Data encryption in an electronic apparatus with several symmetrical processors
Abstract
The method involves selecting a secret key from keys stored with key identifiers in registers. Data is divided into a stream of data words of determined size. A pseudo-random number is generated based on the secret key and an initialization vector. The data word and number are combined to generate an encrypted data word and the encrypted data word is stored with the vector and the identifier of the key in an external memory (23). Independent claims are also included for the following: (A) a device for implementing a data encrypting method (B) an electronic apparatus having processors with encrypting/decrypting unit.

Term
Term ended
Projected expiry passed 6 September 2024, 2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
14 claims: 5 independent, 9 dependent
- 1Method of encryption in a circuit (2) of an electronic apparatus, of data storing in a memory (23) external to said circuit, comprising the steps of:select a secret key (K) from a secret key list (K) respectively stored in a set of registers (32) of the circuit each combination with a key identifier (KID), at least one said keys being a key shared with at least one other circuit the electronic apparatus;cut data as a stream of data words (Wi) of size determined;and, continuously for each data word,generating a pseudo random number (PNi) of the determined size means of a pseudorandom generator implementing an algorithm of generation based on said secret key and an initialization vector (IVi) changing value to each data word;combining the data word and the pseudo random number corresponding to generate an encrypted data word (Ci);then,storing in said external memory each encrypted data word in association with the initialization vector and the key identifier (KIDI) associated with the secret key used to encrypt it. Procédé de chiffrement dans un circuit (2) d'un appareil électronique, de données à stocker dans une mémoire (23) externe audit circuit, comprenant les étapes consistant à : - sélectionner une clé secrète (Ki), à partir d'une liste de clés secrètes (K) respectivement stockées dans un ensemble de registres (32) du circuit en association chacune avec un identificateur de clé (KID), au moins l'une desdites clés étant une clé partagée avec au moins un autre circuit de l'appareil électronique ;- découper les données en un flux de mots de données (Wi) de taille déterminée ;et, en continu pour chaque mot de données,- générer un nombre pseudo aléatoire (PNi) de taille déterminée au moyen d'un générateur pseudo aléatoire mettant en oeuvre un algorithme de génération en fonction de ladite clé secrète et d'un vecteur d'initialisation (IVi) changeant de valeur à chaque mot de données ;- combiner le mot de données et le nombre pseudo aléatoire correspondant, pour générer un mot de données chiffré (Ci) ;puis,- stocker dans ladite mémoire externe chaque mot de données chiffré en association avec le vecteur d'initialisation et l'identificateur de clé (KIDi) associé à la clé secrète ayant servi à le chiffrer.
- 4A method of decryption, in a circuit (2) of an electronic apparatus, data stored in the form of encrypted data words in a memory (23) external to said circuit, comprising the steps of:said external memory read an encrypted data word (Cj) and an initialization vector (IVj) and a secret key identifier (KIDj) respectively associated with said data word;select a secret key (K) from a secret key list (K) respectively stored in a set of registers (32) of the circuit and of which at least one is a key shared with at least one other circuit the electronic device, and from further said identifier;and, continuously for each encrypted data word,generating a pseudo random number (PN) of fixed size, means of a pseudorandom generator (10) implementing an algorithm based generation of said secret key and of said initialization vector;and,combining the data word and the pseudo random number corresponding to generate a decrypted data word (wj). Procédé de déchiffrement, dans un circuit (2) d'un appareil électronique, de données stockées sous la forme de mots de données chiffrés dans une mémoire (23) externe audit circuit, comprenant les étapes consistant à : - lire dans ladite mémoire externe un mot de données chiffrés (Cj) ainsi qu'un vecteur d'initialisation (IVj) et qu'un identificateur de clé secrète (KIDj) respectivement associés audit mot de données ;- sélectionner une clé secrète (Kj), à partir d'une liste de clés secrètes (K) respectivement stockées dans un ensemble de registres (32) du circuit et dont l'une au moins est une clé partagée avec au moins un autre circuit de l'appareil électronique, et à partir en outre dudit identificateur ;et, en continu pour chaque mot de données chiffré,- générer un nombre pseudo aléatoire (PNj) de taille déterminée, au moyen d'un générateur pseudo aléatoire (10) mettant en oeuvre un algorithme de génération en fonction de ladite clé secrète et dudit vecteur d'initialisation ;et,- combiner le mot de données et le nombre pseudo aléatoire correspondant, pour générer un mot de données déchiffré (Wj).
