System for preventing electronic memory tampering
Abstract
Methods and apparatus for preventing tampering with memory in an electronic device, such as a cellular telephone, are disclosed. An electronic device having a memory and a processing means contains logic that is used to perform a one-way hash calculation on the device's memory contents whereby an audit hash value, or signature, of such contents is derived. The audit hash value si compared to an authenticated valid hash value derived from authentic memory contents. A difference between the audit and valid hash values can be indicative of memory tampering. In accordance with another aspect of the invention, electronic device memory contents can be updated by a data transfer device that is authenticated before being permitted access to the memory contents. Data transfer device authentication involves the use of a public/private key encryption scheme. When the data transfer device interfaces with an electronic device and requests memory access, a process to authenticate the data transfer device is initiated.

Term
Term ended
Projected expiry passed 5 September 2017, 9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
19 claims: 6 independent, 13 dependent
- 1PATENDINÕUDLUS 1. Elektroonikaseade, mis sisaldab:mälu (410, 420);ja 5 mikroprotsessorit (402) autentse mälusisu õige räsiväärtuse arvutuseks, viies läbi mälu sisu (410, 420) räsiväärtusarvutuse, et eraldada kontrollräsiväärtus, ja kontrollräsiväärtuse võrdlemiseks õige räsiväärtusega, räsiväärtusarvutused ja võrdlemine on võltsimiskindlad. 10
- 2Seade vastavalt patendinõudluse punktile 1, milles mikroprotsessor (402) sisaldab vahendit perioodiliselt kontrollräsiväärtuse eraldamiseks ja kontrollräsiväärtuse võrdlemiseks õige räsiväärtusega.
- 3Seade vastavalt patendinõudluse punktile 2, milles mikroprotsessor (402) 15 sisaldab vahendit perioodiliseks räsiväärtuse eraldamiseks riistvaralise taimeri aja abil.
- 4Seade vastavalt patendinõudluse punktile 1, milles mälu sisaldab muutmälu (420) ja EEPROM mälu (410). 20 5. Seade vastavalt patendinõudluse punktile 1, sisaldades lisaks:kaitstud juhupöördusmälu (407) räsiväärtuse arvutamiseks koostöös mikroprotsessoriga (402). 6. Seade vastavalt patendinõudluse punktile 4, milles mikroprotsessor (402) 25 sisaldab vahendit kontrollräsiväärtuse eraldamiseks, mis baseerub muutmälu (420) ja EEPROM mälu (410) valitud sisul. 7. Seade vastavalt patendinõudluse punktile 6, milles valitud sisu sisaldab elektroonilist seerianumbrit. 8. Seade vastavalt patendinõudluse punktile 6, milles valitud sisu hõlmab mikroprotsessori programmikoodi. EE 199900084 A 9. Seade vastavalt patendinõudluse punktile 1, milles mikroprotsessor (402) sisaldab vahendit õige räsiväärtuse autentimiseks, kasutades mällu (410, 420) salvestatud avalikku võtit.
- 55 10. Seade vastavalt patendinõudluse punktile 1, milles mikroprotsessor (402) sisaldab vahendit õige räsiväärtuse krüpteerimiseks lisatud salajasel võtmel põhineva digitaalse allkirjaga. 11. Seade vastavalt patendinõudluse punktile 1, milles mikroprotsessor (402) 10 sisaldab vahendit räsiväärtuse arvutusteks, kasutades ühte räsifunktsiooni grupist, kuhu kuuluvad:Snerfu, H-Hash, MD2, MD4, MD5, Secure Hash Algoritm (SHA) ja HAVAL. 12. Seade vastavalt patendinõudluse punktile 10, milles mikroprotsessor (402) sisaldab vahendit autentimiseks ja krüpteerimiseks, kasutades ühte avalik/salajase võtme 15 süsteemi algoritmide grupist, kuhu kuuluvad: ELGAMAL, RSA, DSA, Fiege-Fiat-Shamir ja Fiat-Shamir. 13. Seade vastavalt patendinõudluse punktile 5, sisaldades lisaks turvaloogikat, milles turvaloogika jälgib juurdepääsu kaitstud juhupöördusmälu piirkonda. 14. Seade vastavalt patendinõudluse punktile 1, milles elektroonikaseade on mobiiltelefon. 15. Seade vastavalt patendinõudluse punktile 6, milles muutmälu sisaldab 25 elektroonikaseadme juhtkoode ja EEPROM sisaldab õiget räsiväärtust, milles mikroprotsessor sisaldab vahendit ühesuunalise räsifunktsiooni arvutamiseks valitud autentsele muutmälu ja EEPROM mälu piirkonnale, et saada õige räsi väärtus, vahendit räsiväärtuse perioodiliseks genereerimiseks, kasutades räsiarvutust üle valitud mäluosa, ja vahendit kontrollräsiväärtuse võrdlemiseks autentse õige räsiväärtusega, hindamaks seda, 30 kas muutmälust ja EEPROM mälust vähemalt ühte on muudetud. 16 Seade vastavalt patendinõudluse punktile 15, milles mikroprotsessor (402) sisaldab vahendit ühesuunalise räsifunktsiooni arvutuseks, kasutades ühte räsifunktsiooni EE 199900084 Α grupist, kuhu kuuluvad: Snerfu, H-Hash, MD2, MD4, MD5, Secure Hash Algoritm (SHA) ja HAVAL. : .17. Seade vastavalt patendinõudluse punktile 10, milles mikroprotsessor (402) sisaldab vahendit õige räsiväärtuse krüpteerimiseks digitaalallkirjaga salajase võtme abil, kasutades elektroonikaseadme välist töötlusvahendit. 18. Meetod elektroonikaseadmes asuva mälu võltsimise avastamiseks, milline meetod sisaldab:
- 610 õige signeeritud räsiväärtuse, mis on saadud valitud mäiupiirkonnas (410, 420) räsitehte läbiviimisel, salvestamist mällu, kus valitud mälupiirkond on teadaolevalt autentne;kontrollräsiväärtuse saamist, rakendades räsiarvutust valitud mäiupiirkonnas (410, 420);ja
- 715 kontrollräsiväärtuse võrdlemist õige räsiväärtusega, mille tulemusena leitud erinevust kontroll- ja õige räsiväärtuse vahel tõlgendatakse valitud mäiupiirkonnas toimunud muutusena, milles salvestamine, läbiviimine ja võrdlemine on võltsimiskindlad.
- 819. Meetod vastavalt patendinõudluse punktile 18, milles kontrollräsiväärtuse 20 saamine on teostatav koostöös kaitstud juhupöördusmäluga (407).
- 920. Meetod vastavalt patendinõudluse punktile 18, mis lisaks sisaldab astet õige räsiväärtuse allkiijastamiseks salajasel võtmel baseeruva digitaaiallkiijaga. 25
- 1021. Meetod vastavalt patendinõudluse punktile 18, milles kontrollräsiväärtuse arvutamist ning kontroll-ja õige räsiväärtuse võrdlemist viiakse läbi perioodiliselt.
