Semiconductor device and control method thereof
A semiconductor device with synchronized encryption and decryption processes in a single cryptographic module addresses the challenge of meeting security and functional safety without increasing circuit size, enhancing resistance to side-channel attacks.
Patent Information
- Application Number
- JP2022011160
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-01-27
- Publication Date
- 2025-11-10
- Estimated Expiration
- 2042-01-27
AI Technical Summary
The duplication of cryptographic modules in semiconductor devices to meet functional safety requirements increases circuit size and reduces resistance to side-channel attacks, compromising security requirements.
Implementing a semiconductor device with a single cryptographic module that includes an encryption device, a decryption device, a selector, and a comparator, where encryption and decryption processes are synchronized to disrupt side-channel noise, thereby enhancing resistance to attacks while maintaining functional safety and security without increasing circuit size.
The solution effectively satisfies both security and functional safety requirements while preventing an increase in circuit size and improving resistance to side-channel attacks, such as DPA and CPA, by synchronizing encryption and decryption processes within a single cryptographic module.
Smart Images

Figure 0007766503000001 
Figure 0007766503000002 
Figure 0007766503000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a semiconductor device and a control method thereof, and more particularly to a semiconductor device and a control method thereof that are suitable for satisfying both security requirements and functional safety requirements while suppressing an increase in circuit size, for example. [Background technology]
[0002] In recent years, in the field of ECUs (Electronic Control Units), an example of semiconductor devices, there has been an increasing need to meet security requirements to prevent attacks from malicious third parties in communications between ECUs. At the same time, high-level functional safety requirements must be met in communications between ECUs to prevent malfunctions.
[0003] Here, AES (Advanced Encryption Standard) is known as an example of encryption technology used to satisfy security requirements.
[0004] Furthermore, functional safety requirements require ensuring a high level of safety that meets the functional safety standard ASIL (Automotive Safety Integrity Level). ASIL indicates the level of hazards that must be avoided among the possible failures (hazards) that can occur in electronic systems, and is specified in ISO 26262. Specifically, ASIL is expressed in four levels, A to D, with ASIL_A indicating the lowest level of hazard and ASIL_D indicating the highest level of hazard.
[0005] In automotive electronic systems that require the highest functional safety level (i.e., ASIL_D), a safety mechanism called DCLS (Dual Core Lock-Step) is used, in which two cores work in pairs and operate in lockstep. In lockstep operation, the processing results of two cores that simultaneously execute the same process are compared, and if the processing results match, it is determined that no fault has occurred, but if the processing results do not match, it is determined that a fault has occurred.
[0006] Here, when a cryptographic module that employs encryption technology that satisfies security requirements (for example, a cryptographic module that employs AES encryption technology) is converted to DCLS to satisfy functional safety requirements, the cryptographic modules are duplicated, and the original encryption process is performed in one cryptographic module, while the encryption process for verification (comparison) is performed in the other cryptographic module. After that, the result of the encryption process by one cryptographic module is compared with the result of the encryption process by the other cryptographic module, thereby achieving lockstep operation.
[0007] More specifically, one of the duplicated cryptographic modules encrypts plaintext data input from outside to generate first encrypted data, while the other cryptographic module encrypts plaintext data shared with the first cryptographic module to generate second encrypted data. The comparator then compares the encrypted data generated by each of the duplicated cryptographic modules to determine whether the encrypted data match. This enables a high level of fault detection.
[0008] Note that cryptographic module duplication is effective not only in detecting accidental failures, but also in detecting intentional failures caused by fault attacks, which are a type of side-channel attack. A side-channel attack is an attack method that attempts to illegally obtain secret information by physically observing leaked information that is implementation-dependent, such as current consumption and processing time, unlike the security basis of modern cryptography such as AES and RSA, which are considered computationally secure against cryptographic analysis methods. Specific attack methods known include DPA (Differential Power Analysis), CPA (Correlation Power Analysis), and fault attacks. Summary of the Invention [Problem to be solved by the invention]
[0009] However, the duplication of cryptographic modules not only increases the circuit size, but also reduces the resistance to side-channel attacks when the duplication of cryptographic modules is performed in lockstep, compared to when a single cryptographic module is operated. Other issues and novel features will become apparent from the description of this specification and the accompanying drawings. [Means for solving the problem]
[0010] According to one embodiment, a semiconductor device includes a first encryption device having a first encryption processing unit that performs encryption processing on plaintext data input from outside to generate first encrypted data, a first decryptor having a first decryption processing unit that performs decryption processing on the first encrypted data generated in the first encryption device in synchronization with the encryption processing in the first encryption device to generate first decrypted data, a comparator that compares the plaintext data with the first decrypted data corresponding to the plaintext data, and a control unit that performs fault determination for the first encryption device and the first decryptor based on the comparison result by the comparator.
[0011] According to one embodiment, a method for controlling a semiconductor device includes using a first encryption device to perform an encryption process on plaintext data input from outside to generate first encrypted data, using a first decryptor to perform a decryption process on the first encrypted data generated in the first encryption device in synchronization with the encryption process in the first encryption device to generate first decrypted data, comparing the plaintext data with the first decrypted data corresponding to the plaintext data, and making a fault determination for the first encryption device and the first decryptor based on the comparison result. [Effects of the Invention]
[0012] The present disclosure can provide a semiconductor device and a control method thereof that can satisfy both security requirements and functional safety requirements while suppressing an increase in circuit size. [Brief explanation of the drawings]
[0013] [Figure 1] FIG. 1 is a block diagram showing an example of the configuration of a semiconductor device at the conceptual stage. [Figure 2] FIG. 2 is a timing chart showing an example of the operation of the semiconductor device shown in FIG. [Figure 3] FIG. 3 is a block diagram illustrating a configuration example of the semiconductor device according to the first embodiment. [Figure 4] FIG. 4 is a timing chart showing an example of the operation of the semiconductor device shown in FIG. [Figure 5] FIG. 5 is a block diagram showing a modification of the semiconductor device according to the first embodiment. [Figure 6] FIG. 6 is a block diagram illustrating a configuration example of a semiconductor device according to the second embodiment. [Figure 7] FIG. 7 is a timing chart showing an example of the operation of the semiconductor device shown in FIG. DETAILED DESCRIPTION OF THE INVENTION
[0014] Hereinafter, embodiments will be described with reference to the drawings. Note that the drawings are simplified, and the technical scope of the embodiments should not be narrowly interpreted based on the description in the drawings. Furthermore, identical elements are given the same reference numerals, and duplicate explanations will be omitted.
