System and method for securing executable code
Abstract
A system and method for the secure storage of executable code and the secure movement of such code from memory to a processor. The method includes the storage of an encrypted version of the code. The code is then decrypted and decompressed as necessary, before re-encryption in storage. The re-encrypted executable code is then written to external memory. As a cache line of executable code is required, a fetch is performed but intercepted. In the interception, the cache line is decrypted. The plain text cache line is then stored in an instruction cache associated with a processor.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
10 claims: 10 independent, 0 dependent
- 1一種用於處理器指令的保密執行之系統,包括:一第一記憶體,其包含起動代碼及用第一密鑰所加密之圖像;一保密嵌入式處理器系統,其包括:一處理器;一與所述處理器相通訊之指令超快取記憶體;一與所述指令超快取記憶體通訊之記憶體控制器;一與所述指令超快取記憶體通訊之保密控制器;及一第二記憶體,其位於所述保密嵌入式處理器系統之外部,並與所述第一記憶體、記憶體控制器及保密控制器通訊,其中,所述用第一密鑰加密之圖像被傳輸至所述第二記憶體,被所述保密控制器解密,並由所述保密控制器使用第二密鑰再加密,用所述第二密鑰加密之圖像之一超快取記憶體線從所述第二記憶體被讀取,再用所述第二密鑰進行解密,然後存儲於所述指令超快取記憶體中,以被所述處理器所執行。
- 2如申請專利範圍第1項所述之系統,其中所述保密控制器包括使用三重資料加密標準(3DES)演算法及所述第一密鑰對所述被加密圖像進行解密之邏輯電路。
- 3如申請專利範圍第1項所述之系統,其進一步包括一密鑰管理模組,該密鑰管理模組包括:以加密形式接收所述第一密鑰之邏輯電路;使用會話密鑰對所述被加密之第一密鑰進行解密之邏輯電路;將所述第一密鑰轉發到所述保密控制器之邏輯電路。
- 4如申請專利範圍第1項所述之系統,其中所述保密控制器中包括:使用高級加密標準(AES)演算法重加密所述圖像的邏輯電路;及使用所述AES演算法解密所述超快取記憶體線的邏輯電路。
- 5一種提供處理器指令的保密執行的方法,其包括以下步驟:a.啟動處理器,以將加密編碼載入到外部記憶體中;b.使用圖像密鑰對所述加密編碼中解壓縮之部分進行解密,以產生解密解壓縮碼之第一部分;c.執行所述解密解壓縮碼之第一部分;d.使用所述圖像密鑰對所述加密編碼中之壓縮部分進行解密,以產生一圖像;e.鑒別所述圖像;f.解壓縮該圖像從而使其佔據外部記憶體中之一部分,起點在第一地址並且終點在終端地址;及g.執行所述圖像之保密執行。
- 6如申請專利範圍第5項所述之方法,其中使用三重資料加密標準(3DES)演算法執行所述解密步驟b及d。
- 7如申請專利範圍第5項所述之方法,在執行步驟a之前,所述方法進一步包括以下步驟:h.確定所述圖像密鑰是否失效,僅於所述圖像密鑰還沒有失效之條件下,才執行所述步驟a-g。
- 8如申請專利範圍第5項所述之方法,執行步驟a之前,所述方法進一步包括以下步驟:h.產生加密編碼。
- 9如申請專利範圍第8項所述之方法,其中所述步驟h包括:i.壓縮所述圖像;ii.對所述圖像進行散列處理以產生一散列值;iii.加密所述圖像;及iv.存儲所述加密編碼。
- 10如申請專利範圍第9項所述之方法,其中在所述步驟h.ii.中,使用保密散列演算法1(SHA-1)對所述圖像進行散列處理。
Independent claims10
52 paragraphs, as filed
System and method for secure executable coding
The present invention relates to information confidentiality, and especially relates to a confidential processing.
As everyone knows, confidentiality in computing platforms is a problem. In particular, any unintentional or unintended changes in executable code will produce terrible results. For example, malicious code (for example, a Trojan horse) can be inserted into the executable code to cause the processor to perform undesired and/or unpredictable operations. In other words, the hostile user can change the order of instructions so that the malfunctioning processor performs the operation. At this time, the result may also be undesirable. Other threats may not be malicious. For example, a memory hardware failure may change the executable code. Obviously, it will affect the operation of the processor and its results.
In addition, security is a problem related to the programmable logic circuit itself. The executable code itself may leak information that should be considered to be kept secret. The disclosure of executable code can cause undesired damage to sensitive information. Generally speaking, executable codes are easily damaged when they are stored and when they are transferred between the memory and the processor or its ultra-cache.