- 1122. Meetod vastavalt patendinõudluse punktile 18, milles kontrollräsiväärtuse eraldamine on juhitav riistvaralise taimeri aja abil.
- 1223. Meetod vastavalt patendinõudluse punktile 18, milles kontrollräsiväärtuse arvutamine sisaldab kontrollräsiväärtuse segmentide arvutamist. EE 199900084 A
- 1324. Meetod vastavalt patendinõudluse punktile 23, milles kontrollräsiväärtuse segmentide arvutamine on vajadusel ajatatud, kuni teised mobiiltelefonis toimuvad protsessid on lõppenud. 5 25. Meetod vastavalt patendinõudluse punktile 18, milles õige räsiväärtus omab digitaalallkirja, ja milles kontrollräsiväärtuse ja õige räsiväärtuse võrdlemine sisaldab autentsuse kontrolli allkirja suhtes. 26. Meetod vastavalt patendinõudluse punktile 18, milles elektroonikaseade on 10 mobiiltelefon. 27. Süsteem programmeeritava mäluga elektroonikaseadme kaitsmiseks volitamata juurdepääsu eest, mis hõlmab:mikroprotsessorit (402) kutsungsõnumi autentimise alustamiseks vastuseks 15 andmeülekandeseadiselt (750) vastuvõetud juurdepääsupalvele, milles andmeülekandeseadis (750) sisaldab vahendit kutsungsõnumi signeerimiseks, kasutades salajast krüpteerimisvõtit, ja vahendit signeeritud kutsungsõnumi saatmiseks elektroonikaseadmele, ja milles elektroonikaseade sisaldab lisaks vahendit signeeritud kutsungsõnumi autentsuskontrolliks, kasutades avalikku võtit, milline avalik võti on vastavuses salajase krüpteerimisvõtmega, ja 20 vahendit andmeülekandeseadise (750) blokeerimiseks, juhul kui kutsungsõnum autentsuskontrolli käigus tagasi ei pöördu. 28. Süsteem vastavalt patendinõudluse punktile 27, milles elektroonikaseade on mobiiltelefon. 29. Süsteem vastavalt patendinõudluse punktile 28, mis lisaks sisaldab: üldotstarbelist arvutit, millel on esimene ja teine port;milles andmeülekandeseadis (750) sisaldab vahendit esimese pordiga liitumiseks, ning mobiiltelefon sisaldab vahendit teise pordiga liitumiseks, milles mobiiltelefonil on vahend 30 vastusena andmeülekandeseadiselt vastuvõetud programmeerimispäringu kutsungi tagastamiseks, milline kutsung on allkirjastatud andmeülekandeseadise poolt ja tagastatud mobiiltelefonile autentsuskontrolliks, ning allkirjastatud kutsungi tagastamine EE 199900084 A autentsuskontrolli vältel, mille abil määratakse andmeülekandeseadise autentsus ja viiakse mobiiltelefon programmeerimisrežiimi. 30. Meetod programmeeritava mäluga elektroonikaseadme kaitsmiseks 5 volitamata juurdepääsu eest, mis hõlmab: kutsungsõnumi saatmist vastuseks programmeerimispäringule andmeülekandeseadisest;kutsungsõnumi allkirjastamine andmeülekandeseadises (750), kasutades salajast krüpteerimisvõtit;10 allkirjastatud kutsungsõnumi saatmine andmeülekandeseadisesse (750);allkirjastatud kutsungsõnumi autentsuskontroll andmeülekandeseadises (750), kasutades avalikku võtit, milline avalik võti on vastavuses salajase krüpteerimisvõtmega;andmeülekandeseadise (750) blokeerimine, juhul kui kutsungsõnum autentsuskontrolli käigus tagasi ei pöördu. 31. Meetod vastavalt patendinõudluse punktile 30, milles elektroonikaseade on mobiiltelefon. 32. Meetod vastavalt patendinõudluse punktile 28, milles allkiijastatud 20 kutsungsõnum sõltub kutsungsõnumi osadest, meetod sisaldab lisaks autentimise sisenemist programmeerimisrežiimi kui allkirjastatud kutsungsõnumi vastuse autentsuskontroll kinnitab andmeülekandeseadise autentsust. 33. Programmeeritav elektroonikaseade, mis sisaldab:
- 1425 mikroprotsessorit (402) elektroonikaseadmele volitamata juurdepääsu vältimiseks, milles elektroonikaseade sisaldab vahendit kutsungsõnumi väljastamiseks andmeülekandeseadisele (750), vastuseks andmeülekandeseadiselt (750) vastuvõetud juurdepääsupalvele, andmeülekandeseadis (750) sisaldab vahendit kutsungsõnumi allkirjastamiseks, kasutades salajast krüpteerimisvõtit, ja vahendit allkirjastatud
- 1530 kutsungsõnumi saatmiseks elektroonikaseadmele, ja milles elektroonikaseade sisaldab lisaks vahendit allkirjastatud kutsungsõnumi autentsuskontrolliks, kasutades avalikku võtit, milline avalik võti on vastavuses salajase krüpteerimisvõtmega, ja vahendit andmeülekandeseadise (750) blokeerimiseks, juhul kui kutsungsõnum autentsuskontrolli käigus tagasi ei pöördu. EE 199900084 A
- 1634. Elektroonikaseade vastavalt patendinõudluse punktile 33, milles elektroonikaseade on mobiiltelefon ja andmeülekandeseadis on programmaator.
- 1735. Süsteem mälule juurdepääsu takistamiseks, mis sisaldab:5 mikroprotsessorit (402), juhtkoodi sisaldavat püsimälu (403);kaitstud suvapöördusmälu (407);ja turvaloogikat (1124) kaitstud suvapöördusmälule (407) juurdepääsukatsete kindlakstegemiseks, juurdepääsu lubamiseks püsimälule (403), ja muul juhul 10 mikroprotsessori (402) töö katkestamiseks ja taolise juurdepääsu vältimiseks.
- 1836. Süsteem vastavalt nõudluspunktile 35, mis lisaks sisaldab riistvaral baseeruvat taimerit (401), milles turvaloogika (1124) sisaldab vahendit juurdepääsuks püsimälule (403), ja muul juhul takistab pöördumisi riistvaralise taimeri (401) poole.
- 1937. Süsteem vastavalt nõudluspunktile 35, milles pöördumised kaitstud suvapöördusmälu (407) poole on jälgitavad püsimälus (403) asuva juhtkoodiga ja võivad toimuda ainult siis, kui süsteem on jälgimisrežiimis. 20 38. Süsteem vastavalt nõudluspunktile 35, milles süsteem takistab mobiiltelefoni mälule juurdepääsu.
Independent claims19
123 paragraphs in 8 sections, as filed
ELECTRONIC MEMORY PROTECTION SYSTEM
The invention relates to systems for protecting electronic memories, more particularly to methods and techniques for preventing unwanted alteration of the contents of electronic devices.
