Computer architecture for executing a program in a secure of insecure mode
Abstract
Circuitry to provide data security, said circuitry contains at least one processor and at least one storage circuit and said circuitry comprises: At least one storage area in said storage circuit, in which storage area the relative protected data is located to circuitry safety; mode setting means arranged to adjust access control means of the storage circuit to indicate at least one of two different operating modes, the mode setting means being able to alter the operating modes of the processor; Said access control means of the storage circuit arranged to control the processor to operate in a first operating mode or a second operating mode of the processor of said at least two different operating modes, The first operating mode allows said processor to access said storage area in which said protected data is located and the second operating mode prevents the processor from accessing said storage area in which the protected data is located, in which said processor manages all accesses to said storage area to protect said protected data located in said storage area, characterized in that authentication means arranged, in the start-up, to authenticate, by signature verification, unverified software downloaded in the circuitry in said first operating mode; wherein said processor operating mode is set to said second processor operating mode when an unverified software to be downloaded has not been authenticated in said authentication means thereby allowing said at least one processor to run unverified software downloaded in the circuitry

Term
Term ended
Projected expiry passed 13 August 2022, 4.1 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
10 claims: 8 independent, 2 dependent
- 1ES 2 357 421 T3 REIVINDICACIONES 1. - Circuitería para proporcionar seguridad de datos, dicha circuitería contiene al menos un procesador y al menos un circuito de almacenamiento y dicha circuitería comprende:Al menos un área de almacenamiento en dicho circuito de almacenamiento, en la cual área de almacenamiento se sitúan los datos protegidos relativos a la seguridad de la circuitería;medios de ajuste de modo dispuestos para ajustar medios de control de acceso del circuito de almacenamiento para indicar uno al menos de dos modos operativos diferentes, siendo los medios de ajuste de modo capaces de alterar los modos operativos del procesador;Dichos medios de control de acceso del circuito de almacenamiento dispuestos para controlar que el procesador para que opere en un primer modo operativo o un segundo modo operativo del procesador de dichos al menos dos modos operativos diferentes, El primer modo operativo permite que dicho procesador acceda a dicha área de almacenamiento en la cual se encuentran dichos datos protegidos y el segundo modo operativo evita que el procesador acceda a dicha área de almacenamiento en la cual se encuentran los datos protegido, en la cual dicho procesador gestiona todos los accesos a dicha área de almacenamiento para proteger dichos datos protegidos situados en dicha área de almacenamiento, caracterizada porque medios de autenticación dispuestos, en la puesta bajo tensión, para autenticar, por verificación de firma, un software no verificado descargado en la circuitería en dicho primer modo operativo;en la que dicho modo operativo de procesador se ajusta en dicho segundo modo operativo de procesador cuando un software no verificado a descargar no se ha autenticado en dichos medios de autenticación permitiendo de este modo que dicho al menos un procesador ejecute software no verificado descargado en la circuitería.
- 2- Circuitería para proporcionar seguridad de datos según la reivindicación 1, que comprende, además:un temporizador dispuesto para controlar el periodo de tiempo durante el cual el procesador está en dicho modo operativo no seguro.
- 3- Circuitería para proporcionar seguridad de datos según cualquiera de las reivindicaciones anteriores, que comprende, además:medios dispuestos para indicar en qué modo está operando el procesador.
- 4- Circuitería para proporcionar seguridad de datos según cualquiera de las reivindicaciones anteriores, en la cual dichos medios de ajuste de modo comprenden un programa de aplicación.
- 5- Circuitería para proporcionar seguridad de datos según cualquiera de las reivindicaciones anteriores, dicha circuitería está comprendida en un terminal móvil de telecomunicación.
