Method for secure storage of sensitive data in a silicon chip integrated system storage, in particular a smart carp, and integrated system therefor
Abstract
The present invention relates to a method for safely storing so-called sensitive data, such as a fragment of an encryption key, in the memory (M) of an embedded microchip system, especially a smart card (CP). The memory (M) includes two physically different storage devices (1, 2), such as a "ROM" type permanent memory (1) and a "EEPROM" type second reprogrammable memory (2). The sensitive data segment is divided into at least two parts (d, d') according to a designated logical structure, and each part is stored in one of different storage devices (1, 2). An additional piece of verification data, a checksum or hash data can also be stored in the first storage device (1) at the same time as the first sensitive data part (d). The invention also relates to an embedded microchip system, especially a smart card (CP).

Term
Term ended
Expired 8 June 2021, 5.3 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
11 claims: 2 independent, 9 dependent
- 1一个在嵌入式微芯片系统存储器中安全存储一段所谓的敏感数据的方法,上述嵌入式微芯片系统包括至少两个物理上不同的存储装置,其特征在于根据指定逻辑结构将上述敏感数据片段分成至少两个部分(d,d′),上述各个分割部分(d,d′)被存储在上述物理上不同的存储装置(1,2)中的一个内。
- 2如权利要求1所述的方法,其特征在于,当上述敏感数据片段被分成至少两个部分(d,d′)时,上述敏感数据片段构成一个单独的秘密,并且各个上述分割部分被存储在上述物理上不同的存储装置(1,2)中的一个内。
- 3如权利要求1所述的方法,其特征在于,上述敏感数据片段被分成至少两个部分(d,d′),其中第一部分(d)构成一个第一秘密并且根据上述第一部分(d)导出上述数感数据片断的各另外部分以便构成各另外秘密,并且各个上述各分割部分被存储在上述物理上不同的存储装置(1,2)中的一个内。
- 4如权利要求1所述的方法,其特征在于上述敏感数据片段是一个长度等于指定字节数量的二进制字并且被加以分割以便被存储在两个物理上不同的存储装置(1,2)中,一个第一部分是由长度与上述敏感数据片段相同的字节模块(B1-B8)构成的第一二进制字(d),上述第一部分(d)包含一个由正确字节和被改变的字节(O1-O8)构成并且按照预定结构被分布在上述字中的字节串,一个第二部分是长度等于上述被改变的字节(O1-O8)的数量并且由和上述被改变的字节(O1-O8)一一对应的字节(O′1-O′8)构成的第二二进制字(d′),因而可以校正这些被改变的字节(O1-O8),并且根据上述第一部分(d)和第二部分(d′)可以重构上述敏感数据片段。
- 5如权利要求4所述的方法,其特征在于上述敏感数据片段是一个加密密钥。
- 6如权利要求1所述的方法,其特征在于,上述敏感数据片段被分成第一部分(d)和第二部分(d′)并且分别被存储在物理上不同的第一存储装置(1)和第二存储装置(2)中,对上述敏感数据执行一个被称作校验和的运算并且同时存储上述第二部分(d′),校验和运算的结果具有信息数据片段的形式,上述信息数据被存储在上述第一存储装置(1)中,该方法还包括步骤读取上述信息数据,对上述敏感数据执行一个附加校验和运算,每当使用上述敏感数据时比较上述读取的信息数据和执行上述附加校验和运算的结果以证实该敏感数据的完整性。
- 7如权利要求1所述的方法,其特征在于,上述敏感数据片段被分成第一部分(d)和第二部分(d′)并且分别被存储在物理上不同的第一存储装置(1)和第二存储装置(2)中,伴随着存储上述第二部分(d′)对上述敏感数据执行一个被称作杂凑的运算,其结果具有信息数据片段(H)的形式,上述信息数据(H)被存储在上述第一存储装置(1)中,该方法包含读取上述信息数据(H),对上述敏感数据执行一个附加杂凑运算,每当使用上述敏感数据时比较上述读取的信息数据和执行上述附加杂凑运算的结果以证实其完整性。
- 8如权利要求7所述的方法,其特征在于通过对上述敏感数据片段使用被称为″SHA-1″的散列算法来获得上述杂凑运算。
- 9配备存储至少一个所谓的敏感数据片段的存储装置的嵌入式微芯片系统,上述存储装置包括至少两个物理上不同的存储设备,其特征在于,当上述敏感数据片段被分成至少两个具有指定结构的部分(d,d′)时,每个上述存储设备均存储上述敏感数据部分(d,d′)中的一个。
- 10如权利要求9所述的系统,其特征在于上述存储装置(M)包括一个所谓的″ROM″型第一只读存储设备,和一个所谓的″EEPROM″型第二电可擦除可再编程只读存储设备,并且每个上述第一存储设备和第二存储设备均存储上述敏感数据片段的上述分割部分(d,d′)中的一个。
- 11如权利要求9所述的系统,其特征在于该系统由一个智能卡(CP)构成。
Independent claims11
59 paragraphs, as filed
Method for safely storing sensitive data in embedded microchip system, especially smart card memory, and embedded system implementing the method
Technical field
The invention relates to a method for safely storing sensitive data in the memory of an embedded microchip system.
More specifically, it involves smart cards.
The invention also relates to an embedded system implementing the method.
Background technique
Within the scope of the present invention, the term "embedded system" refers to various systems or devices that use a microchip including data storage and data processing devices. The microchip is usually composed of a microprocessor or a microcontroller. In particular, this kind of embedded system can be constituted by a smart card.