The present invention relates to any electronic device in which the contents of memory are predominantly stored in an unchanged state. The claim is necessary for security purposes, to prevent, for example, fraudulent cell phone memory alteration or to provide control of critical electronic devices such as airplane navigation or medical equipment. As disclosed and described below, the advantages of the invention and the security methods are exemplified by using an example of a cellular phone memory. Also described below is a system that permits access and control of one or more storage devices of an electronic device using a data transfer device that performs a user rights control process before granting access to the electronic memory. In the remainder, the system performance is also described using the mobile application. While the detailed description of the invention is in the context of cellular phone memory security and methods of providing secure access and integrity, it is readily apparent that the method based on the invention is applicable to any electronic device containing one or more non-volatile memory or memory only. Accordingly, the scope of the invention is not limited only by the wording described below, but also by the appended claims and their equivalents.
In the United States, 1995 $ 600 million in damage caused by mobile phone hacking. In response, manufacturers, service providers, the Federal Communications Commission (FCC) and industry trade groups tried a number of measures to combat fraudsters. The most common type of fraud in the United States was the falsification of a reported telephone's Electronic Serial Number (ESN) when creating a communication written on a mobile phone's memory. Consequently, one of the anti-counterfeiting techniques employed by the FCC was to require phone manufacturers to lock the microprocessor code and ESN. Some of the basic backgrounds of mobile communications are provided to illustrate the environment of mobile phone operators and the associated problems associated with the present invention.
A schematic diagram of a simplified mobile communication system is shown in Figure 1. Mobile phones
The M1-M10 is connected to a general switching network to send and receive a radio signal through base stations B1-B10. The base stations B1-B10, in turn, are connected to the general
EE 199900084 Α Mobile Switching Network (MSC) with a switched network. Each base station B1-B10 sends signals to a corresponding area, called a "cell" Cl-CIO. As illustrated in Figure 1, the idealized base station layout is calculated so that areas where communications are likely to be established are substantially covered with minimal overlap.
When the user activates the phone inside the cell, the phone sends a corresponding signal to the base station. The cellular telephone transmits a signal, which may include an ESN, through a dedicated setup channel monitored by each base station. When a base station receives a signal from a cellular phone, the cellular location is recorded in the cell. This process is repeated periodically, so phone registration is guaranteed even if it moves to another cell.
When a call is made to a mobile phone, the telephone company exchange recognizes the selected number as belonging to the mobile phone and forwards the call to the MSC. The MSC sends a paging signal to specific base stations depending on the number dialed and the known registration information15. One or more base stations transmit the paging via the configuration channel. The called phone recognizes its identification in the setup channel and responds to the base station call. At the same time, the mobile phone follows the instruction to tune in to the designated voice channel and to generate a ring signal. If the mobile user disconnects, a signal is transmitted to the base station and both parties release the voice channel.
In the case described above, the mobile phones are not permanently connected to a fixed network, instead they are connected via a so-called "air interface". This, of course, gives flexibility to the mobile communication system as the user can transport the mobile phone without restrictions while physically connected to the communication system. At the same time, it creates difficulties in the security of information transmitted via the mobile communication system.
For example, in a conventional wired telephone system, the exchange can identify the user in question for charging the use of the telephone device by the physical part of the line to which the device is connected. Thus, fraud at the expense of the user usually requires physical connection to the user's line section. This carries the risk of being detected as a fraudster.
The mobile communication system, on the other hand, does not provide such a connection problem to the fraudster from the point at which the system communicates using the air interface. There is no protection scheme, the fraudster is able to use the customer's electronic serial number (ESN), which
EE 199900084 A is transmitted from a mobile phone to the network at various times to establish and manage a connection, to make calls from a foreign account.
In order to establish a standard mobile connection, two identification codes are transmitted from the mobile telephone to the system. These are the Mobile Identification Number (MIN) and the ESN. The MIN identifies the user, while the ESN identifies the hardware used by the user. Accordingly, a partially ESN-compliant MIN is assumed to be changeable when the user purchases a new device. MIN is a 34-bit binary number that identifies a mobile phone. ESNs are usually assigned at the manufacturing plant.
The most common authentication method used in communications is illustrated by way of example in the Advanced Mobile Telephone System (AMPS) shown in Figure 2 attached. In this method, the base station receives a MIN and an ESN from the cellular unit in block 200. These identification codes are called ESNs<sub>m</sub> and MIN<sub>m</sub> to indicate that they have arrived from a mobile phone. Next, in block 202, the base station searches the system memory ESN<sub>sys</sub>that matches MIN<sub>m</sub>with. ESN<sub>sys</sub>is compared to ESN<sub>m</sub>If the two serial numbers are the same, the diagram travels to block 206 and system access is allowed. Otherwise, access to the system at block 208 is denied.
One of the downsides of this system is the relatively easy way for a rogue to capture a valid MIN / ESN combination by listening to the ether using the device. As long as, according to a common system, access is presumed to be based on a match between the MIN and ESN numbers received from the mobile phone and stored in the system memory, all information necessary for fraudulent access can be acquired by electronic interception.
Other techniques have been suggested to prevent abuse. For example, U.S. Patent No. 5,386,486 describes a method for registering an identification number in a personal communications terminal with a service carrier. EP 0 583 100 A1 discloses a system for assigning a number 25 transfer module for a portable telephone, which prevents the unauthorized setting of a number transfer module in the portable telephone.
Systems that operate under the European GSM (Global System for Mobile) standard, the American TIAEIA / IS-136 standard, and the Japanese Personal Digital Cellular standard for radio communications, prevent fraudulent data interception using a challenge response method. According to the call-response method, each mobile phone is provided with a unique secret key stored in the database of both the mobile phone and the mobile network. An algorithm that is unique to the system is stored on each mobile phone and on the desired network. When a call is initiated, the network requests a call number
EE 199900084 A (random number) by sending a cell phone authentication. Based on the received call number and the stored secret key, the cellular telephone calculates the response message using an algorithm and sends it to the network. At the same time, the network calculates an "expected" response message based on the same call number and network secret key. The network then receives the response calculated by the mobile phone and compares the response calculated by the mobile phone with the response calculated by the network. In the event of an incompatibility, appropriate action will be taken, such as denying access to the system or issuing a warning. The method that performs authentication between a base station and a mobile phone belonging to a mobile communication system is P. U.S. Patent No. 5,282,250 to Dental.
In common analog systems, such as AMPS, most are harmed by rogue users who "clone" existing subscribers by acquiring working MIN / ESN pairs and using them to reprogram mobile phones. In more embodiments of more intelligent cloning methods, cellular phone software is programmed to use multiple MIN / ESN pairs and is called "tumbling." A cell phone that is programmed with a tumbling routine will switch randomly
MIN / ESN pairs to make a call. If the cheater is identified by the service provider or user, the MIN / ESN pair is considered invalid. If an invalid MIN / ESN pair is detected during a call attempt, the tumbling routine discards this MIN / ESN pair and continues searching until a valid MIN / ESN pair is found. If all the mobile phone programmed
As the MIN / ESN pairs become invalid, the phone user will usually contact the clone to program a new set of MIN / ESN numbers for the mobile phone.
