Method for secure storage of sensitive data in a silicon chip integrated system storage, in particular a smart card, and integrated system therefor
Abstract
This record has no abstract on file.
Term
Term ended
Projected expiry passed 8 June 2021, 5.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
11 claims: 2 independent, 9 dependent
- 1Claims of equivalent WO 0195273 A1 REVENDICATIONS 1. Procédé d'enregistrement sécurisé d'une donnée dite sensible dans une mémoire d'un système embarqué à puce électronique comprenant aux moins deux moyens de mémoire physiquement distincts, caractérisé en ce que ladite donnée sensible est scindée en au moins deux parties {d, d'), selon une configuration logique déterminée, et en ce que chacune desdites parties scindées (d, d') est enregistrée dans un desdits moyens de mémoire physiquement distincts (1 , 2).
- 2Procédé selon la revendication 1 , caractérisé en ce que, ladite donnée sensible étant scindée en au moins deux parties (d, d'), elle constitue un secret unique et en ce que chacune desdites parties scindées est enregistrée dans un desdits moyens de mémoire physiquement distincts (1 , 2).
- 3Procédé selon la revendication 1 , caractérisé en ce que ladite donnée sensible étant scindée en au moins deux parties (d, d'), ladite première partie (d) constitue un premier secret et chacune desdites parties supplémentaires (d') sont dérivées de ladite première partie (d) pour constituer des secrets supplémentaires, et en ce que chacune desdites parties scindées est enregistrée dans un desdits moyens de mémoire physiquement distincts (1 , 2).
- 4Procédé selon la revendication 1 , caractérisé en ce que ladite donnée sensible est un mot binaire de longueur égale à un nombre déterminé d'octets et est scindée de façon à être enregistré dans deux moyens de mémoire physiquement distincts (1 , 2), en ce qu'une première partie est un premier mot binaire (d) constitué de blocs d'octets (B B 8 ), de même longueur que ladite donnée sensible, en ce que cette première partie (d) comporte une suite d'octets corrects et d'octets altérés (Oι-0 8 ), répartis dans ledit mot (d) selon une configuration prédéterminée, en ce que ladite seconde partie est un second mot binaire (d'), de longueur égale au nombre desdits octets altérés {O^O β ) et constitué d'octets (0'ι-0' 8 ) en correspondance biunivoque avec lesdits octets altérés (Or0 8 ), de manière à pouvoir corriger ces octets altérés (Or0 8 ) et à reconstituer ladite donnée sensible à partir desdites première (d) et seconde parties (d').
- 5Procédé selon la revendication 4, caractérisé en ce que ladite donnée sensible est une clé de chiffrage.
- 6Procédé selon la revendication 1 , caractérisé en ce que, ladite donnée sensible étant scindée en des première (d) et seconde parties (d'), enregistrées respectivement dans des premier (1 ) et second (2) moyens de mémoire physiquement distincts, il est procédé à une opération, concomitante à l'enregistrement de ladite première partie (d), dite de somme de contrôle sur ladite donnée sensible dont le résultat se présente sous la forme d'une donnée d'information, en ce que ladite donnée d'information est enregistrée dans lesdits premiers moyens de mémoire (1 ), et en ce qu'il comprend une lecture de ladite donnée d'information, une opération supplémentaire de contrôle de somme sur ladite donnée sensible et une comparaison entre ladite donnée d'information lue et le résultat de ladite opération de contrôle de somme supplémentaire lors de chaque utilisation de ladite donnée sensible, de manière à en certifier l'intégrité.
- 7Procédé selon la revendication 1 , caractérisé en ce que, ladite donnée sensible étant scindée en des première (d) et seconde parties (d'), enregistrées respectivement dans des premier (1) et second (2) moyens de mémoire physiquement distincts, il est procédé à une opération, concomitante à l'enregistrement de ladite première partie (d), dite de hachage de ladite donnée sensible dont le résultat se présente sous la forme d'une donnée d'information (H), en ce que ladite donnée d'information (H) est enregistrée dans lesdits premiers moyens de mémoire (1), et en ce qu'il comprend une lecture de ladite donnée d'information (H), une opération supplémentaire de hachage de ladite donnée sensible et une comparaison entre ladite donnée d'information lue et le résultat de ladite opération de hachage supplémentaire lors de chaque utilisation de ladite donnée sensible, de manière à en certifier l'intégrité.