Understand the term "sensitive" in its most general aspect. It involves all the secret or confidential data stored in one or more types of smart card-equipped memories, including encryption algorithms, secret encryption keys, identification data or confidential information, and so on. This type of data is hereinafter referred to as "secret".
The present invention relates particularly but not exclusively to the storage of secret keys stored for the secure pre-initialization of smart cards. In fact, it is well known that security-related functions are transferred to smart cards. Here again, the term "security" should be understood in a broad sense. This term actually includes different concepts: confidentiality, authentication, and so on.
Hereinafter, in order to illustrate each concept without any limitation on its scope, we will consider the best application of the present invention, unless otherwise proposed.
In the prior art, the secrets contained in the smart card are usually stored linearly in the same storage area. Specifically, the secret is stored in a permanent read-only memory ("ROM") or semi-permanent, that is, an electrically erasable programmable read-only memory of the "EEPROM" type. The memory of the microchip is vulnerable to hacker attacks, and attacks are becoming more and more sophisticated.
"Dumping" (or copying) of "ROM" memory is an old problem of smart cards.
At present, most of the known attacks are aimed at "EEPROM" type memory that usually contains so-called sensitive data.
Summary of the invention
The objective of the present invention is to eliminate some of the aforementioned disadvantages of prior art devices.
The object of the present invention is to provide a method for safely storing sensitive data in a smart card memory, and more generally, an embedded microchip system memory.
The invention also relates to an embedded microchip system for realizing the method. Microchips include data storage and data processing devices that are generally controlled by an operating system (or "OS").
To this end, according to an advantageous feature, the secret is physically and logically "divided" into several storage devices equipped with microchips.
In an advantageous embodiment, the memory of the aforementioned microchip is divided into different parts, the first part is composed of a "ROM" type memory, usually a permanent ROM, and the second part is composed of an "EEPROM" type memory, usually a semi-permanent EEPROM constitute.
According to the first variant of the method of the present invention, the same secret is "split" in two or more physically different memory sections.
Specifically, in the optimal application field of the present invention, when the "EEPROM" type memory part does not contain any other data except the data programmed in by the entity called the "chip manufacturer", this method allows the The smart card is authenticated during the initialization phase.
Within the scope of the present invention, the term "pre-initialization" has a general meaning. It particularly relates to the manufacturing stage of traditional smart cards, or the stage before the so-called initialization stage of open smart cards.