Many mobile hackers use some form of memory manipulation. This is illustrated with reference to Figure 3, which is a block diagram illustrating the cooperation between a conventional mobile phone memory and a processor. Controller 300 communicates with read only memory (ROM) or random access memory 320,
EEPROM 310 and Random Access Memory (RAM) 330 using memory bus 308. Program memory 320 is read / unread memory used to store control codes for basic cellular process operations. EEPROM 310 is used to store MIN / ESN pairs 314 and 316, user profile 312 (e.g., speed dial numbers), and RAM is a read / unread type cache. Hackers look at the signals between the memory and the controller for information that can be used to modify or disable random access memory 320 or EEPROM 310 by monitoring them.
The most common methods of telephone hacking include the arbitrary use of test commands for phone service and repair to modify the ESN. Either way,
EE 199900084 A newer phones resist such a counterfeiting attempt and are capable of eliminating the attack in this way. As a result, hackers are looking for more sophisticated attack methods.
One such technique utilizes the removal and replacement of the EEPROM 310 containing the original ESN 314. After removing the EEPROM, decrypting and analyzing its contents. The decrypted structure is then used to program an EEPROM that replaces an ESN / MIN pair that was acquired illegally at the expense of a valid user. This technique is of interest to a hacker who only wants to change the ESN once. However, this technique is lab-centric and technically less well-equipped hackers, if not careful, can damage the device's printed circuit board.
Major advances in hacking sophistication include analyzing the phone's microprocessor code and rewriting one or more portions of the code to transmit a fraudulent user identity (ESN / MIN pair) to the base station. Often, this requires engineering knowledge of the phone's hardware design and requires a substantial knowledge of the software installed. The obvious advantage of this method is that once the phone has been modified, it can be reprogrammed with a new identity as often as needed.
In a more sophisticated attack, the microprocessor changes described above are combined with a hardware modification. One example of this technique uses the so-called "shadow memory" to prevent a regular memory authentication routine that is performed during the boot-up process. The boot process is performed using a small number of boot codes 304 contained in controller 300 (see Figure 3). The initialization process configurates the mobile phone to an operating state and sets the program counter in microprocessor 301 to the required position in RAM 320. When the process is complete, the controller 300 indicates to the user that the telephone is ready for use by LED 318 (or other equivalent signal). The hacker can monitor the connection between the controller 300 and the LED 318 to alter the effect of the normal control code in the RAM 320, as described in more detail below.
The random access memory 320 in a typical cell phone has an addressable capacity of 512 K. The hacker can remove the RAM 320 and replace it with the 1024 K shadow memory 322 after copying the contents of the original memory to the 1024 K shadow memory 322 for the first 512 K addresses. During the boot process, all memory accesses are successfully directed to the first 512K RAM 320. The hacker can monitor the available signal (for example, LED signal 306) triggered by the execution of the boot process and force the following programs
EE 199900084 A memory accesses 322. Then the cellular phone operates in the shadow memory accordingly
322 existing command set, which may be programmed to include the tumbling routine and the corresponding MIN / ESN pairs.
There are several ways to prevent attempts to falsify memory. For example, WO 91/09484 5 describes a security technique in which access to memory areas of a mobile phone is permitted only through the CPU instructions received from the ROM. FR 2 681 965 describes a system for protecting memory from being overwritten after certain events occur. Other systems for preventing malicious use and / or counterfeiting are described in U.S. Patent No. 5,046,082, which describes a remote access system for cellular phones that prevents unauthorized access and counterfeiting of cellular phone programming, and in U.S. Patent No. 5,442,645, which describes a program or data integrity check the signature calculated by the processor is compared with the signature of the original message.
As most mobile phone piracy is based to some extent on memory manipulation, the Federal Communications Commission (FCC) has issued measures to address this type of mobile piracy. The solution is proposed by a published FCC Regulation. Section 22.219 of the Act prohibits the publication of software for mobile phones; calls for factory setting of the ESN and the impossibility of altering, transferring, deleting or altering in any way; and requires the mobile phone to become useless if anyone, including the manufacturer, attempts to remove, tamper with, or modify the ESN, system logic, or mobile phone hardware.
From the consumer's point of view, it is convenient to exchange cell phones that are not working properly through the factory-enabled mobile phone programming option provided by this manufacturer to factory authorized dealerships. For example, if a customer's mobile phone is down, they can purchase the same electronic "personal" device from an authorized dealer at the factory. The electronic personality of the mobile phone includes not only the ESN but also the user profile and most of the information programmed into the device by the customer, such as personal and / or work phone numbers. Program Service / Replacement and technology to quickly make mobile phone ESN and other memory changes have been developed based on the requirements of mobile network operators, which do not want the inconvenience of defective devices for their customers.
FCC § 22.219 also provides for the replacement of a non-working cellular phone with the one described below. Therefore, since the new fixed ESN is associated with a new device, it is necessary to notify the network administrator who will program the new number in the network database. This may cause an extension of the period during which the customer will not receive the service
EE 199900084 A to use. The client also needs to reprogram their personal and business information. A far more important issue under § 22.219 is the adverse impact on mobile network operators, which must provide system updates to their customers by reprogramming their cell phones.
The practical impact of § 22.219 on mobile phone manufacturers in upgrading the system is outlined below. By using a digital control channel, such as a TIA / EIA / IS-136 specification, the mobile operator can provide additional services such as short message service. If operators, manufacturers or authorized agents can make changes to the software and hardware of mobile phones, these services will be available to customers quickly and efficiently through changes to the software. No changes to the software may be made by any manufacturer, network operator, or service provider authorized by the manufacturer pursuant to § 22.219 (in its current version). All that an operator can do is inform the customer that upgrading the system may require the customer to purchase a new mobile phone.
In order to improve the compliance of § 22.219 with customers and with the manufacturers' association, the FCC declared the law applicable to mobile phones whose application has been fixed after January 1, 1995. As a result, the FCC has declared over 20 million currently operating mobile phones, including millions of functional cell phones based on application types in effect before January 1, 1995, that were turned on after January 1, 1995. The fact that there are so many cell phones on the market whose electronic information may be used for unauthorized purposes shows that § 22.219 has very little effect on the hacking problem. Institutions engaging in such unlawful ESN violations may do so using millions of terminals that are not subject to the restrictions in § 22.219.
As is evident from the foregoing, the introduction of a secure memory mobile phone is highly desirable. There is currently no way to protect your mobile phone from damage. In addition, no method or device has been found that would allow the contents of the electronic memories to be updated while providing only authorized access.