- 6- Procedimiento para proporcionar seguridad de datos en una circuitería que contiene al menos un procesador y al menos un circuito de almacenamiento y dicho procedimiento comprende las etapas de:almacenar datos protegidos relacionados con la seguridad de la circuitería en al menos un área de almacenamiento en dicho circuito de almacenamiento ajustar medios de control de acceso al circuito de almacenamiento para indicar uno de al menos dos modos operativos de procesador diferentes, siendo capaz el medio de ajuste de modificar el modo operativo de procesador del procesador;controlar mediante dichos medios de control de acceso al circuito de almacenamiento el procesador para que opere en un primer modo operativo de procesador o un segundo modo operativo del procesador de dichos al menos dos modos operativos diferentes, ES 2 357 421 T3 en el cual el primer modo operativo permite que dicho procesador acceda a dicha área de almacenamiento en la cual se encuentran dichos datos protegidos y el segundo modo operativo evita que el procesador acceda a dicha área de almacenamiento en la cual se encuentran los datos protegido, y en el que dicho procesador gestiona todos los accesos a dicha área de almacenamiento para proteger dichos datos protegidos situados en dicha área de almacenamiento, caracterizado por las etapas de: en la puesta bajo tensión, autenticar, por verificación de firma, un software no verificado descargado en la circuitería en dicho primer modo operativo;ajustar dicho modo operativo de procesador en dicho segundo modo operativo de procesador cuando un software no verificado a descargar no se ha autenticado en dicha etapa autenticación, permitir de este modo que dicho al menos un procesador ejecute software no verificado descargado en la circuitería.
- 7- Procedimiento para proporcionar seguridad de datos según la reivindicación 6, que comprende, además, la etapa de:controlar el periodo de tiempo durante el cual el procesador está en dicho modo operativo no seguro mediante un temporizador.
- 8- Procedimiento para proporcionar seguridad de datos según cualquiera de las reivindicaciones 6-7, que comprende, además, la etapa de:indicar en qué modo está operando el procesador.
- 9- Procedimiento para proporcionar seguridad de datos según cualquiera de las reivindicaciones 6-8, en la cual el ajuste de dicho procesador en uno de al menos dos modos operativos alterables diferentes se lleva a cabo mediante un programa de aplicación.
- 10- Procedimiento para proporcionar seguridad de datos según cualquiera de las reivindicaciones 6-9, en el cual la circuitería que contiene al menos un procesador y al menos un circuito de almacenamiento está dispuesta en un terminal móvil de telecomunicación.
Independent claims10
41 paragraphs in 4 sections, as filed
ES 2 357 421 T3
DESCRIPTION
Technical field of the invention
The present invention relates to circuitry for providing data security, said circuitry contains at least one processor and at least one storage circuit. The present invention also relates to a method for providing data security in circuitry containing at least one processor and at least one storage circuit.
Previous technique
Various electronic devices, such as mobile telecommunication terminals, laptops and PDAs require access to security-related components, such as application programs, cryptographic keys, cryptographic key data material, intermediate results of cryptographic calculations, passwords, authentication of externally downloaded data, etc. It is often necessary that these components, and their processing, be kept secret within the device electronically. Ideally, they will be known to as few people as possible. This is due to the fact that a device, for example a mobile terminal, could possibly be manipulated, if these components were known. Access to these types of components can help a malicious criminal to manipulate a terminal.
Also, on devices, the aforementioned security-related components will be handled, processed, and managed alongside more general components that do not require any secure processing. Thus, a secure execution environment is introduced, in which a processor inside the electronic device is able to access the security-related components. Access to, processing in, and exit from the secure runtime should be carefully controlled. The prior art hardware that comprises this secure environment is often confined within a tamper resistant package. It should not be possible to explore or carry out measurements and tests on this type of hardware that could result in the disclosure of safety-related components and their processing.