- 7Device for the implementation of a cryptographic method according to one of claims 1 to 3, comprising:a set of registers (32) storing secret keys (K) respective ones of which at least one is a key shared with another circuit the electronic apparatus, in association with each key identifier (KID);a secret key selection unit adapted to select a secret key (Ki) from the list of keys stored in said set of records;a segmentation unit (22) adapted to cut out data so as to form a stream of data words (Wi) of determined size;a generator of initialization vectors (24) adapted to generate a Flow initialization vectors (IVi) value of changing each word data;a generator of pseudorandom numbers (10) implementing a generating algorithm suitable for generating, for each word data, based on said secret key and of said vectors determined initialization, a pseudo random number (PNi) of determined size;a combination unit (11) suitable for continuously combining the data word and the corresponding pseudo-random number to generate a encrypted data word (Ci);and,means for storing in said external memory each word Data encrypted in association with said determined and initialization vector the key identifier associated with the secret key used to encrypt it. Dispositif pour la mise en oeuvre d'un procédé de chiffrement selon l'une quelconque des revendications 1 à 3, comprenant : - un ensemble des registres (32) stockant des clés secrètes (K) respectives, dont l'une au moins est une clé partagée avec un autre circuit de l'appareil électronique, en association chacune avec un identificateur de clé (KID) ;- une unité de sélection de clés secrètes adaptée pour sélectionner une clé secrète (Ki) à partir de la liste des clés stockées dans ledit ensemble de registres ;- une unité de segmentation (22) adaptée pour découper les données de manière à former un flux de mots de données (Wi) de taille déterminée ;- un générateur de vecteurs d'initialisation (24) adapté pour générer un flux de vecteurs d'initialisation (IVi) changeant de valeur à chaque mot de données ;- un générateur de nombres pseudo aléatoires (10) mettant en oeuvre un algorithme de génération adapté pour générer, pour chaque mot de données, en fonction de ladite clé secrète et d'un déterminé desdits vecteurs d'initialisation, un nombre pseudo aléatoire (PNi) de taille déterminée ;- une unité de combinaison (11) adaptée pour combiner en continu le mot de données et le nombre pseudo aléatoire correspondant, pour générer un mot de données chiffré (Ci) ;et,- des moyens pour stocker dans ladite mémoire externe chaque mot de données chiffré en association avec ledit vecteur d'initialisation déterminé et l'identificateur de clé associé à la clé secrète ayant servi à le chiffrer.
- 8Device for the implementation of a decryption method according to to any one of claims 4 to 6, comprising:a set of registers storing respective secret keys which at least one is a shared key, each in association with a key identifier;reading means for reading from said external memory one word data and an initialization vector and with an identifier of a key secret associated respectively to said data word;selection means for selecting, for each word data, a secret key from a list of keys stored in said registers and from further said key identifier;a generator of pseudorandom numbers (10) implementing a generating algorithm suitable for generating, for each word data, based on said secret key and of said initialization vector, a pseudorandom number of determined size;and,a combination unit adapted to combine the data word and the corresponding pseudo-random number, so as to decrypt said data word of data. Dispositif pour la mise en oeuvre d'un procédé de déchiffrement selon l'une quelconque des revendications 4 à 6, comprenant: - un ensemble de registres stockant des clés secrètes respectives dont l'une au moins est une clé partagée, en association chacune avec un identificateur de clé ;- des moyens de lecture pour lire dans ladite mémoire externe un mot de données ainsi qu'un vecteur d'initialisation et qu'un identificateur d'une clé secrète respectivement associés audit mot de données ;- des moyens de sélection pour sélectionner, pour chaque mot de données, une clé secrète à partir d'une liste de clés stockées dans lesdits registres et à partir en outre dudit identificateur de clé ;- un générateur de nombres pseudo aléatoires (10) mettant en oeuvre un algorithme de génération adapté pour générer, pour chaque mot de données, en fonction de ladite clé secrète et dudit vecteur d'initialisation, un nombre pseudo aléatoire de taille déterminée ;et,- une unité de combinaison adaptée pour combiner le mot de données et le nombre pseudo aléatoire correspondant, de manière à déchiffrer ledit mot de données.