Considering this known threat and vulnerability, there is a need for a system and method that can overcome the above situation, so that the processor can only perform the required operations and maintain the confidentiality of its programs.
The purpose of the present invention is to provide secure storage of executable codes and secure transmission of such codes from memory to processor. The invention includes the storage of an encrypted version of the code. Before re-encryption in a storage device (such as flash memory), the code can be decrypted and decompressed as needed. Then write the re-encrypted executable code into the external memory. When a super cache memory line with executable code is needed, perform a fetching action and intercept it. In the interception process, the ultra-cache memory line is decrypted. The results are then transferred to the plain text super-cache memory line and stored in an instruction super-cache associated with the processor.
In order to solve the object of the present invention, the present invention provides a system for secretly executing processor instructions. The system includes: a first memory containing an activation code and an image encrypted with a first key; and a secret An embedded processor system, comprising: a processor; an instruction super cache memory communicating with the processor; a memory controller communicating with the instruction super cache memory; and a A secure controller for instructing super cache memory communication; and a second memory, which is located outside the secure embedded processor system and communicates with the first memory, the memory controller, and the secure controller , Wherein the image encrypted with the first key is transferred to the second memory, is decrypted by the security controller, and is re-encrypted by the security controller using the second key, using the An ultra-cache memory line of the image encrypted by the second key is read from the second memory, decrypted with the second key, and then stored in the command ultra-cache memory , To be executed by the processor.
In a preferred embodiment, the security controller includes a logic circuit that uses a Triple Data Encryption Standard (3DES) algorithm and the first key to decrypt the encrypted image.
In a preferred embodiment, the system further includes a key management module, which includes: a logic circuit for receiving the first key in an encrypted form; A logic circuit for decrypting the first key; and a logic circuit for forwarding the first key to the security controller.
In a preferred embodiment, the security controller includes: a logic circuit that uses an Advanced Encryption Standard (AES) algorithm to re-encrypt the image; and uses the AES algorithm to decrypt the super cache The logic circuit of the memory line.
In a preferred embodiment, the logic circuit for re-encrypting the image includes a logic circuit that implements the cipher block chaining (CBC, cipher block chaining) mode of the AES algorithm; and the logic circuit for decryption The logic circuit of the super cache line includes a logic circuit that implements the CBC mode of the AES algorithm.
A preferred embodiment is that the logic circuit for re-encrypting the image includes a logic circuit that implements the decryption mode of the CBC mode of the AES algorithm; and the logic circuit for decrypting the super cache memory The logic circuit of the body line includes a logic circuit that implements the encryption mode of the CBC mode of the AES algorithm.
A preferred embodiment is that in the logic circuit for re-encrypting the image, an address of the second memory is used as the initialization vector (IV) of the AES algorithm, wherein The address corresponds to the location of the ultra-cache line in the second memory; and in the logic circuit for decrypting the ultra-cache line, the address is used as The initialization vector.
In another aspect, the present invention provides a method for providing secure execution of processor instructions, which includes: a. activating the processor to load an encrypted code into an external memory; b. using an image key to encode the encrypted code The decompression part is decrypted to generate the first part of the decryption and decompression code; c. Execute the first part of the decryption and decompression code; d. Use the image key to decrypt the compressed part of the encryption code , To generate an image; e. Identify the image; f. Decompress the image so that it occupies a part of the external memory, with the starting point at the first address and the ending point at the terminal address; and g. Executing the image Like the confidential execution.
In a preferred embodiment, the decryption steps b and d are performed using the Triple Data Encryption Standard (3DES) algorithm.
In a preferred embodiment, before performing step a, the method further includes the following steps: h. It is determined whether the image key is invalid, and the step ag is executed only if the image key is not invalid.
In a preferred embodiment, before performing step a, the method further includes the following steps: h. Generate encryption codes.
A preferred embodiment is that the step h includes: i. Compress the image; ii. Hashing the image to generate a hash value; iii. Encrypting the image; iv. Store the encryption code.
In a preferred embodiment, in the step h.ii., the secure hash algorithm 1 (SHA-1) is used to hash the image.
In a preferred embodiment, in the step h.iii., the image is encrypted using the Triple Data Encryption Standard (3DES) algorithm.
In a preferred embodiment, in the step h.iv., the encrypted code is stored in the flash memory.
