Nova Patents
EP1632835B1

A secure processor

Abstract

This record has no abstract on file.

EP1632835B1, drawing sheet 1
Sheet 1 of 75

Term

Term ended

Expired 23 February 2025, 1.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

15 claims: 1 independent, 14 dependent

  1. 1
    A secure processor (1, 10) having a core (11) configured to execute an instruction code, comprising:a key memory unit (2, 15) configured to store a specific key in the core;an instruction code memory unit (3, 14) storing an encrypted instruction code in a non-rewritable format;an authentication processing unit (4, 13) configured to authenticate instruction codes including the encrypted instruction codes stored in the instruction code memory unit using one of the specific key or a key authenticated by the specific key;and an encryption processing unit (5, 12) configured to encrypt the data input and output between the core and the outside;wherein the secure processor is characterized in that the core (11) comprises: a secure core (31) configured to execute an instruction code which has been authenticated by the authentication processing unit;a normal core (32) configured to execute a regular instruction code which has not been authenticated by the authentication processing unit (4, 13);wherein the secure processor is configured firstly to boot the secure core (31) using the encrypted instruction code stored in the instruction code memory unit (14), and secondly to boot the normal core (32), after the secure core has been booted.
  2. 2
    The secure processor (1, 10) according to Claim 1, wherein said encryption processing unit (5, 12) is configured to encrypt the instruction code which has been authenticated by the authentication processing unit (4, 13), and is configured to store it in a memory unit connected to the secure processor at a page unit.
  3. 3
    The secure processor (1, 10) according to Claim 2, further comprising an illegal instruction execution termination unit (11) configured to terminate the execution of the encrypted instruction code at the page unit if an illegal instruction is detected while the encrypted instruction code stored in the memory unit is executed.
  4. 4
    The secure processor (1, 10) according to Claim 1, wherein authenticated information is added to the instruction code which is to be authenticated by the authentication processing unit (4, 13).
  5. 5
    The secure processor (1, 10) according to Claim 4, wherein if an encryption key is specified in the authentication information, the encryption processing unit (5, 12) is configured to perform encryption of the instruction code using the specified key.
  6. 6
    The secure processor (1, 10) according to Claim 4, wherein if the encryption key is not specified in the authenticated information, the encryption processing unit (5, 12) is configured to perform encryption of the instruction code using an arbitrary page key.
  7. 7
    The secure processor (1, 10) according to Claim 1, wherein the encryption processing unit (5, 12) is configured to perform encryption of the data of the same process corresponding to the authenticated instruction code using a different encryption key which is different from the encryption key for the instruction code.
  8. 8
    The secure processor (1, 10) according to Claim 7, wherein the encryption key for the instruction code is used instead of the different encryption key when the instruction code stored in the data storage area in the memory unit connected to the secure processor is executed.
  9. 9
    The secure processor (1, 10) according to Claim 1, further comprising a code execution termination processing unit configured to terminate the execution of the instruction code for which the authentication by the authentication processing unit (4, 13) has failed.
  10. 10
    The secure processor (1, 10) according to Claim 1, comprising a normal core (32) monitoring unit (31) configured to terminate operation of the normal core or branching out to a specific processing if an abnormal state is detected, when the secure core (31) monitors the operation of the normal core after booting of the normal core.
  11. 11
    The secure processor (1, 10) according to Claim 1, wherein said secure core (31) gives a core control signal to the normal core (32) to control the operations of the normal core.
  12. 12
    The secure processor (1, 10) according to Claim 1, wherein accessing the core specific key is permitted to the secure core (31), but prohibited to the normal core (32).
  13. 13
    The secure processor (1, 10) according to Claim 12, further comprising a key generation unit (34) configured to generate a pair of a public key and a secret key, and a shared key, using the core specific key under the control of the secure core (31).
  14. 14
    The secure processor (1, 10) according to Claim 13, wherein the secure core (31) is configured to inform exteriorly a public key generated by the key generation unit via the normal core (32), receive an original text which is encrypted using the public key externally via the normal core, and decrypt the encrypted original text using the secret key.
  15. 15
    The secure processor (1, 10) according to Claim 14, wherein the original text is the key used for the encryption of the information.
Independent claims15