EP1535124B1

Computer architecture for executing a program in a secure of insecure mode

Abstract

This record has no abstract on file.

EP1535124B1, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Expired 13 August 2022, 4.1 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

10 claims: 8 independent, 2 dependent

  1. 1
    Circuitry for providing data security, which circuitry contains at least one processor and at least one storage circuit and which circuitry comprises:at least one storage area in said storage circuit, in which storage area protected data relating to circuitry security are located;mode setting means arranged to set storage circuit access control means to indicate one of at least two different processor operating modes, the mode setting means being capable of altering the processor operating mode of the processor;said storage circuit access control means arranged to control the processor to operate in a first processor operating mode or a second processor operating mode of said at least two different operating modes, the first operating mode enables said processor access said storage area in which said protected data are located and the second operating mode prevents said processor from accessing said storage area in which said protected data are located, wherein said processor manages all accesses to said storage area to protect said protected data located in said storage area, characterized in that authentication means arranged, at power up, to authenticate, by signature checking, a non verified software downloaded to the circuitry in said first operating mode;wherein said processor operating mode is set to said second processor operating mode when a non verified software to be downloaded has not been authenticated in said authentication means thereby enabling said at least one processor to execute non-verified software downloaded into the circuitry.
  2. 3
    The circuitry for providing data security according to any of the preceding claims, further comprising:means arranged to indicate in which mode the processor is operating.
  3. 4
    The circuitry for providing data security according to any of the preceding claims, wherein said mode setting means comprise an application program.
  4. 5
    The circuitry for providing data security according to any of the preceding claims, which circuitry is comprised in a mobile telecommunication terminal.
  5. 6
    A method for providing data security in a circuitry containing at least one processor and at least one storage circuit and which method comprises the steps of:storing protected data relating to circuitry security in at least one storage area in said storage circuit, setting storage circuit access control means to indicate one of at least two different processor operating modes, the mode setting means being capable of altering the processor operating mode of the processor;controlling by said storage circuit access control means the processor to operate in a first processor operating mode or a second processor operating mode of said at least two different operating modes, wherein the first operating mode enables said processor access said storage area in which said protected data are located and the second operating mode prevents said processor from accessing said storage area in which said protected data are located, and wherein said processor manages all accesses to said storage area to protect said protected data located in said storage area, characterized by the steps of: at power up, authenticating by signature checking a non verified software downloaded to the circuitry in said first operating mode;setting said processor operating mode to said second processor operating mode when a non-verified software to be downloaded has not been authenticated in said authenticating step, thereby enabling said at least one processor to execute non-verified software downloaded into the circuitry.
  6. 8
    The method for providing data security according to any of claims 6-7, further comprising the step of:indicating in which mode the processor is operating.
  7. 9
    The method for providing data security according to any of claims 6-8, wherein the setting of said processor in one of at least two different alterable operating modes is performed by means of an application program.
  8. 10
    The method for providing data security according to any of claims 6-9, wherein the circuitry containing at least one processor and at least one storage circuit is comprised in a mobile telecommunication terminal.