- 14An electronic apparatus comprising at least two circuits according to any one of claims 9 to 13, wherein at least one of the keys secret is shared between said circuits so as to form a subsystem secured. Appareil électronique comprenant au moins deux circuits selon l'une quelconque des revendications 9 à 13, dans lequel au moins l'une des clés secrètes est partagée entre lesdits circuits de manière à former un sous-système sécurisé.
Independent claims5
54 paragraphs, as filed
The present invention relates generally to encryption or encryption of data to be used in one or more processors, where data must be stored in a memory external to the processors.
It finds applications in particular in apparatus electronic architecture with several symmetric processors and external shared memory (SMP architecture, standing for "Symmetric Multi-Processor"). More specifically, the present invention relates to applications where it is desired to prevent an unauthorized user accesses operably data, and in which said data is to, in least in part, can be accessed by more than one circuit.
This refers to the term "data" to refer indifferently any binary code whether executable programs, or binary data processed by these programs. In addition, it is reference to the term "circuit" to describe any unit indifferently Function of an electronic apparatus connected to other functional units via one or more communication bus, be it a processor, device controller (eg, a disk controller), a map network, etc.
Figure 1 schematically illustrates the SMP architecture of a device electronic, to which the present invention applies. multiple processors 2 (CPU) are coupled to an external memory 4 (EXT MEM), through one or more bus 3. We can define a zone 1, said safe area, inside of which there is one or more processors 2, and within which it is considered that the processed data are not likely to be pirated. In practice, the secure area 1 usually comprises one or several integrated circuit chips corresponding to respective processors, the memory 4 being another chip that does not belong to the secure area. In Additionally, other circuit 5 as a disk controller (CTRL DSK) or NIC (NET CARD), may be connected to processor 2 by via bus 3.
Encryption which applies the present invention more particularly that of data transmitted on the bus or 3, between 4 memory and the processor 2 in zone 1. In the jargon of Man the trade, we talk about memory encryption or encryption of bus. This encryption is to encode the data stored in the memory 4 by means of a bus encryption key known by the processors concerned.
Examples of solution to encrypt a memory external to a microprocessor are described in U.S. Patent 5,825,878, 5,982,887, and 6,041,449.
These solutions are not suited to the case of systems SMP architecture, in so far as they must use the same key bus encryption to encrypt and to decrypt the data while each processor uses a bus encryption key of its own. In Indeed, measures must be taken to allow another processor of the secure area to decipher, to use, encrypted data and stored in the shared external memory with another processor of said secure area. These measures must be compatible with the secret key character of the bus encryption keys.
Another constraint is associated with the encryption method used. In the prior art, are generally used block ciphers with type algorithms DES ( "Data Encryption System") or AES ( "Advanced Encryption System "), as a mode electronic coding book says fashion ECB ( "Electronic Code Book") or mode by chaining said blocks CBC mode ( "Cipher-Block Chaining"). The size of a block depends on the algorithm used encryption. In the ECB mode, two identical blocks are encrypted in the same way. Attacks are possible by the technique called "Dictionary", insofar as the redundancy of encrypted messages identically may allow the identification of clear messages. By opposition in the CBC mode, each block is encrypted function blocks precedents. This mode is more robust. Nevertheless, it requires access sequential memory, which makes it incompatible with the encryption data that is desired to randomly access the external memory.
