System for preventing electronic memory tampering
Abstract
This record has no abstract on file.
Term
Projected expiry 17 January 2031.
- Priority
- Filed
- Granted
- Today
- Projected expiry
7 claims: 2 independent, 5 dependent
- 1電子装置のメモリへの無許可のアクセスを防止するシステムであって、 マイクロプロセッサ(402)と、 命令コードを含む読み出し専用メモリ(403)と、 保護されたランダム・アクセス・メモリ(407)と、 安全論理回路(1124)と、を含み、 前記安全論理回路は、 モードの遷移がプログラムによって指定され、かつ前記読み出し専用メモリ(403)がメモリアクセス先として選択されている場合に、安全モードに移行し、前記安全モードにない場合に、前記保護されたランダム・アクセス・メモリ(407)がメモリアクセス先として選択された場合、前記マイクロプロセッサ(402)の動作を停止させる ことを特徴とするシステム。
- 2請求項1記載のシステムであって、ハードウェアに基づくタイマ(401)を更に含み、 前記安全論理回路(1124)が、前記読み出し専用メモリ(403)以外のメモリ装置に記憶された命令コードを実行して前記タイマ(401)へアクセスする企図を検出し、当該企図が検出された場合に、前記マイクロプロセッサ(402)の動作を停止させて、係るアクセスを防止する、システム。
- 3請求項1記載のシステムにおいて、前記システムが監視モードにある場合にのみ、前記安全論理回路(1124)が、前記読み出し専用メモリ(403)に記憶された前記命令コードの実行に基づいて前記保護されたランダム・アクセス・メモリ(407)へアクセスする、システム。
- 4請求項1記載のシステムであって、セルラー電話におけるメモリアクセスを防止するシステム。
- 5予め計算されている前記電子装置のメモリの内容のハッシュ値を、前記保護されたランダム・アクセス・メモリ(407)へと読み出す手段と、 前記電子装置のメモリの内容のハッシュ値を計算する手段と、 前記計算されたハッシュ値が前記保護されたランダム・アクセス・メモリ(407)に読み出されたハッシュ値と一致しているか否かを比較する手段と、 前記計算されたハッシュ値が前記保護されたランダム・アクセス・メモリ(407)に読み出されたハッシュ値と一致していない場合、前記電子装置の動作を停止させる手段と、 をさらに含む こと を特徴とする、請求項1記載のシステム。
- 6前記電子装置のメモリの内容のハッシュ値の前記計算を行わせるタイマ(401)をさらに含み、 前記安全論理回路は、前記読み出し専用メモリ(403)以外のメモリ装置に記憶された命令コードを使用して前記タイマ(401)へアクセスする企図を検出し、前記企図が検出された際に、前記マイクロプロセッサ(402)の動作を停止させて、係るアクセスを防止する ことを特徴とする、請求項5記載のシステム。
- 7前記メモリアクセス先はチップ選択信号によって指定される ことを特徴とする、請求項1乃至6の何れか1項記載のシステム。
Independent claims7
77 paragraphs, as filed
The present invention relates to electronic memory operations, in particular methods and devices for preventing unauthorized operations of memory contents for which safety is desired in electronic devices.
The invention disclosed herein relates to any electronic device having memory contents that should be kept in a safe or preferably immutable state. Such requirements are for safety reasons such as preventing fraudulent manipulation of cellular phone memory, or for the purpose of maintaining the integrity of electronic device operation in critical applications such as aircraft control or medical device operation. It can be said that it is required for. As disclosed and described herein, exemplary embodiments of the invention are described in the description of systems and methods that ensure the security of one or more electronic memories in a cellular telephone. Also described herein are access to and memory of one or more electronic memories within an electronic device by using a data transfer device that undergoes an authentication process before being allowed to access the electronic memory. It is a system that allows operation. The latter system is also described in the discussion of cellular telephone applications. Even if the exemplary embodiments of the invention disclosed herein are described in the description of a secure cellular telephone memory and means for safely accessing and modifying the contents of the memory in the cellular telephone, those skilled in the art will appreciate it. As will be appreciated, a system according to the present invention shall be applied to any electronic system having one or more memories whose contents should be kept unchanged or whose contents should be accessed only by authorized means. Can be done. Therefore, it is intended that the scope of the present invention is not limited by the exemplary embodiments dealt with herein, but by the claims and equivalents herein.
In the United States, losses from cellular phone fraud were estimated at $ 600 million in 1995. In response, manufacturers, service providers, the Federal Communications Commission (FCC) and industry trade groups have been investigating a number of technologies to combat such fraud. The majority of cellular phone scams committed in the United States are due to some of the memory manipulation techniques that cellular phones must prepare to establish communication to change the electronic serial number (ESN) of cellular phones. Involved. Therefore, under the idea of a rule by the FCC, one anti-fraud technology is to require cellular phone manufacturers to make all microprocessor codes and ESNs immutable. Some background is given below for basic cellular communications to help explain the cellular telecommunications operating environment and related issues addressed by systems incorporating the present invention.
Figure 1 shows a simplified layout of the cellular communication system. Mobile telephones M1 to M10 communicate with the fixed portion of the public switched network by receiving radio signals with cellular base stations B1 to B10. Cellular base stations B1 and B2 are connected to the public exchange network via the Mobile Switching Center (MSC). Each base station B1 to B10 transmits a signal in the corresponding area, that is, in the "cells" C1 to C10. As shown in Figure 1, the ideal placement of base stations effectively minimizes the amount of overlap of those cells and effectively covers the areas (eg, urban areas) where mobile phone communications normally occur. Organized to cover.
When a user activates a mobile phone in a cell, the mobile phone sends a signal indicating the presence of the mobile phone to the base station in that cell. The mobile phone sends a signal that may contain the ESN of the mobile phone to a designated setup channel that is continuously monitored by each base station. When the base station receives the mobile phone signal, the base station registers the presence of the mobile phone in the cell. This process is repeated continuously so that as the mobile phone moves into another cell, it is properly registered.