- 8Procédé selon la revendication 7, caractérisé en ce que ladite opération de hachage est obtenue par l'application sur ladite donnée sensible de l'algorithme de hachage dit "SHA-1 ".
- 9Système embarqué à puce électronique muni de moyens de mémoire pour l'enregistrement d'au moins une donnée dite sensible, lesdits moyens de mémoire comprenant au moins deux organes de mémoire physiquement distincts, caractérisé en ce que ladite donnée sensible étant scindée en au moins deux parties (d, d') de configurations déterminées, chacun desdits organes de mémoire (1 , 2) enregistre l'une desdites parties de donnée sensible (d, d').
- 10Système selon la revendication 9, caractérisé en ce que lesdits moyens de mémoire (M) comprennent un premier organe de mémoire fixe à lecture seule, de type dit "ROM" (1), et un deuxième organe de mémoire re-programmable par effacement par voie électrique à lecture seule, de type dit "EEPROM" (2), et en ce que chacun desdits premier (1 ) et deuxième (2) organes de mémoire enregistre une desdites parties (d, d') scindées de ladite donnée sensible.
- 11Système selon la revendication 9, caractérisé en ce qu'il est constitué par une carte à puce (CP).
Independent claims11
39 paragraphs in 4 sections, as filed
Translation of description of equivalent WO 0195273 A1
SAFE STORAGE METHOD OF SENSITIVE DATA IN
A MEMORY OF A SYSTEM BOARD SMART ELECTRONIC
IN PARTICULAR A SMART CARD, AND EMBEDDED SYSTEM
IMPLEMENTING THE PROCESS
A secure registration process sensitive data in a memory of an embedded microchip system.
It applies more particularly to a smart card. The invention also concerns an embedded system for the implementation of the process.
In the context of the invention, the term "embedded system" refers to the various systems or devices having in common the fact of having an electronic chip including memory means and data processing, generally constituted by a microprocessor or a microcontroller. Such an embedded system can be composed in particular of a smart card.
Similarly, the term "sensitive" should be understood in its most general sense. It covers all sorts of secret data or at least confidential, including encryption algorithms, secret key encryption, identification data or secret information, etc., stored in one or more types of memory which are equipped with smart cards. This type of data will be referred to hereinafter as "secret", generically. The invention applies more particularly, but not exclusively, for the storage of secret keys stored in seen to be used to secure the pre-initialization of chip cards. It is well known that the safety-related functions are devolved to smart cards. Again the term security is to be understood in a broad sense. This covers in fact various concepts: confidentiality, authenticated cation, etc. Below, to fix ideas and without limiting anything in his reach, we will place in this case preferred embodiment of the invention, unless otherwise indicated.
Usually, in the prior art, the secrets contained in the smart cards are linearly stored in the same memory area. In particular, the secrets are stored in fixed memory to read-only ( "ROM", for "Read Only Memory") or semi-fixed, that is to say reprogrammable electrically erasable read-only, e.g. so-called "EEPROM" ( "Electrically Erasable Programmable Read-Only Memory"). But the memories of the chips fall prey to fraudsters and attacks that can be seen are increasingly numerous and sophisticated.
In particular, the "dumping" ( "dump" or copy from memory) Memory "ROM" is a constant concern for smart cards. The type of memory "EEPROM" containing traditionally called sensitive data, are subject to most attacks known at present.
The invention aims to overcome the drawbacks of the prior art, some of which have been recalled. The invention has set the goal a secure method of storing sensitive data in the memory of a smart card, and more generally in the memory of an embedded microchip system.
It also relates to an embedded microchip system for implementing the method. The chip includes means for memory and data processing, usually under the control of an operating system (or "OS" to "Operating System" according to the English terminology).
To do this, according to an advantageous feature, the secret is "broken" physically and logically in several memory means which is provided with the electronic chip. In one advantageous embodiment, the memory of said chip is divided into two distinct parts, the first consisting of a type of memory "ROM", more generally a fixed read-only memory, the second part consisting of a type of memory "EEPROM", more generally a semi-permanent memory reprogrammable.