The present invention is to provide, in the context of a device electronic SMP architecture, a new encryption technique, a processor, data to be stored in a memory external to the processor, when data needs to be processed by more than one processor.
To this end, a first aspect of the invention provides a method of encryption in a circuit of an electronic apparatus, of data to be stored in a memory external to said circuit, comprising the steps of:<ul><li>select a secret key from a secret key list respectively stored in a set of registers in circuit each combination with a key identifier, at least one of said key being a key shared with at least another unit circuit electronics;</li><li>cut data as a stream of size data words determined; and, continuously for each data word,</li><li>generating a pseudo random number determined by size a pseudorandom generator implementing an algorithm of generation based on said secret key and an initialization vector changing value to each data word;</li><li>combining the data word and the pseudo random number corresponding to generate an encrypted data word; then,</li><li>storing in said external memory each encrypted data word in association with the initialization vector and the key identifier associated with the secret key used to encrypt it.</li></ul>
A second aspect of the invention provides a method of decryption, in a circuit of an electronic apparatus, of data stored in the form of encrypted data words in a memory external audit circuit, comprising the steps of:<ul><li>said external memory read an encrypted data word and an initialization vector and a secret key identifier respectively associated with said data word; </li><li>select a secret key from a secret key list respectively stored in a set of system registers and including a at least is a key shared with at least another unit circuit electronics, and from further said identifier; and, continuously for each encrypted data word,</li><li>generating a pseudo random number determined by size a pseudorandom generator implementing an algorithm of generation based on said secret key and of said initialization vector; and</li><li>combining the data word and the pseudo random number corresponding to generate a decrypted data word.</li></ul>
A third aspect of the invention relates to a device for implementing an encryption method according to the first aspect, comprising:<ul><li>a set of registers storing respective secret keys, of which at least one is a shared key with another device circuit electronics, each in association with a key identifier;</li><li>a secret key selection unit adapted to select a secret key from the list of keys stored in said set of records;</li><li>a segmentation unit suitable for cutting data to form a stream of fixed sized data words;</li><li>an initialization vector generator adapted to generate a flow initialization vectors changing value to each data word;</li><li>a generator of pseudorandom numbers implementing a generating algorithm suitable for generating, for each data word, based on said secret key and of said vectors determined initialization, a pseudo random number of fixed size;</li><li>a combination unit suitable for continuously combining the word data and the corresponding pseudo-random number to generate a word encrypted data; and,</li><li>means for storing in said external memory each word Data encrypted in association with said determined and initialization vector the key identifier associated with the secret key used to encrypt it.</li></ul>
In addition, in a fourth aspect, the invention provides a device for the implementation of a decryption method according to the second aspect. This device comprises:<ul><li>a set of registers storing respective secret keys which at least one is a shared key, each in association with a key identifier;</li><li>reading means for reading from said external memory one word data and an initialization vector and with an identifier of a key secret associated respectively to said data word;</li><li>selection means for selecting, for each word data, a secret key from a list of keys stored in said registers and from further said key identifier;</li><li>a generator of pseudorandom numbers implementing a generating algorithm suitable for generating, for each data word, based on said secret key and of said initialization vector, a number pseudorandom fixed size; and,</li><li>a combination unit adapted to combine the data word and the corresponding pseudo-random number, so as to decrypt said data word of data.</li></ul>
A fifth aspect of the invention relates to a circuit comprising a encryption unit / decryption forming encryption device according to the third aspect and decryption device of the fourth aspect. The set of registers, the pseudo-random numbers and unity combination are then common to both devices.
According to a sixth and final aspect, the invention also provides a Electronic apparatus comprising at least two circuits according to the fifth aspect, wherein at least one of the secret keys is shared between said circuits so as to form a secure subsystem.
The keys are called shared in that other circuits the electronic device know, for example the circuits belonging to the secure area, that is to say to the secure subsystem. The invention thus provides a solution that allows to individualize encryption depending on the processor carries, while ensuring that all processors have the authorization to use data stored in external memory can decipher.