When the mobile phone number is dialed, the telephone company's telephone office recognizes the number as a mobile phone and forwards the call to the MSC. The MSC sends a paging message to certain fixed base stations based on the dialed mobile phone number and current registration information. One or more of these base stations send pages on their setup channel. The dialed mobile phone recognizes its identity on the setup channel and answers the base station page. The mobile phone also follows a command to tune to the assigned voice channel and then initiates a ringing signal. When the mobile user terminates the communication, a signal confirmation sound is transmitted to the base station and both sides release the voice channel.
In the operation described above, the mobile phone does not endurely connect to the fixed network, but instead communicates with the base station through the so-called "air interface". This, of course, gives the flexibility of a cellular communication system because the user can easily transport the mobile phone without the constraints of being physically linked to the communication system. However, this same feature also creates difficulties in ensuring the security of information transmitted through cellular telephone systems.
For example, in a normal wired telephone system, a central office switch can identify a particular subscriber who is charged for using the telephone over the communication line to which the telephone is physically attached. Therefore, fraudulent use of a subscriber's account typically requires a physical connection to that subscriber's track. This creates a risk of discovery for fraudulent users.
On the other hand, since cellular telecommunications communicate through air interfaces, these systems do not impose such connectivity issues on fraudulent users. Due to the lack of protection systems, fraudulent users have access to other subscribers' electronic serial numbers (ESNs) sent to the network by mobile phones at various times to establish and maintain communications. By doing so, the subscriber's account can be used. In establishing a standard cellular connection, two identification codes are sent to the system by a mobile phone. These are the Mobile Identification Number (MIN) and ESN.
MIN identifies the subscriber, while ESN identifies the actual hardware used by that subscriber. Therefore, it is expected that the MIN corresponding to a specific ESN may change over time as the subscriber purchases a new device. MIN is a 10-digit directory phone number, while ESN is a 32-bit binary number that uniquely identifies a mobile phone. The ESN is typically set by the mobile phone manufacturer.
For example, the customary authentication method used to set up communications on the Advanced Mobile Phone System (AMPS) is shown in the flow diagram depicted in Figure 2. According to this method, at block 200, the base station receives both ESN and MIN from the mobile telephone. These authorization codes are ESN to indicate that this is received from the mobile phone.<sub>m</sub>And MIN<sub>m</sub>Specified by. Then, in block 202, the base station MINs from system memory.<sub>m</sub>ESN corresponding to<sub>sys</sub>To search for. Then in block 204, ESN<sub>sys</sub> Is ESN<sub>m</sub>Is compared with. If these two serial numbers are the same, the flow diagram proceeds to block 206 and system access is granted. Otherwise, system access is denied at block 208.
One drawback of this system is that it is relatively easy for fraudulent users to combine effective MIN / ESNs on the air interface or by eavesdropping from other sources. If the MIN and ESN received from the mobile phone correspond to those stored in system memory, then all of the information needed for fraudulent access is presumed to be valid for access by this traditional system. Can be obtained by electronic eavesdropping. Other technologies have been proposed to prevent fraudulent use. For example, Patent Document 1 describes a method of registering an identification number in a dedicated communication terminal with a service carrier. Patent Document 2 describes a number assignment module setting system for a mobile phone that prevents illegal setting of a number assignment module in a mobile phone.
European GSM standard (Global System for Mobile Communication; GSM)), Visiting TIA / EIA / IS-136, And in systems operating under the Japan Personal Digital Cellular Standard Wireless Communication System, fraud resulting from eavesdropping is prevented by a challenge-response method. According to the challenge-response method, each mobile phone is associated with a unique private key stored in both the mobile phone and the database in the network. System-specific algorithms are stored in each mobile phone and desired network node. When the call is set up, authentication is requested, which causes the network to send a challenge (random number) to the mobile phone. Based on the challenge received and the private key recorded, the mobile phone uses its algorithm to calculate the response and send the response to the network. At the same time, the network "calculates the" expected "response based on the same challenge and network memory private key. The network then receives the mobile phone's calculated response and compares the mobile phone's calculated response with the network's calculated response. If a discrepancy occurs, appropriate action will be taken, for example, access will be denied or a warning flag will be set. A method of performing an authentication inspection between a base station and a mobile telephone in a mobile radio system is described in Patent Document 3 of P. Dent et al.
In customary analog systems, such as AMPS, most scams "clone" valid subscribers by acquiring a valid MIN / ESN pair and using this pair to reprolog the cellular phone. It is done by the user due to fraud. In a more elaborate counterfeit configuration, cellular phone software "tambling" some MIN / ESN pairs. This software is reprogrammed so that it can be used in a practice called. A cellular phone programmed using a tumbling routine scrolls randomly to select a MIN / ESN pair to initiate a call. As the fraud is identified by the service provider or subscriber, the MIN / ESN pair becomes invalid. If an invalid MIN / ESN pair is encountered while attempting to make a call, the tumbling routine simply cancels the MIN / ESN pair and continues scrolling until a valid MIN / ESN pair is found. After all of this MIN / ESN pair programmed into the cellular phone has been disabled, the phone user typically has a new pair of MIN / ESN pairs programmed into the cellular phone. Reward (cloner).
Most cellular scams involve a certain amount of memory manipulation. This will be described with reference to FIG. 3, which shows a conventional cellular telephone memory and processor configuration.
Controller 300 uses memory bus 308 to communicate with ROM or flash memory 320, EEPROM 310, and random access memory (RAM) 330. The programmable memory 320 is a non-volatile read / write memory, which is used to store most of the code used for the general operation of cellular phones. The EEPROM 310 is used to store the MIN / ESN pairs 314 and 316, and the user profile information 312 (eg, speed dialing number), and the RAM is used for the read / write scratch pad. The counterfeiter knows to monitor messages between memory and controller 300 to collect information to use and bypass or modify the information stored in flash memory 320 or EEPROM 310.
The most common method of telephone fraud was the illegal use of telephone services and test orders intended for repairs to change the ESN. However, more recently developed phones are resistant to such mischief and effectively eliminate this type of attack. Therefore, counterfeiters have resorted to attacks in more sophisticated ways.
