensitive result 45 can be any type of data provided by the programmable device 35. For example, the sensitive result can be a business value or a cryptographic key.
[0034] The first step S1 of the method aims to transmit a first program code 41 to the programmable device 35. This first program code 41 can be regarded as a characterization netlist or a setting netlist. Therefore, the first program code 41 should not be confused with the program code 40 shown in FIG. 1. In fact, once loaded onto a device such as the programmable device 35, the program code 40 is a functional program code that can be directly used to provide the sensitive expected result 45. On the other hand, since the first program code 41 is not designed for such a purpose, it is impossible to provide such an expected result 45. In fact, the first program code 41 is configured to obtain at least one unique data 35d that is unique and physically specific to the programmable device 35. In FIG. 2, this unique data 35d is schematically indicated by the DNA portion of the programmable device, and the first program code 41 is schematically stamped with a vial to collect such a DNA portion.
[0035] Such unique data can be derived from an oscillator, e.g., a ring oscillator 35e having a specific frequency that is not exactly the same as the frequency of another ring oscillator of the same type. This holds even if both oscillators are produced according to the same manufacturing process by a single production line. In fact, each oscillator has a unique frequency that essentially results from the small variations it undergoes during manufacturing. These slight variations result from manufacturing process tolerances and, thanks to their unique characteristics, make the oscillator unique. Since the same is true for other electronic components or circuits, it is not necessary to extract unique data 35d only from the oscillator, and other electronic components can be used. Obtaining unique data 35 from an electronic component can be performed by measuring one or more physical quantities on the electronic component. For this purpose, sharp measurement devices and / or processes can be applied. Furthermore, note that other techniques, such as those based on magnetoresistive random access memory (MRAM) or static random access memory (SRAM), both of which depend on memory behavior, can be used to create functions that are difficult to physically replicate.
[0036] The second step of this method (S2’ and S2”) aims to first search for the specific data 35d in order to generate the second program code 42. In FIG. 2, this operation S2’ is schematically illustrated by sampling the vial containing the DNA portion of the programmable device 35. Searching for such data can be achieved by receiving the specific data 35d from the platform 30, for example, from the programmable device 35, or from any other device of the platform configured to obtain the specific data 35d of the programmable device. For this purpose, the latter can be configured to transmit its specific data 35d to the provider 10, for example, thanks to the first program code 41. Preferably, such transmission can be executed as soon as the specific data 35d of the programmable device 35 is acquired. This transmission can be secured, for example, by applying an encryption process, preferably similar to the authentication process, to the specific data 35d before its transmission to the provider 10. The encryption process can refer to any type of encryption algorithm, and the authentication process can typically be based on a digital signature scheme.
[0037] For example, once retrieved by the provider 10, the latter can generate the second program code 42 during the operation shown as S2”, which is schematically illustrated in FIG. 2 by using the DNA collected by the vial to generate the second program code 42. This operation can be considered as the second part of the second step.
[0038] The second program code 42 is program code configured to provide an expected sensitive result 45 when executed on a programmable device 35 that generates unique data 35d. In other words, when the second program code 42 is executed on a device different from the programmable device 35 from which the unique data 35d is obtained, the result provided by the second program code 42 will be different from the expected sensitive result 45. This is because the second program code 42 is configured according to a part of the "DNA" of the programmable device 35, more specifically, according to the unique data 35d that is unique and physically specific to a particular programmable device 35. Therefore, when the second program code 42 is loaded onto this programmable device 35, only the single and unique programmable device 35 from which the unique data 35d is extracted can provide the expected sensitive result 45. It should be further noted that the sensitive result, if it is correct, is defined as the expected sensitive result 45. When the second program code 42 is loaded and executed on a third device, that is, a device different from the programmable device 35 that generates the unique data 35d, the sensitive result provided by this third device will be inaccurate. This means that the second program code 42 can operate on the third device without necessarily causing a system error, but the result provided by this third device is different from the expected sensitive result 45.
[0039] The third step S3 of this method aims to transmit the second program code 42 to the programmable device 35 so as to load the second program code 42 onto the programmable device.
[0040] Thanks to this method, since the first program code 41 is not designed for such a purpose, it cannot provide the expected sensitive result 45. The second program 42 can typically provide the expected sensitive result 45 only when executed on the programmable device 35 that generates the unique data 35d. Thus, there is no longer an efficient attack point between the provider 10 and the programmable device 35. Further, note that the expected sensitive result 45 is usually the response provided to the input 44 by the programmable device 35. This means that the expected sensitive result 45 can depend not only on the unique data 35d but also on the input 44. Considering that the unique data 35d is physically tied to the programmable device 35 to calculate the expected sensitive result 45, there is no possibility for a hacker to remotely obtain such unique data 35d, which can be regarded as closer to hardware than software. Therefore, obtaining the unique data 35d of the programmable device requires a hardware attack rather than a software attack. However, since a hardware attack requires the hacker to physically go to the site where the programmable device 35 is located, it is considered to be excluded.