EXECUTIVE SUMMARY
This, as well as other common drawbacks and limitations of conventional mobile phone memory, and more generally memory protection systems, can be overcome by protecting the contents of the memory from unauthorized access and alteration as described in the present invention.
According to the content of the invention, security can be achieved by periodically checking the contents of the memory of the electronic device in order to detect any changes made.
EE 199900084 A in memory. The check includes a fractional hash calculation of the contents of a selected region of the electronic memory, resulting in a region hash value or code word. The result of the check is compared with a known hash value previously obtained from the contents of the authentic memory. The correct hash value is usually stored in encrypted form in electronic memory and decrypted for comparison purposes only. A parity error between the correct hash value and the control hash value may indicate a memory change that results in a device with electronic memory stopping or giving a warning signal.
According to another aspect of the invention, the contents of the electronic memory containing the cellular phone memory data (including the cellular telephone ESN) are updated by means of a data transfer device, the user authentication of which is performed prior to granting access to the memory content. The authentication of the data transfer device also involves the use of a public / private key authentication scheme. When the data transfer device accesses the electronic device and requests access, the device initiates the authentication process of the data transfer device. This process involves the serial exchange of messages between the electronic device and the data transfer device. A public key is used in an electronic device to decrypt or "tag" an encrypted message with a secret key stored in a data transfer device. Specifically, when the data transfer device requests an electronic device to request memory programming, the device initiates a process for verifying the authenticity of the data transfer device. The electronic device responds with a response message which is sent back to the data transfer device. The reply message is marked with an electronic signature using a secret key on the data transfer device. The signed reply message is sent back to the electronic device which performs the user authentication using the public key. Once the right of use is established, the data transfer device shall be granted access to privileged commands and the resources of the electronic device.
After each reprogramming of the electronic memory, the electronic device calculates a new correct hash value to be extracted from the modified memory. The new hash value is sent back to the data transfer device for digital signing using a secret key. The signed hash value is sent to the electronic device for recording. Now that the electronic device is performing a subsequent memory check, the audit result is compared to the new hash value.
BRIEF DESCRIPTION OF THE DRAWINGS
The foregoing and other objects, features, and advantages of the present invention will be more readily understood upon reading this description in conjunction with the drawings, in which:
Fig. 1 of an EE 199900084 A shows an schematic of an idealized cellular telephone network;
Figure 2 shows a diagram of the operation of a conventional cellular phone authentication method when initiating a mobile call;
Figure 3 shows the processor and memory structure of a conventional mobile phone;
Figure 4 illustrates a processor and memory structure of a cellular telephone according to the invention;
Figure 5 is a diagram illustrating a cellular phone start-up process as described in the invention;
Figure 6 is a diagram illustrating a periodic memory control process in accordance with the invention;
Figure 7 shows a data transmission device as described in the invention;
Figure 8 is a diagram illustrating, by way of example, the authentication of a data transmission device as described in the invention;
Figure 9 is a diagram illustrating, by way of example, the insertion of an ESN into a mobile phone memory as described in the invention;
Figure 10 is a diagram illustrating an exemplary reprogramming of an ESN according to the invention; and Figure 11 illustrates the structure of a protected memory according to the example of the present invention; and FIG. 12 illustrates a mobile phone programming device as described in the present invention.
DETAILED DESCRIPTION
The electronic memory incorporating the method and technique described in the present invention is described below in more detail by way of example in the context of a mobile application. The following examples are provided only to illustrate an ideal embodiment according to the invention.
Referring to Figure 4, it will be apparent that controller 400 controls the operation of the cellular telephone (see position number 1204 in Figure 12). Controller 400 cooperates with random access memory 420, electronically erasable read only memory (EEPROM) 410, and random access memory (RAM) 408. Controller 400 includes microprocessor 402 and internal read-only memory (IROM) 403. Internal read-only memory (IROM) 403 includes boot code 404, hash code 405, an authentication code 409 and a public key 406. In addition, controller 400 includes a protected static random access memory (PSRAM) 407 and a hardware timer 401 for periodically triggering a hash value calculation of selected memory content performed by microprocessor 402. EEPROM 410 includes user profile 412, ESN 414, MIN 416 and
EE 199900084 Α Signed / Unsigned Hash Values Pair 418. The control code for basic cellular phone operations is contained in random access memory 420. The RAM 408 is used to control cache memory, which is part of the cellular phone's normal cellular operation. Command sensitive data, hash value calculations, and authentication processes are all controlled in collaboration with the PSRAM 407.
Controller 400 communicates with RAM 420, RAM 408 and EEPROM 410 via memory bus 424.
The phone memory check and boot process in the system described in Figure 4 according to the invention is illustrated in Figure 5. After the mobile phone is turned on, the microprocessor 402 initiates a controller (block 500) using the boot code 404 in the IROM 403. The hash value code 405 in the IROM 403 then triggers the process of checking the selected content in the flash memory 420 and the ESN value stored in the EEPROM 410 (block 502). The controller now authorizes a valid signed hash value pair stored in the EEPROM (block 504). This process may also include checking a valid signed hash value by processing the hash value with a public key and comparing the result obtained with an unsigned hash value. The authorized hash value is stored in PSRAM 407 (block 506). The hash value obtained in block 502 is now compared with the authorized hash value obtained in block 504 (block 508). When the hash values match, the microprocessor program counter is set to its corresponding position in the flash memory 420, and the periodic hash value calculation process is enabled (block 510), after which the cellular phone begins normal operation (block 512). If hash values in block 508 do not match, the system is set to end loop (block 514) or it may be disabled. The above process prevents the hacker from replacing the program in random access memory or changing the ESN in the EEPROM, causing a hash mismatch and blocking the phone.
In order to prevent flash memory 420 from being replaced by shadow memory 422, it is desirable to perform periodic hash calculation. During normal phone operation, the periodic hash value calculation occurs at the end of the timer time or according to another system event. In the example shown in Figure 4, periodic hash value calculation is triggered by hardware timer 401, which causes non-concealed interrupt (NMI) generation. NMI is a hardware-oriented interrupt that cannot be masked by software processes. As a result, the hacker cannot configure the var code to bypass the NMI. Other interruptions are also hardware that may compete with other common interruptions that occur when performing normal phone commands to allow access.
EE 199900084 A for microprocessor resources. A regular interrupt is acknowledged and filled when it arrives by a higher priority interrupt control.
Because a complete hash calculation may take longer than the tolerance allowed for a normal phone to operate, it is better to perform this process in smaller increments over shorter intervals (a few seconds). According to a further part of the invention, a two-step process is built into the hardware based timer to create two hash value calculation segments. First, a non-masking interrupt (NMI) causes the microprocessor to immediately restore the contents of the next random access memory or EEPROM address at a time with periodic hash calculation and save it in PSRAM. NMI, unlike others, is a set of short, high-priority interruptions that negatively impact the microprocessor tasks that may be performed when an NMI is provided. This ensures that cloned software cannot prevent detection by hash value calculation. Second, the lower priority of the standard interrupt, which is also generated by a hardware-based timer 401 that requires servicing to complete the hash calculation of an ongoing segment, is based on the memory byte previously occupied by the NMI routine. This task can also be postponed if it is required for normal speech process tasks to occur for a predetermined maximum time (T) before the hardware-based timer turns off the phone. The maximum time (T) is selected to ensure complete processing of any normal call, complete the hash calculation of the segment, and reset the hardware-based timer to begin the countdown cycle. A strategy for using two types of interrupts to periodically calculate segmental hash value avoids a reduction in system response time and provides security controls that cannot be circumvented by clone software residing in shadow memory.