One such technique involves removing and replacing the original EEPROM 310 containing ESN314. Following its removal, the EEPROM is studied and its contents deciphered (dechiper). The replaced EEPROM is then programmed with the decrypted content to embrace the ESN / MIN pair from the valid user account. This technique may be appealing to counterfeiters if they only want to change one ESN at a time. However, this technique can damage printed wiring unless too tedious and inexperienced counterfeiters are extremely careful.
A major step in counterfeiting sophistication involves analyzing the telephone microprocessor program code and rewriting one or more sections of that code to send fraudulent identification information (ESN / MIN vs.) to the cellular base station. .. This often involves reverse engineering of telephone hardware design and requires a considerable understanding of embedded software design. However, the obvious advantage of this method is that once the modification is complete, the phone can be reprogrammed with the new identification information as often as desired.
Most elaborate attacks combine the above mentioned cellular phone microprocessor code changes with hardware modifications. An example of this technique uses so-called "shadow memory" to avoid detection by traditional memory validation routines that run only during the bootup process when the cellular phone is first tuned. The bootup process runs according to a small portion of boot code 304 contained in controller 300 (see Figure 3). The boot-up process configures the cellular phone to be in service and sets the program counter in microprocessor 301 to a suitable location in flash memory 320. When this process is complete, controller 300 will turn on LED 318 (or any other equivalent signal) to indicate to the user that the phone is in use. The counterfeiter can monitor the connection 306 between controller 300 and LED 318 to disrupt the execution of normal operating code in flash memory 320, as described in more detail below.
The flash memory 320 included in a typical modern cellular phone has a addressable capacity of 512K. The counterfeiter removes the flash memory 320, copies the contents of the original flash memory into the first 512K of the 1024K shadow memory 322, and then replaces the original flash memory 320 with the 1024K shadow memory. You can also do it. During bootup, any access to program memory is successfully directed to the first 512K of flash memory 320. The counterfeiter is then available in the phone (such as LED signal 306) to indicate that the boot process is complete in order to switch all future program memory access to shadow memory 322. You can also monitor the signal. The cellular phone then operates according to instructions in shadow memory 322, which memory can be programmed to contain tumbling routine code and an equivalent MIN / ESN pair.
Various attempts have been made to prevent memory tampering. For example, Patent Document 4 describes a safety technique in which access to a memory area in a mobile radiotelephone is permitted only by a CPU instruction extracted from a ROM. Patent Document 5 describes a system that prevents memory from being written when certain events occur. Other systems that prevent fraudulent use and / or tampering are described in Patent Document 6, which describes and patents remote access systems for cellular phones that prevent unauthorized access and tampering with cellular phone programming. Reference 7 describes checking the integrity of a program or data, in which the signature calculated by the processing circuit of the portable object is compared to the original message signature.
The Federal Communications Commission (FCC) is currently considering a solution to this aspect of cellular phone fraud, as most cellular frauds are based on some degree of memory manipulation. This solution is incorporated into the draft FCC Regulations set out in Chapter 22.219. As currently written, Chapter 22.919 prohibits the operating software of mobile phones from being modifiable, and ESNs may be factory-set and modified, transferred, removed or manipulated in any way. If you request that it is not possible and the mobile transmitter intends to remove, tamper with, or change the ESN, system logic, or firmware of the cellular phone by anyone, including the manufacturer, it will work. Demand that it be impossible.
From the consumer's point of view, the ability of the current manufacturer or service agent authorized by its factory to program the current cellular phone facilitates the replacement of a malfunctioning cellular phone. For example, if a subscriber's cellular phone does not work properly, the subscriber obtains a new device from a factory-licensed agent and gives it the same electronic "personality" as that of the old device. Can be programmed to include. The electronic personality of a cellular telephone includes not only the ESN, but also a significant amount of information programmed into the device by the subscriber, such as user profiles and personal and / or business telephone numbers. The technology to quickly and easily add ESN changes and other memory changes to repair / replacement programs and cellular phones was developed at the insistence of cellular service providers who do not want to inconvenience their subscribers with defective terminals. It has been.
Under FCC Chapter 22.219, subscribers in the situations described above will still be able to obtain new equipment if their old mobile equipment is defective. However, because the new fixed ESN will be associated with the new device, the new ESN information must be communicated to the cellular carrier, which will use it in their database. You will have to program. As a result, the subscriber will not be able to receive the service for a long time. The subscriber will also have to program the cellular phone with some personal or business phone number. A far more prominent issue with Chapter 22.919 is the ability of cellular service providers to perform system upgrades to their subscribers by programming or reprogramming their subscribers' cellular phones 22.919. This is the opposite effect of the chapter.
The actual impact of Chapter 22.919 on the ability of the cellular industry to upgrade systems is expressed as follows: For example, the use of digital control channels, as specified in the TIA / EIA / IS-136 standard, allows cellular carriers to offer new extended services, such as short messaging services. If carriers, manufacturers, or authorized distributors are allowed to make changes to cellular phone software or firmware, such services will be promptly and efficiently provided to subscribers through terminal software upgrades. Can be made available. Under Chapter 22.919 (in its current form), neither the manufacturer, the manufacturer's authorized service agent, nor the cellular operator can make such software changes. The only way carriers can offer subscribers system enhancements is to require them to purchase new cellular phones.
In order to improve the impact of Chapter 22.919 on the manufacturing industry as well as the subscribers, the FCC has sent the rule to cellular phones for which an application for initial type acceptance was submitted after January 1, 1995. It was stated that it would be applied. In fact, the FCC has entered service after January 1, 1995, as well as the 20 million cellular phones currently in operation, based on an application for type approval filed before January 1, 1995. Ten thousand cellular phones have been exempt from this rule. The fact that there are so many cellular devices on the market that can manipulate electronic information for illegal purposes suggests that Chapter 22.919 has a very small impact on the fraud problem. These entities involved in fraud by illegally tampering with ESNs may continue to be involved in fraud by using millions of unconstrained terminals in Chapter 22.919.