A preferred embodiment is that the step a includes: i. resetting the state of the processor; ii. loading the image key; iii. transmitting the encrypted code into the external memory; and iv. switching the processor to confidentiality model.
In a preferred embodiment, the external memory includes a double data transfer rate synchronous dynamic random access memory (DDR-SDRAM).
A preferred embodiment is that the step a.iv. includes: clearing the state of the processor; A. Set an instruction super cache memory associated with the processor to an invalid state; and limit the execution of the image to a part of the external memory.
In a preferred embodiment, the step g includes: i. Encrypt each ultra-cache memory line of the image separately; ii. Take out an encrypted ultra-cache memory line; iii. Intercept the extraction process; iv. .Decrypt the encrypted ultra-cache cable taken out; v. Determine whether the decrypted ultra-cache cable is valid; vi. If the decrypted ultra-cache cable is invalid, capture the decrypted ultra-cache cable; and vii If the decrypted super cache line is valid, execute the decrypted super cache line.
In a preferred embodiment, the step gi includes using the Advanced Encryption Standard (AES) to encrypt each ultra-cache memory line, and the step g.iv. includes using the AES algorithm to decrypt the extracted encryption Super cache memory line.
A preferred embodiment is that the AES algorithm is used in Cipher Block Chaining (CBC) mode.
In a preferred embodiment, the step gi includes using the AES algorithm decryption mode to encrypt each ultra-cache memory line, and in the step g.iv., the encryption mode of the AES algorithm is used to decrypt and retrieve the Encrypted super cache memory line.
A preferred embodiment is that the initialization vector (IV) of the AES algorithm of each ultra-cache line is the address of the ultra-cache line in the external memory.
The preferred embodiments of the present invention will now be described with reference to the accompanying drawings, and the reference numerals indicate elements with the same or similar functions. In the figures, the leftmost digit of each label corresponds to the figure in which the label is used for the first time. For the specific configurations and equipment described therein, it should be understood that they are for illustrative purposes only. Those skilled in the art can use other configurations and devices without departing from the spirit and scope of the present invention. For those skilled in the art, it is obvious that the present invention can also be used in a variety of devices, systems and applications.
I. Overview
The preferred embodiments of the present invention will now be described with reference to the accompanying drawings, and the reference numerals indicate elements with the same or similar functions. In the figures, the leftmost digit of each label corresponds to the figure in which the label is used for the first time. For the specific configurations and equipment described therein, it should be understood that they are for illustrative purposes only. Those skilled in the art can use other configurations and devices without departing from the spirit and scope of the present invention. For those skilled in the art, it is obvious that the present invention can also be used in a variety of devices, systems and applications.
II. System
The invention provides a secure embedded processor system for communicating with a memory module. The first figure is an embodiment of the present invention. In the figure, the secure embedded processor system 105 is connected to the external memory module 160 and the flash memory module 175. The flash memory module 175 stores executable codes (hereinafter referred to as images) in a compressed and encrypted form. As can be seen from the detailed description below, the encrypted and compressed image is transferred to the external memory 160 during the startup process. Then, the image is decrypted, decompressed, re-encrypted and stored in the external memory 160.
For instructions to be executed by the processor 110, one ultra-cache memory line is fetched from the external memory 160 each time. However, the removal process will be intercepted by the memory controller 150. Before loading the fetched super cache line into the command super cache 130, the security controller 140 decrypts it.
As shown in the figure, a key management module 170 is provided in the secure embedded processor system 105, which provides key management services for the secure controller 140. In an embodiment of the present invention, an external interface 180 can also be provided to realize the interconnection between the flash memory 175 and the system 105. A Peripheral Component Connection (PCI) interface 185 can also be provided to realize communication with the secure embedded processor system 105. The PCI interface 185, the external interface 180, the key management module 170, the security controller 140, and the processor 110 are connected to each other through an infrastructure 145 such as a bus.
The second figure shows the flash memory 175 in more detail. The second figure reveals the image structure when the image resides in the flash memory 175. The image includes an activation code 210. Next are two code blocks 220 and 230. Use the first encryption key, here called the image key, to encrypt the two code blocks together. In an embodiment of the present invention, these code blocks are encrypted using the Triple Data Encryption Standard (3DES) algorithm. In the illustrated embodiment, the code block 220 includes the logic required to decrypt the remaining code block 230. It should be noted that in the illustrated embodiment, the code block 230 is compressed. The code block 240 represents the authentication data obtained from the code blocks 210, 220, and 230. The code block is not part of the image itself. In the illustrated embodiment, the authentication process is a Hash Message Authentication Code (HMAC) process.