Figure 6 is a block diagram illustrating, by way of example, a periodic hash value calculation process according to the invention. As shown in the figure, at block 604, both the NMI and the normal interrupt are generated when the counter T1 in the hardware-based timer reaches the end of the specified time. When the NMI obtains control over the microprocessor (block 604), the system disables or redirects the normal interrupt queue for a short time during which the next bit in random access memory or EEPROM required for hash calculation is copied to the PSRAM (block 606). The control then returns to the executable command when an NMI is generated (block 608). Normally, the clock generated by the hardware-based timer 401 (block 601) is also used for a short period of time, and the hash value calculation segment is based on a memory byte previously stored in PSRAM (block 616). If hash calculation
EE 199900084 A has not yet completed, hardware-based timers (T1 and T2) 401 reset to initial values (block 624) and normal phone operation continues (block 600) until the end of the next timer T1. If the timer T2 (block 612) expires before the next normal clock (block 610) arrives, the phone is switched off. The default timer T2 time (until a normal attack is working correctly) prevents a hacker from obstructing the periodic hash value calculation.
This piecewise hash value calculation continues until the control hash value calculation is completed (block 618). The authentic hash value from PSRAM above is compared to the hash value obtained from the control. If they coincide, the hardware-based timers 401 (block 624) will be reset and the phone will continue to function normally. If an incompatibility is found, the system (block 622) is disabled by bringing the microprocessor 402 to a halt.
The memory portion of the selected mobile phone subject to hash calculation includes, in particular, the contents of random access memory 420 and the ESN in the EEPROM 414. This prevents a hacker from physically removing or modifying both random access memory and EEPROM and replacing them with reprogrammed chips containing modified ESN and / or program code designed to deceive the network operator. The advantage is to select the contents of the memory and use the hash value calculation, which stops the phone if even one bit covered by the hash value is changed.
According to another aspect of the invention, the mobile phone can be programmed securely using a data transmission device. An example of a data transfer device according to the invention is shown in Figure 7. The numbering, content and associated memory of the components of the controller 400 are identical to the diagram shown in Figure 4. An example of a data transfer device 750 consists of a secure microprocessor 752 comprising a personal encryption key 754 corresponding to a public encryption key 406 in the IROM 403 of the controller 400. The secure microprocessor 752 communicates with the mobile controller 400 via interface 758. Interface
758 may be a serial cable connection, such as an RS 232 link, an infrared wireless link, or an RF link using a cellular phone antenna (not shown) or any other cellular antenna.
Access to the mobile phone memory via the data transfer device 750 is only possible after successful rigorous user authentication. Specifically, the controller 400 (and its associated memory components) is accessible only for downloading data after the data transfer device 750 has successfully completed a user access control call / response process. Figure 8 illustrates the progress of the authorization process in the data transfer device 750 according to the example described in the invention. First
EE 199900084 In step A (block 800), the phone is brought to normal operation using security measures, which are illustrated in more detail with reference to FIG. After the interface stabilizes, secure microprocessor 752 sends a request to controller 400 to start programming with a random number generated by secure microprocessor 752 (Rand 1) (block 802).
Controller 400 responds to secure microprocessor 752 with a random number (Rand 2) response code (block 804). Now, secure microprocessor 752 generates a paging response based on Rand 1, Rand 2, and private key 754 (block 806). The call response is returned to controller 400 (block 808). Controller 400 processes the paging response using Rand 1, Rand 2, and public key 406 (block 10). The processed paging response is authenticated by comparing its value to Rand 2 (block 814). If the paging response is decrypted correctly (eg, Rand 2), the data transmission device is authenticated and the phone enters programming mode (block 814). Thereafter, the data transfer device may gain access to different memory areas of the mobile phone and / or download new contents of the random access memory 420.
If the paging response is not valid, the entry is added to the error counter (block 816).
Error calculation checks that the specified maximum number of failed attempts (maxcount) is reached (block 818). The error calculator takes into account the fact that the data transfer device 750 may communicate with the controller 400 over noise-containing media. Any error that occurs may cause an authentication error. Therefore, it is desirable to give the data transfer device 750 more than one opportunity to attempt to enter the programming mode of the mobile phone. According to the example of the invention, fifty are chosen as the appropriate limit. Until the limit is reached, an error message is sent to the data transfer device 750 for failure to authenticate (block 822). Upon receipt of the error message, the authentication process is restarted from block 802. When the test limit is reached, the phone is turned off and a message is issued to the user to return the phone to an authorized service.
When the data transfer device 750 has completed either ESN programming or downloading to flash memory 420, the phone controller 400 begins a new hash value calculation, for example, including the corrected flash memory 420 and ESN 414. The resulting hash value is sent to the data transfer device 750 for digital signing using private key 754. Signed _ hash value 418 is sent back to controller 400 for storage in EEPROM 410 along with an unsigned version of the same hash value.
As described in the invention, it is possible to reprogram the ESN, but for security reasons, it is better to do it at the manufacturer level, rather an authorized factory
EE 199900084 A offices. ASN programming may be necessary in two cases: programming the original ESN during production, and overwriting the existing ESN-ί. The original ESN may be programmed using a data transfer device similar to that of FIG. The initial ESN programming process is described below with reference to Figure 9.
As a first step (block 900), the phone is put into programming mode (see Figure 5). After the interface has stabilized, the secure processor 752 sends the controller 400 an ESN programming request with a random number (Rand 1) (block 902). Controller 400 conducts an ESN check to determine if all the steps of the ESN are zero, which is always the case on the new phone (block 904). If all steps of the ESN are not zeros, access to ESN programming will be disabled (block 906). When all steps of the ESN are zero, a call-response process analogous to that shown in FIG. 8 is initiated in steps 804 to 820 (see block 908). After a successful authentication of the data transfer device 750, the new ESN EEPR.OM 410 is loaded into memory.
After downloading the ESN completed by the data transfer device 750 to the EEPROM
410 controller 400 starts a new hash value calculation that includes the new ESN. The resulting hash value is sent to the data transfer device 750 for digital sub-signing using the private key 754. Signed hash value 418 is sent back to controller 400 for storage in EEPROM 410 along with unsigned version of same hash value.