As can be seen from the above, it is highly desirable to prepare a cellular telephone having a safety memory. There currently seems to be no solution to improve these phones to counter pranks on cellular phones. Moreover, there appears to be no method or device for updating electronic device memory in a way that guarantees only authorized access.
<p><patcit num="1"><text>U.S. Pat. No. 5,386,486</text></patcit><patcit num="2"><text>European Patent Application Publication No. 0 583 100</text></patcit><patcit num="3"><text>U.S. Pat. No. 5,282,250</text></patcit><patcit num="4"><text>International Publication No. 91/09484 Pamphlet</text></patcit><patcit num="5"><text>French Patent Invention No. 2 681 965</text></patcit><patcit num="6"><text>U.S. Pat. No. 5,046,082</text></patcit><patcit num="7"><text>U.S. Pat. No. 5,442,645</text></patcit></p>
<p> These and other shortcomings, and limitations of the conventional methods and proposed solutions to prevent cellular telephone memory tampering, and electronic device memory tampering in general, are overcome by the present invention, and exemplary embodiments of the present invention are electronic memory. Protect the content from unauthorized access and operation.</p>
<p> According to one aspect of the invention, safety is achieved by periodically auditing the contents of electronic memory in the electronic device to ensure that they have not been tampered with. This audit involves performing a hash calculation on the audit hash value of such content, or the selected content of electronic memory to derive the audit signature. The audit hash value is compared to the valid hash value previously derived from the genuine memory contents. The valid hash value is preferably stored in electronic memory in encrypted form and decrypted for comparison purposes only. A discrepancy between the audit hash value and the valid hash value can display a memory prank and thus can render the electronic device containing the electronic memory inoperable or provide a warning display.</p><p> According to another aspect of the invention, electronic memory contents, such as those contained in a cellular phone memory (including the ESN of a cellular phone), are authenticated data before the memory contents are allowed access. It can be updated by the transfer device. Data transfer device authentication involves the use of public / private key authentication methods. When the data transfer device interfaces with the electronic device and requests access, the electronic device initiates the process of authenticating the data transfer device. This can involve exchanging a series of messages between an electronic device and a data transfer device. The public key is "signed" with a secure private key that is maintained in the electronic device used to decrypt the encrypted message or in the data transfer device. Will be done. In particular, the authentication process begins when the data transfer device requests to program the electronic device. The electronic device responds by sending a challenge message to the data transfer device. The challenge message is signed with a digital signature using a private key maintained within the data transfer device. The signed challenge message is sent back to the electronic device, which authenticates the message with the public key. Once authenticated, the data transfer device is allowed access to privileged instructions and capabilities within the electronic device.</p><p> Following some reprogramming of the electronic memory, the electronic device performs a hash calculation on the modified memory contents to derive a new (valid) hash value. The new hash value is returned to the data transfer device for a digital signature with the private key. The new signed hash value is returned to the data transfer device for storage. When the electronic device performs a subsequent memory audit, the resulting hash value is compared to the new valid hash value.</p><p> The above and other objects, features and advantages of the present invention will be more easily understood when reading this description in connection with the accompanying drawings.</p>
<figref num="1">It is a diagram which shows the ideal layout of a cellular communication system.</figref><figref num="2">It is a flow chart which shows the customary cellular authentication method of setting a cellular call.</figref><figref num="3">It is a block diagram which shows the customary cellular telephone processor and memory composition.</figref><figref num="4">FIG. 5 is a block diagram showing a cellular telephone processor and memory configuration according to an exemplary embodiment of the present invention.</figref><figref num="5">It is a flow chart which shows the exemplary cellular telephone start-up process according to the Example of this invention.</figref><figref num="6">It is a flow chart which shows the exemplary periodic memory validation process according to this invention.</figref><figref num="7">It is a block diagram which shows the exemplary data transfer apparatus according to the Example of this invention.</figref><figref num="8">It is a flow chart which shows the exemplary process which authenticates the data transfer apparatus according to the Example of this invention.</figref><figref num="9">It is a flow diagram which shows the exemplary process of inputting an initial ESN into a cellular memory according to the Example of this invention.</figref><figref num="10">It is a flow chart which shows the exemplary process of reprogramming ESN established according to this invention.</figref><figref num="11">It is a block diagram which shows the memory structure protected according to the exemplary embodiment of this invention.</figref><figref num="12">FIG. 6 is a block diagram showing a model cellular telephone programmer according to an embodiment of the present invention.</figref>
An exemplary electronic memory relating to an apparatus and method according to the present invention is disclosed below in the context of cellular telephone applications. The examples described below are provided solely to illustrate the ideal application that incorporates the invention.
In FIG. 4, controller 400 controls a cellular telephone (see, eg, reference numeral 1204 in FIG. 12). Controller 400 includes flash program memory 420, electronically erasable programmable read-only memory (EEPROM). Works in conjunction with 410 and random access memory (RAM) 408. Controller 400 includes microprocessor 402 and internal read-only memory (IROM) 403. The IROM403 includes a boot code 404, a hash code 405, an authentication code 409, and a public encryption key 406. Controller 400 also includes a protected static random access memory (PSRAM) 407, an interrupt controller 421, and a hardware-based timer 401 to initiate periodic hash calculations by microprocessor 402 to selected memory contents. Including. The EEPROM 410 contains user profile data 412, ESN414, MIN416, and signed / unsigned valid hash value vs. 418. The flash program memory 420 contains instruction codes related to the general operation of the cellular telephone. The RAM memory 408 is used as a scratchpad for operations that are part of the regular cellular phone call processing. Operations related to sensitivity data, hash value calculation and authentication process are preferably performed in cooperation with PSRAM407. The controller 400 communicates with the flash program memory 420, RAM408, and EEPROM 410 via memory bus 424.