In a first embodiment of the invention, one secret is "split" between two or more memory parts physically distinct. In particular, in the preferred scope of the invention, the method allows the authentication of a smart card pre-boot phase, when the portion of memory type "EEPROM" is still a virgin data outside of those programmed by an entity that will be called hereinafter "depth". In the context of the invention, the term "pre-boot" means in a general sense. It is particularly related to the manufacturing phase of a conventional smart card or to the phase preceding the phase of initialization of a card called open chip.
According to one further advantageous embodiment, the bulk of the data constituting the secret is stored in memory "ROM". Only a small portion of this data is stored in memory "EEPROM."
According to this additional feature of the invention, a secret key is then contained in the type memory portion "ROM", in its great majority. Just write to the founder of a smaller part of the secret key in the part of type memory "EEPROM" for the above operating system may have the secret key in its entirety. Due to its particular storage, it should be noted that the secret key is sent in two parts with two separate services at the foundry, which reduces the risk of fraud when transferring secret. This particular storage therefore minimizes the number of bytes programmed in by the tip depth and therefore presents the advantage of reducing the manufacturing costs. In order to ensure a high degree of security, currently used keys are of great length. One can thus reduce the storage of these key of great length, usually carried out in "EEPROM" in deporting the greater part in the "ROM".
In a second embodiment, a first secret is stored in a first portion of memory and one or more other secrets, derivative (s) of the first secret, directly or indirectly, is (are) stored (s) in at least one another part of physically separate memory. This or these secret (s) extra (s) may be obtained (s) advantageously by encryption.
For example, in a typical application of the method according to the invention, an encryption key (symmetric) is present in a first memory area of a chip card, such as "ROM", at the time masking thereof. Confidential information is stored in a second memory area, type "EEPROM" when using the smart card. This information is encrypted (for example using the algorithm known triple "DES") with the aforementioned encryption key of this in the "ROM". This method is of great interest. Indeed, in addition to protection against "dumping" of memory, we find that the information is protected when it is written to the smart card. Even the entity that "writing" key does not know.
From the foregoing, it follows that, whatever the embodiment considered or variations of such embodiments, a successful fraudulent attack a party of memory can lead to the complete knowledge of the secret . In reality, and to the extent the distribution of secret elements between the distinct parts of the memory is carried out wisely, partial knowledge of the secret acquired fraudulently never will later find the secret, for example by trying a decryption using appropriate mathematical treatment, thereby to deduce the complete secrecy of the aforementioned partial knowledge. This judicious distribution is in itself accessible to the skilled worker. We can therefore consider that the attack ultimately failed.
In addition, as will be shown hereinafter in more detail, it is possible to combine the method of the invention for verification provisions, authentication and / or encryption, known per se, but whose degree of security is achieved through strengthened provisions to the invention.
The invention therefore principal object a secure method for recording sensitive data in a memory called an embedded system on chip including at least two physically distinct storage means, characterized in that said sensitive data is split in at least two parts, according to a specific logic configuration, and in that each of said parts split is recorded in one of said physically distinct storage means.
The invention also relates to an embedded microchip system for implementing the method.
In a particular embodiment, the method is characterized in that said sensitive data being split into first (d) and second parts (d "), recorded respectively in the first (1) and second (2) memory means physically distinct, there shall be an operation concurrent with the recording of said first part (d), called checksum control on said sensitive data, the result is in the form of a given information, in that said information data is recorded in said first memory means (1), and in that it comprises a reading of said information data, an additional operation checksum on said sensitive data and comparison between said read information given and the result of said additional checksum operation with each use of said sensitive data in order to certify its integrity. In another particular embodiment, the method is characterized in that said sensitive data being split into first (d) and second parts (o "), recorded respectively in the first (1) and second (2) ways to physically distinct memory, there shall be an operation concurrent with the recording of said first part (d), called hash said sensitive data, the result is in the form of a given information (/ - / ), in that said information data (H) is stored in said first memory means (1), and in that it comprises a reading of said information data (H), an additional hashing operation said sensitive data and comparing said read information data and the result of said additional hash operation during each use of said sensitive data, so as to certify the integrity.
The invention will now be described in more detail with reference to the accompanying drawings, in which: Figure 1 schematically illustrates an example of the memory configuration of a smart card according to one aspect of the invention, for an application the method for recording a secret key; and Figure 2 schematically illustrates an alternative embodiment of the memory configuration of a smart card of Figure 1. As indicated in the preamble of the present description, reference is hereafter placed under the preferred application of the invention, that is to say in the case of securing the preboot phase of a smart card.