An electronic device that processes information in a secure environment and that stores security-related information in a secure manner is shown in US Patent No. 5,892,900. The patent discloses a virtual distribution environment that protects, manages and controls the use of electronic information. It comprises a rights protection solution for distributors, financial service providers, end users and others. The invention uses electronic devices called Secure Processing Units to provide security and secure storage and communication of information. Such a device, which includes a processor, is confined within a "tamper resistant security barrier", which separates the safe environment from the outside world. The electronic device provides both the safe environment and an unsafe environment, in the latter case the processor of the device does not have access to the safety-related information
A problem to be solved is to allow a third party to carry out the testing, debugging and maintenance of the electronic device and its software without running the risk of this third party accessing the information that makes it possible to manipulate the components. related to the security of the device, affecting the security functions when it is in a secure environment. It should be possible to move between the two environments smoothly, without having to restart one or the other each time a move is made.
Document EP-A-1262856 represents a prior art document according to article 54 (3) CEP. US-A-57537760 discloses a microcontroller that works in a safe mode or an unsafe mode indicated by a control register. The microcontroller provides security for internal instructions and data stored in ROM while allowing an instruction to access external off-chip memory connected to an expansion bus. If access to the ROM is carried out, the security logic is put into a first operating mode called non-secure mode in which the security circuitry allows access of the instructions to both memories. Once the microcontroller CPU accesses an off-chip instruction (over the expansion bus), the security logic is put into a secure mode in which access to the ROM is not allowed by a user. which has access to the ROM by the expansion bus.
ES 2 357 421 T3
Summary of the invention
An object of the present invention is to provide a solution to the problem given above by proposing an architecture that comprises a secure environment in which it is possible to store and process information, such as cryptographic keys and other security-related data, in a secure manner and being It is also possible to test and debug the architecture and its accompanying software in a secure environment without providing access to security data.
This object is achieved by the invention in a first aspect in the form of circuitry for providing data security, said circuitry contains at least one processor and at least one storage circuit according to claim 1 and in a second aspect in the form of a method for providing data security in circuitry containing at least one processor and at least one storage circuit according to claim 6. Preferred embodiments are defined by the dependent claims.
A first aspect of the invention refers to the circuitry comprising at least one storage area in a storage circuit, in which the protected data of the storage area relating to the security of the circuitry is located. The circuitry is arranged with mode setting means arranged to install a processor comprised in the circuitry in one of at least two different operating modes, the mode setting means being capable of altering the operating modes of the processor. It also comprises access control means to the storage circuit arranged to control that the processor accesses the storage area in which the protected data based on a first operating mode is located, and arranged to prevent the processor from accessing the storage area. in which the protected data is located, based on a second operating mode of the processor, thus allowing the processor to execute unverified software downloaded onto the circuitry.
A second aspect of the invention relates to a method in which the protected data relating to the security of the circuitry is stored in a storage circuit. A processor is set to one of at least two different alterable operating modes. The method further comprises the step of allowing the processor to access an area in which the protected data is located, putting the processor in a first operating mode and preventing the processor from accessing the storage area in which the data is located. protected by putting the processor in a second operating mode, thereby allowing the processor to execute unverified software downloaded into the circuitry.
The invention is based on the idea that circuitry is provided in which a processor can operate in at least two different modes, a first safe operating mode and a second non-secure operating mode. In secure mode, the processor has access to security-related data found in various memories located within the circuitry. Security data includes cryptographic keys and algorithms, software to drive the circuitry, secret data such as random numbers used as cryptographic key material, application programs, etc. The circuitry can be used advantageously in mobile telecommunications terminals but also in other electronic devices, such as computers, PDAs or other devices with data protection needs. In the case where the circuitry is within a mobile telecommunication terminal, it should be desirable for the circuitry to provide the terminal with a unique identification number and accompanying keys for cryptographic operations on the identification number. Access to and processing of this security data needs to be limited, as an intruder with access to the security data could tamper with the terminal. When testing and / or debugging the Terminal, access to security information is not allowed. For this reason, the processor is put into the non-secure operating mode, in which mode access to protected data is no longer provided.