[0015] In the following embodiments, when necessary for convenience, the description will be divided into multiple sections or embodiments. However, unless otherwise specified, they are not unrelated to each other, and one is a partial or complete modification, application example, detailed explanation, supplementary explanation, etc. of the other. Furthermore, in the following embodiments, when the number of elements (including the number, numerical value, amount, range, etc.) is mentioned, it is not limited to that specific number, and may be more or less than the specific number, unless otherwise specified or when it is clearly limited to a specific number in principle.
[0016] Furthermore, in the following embodiments, the components (including operational steps, etc.) are not necessarily essential unless otherwise specified or considered to be clearly essential in principle. Similarly, in the following embodiments, when referring to the shape, positional relationship, etc. of components, etc., it is intended to include those that are substantially similar or approximate to the shape, etc., unless otherwise specified or considered to be clearly not essential in principle. The same applies to the above numbers, etc. (including numbers, numerical values, amounts, ranges, etc.).
[0017] <Preliminary review by the inventor> Before describing the details of the semiconductor device according to the first embodiment, a semiconductor device previously studied by the present inventors will be described.
[0018] 1 is a block diagram showing an example of the configuration of a conceptual semiconductor device 5. The semiconductor device 5 is, for example, an SoC (System On Chip), and includes a host computer 51 and a security IP (Intellectual Property) 52.
[0019] The security IP 52 is one of the functional blocks, and performs encryption and decryption processes for data used in the host computer 51 to enhance security. For example, the security IP 52 encrypts plaintext data received from the host computer 51 and returns the encrypted data to the host computer 51, or decrypts the encrypted data received from the host computer 51 and returns the plaintext data to the host computer 51. The security IP 52 also employs a safety mechanism called DCLS, in which duplicated cryptographic modules operate in lockstep as a pair. This allows the semiconductor device 5 to satisfy both security requirements and functional safety requirements.
[0020] Specifically, the security IP 52 includes at least an interface unit (I / F) 53, a control unit 54, a bus 55, a comparator 56, a cryptographic module 57, and a cryptographic module 58.
[0021] The interface unit 53 is a unit that exchanges data with the host computer 51 .
[0022] The control unit 54 performs overall control of the security IP 52. For example, the control unit 54 instructs the cryptographic modules 57 and 58 to encrypt plaintext data and to decrypt encrypted data. The control unit 54 also instructs the comparator 56 to perform a predetermined comparison process. Data (including instructions) is exchanged between the control unit 54 and the cryptographic modules 57 and 58, and the comparator 56, via a bus 55.
[0023] The cryptographic module 57 encrypts plaintext data received from the host computer 51 and decrypts encrypted data received from the host computer 51 in accordance with instructions from the control unit 54. The cryptographic module 58 encrypts plaintext data received from the host computer 51 and decrypts encrypted data received from the host computer 51 in accordance with instructions from the control unit 54. Each of the cryptographic modules 57 and 58 employs, for example, AES encryption technology.
[0024] The encryption module 57 includes at least an encryption device 571 , a decryption device 572 , and a data storage register 573 .
[0025] The encryptor 571 has at least a buffer 5711 and an encryption processor 5712. The buffer 5711 temporarily holds plaintext data received from the host computer 51. The encryption processor 5712 performs encryption processing, for example, using an S-box (Substitution box), on the plaintext data held by the buffer 5711 to generate encrypted data. The decryptor 572 performs decryption processing, for example, using an inverse S-box, on the encrypted data received from the host computer 51 to generate decrypted data (plaintext data).
[0026] The cryptographic module 58 has the same configuration as the cryptographic module 57 and includes at least an encryptor 581 , a decryptor 582 , and a data storage register 583 .
[0027] The encryptor 581 has at least a buffer 5811 and an encryption processor 5812. The buffer 5811 temporarily stores plaintext data received from the host computer 51. The encryption processor 5812 performs encryption processing, for example, using an S-box, on the plaintext data stored in the buffer 5811 to generate encrypted data. The decryptor 582 performs decryption processing, for example, using an inverse S-box, on the encrypted data received from the host computer 51 to generate decrypted data (plaintext data). The encryption module 58 is provided for verifying (comparing) whether the processing result by the encryption module 57 is correct.
[0028] The comparator 56 compares the processing results of the cryptographic modules 57 and 58 in accordance with instructions from the control unit 54. The detailed operations of the cryptographic modules 57 and 58 and the comparator 56 will be described later.
[0029] (Operation of the semiconductor device 5) Next, the operation of the semiconductor device 5 will be described with reference to Fig. 2. Fig. 2 is a timing chart showing an example of the operation of the semiconductor device 5. Note that the following description will be given taking as an example a case where the data format of the communication protocol is composed of a control command CMD and n (n is an integer equal to or greater than 1) blocks of plaintext data PD1 to PDn added to the control command CMD.
[0030] First, the host computer 51 transmits a command CMD instructing encryption processing to the security IP 52 (time t50), and subsequently transmits n blocks of plaintext data PD1 to PDn following the command CMD (times t51 to t56).
[0031] In the security IP 52, the control unit 54 receives and decodes the command CMD transmitted from the host computer 51 via the interface unit 53. This allows the control unit 54 to recognize the instruction content from the host computer 51. The control unit 54 also sequentially receives, via the interface unit 53, plaintext data PD1 to PDn transmitted from the host computer 51 following the command CMD.
[0032] Then, the control unit 54 sequentially transfers the plaintext data PD1 to PDn to both the cryptographic modules 57 and 58 (times t52 to t57).
[0033] In the encryption module 57, pipeline processing of encryption is performed on the plaintext data PD1 to PDn.
[0034] Specifically, in the encryptor 571, the buffer 5711 sequentially temporarily holds the plaintext data PD1 to PDn sequentially transferred from the control unit 54 (times t52 to t57). Then, the encryption processing unit 5712 performs encryption processing on the plaintext data PD1 to PDn sequentially held by the buffer 5711 (times t52 to t57). The encrypted data ED1 to EDn sequentially generated by the encryption processing unit 5712 are sequentially temporarily stored in the data storage register 573 (times t53 to t58).
[0035] Regarding the pipeline processing in more detail, first, the buffer 5711 temporarily holds the plaintext data PD1 transferred from the control unit 54 (time t52). The encryption processing unit 5712 performs encryption processing on the plaintext data PD1 held by the buffer 5711 (time t52). The encrypted data ED1 generated by the encryption processing unit 5712 is temporarily stored in the data storage register 573 (time t53). At this time, the buffer 5711 temporarily holds the plaintext data PD2 transferred next from the control unit 54 (time t53). This allows the encryption processing unit 5712 to immediately encrypt the plaintext data PD2 after encrypting the plaintext data PD1 (time t53). The encrypted data ED2 generated by the encryption processing unit 5712 is temporarily stored (overwritten) in the data storage register 573 (time t54). In the encryption module 57, such pipeline processing is repeated until encryption of the plaintext data PDn is performed.