[0041] According to one embodiment, the first program code 41 and the second program code 42 are designed by a provider 10 remotely linked to the programmable device 35 via a communication channel 1. The provider 10 is preferably a security provider, i.e., a provider located within a secure area. Thus, generating the first and second program codes 41, 42 can be safely achieved by a program code generator 14 that can be preferably located within the provider 10 in a reliable environment. The communication channel 1 between the provider 10 and the programmable device 35 or the platform 30 does not need to be a secure channel and can be a channel within any network such as the Internet. Generally speaking, the communication channel 1 is at least partially provided by a global network (e.g., the Internet) or by an untrusted communication channel. Nevertheless, when the communication channel 1 is an untrusted channel, the first program code is preferably transmitted to the programmable device in a secure manner so as to guarantee its authenticity and its integrity. For this purpose, the first program code 41 can be transmitted in an encrypted form together with a digital signature to guarantee that no change has been made to the first program code during the transmission between the provider 10 and the programmable device 35.
[0042] In a preferred embodiment, the unique data 35d results from, or is derived from, a physical unclonable function (PUF) applied to at least one component 35e of the programmable device 35. The PUF function aims to utilize the manufacturing process variations of electronic components such as the component 35e, and thanks to the unique characteristics of these electronic components, makes the electronic circuit of the programmable device 35 unique. Note that although a ring oscillator 35e is used as an example in the illustrative diagram of FIG. 2, the PUF function does not need to be limited to a ring oscillator. The PUF function can be a function that is part of the first program code 41 or a function that is part of the programmable device 35 or another suitable device, e.g., a function that can be triggered by the first program code 41.
[0043] In one embodiment, the second program code 42 is parameterized and / or modified according to the unique data 35d. For example, the second program code 42 can be program code that is transformed by a reversible function according to the unique data 35d. In other words, the second program code 42 can be one that has undergone a transformation received by a reversible function that depends on the unique data 35d. Preferably, the reversible function is a mathematical or logical function such as, for example, an XOR function.
[0044] In one embodiment, the second program code 42 is transformed by replacing at least one program code portion with a modified portion. In this case, the aforementioned program code portion being replaced remains searchable using the unique data 35d. For example, the program code portion can be transformed by a reversible function, and more specifically, by a bijective reversible function (e.g., an encryption function) parameterized by the unique data 35d.
[0045] According to another embodiment schematically shown in FIG. 3, the second program code 42 is global program code 42' common to a set of distinguishable programmable devices 35. In other words, a single global program code 42' is intended or configured to be used by a plurality of programmable devices 35. Thus, this embodiment can be considered to be more cost-effective. Additionally, this embodiment is easier to implement considering that when a plurality of programmable devices 35 are considered, it is not necessary to generate a second program code 42 for each programmable device 35. Thus, the global program code 42' can then be regarded as a general-purpose second program code 42 that can be individualized by sending an individualized setting message 43 to, for example, a programmable device 35, that is, to each programmable device when a plurality of such devices are considered, or to at least one programmable device 35 among the plurality of programmable devices 35.
[0046] The personalized setting message 43 should be based on the unique data 35d of the associated programmable device 35. For example, the personalized setting message 43, in combination with the PUF value (i.e., the value provided by the PUF function applied to the programmable device), can be a value that provides the content of the variables included in the global program code. Thus, even if the second program code is global and thus common to a plurality of programmable devices 35, the expected sensitive result 45 provided as output can be specific and unique to each programmable device 35.
[0047] Advantageously, generating the personalized setting message requires fewer computer resources than generating the second program code 42 for each programmable device 35. Additionally, such an embodiment is also more flexible as it allows for the easy addition of further programmable devices 35 at a later stage without the need to adapt or modify the second program code. In fact, the unique data 35d of any newly added programmable device 35 can still be collected by using the first program code 41. Then, for example, the personalized setting message 43 generated by the provider 10 can be transmitted to the programmable device 35, preferably to remotely personalize the global program code 42' and, thus, to remotely personalize the expected sensitive result 45 provided by the global program code 42'.