The invention advantageously allows the circuitry processor to execute unverified software downloaded into the circuitry. This allows the electronic device and its software to be tested, debugged and maintained without risking a third party having access to the information that makes it possible to tamper with the security-related components thereby affecting security functions when in the device. safe environment.
It should be noted that in US Patent No. 5,892,900, the non-secure mode is the "normal" mode, used when transactions and communications must be secure, while in the present invention, the secure mode is normal mode. In the present invention, the insecure mode is only entered during testing and / or debugging or other types of special cases when data must be protected from
ES 2 357 421 T3 security, that is, when the safe mode cannot practically be maintained.
The present invention eliminates the use of special purpose terminals adapted for use in research and development. During a development stage, sometimes a condition is to be able to download unreliable and / or unverified code at the terminals. By enabling insecure mode, a channel is provided within the terminal without giving access to security-related components. Consequently, the same terminal can be used for normal operation as well as in the development stage. It is to be understood that it is more expensive to manufacture special purpose terminals.
According to one embodiment of the invention, the circuitry of the invention is provided with a timer that controls the period of time during which the processor is in non-secure mode. If other security control actions fail, a given maximum period of time is established during which access to an unsecured processor mode is given. This limits the potential for an intruder to debug and test the device.
According to the invention authentication means are provided, said means being arranged to authenticate data provided externally to the terminal. An advantage with this feature is that during the manufacturing stage, and other stages where the normal secure operating mode is no longer activated, the terminal can be used for a limited period of time, sufficient to load an accepted signed code into the terminal. It is also possible to download signed code packages within the terminal during safe mode operation. This facilitates the possibility of adding new security features to the terminal providing flexibility to the architecture. The architecture allows applications to be divided into secure and non-secure parts. The circuit checks the code packets that they are properly signed. Secure applications are downloaded to and run from the storage area that contains the protected data. This makes downloading the data smoother. If these features were not present, it would be necessary to download secure applications and non-secure applications separately.
According to yet another embodiment of the invention, the circuitry is arranged with means for indicating the mode in which the processor is operating. It is appropriate for a mode register to be established within the circuitry, keeping a current mode check. In the event that the circuitry is arranged within a mobile communication terminal, it would be possible to indicate on the terminal screen, by the terminal loudspeaker or by any other way, to the terminal user the fact that the terminal is operating in not secure mode. This will alert the user to the fact that unsafe mode has been entered.
According to other embodiments of the present invention, the mode setting means arranged to control the modes of the processor comprise an application program. This has the advantage that the mode could be adjusted by the device itself, without having to depend on external signals. From a security point of view, the latter is preferred since by controlling the application software, the setting of the processor modes can also be controlled. It is also possible to have an external signal connected to the circuitry, by means of which signal it is possible to control the mode of the processor. Using an external signal, a mode change can be executed easily and quickly, which can be advantageous in rehearsal environments. A combination of these two mode setting means is feasible.
Brief description of the drawings
The present invention will be described in greater detail with reference to the following drawings, in which:
Figure 1 shows a block diagram of a preferred embodiment of circuitry for providing data security in accordance with the present invention; Y
Figure 2 shows a startup procedure flow chart for circuitry in accordance with the present invention.
Description of preferred embodiments of the invention
Figure 1 shows a block diagram of a preferred embodiment of the present invention. As you can see, the architecture in Figure 1 contains both software and hardware. The architecture is implemented in the form of an ASIC (Application Specific Integrated Circuit). The processing part of the architecture contains a CPU and a DSP digital signal processor. These two processors can be merged into a single processor. Normally the CPU takes care of the communication operations and the DSP takes care of the data calculation.
ES 2 357 421 T3
The secure environment comprises a ROM memory from which the ASIC is powered. This ROM contains boot application software and an OS operating system. The operating system controls and runs applications and provides various security services to applications such as application software integrity control and access control. The operating system has access to the ASIC hardware and cannot provide the same rigorous hardware security, but it can count on the security architecture.