Encryption of the invention is the type of a stream cipher ( "Stream Cipher"), which is simpler and therefore faster than a cipher blocks. A stream cipher is also insensitive to attacks dictionary, because the same data word is encrypted with a different word each encryption.
In addition, the encryption according to the invention is compatible with an access random to the external memory.
Other features and advantages of the invention will still on reading the description which follows. This is purely illustrative and should be read with reference to the accompanying drawings in which:<ul><li>FIG 1 is a diagram of an electronic apparatus which can apply the various aspects of the invention;</li><li>Figure 2 is a block diagram of exemplary circuitry coupled to an external memory, according to an embodiment of a circuit according the invention.</li></ul>
In the drawings, the same elements are designated by the same references in the different figures. For clarity, only steps of the method and the elements that are necessary for the understanding of the invention have been shown and are described in the following. In particular, all the elements of a circuit has not been detailed, the invention operating components known for its implementation.
A feature of the present invention to encrypt data (programs, any binary data) to be stored in a shared external memory by several circuits of a device electronic. Data is encrypted using a secret key, clean the circuit performing the encryption, which may be different from the secret key used by other circuits for comparable encryption.
To allow the use of encrypted data over a circuit, at least some of secret keys may be used by a circuit are shared with one or more other circuits, that is to say, it is known of these circuits while secret vis-à-vis the rest of the system. A shared key defines a circuit subsystem can use common data stored in external memory. Typically, this subsystem may correspond to a secure area as shown in introduction in conjunction with the diagram of Figure 1.
In addition, data is stored in the external memory association with an identifier of the secret key used to encrypt them. This identifier allows authorized circuits to determine the secret key used to decrypt data. This identifier can match to an index into a set of internal registers in which the key Secret supported by a circuit are stored respectively. It is therefore not the secret key itself is stored with the data encrypted it, but the identifier of this secret key. The disclosure of the identifier by storage in external memory offers no weakness encryption, since only authorized circuits can know the key Secret to use from this identifier.
Another feature of the present invention is to provide a encryption and decryption continuously during transfers between a circuit and external memory. The stream cipher is obtained from a cutting fixed-size words of data which are then stored as encrypted in the external memory. It also provides encryption uses the combination of a data word with a pseudo random number, which is generated from the secret key and an initialization vector.
Advantageously, the initialization vector changing value for every word, preferably randomly, in order to strengthen security encryption. The initialization vector used to encrypt a password data is conveniently stored in external memory in association with the data codeword, as well as the identifier of the secret key as indicated above. Is thus avoided the problems related to stream cipher which are typically incompatible with access Direct random to a memory.
The diagram of Figure 2 shows the essential means of example embodiment of a circuit suitable for carrying out the method of encryption (shown by the solid arrows) and for the implementation decryption process (illustrated by the arrows in dotted lines).
The circuit here is a processor 2 (CPU) comprising a core processor 44 (CORE), cache memories 33 and 34 (CACHE), a unit 31 (KSEL) encryption key selection (K), and a unit 38 (BEU) to encryption / decryption.
The unit 38 includes a unit 22 (SEGM) segmentation data, a set 32 (KREG) secret keys registers, a first pseudorandom generator 24 (IVGEN), a cache memory 25 (IVCACHE) an encryption key register 12 and an initialization vector register 13, a second pseudo random generator 10 (PRNG), and finally a unit 11 combination.
The segmentation unit 22 is operable to segment data encrypting (DATA) received from the processor core 44, data words (W) of predetermined size. A data word can thus comprise a single bit. Preferably, however, the size of a word is equal to one byte, that is to say qu'un mot comprend huit bits.
Each register of the assembly 32 is adapted to store so nonvolatile a secret key (K) to which is associated a key identifier Secret (KID). Or all of the secret keys can be provided to processor via a secure channel, for example during manufacture of the system. Some at least secret keys may, conversely, be internally generated by an ad hoc algorithm whose description is beyond the scope of this paper. In a preferred embodiment for its simplicity, the identifier is an index, such a record number, allowing access to the secret key corresponding one of the secret key list supported by the processor and stored in the assembly 32.
