Memory content testing
Abstract
PCT No. PCT/GB95/01642 Sec. 371 Date Jan. 13, 1997 Sec. 102(e) Date Jan. 13, 1997 PCT Filed Jul. 12, 1995 PCT Pub. No. WO96/02917 PCT Pub. Date Feb. 1, 1996A method of testing a memory associated with a microprocessor, particularly for use in smart cards. The method involves comparing the output from the memory (2) passed along a read path (10) with predetermined data signals generated externally and passed via a port (7) along a read path (9). Comparison is carried out in a comparison device (3) which may, for example, be the microprocessor, suitably programmed. The output form the comparison device (3) is a simple pass/fail verification signal applied to a port (5). The stored data held in memory (2) may be permanently held data such as in a ROM, or (where the memory is alterable) may be specially written to the memory for the purpose of the text.

Term
Term ended
Expired 12 July 2015, 11.2 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
16 claims: 2 independent, 14 dependent
- 1Patent claims Zastrzeżenia patentowe 1. A method of testing the correct operation of a memory coupled to a module, which method provides predetermined data as input to the module, compares the predetermined data internally in the module with data stored in memory, and produces a module verification output characterized by that the test data is entered into the memory (2), the predetermined data is encrypted before being supplied as input, and the encrypted predefined data is compared with the test data stored in memory (2), an integrated circuit (1) is used as the module, and correctness is determined from the output verification signal, or the incorrectness of the write function coupled with the memory integrated circuit (1) (2) and its storage properties. 1. Sposób testowania poprawności działania pamięci sprzężonej z modułem, w którym to sposobie podaje się określone wstępnie dane jako dane wejściowe do modułu, porównuje się te określone wstępnie dane wewnętrznie w module, z danymi przechowywanymi w pamięci oraz wytwarza się wyjściowy sygnał weryfikacyjny modułu, znamienny tym, że wpisuje się dane testowe do pamięci (2), szyfruje się określone wstępnie dane przed ich doprowadzeniem jako dane wejściowe i porównuje się zaszyfrowane określone wstępnie dane z danymi testowymi przechowywanymi w pamięci (2), przy czym jako moduł stosuje się układ scalony (1), a na podstawie wyjściowego sygnału weryfikacyjnego określa się poprawność lub niepoprawność funkcji zapisu sprzężonej z układem scalonym (1) pamięci (2) i jej własności zapamiętywania.
- 8A method of testing the correct operation of a memory coupled to a module, which method provides predetermined data as input to the module, compares the predetermined data internally in the module with data stored in memory, and produces a module verification output characterized by that the predetermined data is encrypted before it is provided as input and the encrypted predetermined data is compared with the data stored in the memory (2), and the correctness or incorrectness of the memory contents is verified based on the result of the comparison. 8. Sposób testowania poprawności działania pamięci sprzężonej z modułem, w którym to sposobie podaje się określone wstępnie dane jako dane wejściowe do modułu, porównuje się te określone wstępnie dane wewnętrznie w module, z danymi przechowywanymi w pamięci oraz wytwarza się wyjściowy sygnał weryfikacyjny modułu, znamienny tym, że szyfruje się określone wstępnie dane przed ich doprowadzeniem jako dane wejściowe i porównuje się zaszyfrowane określone wstępnie dane z danymi przechowywanymi w pamięci (2), przy czym na podstawie wyniku porównania weryfikuje się poprawność lub niepoprawność zawartości pamięci.
Independent claims2
29 paragraphs, as filed
The subject of the invention is a method of testing the correct operation of a memory coupled with a module.
The memory is typically an invariant memory, i.e., a non-volatile memory ROM, or a memory whose contents can be changed, e.g., an electrically programmable fixed EPROM or a random access memory RAM.
In many cases it is necessary to test memory containing specific information. An example is the use of integrated circuit credit cards known as smart cards. Typically, the memory of a smart card is tested by attaching the card to a reader, reading the contents of the memory and checking the read content, possibly by checking a checksum or by comparing the read content with the data that should be present. Often the contents of the memory are confidential and it is possible for unauthorized persons to gain access to the information by simulating a memory test.
EP 0215464 describes an integrated circuit comprising a read-only non-volatile memory whose output is not allowed for an external terminal and a comparator for comparing the data read from the non-volatile memory with the data fed to the external terminal. The result of the comparison is sent to an external terminal.
Moreover, from EP 0267114 an integrated circuit containing an electrically programmable memory is known. Data from the I / O device is decoded and compared in the comparator with memory removal.
The method according to the invention is intended for testing the correct operation of the memory coupled with the module. According to this method, the predetermined data is provided as input to the module, internally compared those predefined in the module with the data stored in memory, and the module verification output is generated. A method of this type is characterized in that the test data is stored in a memory, the predetermined data is encrypted before it is fed as input and the encrypted predetermined data is compared with the stored test data. An integrated circuit is used as a module, and the correctness or incorrectness of the write function coupled to the memory chip and its storage properties are determined on the basis of the verification output signal.