FIG. 5 shows the process of telephone power-on and memory validation for the system shown in FIG. 4 according to the exemplary embodiment of the present invention. After the cellular phone is turned on, the boot code 404 in the IROM 403 is executed by the microprocessor 402 to initialize the controller (block 500). The hash code 405 contained within the IROM 403 is run to perform the audit hash value calculation on the selected contents of the flash program memory 420 and the ESN value 414 stored in the EEPROM 410 (block 502). The controller then authenticates the signed hash value pair 418 stored in EEPROM 410 (block 504). This may involve authenticating the signed valid hash value by processing the signed valid hash value with the public key 406 and then comparing the result with the unsigned hash value. The authenticated hash value is then stored in PSRAM407 (block 506). .. The audit hash value derived in block 502 is then compared to the authenticated hash value derived in block 504 (block 508). If these two hash values match, the microprocessor program counter is set to an appropriate location in flash memory 420 and the periodic hash calculation process is enabled (block 510), after which. The cellular phone begins normal operation (block 512). If the hash values do not match in block 508, the system is placed in an infinite loop (block 514), otherwise it is disabled. The above process both prevents the counterfeiter from substituting the modified program into flash memory or the modified ESN into EEPROM 410. This is because any attempt to do so will result in a hash value mismatch, which will render the phone inoperable.
Periodic hash value processing is preferably performed to prevent the shadow memory 422 from being assigned to the active flash memory 420 following the start of normal operation. During regular telephone operation, periodic hash value calculations are performed in response to timer expiration or other system events. In the exemplary embodiment shown in Figure 4, the periodic hash calculation is started in response to the expiration of the hardware-based timer 401, which has a non-maskable interrupt (NMI). generate. NMI is a hardware-friendly process that cannot be "masked" output by software processes. Therefore, counterfeiters cannot configure shadow code designed to ignore NMI. Regular interrupts are also hardware interrupts, which must compete with other regular interrupts from regular cellular phone events to gain access to microprocessor resources. A regular interrupt is acknowledged and processed when it becomes the highest priority interrupt requesting service.
Since the full hash value calculation can take longer than can be tolerated by normal phone operation, it is preferable to perform the processing fragmentarily in several segments distributed over time intervals (eg, seconds). Is. According to another aspect of the invention, the hardware-based timer evokes two steps to perform a segment of hash value calculation. First, an unmaskable interrupt (NMI) causes the microprocessor to immediately retrieve the contents of the next flash or EEPROM memory location to be included in the periodic hash calculation and store it in PSRAM. NMI is a type of short, highest priority interrupt that has little negligible effect on the micropfrosessa task, which can be active when NMI occurs. This ensures that counterfeit software cannot take action to avoid detection by hashing. Second, a low-priority standard interrupt is also generated by the hardware-based timer 410, which is a service that completes the current segment of hash value calculation based on the memory bytes previously captured by the NMI routine. Request. This task may be postponed for a predetermined maximum time (T) as required for the legitimate call processing task before the hardware timer expires and the phone is disabled. The longest (T) is to complete any legitimate call processing, to finish the hash compute segment, and to reset the hardware timer to the start of its countdown cycle before it expires. Is selected as appropriate. The strategy of using two types of interrupts to periodically complete the hash value calculation segment avoids any degradation of the system response, while safety checks are bypassed by counterfeit software residing in shadow memory. Guarantee you won't get it.
FIG. 6 shows a flow chart showing a model periodic hash value calculation according to the present invention. Referring to this figure, when the T1 counter in the hardware timer 401 expires (block 602), both NMI and regular interrupt occur in block 604. Once NMI gains microprocessor control (block 604), the system disables or queues regular interrupts during a short time interval, during which time the flash memory required for hash computation. The next byte in or in EEPROM memory is copied into PSRAM (block 606).
Control then reverts to the task it performs when the NMI occurs (block 608). Under normal conditions, within a short time interval, a regular interrupt from the hardware-based timer 401 is also provided (block 610), and the hash calculation segment completes based on the memory bytes previously stored in PSRAM. Is done (block 616). If the hash value calculation is not yet complete, the hardware-based timers (T1 and T2) 401 are reset to their initial values (block 624) and regular phone operation continues until the next expiration of timer T1 (block 624). Block 600). If the timer T2 expires (block 612) before the regular interrupt is supplied (block 610), the phone is disabled (block 614). The default expiration of timer T2 (unless the regular interrupts are properly supplied) prevents counterfeiters from disabling periodic hash computations.
This periodic fragmentation of the hash value continues until the audit hash value calculation is complete (block 618). The previously authenticated hash value is then retrieved from PSRAM and compared to the audit hash value (block 620). If they match, the hardware-based timer 401 is reset (block 624) and the phone continues to operate normally (block 600). If there is a mismatch, the system is disabled, for example, by placing the microprocessor 402 in a stop condition (block 622).
Selected contents of the cellular telephone memory where the hash calculation is preferably performed include the contents from the flash memory 420 and the ESN in the EEPROM 414.
This is a reprogrammed device containing modified ESN and / or program code designed for counterfeiters to physically remove either flash memory or EEPROM and scam them into cellular carriers. Prevents replacement with. It is preferable that the selected memory contents and the hash value used render the phone inoperable even by modifying one bit of the memory included in the hash value calculation.
According to another aspect of the invention, the cellular phone can be programmed in a secure manner using a data transfer device. An exemplary data transfer device according to the present invention is shown in FIG. The reference number of controller 400, its contents, and the associated memory are the same as those in FIG. The exemplary data transfer device 750 includes a secure microprocessor 752, which contains a private encryption key 754, which corresponds to the public encryption key 406 in IPROM 403 in controller 400. The safety microprocessor 752 communicates with the cellular telephone controller 400 via interface 758. The interface 758 may be a wired series connection such as an RS-232 link, a wireless infrared interface, or an RF interface such as the main antenna of a cellular telephone (not shown) or another antenna within a cellular telephone.
Access to cellular phone memory by the data transfer device 750 is only allowed after a rigorous authentication process has been completed. Further detailed, controller 400 (and associated memory components) accesses for the purpose of downloading data only after the data transfer device 750 has undergone a challenge response process to ensure its authenticity. be able to. FIG. 8 shows an exemplary process for authenticating the data transfer device 750 according to an exemplary embodiment of the invention. As a first step (block 800), the phone is preferably subject to operating conditions using the fraud prevention process described above with respect to FIG. After the interface is established, the safety processor 752 sends a programming request message to the controller 400 along with the random number (Rand1) generated by the safety microprocessor 752 (block 802). In response, controller 400 sends a random number challenge code (Rand2) to safety microprocessor 752 (block 804). .. The secure microprocessor 752 then generates a challenge response based on Rand1, Rand2 and private key 754 (block 806).