According to another advantageous embodiment, most of the data constituting a secret is stored in the "ROM". Only a small part of this data is stored in "EEPROM".
According to this additional feature of the present invention, most of a secret key is contained in a "ROM" type memory part. In order to enable the above-mentioned operating system to use the secret key as a whole, the chip manufacturer only needs to write a small part of the secret key into the "EEPROM" type memory part. Due to its specific storage method, it should be noted that the secret key is divided into two parts and shipped to two different departments of the manufacturer, which makes it possible to reduce the risk of fraud during secret transmission.
This specific storage method keeps the number of bytes programmed into the chip by the manufacturer to a minimum, and therefore has the advantage of reducing the cost of the manufacturer. In fact, in order to ensure a high degree of security, the actual key used is very long. By storing the largest part separately in ROM, these very long keys can usually be stored in EEPROM.
According to a second variant of the embodiment, a first secret is stored in a first part of the memory, and one or more other secrets derived directly or indirectly from the first secret are stored in at least one other part of a physically separate memory Inside. The above-mentioned additional secret can be obtained through encryption.
For example, in a typical application of the method according to the present invention, a (symmetric) encryption key is stored in the "ROM" type first storage area of the smart card during its mask period. During the use of the smart card, a piece of confidential information is stored in a second storage area of the "EEPROM" type. This information is encrypted using the aforementioned encryption key provided in the ROM area (for example, using the so-called triple DES algorithm). This method is very advantageous. In fact, in addition to preventing memory "dumping", it obviously also provides protection for information when it is written to the smart card. Even the entity that "writes" the key does not know the key.
As described above, no matter what embodiment or embodiment variant is involved, a successful fraud attack on a part of the memory cannot obtain the full knowledge of the secret. In fact, as long as the secret elements are wisely distributed on different parts of the memory, the partial secret knowledge obtained in a fraudulent manner and the appropriate mathematical operation that can derive all the secrets from the above partial knowledge are used to try to decrypt the secret, the secret will never be found. Those skilled in the art can accomplish this wise distribution. The attack will eventually fail.
In addition, as described below, the method of the present invention can be used in combination with verification, authentication and/or encryption, where verification, authentication and/or encryption are well known in the first place, but the combination of the present invention enhances the security that can be achieved degree.
Therefore, the subject of the present invention is a method for safely storing a piece of so-called sensitive data in the memory of an embedded microchip system. The embedded microchip system includes at least two physically different storage devices. The data segment is divided into at least two parts, and each of the above-mentioned divided parts is stored in the above-mentioned one physically different storage device.
Another subject of the present invention is an embedded microchip system that implements this method.
According to a specific embodiment, the method is characterized in that the above-mentioned sensitive data fragments are divided into first (d) and second (d) parts and stored in physically different first (1) and second (2) parts, respectively. ) In the storage device, an operation called checksum is performed on the sensitive data and the second part (d) is stored at the same time, and the result is in the form of information data fragments, and the information data is stored in the first storage device In (1), the method includes reading the above-mentioned information data, performing an additional checksum operation on the above-mentioned sensitive data, comparing the read information data with the result of performing the above-mentioned additional checksum operation using the above-mentioned sensitive data to verify it Completeness.
According to a specific embodiment, the method is characterized in that the above-mentioned sensitive data fragments are divided into first (d) and second (d) parts and stored in physically different first (1) and second (2) parts, respectively. ) In the storage device, when storing the second part (d), an operation called checksum is performed on the sensitive data, and the result is in the form of information data fragments, and the information data is stored in the first storage device In (1), the method includes reading the above-mentioned information data, performing an additional checksum operation on the above-mentioned sensitive data, comparing the read information data with the result of performing the above-mentioned additional checksum operation using the above-mentioned sensitive data to verify it Completeness.
Description of the drawings
The present invention will now be described in more detail with reference to the accompanying drawings, in which:-Figure 1 illustrates an exemplary structure of a smart card memory based on an aspect of the present invention for an application using the above method to store a secret key; and-Figure 2 illustrates A variation of the embodiment of the smart card memory structure of FIG. 1.
detailed description
As mentioned in the preamble of this specification, from now on we will consider the optimal application range of the present invention, that is, considering the security of the pre-initialization phase of the smart card.