The random number generator 24 is adapted to generate vectors Boot to the rhythm of an initialization vector by data word encrypt, according to a pseudo random any algorithm.
The cache 25 is adapted to store pairs formed each of an initialization vector and a key identifier associated with a data word.
The register 12 is adapted to store an encryption key, namely one of the secret keys stored in the register file 32. This register shown here for the sake of clarity, but may be omitted if it is anticipated means for managing the set of registers 32 adapted.
The register 13 initialization vector has the function of storing the Initialization Vector continuously generated by the pseudo random generator 24. Preferably, the size of the initialization vectors is equal to the word size data to be encrypted.
The role of the pseudo-random generator 10 is to generate a continuous flow pseudo-random number (PN), by reason of such a number by word data to be encrypted. Each pseudo random number is generated from the encryption key stored in the register 12 and the initialization vector stored in the register 13, the latter changing value to each word data.
In one example, the combination unit is an Exclusive-OR gate (XOR). The pseudo-random generator 10 and XOR gate form a cryptosystem, in itself, is well known to the skilled person. The words of encrypted data it outputs the same size as the words of data (before encryption) being input. Such a cryptosystem present the advantage of a simple encryption algorithm, so fast, and whose vis-à-vis security attacks strength is determined by the details internal pseudo random generator 10. More flow generated number PN by the latter is random, the better the algorithm of the safety encryption. Another advantage of an encryption algorithm by XOR gate is that the deciphering is performed in the same way as encryption, which simplifies the hardware design of the cryptosystem.
The circuit in encryption mode, will now be explained by considering the solid arrows shown in Figure 2.
Encryption mode is typically activated by the processor core 44 when the data DATA stored in, or passing through the memory Cache 34 must be written in the external memory 23, and must for this purpose transit via the communication bus 3.
The core 44 controls the selection unit 31 so as to select one of the secret keys stored in the set of register 32. In one example, the unit 31 selects a key identifier secret kidi associated with a secret key determined. This identifier is provided by kidi the unit 31 to the encryption unit 38.
In the encryption unit 38, the key Ki associated with the identifier kidi is read from the set register 32 with said kidi identifier, used for example as an index into the path of the set of registers 32. The Ki key is then stored in the register 12.
Furthermore, the core 44 controls the cache memory 34 so that the data DATA are supplied to the encryption unit 38, and more particularly the input of the segmenting unit 22. The latter delivers a stream of binary words Wi, each corresponding to a segment of the stream DATA data. Meanwhile, the pseudo-random generator 24 generates a flow IVi initialization vectors, the pace of issuing words Wi data by the unit 22, the initialization vectors changing value each Wi words. In other words, each data word Wi is associated an initialization vector IVi whose value is different from the vector Initialization associated with the previous word in the data word stream. The initialization vectors IVi, which are continuously generated, are each stored in the register 13.
For each word of Wi data, the following operations are then carried out continuously.
On the one hand, the pseudo random number generator 10 generates a pseudorandom PNi depending on the secret key Ki stored in the register 12 and initialization vector IVi stored in the register 13. Each time, the PNi number is issued at a second input of the XOR gate 11.
Furthermore, the data word Wi and pseudo random PNi are combined by the corresponding XOR gate 11, so as to generate a The encrypted data word.
The encryption unit 38 then stores the password in the memory Ci external 23 and and in combination with the initialization vector IVi and kidi the secret key ID that was used to encrypt it. In this writing, the encrypted data word Ci, the initialization vector and the identifier of IVi secret key kidi transiting Intermed iaire the communication bus 3. This however, is not a weakness of security of the encryption method in the Since the word Ci is encrypted, where the IV is not enough to IVi alone to perform decryption, and which has no identifier kidi meaning for another circuit which does not have the secret key associated to this identifier.
The operation of the circuit in decryption mode is now exposed by considering the dotted line arrows shown in Figure 2.