The challenge response is then returned to controller 400 (block 808). The challenge response is processed by controller 400 using Rand1, Rand2, and public key 406 (block 810). The processed challenge response is then authenticated by comparing its value to Rand2 (block 812). If the challenge response (eg Rand2) decrypts properly, the data transfer device authentication is validated and the phone enters programming mode (block 814). The data transfer device 750 can then access and / or download the contents of the new flash memory 420 in the cellular phone.
If the challenge response is not valid, the failure count is incremented (block 816). The failure count is checked to see if it has reached a given number (maximum count) (block 818). The fault count takes into account that the data transfer device 750 may be communicating with the controller 400 through a noisy medium. It can be said that any resulting transmission error causes an authentication failure. Therefore, it is preferable to give the data transfer device 750 more than one opportunity to put the cellular phone in programming mode. In the exemplary embodiment of the invention, a maximum count of 50 was determined to be appropriate. If the maximum is not reached, a message is sent to the data transfer device 750 indicating that an authentication failure has occurred (block 822). Upon receiving such an indication, the authentication process restarts at block 802. If a certain number of attempts have been reached, the phone may display a message indicating to the user that it has been placed in an inoperable condition and that the phone must return to an authorized service.
After the data transfer device 750 completes some ESN reprogramming or downloading to the flash memory 420, the controller 400 in the phone begins a new hash calculation, which is, for example, the revision of the flash memory 420 and Includes ESN414. The resulting hash value is sent to the data transfer device 750 for a digital signature using the private key 754. The signed hash value, along with the unsigned hash value of the same hash value, is then returned to controller 400 for storage in EEPROM 410.
The ESN can be reprogrammed according to the present invention, but for safety reasons, ESN programming is preferably performed at the factory level rather than a licensed factory agent. ESN programming can occur in two situations. That is, initial ESN programming in production and reprogramming of existing ESNs. The initial ESN can be programmed using a data transfer device similar to that shown in Figure 7. The initial ESN programming process is described below with reference to Figure 9.
The first step (block 900) is to bring the phone up and running (see Figure 5). Following the establishment of an interface with this phone, the safety processor 752 sends an ESN programming request message with a random number (Rand1) to controller 400 (block 902). Controller 400 performs a check to determine if all ESNs in the phone are zero, as is the case with newly manufactured phones (block 906). If the ESNs are all non-zero, the ESN programming mode request is denied (block 906). If the ESNs are all zero, a challenge-response process that is substantially similar to that set in steps 804-820 of Figure 8 is initiated (block 908).
Following the successful certification of the data transfer device 750, the new ESN can be downloaded into the EEPROM 410.
After the data transfer device 750 completes downloading the ESN into the EEPROM 410, the controller 400 initiates a new hash calculation that includes the new ESN 414. The resulting hash value is sent to the data transfer device 750 for a digital signature using the private key 754. The signed hash value 418 is then returned to controller 400 along with the unsigned hash value of the same hash value for storage in EEPROM 410.
Existing ESNs can also be reprogrammed within systems incorporating the present invention. ESN reprogramming is preferably performed only at the factory and not by a licensed local factory agent. Security is added by utilizing a set of factory-only microprocessor instructions loaded into the phone for the purpose of altering the previously programmed ESN into the phone. This process can be performed using a data transfer device similar to that shown in FIG. 7, which is described below with respect to FIG.
As the first step (1000), the phone is put into regular programming mode according to the process shown in Figure 8. Factory data transfer device 750 includes ESN reprogramming code 756, which can be downloaded into PSRAM407 of a cellular phone to facilitate ESN reprogramming. Once the system is in programming mode, ESN reprogramming code 756 is downloaded into PSRAM407 (block 1002). In executing ESN reprogramming code 756, controller 400 zeros the existing ESN (block 1004) and initiates the ESN reprogramming process (block 1006).
After the data transfer device 750 completes inputting the new ESN into EEPROM 410, controller 400 initiates a new hash calculation, which includes the new ESN 414 (block 1008). The resulting hash value is sent to data transfer device 750 for a digital signature using private key 754 (block 1010). The signed hash value 418 is then returned to controller 400 along with the unsigned hash value of the same hash value for storage in EEPROM 410 (block 1012).
The hash value calculation and digital signature in the exemplary embodiment of the present invention are performed using a one-way hashing function and a private / public key authentication scheme. The one-way hash function is used to derive a hash value that represents the memory contents in the cellular phone. The public / private key scheme is used to secure the valid hash value stored in EEPROM and to authenticate a data transfer device or programmer who intends to manipulate the memory in a cellular phone. One-way hashing is known to those of skill in the art and is described, for example, in Moore's US Pat. No. 5,343,527.
A one-way hash function is a function that is easy to calculate in the forward direction but difficult to calculate in the reverse direction. The one-way hash function H (M) operates on an arbitrary length input M, which in the exemplary embodiment of the invention consists of selected electronic memory contents. The hash function performed on M yields a fixed-length hash value h (see Equation 1).
h = H (M) Equation 1 There are many functions that can take arbitrary length inputs and produce fixed length outputs, but unidirectional hash functions have the following additional features: That is, given M, it is easy to calculate h. Given h, it is difficult to calculate M. And given M, it is difficult to find other messages M'like H (M) = H (M').
The basic attack on a one-way hash is as follows: That is, given the hash value of the memory contents (hashed contents), the counterfeiter will try to create another set of memory contents M', such as H (M) = H (M'). Let's go. If the counterfeiter succeeded in doing this, it would secretly break the security of this one-way hash function. The purpose of the one-way hash function is to provide a signature unique to M, the fingerprint. In the present invention, the secure one-way hash function is performed on the selected contents of the cellular telephone memory to provide the audit hash value. The audit hash value is compared to the previously generated valid hash value by performing a one-way hash function based on the selected memory contents known to be authentic from memory.