[0036] In the encryption module 58, in parallel with the encryption module 57, pipeline processing of encryption is performed on the plaintext data PD1 to PDn.
[0037] Specifically, in the encryptor 581, the buffer 5811 sequentially temporarily holds the plaintext data PD1 to PDn sequentially transferred from the control unit 54 (times t52 to t57). Then, the encryption processing unit 5812 performs encryption processing on the plaintext data PD1 to PDn sequentially held by the buffer 5811 (times t52 to t57). The encrypted data ED1 to EDn sequentially generated by the encryption processing unit 5812 are sequentially temporarily stored in the data storage register 583 (times t53 to t58).
[0038] Regarding the pipeline processing in more detail, first, the buffer 5811 temporarily holds the plaintext data PD1 transferred from the control unit 54 (time t52). The encryption processing unit 5812 performs encryption processing on the plaintext data PD1 held by the buffer 5811 (time t52). The encrypted data ED1 generated by the encryption processing unit 5812 is temporarily stored in the data storage register 583 (time t53). At this time, the buffer 5811 temporarily holds the plaintext data PD2 transferred next from the control unit 54 (time t53). This allows the encryption processing unit 5812 to immediately encrypt the plaintext data PD2 after encrypting the plaintext data PD1 (time t53). The encrypted data ED2 generated by the encryption processing unit 5812 is temporarily stored (overwritten) in the data storage register 583 (time t54). In the encryption module 58, such pipeline processing is repeated until encryption of the plaintext data PDn is performed.
[0039] The comparator 56 sequentially compares (times t53 to t58) the encrypted data ED1 to EDn sequentially stored in the data storage register 573 with the encrypted data ED1 to EDn sequentially stored in the data storage register 583. In the example of Fig. 2, the comparison process by the comparator 56 between the encrypted data EDi (i is any integer from 1 to n) stored in the data storage register 573 and the encrypted data EDi stored in the data storage register 583 is represented as CMPi.
[0040] Based on the comparison result by the comparator 56, the control unit 54 determines whether or not the encryption module 57 (encryptor 571) has a malfunction.
[0041] For example, if the processing results of the cryptographic modules 57 and 58 compared by the comparator 56 match, the control unit 54 determines that no failure has occurred in the cryptographic module 57, and transmits the encrypted data ED1 to EDn obtained from the data storage register 573 to the host computer 51 sequentially via the interface unit 53 (times t54 to t59).
[0042] On the other hand, if the processing results of the cryptographic modules 57 and 58 compared by the comparator 56 do not match, the control unit 54 determines that a malfunction has occurred in one of the cryptographic modules 57 and 58, does not send the encrypted data ED1 to EDn to the host computer 51, and interrupts further processing.
[0043] In this way, the semiconductor device 5 performs encryption processing using the security IP 52 equipped with duplicated cryptographic modules, thereby satisfying both security requirements and functional safety requirements.
[0044] However, in the semiconductor device 5, the cryptographic modules must be duplicated to achieve lockstep operation to satisfy the functional safety requirements, which increases the circuit size. Furthermore, in the semiconductor device 5, encryption processing by each of the duplicated cryptographic modules increases the amount of side-channel information compared to encryption processing by a single cryptographic module, which reduces resistance to side-channel attacks. In other words, the semiconductor device 5 still cannot fully satisfy the security requirements.
[0045] Therefore, the semiconductor device 1 according to the first embodiment has been found, which is capable of satisfying both the security requirements and the functional safety requirements while suppressing an increase in the circuit size.
[0046] <First Embodiment> 3 is a block diagram showing a configuration example of the semiconductor device 1 according to the first embodiment. The semiconductor device 1 is, for example, an SoC, and includes a host computer 11 and a security IP 12.
[0047] The security IP 12 is one of the functional blocks, and for enhanced security, performs encryption and decryption processing of data used in the host computer 11. For example, the security IP 12 encrypts plaintext data received from the host computer 11 and returns the encrypted data to the host computer 11, or decrypts the encrypted data received from the host computer 11 and returns the plaintext data to the host computer 11. Furthermore, the security IP 12 achieves operations equivalent to those of a DCLS by using an encryptor and decryptor implemented in a single cryptographic module.
[0048] Specifically, the security IP 12 includes at least an interface unit (I / F) 13 , a control unit 14 , a bus 15 , a comparator 16 , and a cryptographic module 17 .
[0049] The interface unit 13 is a unit that exchanges data with the host computer 11 .
[0050] The control unit 14 performs overall control of the security IP 12. For example, the control unit 14 instructs the cryptographic module 17 to encrypt plaintext data and to decrypt encrypted data. The control unit 14 also instructs the comparator 16 to perform a predetermined comparison process. Data (including instructions) is exchanged between the control unit 14, the cryptographic module 17, and the comparator 16 via a bus 15.
[0051] The cryptographic module 17 encrypts plaintext data received from the host computer 11 and decrypts encrypted data received from the host computer 11 in accordance with instructions from the control unit 14. The cryptographic module 17 employs, for example, AES encryption technology.
[0052] The encryption module 17 includes at least an encryption device 171, a decryption device 172, a selector 173, and a buffer (data storage unit) 174.
[0053] The encryption device 171 has at least a buffer 1711 and an encryption processing unit 1712. The buffer 1711 temporarily holds plaintext data received from the host computer 11. The encryption processing unit 1712 performs encryption processing using, for example, an S-box on the plaintext data held by the buffer 1711 to generate encrypted data. The buffer 174 temporarily holds the plaintext data held by the buffer 1711, i.e., the plaintext data to be encrypted by the encryption processing unit 1712.
[0054] The selector 173 selects and outputs either the encrypted data generated by the encryptor 171 or the encrypted data received from the host computer 11, depending on the operation mode. For example, when the operation mode is the first mode, the selector 173 selects and outputs the encrypted data generated by the encryptor 171, and when the operation mode is the second mode, the selector 173 selects and outputs the encrypted data received from the host computer 11. The operation mode is switched under the control of the control unit 14, which receives an instruction from the host computer 11.