More precisely, we will illustrate the method according to the invention in its application to the storage of an asymmetric secret key that will be referenced below d. This key d can allow a smart card to generate a cryptogram from an appropriate asymmetric algorithm. This cryptogram, if it is returned to an authentication terminal the chip card can be used for authentication thereof.
Figure 1 illustrates, schematically, a map of exemplary architecture chip CP. The latter includes a memory M, itself constituted in the example described, a RAM random access type called "RAM" (for "Random Access Memory") 3 and a non-volatile memory including a portion fixed 1, type "ROM", and a semi-fixed part 2, type "EEPROM" or similar. The smart card CP further comprises data processing means, for example a microprocessor referenced CPU cooperating with an operating system 4. The operating system is a piece of software consists of a sequence of microinstructions that can be stored in whole or part within the area "ROM" 1 and / or zone "EEPROM" 2 of the memory M.
According to a feature of the invention, the storage of the key is performed in at least two physically separate parts of the memory M. More specifically, in the illustrated example, the storage of this key is performed in non-volatile part of the memory M: some fixed memory 1, type "ROM", and some semi-permanent memory 2, type "EEPROM" or similar. The secret key d is therefore composed of a part in "ROM" 1 this before arrival in the entity that has been called "depth" and a written portion during an operation called "sub peak "by the latter, in" EEPROM "2. bytes programmed" EEPROM "2 are extremely sensitive data, treated as security bytes. This of course implies that the secret key d is already known at the time of masking.
For example, to fix ideas, we will consider following a secret key of 1024 bits (128 bytes).
In a preferred embodiment of the invention, the key to totally lies in "ROM" 1, but some bytes are false or altered. For example, a sixteen byte by byte block is false, a false value having been intentionally written into the code "ROM".
Is shown in FIG 1 the different blocks of the key to under the references B to B<sub>8</sub>. The erroneous bytes are referenced O 0<sub>8</sub>. Valid values referenced bytes, 0-0 '<sub>8</sub>Are stored in
"EEPROM" 2, also in the form of eight corresponding bytes. These bytes, O'I 0 '<sub>8l</sub> form a key part o ".
In this example, eight bytes (or 128/16 = 8) must be programmed in "EEPROM" 2. But it should be understood that the storage "EEPROM" 2 may be any operating system 4, cooperating with CPU data processing means being responsible for reconstitution into "RAM" 3 of the exact complete key, that can be called of "in use. This reconstruction is carried out, in the example described, simply by substitution of correct bytes, 0 0 '<sub>8</sub>, The erroneous bytes, Ot 0<sub>8</sub>.
This shows that the knowledge of a key, either, or of, by any means whatsoever, including the fraudulent "dumping" above, does not allow to deduce the "complete secrecy" that is to say, the correct key to complete. "as noted, the key to getting a good security are usually long, for example 128 bytes or 1024 bits as described above. the process of the invention, besides the degree of security it brings, allows not having to register in "EEROM" 2 very small a fraction of the total key d, or 8 bytes or 64 bits. only this key fraction should be written under "advanced" by the founder, which has a significant advantage, as this is long and expensive.
It should be understood that many other key distribution patterns between the two types of memory, "ROM" 1 and "EEPROM" 2, are possible. Both sets of bytes should only be one correspondence. However, the skilled person must ensure that this distribution does not allow that knowledge a two partial keys: d (having the same length as the correct total key d ", but partly" altered ") or authorizes, by mathematical or other methods, the deduction of the total key, from this partial knowledge. the distribution which has just been described with reference to Figure 1, for the considered key lengths satisfies this requirement.
In a further alternative embodiment of the inventive method, in order to further increase the degree of security obtained, the storage is provided in "ROM" 1 of a given information to ensure the integrity of the key d secret and thus preserve over time the integrity of memory "ROM" 1 and "EEPROM" 2. This data may take the form of a checksum calculation on the secret key, known as Anglo-Saxon "checksum". This data can still be obtained by using a hash function or "hash" of the same key. To do this, in the latter case, there is advantageously used an algorithm of the type known as "SHA-1" symbol. This particular algorithm must be implanted in the smart card. The result of this hash function has a length of 160 bits. The initial operation for obtaining said data is concomitant with the registration of the key of the "ROM" 1. "checksum" or "hash" is performed at each use of the secret key and compared with the given of information recorded in the memory "ROM" 1.