In a preferred embodiment, a message digest algorithm such as MD5 is used for safe one-way hash calculation. The MD5 algorithm produces an N-bit hash of the input message, that is, a message digest (ie, the selected memory contents). The MD5 algorithm is very sensitive in that changing a single bit in the selected content statistically causes a change in half of its hash value bits. The MD5 algorithm is also known for its speed and simplicity. Speed is an important issue to consider in that the time demands placed on the microprocessor of a cellular phone must not be so great that it unacceptably interferes with normal system processes.
The MD5 algorithm can also perform this algorithm incrementally, which allows the hashing process to be interrupted, thus allowing it to tackle normal microprocessor tasks before reinitiating hashing. Suitable for. In addition, the MD5 algorithm is well suited for use in traditional microprocessor architectures. Other one-way hash algorithms that can be used according to the embodiments of the present invention include, but are not limited to: That is, Snerfu, H-Hash, MD2, MD4, Secure Hash Algorithm (SHA), and HAVAL. Those skilled in the art can easily program the microprocessor to perform a one-way hashing process.
Public key algorithms use two keys, one is publicly available and one is privately (confidential), such as message encryption and decryption, message authentication, and digital signatures. For tasks. These keys can be used in different ways to achieve different goals. For example, if the purpose is to keep the message secret, the recipient should keep the private key secure so that only the recipient can decrypt the message. In such cases, the encryption key may be known to be publicly known and associated with a particular potential recipient. The sender can guarantee the security of the information in this process, but the receiver cannot guarantee the authenticity of the sender. If the private key of a pair of keys is kept secret by the sender for encryption, then any recipient with the corresponding public key is guaranteed the authenticity of the sender, although there is no guarantee of security. obtain. It is the latter method that is used to authenticate the data transfer device according to the present invention.
The public key algorithm operates on the basis of a mathematical trapdoor function, which makes it computationally infeasible to calculate the private key from the public key. The well-known RSA (Rivest, Shamir, and Adlemen) algorithm is based on the difficulty of factoring the product of two large prime numbers. Key selection begins with the selection of two large prime numbers p and q, which are multiplied by each other to yield the large number n.
n = pq Equation 2 The encryption key e is then randomly selected so that e and (p-1) (q-1) are relatively prime numbers. Finally, using the Euclidean algorithm, the decryption key d is calculated as follows.
F = (p-1) (q-1) Equation 3 ed = 1 (modF) Equation 4 The numbers e and n are public keys and the numbers d are private keys. Equation 5 gives the RSA encryption process, and Equation 6 gives the decryption process.
C = M<sup>e</sup>(modn) Equation 5 M = C<sup>d</sup>(modn) Equation 6 An enemy capable of finding the factor n may be able to use Equation 3 to determine the coefficient F, and then, given the public key e, determine the private key d from Equation 4. Nevertheless, as noted above, n is usually so large that it makes such factorization infeasible. Further details on the RSA algorithm can be found in Rivest et al., US Pat. No. 4,405,829.
In a preferred embodiment of the present invention, the Fiat-Shamir (FS) algorithm or a collateral system thereof is used (US Pat. No. 4,748,668 is referred to, and the content of this patent is described by reference. Fully incorporated in the specification). The FS algorithm is suitable for implementing authentication and digital signature methods, which are well suited for the limited computing power of typical cellular phones.
The FS algorithm is a square surplus (ν) that this algorithm modifies n.<sub>i</sub>It differs from the previous method, such as RSA, in that it uses a factor based on the difficulty of finding the reciprocal of). Further described in detail, the FS scheme preferably involves selecting a number n, which is the product of two large prime numbers ranging in length from 512 bits to 1064 bits. Public key (ν): ν<sub>1</sub>, ν<sub>2</sub>, ... ν<sub>k</sub>, And private key (s): s<sub>1</sub>, s<sub>2</sub>, ... s<sub>k</sub>, Is s<sub>i</sub>= sqrt (1 / -ν)<sub>i</sub>) Occurs like mod n. Reciprocal (1 / -ν) in the context of the above formula<sub>i</sub>) It can be shown that the difficulty of finding mod n is equivalent to the difficulty of finding the factor of the prime number n. This algorithm runs much faster than other methods without sacrificing safety. In fact, the FS method is superior to the RSA method in that the FS calculation requires only 1% to 4% of the modular multiplication normally required to complete the required authentication calculation. I know. This is equivalent to authenticating a hash value signed up to two orders of magnitude faster than using the RSA method to perform the same task. Therefore, data transfer device authentication and periodic audit hash value comparison can be performed much faster using the FS method than the RSA method. When programming a large amount of cellular telephone memory or other electronic memory at the factory level, the use of the FS algorithm reduces production time by generating digital signatures of valid hash values to be stored more quickly. Algorithms that can be applied include, but are not limited to, ELGAMAL, DSA, and Feige-Fiat-Shamir.
According to another aspect of the invention, the controller hardware in the cellular phone has safety features that prevent the counterfeiter from determining the contents of the safety memory or bypassing the safety scheme described above. .. FIG. 11 shows details of the controller hardware, external memory, and memory / address bus structure. Except for the chip select logic 1122 and safety logic 1124, Con function and operation of the components in the controller is the same as described for FIG. The chip selection logic 1122 decodes the address on bus 1102 to provide the hardware selection signal to the memory components and hardware devices connected to the microprocessor address bus 1102. For example, IROM chip selection (CS) is enabled whenever the address assigned to IROM memory 403 appears on address bus 1102.
Safety logic 1124 functions to detect attempts to access the contents of PSRAM407 or reset the hardware-based timer 401 using microprocessor instruction codes stored in memory devices other than IROM memory 403. For example, a read or write instruction placed in the flash memory 402 using the target address of the memory location in PSRAM407 will be detected as an illegal operation. Any illegal access attempt puts the microprocessor into a stopped state, which requires a complete power reset of the phone for the cellular phone to restore normal operation.