Preferably, the encrypted predetermined data is fed as the first input data to a comparator forming part of the integrated circuit in which the memory content is passed as the second input to the comparator, the comparator comparing the data fed to its two inputs and generating a verification output that identifies the comparison as valid or not valid. Test data is applied to the write input of a memory and is temporarily stored in that memory before it is fed to the second input of the comparator. The verification signal is generated
178 997 with a time delay. The comparison of said data is carried out by means of a programmed microprocessor of the integrated circuit. The integrated circuit is a module part having at least one integrated circuit with a memory and a microprocessor. A smart card is used as the integrated circuit.
In an alternate embodiment, the method of testing the correct operation of a memory coupled to a module is characterized by encrypting the predetermined data before supplying it as input and comparing the encrypted predetermined data with the data stored in the memory, and verifying the correctness or incorrectness based on the result of the comparison. memory contents.
Preferably, the encrypted predetermined data is fed as the first input to a comparator forming part of the module, the memory contents are passed as the second input to the comparator, and the comparator compares the data fed to its two inputs and generates a verification test. an output signal identifying the comparison as valid or not valid. Data contained in memory includes the resident data of that memory. For testing the memory write function, the data stored in this memory includes test data which is fed as input to the module and stored in memory prior to comparison. An electrically modifiable memory is used as the memory, the test data being applied to the write input of the memory and stored temporarily in the memory before being fed to the second input of the comparator. The verification signal is generated with a time delay. The comparison of said data is carried out by means of a programmed microprocessor. Preferably, a module is used having at least one integrated circuit including memory and microprocessor. At least one chip is a smart card.
The method according to the invention provides for obtaining output verification information about the correctness or incorrectness of the memory contents. It is also possible to check the operation of the memory write function with electrically changed contents. When using this method with internal comparison, the memory contents are not directly accessible from the outside. The only output is the verification signal. The applied encryption of the input data ensures that the input data does not have a clear correlation with the memory content. A confidential algorithm is used for encryption.
The subject of the invention has now been elucidated with reference to a block diagram of a system shown in the drawing, which system is adapted to carry out the method according to the invention.
The drawing shows an integrated circuit 1 provided with a memory 2 in the form of an electrically programmable EEPROM containing specific data, which memory 2 is coupled to a comparator 3, for example in the form of a microprocessor programmed to perform the data comparison. The interface 4 connected to the outside world is represented by a dashed line. The interface 4 has three ports: an output port 5, an address / control port 6 and an input port 7 through which signals pass back and forth between the chip 1 and the outside world. The internal path from input port 7 is split into two paths: input data write path 8 going to memory 2 and input data read path 9 going to comparator 3.
The testing process is performed by inputting program data into chip 1 and making an internal comparison with comparator 3. The program data is generated by external means (not shown) and transferred to comparator 3 via input port 7 and reading path 9 of input data. Corresponding data stored in memory 2 are transferred to comparator 3 through the read path 10 of data stored in memory 2. The comparator compares the data coming from the two paths, the input data read path 9 and the data read path 10 stored in memory 2, and the result of the comparison is communicated to the outside world via the output port 5 by means of a verification signal identifying the comparison as valid (pass) or incorrect (folded). This method prevents the contents of the sca memory from being emptied
178 997 lane 1 at any time and therefore offers a high degree of protection. Read addresses and control signals are preferably generated by external means (not shown) and inputted into the chip through the address / control port 6 of interface 4. The address / control signals pass into memory and control the flow of data from memory 2 to comparator 3 in a conventional manner.
In an alternate embodiment (not shown), the output port 5 and the input port 7 are combined into a single multiplexed read / write port, and the address / control port 6 is omitted. The address and control signals that would otherwise use the address / control port 6 were input by multiplexing through the subport of the combined output and input port and recording path.
This flowchart also allows the electrically modifiable memory write function to be tested by being able to write test data to the memory 2 via the input port 7 on the interface 4 and the write path 8 of the input data. The correctness of the record was then checked as already described, also under the control of address / control signals. In this way, properties such as persistence, memorization time and memory cell boundaries can be checked.
Example 1. Using the circuit shown in the figure, the process of testing the correct operation of the electrically modified complex memory with the integrated circuit was carried out. Test data was written to memory 2 and predetermined data was fed to IC 1, then the data was internally compared by comparator 3 on IC 1 with test data stored in memory 2, and a verification output was generated by IC 1. On the basis of the output verification signal, the correctness or incorrectness of the notation function and the memory memorization properties were ascertained. In this way, the writing function and storage properties of the electrically modifiable memory were tested.