The third figure shows the image structure when the image is decrypted and decompressed and resides in the external memory 160. As shown in the figure, the block 330 occupies 10KB of storage capacity of the memory. The initial address of the storage interval is 310. The terminal address of this interval is 320. In an embodiment of the present invention, the initial address 310 and the terminal address 320 are forwarded to the memory controller 150. In order to activate the security check, it is not allowed to execute instructions outside these boundaries.
The fourth diagram is the flow when the instruction is fetched from the external memory 160. After the image is decrypted, the second key is used to re-encrypt the image to form a re-encrypted image 410. Then, the re-encrypted image 410 is retrieved based on the super cache memory line. For the purpose of decryption, the decryption logic circuit 440 finds and reads the ultra-cache line 420. In the illustrated embodiment, the address 430 of the ultra-cache line 420 is used to initiate the decryption process. In an embodiment of the present invention, the re-encryption process uses the Advanced Encryption Standard (AES) algorithm according to the Cipher Block Chaining (CBC) mode. In addition, in an embodiment of the present invention, the re-encryption process can use the AES/CBC process in the decryption mode. As a result, in this embodiment, the decryption process 440 actually uses the AES encryption mode. Then forward the obtained plaintext super-cache line 450 to the command super-cache 130. Finally, the processor 110 executes the plaintext super cache line 450.
As shown in the first figure, the key management module 170 handles part of the management and security functions related to the protection of encryption keys. In particular, in one embodiment of the present invention, the secure embedded processor system 105 receives the image key in encrypted form. The key management module 170 uses a session key to decrypt the encrypted image key. As a result, the security controller 140 uses the obtained plaintext image key as described above.
In addition, a time limit can be associated with the image key, so that the image key can only be used for a given duration or at a specific point in time. After this point in time, the key can no longer be used, and it is called invalid. In an embodiment of the present invention, the security controller 140 checks whether the image key has expired before using the key. Of course, the verification can also be performed in the key management module 170.
III. Method
The fifth picture shows the initial compression and encryption process when the image is stored in the flash memory. The process starts at step 510. In step 520, the image is compressed. In step 530, the image is hashed to generate HMAC. In one embodiment of the present invention, it uses Secure Hash Algorithm 1 (SHA-1). In step 540, the compressed image is encrypted using the image key. As mentioned above, the encryption can be performed using the 3DES algorithm. In step 550, the obtained compressed and encrypted image is stored in the flash memory. This process ends in step 560.
The sixth picture is the overall process of secretly accessing and executing images. The process starts at step 610. In step 620, the processor undergoes its startup operation. In step 630, the undecompressed part of the image is decrypted using the image key. In step 640, the decompression code is executed. The logic in the decompression code part of the encoding is used to decrypt the remaining images. In step 650, the remaining part of the image is decrypted using the image key. In step 660, the image is identified. As mentioned above, the SHA-1 algorithm can be used to perform authentication. In step 670, the image is decompressed. In step 680, the confidential execution is started. The process ends in step 690.
The seventh figure shows in more detail the startup steps of the processor (ie, step 620 in the sixth figure). The process starts at step 710. In step 720, the device status is reset. In step 730, for the purpose of sequential encryption processing, an encryption code is loaded. In step 740, the image is moved from the flash memory to the external memory. In an embodiment of the present invention, a double data transfer rate synchronous dynamic random access memory (DDR-SDRAM) can be used to implement an external memory. In step 750, the system is switched to the secure mode. The process ends in step 760.
The eighth figure shows in more detail the steps of switching to the secure mode (ie, step 750 in the seventh figure). The process starts at step 810. In step 820, the processor state is cleared. In step 830, the instruction and data super cache associated with the processor is set to an invalid state. It can prevent any information that happens to reside in these caches from being executed by the processor. In step 840, the address boundaries above and below the image are forwarded to the memory controller, thereby limiting execution to n kilobytes below the DDR-SRAM. This process ends at step 850.