2 schematically illustrates the architecture of a smart card CP storing such data "hash" in memory "ROM" 1. Common elements in Figure 1 have the same references and are described again as needed.
The data is stored in H "ROM" 1 and checked every time the key to preserve the integrity of the memory area "ROM" 1 and "EEPROM" 2. This check is performed under control of the processing means CPU data and programs stored in memory. Up to this stage of the description, it was assumed, at least implicitly, that the secret data shared between the two physically separate parts of the memory M were one and the same secret. In a further variant of the method according to the invention, the secret data stored in memory "ROM" 1 may be a first secret. second secret data, derived from the first secret data, can be a second secret. This data, according to a feature of the invention, are then stored in a physically separate second part of the memory M, for example in
"EEPROM" 2. This data may advantageously be obtained by encryption of the first data, by using any appropriate algorithm, of symmetrical type or not. We can consider that the secret is "shared" or "split" within the meaning of the method of the invention, it can not be deduced from the knowledge of one part of the memory M.
On reading the above, we can easily see that the invention achieves the goals it has set.
It allows a great degree of security for the storage of sensitive data, such key or the like, by physically distributing them in at least two physically separate parts of the memory of a smart card, and more generally a system embedded microchip.
It should be clear however that the invention is not limited to just the exemplary embodiments explicitly described, particularly in connection with Figures 1 and 2.
It can include distributing secret data in more than two parts of discrete memory. Similarly, when the distributed data do not represent one and the same secret, the number of secrets derived from the first may be greater than unity. One can also derive cascading secrets and record them separately in parts physically separate memories. The invention is also not limited to applying the pre-authentificatiorc initilisation phase of a smart card which has been mentioned in more detail. It applies whenever a sensitive data, encryption key or other, must be stored in the memory of an embedded system.
Contents4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO9839701A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
12 members in 6 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 0007318 | France | A | |
| 0007318 | France | A | |
| 0007318 | France | – | |
| 0101773 | France | W | |
| 0101773 | France | W | |
| 0007318 | – | – | – |
| FR0101773 | – | – | – |
| FR20000007318 | – | – | – |
| WO2001FR01773 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| WO0195273A1 | World Intellectual Property Organization (WIPO) | A1 | |
| FR2810138A1 | France | A1 | |
| US2002108051A1 | United States of America | A1 | |
| EP1247263A1This record | European Patent Office (EPO) | A1 | |
| CN1386250A | China | A | |
| JP2003536154A | Japan | A | |
| FR2810138B1 | France | B1 | |
| CN1193320C | China | C | |
| JP3734473B2 | Japan | B2 | |
| JP2006048704A | Japan | A | |
| US7260727B2 | United States of America | B2 | |
| JP5082046B2 | Japan | B2 |
6 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 1247263
- Publication, DOCDB
- 1247263
- Publication, EPODOC
- EP1247263
- Application
- 1945377
- Application, DOCDB
- 01945377
- Application, EPODOC
- EP20010945377
Titles3
- German
- VERFAHREN ZUM GESICHERTEN SPEICHERN VON SENSIBLEN DATEN IN EINEM SPEICHER EINES MIT EINEM ELEKTRONISCHEN CHIP VERSEHENEN SYSTEMS, INSBESONDERE EINER CHIPKARTE, UND EINGEBETTETES SYSTEM ZUR DURCHFÜHRUNG DES VERFAHRENS
- English
- METHOD FOR SECURE STORAGE OF SENSITIVE DATA IN A SILICON CHIP INTEGRATED SYSTEM STORAGE, IN PARTICULAR A SMART CARD, AND INTEGRATED SYSTEM THEREFOR
- French
- PROCEDE DE STOCKAGE SECURISE D'UNE DONNEE SENSIBLE DANS UNE MEMOIRE D'UN SYSTEME EMBARQUE A PUCE ELECTRONIQUE, NOTAMMENT D'UNE CARTE A PUCE, ET SYSTEME EMBARQUE METTANT EN OEUVRE LE PROCEDE
Classification
- CPC, 3
- G07F7/1008
- G06Q20/341
- G07F7/082
- IPC, 5
- G06K19 07
- G06K19 073
- G06K19 10
- G07F7 10
- H04L9 10
Designated states1
- Contracting states, 1
- Türkiye