[0055] The decryptor 172 includes at least a buffer 1721 and a decryption processing unit 1722. The buffer 1721 temporarily stores the encrypted data output from the selector 173. The decryption processing unit 1722 performs a decryption process on the encrypted data stored in the buffer 1721, for example, using an inverse element S-box, to generate decrypted data (plaintext data). Here, the decryption processing unit 1722 performs a decryption process on the encrypted data in synchronization with the encryption process on the plaintext data performed by the encryption processing unit 1712. This causes noise (side channel information) generated by the encryption process by the encryption processing unit 1712 to be disturbed by noise generated by the decryption process by the decryption processing unit 1722, thereby improving resistance to side channel attacks.
[0056] The comparator 16 performs a predetermined comparison process in accordance with an instruction from the control unit 14. For example, when the operation mode is the first mode, the comparator 16 compares the plaintext data held by the buffer 174 with the decrypted data generated by the decryptor 172, and when the operation mode is the second mode, the comparator 16 does not perform the comparison process. The detailed operations of the cryptographic module 17 and the comparator 16 will be described later.
[0057] (Operation of the semiconductor device 1) Next, the operation of the semiconductor device 1 will be described with reference to Fig. 4. Fig. 4 is a timing chart showing an example of the operation of the semiconductor device 1. Note that the following description will be given taking as an example a case where the data format of the communication protocol is composed of a control command CMD and n (n is an integer equal to or greater than 1) blocks of plaintext data PD1 to PDn added to the control command CMD.
[0058] First, the host computer 11 transmits a command CMD instructing encryption processing to the security IP 12 (time t10), and subsequently transmits n blocks of plaintext data PD1 to PDn in sequence following the command CMD (times t11 to t16).
[0059] In the security IP 12, the control unit 14 receives and decodes the command CMD transmitted from the host computer 11 via the interface unit 13. As a result, the control unit 14 recognizes the content of the instruction from the host computer 11. Here, the command CMD includes an instruction to encrypt the plaintext data PD1 to PDn, so the control unit 14 sets the operation mode to the first mode. As a result, the selector 173 selects and outputs the output of the encryptor 171. Furthermore, the control unit 14 sequentially receives, via the interface unit 13, the plaintext data PD1 to PDn transmitted from the host computer 11 following the command CMD.
[0060] Then, the control unit 14 sequentially transfers the plaintext data PD1 to PDn to the cryptographic module 17 (times t12 to t17).
[0061] In the cryptographic module 17, pipeline processing of encryption and decryption is performed on the plaintext data PD1 to PDn.
[0062] Specifically, in the encryptor 171, the buffer 1711 sequentially temporarily holds the plaintext data PD1 to PDn sequentially transferred from the control unit 14 (times t12 to t17). Then, the encryption processing unit 1712 performs encryption processing on the plaintext data PD1 to PDn sequentially held by the buffer 1711 (times t12 to t17). The encrypted data ED1 to EDn sequentially generated by the encryption processing unit 1712 is transferred to the decryptor 172 via the selector 173, and sequentially temporarily held by the buffer 1721 (times t13 to t18). In parallel with this, the plaintext data PD1 to PDn sequentially held by the buffer 1711 of the encryptor 171 is sequentially temporarily held (saved) by the buffer 174 (times t13 to t18).
[0063] In the decryptor 172, the decryption processing unit 1722 performs decryption processing on the encrypted data ED1 to EDn sequentially stored in the buffer 1721 to sequentially generate decrypted data PD1 to PDn (times t13 to t18). Here, the decryption processing unit 1722 performs decryption processing of the encrypted data in synchronization with encryption processing of the plaintext data by the encryption processing unit 1712 provided in the encryptor 171. This improves resistance to side channel attacks because noise (side channel information) generated by the encryption processing by the encryption processing unit 1712 is disturbed by noise generated by the decryption processing by the decryption processing unit 1722.
[0064] Regarding the pipeline processing in more detail, first, the buffer 1711 temporarily holds the plaintext data PD1 transferred from the control unit 14 (time t12). The encryption processing unit 1712 performs encryption processing on the plaintext data PD1 held by the buffer 1711 (time t12). The encrypted data ED1 generated by the encryption processing unit 1712 is transferred to the decryptor 172 via the selector 173 and temporarily held by the buffer 1721 (time t13). The decryption processing unit 1722 performs decryption processing on the encrypted data ED1 held by the buffer 1721 to generate decrypted data PD1 (time t13).
[0065] At this time, the buffer 174 temporarily holds the plaintext data PD1 held by the buffer 1711 of the encryptor 171 (time t13). At this time, the buffer 1711 also temporarily holds the plaintext data PD2 transferred next from the control unit 14 (time t13). This allows the encryption processing unit 1712 to encrypt the plaintext data PD2 immediately after encrypting the plaintext data PD1 (time t13). The encrypted data ED2 generated by the encryption processing unit 1712 is transferred to the decryptor 172 via the selector 173 and temporarily held by the buffer 1721 (time t14). The decryption processing unit 1722 decrypts the encrypted data ED2 held by the buffer 1721 to generate decrypted data PD2 (time t14).
[0066] In the cryptographic module 17, such pipeline processing is repeated until the plaintext data PDn is encrypted and decrypted.
[0067] The comparator 16 sequentially compares the plaintext data PD1 to PDn sequentially held by the buffer 174 with the decrypted data PD1 to PDn sequentially generated by the decoder 172 (times t13 to t18). In the example of Fig. 4, the comparison process by the comparator 16 between the plaintext data PDi held by the buffer 174 and the decrypted data PDi generated by the decoder 172 is represented as CMPi.
[0068] Based on the comparison result by the comparator 16, the control unit 14 determines whether or not there is a failure in the cryptographic module 17 (the encryptor 171 and the decryptor 172).
[0069] For example, if the plaintext data PD1 to PDn before encryption held by the buffer 174 and the decrypted data PD1 to PDn generated in the decryptor 172 match, the control unit 14 determines that no malfunction has occurred in the cryptographic module 17, and transmits the encrypted data ED1 to EDn generated in the encryption unit 171 sequentially to the host computer 11, for example, from the buffer 1721 via the interface unit 13 (times t14 to t19).
[0070] On the other hand, if the plaintext data PD1-PDn before encryption held in the buffer 174 and the decrypted data PD1-PDn generated by the decryptor 172 do not match, the control unit 14 determines that a fault has occurred in the cryptographic module 17 (at least one of the encryptor 171 and the decryptor 172), does not transmit the encrypted data ED1-EDn to the host computer 11, and suspends subsequent processing. Note that in this case, since the fault occurring in the cryptographic module 17 may be an accidental fault, the control unit 14 may again encrypt the plaintext data PD1-PDn, decrypt the encrypted data ED1-EDn, compare the plaintext data PD1-PDn with the decrypted data PD1-PDn, and determine the fault based on the comparison result. However, if it is still determined that a fault has occurred in the cryptographic module 17 after a predetermined number of repetitions, the fault occurring in the cryptographic module 17 is determined to be a permanent fault.
