EP3244375A1

Microcontroller for secure starting with firewall

Abstract

The present invention relates to a microcontroller comprising a processor and a memory divided into different zones which are secured, unsecured or shared, to implement a secure boot comprising a tamper control circuit for detecting the vulnerability conditions and the processor executing a Linux operating system, said processor comprising a monitor for switching operations either in a secure area of ​​the memory for operating at least one authentication process or in an unsecured area for other operations and determining whether the devices connected to or accessed by or accessed by the microcontroller must be managed by the secure zone or the unsecured area using a hardware firewall to determine if theinformation or the command of an application is allowed to access the secure area or not.

EP3244375A1, drawing sheet 1
Sheet 1 of 8

Term

10.6 yearsto projected expiry

Projected expiry 9 May 2037, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

18 claims: 11 independent, 7 dependent

  1. c-fr-0001
    Microcontroller (1) comprising a processor (11) comprising a memory separated into at least two zones, which are secured (110), unsecured (111) or shared, to implement a secure start, a self-protection control circuit (13) comprising at least one sensor (130a, 130b, 130c) for detecting the vulnerability conditions, said processor (11) running a Linux operating system (Linus OS) and also including a monitor for switching the operations either in a secure area (110) of the memory for operating at least one or more authentication processes in an unsecure area (111) for other operations and determining whether the devices connected to or accessing the,or accessed by the microcontroller (1) must be managed by the secure area (110) or by the non-secure area (111), said microcontroller (1) being characterized in that it comprises a hardware firewall (12), used by said processor (11), to determine whether the information or control of an application is authorized to access the secure zone (110) or not, said firewall hardware (12) being connected to said self-protection control circuit (13) to prevent data intrusion and / or recovery in the event of failure of said tamper control circuit (13).
  2. c-fr-0003
    Microcontroller according to claims 1 and 2, wherein the hardware firewall (12) has registers each assigned to a peripheral (16a, 16b, 16c, 16d, 16e, 16f) and which uses the information stored in the Linux device tree, described in the Linux operating system, in which said device tree is added with security attributes, defining the secure (S) or nonsecure (N) status of the device to be stored in each register associated with the device. a device a secure or insecure status to induce the processing of the information or command from a device in the secure area of ​​the processor if the device is defined as secure, and induce the processing of information or the order froma device in the unsecured area of ​​the processor if the device is defined as unsecured.
  3. c-fr-0004
    Microcontroller (1) according to claims 1 to 3, wherein the Linux device tree is authenticated by a secure primary application during the secure boot operation.
  4. c-fr-0005
    Microcontroller (1) according to claims 1 to 4, wherein the secure area (110) comprises a core (110b) receiving at least one instruction of the unsecured area (111) or a peripheral (16a, 16b, 16c, 16d, 16e, 16f) included in the device tree, and performing various operations that depend on the received instruction, a register (110a) comprising a set of secure services including the rules for protecting different types of processes corresponding to different types of services.
  5. c-fr-0006
    Microcontroller (1) according to claims 1 to 4, wherein the unsecure area (111) comprises the operating system kernel (111a), an execution environment (111b) of programs and applications and / or data processing, at least one library, and at least one platform (111c, 111d) dedicated to adding client applications (111d) or proprietary applications (111c), the method of adding and accessing said applications to the features of the device controlled by the microcontroller (1) being defined by security rules implemented by the hardware firewall (12).
  6. c-fr-0007
    Microcontroller according to the preceding claim, in which the execution environment (111 b) is configured to integrate at least one means for interpreting different types of client applications, said means being capable of translating the language of said applications into native programs in order to processing them on said execution environment (111b).
  7. c-fr-0008
    Microcontroller (1) according to claims 6 and 7, wherein the runtime environment is Android.
  8. c-fr-0010
    Microcontroller according to the preceding claim, wherein the display devices, touch screen (16f), keyboard, contactless reader (16th), magnetic card reader (16h), smart card reader (16g), cryptographic material and key manager computers are secure devices, while Bluetooth (16c) / Wifi (16b), Ethernet (16d), printers, GPS, camera (16l), sound, proximity sensor (16k), HDMI and USB (16a) devices receive either a secure status (S) or a non-secure status (N).
  9. c-fr-0014
    Secure boot process of the Linux operating system for a microcontroller (1) according to claims 11 to 13, characterized in that the application platforms (111c, 111d) are separated from the library, the operating system kernel (111 a) and the operating system environment (111 b) by a control module, contained in the operating system, which controls access for applications and limits access to a particular device or service for unauthorized client applications, access control of that device or service being performed by means of of a file provided by SELinux, said file whitelisting the type of operations allowed in combination with the identity (ID) of a particular application or process and establishing the permission of operation for each application.
  10. c-fr-0015
    Secure boot process of the Linux operating system for a microcontroller (1) according to claims 11 to 14, characterized in that the access of an authorized or unauthorized client application to certain functionalities of a device such as, for example, the touch screen display, is controlled by the microcontroller (1) and is done by means of a secure proxy activated by the control module, said secure proxy checking if a message concerning a touch event is signed by a trusted third party before being displayed and if not, the touch event is not transferred to the unsecured area.
  11. c-fr-0017
    Use of a microcontroller (1) according to the preceding claim, characterized in that the upstream safety circuit board (21) comprises at least one proximity sensor (16k) for detecting any presence or action and sending a signal to the microcontroller (1) to perform an analysis and trigger an action:displaying a message of welcome or use.