More precisely, we will describe the method based on the present invention in conjunction with the application of storing the symmetric secret key denoted by the symbol d thereafter. This key d allows the smart card to generate a ciphertext according to an appropriate asymmetric algorithm. When it is returned to a smart card authentication terminal, this cipher text can be used to authenticate the smart card.
Figure 1 illustrates an exemplary architecture of a smart card DP. The smart card contains a memory M. In the described example, the memory M is composed of a so-called "RAM" type random access memory 3 and a non-volatile memory. The above-mentioned non-volatile memory includes a "ROM" type permanent part 1 and a Semi-permanent part 2 of "EEPROM" or similar type. The smart card CP also contains a data processing device that cooperates with an operating system 4, such as a microprocessor represented as a CPU. The operating system is a software segment composed of a sequence of microinstructions, and the sequence of microinstructions described above can be completely or partially stored in the ROM area 1 and/or the EEPROM area 2 of the memory M.
According to a feature of the present invention, the key d is stored in at least two physically different parts of the memory M. More precisely, in the illustrated example, this key d is stored in a non-volatile part of the memory M: a part in the "ROM" type permanent memory 1, and a "EEPROM" or similar type of semi-permanent memory Part of 2.
Therefore, the secret key d includes a part that is stored in the ROM 1 before reaching the entity called the "chip manufacturer", and a part that is written into the EEPROM 2 by the chip manufacturer during the so-called "sous pointe" operation. section. The bytes programmed into EEPROM2 are very sensitive data and are regarded as security bytes. Of course, this requires knowing the secret key d at the time of masking.
For example, to illustrate the concept, hereafter we will consider a 1024-bit (or 128-byte) secret key d.
In an optimal embodiment of the method of the present invention, the key d resides entirely in ROM1, but some bytes are false or changed. For example, every sixteen-byte module has one byte as a dummy byte, and an error value is deliberately written into the ROM code.
In Fig. 1, the symbols B1-B8 are used to denote modules with different keys d. The error bytes are represented as O1-O8. The correct byte value expressed as O'1-O'8 is stored in EEPROM2 and has the form of eight corresponding bytes. These bytes O'1-O'8 constitute a partial key d'.
In this example, eight (or 128/16=8) bytes must be programmed into EEPROM2. However, it should be understood that since the operating system 4 and the data processing device CPU jointly reconstruct the complete key in RAM3, they can be stored in EEPROM2 in any way, and the above key is called d" when in use. Simply by using The correct bytes O'1-O'8 replace the error bytes O1-O8 to complete the reconstruction in the above example.
Obviously, a key d or d'obtained by any means, especially through the above-mentioned fraudulent "dumping" operation, cannot derive "all secrets", that is, a completely correct key d".
As mentioned above, in order to obtain good security, the key is usually longer, such as 128 bytes or 1024 bits in length. In addition to the degree of security it provides, the method based on the present invention can store only a very small part of the total key d in the EEPROM2, that is, 8 bytes or 64 bits. The chip manufacturer should only "probate" the part of the key written into it. The above method is an important advantage due to the long and expensive operation time.
It should be understood that many other structures may be used to distribute keys in two types of memories, namely ROM1 and EEPROM2. The two byte strings only need one-to-one correspondence. However, the expert must confirm that this distribution does not allow to know one of the two partial keys d (having the same length as all the correct keys d", but being partially "altered") or d'to prevent mathematical or other methods based on this Part of the knowledge derives all keys. The distribution described above with reference to Figure 1 can meet this requirement for the key length considered.