[0071] As described above, the semiconductor device 1 according to the present embodiment achieves the same operation as a DCLS using an encryptor and a decryptor provided in a single cryptographic module without using duplicated cryptographic modules, thereby suppressing an increase in circuit size. Furthermore, the semiconductor device 1 according to the present embodiment synchronizes the encryption process by the encryptor with the decryption process by the decryptor, thereby enabling noise (side channel information) generated by the encryption process to be disrupted by noise generated by the decryption process, thereby improving resistance to side channel attacks such as DPA attacks and CPA attacks. In other words, the semiconductor device 1 according to the present embodiment can satisfy both security requirements and functional safety requirements while suppressing an increase in circuit size.
[0072] The control unit 14 may be either a hardware sequencer or a CPU.
[0073] Furthermore, the interface unit 13 may have a register that temporarily stores data exchanged between the host computer 11 and the control unit 14 of the security IP 12. In this case, for example, in the security IP 12, the interface unit 13 first receives and temporarily stores plaintext data transmitted from the host computer 11, and the control unit 14 receives and decodes the plaintext data stored by the interface unit 13.
[0074] (Modification of Semiconductor Device 1) 5 is a block diagram showing a semiconductor device 1a, which is a modified example of the semiconductor device 1. Compared to the semiconductor device 1, the semiconductor device 1a further includes a cryptographic module 18 having at least an encryptor 181 and a decryptor 182. The other configuration of the semiconductor device 1a is the same as that of the semiconductor device 1, and therefore a description thereof will be omitted.
[0075] The semiconductor device 1a does not use both cryptographic modules 17 and 18 to achieve the operation of DCLS, but can achieve the same operation as DCLS using only one cryptographic module 17, allowing the other cryptographic module 18 to be used for encrypted communication of a different application. This allows the semiconductor device 1a to improve the computing performance of the entire security function.
[0076] <Embodiment 2> 6 is a block diagram showing a configuration example of a semiconductor device 2 according to embodiment 2. The semiconductor device 2 is, for example, an SoC, and includes a host computer 21 and a security IP 22. The host computer 21 and the security IP 22 in the semiconductor device 2 correspond to the host computer 11 and the security IP 12 in the semiconductor device 1, respectively.
[0077] The security IP 22 includes an interface unit 23, a control unit 24, a bus 25, a comparator 26, a cryptographic module 27, and a cryptographic module 28. The interface unit 23, the control unit 24, the bus 25, the comparator 26, and the cryptographic module 27 in the semiconductor device 2 correspond to the interface unit 13, the control unit 14, the bus 15, the comparator 16, and the cryptographic module 17 in the semiconductor device 1, respectively.
[0078] The encryption module 27 at least includes an encryption device 271, a decryptor 272, a selector 273, and a buffer (data storage unit) 274. The encryption device 271 includes at least a buffer 2711 and an encryption processing unit 2712. The decryptor 272 includes at least a buffer 2721 and a decryption processing unit 2722. The encryption device 271, the decryptor 272, the selector 273, and the buffer 274 in the semiconductor device 2 correspond to the encryption device 171, the decryptor 172, the selector 173, and the buffer 174 in the semiconductor device 1, respectively. The buffer 2711 and the encryption processing unit 2712 in the encryption device 271 correspond to the buffer 1711 and the encryption processing unit 1712 in the encryption device 171, respectively. The buffer 2721 and the decoding processing unit 2722 in the decoder 272 correspond to the buffer 1721 and the decoding processing unit 1722 in the decoder 172, respectively.
[0079] The cryptographic module 28 at least includes an encryptor 281, a decryptor 282, and a selector 283. The decryptor 282 at least includes a buffer 2821 and a decryption processor 2822. The encryptor 281 performs encryption processing, for example, using an S-box, on plaintext data received from the host computer 21 to generate encrypted data. The selector 283 selects and outputs either the encrypted data generated by the encryptor 271 of the cryptographic module 27 or the encrypted data received from the host computer 21, depending on the operating mode. For example, when the operating mode is the first mode, the selector 283 selects and outputs the encrypted data generated by the encryptor 271 of the cryptographic module 27, and when the operating mode is the second mode, the selector 283 selects and outputs the encrypted data received from the host computer 21. In the decryptor 282, the buffer 2821 temporarily holds the encrypted data output from the selector 283. The decryption processing unit 2822 generates decrypted data (plaintext data) by performing decryption processing using, for example, an inverse S-box on the encrypted data held in the buffer 2821. Here, both of the decryption processing units 2722 and 2822 perform decryption processing of the encrypted data in synchronization with the encryption processing of the plaintext data by the encryption processing unit 2712. This causes noise (side channel information) generated by the encryption processing by the encryption processing unit 2712 to be disturbed by noise generated by the decryption processing of each of the decryption processing units 2722 and 2822, thereby further improving resistance to side channel attacks.
[0080] Comparator 26 performs a predetermined comparison process in accordance with instructions from control unit 24. For example, when the operation mode is the first mode, comparator 26 compares the plaintext data held by buffer 274 with the decrypted data generated by decryptor 272 and the decrypted data generated by decryptor 282, and does not perform the comparison process when the operation mode is the second mode. The detailed operations of cryptographic modules 27, 28 and comparator 26 will be described later.
[0081] (Operation of semiconductor device 2) Next, the operation of the semiconductor device 2 will be described with reference to Fig. 7. Fig. 7 is a timing chart showing an example of the operation of the semiconductor device 2. Note that the following description will be given taking as an example a case where the data format of the communication protocol is composed of a control command CMD and n (n is an integer equal to or greater than 1) blocks of plaintext data PD1 to PDn added to the control command CMD.
[0082] First, the host computer 21 transmits a command CMD instructing encryption processing to the security IP 22 (time t20), and subsequently transmits n blocks of plaintext data PD1 to PDn in sequence following the command CMD (times t21 to t26).
[0083] In the security IP 22, the control unit 24 receives and decodes the command CMD transmitted from the host computer 21 via the interface unit 23. As a result, the control unit 24 recognizes the content of the instruction from the host computer 21. Here, since the command CMD includes an instruction to encrypt the plaintext data PD1 to PDn, the control unit 24 sets the operation mode to the first mode. As a result, both of the selectors 273 and 283 select and output the output of the encryptor 271. Furthermore, the control unit 24 sequentially receives, via the interface unit 23, the plaintext data PD1 to PDn transmitted from the host computer 21 following the command CMD.