According to the method described in the invention, it is also possible to have one present in the system
Reprogram the ESN. It is recommended that the ESN reprogramming process be performed only at the factory and not at local factory offices. Security can also be added by using only factory-available microprocessor technical information and loaded into the phone to modify a pre-programmed ESN. The process is feasible using a data transfer device similar to that of FIG. 7 and described with reference to FIG.
As a first step (block 1000), the phone is put into programming mode according to the process of FIG. 8. The factory-supplied data transfer device 750 includes an ESN programming code to facilitate the reprogramming of the ESN. When entered into programming mode, the system loads ESN programming code 756 into PSRAM 407 (block 1002). By performing ESN programming with ESN programming code 756, controller 400 resets the existing ESN (block 1004) and starts the ESN programming process (block 1006).
EE 199900084 A
When the data transfer device 750 has completed entering the new ESN into the EEPROM 410, the controller 400 starts a new hash value calculation including the new ESN 414 (block 1008). The resulting hash value is sent to the data transfer device 750 for digital signing using private key 754 (block 1010). Signed hash value 418 is sent back to controller 400 for storage in EEPROM 410 along with an unsigned version of the same hash value (block 1012).
The hash value calculation and digital signature in the embodiment of the present invention is performed using one-way hash function and private / public key authentication. The one-way hash function is used to extract the hash value of a typical mobile phone's memory content. The private / public key system is used to attempt to verify the correct hash value stored in the EEPROM and the memory of the cellular telephone for the purpose of verifying the authenticity of the programming device or the data transfer device. One-way hash function is known to those skilled in the art and is described, for example, in U.S. Patent No. 5,343,527 issued to Moor.
A one-way hash function is a function that simply works in the reverse direction, but in a complex reverse direction. The one-way hash function E1 (M) is based on the input of a variable length codeword M located in a selected memory area in the embodiment of the present invention. The hash function of M returns to a fixed hash value of h (see equation 1).
h = Η (Λ4) formula 1
There are many different functions that turn a variable-length input into a fixed-length output, but the one-way hash function has the following additional characteristics: knowing M makes it easy to calculate A; knowing A, it is difficult to know M \ and knowing M, it is difficult to find another codeword Af because H (AQ = H (Af)).
The main attack on a one-way hash function is: Knowing the hash value of a (fragmented content) memory input, a hacker may look for an option to create another memory content state, Af, because H (A /) = H (Af). If successful, the security of a one-way hash function would be compromised. The purpose of one-way hash function is to provide a unique signature, or M fingerprint.
In the present invention, a secure one-way hash function is implemented in a selected area of the cellular phone memory to produce a control hash value. The resulting hash value is compared with the hash value obtained previously by using a one-way hash function applied in a selected area of the authentic memory.
EE 199900084 Α. In this version, a codeword algorithm such as MD5 is used for secure one-way hash function. The MD5 algorithm outputs an N-bit portion or message abbreviation based on an input message (for example, a selected memory area). The MD5 algorithm is very sensitive, with every bit of change in the selected memory area causing the hash value of the halves to change. The MD5 algorithm is also known for its speed and simplicity. Speed is a very important factor as the time required from the microprocessor of a mobile phone cannot be high as it can cause unwanted interference in the normal operation of the system.
MD5 is also suitable because it can be implemented in view of the interruptions on which the hash process is based, so that regular microprocessor tasks may be addressed before the hash process ends. In addition, the MD5 algorithm is very compatible with the most commonly used microprocessor architectures. Other one-way hash algorithms that can be used in the present invention but are not limited to are: Srterfu, H-Hash, MD2, MD4, Secure Hash Algorithm (SHA), and HAVAL. One skilled in the art can program the microprocessor to support a one-way hashing process.
Public key algorithms use two keys, one publicly accessible and one secret (secret) to encrypt and decrypt messages, to verify the authenticity of messages and to digitally sign them. These keys are used differently to achieve different goals. For example, if the purpose of the message is to encrypt the message, the recipient's secret key is kept secret, so only the recipient can decrypt the message. In this case, the key used for encryption is known to everyone and its connection to the potential recipient in question is known. While the sender of a message may be confident in the information in this process, the receiver cannot be sure of the authenticity of the sender. If the private (secret) key or pair of keys is kept secret for the sender, each recipient can, according to the public key, find out whether the sender was authentic, albeit without confirmation of security. Below is a diagram used to verify the authenticity of a data transmission device according to the subject matter of the invention.
Public key algorithms work by using mathematical trap-like functions that make it impossible to compute a secret key using the public key. In the well-known RSA (Rivest, Shamir and Adleman) algorithm, security depends on the complexity of the product of two large prime numbers. The selection of the key begins with the selection of two large prime numbers p and q, multiplied by a large number n.
n = pq formula 2
EE 199900084 A
The random encryption key e is then selected such that e and (pl) (ql) are relatively prime numbers. Finally, the Euclidalgorithm's encryption key d is used to calculate:
F = (pl) (qI) Formula 3 ed = 1 (mod F) Formula 4
The numbers e and n are public keys; d is the secret key. Formula 5 depicts the RSA encryption process and formula 6 depicts the decryption process.
C = Afjmod (n) Formula 5
M - C<sup>1</sup> (mod «) formula 6
The factor n is used in formula 3 to determine the module F and then to reveal the secret key d in formula 4 using the public key e. Nevertheless, as noted above, n is usually so large as to render such operations impractical. The present embodiment of the present invention employs the Fiat-Shamir (FS) algorithm or variants thereof (references are made to U.S. Patent No. 4,748,668, the disclosure of which is incorporated herein by reference). The FS algorithm is used in an authentication and digital signature scheme that fits well with the limited computing capacity of a typical mobile phone.
The FS algorithm differs from previous schemes such as RSA in that the FS algorithm is based on the complexity of finding the square root inversion (vj) module n. More specifically, the FS scheme involves dialing n, which is obtained by two large prime numbers and is expected to be 512 to
1064 bits long. Public key (v): v<sub>t</sub>, v<sub>2</sub>, .. v *, and secret key (s): Sj, s<sub>2</sub>, ... Sk is generated such that s, = square root (l / v /) mod n. The complexity of finding the inversion (1 / v /) mod n in the context of the above formula is shown as the equivalent of the complexity of finding the factors of prime n. Without sacrificing security, the algorithm runs much faster than other schemas. In fact, it has been found that the FS scheme outperforms the RSA scheme in that the FS calculation requires only 1 to 4% of the module multiplication normally required to perform the authentication calculation. This results in up to a two-fold increase in the authentication speed of the signed hash value compared to using the RSA scheme to perform the same task. Consequently, data transfer device authentication and periodic hash comparison is feasible using the FS scheme
EE 199900084 A much faster than using the RSA scheme. When a large number of cell phones or other electronic memories are programmed at the factory, using the FS algorithm can reduce product lead times by generating digital signatures and correct hash values for recording faster. Other algorithms that are implemented in collaboration but are not limited to ELGAMAL, DSAFiege-Fiat-Shamir.