Some application programs that reside in the secure environment, that is, the protected data storage area, take precedence over other application programs. In a mobile communication terminal, in which the ASIC can be arranged, there should be a startup software, said software includes the main functionality of the terminal. It is not possible to start the terminal in normal operating mode without this software. This has the advantage that by controlling this startup software, it is also possible to control the initial activation of each terminal.
The secure environment also includes RAM memory for storing data and applications. The RAM memory preferably stores so-called protected applications, which are smaller applications to carry out critical security operations within the secure environment. Typically, the way to use protected applications is to let “normal” applications request services from some protected application. New protected applications can be downloaded to the secure environment at any time, which would not be the case if they resided in ROM. Safe environment software controls the downloading and running of protected applications. Only signed protected applications are allowed to function. Protected applications can access any resources in the secure environment and can also communicate with normal applications for the provision of security services.
In the safe environment, a fusible memory is available that contains a single random number that is generated and programmed into the ASIC during manufacture. This random number is used as the identity of a specific ASIC and is also used to derive keys for cryptographic operations. Likewise, access control means are provided to the storage circuit in the form of a security control register. The purpose of the security control registry is to provide CPU access to the secure environment, depending on the mode set in the registry. Processor operating modes can be set in the register by application software, resulting in the fact that the architecture does not have to rely on external signals. From a security point of view, this is preferable since by controlling the application software, the setting of the processor modes can also be controlled. It is also possible to have an external signal (not shown) connected to the ASIC, by means of which signal it is possible to set the security control register. Using an external signal, a mode change can be executed easily and quickly, which can be advantageous in test environments. A combination of these two mode setting means is feasible.
Preferably, the mobile telecommunications terminal should indicate on the terminal screen, via the terminal loudspeaker or in any other visual way, to a user of the terminal the fact that the terminal is operating in an insecure mode. This will alert the user to the fact that unsafe mode has been entered.
A watchdog function is provided for various timing purposes. In case the signature verification of the downloaded software fails, the checksums do not match or some other error is detected, the operation of the ASIC or the mobile telecommunication terminal in which it is arranged should be stopped. This should preferably not be done immediately when the error occurs. A random timeout is desired, for example a different time spanning up to 30 seconds. This makes it more difficult for a criminal to detect the instant at which the terminal detected the error. The disablement of the watchdog function update is set in the security check register. The result of this operation is that the terminal itself will restart. The watchdog function can also monitor the length of time the processor is in non-secure mode. If other security control actions fail, a given maximum period of time is established during which access to the processor's non-secure mode is given. This limits the possibility for an intruder to perform device debugging and testing.
The CPU connects to the safe environment hardware through a memory management unit MMU that handles memory operations. It also maps virtual addresses to physical addresses in memory for processes running on the CPU. The MMU is located on a bus that contains data, address, and control signals. It is also possible to have a second MMU arranged to handle memory operations for the ASIC RAM located outside of the secure environment. A standard toggle circuit for limiting the visibility of data on the bus is provided within the ASIC. Architecture should be confined
ES 2 357 421 T3 within a tamper resistant envelope. It should not be possible to explore or carry out measurements and tests on this type of hardware that could result in the disclosure of safety-related components and their processing. The DSP has access to other peripherals such as a direct memory access unit (DMA). The DMA is provided by the architecture to allow data to be sent directly from the DSP to a memory. The DSP is released from the relationship with the data transfer, thus speeding up the overall operation. Other peripherals such as RAM, fast memories and additional processors can be arranged outside the ASIC. A RAM memory is also arranged outside the safe environment in the ASIC, said RAM keeping the unverified software executed by the CPU.
By providing the architecture described above in which the CPU can be used in two different modes, a safe operating mode and a non-secure operating mode, the architecture CPU can be enabled to run unverified software downloaded to the ASIC. This is due to the fact that only verified software has access to the secure environment. This makes it possible to test, debug and maintain the mobile telecommunication terminal and its software without running the risk of a third person having access to the information that would make it possible for them to manipulate the security-related components of the device, thus affecting the functions of the device. safety when they are in the safe environment.