[0084] Then, the control unit 24 sequentially transfers the plaintext data PD1 to PDn to the cryptographic module 27 (times t22 to t27).
[0085] The encryption module 27 performs pipeline processing for encryption and decryption of the plaintext data PD1 to PDn. The encryption module 28 also performs pipeline processing for decryption of the encrypted data ED1 to EDn.
[0086] Specifically, in the encryptor 271, the buffer 2711 sequentially temporarily holds the plaintext data PD1 to PDn sequentially transferred from the control unit 24 (times t22 to t27). Then, the encryption processing unit 2712 performs encryption processing on the plaintext data PD1 to PDn sequentially held by the buffer 2711 (times t22 to t27). The encrypted data ED1 to EDn sequentially generated by the encryption processing unit 2712 is transferred to the decryptor 272 via the selector 273 and sequentially temporarily held by the buffer 2721 (times t23 to t28), and is also transferred to the decryptor 282 via the selector 283 and sequentially temporarily held by the buffer 2821 (times t23 to t28). In parallel with this, the plaintext data PD1 to PDn sequentially held by the buffer 2711 of the encryptor 271 is sequentially temporarily held (saved) by the buffer 274 (times t23 to t28).
[0087] In the decryptor 272, the decryption processing unit 2722 performs a decryption process on the encrypted data ED1 to EDn sequentially stored in the buffer 2721 to sequentially generate decrypted data PD1 to PDn (time t23 to t28). Similarly, in the decryptor 282, the decryption processing unit 2822 performs a decryption process on the encrypted data ED1 to EDn sequentially stored in the buffer 2821 to sequentially generate decrypted data PD1 to PDn (time t23 to t28). Here, both of the decryption processing units 2722 and 2822 perform the decryption process on the encrypted data in synchronization with the encryption process of the plaintext data by the encryption processing unit 2712. As a result, noise (side channel information) generated by the encryption process by the encryption processing unit 2712 is disturbed by noise generated by the decryption processes of the decryption processing units 2722 and 2822, thereby further improving resistance to side channel attacks.
[0088] Regarding the pipeline processing in more detail, the buffer 2711 first temporarily holds the plaintext data PD1 transferred from the control unit 24 (time t22). The encryption processing unit 2712 performs encryption processing on the plaintext data PD1 held by the buffer 2711 (time t22). The encrypted data ED1 generated by the encryption processing unit 2712 is transferred to the decryptor 272 via the selector 273 and temporarily held by the buffer 2721 (time t23), and is also transferred to the decryptor 282 via the selector 283 and temporarily held by the buffer 2821 (time t23). The decryption processing unit 2722 performs decryption processing on the encrypted data ED1 held by the buffer 2721 to generate decrypted data PD1 (time t23). Furthermore, the decryption processing unit 2822 performs decryption processing on the encrypted data ED1 held by the buffer 2821 to generate decrypted data PD1 (time t23).
[0089] At this time, the buffer 274 temporarily holds the plaintext data PD1 held by the buffer 2711 of the encryptor 271 (time t23). At this time, the buffer 2711 also temporarily holds the plaintext data PD2 transferred next from the control unit 24 (time t23). This allows the encryption processing unit 2712 to encrypt the plaintext data PD2 immediately after encrypting the plaintext data PD1 (time t23). The encrypted data ED2 generated by the encryption processing unit 2712 is transferred to the decryptor 272 via the selector 273 and temporarily held by the buffer 2721 (time t24), and is also transferred to the decryptor 282 via the selector 283 and temporarily held by the buffer 2821 (time t24). The decryption processing unit 2722 decrypts the encrypted data ED2 held by the buffer 2721 to generate decrypted data PD2 (time t24). Furthermore, the decryption processing unit 2822 performs decryption processing on the encrypted data ED2 held in the buffer 2821 to generate decrypted data PD2 (time t24).
[0090] In the cryptographic modules 27 and 28, such pipeline processing is repeated until the plaintext data PDn is encrypted and decrypted.
[0091] The comparator 26 sequentially compares the plaintext data PD1 to PDn sequentially held by the buffer 274 with the decrypted data PD1 to PDn sequentially generated by the decoder 272 and the decrypted data PD1 to PDn sequentially generated by the decoder 282 (times t23 to t28). In the example of Fig. 7, the comparison process by the comparator 26 of the plaintext data PDi held by the buffer 274 with the decrypted data PDi generated by the decoder 272 and the decrypted data PDi generated by the decoder 282 is represented as CMPi.
[0092] Based on the comparison result by the comparator 26, the control unit 24 determines whether or not there is a failure in the cryptographic module 27 (encryptor 271 and decryptor 272) and the cryptographic module 28 (decryptor 282).
[0093] For example, when the plaintext data PD1 to PDn before encryption held by the buffer 274, the decrypted data PD1 to PDn generated in the decryptor 272, and the decrypted data PD1 to PDn generated in the decryptor 282 match, respectively, the control unit 24 determines that no failure has occurred in any of the encryption device 271, the decryptor 272, and the decryptor 282. In this case, the control unit 24 sequentially transmits the encrypted data ED1 to EDn generated in the encryption device 271 from, for example, the buffer 2721 to the host computer 21 via the interface unit 23 (times t24 to t29).
[0094] Furthermore, when the plaintext data PD1 to PDn before encryption held by the buffer 274 and the decrypted data PD1 to PDn generated in the decryptor 272 match, respectively, even if they do not match the decrypted data PD1 to PDn generated in the decryptor 282, the control unit 24 determines that no failure has occurred in at least the encryption device 271 and the decryptor 272. In this case, the control unit 24 sequentially transmits the encrypted data ED1 to EDn generated in the encryption device 271 to the host computer 21, for example, from the buffer 2721 via the interface unit 23. At this time, the control unit 24 determines that a failure has occurred in the decryptor 282, and performs control so as not to adopt the output of the decryptor 282.
[0095] Furthermore, when the plaintext data PD1 to PDn before encryption held by the buffer 274 and the decrypted data PD1 to PDn generated in the decryptor 282 match, respectively, even if they do not match the decrypted data PD1 to PDn generated in the decryptor 272, the control unit 24 determines that no failure has occurred in at least the encryption device 271 and the decryptor 282. In this case, the control unit 24 sequentially transmits the encrypted data ED1 to EDn generated in the encryption device 271 to the host computer 21, for example, from the buffer 2821 via the interface unit 23. At this time, the control unit 24 determines that a failure has occurred in the decryptor 272, and performs control so as not to adopt the output of the decryptor 272.
