EP1785902A1

Decryption key table access control on ASIC or ASSP

Abstract

An ASIC or ASSP has processor circuitry (110), a predetermined initialization program (100) for execution by the processor circuitry at power up, and a non-volatile key table (120) readable by the initialization program, and not accessible otherwise by the processor circuitry. The initialization program reads a key index associated with encrypted data, from external memory, and uses the key index to read a corresponding key from the table, to decrypt the encrypted data for use by the processor circuitry. Optionally another key is first decrypted and used for the decryption of the encrypted data. By keeping the key on board the chip and restricting access in this way, the key and therefore the encrypted data can be protected from software based reverse engineering. This means the encrypted data can cheaper memory chips or other storage. Thus the processor circuitry can be formed on a smaller integrated circuit.

EP1785902A1, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 28 October 2025, 0.9 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

18 claims: 11 independent, 7 dependent

  1. 1
    An integrated circuit having processor circuitry, (110) a predetermined initialization program (100) for execution by the processor circuitry at power up, and a non-volatile store (120) readable by the initialization program, and not accessible otherwise by the processor circuitry, the initialization program being arranged to read a key index associated with particular encrypted data, and to use the key index to read a corresponding key from the non-volatile store, the corresponding key being suitable to decrypt the particular encrypted data for use by the processor circuitry or is suitable for a customer defined encryption key to be decrypted, which customer defined encryption key is then used to decrypt the encrypted data.
  2. 4
    The integrated circuit of any preceding claim, the initialization program being arranged to read in the key index from an external location.
  3. 6
    The integrated circuit of any preceding claim, having key table gate circuitry (320) arranged to allow a number of key read operations by the initialization program and then prevent further access until the next power up.
  4. 7
    The integrated circuit of any preceding claim, the processor circuitry being arranged to carry out the decryption on board.
  5. 9
    The integrated circuit of any preceding claim, the decrypted data having executable code, and the processor circuitry being arranged to execute the code.
  6. 10
    The integrated circuit of any preceding claim, the processor circuitry comprising a digital signal processor.
  7. 11
    The integrated circuit of any preceding claim, having one or more analog signal inputs and analog to digital conversion circuitry (135).
  8. 12
    The integrated circuit of any preceding claim, the encrypted data comprising digital signal processing algorithms.
  9. 13
    The integrated circuit of any preceding claim, comprising an ASIC or an ASSP.
  10. 14
    A system having the integrated circuit of any preceding claim and an external storage device (140) coupled to the integrated circuit, for storing the encrypted data and the key index.
  11. 17
    A method of manufacturing the integrated circuit of any of claims 1 to 13, having the steps of assigning (370) a number of secure keys and their corresponding key indexes to each of a number of customers, and manufacturing (380) a common integrated circuit for those customers by storing the secure keys in the read only non-volatile store so as to be accessible using their corresponding key index.