[0048] For example, if the programmable device 35 can provide specific data such as a unique key K2 as the expected sensitive result 45, then this programmable device should receive an individual configuration message 43, that is, a unique message that is specific to the programmable device 35 and is configured for the purpose of configuration. More specifically, the individual configuration message 43 is configured to parameterize or configure the global program code 42’, and as a result, the programmable device 35 provides appropriate data (e.g., the aforementioned unique key K2) as the expected sensitive result 45. Configuring the global program code 42’ can be achieved, for example, by providing specific data to at least one function or at least one variable of the global program code and can be achieved by providing specific data.
[0049] According to another embodiment, the programmable device 35 to which the global program code 42’ and the related individual configuration message 43 are transmitted includes a unique function 35f. This unique function 35f can be configured to provide a first key K1 from the individual configuration message 43 used as input data in this unique function, as shown in FIG. 3. This first key K1 can be further used as input to the global program code 42’ to provide the expected sensitive result 45 therefrom.
[0050] According to one embodiment, the global program code 42’ is an encryption algorithm, for example, a standardized encryption algorithm such as AES. In this embodiment, the first key K1 can be used as input to such a standardized algorithm. Even if the general operation of an algorithm such as AES is well known to hackers, this is not a problem considering that the key injected into this algorithm (i.e., the first key K1) remains secret and is uniquely associated with the related programmable device 35.
[0051] According to another embodiment, the expected sensitive result 45 is a second key K2, preferably an activation key or a cryptographic key. Such a second key can then be used, for example, by the user unit 20 for any purpose.
[0052] In one embodiment, at least one of the transmitting step and the receiving step is secured by at least one of an authentication process and an encryption process. For example, the expected sensitive result 45 can be encrypted by the programmable device 35 or by any other suitable device of the platform 30 before being transmitted to the user unit 20. As another example, the proprietary data 35d provided by the first program code 41 can be transmitted to the provider 10 in encrypted form during the operation S2' of the second step of the method. Similarly, the individual configuration message 43 received by at least one of the programmable devices 35 can also be protected by an encryption mechanism. In addition, for example, if the algorithm used in the second program code 42 is a digital asset, typically an algorithm having specific characteristics such as a proprietary algorithm that should be kept secret (as opposed to a standardized algorithm), the second program code 42 can be transmitted to the programmable device 35 in encrypted form. Thus, the platform 30, preferably the programmable device 35 or an associated device, can comprise an encryption module 35k (Figure 2) configured such that an encryption process, for example an encryption operation and / or a decryption operation, and if any an authentication process are performed.
[0053] In one embodiment, at least one of the first program code 41 and the second program code 42 is a netlist, source code, or machine code.
[0054] According to a second aspect, the solution also relates to a programmable device 35 designed to be remotely programmed according to the method described above, more specifically according to any embodiment of this method or any possible combination of embodiments of this method. Thus, the programmable device is programmed to provide the expected result 45. As shown in FIG. 2, the programmable device 35 comprises - at least one unique data 35d that is unique and physically unique to the programmable device, and - a communication interface 35a, - a first program code 41 configured to obtain the aforementioned unique data 35d, - a communication interface 35a for receiving a second program code 42 configured to provide a sensitive result 45 predicted based on the unique data 35d, - at least one memory 35b for storing the first and second program codes 41, 42, - a processor 35c or a hardware state machine for executing the first and second program codes 41, 42.
[0055] The programmable device 35 preferably comprises a unique function 35f such as, for example, a PUF function. The unique data 35d can be derived from at least one component of the programmable device 35, such as an oscillator 35e, more specifically a ring oscillator. The unique function 35f can be processed by the processor 35c and, if so, stored in the processor itself or in the memory 35b. Alternatively, the unique function 35f can be processed within the fabric of the programmable device 35 by, for example, some custom logic and stored within the programmable device structure. Depending on the embodiment of the method described above, the programmable device 35 may further comprise an encryption module 35 and other modules or units configured to perform other specific tasks. Preferably, the programmable device 35 is a so-called FPGA.
[0056] In a third aspect, the present solution relates to a provider 10 for remotely providing program codes 41, 42 to a programmable device 35, more specifically, according to the method described above, and in particular to at least one programmable device 35, according to any embodiment of this method, or according to any possible combination of embodiments of this method. This provider 10 - a program code generator 14, - a first program code 41 configured to obtain at least one specific data 35d unique and physically unique to the programmable device 35, - a second program code 42 configured to provide a sensitive result 45 predicted based on the specific data 35d, and a program code generator 14 for generating the second program code 42, - a communication interface 11 configured to be connected to a communication channel 1 for transmitting the first and second program codes 41, 42 to the programmable device 35 and receiving the specific data 35d therefrom. According to an embodiment of the foregoing method, the provider 10 may further include an encryption module (not shown) such that the encryption module 35k of the programmable device 35 performs a task similar to what may be intended.