[0096] On the other hand, if the decrypted data PD1 to PDn generated in the decryptor 272 and the decrypted data PD1 to PDn generated in the decryptor 282 match but do not match the plaintext data PD1 to PDn before encryption held in the buffer 274, it is determined that a fault has occurred in the encryption device 271. In this case, the control unit 24 does not transmit the encrypted data ED1 to EDn to the host computer 21 and suspends subsequent processing. Note that in this case, since the fault occurring in the encryption device 271 may be an accidental fault, the control unit 24 may again encrypt the plaintext data PD1 to PDn, decrypt the encrypted data ED1 to EDn, compare the plaintext data PD1 to PDn with the decrypted data PD1 to PDn, and determine whether there is a fault based on the comparison result. However, if it is still determined that a fault has occurred in the encryption device 271 after repeating this process a predetermined number of times, it is determined that the fault occurring in the encryption device 271 is a permanent fault. In this case, for example, the encryptor 281 provided in the cryptographic module 28 may be used instead of the encryptor 271 .
[0097] In this manner, the semiconductor device 2 according to the present embodiment can identify whether a failure has occurred in the encryption device or the decryptor by comparing plaintext data with the multiple decrypted data generated by each of the multiple decryptors. Here, if it is determined that a failure has occurred in a decryptor provided in, for example, a cryptographic module for verification (e.g., cryptographic module 28), the failure can be ignored as a simulated failure, thereby suppressing a decrease in throughput due to retries after the failure detection. Furthermore, the semiconductor device 2 according to the present embodiment synchronizes the encryption process by the encryption device and the decryption process by each of the multiple decryptors, thereby enabling noise (side-channel information) generated by the encryption process to be disrupted by noise generated by the multiple decryption processes, thereby further improving resistance to side-channel attacks such as DPA attacks and CPA attacks.
[0098] In the present embodiment, the case where fault detection is performed by comparing two sets of decrypted data generated using one encryption device 271 and two decryptors 272, 282 with plaintext data has been described as an example, but the present invention is not limited to this. For example, if three or more cryptographic modules each equipped with a decryptor are implemented, fault detection may be performed by comparing three or more sets of decrypted data generated using one encryption device 271 and three or more decryptors with plaintext data. This further improves resistance to side channel attacks.
[0099] The invention made by the inventor has been specifically described above based on the embodiments, but it goes without saying that the present invention is not limited to the embodiments already described, and various modifications are possible within the scope of the gist of the invention.
[0100] In the above-mentioned first and second embodiments, a case where plaintext data supplied from the outside (host computer) is compared with data obtained by encrypting the plaintext data with an encryption device and then decrypting the plaintext data with a decryptor has been described as an example, but the present invention is not limited to this. For example, the same effect can be achieved when encrypted data supplied from the outside (host computer) is compared with data obtained by decrypting the encrypted data with a decryptor and then encrypting the encrypted data with an encryption device.
[0101] Furthermore, the present disclosure can be realized by causing a CPU (Central Processing Unit) to execute a computer program, in whole or in part, the security IP.
[0102] The above-described program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable media or tangible storage media include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, CD-ROM, digital versatile disc (DVD), Blu-ray disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable media or communication media include electrical, optical, acoustic, or other forms of propagated signals. [Explanation of symbols]
[0103] 1. Semiconductor device 1a Semiconductor device 2. Semiconductor Devices 5. Semiconductor Devices 11 Host Computer 12 Security IP 13 Interface section 14 Control Unit 15 Bus 16 Comparators 17 Cryptographic Module 18 Cryptographic Module 21 Host Computer 22 Security IP 23 Interface section 24 Control Unit 25 Bus 26 Comparator 27 Cryptographic Module 28 Cryptographic Module 51 Host Computer 52 Security IP 53 Interface section 54 Control Unit 55 Bus 56 Comparator 57 Cryptographic Module 58 Cryptographic Module 171 Encryptor 172 Decoder 173 Selector 174 buffers 181 Encryptor 182 Decoder 271 Encryptor 272 Decoder 273 Selector 274 buffers 281 Encryptor 282 Decoder 283 Selector 571 Encryptor 572 Decoder 573 Data storage register 581 Encryptor 582 Decoder 583 Data storage register 1711 buffer 1712 Encryption processing unit 1721 buffers 1722 Decryption processing unit 2711 buffers 2712 Encryption processing unit 2721 buffers 2722 Decoding processing unit 2821 buffers 2822 Decoding processing unit 5711 buffer 5712 Encryption processing unit 5811 buffer 5812 Encryption processing unit
Claims
1. a first encryption device having a first encryption processing unit that performs encryption processing on plaintext data input from outside to generate first encrypted data; a first decoder having a first decryption processing unit that performs a decryption process on the first encrypted data generated by the first encryption device in synchronization with the encryption process in the first encryption device to generate first decrypted data; a comparator that compares the plaintext data with the first decrypted data corresponding to the plaintext data; a control unit that determines whether the first encryption device and the first decryption device have any faults based on the comparison result by the comparator; A semiconductor device comprising: In the first encryption device, the first encryption processing unit performs encryption processing on the plurality of pieces of plaintext data sequentially input from an external device to sequentially generate the plurality of pieces of first encrypted data; In the first decoder, the first decryption processing unit performs a decryption process on the plurality of first encrypted data sequentially generated in the first encryptor to sequentially generate a plurality of first decrypted data; the comparator sequentially compares the plurality of plaintext data with the plurality of first decrypted data corresponding to the plurality of plaintext data; the control unit determines whether the first encryption device and the first decryption device have a failure based on the comparison result by the comparator. Semiconductor device.
2. a first encryption device having a first encryption processing unit that performs encryption processing on plaintext data input from outside to generate first encrypted data; a first decoder having a first decryption processing unit that performs a decryption process on the first encrypted data generated by the first encryption device in synchronization with the encryption process in the first encryption device to generate first decrypted data; a comparator that compares the plaintext data with the first decrypted data corresponding to the plaintext data; a control unit that determines whether the first encryption device and the first decryption device have any faults based on the comparison result by the comparator; A semiconductor device comprising: a second decoder having a second decryption processing unit that performs a decryption process on the first encrypted data generated by the first encryption device in synchronization with the encryption process in the first encryption device to generate second decrypted data; the comparator is configured to compare the plaintext data, the first decrypted data corresponding to the plaintext data, and the second decrypted data corresponding to the plaintext data; the control unit determines whether the first encryption device, the first decryption device, and the second decryption device have any failures based on the comparison result by the comparator. Semiconductor device.
