Nova Patents
EP2490146A2

A secure processor

Abstract

In a secure processor (10), the instruction code including an instruction code stored in the area (14) where the encrypted instruction code is stored in a non-rewritable format is authenticated using a specific key (15) which is specific to the core (11) where the instruction code is executed or an authenticated key by a specific key to perform an encryption processing for the input and output data between the core and the outside.

EP2490146A2, drawing sheet 1
Sheet 1 of 76

Term

Term ended

Projected expiry passed 23 February 2025, 1.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

17 claims: 2 independent, 15 dependent

  1. 1
    A secure processor (40) comprising:an instruction execution unit (41) executing instructions;a load/store control unit (42) controlling loading/storing of the data for an external memory in response to a commands from the instruction execution unit;and an encryption processing unit (43, 44) performing data encryption/decryption of data between the load/store control unit and the external memory, wherein the instruction execution unit specifies a key to be used for data encryption/decryption by the encryption processing unit in response to an instruction being executed.
  2. 2
    The secure processor according to Claim 1, further comprising a key storing unit (47, 48) storing multiple keys, wherein the instruction execution unit outputs a key number to specify the key to the key storing unit, and the key storing unit gives the key to be used for data encryption/decryption to the encryption processing unit in response to the key numbers.
  3. 3
    The secure processor according to Claim 1, further comprising a key storing unit (48) storing keys to be used for decryption of the instruction fetched data loaded externally, wherein when the instruction execution unit is in an instruction fetched state, the key storing unit gives the key for decryption to the encryption processing unit.
  4. 4
    The secure processor according to Claim 1, further comprising:a key storing unit (47, 48) storing multiple keys;and a key number storing unit (51, 52) storing key numbers specifying the keys, which are output by the instruction execution unit, wherein the key storing unit gives keys to be used for the data encryption/decryption to the encryption processing unit in response to the key numbers given from the key number storing unit.
  5. 5
    The secure processor according to Claim 1, further comprising:a key storing unit (48) storing multiple keys including the keys to be used for decryption of the instruction fetched data loaded from the outside;and a key number storing unit (52) storing key numbers of the keys to be used for decryption of the instruction fetched data loaded from the outside, wherein when the instruction execution unit is in an instruction fetched state, the key storing unit gives keys to be used for decryption of the instruction fetched data to the encryption processing unit in response to the key numbers output from the key number storing unit.
  6. 6
    The secure processor according to Claim 1, wherein the instruction execution unit outputs supervisor/user switching signals in response to the instruction in addition to the key number as a signal to specify said key;or wherein the instruction execution unit outputs a process identifier including the instruction being executed in addition to the key number as a signal to specify said key.
  7. 7
    The secure processor according to Claim 1, wherein the load/store control unit further comprises:a write-through type cache memory (45);and a read modify write unit (71) giving the data to be stored in the external memory combined with the data loaded via the encryption processing unit from the external memory to the encryption processing unit.
  8. 8
    A secure processor comprising:an instruction execution unit (41) executing instructions;a load/store control unit (42) controlling loading/storing of the data to an external memory in response to a command from the instruction execution unit;and an encryption processing unit (43, 44) performing encryption/decryption of the data between the load/store control unit and the external memory, wherein the instruction execution unit gives a signal to specify a key to be used for data encryption/decryption to the encryption processing unit in response to an access address of data/instruction fetch based on the instruction being executed.
  9. 9
    The secure processor according to Claim 8, further comprising a key storing unit (74, 75) storing multiple keys, wherein the instruction execution unit outputs a logical address as said access address to the key storing unit, and the key storing unit gives key for data encryption/decryption to the encryption processing unit in response to the logical address.
  10. 10
    The secure processor according to Claim 8, further comprising a key storing unit (74, 75) storing multiple keys, wherein the load/store control unit outputs a physical address as said access address to the key storing unit in response to the command given from the instruction execution unit, and the key storing unit gives a key for data encryption/decryption to the encryption processing unit in response to the physical address as said access address.
  11. 11
    The secure processor according to Claim 8, further comprising a key storing unit (74, 75) storing multiple keys respectively corresponding to a logical addresses and the physical addresses as said access addresses, wherein the key storing unit gives the encryption processing unit a key for encryption/decryption which corresponds to an address selected based on the instruction from the instruction execution unit which indicates which of the physical address as said access address given by the load/store control unit or the logical address given from the instruction execution unit should be selected.
  12. 12
    The secure processor according to Claim 8, further comprising:a key storing unit (74, 75) storing multiple keys in response to the logical addresses and physical addresses as said access addresses;and an address selection instruction storing unit (78, 79) storing data for address selection instruction which are output by the instruction execution unit and which indicate key to be given to the encryption processing unit in response to either the logical address or physical address, wherein the key storing unit gives a key responding to the logical address or physical address based on the contents stored in the address selection instruction storing unit as a key for data encryption/decryption to the encryption processing unit.
  13. 13
    The secure processor according to Claim 8, wherein the load/store control unit further comprises a key storing unit (74, 75) storing multiple keys in response to the access addresses, wherein the load/store control unit selects a key stored in the key storing unit in response to the access address given while the instructions are executed from the instruction execution unit and gives the key to the encryption processing unit as the key for data encryption/decryption.
  14. 14
    The secure processor according to Claim 13 wherein when the instruction execution unit outputs a signal indicating ON/OFF of the key storing unit and if the key storing unit indicates an OFF state, a signal giving a key to be used for the data encryption/decryption, to the encryption processing unit, and in response to the ON/OFF signal, the encryption processing unit uses the key given from the key storing unit when the key storing unit indicates ON, whereas it uses the key given from the instruction execution unit when the signal is OFF, as the key for the data encryption and decryption.
  15. 15
    The secure processor according to Claim 8, wherein the instruction execution unit outputs a supervisor/user switching signal in response to the instruction in addition to the access address as a signal to specify said key;or wherein the instruction execution unit outputs a process identifier including the instruction being executed in addition to the access address as a signal to specify said key.
  16. 16
    The secure processor according to Claim 8, wherein the load/store control unit further comprises a write-through type cache memory (45), and a read modify write unit (71) giving the data to be stored in the external memory combined with the data loaded via the encryption processing unit from the external memory to the encryption processing unit.
  17. 17
    The secure processor according to Claim 1 or 8, further comprising a data bypass unit (63, 64, 66, 67) transferring a plain text data without performing encryption/decryption by bypassing the encryption processing unit between the load/store control unit and the external memory.
Independent claims17