In safe mode, the processor has access to security-related data located in the secure environment. Security data includes cryptographic keys and algorithms, software to drive the circuitry, secret data such as random numbers used as cryptographic key material, application programs, etc. The circuitry can be used advantageously in mobile telecommunications terminals but also in other electronic devices such as computers, PDAs or other devices with data protection needs. Access to and processing of these security data needs to be limited, as an intruder with access to the security data could tamper with the terminal. When testing and / or debugging the terminal, access to security information is not allowed. For this reason, the processor is put into the non-secure operating mode, in which mode access to protected data is no longer provided within the secure environment.
Figure 2 illustrates a live startup process flow chart for the architecture. At power-up, the ROM boot software activates safe mode for initial setup. The signatures for the first protected application and the operating system to download are then verified. If the signatures are correct, the application and operating system are downloaded to the Safe Environment RAM. When the desired software has been downloaded, the CPU is informed that the download is complete and the CPU begins to run the verified software. The operating system and the protected application have thus been downloaded into the secure environment in a safe and reliable manner.
However, if the signature verification fails or if the signature is not present, the non-secure mode is activated and the unverified operation is uploaded to the ASIC RMA outside the secure environment. Possibly, the watchdog function is set to limit the period of time during which the non-secure mode is activated. A maximum period of time is established during which the non-secure mode is active. When startup is complete, this unverified application is run by the CPU. The secure environment is now inaccessible.
Although the invention has been described with reference to specific exemplary embodiments thereof, many different alterations, modifications, and the like will be apparent to one of ordinary skill in the art. The described embodiments are not intended, therefore, to limit the scope of the invention, defined by the appended claims.
Contents4
2 sheets
Sheet 1 Sheet 2
25 members in 11 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 0203216 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 0203216 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| WO2002IB03216 | – | – | – |
Members25
| Document | Office | Kind | |
|---|---|---|---|
| WO2004015553A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002321718A1 | Australia | A1 | |
| WO2004070587A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003303882A1 | Australia | A1 | |
| US2004176068A1 | United States of America | A1 | |
| US2005033969A1 | United States of America | A1 | |
| EP1535124A1 | European Patent Office (EPO) | A1 | |
| CN1650244A | China | A | |
| EP1593015A1 | European Patent Office (EPO) | A1 | |
| JP2005535953A | Japan | A | |
| CN1742247A | China | A | |
| JP2006514321A | Japan | A | |
| CN1322385C | China | C | |
| CN100367144C | China | C | |
| JP4394572B2 | Japan | B2 | |
| EP1535124B1 | European Patent Office (EPO) | B1 | |
| AT497618T | Austria | T | |
| ATE497618T1 | Austria | T1 | |
| DK1535124T3 | Denmark | T3 | |
| PT1535124E | Portugal | E | |
| DE60239109D1 | Germany | D1 | |
| US7930537B2 | United States of America | B2 | |
| ES2357421T3This record | Spain | T3 | |
| US9111097B2 | United States of America | B2 | |
| EP1593015B1 | European Patent Office (EPO) | B1 |
Numbers
- Publication
- 2357421
- Publication, DOCDB
- 2357421
- Publication, EPODOC
- ES2357421T
- Application
- 2755462
- Application, DOCDB
- 02755462
- Application, EPODOC
- ES20020755462T
Titles2
- Spanish
- ARQUITECTURA INFORMATICA PARA EJECUTAR UN PROGRAMA EN UN MODO SEGURO O NO SEGURO.
- English
- INFORMATIC ARCHITECTURE TO EXECUTE A PROGRAM IN A SAFE OR UNSAFE MODE.
Classification
- IPC, 4
- G06F12 14
- G06F21 00
- G06F1 00
- G06F9 455