According to another object of the present invention, the hardware of the cellular telephone controller has security measures that prevent a hacker from altering the contents of protected memory or in any way disabling the security schemes described above. Figure 11 shows the controller hardware, external memories and memory / address bus structure details. Except for the chip swap logic 1122 and the security logic 1124, the functions and operation of the controller elements are the same as those of FIG. The chip swap logic 1122 decodes the addresses on the microprocessor address bus 1102 to allocate hardware selection signals to the memory components and to the hardware devices connected to the bus 1102. For example, each time an address appears on address bus 1102 assigned to IROM memory 403, the IROM chip selection (CS) is enabled.
Security logic 1124 acts as a detector for access attempts on the PSRAM 407 or to reset the hardware timer 401 using a microprocessor control code stored on a memory other than IROM 403. For example, a read and write instruction disposed in flash memory 420 with the target language address of the PSRAM 407. Any unauthorized access attempt will result in the microprocessor being forced to disable, which will require the power to be turned off completely to resume normal cellular operation.
Security logic is a tool for performing the following logical operations:
Logic 1 S = tSupvr · B
Logic 2 Halt = not S · (A + C) where
S = safe mode;
TSupvr = Putting the microprocessor into monitoring mode;
A = chip selection signal for PSRAM memory;
B = chip selection signal for IROM memory;
C = chip selection signal for hardware timer;
EE 199900084 A
Halt = A hardware control input to a microprocessor that causes either an infinite loop or a complete standby until the power is turned on and off again.
Logic 1 expresses: Safe Mode (S) is enabled as soon as the microprocessor enters monitoring mode (tSupvr) while the IROM 403 chip option is active (· B). Logic 2 expresses: The microprocessor halo input is activated when controller 400 is not in safe mode (not S) and either the PSRAM 407 or the hardware timer chip option is active (· (A + C)). This logic effectively prevents the security measures applied through the hash value comparison and authentication process described above to circumvent the legitimate access to the PSRAM 407 and hardware timer 401 boot commands, which are rather based on IROM 403 code.
All legitimate Codes in the IROM memory 403 (boot code, hash code, public key code, authentication code) are associated with commands that cause the Safe Mode to turn on at the beginning of the routine and to disarm when the routine is terminated. In the embodiment of the present invention, the software interrupt code (usually possible in modern microprocessors) is placed at the beginning of each IROM 403 routine by switching the microprocessor 402 to monitoring mode and causing the microprocessor hardware signal to activate SPVR. As long as the IROM 403 chip selection signal is active at this point, Safe Mode (S) will be activated. Performing a return command at the end of the software routine terminates the safe mode.
According to a further part of the invention, the data transfer device includes a factory-supplied security device that can be used to connect to a conventional computer. An example of this is shown in Figure 12. The security device 1200 is connected to the I / O port of the PC 1202 by means of a standard plug interface 1206. The second port of the PC 1202 is coupled via another standard plug interface 1208, such as an RS 232, cable or infrared port, to connect to the cellular phone 1204. The processes illustrated in Figure 8 are performed using the methodology of Figure 12 to enable the reprogramming process of the cellular telephone. Authorized factory service representative offices have a standard computer equipped with a security device
1200 reprogramming of phones.
According to a further part of the present invention, an existing cellular telephone may be provided with a programming volume that is protected against attacks that do not include access to the internal circuit board assembly. This level of protection is very effective for common use
EE 199900084 A
<img file="EE9900084A_D0001.tif" />
to prevent memory cloning attempts to modify the phone memory using test commands accessible through an external phone connector. This can be done during the mobile phone upgrade using the pre-data transfer device (DTD) authentication procedure described in Figure 8, allowing access to programming commands. Both the authentication software and the public key are stored in existing random access memory, preventing any changes to the normal design.
Exemplary embodiments of the invention have been described in the context of a one-way hash function and an encryption system, such as the protection and programming of a mobile phone's electronic memory. However, these techniques will be understood and recognized by one of ordinary skill in the art as any relevant function, operation, algorithm, method, or memory signature-creation system that is aligned with the present invention. In addition, the invention has been described in discrete parts. However, one skilled in the art will recognize that the invention may be practiced in embodiments other than the preferred embodiments described above. For example, the invention can be used in any electronic memory and / or electronic memory programming or access device without departing from the spirit of the invention. The invention may further be implemented and implemented in digital signal processors, dedicated processor applications, or any other type of processor or electronic memory-oriented system. Therefore, the chosen version described is for illustrative purposes only and is in no way restrictive. The scope of the invention is given in the appended claims, rather than in the foregoing description.
Contents8
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
29 members in 13 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 70657496 | United States of America | A | |
| 9715311 | United States of America | W | |
| 706574 | – | – | – |
| 9715311 | – | – | – |
| US19960706574 | – | – | – |
| WO1997US15311 | – | – | – |
Members29
| Document | Office | Kind | |
|---|---|---|---|
| WO9810611A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU4172297A | Australia | A | |
| WO9810611A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP0923842A2 | European Patent Office (EPO) | A2 | |
| PL332050A1 | Poland | A1 | |
| BR9712007A | Brazil | A | |
| EE9900084AThis record | Estonia | A | |
| CN1235743A | China | A | |
| US6026293A | United States of America | A | |
| HK1021104A1 | Hong Kong, China | A1 | |
| KR20000068467A | Republic of Korea | A | |
| JP2001500293A | Japan | A | |
| AU734212B2 | Australia | B2 | |
| CN1446015A | China | A | |
| CN1126398C | China | C | |
| KR100492840B1 | Republic of Korea | B1 | |
| EP0923842B1 | European Patent Office (EPO) | B1 | |
| DE69736065D1 | Germany | D1 | |
| ES2262189T3 | Spain | T3 | |
| DE69736065T2 | Germany | T2 | |
| JP2007293847A | Japan | A | |
| JP4050322B2 | Japan | B2 | |
| JP2008112443A | Japan | A | |
| JP2011170841A | Japan | A | |
| JP4777957B2 | Japan | B2 | |
| JP2011238246A | Japan | A | |
| JP4917681B2 | Japan | B2 | |
| JP4955818B2 | Japan | B2 | |
| BRPI9712007B1 | Brazil | B1 |
Numbers
- Publication, DOCDB
- 9900084
- Publication, EPODOC
- EE9900084
- Application
- 19990000084
- Application, DOCDB
- 9900084
- Application, EPODOC
- EE19990000084
Titles2
- English
- Gawk electronic protection system
- Estonian
- Elektroonilise mälu kaitsesüsteem
Classification
- CPC, 13
- G06F21/565
- H04L9/0643
- H04L9/3239
- H04L9/3247
- H04L9/3271
- H04L63/0823
- H04L63/123
- H04L2209/80
- H04W12/00512
- H04W12/06
- H04W12/10
- H04W12/1206
- H04W88/02
- IPC, 7
- G06F12 14
- G06F1 00
- G06F21 00
- G06F21 24
- G09C1 00
- H04L9 32
- H04W88 02