Safety logic is to realize the following formula. That is, Formula 1 S = Supvr B Formula 2 Halt = notS (A + C)
here, S = safe mode, Supvr = Transition to microprocessor monitoring mode, A = Chip selection signal for PSRAM memory, B = Chip selection signal for IROM memory, C = Chip selection signal for hardware timer, Halt = A hardware-controlled input to the microprocessor that puts the microprocessor into an indefinite loop or waits until the power is removed and reapplied to the phone.
The above formula 1 states the following. That is, when the microprocessor transitions to the monitoring mode ( Supvr) and at the same time the IROM403 is active ( B), the safety mode (S) is set. Formula 2 states the following. That is, if the controller 400 is not in safe mode (notS) and either PSRAM407 selection or hardware timer chip selection is active ( (A + C)), the microprocessor stop input is activated. To. This logic is provided by the hash value comparison and authentication process described above, since the legitimate access to PSRAM407 and the reset instruction to the hardware timer 401 are preferably derived from the code stored in IROM403. Effectively prevent bypass of safety measures.
All legal codes (boot code, ash code, public key code, and authentication code) placed in IROM memory 403 are preferably put in parentheses by instruction, which sets the safety mode to the start of the routine. Let and clear when leaving the routine. In a preferred embodiment of the invention, a software interrupt instruction (usually available in modern microprocessors) is placed at the beginning of each routine in the IROM403 to switch the microprocessor 402 to surveillance mode and the microprocessor hardware. Activate the signal SPVR. Since the IROM403 chip selection signal is then active, safety mode S is set. A return instruction is executed at the end of the software routine to cancel safe mode.
According to another aspect of the invention, the data transfer device includes a factory-supplied safety device, which device can be used in combination with a general purpose computer. The safety device 1200 is attached to the input / output port of the PC1202 via the standard connector 1206. The second port on the PC1202 is used in conjunction with a second standard connector 1208, such as an RS-232, cable, or infrared link, to interface with the cellular phone 1204. The process shown in FIG. 8 can be performed using the configuration shown in FIG. 12 to carry out the cellular telephone reprogramming process. A licensed factory service agent with a standard PC and safety device 1200 is equipped to reprogram the telephone.
According to other embodiments of the present invention, existing cellular phones can be equipped with field programming capabilities that are safe against attacks that do not involve access to the internal printed wiring board card assembly. This level of protection is very effective against the most common methods of counterfeit attacks that modify the memory contents in a phone using test instructions accessible through an external phone connector. This can be done by upgrading the current cellular phone to use the data transfer device (DTD) authentication procedure described in Figure 8 prior to granting access to the field programming instructions. Both the authentication software code and the public key are stored in existing flash memory, thus avoiding any changes to the current customary design n.
An exemplary application of the present invention has been described in the description of a one-way hashing and key encryption system applied in ensuring and programming electronic memory in cellular telephones. However, as will be readily appreciated and acknowledged by those skilled in the art, any suitable function, calculation, algorithm, method, and system for deriving the signature of the memory contents can be applied in accordance with the present invention. In addition, the present invention has been described with reference to specific examples. However, as will be readily apparent to those skilled in the art, it is possible to embody the invention in a special form other than the preferred embodiments described above. For example, the present invention can be embodied in any electronic memory and / or electronic memory programming or access device without going against its spirit.
Further, the present invention can be applied to and implemented in digital signal processors, application-specific processors, or any other similar processor, or systems for electronic memory. Therefore, the preferred embodiments described herein are for illustration purposes only and should not be considered in a limited way anyway. The scope of the present invention is given not by the above description but by the appended claims, and all modifications and equivalent embodiments falling within the claims are intended to be included in the claims.
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP05002535A | Cites | Japan |
| JP05053919A | Cites | Japan |
29 members in 13 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 08706574 | United States of America | – | |
| 70657496 | United States of America | A | |
| 1996706574 | – | – | – |
| US19960706574 | – | – | – |
Members29
| Document | Office | Kind | |
|---|---|---|---|
| WO9810611A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU4172297A | Australia | A | |
| WO9810611A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP0923842A2 | European Patent Office (EPO) | A2 | |
| PL332050A1 | Poland | A1 | |
| BR9712007A | Brazil | A | |
| EE9900084A | Estonia | A | |
| CN1235743A | China | A | |
| US6026293A | United States of America | A | |
| HK1021104A1 | Hong Kong, China | A1 | |
| KR20000068467A | Republic of Korea | A | |
| JP2001500293A | Japan | A | |
| AU734212B2 | Australia | B2 | |
| CN1446015A | China | A | |
| CN1126398C | China | C | |
| KR100492840B1 | Republic of Korea | B1 | |
| EP0923842B1 | European Patent Office (EPO) | B1 | |
| DE69736065D1 | Germany | D1 | |
| ES2262189T3 | Spain | T3 | |
| DE69736065T2 | Germany | T2 | |
| JP2007293847A | Japan | A | |
| JP4050322B2 | Japan | B2 | |
| JP2008112443A | Japan | A | |
| JP2011170841A | Japan | A | |
| JP4777957B2 | Japan | B2 | |
| JP2011238246A | Japan | A | |
| JP4917681B2 | Japan | B2 | |
| JP4955818B2This record | Japan | B2 | |
| BRPI9712007B1 | Brazil | B1 |
14 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 4955818
- Publication, DOCDB
- 4955818
- Publication, EPODOC
- JP4955818B
- Application
- 7295
- Application, DOCDB
- 2011007295
- Application, EPODOC
- JP20110007295
Titles2
- Japanese
- 電子メモリ改竄防止システム
- English
- Electronic memory tampering prevention system
Classification
- CPC, 13
- G06F21/565
- H04L9/0643
- H04L9/3239
- H04L9/3247
- H04L9/3271
- H04L63/0823
- H04L63/123
- H04L2209/80
- H04W12/06
- H04W12/10
- H04W88/02
- H04W12/126
- H04W12/71
- IPC, 8
- G06F12 14
- H04L9 32
- H04M1 67
- G06F1 00
- G06F21 00
- G06F21 24
- G09C1 00
- H04W88 02