The ninth figure shows in more detail the steps of the secure execution (step 680 in the sixth figure). The process starts at step 910. In step 915, the image is encrypted using the session key based on each ultra-cache line. In an embodiment of the present invention, this step uses the AES algorithm in the CBC mode. In addition, the decryption configuration of AES can also be used in the encryption process. It provides error checking during the entire image encryption process. In step 920, the encrypted image is written into the external memory. In step 925, an instruction ultra-high-speed ultra-cache memory line is fetched, and the instruction ultra-fetch memory line is fetched within the address boundary. In step 930, the retrieval is intercepted by the memory controller. In step 935, the security controller decrypts the ultra-cache line. If the encryption process uses the AES/CBC algorithm in the decryption mode, then the decryption step 935 will actually use the AES/CBC encryption mode. After decrypting the ultra-cache line in step 935, it is determined in step 940 whether the obtained command is valid. If it is invalid, the command is captured in step 945. Otherwise, the instruction is ready to be executed in step 955. In step 960, it is determined whether there are additional instructions that need to be fetched and executed, or whether the process is aborted. If the process has been aborted, the process ends in step 950. Otherwise, the process returns to step 925 to fetch the additional super cache line.
Figure 10 shows another method of the present invention. The process starts at step 1005. In step 1010, the boot process is initiated from the single-board read-only memory (ROM). In step 1015, the activation code is submitted to the security module. In step 1020, the activation code is hashed. In this step, the security module will keep the hash value. In step 1025, the start code is executed. In step 1030, the compressed code is hashed so that the security module maintains the cached value it has obtained. In step 1035, the hash value is marked. In step 1040, the encrypted image is transferred to the external memory. As described above, in one embodiment of the present invention, the external memory can be implemented by DDR-SRAM. In step 1045, the decompression code is decrypted using the image key. In step 1050, the decompression code is executed. In step 1055, the remaining image is decrypted with the image key. In step 1060, the remaining images are decrypted as needed. This process ends at step 1065.
IV. Conclusion
To sum up, the present invention meets the requirements of an invention patent, and Yan filed a patent application in accordance with the law. However, the above are only preferred embodiments of the present invention. For those who are familiar with the technique of the present application, equivalent modifications or changes made in accordance with the spirit of the present invention should be included in the scope of the following patent applications.
<p>105Confidential embedded processor system</p><p>110Processor</p><p>130Command super cache memory</p><p>140Security Controller</p><p>145Infrastructure</p><p>150Memory Controller</p><p>160External memory</p><p>170Key Management Module</p><p>175Flash memory module</p><p>180External interface</p><p>185Peripheral component connection (PCI) interface</p><p>210Activation code</p><p>220, 230, 240Code block</p><p>310The initial address is</p><p>320The terminal address is</p><p>330 block</p><p>410Re-encrypted image</p><p>420Super Cache Memory Line</p><p>430Address</p><p>440Decryption logic circuit</p>
The first figure is the principle block diagram of the present invention, which shows the overall structure and content of an embodiment of the present invention; the second figure is an embodiment of the present invention when the executable code is in the encrypted and compressed form in the flash memory. Figure 3 is a schematic diagram of an external memory containing executable codes for decryption and decompression in an embodiment of the present invention; Figure 4 is a fetching process of an embodiment of the present invention, in which the code is super cached The memory line is decrypted and forwarded to the command super cache memory; the fifth figure is a flowchart of the generation of an encrypted image according to an embodiment of the present invention; the sixth figure is an embodiment of the present invention to access and use the encrypted image The overall flowchart; the seventh diagram is a detailed flowchart of the processor startup process of an embodiment of the present invention; the eighth diagram is a flowchart of switching to the confidential mode in an embodiment of the present invention; the ninth diagram is an implementation of the present invention The flow chart of the confidential execution process in the example; Figure 10 is a flow chart of a simplified version of the method of the present invention.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| TWI659329B | Cited by | Taiwan Province of China | Examiner |
10 members in 4 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 60518323 | United States of America | – | |
| 51832303 | United States of America | P | |
| 10879349 | United States of America | – | |
| 87934904 | United States of America | A |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| US2005100163A1 | United States of America | A1 | |
| EP1536308A2 | European Patent Office (EPO) | A2 | |
| TW200527872AThis record | Taiwan Province of China | A | |
| CN1677922A | China | A | |
| EP1536308A3 | European Patent Office (EPO) | A3 | |
| TWI298591B | Taiwan Province of China | B | |
| CN100542085C | China | C | |
| US7734932B2 | United States of America | B2 | |
| US2010241841A1 | United States of America | A1 | |
| US8799678B2 | United States of America | B2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A |
Numbers
- Publication
- 200527872
- Application
- 93134287
Titles4
- Chinese
- 保密可執行編碼之系統及方法
- English
- System and method for securing executable code
- Unlabeled
- 保密可執行編碼之系統及方法
- Unlabeled
- System and method for secure executable coding
Classification
- CPC, 2
- G06F21/72
- G06F21/51
- IPC, 4
- H04L9 06
- G06F1 00
- H04L9 00
- H04L9 14