[0057] It should be noted that any feature or combination of features disclosed in connection with this method may also be part of at least one of the programmable device 35 and the provider 10, where applicable.
[0058] Final Considerations Although an overview of the subject matter of the present invention has been described with reference to specific exemplary embodiments, various modifications and changes can be made to these embodiments without departing from the broader spirit and scope of the embodiments of the present invention. For example, the various embodiments of its features can be mixed, adapted, or optionally selected by those skilled in the art. Accordingly, the "mode for carrying out the invention" should not be construed in a limiting sense, and the scope of the various embodiments is defined only by the appended claims, together with the full scope of equivalents to which such claims are entitled.
Claims
1. A method for remotely programming a programmable device (35) designed to provide a predicted sensitive result (45), the method comprising: a provider (10) remotely linked to the programmable device (35) via a communication channel (1), - transmitting a first program code (41) to the programmable device (35), the first program code (41) being configured to obtain at least one unique and physically unique data (35d) for the programmable device (35), - searching for the unique data (35d), - transmitting a second program code (42) to the programmable device (35) to load the second program code (42) into the programmable device (35) based on the searched unique data (35d).
2. The method according to claim 1, wherein the first program code (41) and the second program code (42) are designed by the provider (10).
3. The method according to claim 1 or 2, wherein the unique data (35d) results from or is derived from a physical replication difficulty function (35f) applied to at least one component (35e) of the programmable device (35).
4. The method according to any one of claims 1 to 3, wherein the second program code (42) is converted by a reversible function according to the unique data (35d).
5. The method according to claim 4, wherein the reversible function is a mathematical function or a logical function.
6. The method according to claim 4 or 5, wherein the second program code (42) is converted by replacing at least one searchable program code portion from the unique data (35d) with a modified portion.
7. The second program code (42) is global program code (42') common to a set of distinguishable programmable devices (35), and is configured to be individualized by an individual setting message (43) for at least one programmable device (35) of the set, the individual setting message (43) being based on the specific data (35d) of the associated programmable device (35), the method according to any one of claims 1 to 6.
8. The associated programmable device (35) comprises a unique function (35f), the unique function (35f) being configured to provide a first key (K1) from the individual setting message (43) used as input data in the unique function (35f), the first key (K1) being further used as input to the global program code (42') for providing an expected sensitive result (45) from the global program code (42'), the method according to claim 7.
9. The global program code (42') is an encryption algorithm, the method according to claim 7 or 8.
10. The expected sensitive result (45) is a second key (K2), preferably an activation key or an encryption key, the method according to any one of claims 1 to 9.
11. At least one of the transmitting step and the searching step is secured by at least one of an authentication process and an encryption process, the method according to any one of claims 1 to 10.
12. At least one of the first program code (41) and the second program code (42) is a netlist, source code, or machine code, the method according to any one of claims 1 to 11.
13. If the communication channel (1) is at least partially provided by an untrusted communication channel, the provider (10) transmits the first program code (41) to the programmable device (35) in a secure manner that guarantees the authenticity and integrity of the first program code (41), the method according to any one of claims 1 to 12.
14. A programmable device (35) designed to be remotely programmed according to the method of any one of claims 1 to 13 to provide a predicted sensitive result (45), wherein the programmable device (35) is - at least one unique data (35d) unique and physically specific to the programmable device (35); - a communication interface (35a) for receiving a first program code (41) configured to obtain the unique data (35d) and a second program code (42) configured based on the unique data (35d); - at least one memory (35b) for storing the first and second program codes (41, 42); - a processor (35c) or a hardware state machine for executing the first and second program codes (41, 42). The programmable device (35) comprises.
15. A provider (10) for remotely providing program codes (41, 42) to at least one programmable device (35) according to the method of any one of claims 1 to 13, wherein the provider - a program code generator (14) for generating a first program code (41) configured to obtain at least one unique data (35d) unique and physically specific to the programmable device (35) and a second program code (42) configured based on the unique data (35d); - a communication interface (11) configured to be connected to a communication channel (1) for transmitting the first and second program codes (41, 42) to the programmable device (35) and receiving the unique data (35d) therefrom. The provider (10) comprises.
Citation Information
Patent Citations
Remote rewrite method for electronic control unit
JP2008123147A
Data generation device, communication device, communication system, mobile, data generation method and program
JP2016134671A
Network authentication system with dynamic key generation
JP2017517229A
Bitstream security based on node locking
US20190305927A1