In another variant of the method of the present invention, in order to further improve security, an additional piece of information data is stored in ROM1, so that the integrity of the secret key d can be guaranteed and the integrity of the memory ROM1 and EEPROM2 can be maintained in the future. This piece of data may have the form of a checksum calculated based on the secret key. The data segment can also be obtained through a hash function or a "hash" of the same key. For this reason, in the latter case, an algorithm called "SHA-1" is used. Therefore this specific algorithm must be installed in the smart card. The length of the result of this hash function is 160 bits. The key d is stored in the ROM 1 during the initial calculation to obtain the above key.
Whenever the secret key is used, a checksum or hash is calculated and compared with the pieces of information data stored in the memory ROM1.
Figure 2 illustrates the architecture of a smart card CP that stores such "hash" data in ROM1. Units common to FIG. 1 have the same symbolic representations and are described only when needed.
The data fragment H is stored in the ROM1 and the data fragment H is verified every time the key is used in order to maintain the integrity of the storage areas ROM1 and EEPROM2. This verification is done under the control of the data processing device CPU and the program stored in the memory.
It has been assumed so far, at least implicitly, that the secret data distributed between two physically different parts of the memory M constitutes an identical secret.
In another variant of the method of the present invention, the secret data stored in ROM1 may constitute a first secret. The second secret data derived from the first secret data can constitute a second secret. According to a feature of the present invention, this data is then stored in a second physically different part of the memory M, such as EEPROM2. Regardless of whether it is symmetrical or not, this data can be obtained by encrypting the first data using any appropriate algorithm. When the secret cannot be inferred from the knowledge about a part of the memory M, it can be considered that the secret is correctly "divided" or "divided" within the scope of the method based on the present invention.
It is obvious from reading the above content that the present invention achieves the above objectives.
By physically distributing sensitive data such as keys or similar data to at least two physically different parts of the memory of the smart card, especially the embedded microchip system, the present invention provides high security for the storage of sensitive data.
However, it must be understood that the present invention is not limited to the explicitly described exemplary embodiments, especially the embodiments described in conjunction with FIGS. 1 and 2.
Specifically, the secret data can be distributed to more than two physically different memory sections. Similarly, when the distributed data does not represent the same secret, the number of secrets derived from the first secret cannot be greater than one. It is also possible to derive the cascaded secrets and store them in physically different memory sections.
The present invention is not limited to the authentication application in which the smart card pre-initialization phase is described in detail above. As long as an encryption key or any other sensitive data segment must be stored in the memory of the embedded system, the present invention is applicable.
2 sheets
Sheet 1 Sheet 2
12 members in 6 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 0007318 | France | – | |
| 0007318 | France | A |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| WO0195273A1 | World Intellectual Property Organization (WIPO) | A1 | |
| FR2810138A1 | France | A1 | |
| US2002108051A1 | United States of America | A1 | |
| EP1247263A1 | European Patent Office (EPO) | A1 | |
| CN1386250A | China | A | |
| JP2003536154A | Japan | A | |
| FR2810138B1 | France | B1 | |
| CN1193320CThis record | China | C | |
| JP3734473B2 | Japan | B2 | |
| JP2006048704A | Japan | A | |
| US7260727B2 | United States of America | B2 | |
| JP5082046B2 | Japan | B2 |
6 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Termination of patent right or utility modelEXPY | EXPY | |
| Succession or assignment of patent rightASS | ASS | |
| Transfer of patent application or patent right or utility modelC41 | C41 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 1193320
- Application
- 18019862
Titles4
- Chinese
- 在嵌入式微芯片系统,尤其是智能卡的存储器中安全存储敏感数据的方法和实现该方法的嵌入式系统
- English
- Method for safely storing sensitive data in the memory of an embedded microchip system, especially a smart card, and an embedded system implementing the method
- Chinese
- 在嵌入式微芯片系统,尤其是智能卡的存储器 中安全存储敏感数据的方法和实现该方法的嵌入式系统
- English
- Method for safely storing sensitive data in embedded microchip system, especially smart card memory, and embedded system implementing the method
Classification
- CPC, 3
- G07F7/1008
- G06Q20/341
- G07F7/082
- IPC, 5
- G06K19 07
- G06K19 073
- G06K19 10
- G07F7 10
- H04L9 10