Under control of the processor core 44, data words figures are read from the external memory 23 at given addresses. Every word Cj thus read is delivered to the first input of the XOR gate 11. For each word Cj, the initialization vector IVj and the key identifier KIDj secret associated with that word, are also read into memory External 23.
From the KIDj identifier, the decryption unit 38 selects the secret key Kj associated with this identifier by searching the list of secret keys stored in the register set 32. The key Kj and selected is stored in the register 12. In parallel, the vector is IVj stored in the register 13.
In fact, the IVj vector and KIDj identifier transiting memory Cache 25. This caching improves performance the decryption unit, in decryption speed term. The pseudo-random generator 10 generates a pseudo random number to PNI From the K key stored in the register 12 and stored in the vector IVj register 13. The PN number is issued on the second input of the gate XOR 11.
The XOR gate 11 combines the encrypted data Cj of word and number pseudorandom PNI and outputs a corresponding data word Wj the word Cj deciphered.
The decrypted data word Wj is then supplied to the processor core 44 through the cache 33.
Of course, the present invention is capable of various variations and modifications which will occur to the skilled person. In particular, the invention may be implemented with any algorithm known stream cipher, conditioning the pseudorandom generator 10 From the secret key and initialization vector. In addition, it is assumed that the practical embodiment of the invention is within the reach of the skilled person to From the functional indications given above. In this regard, note that, according to one embodiment of the invention described herein, the various tools Encryption and decryption are realized by hardware resources processor. However, implementation by software resources is of course conceivable.
In addition, the invention is not limited in any way to application in a processor. On the contrary, an encryption / decryption unit such as unit 38 described above may be provided in other circuits of a electronic apparatus as shown in Figure 1, particularly in the disk controller or network card.
Note also that all of the data stored in the external memory does not have to be encrypted. In this regard, one can provide that a key identifier with the value zero indicates no encryption of the corresponding data word, that is to say, said word Data is stored in the clear in the external memory.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| EP1229427A2 | Cites | European Patent Office (EPO) | A | Search report | 1,4,7-9,14 |
| US5438622A | Cites | United States of America | A | Search report | 1,4,7-9,14 |
| US6061449A | Cites | United States of America | DA | Search report | 1,4,7-9,14 |
| WO9912310A1 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | 1,4,7-9,14 |
8 members in 5 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 0312206 | France | A | |
| 0312206 | France | A | |
| 0312206 | France | – | |
| 0312206 | – | – | – |
| FR20030012206 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| EP1524795A1This record | European Patent Office (EPO) | A1 | |
| FR2861234A1 | France | A1 | |
| JP2005122745A | Japan | A | |
| US2005138403A1 | United States of America | A1 | |
| EP1524795B1 | European Patent Office (EPO) | B1 | |
| DE602004001732D1 | Germany | D1 | |
| DE602004001732T2 | Germany | T2 | |
| US7657034B2 | United States of America | B2 |
25 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Designation fees paidAKX | AKX | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1524795
- Publication, DOCDB
- 1524795
- Publication, EPODOC
- EP1524795
- Application
- 4292137
- Application, DOCDB
- 04292137
- Application, EPODOC
- EP20040292137
Titles3
- German
- Datenverschlüsselung in einem elektronischen Gerät mit mehreren symmetrischen Prozessoren
- English
- Data encryption in an electronic apparatus with several symmetrical processors
- French
- Chiffrement de données dans un appareil électronique à plusieurs processeurs symétriques
Classification
- CPC, 3
- H04L9/0662
- H04L9/0894
- H04L2209/12
- IPC, 7
- G06F21 60
- G06F21 62
- G06F21 72
- H04L9 08
- H04L9 12
- H04L9 14
- H04L9 18
Designated states33
- Contracting states, 28
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Poland
- Portugal
- Romania
and 4 moreShow fewer
- Sweden
- Slovenia
- Slovakia
- Türkiye
- Extension states, 5
- Albania
- Croatia
- Lithuania
- Latvia
- North Macedonia