Example II. The process of testing the contents of the memory assigned to the microprocessor in the module was carried out, whereby the predetermined data was fed as input to the module, the predetermined data was encrypted, the encrypted predetermined data inside the module was compared with the data stored in the memory, and the output verification information was obtained at the output of the module. about the correctness or incorrectness of the memory contents in the comparison.
The data stored in the memory are data residing permanently or partially in the memory, preferably programming and / or initialization data, possibly data written into the memory in the first step of the test method.
The module used was an integrated circuit containing a memory and a microprocessor, or a set of integrated circuits physically connected by enclosing them in a common housing. Preferably, a smart card chip was used as the module. When using internal comparison, the contents of the memory are not directly accessible from the outside. The only output is the verification signal.
In order to prevent delinquent attempts to determine the memory content consisting in the automatic introduction of successive sets of test data of systematically changed content until the verification signal indicates that the memory content corresponds to the input data, the microprocessor was programmed in such a way that each output verification signal was output with a specified delay, confirming or not . There was a delay between successive beeps of microseconds or seconds.
In both examples presented, to prevent fraudulent memory control, input data encryption was used, preferably by running a confidential algorithm prior to comparison. As a result, the input data did not have a clear correlation with the memory content. The algorithm or key to it differs from batch to batch of smart cards.
It has been found that criminal attempts to access the contents of the memory are still possible by fully testing all possible memory combinations. This has been found to be it
178 997 more difficult, the less frequently a pass / fail signal is generated. For example, if a valid / invalid signal is generated after reading an 8-bit byte, then 256 reads are required to fully test the byte. If the correct / incorrect signal is generated only after reading a 16-bit word, then a maximum of 65,536 readings are needed to fully test the word. Similarly, a 32-bit word requires 4,294,967,296 reads to fully test. Using this approach can render full testing unusable for extracting memory content.
An additional security is the use of test words going beyond the boundaries of the memory page, possibly to a varying degree.
<img file="PL178997B1_D0001.tif" />
Publishing Department of the Polish Patent Office. Circulation of 60 copies
Price PLN 2.00.
2 sheets
Sheet 1 Sheet 2
34 members in 24 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 9414266 | United Kingdom | A | |
| 9414266 | United Kingdom | A | |
| 9501642 | United Kingdom | W | |
| 9501642 | United Kingdom | W | |
| 9414266 | – | – | – |
| GB9501642 | – | – | – |
| GB19940014266 | – | – | – |
| WO1995GB01642 | – | – | – |
Members34
| Document | Office | Kind | |
|---|---|---|---|
| GB9414266D0 | United Kingdom | D0 | |
| CA2194289A1 | Canada | A1 | |
| WO9602917A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2895595A | Australia | A | |
| ZA955806B | South Africa | B | |
| NO970112D0 | Norway | D0 | |
| NO970112L | Norway | L | |
| GB9626477D0 | United Kingdom | D0 | |
| GB2303950A | United Kingdom | A | |
| EP0770256A1 | European Patent Office (EPO) | A1 | |
| PL318166A1 | Poland | A1 | |
| EE9700015A | Estonia | A | |
| BR9508279A | Brazil | A | |
| JPH10503038A | Japan | A | |
| MX9700366A | Mexico | A | |
| AU692573B2 | Australia | B2 | |
| NZ289190A | New Zealand | A | |
| US5841786A | United States of America | A | |
| GB2303950B | United Kingdom | B | |
| EP0770256B1 | European Patent Office (EPO) | B1 | |
| AT176741T | Austria | T | |
| ATE176741T1 | Austria | T1 | |
| DE69507809D1 | Germany | D1 | |
| ES2126908T3 | Spain | T3 | |
| SI0770256T1 | Slovenia | T1 | |
| DE69507809T2 | Germany | T2 | |
| GR3029918T3 | Greece | T3 | |
| MD970057A | Republic of Moldova | A | |
| DK0770256T3 | Denmark | T3 | |
| TW371339B | Taiwan Province of China | B | |
| GEP19991885B | Georgia | B | |
| PL178997B1This record | Poland | B1 | |
| RU2155996C2 | Russian Federation | C2 | |
| MD1844B2 | Republic of Moldova | B2 |
Numbers
- Publication, DOCDB
- 178997
- Publication, EPODOC
- PL178997B
- Application
- 95318166
- Application, DOCDB
- 31816695
- Application, EPODOC
- PL19950318166
Titles
- English
- MEMORY CONTENT TESTING
Classification
- CPC, 1
- G11C29/52
- IPC, 11
- G06F12 16
- G06F21 60
- G06F12 14
- G06F21 62
- G06F21 64
- G06K19 07
- G06K19 073
- G11C29 00
- G11C29 02
- G11C29 08
- G11C29 52