3. further comprising a data storage unit for storing the plaintext data; the comparator compares the plaintext data held by the data holding unit with the first decrypted data corresponding to the plaintext data and the second decrypted data corresponding to the plaintext data. The semiconductor device according to claim 2 .
4. the control unit determines that no failure has occurred in any of the first encryption device, the first decryption device, and the second decryption device when the comparison by the comparator shows that the plaintext data, the first decryption data corresponding to the plaintext data, and the second decryption data corresponding to the plaintext data match; determines that a failure has occurred in the second decryption device when only the plaintext data and the first decryption data corresponding to the plaintext data match; determines that a failure has occurred in the first decryption device when only the plaintext data and the second decryption data corresponding to the plaintext data match; and determines that a failure has occurred in the first encryption device when only the first decryption data corresponding to the plaintext data and the second decryption data corresponding to the plaintext data match. The semiconductor device according to claim 2 .
5. a first cryptographic module including at least the first encryptor and the first decryptor; a second encryption module including at least a second encryption device having the same configuration as the first encryption device and the second decryptor; Equipped with The semiconductor device according to claim 2 .
6. the first encryption processing unit is configured to perform encryption processing using an S-box (Substitution box), The first decoding processing unit and the second decoding processing unit are both configured to perform a decoding process using an inverse S-box. The semiconductor device according to claim 2 .
7. When the control unit determines that a failure has occurred in the first encryptor, the control unit again performs the encryption process on the plaintext data, the decryption process on the first encrypted data generated by the encryption process, the comparison between the plaintext data and the first decrypted data and the second decrypted data generated by the decryption process, and the failure determination for the first encryptor based on the comparison result. The semiconductor device according to claim 2 .
8. a first cryptographic module including at least the first encryptor and the first decryptor; a second encryption module including at least a second encryption device having the same configuration as the first encryption device and the second decryptor; Equipped with the control unit is configured to use the second encryptor instead of the first encryptor if it continues to determine that a fault has occurred in the first encryptor even after repeating a predetermined number of steps: encrypting the plaintext data; decrypting the first encrypted data generated by the encryption process; comparing the plaintext data with the first decrypted data and the second decrypted data generated by the decryption process; and determining whether a fault has occurred in the first encryptor based on the comparison result. The semiconductor device according to claim 7 .
9. a first selector that selects either the first encrypted data generated in the first encryptor or first external encrypted data that is encrypted data different from the first encrypted data and input from outside, in accordance with an operation mode including at least a first mode and a second mode, and outputs the selected data to the first decryptor; a second selector that selects, in accordance with the operation mode, either the first encrypted data generated in the first encryptor or second external encrypted data that is encrypted data different from the first encrypted data and input from outside, and outputs the selected data to the second decryptor; when the operation mode is the first mode, the first selector selects and outputs the first encrypted data, the first decryptor performs a decryption process on the first encrypted data in synchronization with the encryption process in the first encryptor to generate the first decrypted data, the second selector selects and outputs the first encrypted data, the second decryptor performs a decryption process on the first encrypted data in synchronization with the encryption process in the first encryptor to generate the second decrypted data, and the comparator compares the plaintext data, the first decrypted data corresponding to the plaintext data, and the second decrypted data corresponding to the plaintext data, when the operation mode is the second mode, the first selector selects and outputs the first external encrypted data, the first decoder performs a decryption process on the first external encrypted data to generate first external decrypted data, the second selector selects and outputs the second external encrypted data, the second decoder performs a decryption process on the second external encrypted data to generate second external decrypted data, and the comparator does not perform a comparison using the first external decrypted data and the second external decrypted data. The semiconductor device according to claim 2 .
10. In the first encryption device, the first encryption processing unit performs encryption processing on the plurality of pieces of plaintext data sequentially input from an external device to sequentially generate the plurality of pieces of first encrypted data; In the first decoder, the first decryption processing unit performs a decryption process on the plurality of first encrypted data sequentially generated in the first encryptor to sequentially generate a plurality of first decrypted data; In the second decoder, the second decryption processing unit performs a decryption process on the plurality of first encrypted data sequentially generated in the first encryptor to sequentially generate a plurality of second decrypted data; the comparator sequentially compares the plurality of plaintext data, the plurality of first decrypted data corresponding to the plurality of plaintext data, and the plurality of second decrypted data corresponding to the plurality of plaintext data; the control unit determines whether the first encryption device, the first decryption device, and the second decryption device have any failures based on the comparison result by the comparator. The semiconductor device according to claim 2 .
11. using a first encryption device to encrypt plaintext data input from outside to generate first encrypted data; using a first decryptor, performing a decryption process on the first encrypted data generated by the first encryptor in synchronization with the encryption process in the first encryptor to generate first decrypted data; comparing the plaintext data with the first decrypted data corresponding to the plaintext data; determining whether the first encryption device and the first decryption device have any faults based on the comparison result; A method for controlling a semiconductor device, comprising: In the generation of the first cipher data, the first cipher device encrypts a plurality of the plaintext data sequentially input from an external device to sequentially generate a plurality of the first cipher data; In the generation of the first decrypted data, the first decryptor performs a decryption process on the plurality of first encrypted data sequentially generated by the first encryptor to sequentially generate the plurality of first decrypted data; In the comparison between the plaintext data and the first decrypted data, a plurality of pieces of the plaintext data are sequentially compared with a plurality of pieces of the first decrypted data corresponding to the plurality of pieces of the plaintext data; the failure determination is performed based on the results of the sequential comparison to determine whether the first encryption device and the first decryption device are faulty. A method for controlling a semiconductor device.
12. using a first encryption device to encrypt plaintext data input from outside to generate first encrypted data; using a first decryptor, performing a decryption process on the first encrypted data generated by the first encryptor in synchronization with the encryption process in the first encryptor to generate first decrypted data; using a second decryptor, performing a decryption process on the first encrypted data generated by the first encryptor in synchronization with the encryption process in the first encryptor to generate second decrypted data; comparing the plaintext data, the first decrypted data corresponding to the plaintext data, and the second decrypted data corresponding to the plaintext data; determining whether or not there is a failure in the first encryption device, the first decryption device, and the second decryption device based on the comparison result; A method for controlling a semiconductor device.
Citation Information
Patent Citations
Fault detector
JP1989099341A
Storage system
JP2006319589A
Fast AES Using a Modification Key
JP2018514816A
System and method for efficiently backing up large data sets
JP2022547896A
Storage system
US20060259786A1